What this analysis does
The analyzer segments greeting, EHLO, TLS, envelope, recipient and DATA stages; classifies response codes; and translates protocol failures into an actionable explanation.
An SMTP transcript records the exact command where a delivery attempt stopped. That location is diagnostic on its own: a rejection at RCPT TO means something structurally different from a rejection after DATA, even when both return the same numeric code.
The stage narrows the cause before the code does
A failure at MAIL FROM concerns the envelope sender, usually policy or authentication about the sending identity. A failure at RCPT TO concerns the recipient, typically an unknown address or a rule about that mailbox. A failure after DATA concerns the message itself, which brings content, size and reputation into scope.
Reading the stage first prevents a common misdiagnosis, where a recipient-level rejection is treated as a sender authentication problem. The numeric code is often identical; the position in the conversation is what separates them.
- MAIL FROM rejections concern the envelope sender.
- RCPT TO rejections concern the recipient address or mailbox policy.
- Post-DATA rejections concern the message content, size or reputation.
Read the EHLO response as a capability list
The server’s response to EHLO advertises what it supports, including STARTTLS, SIZE, authentication mechanisms and pipelining. When STARTTLS is absent, the session cannot be upgraded and any TLS requirement will fail at that point rather than later.
The advertised SIZE value explains a class of rejection that otherwise looks arbitrary. A message exceeding it may be refused immediately after MAIL FROM rather than after transmission, which is efficient for the server but confusing when only the final error is examined.
Multi-line replies carry the useful text
SMTP allows multi-line responses, distinguished by a hyphen after the code on continuation lines and a space on the final line. Capturing only the first line frequently discards the sentence that identifies the cause, along with any remediation URL the provider supplied.
Preserve the complete response when recording evidence. The enhanced status code and the provider text together are what make a rejection actionable, and both commonly appear on continuation lines rather than the first.
Example: rejection at the recipient stage
Evidence supplied
A transcript where EHLO and MAIL FROM are accepted and RCPT TO returns a 550 response with a mailbox diagnostic.
How to read the result
The analysis locates the failure at the recipient stage and reports it as an addressing or mailbox-policy condition rather than a sender authentication problem, directing verification toward the recipient address instead of toward SPF or DKIM.
Known limits
- Analysis is bounded by the supplied transcript; a partial capture yields a partial diagnosis.
- Server responses vary between implementations and can be deliberately vague for security reasons.
- A transcript records one attempt and may not represent behaviour across a larger sending pattern.
Common questions
What if the session fails before EHLO?
That points at the connection layer rather than SMTP policy: name resolution, firewall filtering, port blocking or a listener that is not accepting connections.
Does a 250 response mean the message was delivered?
It means the receiving system accepted responsibility for it. Final placement, and any later bounce, are separate events.
Should credentials be included in a transcript?
No. Remove AUTH exchanges and any base64 credential material before sharing a transcript anywhere.