---
title: "Synology MailPlus SMTP Relay: Fixing Rejected Mail With Resend"
description: An SMTP relay is a second mail server that sends your messages on your behalf, so the receiving side judges its reputation instead of yours. On 9 October 2026 we needed one in a hurry. SynoPower Club runs entirely on…
url: "https://synopower.club/nb/docs/synology-mailplus-smtp-relay-resend/"
updated: "2026-10-11"
category: NAS Hosting 101
---

# Synology MailPlus SMTP Relay: Fixing Rejected Mail With Resend

An SMTP relay is a second mail server that sends your messages on your behalf, so the receiving side judges its reputation instead of yours. On 9 October 2026 we needed one in a hurry. SynoPower Club runs entirely on Synology, and every order confirmation and license key leaves through Synology MailPlus. That evening a customer in Belgium paid for a license, and the email carrying the key came straight back with `552 5.2.0 Your message is considered spam`. SPF, DKIM and DMARC were all passing. This NAS Hosting 101 article shows how we added Resend as an SMTP relay for only the recipient domains that reject us, which records it needs, how we tested it, and what the service quietly changes in your messages.

> **SynoPower Club Point:** I spent years on the support side of Synology, and deliverability was the reason most people gave up on running their own mail. They assumed the fix was to move every mailbox to a hosted suite. It rarely is. In our case the mail server was healthy, the DNS was correct, and exactly one hop on the way out had a poor name with a few strict providers. Synology MailPlus lets you change that one hop for those providers only, with a rule that took us ten minutes to create. The mailboxes, the logs and the customer data never left our own NAS.

## Why Correctly Signed Mail From a NAS Still Gets Rejected

Authentication proves who you are. It does not prove you are welcome. SPF, DKIM and DMARC tell the receiving server that a message really comes from your domain, and after that the server asks a second question: what has it seen before from the IP address that is handing the message over?

A self-hosted mail server usually loses that second question in one of two ways. If it sends directly, the public IP often carries a generic reverse DNS name from the internet provider, which many receivers treat as a home connection. If it sends through the provider's own outgoing server instead, as ours did, the message inherits the reputation of a machine shared with thousands of other customers.

![Bounce message from a Belgian mailbox provider rejecting a signed order email as spam before the SMTP relay change](https://synopower.club/wp-content/uploads/2026/10/telenet-bounce-message-considered-spam.webp)
The bounce as it reached our support mailbox on 9 October, with the customer address and our server address hidden. The refusal came from the provider's own mail server during delivery.

That was our situation. The bounce did not complain about our domain or our signature. It was a verdict on the path, and large European mailbox providers such as Telenet and GMX are known for strict filtering on exactly that signal. Nothing inside the mail server could change it, because the problem sat one hop after the NAS.

## What an SMTP Relay Changes, and What It Does Not

An SMTP relay replaces that last hop. Your server authenticates to it on port 587, hands over the message, and the SMTP relay delivers it from its own IP addresses with its own sending history. Transactional email services exist for precisely this job: their addresses send nothing but receipts, password resets and notifications, so receivers trust them more than a general-purpose outgoing server.

A good SMTP relay also signs the message with a DKIM key for your domain, so the customer still sees your address and DMARC still passes. What it cannot do is repair bad content, a missing SPF record or a list of people who never asked for your mail. Fix authentication first, then look at the path.

## Why We Chose Resend as the SMTP Relay

Our first attempt was Amazon SES. We verified the domain, described our volume as 20 to 50 transactional emails a day, and were declined for production access the next day without a stated reason. That is a common experience for a brand new account, and it left a store with license keys waiting to be delivered.

![Amazon SES email declining production access for a new account, with no reason given](https://synopower.club/wp-content/uploads/2026/10/amazon-ses-production-access-declined.webp)
The opening of the reply from Amazon Web Services. The rest of the message explains that the review considers factors it cannot share, so there was nothing specific to fix.

