smtp-commands.md (3571B)
1 --- 2 title: "SMTP Commands" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-smtp/smtp-commands.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-smtp/smtp-commands.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # SMTP Commands 14 15 SMTP is a text protocol. After the server greeting, a client normally sends `EHLO`; the server's multiline response advertises supported extensions. A basic mail transaction then uses `MAIL FROM`, one or more `RCPT TO` commands, and `DATA`.<sup>[[1]](#references)</sup> 16 17 ## Core commands<sup>[[1]](#references)</sup> 18 19 - **`EHLO <domain>`**: Identifies an Extended SMTP client and requests the server's extension list. 20 - **`HELO <domain>`**: Legacy greeting used when ESMTP is unavailable. 21 - **`MAIL FROM:<reverse-path>`**: Starts a transaction and sets its envelope sender. This is not the message's `From:` header. 22 - **`RCPT TO:<forward-path>`**: Adds one envelope recipient; repeat it for additional recipients. 23 - **`DATA`**: Requests permission to transmit the message headers and body. A `354` reply means the client may send the content, terminated by a line containing only a dot. 24 - **`RSET`**: Aborts the current transaction and clears its sender, recipients, and data without closing the SMTP connection. 25 - **`VRFY <string>`**: Requests confirmation that a string identifies a user or mailbox. Servers commonly disable useful responses to reduce enumeration. 26 - **`EXPN <string>`**: Requests expansion of a mailing list. Servers may disable it. 27 - **`HELP [command]`**: Requests general or command-specific help. 28 - **`NOOP`**: Requests a successful reply without changing transaction state. 29 - **`QUIT`**: Ends the SMTP session. 30 31 ## Common extensions 32 33 - **`SIZE [bytes]`**: The server advertises its maximum accepted message size; the client may declare the planned message size on `MAIL FROM`.<sup>[[2]](#references)</sup> 34 - **`AUTH <mechanism>`**: Starts SMTP authentication using a mechanism advertised in the `EHLO` response. Credentials are not necessarily encrypted, so negotiate TLS first unless the selected mechanism provides adequate protection.<sup>[[3]](#references)</sup> 35 - **`STARTTLS`**: Requests an upgrade of the connection to TLS. After a successful TLS negotiation, the client sends `EHLO` again because the advertised extensions can change.<sup>[[4]](#references)</sup> 36 37 The obsolete `TURN` command from RFC 821 reversed the client and server roles on an existing connection. RFC 5321 no longer defines it, so do not expect current servers to support it.<sup>[[1]](#references)[[5]](#references)</sup> 38 39 For a shorter operator-oriented catalog of these commands, the original page used ServerSMTP's command overview.<sup>[[6]](#references)</sup> 40 41 ## References 42 43 - [1] [RFC 5321 - Simple Mail Transfer Protocol](https://www.rfc-editor.org/rfc/rfc5321.html) 44 - [2] [RFC 1870 - SMTP Service Extension for Message Size Declaration](https://www.rfc-editor.org/rfc/rfc1870.html) 45 - [3] [RFC 4954 - SMTP Service Extension for Authentication](https://www.rfc-editor.org/rfc/rfc4954.html) 46 - [4] [RFC 3207 - SMTP Service Extension for Secure SMTP over TLS](https://www.rfc-editor.org/rfc/rfc3207.html) 47 - [5] [RFC 821 - Simple Mail Transfer Protocol (obsolete)](https://www.rfc-editor.org/rfc/rfc821.html) 48 - [6] [ServerSMTP - SMTP commands overview](https://serversmtp.com/smtp-commands/)