---
title: Defending Against SMTP Smuggling with KumoMTA
description: A new SMTP exploit called SMTP Smuggling has been release, learn how to defend against it with KumoMTA.
image: https://kumomta.com/hubfs/Email%20Smuggler.jpg
---

[Skip to content](https://kumomta.com/blog/defending-against-smtp-smuggling-with-kumomta#main-content)

[![KUMO\_Logo\_NEW\_Color](https://kumomta.com/hs-fs/hubfs/KUMO_Logo_NEW_Color.png?width=118&height=32&name=KUMO_Logo_NEW_Color.png "KUMO_Logo_NEW_Color")](https://kumomta.com)

- Technology 
    - [Architecture](https://kumomta.com/technology/architecture)
    - [Features](https://kumomta.com/technology)
    - [Open Source](https://kumomta.com/technology/open-source)
- [Support & Pricing](https://kumomta.com/pricing)
- About Kumo 
    - [About Us](https://kumomta.com/about)
    - [Events](https://kumomta.com/events)
    - [Customers](https://kumomta.com/customers)
    - [Contact Us](https://kumomta.com/contact)
- Resources 
    - [Documentation](https://docs.kumomta.com/)
    - [Migration Center](https://kumomta.com/migration-center) 
          - [Migration Center Hub](https://kumomta.com/migration-center)
          - [Momentum](https://kumomta.com/momentum-migration-guide)
          - [PowerMTA](https://kumomta.com/replace-powermta-with-kumomtas-infrastructure-built-for-mailops)
          - [Halon](https://kumomta.com/halon-migration-guide)
          - [SendGrid](https://kumomta.com/sendgrid-alternative-migration)
          - [Hurricane MTA](https://kumomta.com/hurricanemta-alternative-socketlabs-migration)
    - [Blog](https://kumomta.com/blog)
    - [Community Forum](https://community.kumomta.com/)
    - Guides & Reports 
          - [2026 MTA Buyers Guide](https://kumomta.com/buyers-guide-2026-download)
          - [2026 State of MailOps](https://kumomta.com/2026-state-of-mailops-report-download-page)
    - [YouTube Channel](https://www.youtube.com/channel/UC348UpfbnPgpKPAXIBW_JNQ)
    - [Github Repository](https://github.com/KumoCorp/kumomta)

- [Contact](https://kumomta.com/contact)

- [MTA](https://kumomta.com/blog/tag/mta),
- [On-Prem](https://kumomta.com/blog/tag/on-prem),
- [KumoMTA](https://kumomta.com/blog/tag/kumomta),
- [Open-Source](https://kumomta.com/blog/tag/open-source),
- [security](https://kumomta.com/blog/tag/security),
- [SMTP](https://kumomta.com/blog/tag/smtp)

# Defending Against SMTP Smuggling with KumoMTA

![](https://kumomta.com/hubfs/Email%20Smuggler.jpg)

- December 20, 2023

![Mike Hillyer](https://app.hubspot.com/settings/avatar/ef4bdb34f7a0a0173ce043e53c805f2e)

[Mike Hillyer](https://kumomta.com/blog/author/mike-hillyer)

## What is SMTP Smuggling?

On September 18th there was a new exploit published regarding SMTP Smuggling, which you can read about at [https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/](https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/).

The short version is that an attacker can potentially exploit a situation where a sending MTA is tricked into sending `<lf>.<lf>` as part of the message data, and then relaying that to a receiving MTA that incorrectly interprets that sequence as the end of the message. If the attacker embeds SMTP protocol commands in such a message there is a chance that they will be interpreted as authorized commands by the receiving MTA and may result in additional messages being sent on behalf of the sending MTA, but *without its knowledge or express permission*.

This is different from an attacker directly connecting to the receiving MTA to spoof the messages; because in this situation the messages are coming from the sending MTA they will SPF align and, if the connection is using other authentication mechanisms, they will likely also be considered authenticated in the same way. This makes it potentially possible for the attacker to spoof the same or other domains for which the sending MTA is authorized to send, which is a serious threat if the sending MTA is at a major ESP.

![
            Figure 15: SMTP smuggling from admin@gmx.net to user@provider.example 
        ](https://sec-consult.com/fileadmin/user_upload/sec-consult/Dynamisch/Blogartikel/2023_12/SMTP_Smuggling-SMTP_smuggling_GMX__16_.png)

In the example above, if the sending MTA doesn't consider the non-conformant `\n.\r\n` sequence as the end of the message data, but the receiving MTA does, then the receiving MTA will see two messages coming from the sending MTA and potentially accept both since the incoming session is SPF-aligned.

SMTP Smuggling is a configuration issue, relying on differing, relaxed conformance, configurations on two MTAs, rather than an inherent flaw in SMTP itself. RFC 5321 explicitly forbids the transition of a single `<cr>` or `<lf>` character:

> In addition, the appearance of "bare" "CR" or "LF" characters in text (i.e., either without the other) has a long history of causing problems in mail implementations and applications that use the mail system as a tool. SMTP client implementations MUST NOT transmit these characters except when they are intended as line terminators and then MUST, as indicated above, transmit them only as a \<CRLF\> sequence.

