Why Your Brevo SMTP Setup Should Use TLS Port 587 or 465

You’re sending emails through Brevo, but they’re bouncing. The content is fine. The list is clean. So why are your messages not getting through?

More often than not, the problem isn’t the message — it’s the setup. Misconfiguring the SMTP port or encryption method is a silent killer of deliverability. It’s like trying to unlock a door with the wrong key, but in this case, the lock is a mail server blocking your connection outright.

For Brevo email relay, using the correct TLS port — either 587 with STARTTLS or 465 with implicit TLS — isn’t just a technical detail. It directly impacts whether your emails land in inboxes or vanish into the void.

Key takeaways

  • Port 587 with STARTTLS is the standard for modern SMTP and is widely accepted by email providers and firewalls.
  • Port 465 with implicit TLS is legacy; while supported, it’s less common and may be blocked by default on modern systems.
  • Incorrect port or encryption settings are a top cause of hard bounces in bulk or automated email campaigns.

What’s the Real Difference Between Brevo SMTP Port 587 and 465?

Port 587 uses STARTTLS to begin encryption after the initial connection, while Port 465 starts encryption immediately without negotiation—this is why 587 is preferred by modern email systems like Brevo, Gmail, and Outlook. Though both secure mail transmission, 587 is the standard for user-submitted messages today.

How Each Port Handles Encryption Differently

When you connect to Brevo SMTP on Port 587, your client first establishes a plain text connection. Then, you send a STARTTLS command to request encryption. Only after that negotiation does the connection become encrypted. This is called explicit TLS.

Port 465, by contrast, assumes encryption from the moment the connection is made. No negotiation is needed. The client and server begin sending encrypted data immediately. This is known as implicit TLS.

Why 587 Is the Industry Default

Port 587 was designed specifically for mail submission from email clients—like those used by you or your users—and is the standard recommended by the IETF in RFC 6409. Major providers such as Gmail, Yahoo, and Microsoft enforce it, and many firewalls allow it by default.

Port 465 was originally defined in RFC 8314, but it never gained widespread adoption beyond niche use cases. Today, most modern email infrastructure ignores it, making 587 the only reliable choice for delivery. Using 465 may result in connection drops, especially with large-scale senders or providers like Brevo.

For this reason, you should always use Port 587 with Brevo SMTP unless you have a specific, documented reason not to. It's not just about compatibility—it’s about ensuring your emails reach inboxes reliably.

If you're sending bulk messages or managing a high-volume email flow, validate your addresses first to avoid sender reputation issues. A clean list reduces bounce rates and improves deliverability. You can test and verify your email lists with real-time checks: bulk verification or check individual addresses before sending.

For more on secure email delivery and how verification fits into the broader deliverability picture, see the IETF’s official specification for secure email submission and Spamhaus’s guidance on SMTP best practices.

You should use Port 587 with STARTTLS for Brevo SMTP relay in production. It’s the industry standard, widely supported, and reduces the risk of your emails being blocked or marked as spam. Brevo officially recommends it, and most mail servers expect it. Using Port 587 aligns with modern security practices and avoids common pitfalls tied to older or less secure setups.

Why Port 587 Is the Default Choice

Port 587 is recognized as the standard submission port for outbound email. It’s the port that mail clients and servers expect for message submission. Using it means your connection follows the path most email infrastructure is built to handle.

Most firewalls, ISPs, and security filters treat traffic on Port 587 as legitimate, reducing the chance your messages get flagged as suspicious or throttled. In contrast, Port 465 (implicit TLS) is rarely used in modern systems and can trigger caution in some environments, especially when not properly configured.

Aligned with Standards, Not Just Convenience

Port 587 is defined in RFC 8314, which states that STARTTLS is the preferred method for opportunistic encryption. Implicit TLS (used on Port 465) is outdated and no longer recommended for new deployments. This makes Port 587 not just a best practice, but a technical standard.

Even if your app or system still supports Port 465, using it can create interoperability risks. Some older systems may not handle it correctly, leading to connection issues or silent rejections. Port 587, with its clear handshake and explicit encryption upgrade, avoids these problems.

