Port 587: Message Submission (SMTP with STARTTLS)
Port 587 is reserved for email message submission from mail clients to a Mail Submission Agent, as defined in RFC 6409. RFC 8314 notes that STARTTLS on port 587 is widely deployed for submission. Server-to-server relay stays on SMTP port 25.
Port Details
Security Exposure
Submission servers accept user credentials, which makes 587 a target for password guessing and reuse of stolen credentials. Microsoft notes that Basic authentication makes credential capture easier and complicates MFA enforcement. If STARTTLS is optional, credentials can cross the network unencrypted.
Hardening
- +Require authentication before accepting MAIL commands, as RFC 6409 section 4.3 mandates.
- +Require STARTTLS before AUTH and reject cleartext logins.
- +Accept TLS 1.2 or later only, following RFC 8314.
- +Use modern authentication instead of Basic authentication where the platform allows.
- +Throttle failed logins and per-account sending volume.
Monitoring
Log AUTH failures and successes with source addresses and alert on password-spray patterns across many accounts. Monitor outbound volume per authenticated user.
SMTP Submission Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2010-4344 | Exim Heap-Based Buffer Overflow Vulnerability | - | 9.8 | 71.7% | KEV | 2010-12-14 |
| CVE-2010-4345 | Exim Privilege Escalation Vulnerability | - | 7.8 | 18.0% | KEV | 2010-12-14 |
| CVE-2019-16928 | Exim Out-of-bounds Write Vulnerability | - | 9.8 | 41.6% | KEV | 2019-09-27 |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) Improper Input Validation | exim | 9.0 | 100.0% | KEV | 2019-06-05 |
| CVE-2018-6789 | Exim Buffer Overflow Vulnerability | - | 9.8 | 82.1% | KEV | 2018-02-08 |
Tools for Auditing and Monitoring SMTP Submission
Rspamd
Free / CommercialFast open source spam and phishing filtering system for Postfix, Exim, and Sendmail.
Apache SpamAssassin
Open SourceClassic open source spam filter using heuristic scoring, Bayesian classification, and a plugin architecture.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
What is the difference between port 25 and 587?→
RFC 6409 keeps relay between mail servers on port 25 and reserves 587 for submission from mail clients, which allows separate security policy such as mandatory authentication.
Is port 587 encrypted?→
It starts in plaintext and upgrades with STARTTLS. RFC 8314 recommends TLS 1.2 or later for all traffic between mail clients and submission servers.
Which vulnerabilities affect the service on port 587?→
This database lists 5 CVEs related to SMTP Submission, 5 of them confirmed as exploited by CISA. Examples: CVE-2010-4344, CVE-2010-4345, CVE-2019-16928, CVE-2019-10149.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 587 is not guaranteed to be SMTP Submission. Exploited-in-the-wild data from the CISA KEV catalog (CC0).