## Defending against SMTP Smuggling in KumoMTA

KumoMTA allows you to choose how to handle this kind of input:

1. 1\) You can ignore it and allow it to relay (not recommended)
2. 2\) You can check and reject it (recommended)
3. 3\) You can accept and fix the non-conforming line endings to `<cr><lf>`. If you are interfacing with a legacy system, this might be the option for you.

 Here's an example that shows how to check and reject this kind of message:

`-- Processing of incoming messages via SMTP`

`kumo.on('smtp_server_message_received', function(msg)`

`  -- Protect against SMTP Smuggling (https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/)`

`  local failed = msg:check_fix_conformance(`

`    -- check for and reject messages with these issues:`

`    'NON_CANONICAL_LINE_ENDINGS',`

`    -- fix messages with these issues:`

`    ''`

`  )`

`  if failed then`

`    kumo.reject(552, string.format('5.6.0 %s', failed))`

`  end`

`  -- Call the queue helper to set up the queue for the message.`

`  queue_helper:apply(msg)`

`  -- SIGNING MUST COME LAST OR YOU COULD BREAK YOUR DKIM SIGNATURES`

`  dkim_signer(msg)`

`end)`

To help protect all our users, we have added this check to the [example configuration](https://docs.kumomta.com/userguide/configuration/example/) that we encourage all users to use as their starting point for their installations. For those that would prefer to fix line endings rather than reject the messages, they can move the `NON_CANONICAL_LINE_ENDINGS` element from the first argument in `check_fix_conformance` to the second (from "check" to "fix").

STAY IN TOUCH

## Get periodic updates about the latest releases, features, and news around KumoMTA.

[![KUMO\_Logo\_Files\_Color 1](https://kumomta.com/hubfs/KUMO_Logo_Files_Color%201.svg "KUMO_Logo_Files_Color 1")](https://kumomta.com)

##### Proud member of

![maawg 1](https://kumomta.com/hubfs/maawg%201.png "maawg 1")

[Follow us on LinkedIn](https://www.linkedin.com/company/91414337/) [Follow us on Github](https://github.com/KumoCorp/kumomta) [Follow us on Discord](https://discord.com/servers/kumomta-1072980126737907824) [Follow us on Youtube](https://www.youtube.com/channel/UC348UpfbnPgpKPAXIBW_JNQ)

##### Explore KumoMTA

- [Open Source](https://kumomta.com/technology/open-source)
- [Features](https://kumomta.com/technology)
- [Pricing](https://kumomta.com/pricing)
- [Case Studies](https://kumomta.com/customers)
- [About Us](https://kumomta.com/about)
- [Privacy](https://kumomta.com/privacy)

##### Resources

- [Blog](https://kumomta.com/blog)
- [Documentation](https://docs.kumomta.com/)
- [Community Forum](https://community.kumomta.com/?_gl=1*o6wdcs*_gcl_au*MTAxMDA2MjM0NC4xNzcyNzI4Njg3*_ga*MTQ0NjAzODcyNS4xNzU3MDkzMjQ2*_ga_LNBCW1KF8J*czE3Nzc5MzU3ODYkbzIkZzAkdDE3Nzc5MzYwMjMkajI3JGwwJGgw)
- [FAQ](https://docs.kumomta.com/faq/)
- [YouTube Channel](https://www.youtube.com/channel/UC348UpfbnPgpKPAXIBW_JNQ)
- [GitHub Repository](https://github.com/KumoCorp/kumomta?_gl=1*12d5gs8*_gcl_au*MTAxMDA2MjM0NC4xNzcyNzI4Njg3*_ga*MTQ0NjAzODcyNS4xNzU3MDkzMjQ2*_ga_LNBCW1KF8J*czE3Nzc5MzU3ODYkbzIkZzAkdDE3Nzc5MzU3ODkkajU3JGwwJGgw)

- [© 2026 Kumo Corp, All rights reserved. KumoMTA and the Kumo logo are registered trademarks of Kumo Corp. ](https://kumomta.com/privacy)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mike Hillyer",
    "url" : "https://kumomta.com/blog/author/mike-hillyer"
  },
  "dateModified" : "2023-12-20T18:08:50.372Z",
  "datePublished" : "2023-12-20T18:08:50.000Z",
  "headline" : "Defending Against SMTP Smuggling with KumoMTA",
  "image" : [ "https://kumomta.com/hubfs/Email%20Smuggler.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://kumomta.com/blog/defending-against-smtp-smuggling-with-kumomta",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://kumomta.com/hubfs/KUMO_Logo_NEW_Color.png"
    },
    "name" : "KumoMTA"
  }
}
```