Let’s be clear: using Port 587 isn’t just about compliance. It’s about reliability. If you're sending transactional or marketing emails through Brevo, this setup lowers the chance of delivery failure due to routing or filtering policies. It’s the most predictable path to inbox placement.

Before you send to any list, verify your recipients. Use MailTester’s bulk verification to clean your list and reduce bounces, especially when migrating or scaling out your email campaigns. That way, your delivery reputation stays strong, and your messages reach real inboxes — not just rejections.

When You Might Still Use Port 465 With Brevo

Port 465 is still usable with Brevo if you're running legacy systems, using outdated email clients lacking STARTTLS support, or dealing with strict network filters that block or interfere with port 587. It's technically valid per older standards but is largely deprecated in favor of 587 with STARTTLS. Expect reduced long-term support and fewer ecosystem tools adopting it.

Legacy Infrastructure and Outdated Clients

Some older email clients, especially on internal corporate networks or legacy software, don’t handle STARTTLS negotiation correctly. If you're still using such systems, port 465 might be your only viable option for TLS-encrypted delivery with Brevo. These clients assume TLS starts immediately, which port 465 still provides.

For example, older versions of Microsoft Outlook or certain mail servers running outdated OpenSSL libraries may fail on port 587 if STARTTLS is misconfigured. In those cases, port 465 bypasses the negotiation step entirely, providing a stable encrypted connection—though at the cost of interoperability.

Network-Level Restrictions

On some enterprise networks, firewalls or email gateways filter outbound SMTP traffic based on port numbers. Port 587 may be blocked or throttled if it's misidentified as non-essential or if it’s used for spam in past incidents. In such cases, port 465—still recognized as “officially” for SMTPS—can slip through more reliably.

Even then, that work around is fragile. As newer security policies adopt more granular inspection (like TLS 1.3 enforcement, or protocol fingerprinting), the reliability of port 465 diminishes. The underlying issue—poor port policies—is not solved; it’s just worked around.

The IETF has moved toward deprecating port 465 in favor of the more flexible STARTTLS model over port 587. The practice is still valid under existing standards (as outlined in RFC 8314), but its future is uncertain.

Still, you should prioritize using port 587 with proper STARTTLS setup. If you're stuck using port 465, test your endpoint’s delivery reliability. Use inbox placement testing to confirm messages land in inboxes, not spam folders, and clean up your list with bulk list verification to avoid sending to non-existent or risky addresses that could harm your Brevo sender reputation.

How to Set Up Brevo SMTP with TLS on Port 587

You can set up Brevo SMTP with TLS on port 587 by logging into your Brevo account, generating an SMTP key, and configuring your email client with smtp.brevo.com, port 587, and STARTTLS encryption. Use your email as the username and the generated key as the password. Test the connection with tools like openssl to confirm the TLS handshake completes successfully.

Step-by-step configuration

  1. Log in to your Brevo account and go to Settings > SMTP and API Keys. This is where you manage access to Brevo’s email delivery infrastructure. Without access here, you won’t be able to send emails through your own tools or apps.
  2. Generate a new SMTP key if you haven’t already. This key acts as your password for SMTP authentication. It’s tied to your account, so keep it secure. Brevo does not store the key after generation — ensure you save it immediately.
  3. Configure your app or email client with the following: Host: smtp.brevo.com, Port: 587, Encryption: STARTTLS. Port 587 with STARTTLS is the standard for secure, authenticated SMTP delivery and is widely supported by mail servers.
  4. Enter your SMTP credentials: your email address as the username, and the generated key as the password. Many tools accept these directly. Mismatched credentials will result in immediate fail messages from the server.
  5. Test the connection. Use openssl s_client -connect smtp.brevo.com:587 -starttls smtp in your terminal. If you get a handshake success response, the TLS setup is working. This step confirms encryption is active before sending. For reference, RFC 6409 outlines the security rationale behind STARTTLS as a de facto standard for encrypted SMTP sessions.

Verify your setup before sending

Connection success doesn’t guarantee deliverability. Bad addresses or poor sender reputation can still lead to bounces or spam placement. Use a real email verification tool like MailTester’s email checker to validate addresses before sending. This helps you catch invalid or risky emails early — reducing failed deliveries and protecting your sender reputation. For list hygiene, bulk verification catches invalid, disposable, and risky domains in your list before campaign launch. A clean list improves inbox placement and avoids blacklisting.

