Simple Mail Transfer Protocol (SMTP)
The protocol (RFC 5321) that sends email from clients to mail servers and relays it between servers. It was designed without sender authentication or encryption.
The Simple Mail Transfer Protocol (SMTP), currently specified in RFC 5321, moves email toward its destination. A mail client submits a message to its outgoing server, and servers relay it from one to the next until it reaches the recipient’s domain; server-to-server relay uses TCP port 25 by default. SMTP only sends. Users collect mail with a different protocol, such as IMAP or POP3.
SMTP was designed for a trusting network. It does not verify that the sender named in a message is genuine, which is what makes email spoofing easy, and it originally carried everything in clear text. Later extensions each close part of the gap. STARTTLS (RFC 3207) upgrades a connection to TLS, protecting each hop but not the message once it sits on a server. SMTP authentication lets a server require users to log in before it accepts mail, which helps prevent an open relay that anyone can use to send spam. SPF, DKIM and DMARC let receivers check whether mail really comes from the domain it claims, and S/MIME protects the message end to end.
Exam relevance: a scenario about forged sender addresses or a server relaying mail for outsiders is likely to turn on SMTP’s missing authentication. Candidates are expected to match each add-on to the gap it closes.