Analysis of SMTP Protocol Using Wireshark

Experiment 

Analysis of SMTP Protocol Using Wireshark


Aim

To capture and analyze SMTP (Simple Mail Transfer Protocol) packets using Wireshark and study the communication between an email client and an SMTP server during the transmission of an email.


Objectives

After completing this experiment, students will be able to:

  • Understand the working of the SMTP protocol.
  • Capture SMTP packets using Wireshark.
  • Apply SMTP protocol filters in Wireshark.
  • Identify the SMTP client and SMTP server.
  • Analyze SMTP commands and server response codes.
  • Understand how an email message is transmitted over the Internet.
  • Examine the encapsulated IMF (Internet Message Format) packet.

Theory

Simple Mail Transfer Protocol (SMTP)

SMTP (Simple Mail Transfer Protocol) is an Application Layer protocol used to send email messages over the Internet.

SMTP follows a client-server architecture.

  • The sender's email client acts as the SMTP client.
  • The outgoing mail server acts as the SMTP server.

The SMTP client establishes a TCP connection with the SMTP server and exchanges a sequence of commands and responses before transferring the email message.

SMTP generally uses the following ports:

PortPurpose
25    SMTP (Server-to-server communication)
465    SMTP over SSL (SMTPS)
587    SMTP Submission (Most commonly used by email clients)

SMTP uses TCP because reliable delivery is required for email transmission.


Email Transmission Process

+----------------+        SMTP        +------------------+
| Sender Client | -----------------> | SMTP Mail Server |
+----------------+ +------------------+
|
|
Internet
|
|
+------------------+
| Receiver Server |
+------------------+
|
|
Receiver Mailbox

SMTP Communication

Typical SMTP communication consists of the following sequence:

Client                         Server

------ TCP Connection --------->

EHLO example.com
<------ 250 OK

MAIL FROM:<alice@example.com>
<------ 250 OK

RCPT TO:<bob@example.com>
<------ 250 OK

DATA
<------ 354 Start Mail Input

(Message Body)

.
<------ 250 Message Accepted

QUIT
<------ 221 Bye

Important SMTP Commands

CommandPurpose
HELO / EHLO    Identifies the client
MAIL FROM    Specifies sender's email address
RCPT TO    Specifies recipient's email address
DATA    Starts transmission of email contents
QUIT    Terminates SMTP session
RSET    Resets the current session
NOOP    No operation; used to keep the connection alive
AUTH    Performs user authentication (modern SMTP)

Common SMTP Response Codes

CodeMeaning
220    Service Ready
221    Service Closing Transmission
235    Authentication Successful
250    Requested Action Completed Successfully
251    User Not Local; Forwarding
334    Authentication Challenge
354    Start Mail Input
421    Service Not Available
450    Mailbox Busy
451    Local Processing Error
452    Insufficient Storage
500    Syntax Error
550    Mailbox Unavailable
553    Invalid Mailbox
554    Transaction Failed

Internet Message Format (IMF)

The actual email message is formatted according to the Internet Message Format (IMF).

An IMF message consists of:

  • From
  • To
  • Subject
  • Date
  • MIME-Version
  • Content-Type
  • Message Body

SMTP transports this formatted message to the mail server.


Software Required

  • Wireshark
  • Gmail / Outlook / Yahoo Mail or any SMTP-enabled email client
  • Internet Connection

Important Note Before Performing the Experiment

Modern email providers (such as Gmail, Outlook, and Yahoo) use encrypted protocols (SMTPS or STARTTLS). After encryption begins, the SMTP commands and message contents are no longer visible in Wireshark.

To observe SMTP commands in plain text, you may:

  • Use an educational SMTP server that allows unencrypted SMTP.
  • Use a local mail server (e.g., hMailServer or Postfix in a lab environment).
  • Capture only the initial SMTP handshake before TLS encryption starts.
  • Alternatively, use Wireshark sample capture files provided by the instructor.

Procedure

Step 1

Open your email application.

Compose an email addressed to yourself.

Example:

To:
yourname@example.com

Subject:
SMTP Wireshark Experiment

Message:
This is a test email for SMTP packet analysis.

Do not send the email yet.


Step 2

Open Wireshark.

Select the active network interface.

Click

Start Capturing Packets

Step 3

Return to the email application.

Click Send.

Wait until the email is successfully sent.


Step 4

Return to Wireshark.

Stop packet capture.

Capture
→ Stop

Step 5

Apply the display filter

smtp

Click Apply.

Only SMTP packets will be displayed.

If no packets appear because the session used encryption, try filtering with:

  • tcp.port==587
  • tcp.port==25
  • smtp || tcp.port==587

If STARTTLS is used, only the initial SMTP exchange may be visible before encryption begins.


