Fix · Users can't sign in: auth email in spam, blocked or never sent

VPS outbound SMTP blocked, password reset email times out

Password reset or verification emails send from your laptop, but in production the SMTP connection hangs and the request times out. The usual cause is the hosting provider blocking outbound SMTP ports by default, as DigitalOcean, Hetzner and Google Compute Engine document.

Likely causes, most common first

Cause 1 · in 1 of 3 matching cases

The host blocks the SMTP port your mailer dials

DigitalOcean blocks SMTP ports 25, 465 and 587 on Droplets by default. Hetzner blocks ports 25 and 465 by default on all cloud servers. Compute Engine blocks port 25 when the destination is outside your VPC network. If your mailer dials a blocked port, the connection hangs until the reset request times out.

How to tell: The same credentials and port send from your laptop, and your production host's docs list that port as blocked.

Cause 2

A new account has an SMTP restriction

Linode restricts outbound connections on ports 25, 465 and 587 for some accounts created after 5 November 2019. Hetzner blocks ports 25 and 465 by default. Once you have been a Hetzner customer for a month and paid your first invoice, you can create a limit request.

How to tell: Your account is recent, and the provider's docs describe lifting the block through a support ticket or limit request.

Cause 3

The server moved to another account

Hetzner enforces port blocking per account. If a server is transferred to a project owned by another account, the new owner's port-blocking rules apply. A server that could send on 25 or 465 can lose that ability after the move.

How to tell: Email stopped right after the server was transferred to a project owned by a different account.

Check and fix it, step by step

  1. Compare your production SMTP port with the host's block list

    Read the port from the production config, not your local env file. DigitalOcean blocks 25, 465 and 587 on Droplets. Hetzner blocks 25 and 465. Compute Engine blocks 25 to external destinations.

    Docs: docs.digitalocean.com →

  2. Check whether a new-account restriction applies

    On Linode, some accounts created after 5 November 2019 can't send over the standard SMTP ports until support lifts the restriction. Check your account age and the provider's notice before you change any code.

    Docs: techdocs.akamai.com →

  3. On Hetzner, send through an external delivery service on port 587

    Hetzner does not block port 587 on cloud servers, so you need no limit request. Point the mailer at your external delivery service's submission port.

    SMTP_PORT=587

    Docs: docs.hetzner.com →

  4. On Compute Engine, move off port 25 to 587 or 465

    Port 25 to destinations outside your VPC network is blocked. Google Cloud places no restrictions on traffic to external destinations on TCP ports 587 or 465.

    Docs: docs.cloud.google.com →

  5. On DigitalOcean, send through a third-party email service

    Switching to 587 won't help on a Droplet, because 25, 465 and 587 are all blocked. DigitalOcean recommends a third-party email service provider for mail sent from services it hosts.

    Docs: docs.digitalocean.com →

  6. Request an unblock where the host offers one

    On Hetzner, after a month and a paid first invoice, file a limit request that describes a valid use case. On Linode, contact support with your name, use case, sending practices and the domains you will send from.

    Docs: docs.hetzner.com →

Quick check: Compare the production SMTP port with the host's list: DigitalOcean 25/465/587, Hetzner 25/465, Compute Engine 25 (external)

How often this shows up in our data

3 of the 344 verified cases from the last 12 months in our data match this symptom (0.9%). The most common cause was “The host blocks the SMTP port your mailer dials” (1 of 3); 2 didn't show which cause. How we collect and verify cases.

With Gemmein

On Gemmein, sign-in is by passwordless email codes, and the code email is the one email Gemmein sends on your behalf. You call two SDK methods and Gemmein delivers the code.

Questions

Why does the reset email send locally but time out on the VPS?

The hosting provider applies the block to its servers, not to your laptop. DigitalOcean blocks SMTP ports 25, 465 and 587 on Droplets by default, and Hetzner blocks 25 and 465 on cloud servers. The same code and credentials can send locally and fail in production.


Will a Reserved IP get around the DigitalOcean block?

No. DigitalOcean states that the block applies to all Droplets by default, including traffic passing through a Reserved IP address.


Can I get the SMTP ports unblocked?

On Hetzner, yes. After a month and a paid first invoice you can file a limit request, and Hetzner decides case by case. Linode reviews support requests to lift its restriction. DigitalOcean's page recommends a third-party email service and describes no unblock process.


Should I run my own mail server instead?

DigitalOcean strongly recommends against it, even where SMTP is available. It says self-hosted mail servers are difficult to secure and maintain, and frequently get flagged as spam. Google Cloud says a trusted third-party provider such as SendGrid, Mailgun or Mailjet improves your IP reputation score.


Sources

Every cause and step above was checked against these pages on 1 Oct 2026.

The broader pattern

This is one symptom of a wider failure pattern: Users can't sign in: auth email in spam, blocked or never sent. The guide covers every cause we see for it, on any stack.

Get a heads-up when VPS / Docker breaks something

VPS / Docker

Leave your email and we'll let you know when something big changes for VPS / Docker. Unsubscribe any time by replying. Gemmein Limited. Research terms · Privacy

← All fixes