> For the complete documentation index, see [llms.txt](https://docs.qu35t.pw/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.qu35t.pw/smtp.md).

# SMTP

## Enumeration

{% tabs %}
{% tab title="Configuration" %}

```bash
cat /etc/postfix/main.cf | grep -v "#" | sed -r "/^\s*$/d"
```

{% endtab %}

{% tab title="Commands" %}

```bash
AUTH PLAIN # AUTH is a service extension used to authenticate the client.
HELO # The client logs in with its computer name and thus starts the session.
MAIL FROM # The client names the email sender.
RCPT TO # The client names the email recipient.
DATA # The client initiates the transmission of the email.
RSET # The client aborts the initiated transmission but keeps the connection between client and server.
VRFY # The client checks if a mailbox is available for message transfer.
EXPN # The client also checks if a mailbox is available for messaging with this command.
NOOP # The client requests a response from the server to prevent disconnection due to time-out.
QUIT # The client terminates the session.
```

{% endtab %}

{% tab title="Authentication" %}

```bash
telnet 10.10.10.10 25
```

{% endtab %}

{% tab title="List existing users" %}

```bash
VRFY root
```

```bash
smtp-user-enum -m VRFY -U names.txt "10.10.10.10" 25
```

{% endtab %}
{% endtabs %}
