How Does The Internet Do Email (SMTP)
Let's say Dr. Sue Sender wants to send an email to Gus Getter. Sender uses some program to write her email, say Outlook, Apple Mail, or gmail.com. When she hits "send", the email may bounce around a bit inside her hospital but eventually lands on a computer (a "Server") connected to the Internet.
That Server uses the Internet to hand the email to a Server located in Gus's environment where, similar to the hospital, it may bounce around a bit until get gets someplace Getter can see it.
This document is a simple explanation of exactly how those two Servers transfer an email.
Simple Mail Transport Protocol (SMTP)
One of the very first things that the Internet could do was email (circa 1971), long before shopping, videos, facebook, and google. Still today one of the biggest uses of the Internet is email. The smart people who worked on the early Internet designed a way for email to work that was so good it is still how email works today. It's called "SMTP" which stands for Simple Mail Transport Protocol. And it really is simple yet still powerful enough to transport all email sent through the Internet.
SMTP Example
SMTP is a language that Servers use to send mail over the Internet. Here is a example of an SMTP conversation. Lines are colored to show if they came from Getter or Sender.
220 mail.getter-server.com ESMTP
HELO mail.sender-server.com
250-mail.getter-server.com at your service, [10.11.12.13]
250-SIZE 157286400
250 8BITMIME
MAIL FROM:sue@sender-company.com
250 OK
RCPT TO:gus@getter-company.com
250 OK
DATA
354 Enter mail, end with "." on a line by itself
To: gus@getter-company.com
From: sue@sender-company.com
Subject: test email
This is a test email.
.
250 67PM1toC027114 Message accepted for delivery
QUIT
221 closing connection
SMTP Example Deconstructed
The email transfer starts with Sender's Server contacting Getter's Server and saying "I want to send you an email". How that works is described at the bottom of this post – it's not SMTP.
Getter's Server starts the dialog with a Greeting that has its name:
220 mail.getter-server.com
Sender's Server says Hello and gives its name:
HELO mail.sender-server.com
Getter's Server says Hello back and gives Sender some info about itself:
250-mail.getter-server.com at your service, [10.11.12.13]
250-SIZE 157286400
250 8BITMIME
Sender then says it has a message from Sue:
MAIL FROM:sue@sender-company.com
Getter says it will accept an email from Sue (Getter could say it will not accept a message from Sue):
250 OK
Sender then says the message is for Gus:
RCPT TO:gus@getter-company.com
Getter says it will accept an email for Gus (Getter could say it will not accept a message for Gus):
Sender then says I'm ready to send the email contents:
DATA
Getter answers that it's ready to receive the email contents:
354 Enter mail, end with "." on a line by itself
Sender then sends the message headers and message body, separated by a blank line and ending with a single dot on a line by itself:
To: gus@getter-company.com
From: sue@sender-company.com
Subject: test email
This is a test email.
.
Getter says it got the message and will deliver it (Getter could say it will not deliver the message):
250 67PM1toC027114 Message accepted for delivery
Sender then says it is finished (it could have had another message to send).
QUIT
Getter says ok and disconnects:
221 closing connection
Keeping Email Safe (STARTTLS)
By the late 1990's Internet email was being used to communicate things that should be kept private: credit card numbers, doctor/patient information, trade secrets. All this information was out on the Internet where anyone with access could see it. So the next generation of smart people working on the Internet designed a way for SMTP to use encryptiony to hide the SMTP. It's called STARTTLS and again it was so good that it is still in use today, even with state-of-the-art quantum encryption.
STARTTLS Example
Here is an example of STARTTLS in an SMTP conversation:
220 mail.getter-server.com ESMTP
EHLO mail.sender-server.com
250-mail.getter-server.com [10.11.12.13] Ready
250-SIZE 157286400
250-STARRTLS
250 8BITMIME
STARTTLS
220 Ready to start TLS
17 03 03 00 2d 4c ba 99-73 89 82 0e 4a f3 93 54
52 57 71 78 88 ba 1d fb-fc f9 a3 64 cf 62 f8 32
ae 5e e6 04 a8 3a 23 98-94 54 06 fc 43 3e d6 04
f6 d2
~~~EHLO mail.sender-server.com
17 03 03 00 40 c8 4c 43-7e 54 9a 55 25 ff 0c e2
7e ac 0b fb cb 5a 2b b6-15 a9 30 2f 5c 41 94 88
83 a6 76 db f3 5d 16 47-56 d1 be 49 14 96 ff 23
ef 61 08 12 df 93 7e 46-89 e5 4f b2 9e 54 28 bb
14 62 f8 b9 0b
~~~250-mail.getter-server.com [10.11.12.13] Ready
17 03 03 00 24 7e e1 96-fc 87 b9 8d 93 61 3a e7