Resend was the second attempt, and it was sending signed mail for our domain about ten minutes after sign-up. Three things made it a good fit for a small Synology-hosted shop:

- **It speaks plain SMTP.** No plugin or API integration is needed, so a mail server on a NAS can use it as an SMTP relay without any extra software.
- **The free plan covers a small store.** In October 2026 it allows 3,000 emails a month, 100 a day and 3 domains, which is far above our order volume.
- **Domain verification is automatic with Cloudflare.** One authorisation screen created every DNS record for us.
- **Every message is listed in a dashboard.** You can see whether the receiving server accepted or bounced each one.

![Resend pricing page showing the free plan with 3,000 emails a month for an SMTP relay](https://synopower.club/wp-content/uploads/2026/10/resend-pricing-free-plan.webp)
Resend pricing as we saw it in October 2026. The free plan is enough when only a few recipient domains go through it.

One detail made us smile. The headers of our first test showed the message leaving through Amazon SES infrastructure in Tokyo. Resend is built on the very platform that had turned our own application down, with the sender reputation and the approval already taken care of.

## Relay Everything, or Only the Domains That Reject You?

Most guides tell you to send all outgoing mail through the new SMTP relay. We did not, and Synology MailPlus is the reason we did not have to. Its SMTP relay settings accept exception rules, and each rule carries its own server, port and credentials. Mail for the domains listed in a rule takes that route, and everything else keeps using the default route.

Splitting the traffic this way has real advantages for a business mail server:

- **Ordinary correspondence stays untouched.** Replies, threads and messages with several recipients keep their original headers.
- **Less of your mail passes through a third party.** Only messages for the listed domains leave your own infrastructure early.
- **You stay inside the free allowance.** A hundred emails a day is plenty for a handful of domains and not much for a whole company.
- **Rolling back is one checkbox.** Disable the rule and those domains return to the default route.

We started with two domains, the one that bounced and one more with a similar reputation for strictness, and further European providers will follow as real orders confirm the result.

## Setting Up a MailPlus SMTP Relay With Resend in 4 Steps

The whole SMTP relay setup happens in two browser tabs: the Resend dashboard and the MailPlus Server console in DSM. Take a snapshot or export the mail server configuration first if this is a production system.

### Add your domain in Resend and publish the DNS records

Create a Resend account, open Domains and add the domain you send from. Pick the region at this step. Resend then shows a DKIM record and two records for the bounce subdomain. With Cloudflare DNS, the Auto configure button creates them after one authorisation screen. With any other DNS host, copy the records by hand. Leave your existing SPF, DKIM and DMARC records as they are.

### Wait for Verified, then create a sending-only API key

Verification took a few minutes for us. Once the domain status shows Verified, open API keys and create a key with the Sending access permission, limited to that domain if you like. Copy it immediately, because the full key is displayed only once. This key is the password for the SMTP relay.

### Create a recipient rule in MailPlus Server

In MailPlus Server open Mail Delivery, then Relay Settings, then Exception Rules, and create a rule on the Recipient Rule tab. Enter smtp.resend.com as the server and 587 as the port, tick the secure connection and authentication boxes, type resend as the account and paste the API key as the password. Add each recipient domain to the list, then confirm and apply.

### Send a test and read the result on both sides

Send a message to a mailbox on one of the listed domains. In MailPlus Server the Queue page should be empty a few seconds later. In Resend the Emails page should list the message as Delivered. Finally open the message at the receiving end and check that SPF, DKIM and DMARC all show pass for your own domain.

![Resend domain page listing the DKIM and SPF DNS records created through Cloudflare](https://synopower.club/wp-content/uploads/2026/10/resend-domain-dns-records-cloudflare.webp)
Step 1: the records Resend asked for, a DKIM key and two CNAME records, minutes after Cloudflare created them. The status changed to Verified shortly afterwards.

![Resend API key with Sending access permission, used as the SMTP relay password](https://synopower.club/wp-content/uploads/2026/10/resend-api-key-sending-access.webp)
Step 2: a key that can only send. The token is hidden here, and the Last used column is a handy check later.

![Synology MailPlus Server exception rule sending two recipient domains through the Resend SMTP relay](https://synopower.club/wp-content/uploads/2026/10/mailplus-smtp-relay-recipient-rule-resend.webp)
Step 3: the recipient rule in MailPlus Server. Our older rule for the provider's server sits above it, disabled, and the password field is blanked for this screenshot.

