Zimbra Relay Access Denied Direct

| Setting | Command to Check | Desired State | | :--- | :--- | :--- | | | zmprov getServer zimbraMtaTlsAuthOnly | TRUE | | Submission Port | zmprov getServer zimbraMtaAuthEnabled | TRUE on port 587 | | Trusted Networks | zmprov getServer zimbraMtaMyNetworks | Only internal subnets | Final Thoughts "Relay access denied" is frustrating because it stops legitimate email. But remember: without this guardrail, your Zimbra server would be an open relay—and it would be blacklisted within hours.

This most often happens in three specific scenarios: Zimbra’s default security stance is: Authenticate first, then relay. If a device or script tries to send mail through your server on port 25 (the standard SMTP port) without a username and password, Zimbra will reject it. zimbra relay access denied

zmprov modifyServer `zmhostname` zimbraMtaMyNetworks '127.0.0.0/8 10.0.0.0/24 YOUR_DEVICE_IP/32' zmcontrol restart mta Only do this for internal, static IPs. Never add public IP ranges here. How to Diagnose the Problem in 30 Seconds Still stuck? Check the mail logs. SSH into your Zimbra server and run: | Setting | Command to Check | Desired

Add the device’s IP address to Zimbra’s “mynetworks” setting. This tells Zimbra, "Trust anything coming from this IP." If a device or script tries to send

Found this helpful? Subscribe to our newsletter for more Zimbra and open-source mail server tips.

zmprov modifyAccount [email protected] +zimbraAllowFromAddress [email protected] zmprov fc account [email protected] This is a classic "broken copier" or "buggy CRM" problem. Printers, scanners, and legacy applications often hard-code an IP address and try to send mail without logging in.