Outgoing connections on port 25 / 587 / 143 blocked over IPv6?

Posted September 13, 2014 39.6k views

I just moved my servers, including my mailserver to the new ams3 region because of ipv6. i configured postfix to use ipv6 and i recieved my first email over ipv6 without a problem.

But when i try to send mail over ipv6 to other mailserver that support ipv6 like the connection times out.

I then used netcat to test it and found that three mail relevant ports seem to be blocked for outgoing connections. SSH works fine.

nc -vz [ipv6-address] 25
nc: connect to [ipv6-address] port 25 (tcp) failed: Connection timed out
nc -vz [ipv6-address] 587
nc: connect to [ipv6-address] port 587 (tcp) failed: Connection timed out
nc -vz [ipv6-address] 143
nc: connect to [ipv6-address] port 143 (tcp) failed: Connection timed out

nc -vz [ipv6-address] 22
Connection to [ipv6-address] 22 port [tcp/ssh] succeeded

Are these ports really blocked? If yes, why?


These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

Submit an Answer
11 answers

Hi there; I was in touch with support about this a few months back and I didn’t realise it was still blocked.

The response was:

… the changes you need to make are in /etc/gai.conf

Look for the list of precedences that are commented out.

The last value simply needs to be uncommented and the 10 changed to a 100

This will de-prioritize IPv6 NS lookups and allow IPv4 to take priority.

Eventually we will remove the block on IPv6 SMTP, but for now it will remain in place.

Or, to put it another way:


nano /etc/gai.conf

make the appropriate lines look like this

precedence ::ffff:0:0/96  100

Reboot, test, enjoy, let me know if it works :)

Just checked if this is still the case in 07/2016 and it unfortunately is:
Outgoing connections are blocked on the following ports:
25/tcp filtered smtp
109/tcp filtered pop2
110/tcp filtered pop3
143/tcp filtered imap
465/tcp filtered smtps
587/tcp filtered submission
933/tcp filtered unknown
995/tcp filtered pop3s

I’m in the FRA1 (Frankfurt) Datacenter. I hope this gets changed sometime soon. Other than this I’m really happy with DO but their IPv6 support really sucks big time (the no real v6 subnet and only 16IPs thing being the other big v6 problem).

I got that from the support, for anyone that is interested:


Sorry for the confusion. At this time we’ve blocked SMTP by default on IPv6. Currently we suggest using IPv4 droplet for outgoing SMTP access.

The reason behind this is that it’s a new feature on DigitalOcean and we’re easing into the roll out of SMTP support. This is definitely something we are looking into and hope to support soon, though we have not estimate on when this may be available at this time.

We appreciate your understanding on this. Please let us know if you have any questions.

Is this still the case?

The whole reason I am investigating using Digital Ocean (In conjunction with Forge) is to make life easier. If IPv6 is blocked by default this kind of defeats the point in not having to dig around configuration files - something I don’t really want to have to do in an ideal world. Hence checking this service out.

You can give priority to IPv4 addresses over IPv6 so that you can continue to send out email without disabling IPv6. You would do that by editing the Droplet’s /etc/gai.conf file and removing the comment (#) from the following line:

Default Configuration: #precedence ::ffff:0:0/96 100

Configuration with Priority to IPv4: precedence ::ffff:0:0/96 100

Works for me,

  1. change /etc/gai.conf and restart server
    precedence ::ffff:0:0/96 100

  2. !!!

    Configured firewall for outgoing icmp traffic for ipv4 and ipv6

I’ve just uncommented the line which says:

precedence ::ffff:0:0/96 100

but i still get from “netstat -n” :

tcp 0 1 45.55.175.XXX:45020 SYN_SENT

seems to me it is being blocked, do you know if this still works?

Hy, for who can’t send emails.



nano /etc/gai.conf

and uncomment

precedence ::ffff:0:0/96 100

Reboot, test, and change NETWORK MX, add GMAIL MX.

  • Hello, I still cannot send email from my Digital Ocean droplet :(

    I have enabled ipv6, uncomment above link, rebooted, opened port 465 and 587 using ufw allow out. When I try telnet 465 , my droplet still cannot connect and still cannot send email.. any idea and tips?

  • Hello, Which service do you have to reboot after changing /etc/gai.conf?

Previous 1 2 Next