---
title: "Open Mail Relay Vulnerability"
canonical: "https://kb.cynergy.app/space/MD/906985473/Open%20Mail%20Relay%20Vulnerability"
format: markdown
---
**Description**

An open mail relay is an **SMTP** **server** misconfiguration that allows a third party to relay (send/receive email messages that are neither from nor for local users). Therefore, such servers are usually targeted by **spam** senders to send spoofed emails to victims' inboxes.

**Hacker's View**

As a hacker, I can identify an open mail relay by scanning a target with Nmap:

```
nmap -sV --script smtp-open-relay -v <target>
```

or alternatively, I can use a tool like [SMTP Replay Phisher](https://github.com/crazywifi/SMTP_Relay_Phisher) to test and exploit the vulnerability. 

After detecting an open mail relay, I can use it for:

- Spamming - the impact is that the organization's email servers are getting blacklisted.
- Phishing - I can use the mail relay to send emails to the organization’s users, bypass email gateways, and elevate my chances to get to the victim’s mailbox.

**Mitigation**

Change mail server configuration to disallow mail relay.

**Cynergy’s View**

Cynergy allows you to identify automatically mail relay vulnerabilities and open port 25.

Once identified, you can create a ticket and manage the fix of the vulnerability. 

**Reference**

AWS - [https://docs.aws.amazon.com/elemental-statmux/latest/configguide/notification-email-sendmail.html](https://docs.aws.amazon.com/elemental-statmux/latest/configguide/notification-email-sendmail.html) 

GCP - [https://cloud.google.com/compute/docs/tutorials/sending-mail](https://cloud.google.com/compute/docs/tutorials/sending-mail) 

Azure - [https://docs.microsoft.com/en-us/azure/devops/server/admin/setup-customize-alerts?view=azure-devops-2020](https://docs.microsoft.com/en-us/azure/devops/server/admin/setup-customize-alerts?view=azure-devops-2020)