Sending through Brevo with proper TLS setup is only one part of deliverability. You must also ensure your content, domain reputation, and sending volume align with email provider guidelines. Tools like MailTester help validate the entire sender stack — from email authenticity to inbox placement — not just SMTP configuration.

Common Errors When Configuring Brevo SMTP and How to Fix Them

You’re setting up Brevo SMTP with port 587 or 465 and hitting roadblocks? Let’s cut through the noise: “Connection refused” usually means port 587 is blocked by your firewall or ISP; “Handshake failed” points to misconfigured STARTTLS; “Authentication failed” comes down to a typo in your password; and “TLS not supported” means your client isn’t updated to at least TLS 1.2. These are the top four pain points — and each has a clear fix.

Port & Network Issues

  • If you see “Connection refused,” verify that port 587 is allowed through your firewall, proxy, or ISP. Some networks block outgoing port 587 by default — especially in corporate or restricted environments. TLS 1.2+ is now the standard for secure transport, so ensure you’re not stuck with outdated policies.
  • Use tools like MXToolbox to test your outbound SMTP connectivity in real time — it’s a reliable way to confirm if your network is the bottleneck.

Authentication & TLS Configuration

  • “Handshake failed” typically means your client isn’t properly negotiating STARTTLS. Confirm that STARTTLS is enabled in your client (e.g., in Mailgun, SendGrid, or custom code) and that you’re not using a legacy protocol like plain-text SMTP or SSL instead of TLS.
  • “Authentication failed” is almost always due to a simple mistake: an incorrect username (your Brevo email), password (the SMTP password from your Brevo settings), or typo in the server address. Double-check these in your Brevo dashboard under SMTP Settings. Even one wrong character breaks the connection.
  • “TLS not supported” means your email client or library is outdated. Older libraries like PHP 5.6 may not support TLS 1.2. Upgrade to a modern version — this is standard practice in secure communication. The Internet Engineering Task Force (IETF) explicitly deprecated SSL 3.0 and early TLS versions for this reason.

Before sending bulk campaigns, use a tool like MailTester’s email checker to validate all addresses in your list. It can catch invalid or risky emails before they trigger blocks or bounces — reducing delivery issues even before they hit your SMTP setup.

Why Sender Reputation Suffers When SMTP Settings Are Incorrect

You don’t need to be a security expert to know that sending email from the wrong port, with broken TLS, or without proper validation harms your sender reputation. Misconfigured SMTP settings—particularly using blocked ports like 587 or 465 incorrectly—can trigger rate-limiting, spam filters, and failed deliveries. These small errors stack up quickly, dragging down your reputation across multiple email providers. A single broken connection affects not just one recipient, but every address in your list. You can avoid this by catching invalid or misconfigured setups early—tools like MailTester’s email checker help validate addresses before they ever hit your send queue.

Bad Ports and Failed Connections Hit Your Reputation Fast

Using port 587 or 465 with incorrect TLS negotiation or outdated authentication methods leads to repeated handshake failures. Email providers track these incidents. Too many in a short time signal poorly managed infrastructure, prompting rate-limiting or temporary blacklisting. Even if your message eventually sends, the trail of failed attempts gets logged. Providers like Gmail and Outlook consider this a red flag, especially if linked to a new or underperforming sender. You’re not just failing one send—you’re building a record of unreliability.

Hard Bounces and TLS Misconfiguration Are Hidden Killers

Every hard bounce—especially from misconfigured or non-existent addresses—increases your hard bounce rate. High bounce rates directly hurt deliverability, as providers interpret them as a sign of poor list hygiene. Worse, TLS misconfiguration (like missing certificate validation or using outdated cipher suites) is flagged by email security services like RFC 5246 as a potential risk. Even if your content is clean, a weak TLS setup may trigger automated filters or place you in low-priority queues.

Let’s be clear: a single misconfigured SMTP connection isn’t isolated. It can affect multiple recipients across domains, especially if your system retries failed deliveries without throttling. This amplifies the damage. One bad setup on port 587 can look like a scanning attempt or spam campaign to providers monitoring for abuse patterns.

