
A high-speed covert tunnel that disguises TCP traffic as SMTP email communication to bypass Deep Packet Inspection (DPI) firewalls.
A high-speed covert tunnel that disguises TCP traffic as SMTP email communication to bypass Deep Packet Inspection (DPI) firewalls.
┌─────────────┐ ┌─────────────┐ ┌─────────────┐ ┌──────────────┐
│ Application │─────▶│ Client │─────▶│ Server │─────▶│ Internet │
│ (Browser) │ TCP │ SOCKS5:1080 │ SMTP │ Port 587 │ TCP │ │
│ │◀─────│ │◀─────│ │◀─────│ │
└─────────────┘ └─────────────┘ └─────────────┘ └──────────────┘
│ │
│ Looks like │
│ Email Traffic │
▼ ▼
┌────────────────────────────────┐
│ DPI Firewall │
│ ✅ Sees: Normal SMTP Session │
│ ❌ Cannot see: Tunnel Data │
└────────────────────────────────┘
| Feature | Description |
|---|---|
| 🔒 TLS Encryption | All traffic encrypted with TLS 1.2+ after STARTTLS |
| 🎭 DPI Evasion | Initial handshake mimics real SMTP servers (Postfix) |
| ⚡ High Speed | Binary streaming protocol after handshake - minimal overhead |
| 👥 Multi-User | Per-user secrets, IP whitelists, and logging settings |
| 🔑 Authentication | Per-user pre-shared keys with HMAC-SHA256 |
| 🌐 SOCKS5 Proxy | Standard proxy interface - works with any application |
| 📡 Multiplexing | Multiple connections over single tunnel |
| 🛡️ IP Whitelist | Per-user access control by IP address/CIDR |
| 📦 Easy Install | One-liner server installation with systemd service |
| 🎁 Client Packages | Auto-generated ZIP files for each user |
| 🔄 Auto-Reconnect | Client automatically reconnects on connection loss |
📚 For in-depth technical details, protocol specifications, and security analysis, see TECHNICAL.md.
Get a free domain pointing to your VPS:
Example: myserver.duckdns.org → 203.0.113.50 (your VPS IP)
curl -sSL https://raw.githubusercontent.com/x011/smtp-tunnel-proxy/main/install.sh | sudo bash
The installer will:
That's it! Your server is ready.
smtp-tunnel-adduser bob # Add user + generate client ZIP
smtp-tunnel-listusers # List all users
smtp-tunnel-deluser bob # Remove a user
smtp-tunnel-update # Updates code, preserves config/certs/users
username.zip file from the server admin| Platform | How to Run |
|---|---|
| 🪟 Windows | Double-click start.bat |
| 🐧 Linux | Run ./start.sh |
| 🍎 macOS | Run ./start.sh |
The launcher will automatically install dependencies and start the client.
✅ You should see:
SMTP Tunnel Proxy Client
User: alice
[INFO] Starting SMTP Tunnel...
[INFO] SOCKS5 proxy will be available at 127.0.0.1:1080
Connecting to myserver.duckdns.org:587
Connected - binary mode active
SOCKS5 proxy on 127.0.0.1:1080
cd alice
pip install -r requirements.txt
python client.py
# Download files
scp [email protected]:/etc/smtp-tunnel/ca.crt .
# Create config.yaml:
cat > config.yaml << EOF
client:
server_host: "myserver.duckdns.org"
server_port: 587
socks_port: 1080
username: "alice"
secret: "your-secret-from-admin"
ca_cert: "ca.crt"
EOF
# Run client
python client.py -c config.yaml
Set SOCKS5 proxy to: 127.0.0.1:1080
127.0.0.1, Port: 1080127.0.0.1:1080Settings → Network & Internet → Proxy → Manual setup → socks=127.0.0.1:1080
System Preferences → Network → Advanced → Proxies → SOCKS Proxy → 127.0.0.1:1080
export ALL_PROXY=socks5://127.0.0.1:1080
# curl
curl -x socks5h://127.0.0.1:1080 https://ifconfig.me
# git
git config --global http.proxy socks5://127.0.0.1:1080
# Environment variable
export ALL_PROXY=socks5://127.0.0.1:1080
# Should show your VPS IP
curl -x socks5://127.0.0.1:1080 https://ifconfig.me
config.yaml)| Option | Description | Default |
|---|---|---|
host | Listen interface | 0.0.0.0 |
port | Listen port | 587 |
hostname | SMTP hostname (must match certificate) | mail.example.com |
cert_file | TLS certificate path | server.crt |
key_file | TLS private key path | server.key |
users_file | Path to users configuration | users.yaml |
log_users | Global logging setting | true |
users.yaml)Each user can have individual settings:
users:
alice:
secret: "auto-generated-secret"
# whitelist: # Optional: restrict to specific IPs
# - "192.168.1.100"
# - "10.0.0.0/8" # CIDR notation supported
# logging: true # Optional: disable to stop logging this user
bob:
secret: "another-secret"
whitelist:
- "203.0.113.50" # Bob can only connect from this IP
logging: false # Don't log Bob's activity
| Option | Description | Default |
|---|---|---|
secret | User's authentication secret | Required |
whitelist | Allowed IPs for this user (CIDR supported) | All IPs |
logging | Enable activity logging for this user | true |
| Option | Description | Default |
|---|---|---|
server_host | Server domain name | Required |
server_port | Server port | 587 |
socks_port | Local SOCKS5 port | 1080 |
socks_host | Local SOCKS5 interface | 127.0.0.1 |
username | Your username | Required |
secret | Your authentication secret | Required |
ca_cert | CA certificate for verification | Recommended |
# Check status
sudo systemctl status smtp-tunnel
# Restart after config changes
sudo systemctl restart smtp-tunnel
# View logs
sudo journalctl -u smtp-tunnel -n 100
# Uninstall
sudo /opt/smtp-tunnel/uninstall.sh
python server.py [-c CONFIG] [-d]
-c, --config Config file (default: config.yaml)
-d, --debug Enable debug logging