# Network and sending email

## Your addresses

| Address          | Its role                                                                                                                                         |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| **IPv4 address** | your dedicated address, which belongs to your server alone: your domains, your certificates, your filtering rules and your reputation rest on it |
| **IPv6 address** | your server's public IPv6 address                                                                                                                |

Both are shown in your server's card, **VPS** section of your client area.

## All ports

Your dedicated IPv4 address receives traffic on **all ports**: a site on 80 and 443, SSH on 22, a WireGuard VPN on 51820/udp, an API on the port of your choice. Your firewall decides what your server exposes.

## Your firewall

Open only what your services expose to the public. With **ufw**, on Ubuntu or Debian:

```
apt install ufw

ufw default deny incoming

ufw default allow outgoing

ufw allow 22/tcp      # SSH

ufw allow 80/tcp      # HTTP

ufw allow 443/tcp     # HTTPS

ufw enable

ufw status verbose
```

Open the SSH port **before** enabling the firewall, to keep your access. On Windows Server, **Windows Defender Firewall** plays the same role.

## Anti-DDoS protection

Always-on network filtering stops flood attacks before they reach your server, continuously and with no setup on your part.

## Traffic

Your VPS Ultra has no monthly traffic limit.

## Sending email

Two ways to do it, depending on your project.

### Through an authenticated SMTP relay

Your applications send their email through an SMTP relay, on port **587** with STARTTLS: an address from your current email provider, or Simafri Suite, the professional email at your own domain name (see the [Simafri Suite documentation](https://docs.simafri.com/en/suite/)). It is the simplest route, and it works from the moment the server goes into service.

### Directly, from your own address

Your VPS Ultra can also send its mail itself, from your dedicated IPv4 address: a complete mail server, or an application that delivers its email without a relay. Direct sending is enabled **on request**, once your account is verified:

1. Write to support with your server's name, the sending domain and the intended use.
2. At the same time, request the **reverse name** (PTR) of your IPv4 address, for example `mail.my-company.com`: receiving servers check it.
3. Publish your server's **SPF**, **DKIM** and **DMARC** records in your domain's DNS zone.

Your sending reputation then rests on your address: send to recipients who are expecting your messages, and handle unsubscribes and addresses in error.

## Frequently asked questions

### How do I check that my emails are properly signed?

Send a message to a mailbox you read and display its source: the `Authentication-Results` headers show `spf=pass`, `dkim=pass` and `dmarc=pass` when everything is in place.

### Can my server reach external services?

Yes: your applications call APIs, package repositories and services all over the world, over IPv4 as well as IPv6.
