Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Allow Outbound SMTP in the CSF Firewall

This guide shows how to let your server send email by opening the SMTP ports in CSF. It needs root access, so it fits VPS and dedicated server customers.

Firewall2 min read14 steps5 screenshots

What is this about?

SMTP is the system servers use to send email. It is like the postal service for email. Outbound means going out from your server to other servers.

CSF is ConfigServer Security and Firewall. A firewall is a guard that decides which connections may pass. CSF is a popular firewall for servers with WHM and cPanel. WHM is the control panel for the server owner. Customers with a VPS or dedicated server have root access, which is full control of the server.

Sometimes CSF blocks outgoing SMTP. Then emails from your website or a mail program fail to send. Typical ports are 25, 465 and 587. A port is like a numbered door on the server.

Steps in WHM

  1. Log in to WHM as root.
    Screenshot: Log in to WHM as root .
  2. In the search box on the left, type CSF.
  3. Click ConfigServer Security & Firewall.
    Screenshot: Click ConfigServer Security & Firewall .
  4. Click Firewall Configuration.
    Screenshot: Click Firewall Configuration .
  5. Find the line TCP_OUT.
  6. Check that the list contains 25, 465 and 587. Add any missing number, separated by commas.
  7. Scroll down to SMTP_BLOCK. If it is set to 1, SMTP is limited to certain users. Set it to 0 to switch the block off.
    Screenshot: Scroll down to SMTP_BLOCK . If it is set to 1 , SMTP is limited to certain users. Set it t
  8. Scroll to the bottom and click Change.
  9. Click Restart csf+lfd.
    Screenshot: Click Restart csf+lfd .
Warning: Take a copy of the file /etc/csf/csf.conf first. A wrong change can lock you out of the server. Keep your own IP address allowed in CSF.

Steps on the command line

  1. Connect to the server over SSH as root. SSH is a secure way to type commands on a server.
  2. Make a backup copy:
cp /etc/csf/csf.conf /etc/csf/csf.conf.bak

This saves a safe copy of your settings.

  1. Open the file with a text editor:
nano /etc/csf/csf.conf
  1. Edit the TCP_OUT line and the SMTP_BLOCK line, then save.
  2. Restart CSF:
csf -r

This reloads the firewall with your new rules.

Test it

Send a test email from your site or mail program. You can also check the port from the server:

telnet smtp.example.com 587

If you see a reply starting with 220, the port is open.

Tip: Some hosting providers block port 25 on their network. If the ports are open in CSF but mail still fails, ask Hostvento support. Open a support ticket.

Quick recap

  • SMTP sends email, and CSF can block it.
  • Add 25, 465 and 587 to TCP_OUT.
  • Check SMTP_BLOCK.
  • Back up the config, save and restart CSF.
  • Test with a real email.