Analysis of SMTP Protocol Using Wireshark
Experiment
Analysis of SMTP Protocol Using Wireshark
Aim
To capture and analyze SMTP (Simple Mail Transfer Protocol) packets using Wireshark and study the communication between an email client and an SMTP server during the transmission of an email.
Objectives
After completing this experiment, students will be able to:
- Understand the working of the SMTP protocol.
- Capture SMTP packets using Wireshark.
- Apply SMTP protocol filters in Wireshark.
- Identify the SMTP client and SMTP server.
- Analyze SMTP commands and server response codes.
- Understand how an email message is transmitted over the Internet.
- Examine the encapsulated IMF (Internet Message Format) packet.
Theory
Simple Mail Transfer Protocol (SMTP)
SMTP (Simple Mail Transfer Protocol) is an Application Layer protocol used to send email messages over the Internet.
SMTP follows a client-server architecture.
- The sender's email client acts as the SMTP client.
- The outgoing mail server acts as the SMTP server.
The SMTP client establishes a TCP connection with the SMTP server and exchanges a sequence of commands and responses before transferring the email message.
SMTP generally uses the following ports:
| Port | Purpose |
|---|---|
| 25 | SMTP (Server-to-server communication) |
| 465 | SMTP over SSL (SMTPS) |
| 587 | SMTP Submission (Most commonly used by email clients) |
SMTP uses TCP because reliable delivery is required for email transmission.
Email Transmission Process
+----------------+ SMTP +------------------+
| Sender Client | -----------------> | SMTP Mail Server |
+----------------+ +------------------+
|
|
Internet
|
|
+------------------+
| Receiver Server |
+------------------+
|
|
Receiver Mailbox
SMTP Communication
Typical SMTP communication consists of the following sequence:
Client Server
------ TCP Connection --------->
EHLO example.com
<------ 250 OK
MAIL FROM:<alice@example.com>
<------ 250 OK
RCPT TO:<bob@example.com>
<------ 250 OK
DATA
<------ 354 Start Mail Input
(Message Body)
.
<------ 250 Message Accepted
QUIT
<------ 221 Bye
Important SMTP Commands
| Command | Purpose |
|---|---|
| HELO / EHLO | Identifies the client |
| MAIL FROM | Specifies sender's email address |
| RCPT TO | Specifies recipient's email address |
| DATA | Starts transmission of email contents |
| QUIT | Terminates SMTP session |
| RSET | Resets the current session |
| NOOP | No operation; used to keep the connection alive |
| AUTH | Performs user authentication (modern SMTP) |
Common SMTP Response Codes
| Code | Meaning |
|---|---|
| 220 | Service Ready |
| 221 | Service Closing Transmission |
| 235 | Authentication Successful |
| 250 | Requested Action Completed Successfully |
| 251 | User Not Local; Forwarding |
| 334 | Authentication Challenge |
| 354 | Start Mail Input |
| 421 | Service Not Available |
| 450 | Mailbox Busy |
| 451 | Local Processing Error |
| 452 | Insufficient Storage |
| 500 | Syntax Error |
| 550 | Mailbox Unavailable |
| 553 | Invalid Mailbox |
| 554 | Transaction Failed |
Internet Message Format (IMF)
The actual email message is formatted according to the Internet Message Format (IMF).
An IMF message consists of:
- From
- To
- Subject
- Date
- MIME-Version
- Content-Type
- Message Body
SMTP transports this formatted message to the mail server.
Software Required
- Wireshark
- Gmail / Outlook / Yahoo Mail or any SMTP-enabled email client
- Internet Connection
Important Note Before Performing the Experiment
Modern email providers (such as Gmail, Outlook, and Yahoo) use encrypted protocols (SMTPS or STARTTLS). After encryption begins, the SMTP commands and message contents are no longer visible in Wireshark.
To observe SMTP commands in plain text, you may:
- Use an educational SMTP server that allows unencrypted SMTP.
- Use a local mail server (e.g., hMailServer or Postfix in a lab environment).
- Capture only the initial SMTP handshake before TLS encryption starts.
- Alternatively, use Wireshark sample capture files provided by the instructor.
Procedure
Step 1
Open your email application.
Compose an email addressed to yourself.
Example:
To:
yourname@example.com
Subject:
SMTP Wireshark Experiment
Message:
This is a test email for SMTP packet analysis.
Do not send the email yet.
Step 2
Open Wireshark.
Select the active network interface.
Click
Start Capturing Packets
Step 3
Return to the email application.
Click Send.
Wait until the email is successfully sent.
Step 4
Return to Wireshark.
Stop packet capture.
Capture
→ Stop
Step 5
Apply the display filter
smtp
Click Apply.
Only SMTP packets will be displayed.
If no packets appear because the session used encryption, try filtering with:
tcp.port==587tcp.port==25smtp || tcp.port==587If STARTTLS is used, only the initial SMTP exchange may be visible before encryption begins.