The DNS side deserves one extra sentence. Resend signs with its own DKIM selector and uses its own subdomain for bounces, so nothing it adds collides with the records your mail server already relies on. Both routes stay fully authenticated at the same time, which is what makes a split setup safe.

## How to Confirm the SMTP Relay Is Really in Use

Our first save of the rule was wrong, and nothing on screen said so. The browser's password manager had filled the Password field with the DSM login password while we were typing the other fields, and the form accepted it happily. A message for those domains would have sat in the queue with an authentication error.

Three checks tell you whether the SMTP relay is working before a customer does:

- **Paste the key last, and look at its length.** A Resend key starts with `re_` and is 36 characters long. A short row of dots means the browser filled in something else.
- **Watch the queue.** After a test message, the Queue page in MailPlus Server should be empty. A deferred message there shows the reason the SMTP relay gave.
- **Watch the key.** The Last used column on the Resend API keys page says No activity until the first message authenticates successfully.

We also tested the SMTP relay directly before touching the mail server, by sending messages to one of our own mailboxes over SMTP. They arrived with SPF, DKIM and DMARC passing for our domain, and a non-English subject, an HTML body with a plain text part, a PDF attachment and a custom header all came through intact, so the SMTP relay does not damage ordinary message content. That matters for a store whose order emails go out in 16 languages.

Then came the test that mattered. On 11 October we sent the Belgian customer's order email again, the same message that had bounced two days earlier. The mail log showed MailPlus Server handing it over 3.2 seconds after it entered the queue, and the dashboard marked it Delivered, which means the provider's server accepted the message instead of refusing it.

![Resend dashboard showing the order email delivered through the SMTP relay to the provider that had rejected it](https://synopower.club/wp-content/uploads/2026/10/resend-email-delivered-telenet.webp)
The same order email that was refused on 9 October, accepted on 11 October. The customer address is replaced for this screenshot.

One message is a result, not a statistic. Delivered tells you the receiving server said yes, and it cannot tell you which folder the message was filed in. We will keep watching real orders to these providers before we move more domains across.

## What Resend Rewrites in Your Messages

An SMTP relay that rebuilds messages is not a transparent pipe, and the differences are worth knowing before you route anything important through it. Comparing what we sent with what arrived showed four changes:

- **The To header becomes the single recipient.** Each recipient gets a copy addressed only to them, so the original list of recipients is no longer visible.
- **The Message-ID is replaced.** Mail clients use that value to group replies, so threads can split.
- **The Date header is converted to UTC.** The moment is the same, the displayed time zone is not.
- **The Received lines from your own server are removed.** The recipient no longer sees the internal path.

None of this matters for an order confirmation sent to one customer. It matters a great deal for a conversation with three people in copy, and it is the strongest argument for giving the SMTP relay only selected domains instead of everything.

## Why Our Mail Still Lives on Synology MailPlus

Adding an outside SMTP relay for two domains does not change where our mail lives. Every mailbox, every sent message and every delivery log is still on our own NAS, and [Synology MailPlus](https://synopower.club/synology-mailplus-license-pack-5-users/) still decides, message by message, which route to take. A hosted mail suite would not have given us that choice. We would have had one outgoing path, the vendor's, and no rule to steer around a problem.

It is also why the fix cost nothing. The server includes five email accounts for free, the licenses for more are bought once instead of rented monthly, and the SMTP relay rules are part of the package. If you are weighing up running your own mail, the full picture is in our guide: [Synology MailPlus mail server guide](https://synopower.club/synology-mailplus-mail-server-guide/).

  [Get a MailPlus license](https://synopower.club/synology-mailplus-license-pack-5-users/)

## SMTP Relay Limits and Caveats

An SMTP relay solves one specific problem, and it brings a few of its own.

The messages you route through it are processed by a third party. Ours contain license keys, so we keep the list of domains short and use a key that can send and do nothing else. Check your own privacy commitments before sending customer mail through any outside service, particularly for customers in the European Union.

