# Network and sending email

## Your addresses

Your server's card, **VPS** section of your client area, shows two addresses:

| Address          | Its role                                                                                                                                                                 |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **IPv4 address** | the address at which your visitors reach your sites over IPv4 (ports 80 and 443, under your domain names) and you reach your server over SSH, on the port from your card |
| **IPv6 address** | your server's public address, which belongs to it alone                                                                                                                  |

These two addresses are the ones for your `A` and `AAAA` DNS records (see [Putting a site or an application online](/en/vps-pro/mettre-en-ligne.md)).

## Your server's ports

| Port                                       | What arrives there                                                                                           |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------ |
| **80** and **443**                         | your sites and your APIs, over HTTP and HTTPS, under your server's name and the domains you have added to it |
| the **SSH connection** port from your card | your SSH access, over IPv4                                                                                   |
| all ports, over **IPv6**                   | whatever you choose to open on your IPv6 address                                                             |

Your IPv6 address belongs entirely to you: your firewall decides what it exposes.

## Your firewall

Open only what your services expose to the public. With **ufw**, shipped with Ubuntu:

```
apt install ufw

ufw default deny incoming

ufw default allow outgoing

ufw allow 22/tcp      # SSH

ufw allow 80/tcp      # HTTP

ufw allow 443/tcp     # HTTPS

ufw enable

ufw status verbose
```

Keep port **22** open: it is through this port that your SSH connection arrives on your server, whatever port is shown in your card. Your databases stay listening on `localhost`, and you reach them through an SSH tunnel.

## Anti-DDoS protection

Always-on network filtering stops flood attacks before they reach your server. It works continuously, with no setup on your part.

## Traffic

Your VPS Pro has no monthly traffic limit: your visitors, your downloads and your outbound backups flow without a meter.

## Sending email from your server

Your applications send their email (sign-up, forgotten password, notifications, invoices) through an **authenticated SMTP relay**, on port **587** with STARTTLS. This is also what gives your email the best deliverability: it leaves from a service that carries your domain's reputation and signatures.

Two ways to do it:

* **from an address you already have**, with your current email provider;
* **from Simafri Suite**, the professional email at your own domain name, when your volumes grow (see the [Simafri Suite documentation](https://docs.simafri.com/en/suite/)).

The settings in your application, for example for a `.env` file:

```
MAIL_HOST=smtp.your-provider.com

MAIL_PORT=587

MAIL_ENCRYPTION=tls

MAIL_USERNAME=notifications@my-company.com

MAIL_PASSWORD=...
```

For the system tools (`cron` alerts, `unattended-upgrades`), a small relay such as `msmtp`, or Postfix configured as a "satellite", forwards everything to the same SMTP relay.

## Frequently asked questions

### My application cannot send email.

Set it to port **587** with the authentication of your email account. To test the relay from your server:

```
openssl s_client -starttls smtp -connect smtp.your-provider.com:587
```

A banner that starts with `220` shows that the connection goes through; all that remains is to check the username and the password in your application.

### How do my emails stay out of spam?

By leaving from your SMTP relay with an address on your domain, whose DNS zone publishes the **SPF**, **DKIM** and **DMARC** records of that relay. Simafri Suite gives you these records when you set up your domain.

### Can my server reach external services?

Yes: your applications call APIs, package repositories and services all over the world, over IPv4 as well as IPv6.