Understanding SMTP Packets
Typical SMTP packet sequence:
220 Service Ready
EHLO mycomputer
250 OK
AUTH LOGIN
334 Username
334 Password
235 Authentication Successful
MAIL FROM
250 OK
RCPT TO
250 OK
DATA
354 Start Mail Input
Email Header
Email Body
.
250 Message Accepted
QUIT
221 Closing Connection
Analysis of Captured Packets
Question (a)
Determine the Source and Destination IP Addresses
Expand
Internet Protocol Version 4
Example
Source Address
192.168.1.12
Destination Address
74.125.24.108
Answer
| Field | Value |
|---|---|
| Client IP | 192.168.1.12 |
| SMTP Server IP | 74.125.24.108 |
Explanation
- The source IP corresponds to the user's computer (SMTP client).
- The destination IP corresponds to the SMTP mail server.
Question (b)
Determine the SMTP Client Port Number
Expand
Transmission Control Protocol
Example
Source Port
52184
Destination Port
587
Answer
SMTP Client Port
52184
Client Port Range
Client ports are called ephemeral (dynamic) ports.
Typical range
49152 – 65535
(Operating systems may use a slightly different dynamic port range.)
Question (c)
Determine the SMTP Server Port Number
Example
Destination Port
587
Answer
SMTP Server Port
587
Possible values
| Port | Purpose |
|---|---|
| 25 | SMTP |
| 465 | SMTPS |
| 587 | SMTP Submission |
Question (d)
Examine SMTP Commands and Response Codes
Expand
Simple Mail Transfer Protocol
You may observe commands such as
| SMTP Command | Meaning |
|---|---|
| EHLO | Introduces the client and requests extended SMTP features |
| AUTH LOGIN | Requests authentication using username/password |
| MAIL FROM | Specifies the sender's email address |
| RCPT TO | Specifies the recipient's email address |
| DATA | Indicates that the email content follows |
| QUIT | Terminates the SMTP session |
Common response codes
| Response Code | Meaning |
|---|---|
| 220 | SMTP service ready |
| 235 | Authentication successful |
| 250 | Requested mail action completed successfully |
| 334 | Server requests authentication credentials |
| 354 | Start mail input; end the message with a single period (.) on a line by itself |
| 221 | Closing connection |
Question (e)
Examine the Encapsulated IMF Packet
Expand
Internet Message Format
Typical contents
From:
student@example.com
To:
student@example.com
Subject:
SMTP Wireshark Experiment
Date:
Mon, 06 Jul 2026
MIME-Version: 1.0
Content-Type:
text/plain
This is a test email for SMTP packet analysis.
IMF Contains
- Sender address
- Recipient address
- Subject
- Date
- MIME version
- Content type
- Email body
The IMF packet represents the complete email message that SMTP transports to the mail server.
Observation Table
| Parameter | Observed Value |
|---|---|
| Source IP Address | _____________________ |
| Destination IP Address | _____________________ |
| SMTP Client Port | _____________________ |
| SMTP Server Port | _____________________ |
| SMTP Commands Observed | _____________________ |
| SMTP Response Codes | _____________________ |
| Sender Email Address | _____________________ |
| Recipient Email Address | _____________________ |
| Subject | _____________________ |
| MIME Version | _____________________ |
| Content Type | _____________________ |
| Message Body | _____________________ |
Result
SMTP communication between the email client and the SMTP server was successfully captured and analyzed using Wireshark. The experiment demonstrated the client-server interaction during email transmission, including the identification of IP addresses, port numbers, SMTP commands, response codes, and the encapsulated Internet Message Format (IMF) containing the email headers and body. Students gained practical insight into how email is transmitted using the SMTP protocol.
Precautions
- Ensure packet capture starts before sending the email.
- Stop the capture immediately after the email is sent to reduce unnecessary packets.
-
Use the appropriate display filter (
smtportcp.port==587) to isolate SMTP traffic. - Be aware that modern email services encrypt SMTP sessions using STARTTLS or SMTPS, so many commands and the email body may not be visible after encryption begins.
- Do not expose real passwords or sensitive email content during packet analysis.
Additional Exercises
- Capture and compare SMTP sessions using ports 25, 465, and 587 (if available in your lab environment).
- Identify whether the email session uses STARTTLS, and determine at which point the traffic becomes encrypted.
- Compare the SMTP headers generated by different email clients (e.g., Outlook and Thunderbird) using the same SMTP server.
- Analyze the MIME structure of an email containing an attachment and identify the different MIME parts.
- Send an email with both plain text and HTML content, then compare the IMF message structure in Wireshark.
-
Measure the time between the
DATAcommand and the server's250 OKresponse, and discuss factors that may influence email delivery latency.
Comments
Post a Comment