The free plan has a daily ceiling. A hundred emails a day is generous for selected domains, but a mailing to your whole customer list would hit it within minutes. Newsletters belong on a separate plan, and ideally on a separate subdomain, so that marketing complaints never touch the reputation of your order emails.

Reputation is borrowed, not owned. Shared sending addresses are well kept, but you do not control who else uses them. If a provider still rejects you after the change, read the bounce text in the dashboard before assuming the path is at fault.

Finally, an API key that has been pasted into a chat, a ticket or a screenshot should be replaced. Create a new key, update the SMTP relay rule, send a test and delete the old one. It takes two minutes and removes a risk that otherwise lasts for years.

## Frequently Asked Questions

### What is an SMTP relay?

An SMTP relay is a mail server that accepts messages from your own server and delivers them for you. The receiving side then judges the reputation of the relay instead of the address your server sends from.

### Why does mail from my Synology NAS land in spam when SPF, DKIM and DMARC pass?

Those three checks prove the message is really from your domain. Receivers also score the IP address that delivers it. A generic reverse DNS name or a shared outgoing server with a mixed history can fail that second test on its own.

### Does Synology MailPlus support an SMTP relay for specific domains only?

Yes. Under Mail Delivery, Relay Settings, Exception Rules you can create recipient rules, each one a separate SMTP relay. Each rule has its own server, port and credentials, and applies only to the domains or addresses in its list.

### Is Resend free to use as an SMTP relay?

The free plan allowed 3,000 emails a month, 100 a day and 3 domains when we signed up in October 2026. That is enough for the transactional mail of a small store, especially when only some domains use it.

### Which SMTP relay server, port and login does Resend use?

The server is smtp.resend.com. Port 587 with STARTTLS works with MailPlus Server, and 465 is available for implicit TLS. The account name is always resend and the password is your API key.

### Do I have to change my existing SPF or DKIM records?

No. Resend adds a DKIM key under its own selector and uses its own subdomain for bounces. The records your mail server already uses stay in place, so the default route and the SMTP relay both remain authenticated.

### Will customers still see my own address as the sender?

Yes. The From address is unchanged and the message is signed for your domain, so DMARC passes. In our tests the visible changes were limited to the To, Message-ID, Date and Received headers.

### Can I choose the SMTP relay by sender instead of by recipient?

MailPlus Server also has a Sender Rule tab next to Recipient Rule, for routing by the sending address. When both kinds of rule match the same message, the console states that the recipient rule takes priority.

## References and Video Walkthroughs

- [Resend SMTP documentation](https://resend.com/docs/send-with-smtp), listing the server name, the available ports and the login format.
- [Resend pricing](https://resend.com/pricing), for the current allowances of the free and paid plans.
- [Synology MailPlus Server Mail Delivery help](https://kb.synology.com/en-global/DSM/help/MailPlus-Server/mailplus_server_delivery), the official description of the delivery and relay settings.
- [Google email sender guidelines](https://support.google.com/a/answer/81126), the authentication and reputation rules Gmail applies to incoming mail.
- [DMARC overview](https://dmarc.org/overview/), explaining how SPF and DKIM alignment decide whether a message passes.

These Synology videos cover the mail server this article is built on, from first installation to the security settings.

[How to Set Up Your Synology MailPlus Server](https://www.youtube.com/embed/tBLjJWn-WBk?feature=oembed)

How to Set Up Your Synology MailPlus Server

[How to Configure Synology MailPlus Server to Protect Your Mail Service](https://www.youtube.com/embed/I_ap-K0Y9jg?feature=oembed)

How to Configure Synology MailPlus Server to Protect Your Mail Service

[Introducing Synology MailPlus | Synology](https://www.youtube.com/embed/3XGTSb3D3TA?feature=oembed)

Introducing Synology MailPlus

More from this series on hosting a business on a NAS: [Email bombing through a contact form](/docs/email-bombing-contact-form-synology-nas/). Planning your own mail server? Start with [a MailPlus license pack](https://synopower.club/synology-mailplus-license-pack-5-users/), or browse all licenses on [SynoPower Club](https://synopower.club/).
