How Does The Internet Do Email (SMTP)

Let's say Dr. Sue Sender wants to send an email to Gus Getter. Sender uses some program to write her email, say Outlook, Apple Mail, or gmail.com. When she hits "send", the email may bounce around a bit inside her hospital but eventually lands on a computer (a "Server") connected to the Internet.

That Server uses the Internet to hand the email to a Server located in Gus's environment where, similar to the hospital, it may bounce around a bit until get gets someplace Getter can see it.

This document is a simple explanation of exactly how those two Servers transfer an email.

Simple Mail Transport Protocol (SMTP)

One of the very first things that the Internet could do was email (circa 1971), long before shopping, videos, facebook, and google. Still today one of the biggest uses of the Internet is email. The smart people who worked on the early Internet designed a way for email to work that was so good it is still how email works today. It's called "SMTP" which stands for Simple Mail Transport Protocol. And it really is simple yet still powerful enough to transport all email sent through the Internet.

SMTP Example

SMTP is a language that Servers use to send mail over the Internet. Here is a example of an SMTP conversation. Lines are colored to show if they came from Getter or Sender.

220 mail.getter-server.com ESMTP HELO mail.sender-server.com 250-mail.getter-server.com at your service, [10.11.12.13] 250-SIZE 157286400 250 8BITMIME MAIL FROM:sue@sender-company.com 250 OK RCPT TO:gus@getter-company.com 250 OK DATA 354 Enter mail, end with "." on a line by itself To: gus@getter-company.com From: sue@sender-company.com Subject: test email This is a test email. . 250 67PM1toC027114 Message accepted for delivery QUIT 221 closing connection
SMTP Example Deconstructed

The email transfer starts with Sender's Server contacting Getter's Server and saying "I want to send you an email". How that works is described at the bottom of this post – it's not SMTP.

Getter's Server starts the dialog with a Greeting that has its name:

220 mail.getter-server.com

Sender's Server says Hello and gives its name:

HELO mail.sender-server.com

Getter's Server says Hello back and gives Sender some info about itself:

250-mail.getter-server.com at your service, [10.11.12.13] 250-SIZE 157286400 250 8BITMIME

Sender then says it has a message from Sue:

MAIL FROM:sue@sender-company.com

Getter says it will accept an email from Sue (Getter could say it will not accept a message from Sue):

250 OK

Sender then says the message is for Gus:

RCPT TO:gus@getter-company.com

Getter says it will accept an email for Gus (Getter could say it will not accept a message for Gus):

250 OK

Sender then says I'm ready to send the email contents:

DATA

Getter answers that it's ready to receive the email contents:

354 Enter mail, end with "." on a line by itself

Sender then sends the message headers and message body, separated by a blank line and ending with a single dot on a line by itself:

To: gus@getter-company.com From: sue@sender-company.com Subject: test email This is a test email. .

Getter says it got the message and will deliver it (Getter could say it will not deliver the message):

250 67PM1toC027114 Message accepted for delivery

Sender then says it is finished (it could have had another message to send).

QUIT

Getter says ok and disconnects:

221 closing connection
Keeping Email Safe (STARTTLS)

By the late 1990's Internet email was being used to communicate things that should be kept private: credit card numbers, doctor/patient information, trade secrets. All this information was out on the Internet where anyone with access could see it. So the next generation of smart people working on the Internet designed a way for SMTP to use encryptiony to hide the SMTP. It's called STARTTLS and again it was so good that it is still in use today, even with state-of-the-art quantum encryption.

STARTTLS Example

Here is an example of STARTTLS in an SMTP conversation:

