A scanner emailing a scanned document, a monitoring tool sending an alert, a line-of-business application emailing an invoice, and a backup job emailing a completion report all need to send mail, but none of them are a person reading a mailbox. Rather than creating and managing a mailbox and password for each device or app, they send through a relay (also called a smart host): a point on your network that accepts the outgoing message and delivers it onward, either to your mail server or to the Internet.
This is one of the most common and most commonly misconfigured pieces of small-business mail infrastructure, because the wrong configuration creates an open relay — a server that will forward mail from anyone to anyone, which spammers actively scan the Internet to find.
There are two common ways to permit relay, and they suit different clients:
- IP-based relay. The relay is configured to accept mail without authentication only from specific, known internal IP addresses (a scanner's fixed LAN address, a specific application server). Simple, works for devices that cannot do SMTP authentication, but only as safe as your network — anything on that IP, or able to spoof it, can relay.
- Authenticated (SMTP AUTH) relay. The client logs in with a username and password (ideally a dedicated relay account, not a real mailbox) over TLS. More secure and works from outside a fixed IP range, but requires the client software to support SMTP authentication — most modern applications do; some older scanners and appliances do not.
Use authenticated relay wherever the device supports it. Reserve IP-based relay for devices that genuinely cannot authenticate, and restrict it as tightly as possible — a specific IP, not a whole subnet.
A few rules avoid turning a convenience feature into a security incident:
- Never relay unauthenticated mail from "anyone" — always restrict by specific IP address, authenticated account, or both.
- Use TLS for the relay connection wherever the client supports it, especially for authenticated relay, so credentials are not sent in plaintext.
- Give relay-only clients a dedicated account, not a real person's mailbox password — if that credential leaks, revoking it does not lock a person out of their own mail.
- Restrict what a relay account can send as — allow it to use only the From address(es) it actually needs, not any address on your domain.
- Periodically test from an external network that your relay does not accept unauthenticated mail for domains you do not host — this is exactly what an open-relay scanner is checking for.
Devices and systems that typically need relay access, rather than a mailbox:
- Network scanners and multi-function printers emailing scanned documents.
- Backup software, UPS/monitoring appliances, and NAS devices sending status alerts.
- Line-of-business applications (invoicing, CRM, ticketing) sending transactional email.
- Web applications and scripts sending order confirmations, password resets, or notifications — see also sending email from a web application.
- Development/test environments that need to send mail without touching production mailboxes.
A quick way to test connectivity before configuring the actual device: from the device's network segment, use telnet <relayserver> 25 (or 587 for submission) and confirm you get a banner response starting with 220. If that fails, the problem is network/firewall before it is a mail configuration problem — check the relay server's allowed IP list and any firewall between the device and the relay.
Once connectivity works, send a real test message from the device itself (most scanners and appliances have a "send test email" option) and confirm it both leaves the relay and arrives at the destination, since a device can successfully connect and still be rejected if its configured From address is not one the relay permits.
Hexamail Server, Hexamail Guard and Hexamail Nexus can all act as an SMTP relay/smart host for applications, scanners and appliances, with per-IP and authenticated relay rules, TLS, and control over which From addresses each relay client may use — so scanners and line-of-business apps get a working relay without becoming an open one.