daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

smtp-commands.md (3571B)


      1 ---
      2 title: "SMTP Commands"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-smtp/smtp-commands.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-smtp/smtp-commands.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # SMTP Commands
     14 
     15 SMTP is a text protocol. After the server greeting, a client normally sends `EHLO`; the server's multiline response advertises supported extensions. A basic mail transaction then uses `MAIL FROM`, one or more `RCPT TO` commands, and `DATA`.<sup>[[1]](#references)</sup>
     16 
     17 ## Core commands<sup>[[1]](#references)</sup>
     18 
     19 - **`EHLO <domain>`**: Identifies an Extended SMTP client and requests the server's extension list.
     20 - **`HELO <domain>`**: Legacy greeting used when ESMTP is unavailable.
     21 - **`MAIL FROM:<reverse-path>`**: Starts a transaction and sets its envelope sender. This is not the message's `From:` header.
     22 - **`RCPT TO:<forward-path>`**: Adds one envelope recipient; repeat it for additional recipients.
     23 - **`DATA`**: Requests permission to transmit the message headers and body. A `354` reply means the client may send the content, terminated by a line containing only a dot.
     24 - **`RSET`**: Aborts the current transaction and clears its sender, recipients, and data without closing the SMTP connection.
     25 - **`VRFY <string>`**: Requests confirmation that a string identifies a user or mailbox. Servers commonly disable useful responses to reduce enumeration.
     26 - **`EXPN <string>`**: Requests expansion of a mailing list. Servers may disable it.
     27 - **`HELP [command]`**: Requests general or command-specific help.
     28 - **`NOOP`**: Requests a successful reply without changing transaction state.
     29 - **`QUIT`**: Ends the SMTP session.
     30 
     31 ## Common extensions
     32 
     33 - **`SIZE [bytes]`**: The server advertises its maximum accepted message size; the client may declare the planned message size on `MAIL FROM`.<sup>[[2]](#references)</sup>
     34 - **`AUTH <mechanism>`**: Starts SMTP authentication using a mechanism advertised in the `EHLO` response. Credentials are not necessarily encrypted, so negotiate TLS first unless the selected mechanism provides adequate protection.<sup>[[3]](#references)</sup>
     35 - **`STARTTLS`**: Requests an upgrade of the connection to TLS. After a successful TLS negotiation, the client sends `EHLO` again because the advertised extensions can change.<sup>[[4]](#references)</sup>
     36 
     37 The obsolete `TURN` command from RFC 821 reversed the client and server roles on an existing connection. RFC 5321 no longer defines it, so do not expect current servers to support it.<sup>[[1]](#references)[[5]](#references)</sup>
     38 
     39 For a shorter operator-oriented catalog of these commands, the original page used ServerSMTP's command overview.<sup>[[6]](#references)</sup>
     40 
     41 ## References
     42 
     43 - [1] [RFC 5321 - Simple Mail Transfer Protocol](https://www.rfc-editor.org/rfc/rfc5321.html)
     44 - [2] [RFC 1870 - SMTP Service Extension for Message Size Declaration](https://www.rfc-editor.org/rfc/rfc1870.html)
     45 - [3] [RFC 4954 - SMTP Service Extension for Authentication](https://www.rfc-editor.org/rfc/rfc4954.html)
     46 - [4] [RFC 3207 - SMTP Service Extension for Secure SMTP over TLS](https://www.rfc-editor.org/rfc/rfc3207.html)
     47 - [5] [RFC 821 - Simple Mail Transfer Protocol (obsolete)](https://www.rfc-editor.org/rfc/rfc821.html)
     48 - [6] [ServerSMTP - SMTP commands overview](https://serversmtp.com/smtp-commands/)