220 mail.getter-server.com ESMTP EHLO mail.sender-server.com 250-mail.getter-server.com [10.11.12.13] Ready 250-SIZE 157286400 250-STARRTLS 250 8BITMIME STARTTLS 220 Ready to start TLS 17 03 03 00 2d 4c ba 99-73 89 82 0e 4a f3 93 54 52 57 71 78 88 ba 1d fb-fc f9 a3 64 cf 62 f8 32 ae 5e e6 04 a8 3a 23 98-94 54 06 fc 43 3e d6 04 f6 d2 ~~~EHLO mail.sender-server.com 17 03 03 00 40 c8 4c 43-7e 54 9a 55 25 ff 0c e2 7e ac 0b fb cb 5a 2b b6-15 a9 30 2f 5c 41 94 88 83 a6 76 db f3 5d 16 47-56 d1 be 49 14 96 ff 23 ef 61 08 12 df 93 7e 46-89 e5 4f b2 9e 54 28 bb 14 62 f8 b9 0b ~~~250-mail.getter-server.com [10.11.12.13] Ready 17 03 03 00 24 7e e1 96-fc 87 b9 8d 93 61 3a e7 44 19 64 8f f5 ac d2 a0-08 72 50 2d 81 73 02 b8 17 cc e8 48 bf e0 36 7a-86 ~~~250-SIZE 157286400 17 03 03 00 1e 6e aa 8a-b7 23 6d 00 9a ea b6 7e d7 02 24 0c f7 96 39 2d-81 72 93 29 b7 ac 0b 93 d8 66 50 ~~~250 8BITMIME 17 03 03 00 32 bd 0d c6-f3 be ae 56 7f 7e 19 51 d3 08 c9 29 2a 27 02 b0-c4 6f 87 6b 67 3c a2 66 95 67 ce 4f bb 73 3a 90-e0 ae ff fd d0 90 cc b7 4b d7 fc 77 f5 f1 75 ~~~MAIL FROM:sue@sender-company.com 17 03 03 00 18 d3 44 ba-af 90 74 97 04 d3 76 80 da 52 fd 77 39 07 3e 42-bf 46 fa 7c 64 ~~~250 OK 17 03 03 00 13 8c 6a 44-59 66 f7 dd 0f 4c d9 fb e0 e8 9e 5f 48 44 5b fa- ~~~RCPT TO:gus@getter-company.com 17 03 03 00 18 24 a0 a1-6f 43 91 03 1a bc 0d f3 c0 d1 b3 c3 d1 52 b5 61-f6 4f bc 07 e0 ~~~250 OK 17 03 03 00 16 2b 0d da-2b 33 04 3f 6f 10 c9 2a 3e 58 6e 62 db 87 8e 41-8f 5e 8c ~~~DATA 17 03 03 00 42 ae 7c 38-0b f3 8e e8 3a 70 58 98 d2 3d 48 f4 83 2b 35 cf-3e 70 f8 a2 cc 4a ae 72 8f b6 35 cd 45 29 5b a4-1b c0 aa d0 47 16 b4 bd 93 17 3d 30 40 5b 45 13-40 62 d2 cd d3 99 4e 03 1c f0 73 97 50 2c c3 ~~~354 Enter mail, end with "." on a line by itself 17 03 03 00 2c ba ab a7-a1 08 b2 f7 2e e5 de 5f 91 84 d3 b6 ef 07 bb a4-d8 c0 bd 26 22 db 38 55 1a 53 80 35 41 c9 14 19-2e 84 bb ce 04 c2 41 3a 6a ~~~To: gus@getter-company.com 17 03 03 00 2e dd 69 51-8c 0e 31 40 06 7e 88 5c 10 9d ce 94 60 07 cb 41-ed 01 95 75 da fc 85 64 42 9e c9 05 ec 7b 17 a3-15 e8 c4 78 ac 79 7c 7e 60 3f c1 ~~~From: sue@sender-company.com 17 03 03 00 25 ca 07 a4-34 cf 9b cb b3 27 e5 a5 c1 75 d1 28 8d a3 b6 58-38 87 56 21 aa 8b e0 b6 5e e1 a0 ac fb e5 fe a1-00 55 ~~~Subject: test email 17 03 03 00 12 92 36 e8-2c 54 92 9b 2d 3b 33 f7 fd 5f 42 66 f6 81 39 ~~~ 17 03 03 00 27 c8 19 55-5a 5e 0a 6f 43 4c aa 13 06 bd 18 0b 2c 4a 1e a1-48 75 b6 57 95 06 3a 96 97 aa e2 98 d9 db 16 31-84 aa af 12 ~~~This is a test email. 17 03 03 00 13 39 92 4f-78 e2 06 9f 6d f1 6d ae ca 38 22 9b f9 39 91 a3- ~~~. 17 03 03 00 42 ce f0 eb-14 79 48 c1 9b e0 ff cb aa 5c 92 8e 0d 62 e0 8b-4f be c5 05 22 9b ab ff 8c ea 81 3a c1 92 0c ef-f7 4f 77 0e 32 0e 3c 2c 19 39 1a d9 ec cd 82 f7-a8 2b f9 31 41 7a 97 6b 5f f9 06 5c e1 f6 df ~~~250 67PM1toC027114 Message accepted for delivery 17 03 03 00 13 0b 34 6c-5c 51 36 1d 75 5e db e5 5e b4 cb 54 76 4f 2c e2- ~~~QUIT 17 03 03 00 28 3f fa 38-f4 e2 33 f7 f6 c4 9d f0 c9 a2 b5 c5 f8 4e 48 4d-55 de e5 a9 51 cd 0b d8 55 6b fe 03 de 7e 77 bd-23 a0 66 1c 06 ~~~221 closing connection

Uncolored lines starting with ~~~ are not real: they are the decrypted contents of the binary data that was actually sent. Only Gus and Sue's servers know the decrypted contents, the Internet can only see the unintelligable binary data.

Keeping Email Even Safer

Since STARTTLS there have been a number of additional security features grafted onto Internet email. These are beyond the scope of this document, but they include:

SPF
adds security to HELO and MAIL FROM parts of SMTP
i.e. mail.sender-server is allowed to send mail that says it is from sender-company.com
DKIM
adds security to MAIL FROM and DATA parts of SMTP
i.e. it signs and protects the email like a wax-seal on a paper envelope
DMARC
adds even more security to SPF and DKIM
MTA-STS
adds security help Sender be sure they are connecting to Getter's real servers
DANE
adds security features to SSL Certificate usage
TLS-RPT
provides a way for Sender to tell Getter something is wrong with Getter's email
BIMI
provides visual confirmation to Gus that the email really came from Sue
DNSSEC
adds security to all DNS name lookups
i.e. prevents someone from saying my IP address is also good for mail.sender-company.com
FCrDNS
makes sure host names and addresses match
i.e. prevents someone from saying this host name goes to this (bad) IP address
Before SMTP Starts

We said above that before SMTP, an email transfer starts with Sender's Server contacting Getter's Server and saying "I want to send you an email". Sender knows it wants to send an email, but how does Getter know that Sender is out there wanting to send it something?

Getter's Server is like an amusement park. Just as an amusement park has different locations for the different ride lines, Servers have different locations ("Ports") for the different things they can do. Each different Port knows how to talk a certain Protocol (language), like the SMTP language described above. These protocols are things like "send me this webpage" (HTTP), "tell me what the IP address is for this domain name" (DNS), "let me run a program" (TELNET, SSH, RDP), or "I want to send you an email" (SMTP).

So when a Sender wants to send an email, it contacts a Getter's Server on the SMTP Port (port #25), and the two of them know to start talking SMTP.