Understanding SMTP Packets

Typical SMTP packet sequence:

220 Service Ready

EHLO mycomputer

250 OK

AUTH LOGIN

334 Username

334 Password

235 Authentication Successful

MAIL FROM

250 OK

RCPT TO

250 OK

DATA

354 Start Mail Input

Email Header

Email Body

.

250 Message Accepted

QUIT

221 Closing Connection

Analysis of Captured Packets


Question (a)

Determine the Source and Destination IP Addresses

Expand

Internet Protocol Version 4

Example

Source Address

192.168.1.12

Destination Address

74.125.24.108

Answer

FieldValue
Client IP    192.168.1.12
SMTP Server IP         74.125.24.108

Explanation

  • The source IP corresponds to the user's computer (SMTP client).
  • The destination IP corresponds to the SMTP mail server.

Question (b)

Determine the SMTP Client Port Number

Expand

Transmission Control Protocol

Example

Source Port

52184

Destination Port

587

Answer

SMTP Client Port

52184

Client Port Range

Client ports are called ephemeral (dynamic) ports.

Typical range

49152 – 65535

(Operating systems may use a slightly different dynamic port range.)


Question (c)

Determine the SMTP Server Port Number

Example

Destination Port

587

Answer

SMTP Server Port

587

Possible values

PortPurpose
25    SMTP
465    SMTPS
587    SMTP Submission

Question (d)

Examine SMTP Commands and Response Codes

Expand

Simple Mail Transfer Protocol

You may observe commands such as

SMTP CommandMeaning
EHLOIntroduces the client and requests extended SMTP features
AUTH LOGINRequests authentication using username/password
MAIL FROMSpecifies the sender's email address
RCPT TOSpecifies the recipient's email address
DATAIndicates that the email content follows
QUITTerminates the SMTP session

Common response codes

Response CodeMeaning
220SMTP service ready
235Authentication successful
250Requested mail action completed successfully
334Server requests authentication credentials
354Start mail input; end the message with a single period (.) on a line by itself
221Closing connection

Question (e)

Examine the Encapsulated IMF Packet

Expand

Internet Message Format

Typical contents

From:
student@example.com

To:
student@example.com

Subject:
SMTP Wireshark Experiment

Date:
Mon, 06 Jul 2026

MIME-Version: 1.0

Content-Type:
text/plain

This is a test email for SMTP packet analysis.

IMF Contains

  • Sender address
  • Recipient address
  • Subject
  • Date
  • MIME version
  • Content type
  • Email body

The IMF packet represents the complete email message that SMTP transports to the mail server.


Observation Table

ParameterObserved Value
Source IP Address_____________________
Destination IP Address_____________________
SMTP Client Port_____________________
SMTP Server Port_____________________
SMTP Commands Observed_____________________
SMTP Response Codes_____________________
Sender Email Address_____________________
Recipient Email Address_____________________
Subject_____________________
MIME Version_____________________
Content Type_____________________
Message Body_____________________

Result

SMTP communication between the email client and the SMTP server was successfully captured and analyzed using Wireshark. The experiment demonstrated the client-server interaction during email transmission, including the identification of IP addresses, port numbers, SMTP commands, response codes, and the encapsulated Internet Message Format (IMF) containing the email headers and body. Students gained practical insight into how email is transmitted using the SMTP protocol.


Precautions

  1. Ensure packet capture starts before sending the email.
  2. Stop the capture immediately after the email is sent to reduce unnecessary packets.
  3. Use the appropriate display filter (smtp or tcp.port==587) to isolate SMTP traffic.
  4. Be aware that modern email services encrypt SMTP sessions using STARTTLS or SMTPS, so many commands and the email body may not be visible after encryption begins.
  5. Do not expose real passwords or sensitive email content during packet analysis.


Additional Exercises

  1. Capture and compare SMTP sessions using ports 25, 465, and 587 (if available in your lab environment).
  2. Identify whether the email session uses STARTTLS, and determine at which point the traffic becomes encrypted.
  3. Compare the SMTP headers generated by different email clients (e.g., Outlook and Thunderbird) using the same SMTP server.
  4. Analyze the MIME structure of an email containing an attachment and identify the different MIME parts.
  5. Send an email with both plain text and HTML content, then compare the IMF message structure in Wireshark.
  6. Measure the time between the DATA command and the server's 250 OK response, and discuss factors that may influence email delivery latency.

Comments

Popular posts from this blog

Networks Lab PCCSL507 Semester 5 KTU CS 2024 Scheme - Dr Binu V P

Study of whois Command

Study and Use of ifconfig Command