How It Actually Works
A session kicks off when one server connects to another. Receiving server says hello, usually a 220 code, sender replies with EHLO to introduce itself. From there the order barely changes, who it’s from, who it’s going to, then the actual message.
The Commands You’ll Actually See
EHLO introduces the sender and asks what features the server supports. Older systems still use HELO.
MAIL FROM gives the envelope sender, can be different from the “From” you see in your inbox, worth knowing that.
RCPT TO names the recipient, server checks if it’ll even accept mail for that address.
DATA signals the message is coming next, headers and body follow, a single period on its own line ends it.
QUIT closes things out.
Why Any Of This Matters
Every reply tells the sender exactly what happened. A 250 after MAIL FROM means good to go. Recipient gets rejected, you get a different code, and that’s usually where admins spot where delivery actually broke. This is why SMTP logs are genuinely useful, you see what was actually said back and forth, not just a vague “email failed” message.
Commands Around Security
AUTH is how a sender proves who they actually are. STARTTLS moves the whole connection over to encrypted TLS. What’s available depends on what the server lists back after EHLO.
What A Conversation Actually Looks Like
Simplified version:
EHLO mail.example.com
250
MAIL FROM:<sender@example.com>
250
RCPT TO:<person@example.net>
250
DATA
354
message content
250
QUIT
221
Those numbers are just the server telling the sender to keep going, change something, or stop.
Is This Worth Learning
If you’re just sending personal emails, skip it, your provider’s already handling all this. But if you’re dealing with mail servers, email APIs, deliverability issues, or troubleshooting, it’s worth knowing. Turns a confusing delivery problem into something you can actually trace and understand instead of just guessing.