There used to be public SMTP servers a person could point their mail client at without an account. You typed in mail.some-university.edu or your ISP’s outgoing server, hit send, and the message went. In 2026 that class of server is functionally extinct: the ones that still exist do not reach inboxes, and the search for a free, no-login SMTP relay is a search for a version of the internet that ended somewhere between the spam-blocklist wars of the 2000s and Gmail’s bulk-sender rules of 2024.
The answer to the query is not another list of ten free relays. What sits under it, can I send mail without an account and without paying?, has three real options in 2026, and none of them look the way the query expects.
What “unauthenticated SMTP” actually means
SMTP is a text protocol defined in
RFC 5321. Its 2008 revision, like the 1982 original before it, describes a conversation between two servers: the sending side offers a message, the receiving side accepts or refuses. Authentication is nowhere in the mail transaction the RFC describes. A server that accepts a message from any client that can open a TCP connection to port 25 and speak the protocol is, in the strict sense, an open relay. It relays mail without requiring the client to prove anything about who they are.
SMTP authentication was added later, as an extension: the AUTH command, first standardised in RFC 2554 (1999) and superseded by
RFC 4954 in 2007. AUTH runs during the ESMTP handshake, before the message envelope is negotiated, and it lets the receiving server tie the connection to a known account. Every modern mail server supports it; every provider that lets a WordPress site send mail through them requires it. But the protocol itself still permits the older, credential-free conversation. An operator can stand up an open relay today with three lines of Postfix config. It will accept mail. It will not deliver any of it.
The important split is between what the protocol permits and what the delivery graph accepts. The protocol permits unauthenticated submission. The delivery graph, meaning the set of mailbox providers, spam filters, and reputation systems that decide what lands in an inbox, treats unauthenticated mail from an unknown sender as spam by default. That change is what makes the search for a free, unauthenticated SMTP server a search for something that cannot do the job even when you find it.
Why open relays stopped being deliverable
Three separate changes closed the door on unauthenticated SMTP, each stacked on top of the last.
The first was blocklisting. Real-time blackhole lists (RBLs) such as Spamhaus SBL and XBL, SORBS, and SpamCop indexed known open relays through the 2000s. Any mail server that queried an RBL before accepting a connection could refuse mail from a listed source outright. By the late 2000s, an open relay was on Spamhaus within hours of being scanned, and refusing SBL-listed sources was default configuration for essentially every serious mail receiver.
The second was port 25 blocking. Consumer ISPs began filtering outbound TCP port 25 as a matter of policy in the mid-2000s, formalised in
M3AAWG’s port 25 management recommendation (originally 2005, updated 2019). The reasoning was practical: a compromised home PC on a residential connection had no legitimate business speaking SMTP to a stranger’s mail server, and blocking it at the ISP edge cut spam volumes at the source. Cloud providers picked up the same practice. Amazon EC2, Google Compute Engine, and Microsoft Azure all block outbound port 25 by default; unblocking it requires a support case and an approved use case. An open relay on an EC2 instance cannot make an outbound SMTP connection to a Gmail MX in the first place.
The third was the bulk-sender rules. In February 2024, Gmail began enforcing authentication requirements for any sender delivering more than 5,000 messages per day to Google users: SPF and DKIM on every message, DMARC alignment, one-click unsubscribe for marketing mail, a spam-complaint rate kept below 0.30%, valid PTR records, TLS on the connection, and RFC 5322 message format. Yahoo announced comparable requirements on the same enforcement schedule. Microsoft applied a matching bulk-sender policy to Outlook.com and Hotmail in 2025. The threshold is written as 5,000/day, but in practice the filters that enforce alignment and DMARC run against every message, not just the ones above the line; an unauthenticated sender at any volume is scored down.
The cumulative effect: an open SMTP relay in 2026 is on a blocklist, can’t reach the ports it needs, and would be rejected on the authentication check even if it did. None of this is a policy someone can waive for a small site. It is the delivery graph the internet actually runs on.
Why every “free SMTP server” authenticates
The category of provider marketed as free SMTP, including Brevo, Mailjet, MailerSend, Elastic Email, SMTP2GO, and Resend, is neither free in the sense of no account nor in the sense of no strings. Every one of them issues the sender an SMTP username and password (or an API key that plays the same role) and requires that credential on every message. The reason isn’t a business decision; it’s the delivery graph. A provider that let its senders relay unauthenticated mail would be blocklisted for the abuse the open service would attract, and its paying customers would stop reaching inboxes.
What these providers offer for zero dollars is not unauthenticated SMTP. It is a tiered account with a monthly or daily message cap, a signed sending domain, and, in most cases, a “sent via” footer or subject-line badge until the sender upgrades. The tiers are finite (a few hundred to a few thousand messages a month depending on provider), the sending domain has to be verified by DNS, and the SPF/DKIM records the provider generates have to be published on the domain the mail goes out from. There is no path through any of them that involves typing a hostname into a WordPress plugin and hitting save without an account.