44 19 64 8f f5 ac d2 a0-08 72 50 2d 81 73 02 b8
17 cc e8 48 bf e0 36 7a-86
~~~250-SIZE 157286400
17 03 03 00 1e 6e aa 8a-b7 23 6d 00 9a ea b6 7e
d7 02 24 0c f7 96 39 2d-81 72 93 29 b7 ac 0b 93
d8 66 50
~~~250 8BITMIME
17 03 03 00 32 bd 0d c6-f3 be ae 56 7f 7e 19 51
d3 08 c9 29 2a 27 02 b0-c4 6f 87 6b 67 3c a2 66
95 67 ce 4f bb 73 3a 90-e0 ae ff fd d0 90 cc b7
4b d7 fc 77 f5 f1 75
~~~MAIL FROM:sue@sender-company.com
17 03 03 00 18 d3 44 ba-af 90 74 97 04 d3 76 80
da 52 fd 77 39 07 3e 42-bf 46 fa 7c 64
~~~250 OK
17 03 03 00 13 8c 6a 44-59 66 f7 dd 0f 4c d9 fb
e0 e8 9e 5f 48 44 5b fa-
~~~RCPT TO:gus@getter-company.com
17 03 03 00 18 24 a0 a1-6f 43 91 03 1a bc 0d f3
c0 d1 b3 c3 d1 52 b5 61-f6 4f bc 07 e0
~~~250 OK
17 03 03 00 16 2b 0d da-2b 33 04 3f 6f 10 c9 2a
3e 58 6e 62 db 87 8e 41-8f 5e 8c
~~~DATA
17 03 03 00 42 ae 7c 38-0b f3 8e e8 3a 70 58 98
d2 3d 48 f4 83 2b 35 cf-3e 70 f8 a2 cc 4a ae 72
8f b6 35 cd 45 29 5b a4-1b c0 aa d0 47 16 b4 bd
93 17 3d 30 40 5b 45 13-40 62 d2 cd d3 99 4e 03
1c f0 73 97 50 2c c3
~~~354 Enter mail, end with "." on a line by itself
17 03 03 00 2c ba ab a7-a1 08 b2 f7 2e e5 de 5f
91 84 d3 b6 ef 07 bb a4-d8 c0 bd 26 22 db 38 55
1a 53 80 35 41 c9 14 19-2e 84 bb ce 04 c2 41 3a
6a
~~~To: gus@getter-company.com
17 03 03 00 2e dd 69 51-8c 0e 31 40 06 7e 88 5c
10 9d ce 94 60 07 cb 41-ed 01 95 75 da fc 85 64
42 9e c9 05 ec 7b 17 a3-15 e8 c4 78 ac 79 7c 7e
60 3f c1
~~~From: sue@sender-company.com
17 03 03 00 25 ca 07 a4-34 cf 9b cb b3 27 e5 a5
c1 75 d1 28 8d a3 b6 58-38 87 56 21 aa 8b e0 b6
5e e1 a0 ac fb e5 fe a1-00 55
~~~Subject: test email
17 03 03 00 12 92 36 e8-2c 54 92 9b 2d 3b 33 f7
fd 5f 42 66 f6 81 39
~~~
17 03 03 00 27 c8 19 55-5a 5e 0a 6f 43 4c aa 13
06 bd 18 0b 2c 4a 1e a1-48 75 b6 57 95 06 3a 96
97 aa e2 98 d9 db 16 31-84 aa af 12
~~~This is a test email.
17 03 03 00 13 39 92 4f-78 e2 06 9f 6d f1 6d ae
ca 38 22 9b f9 39 91 a3-
~~~.
17 03 03 00 42 ce f0 eb-14 79 48 c1 9b e0 ff cb
aa 5c 92 8e 0d 62 e0 8b-4f be c5 05 22 9b ab ff
8c ea 81 3a c1 92 0c ef-f7 4f 77 0e 32 0e 3c 2c
19 39 1a d9 ec cd 82 f7-a8 2b f9 31 41 7a 97 6b
5f f9 06 5c e1 f6 df
~~~250 67PM1toC027114 Message accepted for delivery
17 03 03 00 13 0b 34 6c-5c 51 36 1d 75 5e db e5
5e b4 cb 54 76 4f 2c e2-
~~~QUIT
17 03 03 00 28 3f fa 38-f4 e2 33 f7 f6 c4 9d f0
c9 a2 b5 c5 f8 4e 48 4d-55 de e5 a9 51 cd 0b d8
55 6b fe 03 de 7e 77 bd-23 a0 66 1c 06
~~~221 closing connection
Uncolored lines starting with ~~~ are not real: they are the decrypted contents of the binary data that was actually sent. Only Gus and Sue's servers know the decrypted contents, the Internet can only see the unintelligable binary data.
Keeping Email Even Safer
Since STARTTLS there have been a number of additional security features grafted onto Internet email. These are beyond the scope of this document, but they include:
- SPF
- adds security to HELO and MAIL FROM parts of SMTP
i.e. mail.sender-server is allowed to send mail that says it is from sender-company.com - DKIM
- adds security to MAIL FROM and DATA parts of SMTPi.e. it signs and protects the email like a wax-seal on a paper envelope
- DMARC
- adds even more security to SPF and DKIM
- MTA-STS
- adds security help Sender be sure they are connecting to Getter's real servers
- DANE
- adds security features to SSL Certificate usage
- TLS-RPT
- provides a way for Sender to tell Getter something is wrong with Getter's email
- BIMI
- provides visual confirmation to Gus that the email really came from Sue
- DNSSEC
- adds security to all DNS name lookups
i.e. prevents someone from saying my IP address is also good for mail.sender-company.com - FCrDNS
- makes sure host names and addresses match
i.e. prevents someone from saying this host name goes to this (bad) IP address
Before SMTP Starts
We said above that before SMTP, an email transfer starts with Sender's Server contacting Getter's Server and saying "I want to send you an email". Sender knows it wants to send an email, but how does Getter know that Sender is out there wanting to send it something?
Getter's Server is like an amusement park. Just as an amusement park has different locations for the different ride lines, Servers have different locations ("Ports") for the different things they can do. Each different Port knows how to talk a certain Protocol (language), like the SMTP language described above. These protocols are things like "send me this webpage" (HTTP), "tell me what the IP address is for this domain name" (DNS), "let me run a program" (TELNET, SSH, RDP), or "I want to send you an email" (SMTP).
So when a Sender wants to send an email, it contacts a Getter's Server on the SMTP Port (port #25), and the two of them know to start talking SMTP.