You can’t trust your sender reputation to luck. Regular verification of your email list and SMTP configuration prevents these issues before they escalate. With MailTester’s bulk verification tool, you can identify and remove invalid addresses, catch domains with broken configurations, and reduce the risk of damaging your reputation through automation or misconfiguration.

How to Verify Emails Before Sending to Prevent SMTP Issues

You can avoid SMTP failures with Brevo by cleaning your email list before sending. Use a tool like MailTester to check every address for validity, catch-all status, or disposable domains—this reduces bounces, improves sender reputation, and increases inbox placement, regardless of your TLS port setup (587 or 465).

Why Verification Matters Before You Send

Even with a perfectly configured Brevo SMTP relay, sending to invalid or risky addresses leads to bounces, spam complaints, and damaged sender reputation. A single bad address can trigger a blocklist entry. Let’s be clear: no SMTP configuration fixes a bad list.

Most bounces aren’t about the port choice. They’re about addresses that don’t exist, are auto-responding, or belong to disposable domains. Validating your list in advance—before hitting SendGrid, Brevo, or any ESP—prevents this entirely.

How to Clean Your List with Confidence

Use a dedicated email-verification SaaS like MailTester’s bulk verification tool. It checks thousands of addresses at once, flagging invalid, catch-all, or disposable domains in seconds. This isn’t just filtering; it’s risk mitigation.

When you run a bulk check, the system returns each address with a verdict: valid, invalid, catch-all, or risky. A catch-all email address will accept any sender—meaning it’s a dead end for deliverability. Disposable domains? They’ll vanish in hours, leading to high bounce rates and poor sender reputation.

Real-time verification via API, available at MailTester's API endpoint, integrates directly into your signup or onboarding flow. This stops bad addresses from ever entering your system.

For a single test, use MailTester’s email checker to validate one address before sending. It’s fast, accurate, and shows you exactly why an address fails—like a missing MX record or a known spam trap.

And yes, this matters for inbox placement. According to industry standards, maintaining a low bounce rate and avoiding known spam traps directly impacts your sender score. Even if you’re using TLS 587 or 465 correctly, poor list hygiene will still harm your results.

MailTester Integration: Real-Time Verification for Brevo Workflows

Run your Brevo email lists through MailTester before sending to catch invalid, risky, or disposable addresses. Use MailTester’s real-time verification API at signup or via CRM integrations to block bad emails at the source, and verify bulk lists via CSV or API upload—ensuring only deliverable addresses reach Brevo’s SMTP relay on port 587 or 465.

Pre-emptive Verification: Clean Lists Before Brevo Sends

Before you push a list to Brevo via API or CSV, run it through MailTester’s bulk verification tool. This catches hard bounces—like missing domains or syntax errors—before they damage your sender reputation. You’ll see which addresses are invalid, catch-all, or risky, so you don’t waste sends on dead ends.

Real-Time Guardrails: Stop Bad Emails at the Source

Let’s say you collect emails on a landing page or in a CRM. Integrate MailTester’s real-time API to check each address instantly. It’s not just a pass/fail; you’ll know if it’s a role account (@admin, @sales), a disposable domain, or a typo. This stops delivery failure before it starts.

You can connect MailTester directly to Mailchimp, HubSpot, Klaviyo, or SendGrid, so every new subscriber gets verified before syncing into your Brevo workflow. No more surprise bounces or reputation hits.

MailTester uses real-time SMTP checks, MX validation, and heuristics to achieve 98.9% accuracy—so you can trust the list before sending via Brevo’s SMTP relay, whether you’re using port 587 with TLS or port 465 with SSL. This isn’t just filtering; it’s building a deliverability-safe foundation.

For more on how real-time email verification works across protocols, see the SMTP RFC or TLS in email guidelines. Email hygiene isn't just about the protocol—it’s about ensuring every address you send to is valid, active, and inbox-friendly.

Whether you’re verifying a single address with the email checker, testing inbox placement with the inbox tester, or managing a large list via the bulk verification tool, MailTester ensures you’re sending only what’s safe—and what will land in the inbox, not the spam folder.