The specific numbers move month to month. For the current state of the free tiers a WordPress site can actually use, with permanent free plans, time-limited trials, and testing sandboxes distinguished from each other, see free SMTP servers for WordPress. What matters here is the shape: every entry on that page requires authentication. There is no listing where the answer is point your mailer at this hostname.
The three genuinely free paths in 2026
If the question is how do I send mail without paying a provider, three answers are actually available. None of them is what the search query implies.
The closest to what most people mean by free SMTP is a free tier at a real provider. Free in dollars, capped in volume (typically 100 to 500 messages a day, or a few thousand a month), authenticated with a per-account SMTP credential, and paid for elsewhere in the provider’s business, usually by the sender’s expected conversion to a paid tier. Deliverability on a free tier is the same as on a paid tier at the same provider; the cap is the constraint, not the reputation. For a WordPress site sending contact-form replies and WooCommerce order confirmations at low volume, this path is the working answer, and the roundup linked above has the current numbers.
The second option is a self-hosted mail server on a warmed IP. Free in software (Postfix, OpenSMTPD, and Haraka are open source), free in cloud compute at the lowest tiers, and expensive in the one currency that matters: time. Standing up an MTA that reaches Gmail and Microsoft 365 inboxes requires an IP that isn’t on a blocklist, a hostname with a valid PTR record, working SPF and DKIM on the sending domain, a DMARC policy the receivers can align against, port 25 unblocked at the cloud provider (which requires a support case), and, the hard part, a period of gradual send-rate ramp so the receiving side builds a sender reputation for the IP. The ramp typically takes weeks to months, and small IPs never accumulate the reputation of a shared pool at an established provider; a WordPress site sending under a few thousand messages a month is unlikely to earn better placement from a personal MTA than from a free-tier ESP. The path is real, and it is the honest answer to the without paying anyone framing, but calling it free is a category error. It is free of monthly bills and expensive of operator hours.
The third is a provider free trial, meaning time-limited access at a higher tier. SendGrid’s 60-day trial is the canonical case; Postmark’s sandbox and several others follow a similar pattern. Useful for evaluating a provider or migrating a site; not a strategy for sending mail permanently. When the trial expires, the site is either on the paid plan or offline. The path is worth naming because the search query often lands on trial listings that read as free plans, and the distinction between free and free until Tuesday matters for a site owner deciding what to configure.
Missing from this list, deliberately: the residential ISP outgoing server. Most ISPs that still operate one require authentication with the account owner’s credentials, apply a rate cap in the low tens per hour, rewrite the envelope sender to the ISP domain, and, in the case of the major US and UK carriers, quietly stop retrying for external addresses that treat their range as low-reputation. It is not a general-purpose SMTP server; it is a submission point for the ISP’s own subscribers, and only for their own mail.
Also missing: Gmail SMTP as an unauthenticated server. Gmail’s SMTP endpoint (smtp.gmail.com) is often what searchers land on when they type google free smtp server, but Gmail SMTP always requires authentication with either an App Password or OAuth. It is free at low volume within a Google account’s daily send limit, but the account is the authentication.
What a WordPress operator should actually do
A WordPress site that wants to send mail without paying a provider has one working path in the small volumes most sites operate at: pick a free-tier ESP, verify the sending domain with the SPF and DKIM records the provider generates, and point FluentSMTP, WP Mail SMTP, or Post SMTP at the credential. The site’s transactional mail (password resets, order confirmations, form submissions) is well under any of the free-tier daily caps, and the authentication burden is a one-time DNS edit.
A site that expects to grow past the free-tier cap should pick the provider whose paid pricing suits the expected volume from the start; migrating between ESPs after the domain reputation is built is a mild operational chore, but it’s easier than migrating after the first month where the free tier throttles the mail. The roundup ranks the tiers by their permanence for exactly this reason.
A site with an unusual constraint (no third-party providers permitted, self-hosted infrastructure requirement, or a technical operator who wants the education) can run a personal Postfix on a cloud VM. The setup is documented widely and the software is stable; the deliverability work is the load. Treat the first three months as the ramp, treat Gmail and Microsoft 365 placement as an eventual result rather than a starting condition, and keep a free-tier fallback provider configured in case the ramp doesn’t take.
The search for free SMTP server without authentication has no answer that both matches the query and does the job. The search for how do I send email from my WordPress site without paying does, and it is the second search the reader actually needs.
Related reading
- Free SMTP servers for WordPress: the ranked comparison, with current tier numbers.
- How to use Gmail as an SMTP server without OAuth: the App Password path for Gmail SMTP.
- Reading SMTP bounce codes in WordPress mailer logs: decoding the rejections an unauthenticated relay attempt would produce.
