smtp.session.unavailable
SMTP Session Not Established
What we check
We connect to each MX IP on port 25 and try to open an SMTP session — read the greeting banner and send EHLO — before testing STARTTLS. This finding is emitted when the host accepted the TCP connection but no usable session came about: it refused the session with a 4xx/5xx greeting or EHLO reply, or it sent no greeting at all within the scanner's wait.
A connection the operating system could not complete — refused, connect timeout, no route — is a different, scored finding: MX Endpoint Unreachable. The MX table tells the two apart: "No SMTP greeting (timed out)" belongs to this finding, "Connection timed out" to that one.
What this finding means
The server accepted the connection, but no session with the scanner came about. Common causes:
- Greylisting. A
4xxgreeting ("421 try later") asks unknown senders to come back — standard anti-spam behaviour. - EHLO or rDNS policy. A
5xxrejection of the scanner'sEHLOor of its connecting IP by a reverse-DNS or reputation rule. - Silent stall. Postfix
postscreenand anti-bot tarpits delay or withhold the greeting for unknown or suspicious clients — often after the scanner's own probes have tripped an error limit on an earlier connection. The scanner gives up after its wait and records "no greeting". - Rate or connection limits tied to the connecting IP.
Because the refusal or stall is tied to the connecting IP and the moment, it is usually not a fault of the server's configuration, and it says nothing about the server's TLS. That is why it is not scored, even when the same endpoint completed a session in an earlier scan.
Why it matters
- TLS could not be tested for this IP from the scanner's vantage point. The STARTTLS, cipher, certificate and DANE checks for this endpoint are unavailable, not failed.
- Per-IP. Every IP is probed on its own; the other IPs of the same MX carry the verdict.
- Usually transient. Greylisting clears on retry; a re-scan a few minutes later typically completes.
What to do
- Re-scan later. Greylisting is designed to be temporary.
- If it persists across scans, check whether your server's rDNS/EHLO policy or reputation rules reject the scanner's IPs — they have matching forward and reverse DNS under
mxaud.it. - If the server refuses every connecting IP, delivery is affected — but that shows up as delivery problems reported by real senders, not from this finding alone.
How it's graded
Not scored. This finding deducts nothing. The TLS and SMTP categories are graded from the endpoints that did establish a session. See Grading Methodology for the full scoring model.
Evidence example
A refused session:
220 mail.example.com ESMTP
EHLO scan-01.mxaud.it
421 Greylisting enabled, please try later
A silent stall, as listed in the finding:
mx2.example.com 192.0.2.11 (no greeting: i/o timeout)