TLS and Security: What Your Brevo SMTP Setup Should Protect Against

You must use TLS 1.2 or higher with Brevo SMTP on port 587 (STARTTLS) or port 465 (SMTPS) to prevent email content and credentials from being exposed in plaintext. Without encryption, attackers can intercept messages and log login details during transmission—this defeats the purpose of any email delivery system. Always verify that both your client and server enforce modern TLS, as older versions like TLS 1.0 or 1.1 are no longer secure or compliant.

Why STARTTLS Matters for Your Email Flow

STARTTLS upgrades an unencrypted SMTP connection to a secure one mid-session. It’s the standard for port 587 and protects your messages from man-in-the-middle attacks during transmission. Without it, anyone with access to your network—like a public Wi-Fi attacker—can read or alter your emails. This isn't theory; it's how breaches begin. RFC 8314 details the protocol’s role in modern email security, and major platforms including Google and Microsoft now require it.

Don’t Skip the Basics: TLS Version and Configuration

Using TLS 1.2 or later isn’t optional—it’s a baseline for inbox placement and compliance. Older TLS versions have known vulnerabilities and are blocked by most modern email providers. If your client or server still supports TLS 1.0 or 1.1, disable it immediately. Even a single insecure hop can damage your sender reputation or trigger filtering. Make sure your SMTP client (your app, CRM, or automation tool) is configured to negotiate encryption properly—no exceptions.

And yes, this includes your own infrastructure. If you’re using Brevo’s SMTP relay, you’re not off the hook. Your outbound system must trust the certificate, enforce strong ciphers, and never fall back to unencrypted connections. If you're unsure, test your setup with a tool like inbox placement tester to simulate real-world delivery paths and verify encryption behavior under actual email conditions.

Conclusion: Deploy Brevo SMTP with Port 587 and TLS for Reliable Delivery

Port 587 with STARTTLS is the standard for modern email relay. It offers strong encryption, broad compatibility, and consistent deliverability across email providers.

Avoid port 465 unless you're working with a legacy system that doesn't support STARTTLS. It’s rarely needed today and can complicate configuration without adding value.

  • Use TLS 1.2 or higher for encryption.
  • Ensure your DNS records (SPF, DKIM, DMARC) are correctly configured.
  • Test your setup with inbox placement tools to validate real-world delivery.

Even with perfect SMTP setup, deliverability fails if your email list contains invalid or stale addresses. Clean data is just as critical as correct configuration.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Does Brevo support both TLS ports 587 and 465?

Yes, Brevo supports both ports. However, port 587 with STARTTLS is recommended for modern, secure delivery.

Why is port 587 preferred over 465 for Brevo SMTP?

Port 587 is the modern standard, widely supported, and less likely to be blocked by firewalls or filters.

Can I use port 465 with Brevo in 2026?

Technically yes, but it’s increasingly rare. Use port 587 unless your network explicitly blocks it.

What encryption method should I use with Brevo SMTP?

Use STARTTLS on port 587. Avoid plain text or outdated TLS versions like 1.0 or 1.1.

How can I test if my Brevo SMTP setup is working?

Use tools like telnet, openssl s_client, or an email testing service to verify the TLS handshake and connection.

What happens if I send emails with incorrect SMTP settings?

Messages may not deliver, trigger bouncebacks, and harm your sender reputation over time.

How does list hygiene affect Brevo SMTP delivery?

Invalid or spam-trap emails lead to higher bounce rates and damage your sender reputation, affecting inbox placement.

Can MailTester help me prevent SMTP delivery failures?

Yes — by verifying email addresses before sending, MailTester helps eliminate invalid, catch-all, and disposable emails.

Does MailTester integrate with Brevo?

MailTester integrates with major platforms including Mailchimp, HubSpot, Klaviyo, and SendGrid. You can use it with Brevo workflows via API or CSV.

Is there a free way to test email verification before using it with Brevo?

Yes — MailTester offers 100 free verifications to start, with no expiry on purchased credits.

What does 'valid' mean in MailTester's email verification results?

A 'valid' result means the email address exists and is likely deliverable, with no known blockages or risks.

What is the accuracy of MailTester's email verification?

MailTester has a 98.9% accuracy rate, verified across billions of checks and real-world deliverability metrics.