FTP (File Transfer Protocol) and SMTP (Simple Mail Transfer Protocol) are two application-layer protocols handling different types of network data transfer. FTP uploads and downloads files between a client and a server, while SMTP sends email messages between mail servers — handling the outbound journey from your device to the recipient's inbox.

What is FTP and when is it used?

FTP (File Transfer Protocol) was designed to transfer files reliably between a client computer and a server. When a web developer uploads HTML, CSS, and image files to a web hosting server, they typically use FTP or a modern secure variant. When a media organisation downloads large video files from a remote archive, FTP provides a standardised, reliable mechanism.

FTP uses two separate TCP connections:

  • Control connection (port 21) — carries commands (login credentials, directory navigation, transfer requests) and server responses throughout the session.
  • Data connection (port 20 in active mode) — carries the actual file data, opened when a transfer begins and closed when it ends.

FTP has two operating modes:

Mode Who opens the data connection Typical use
Active Server connects back to the client Older servers; may be blocked by firewalls
Passive Client connects to the server Works through NAT and firewalls; most common today

Security note: Standard FTP transmits usernames, passwords, and file contents in plain text — anyone monitoring the network can read them. For secure file transfer, modern alternatives are used:

  • SFTP (SSH File Transfer Protocol) — tunnels file transfer through an encrypted SSH session.
  • FTPS (FTP Secure) — adds TLS encryption to standard FTP.

What is SMTP and how does it work?

SMTP (Simple Mail Transfer Protocol) handles the sending of email. When you press Send in a mail client, your device connects to an SMTP server (your email provider's outbound mail server) and hands over the message. The SMTP server then relays the message to the recipient's mail server, which stores it until the recipient retrieves it.

Typical SMTP ports:

Port Use Security
25 Server-to-server relay Not encrypted (legacy)
587 Client-to-server submission STARTTLS (upgrades to TLS)
465 Client-to-server submission Implicit TLS (always encrypted)

Port 25 is blocked by most ISPs for end-user connections to prevent spam; mail clients use 587 or 465. Server-to-server relay still uses 25.

How does an email journey work end to end?

  1. Compose and send: You write an email in your mail client (e.g., Outlook) and press Send. Your client connects to your provider's SMTP server (e.g., smtp.gmail.com:587) using your credentials.
  2. Outbound relay: Your SMTP server looks up the recipient's domain using a DNS MX (Mail Exchange) record to find the recipient's mail server address.
  3. Delivery: Your SMTP server connects to the recipient's SMTP server (still port 25) and delivers the message.
  4. Storage: The recipient's mail server stores the message until the recipient's client retrieves it.
  5. Retrieval: The recipient's mail client collects the message using IMAP or POP3.

What is the difference between IMAP and POP3?

SMTP handles outbound mail. Incoming mail is retrieved using one of two different protocols:

Feature IMAP (port 143 / 993 TLS) POP3 (port 110 / 995 TLS)
Where messages are stored On the server Downloaded to client
Multiple devices Synchronised — all devices see the same inbox Each device downloads its own copy
Deleting a message Deletes on server (all devices see the change) Typically deletes from server after download
Offline access Requires synchronisation first Full access after download
Best for Multiple devices; modern use Single device; limited server storage

Most modern email clients use IMAP so that your inbox looks identical on your phone, laptop, and web browser.

How do these protocols fit into the TCP/IP model?

Layer Protocol Role
Application FTP, SMTP, IMAP, POP3, HTTP Defines the rules for specific services
Transport TCP Reliable, ordered delivery; error checking
Internet IP Addressing and routing between networks
Link Ethernet, Wi-Fi Physical transmission on local network

FTP, SMTP, IMAP, and POP3 all sit at the application layer and rely on TCP at the transport layer for reliable delivery. TCP's acknowledgement and retransmission mechanism ensures file transfers and email messages arrive complete and in order.

Frequently asked questions

Do I need to know port numbers for GCSE exams?

AQA and OCR GCSE Computer Science expect you to know that different protocols use different port numbers and why this matters (ports allow the operating system to direct incoming packets to the correct application). Specific port numbers — 25/587 for SMTP, 20/21 for FTP, 80 for HTTP, 443 for HTTPS, 143/993 for IMAP — appear in some exam mark schemes, particularly at the higher tiers. Learning the most common ones is good preparation.

Why is standard FTP considered insecure?

FTP transmits everything — including your username, password, and file contents — as plain text. A packet sniffer on the same network (or at any point between client and server) can read this data directly. SFTP and FTPS add encryption to prevent eavesdropping. For any situation involving sensitive data or login credentials, SFTP or FTPS should always be used instead of plain FTP.

What is a DNS MX record and why does SMTP need it?

A Mail Exchange (MX) record is a DNS record that specifies which server is responsible for accepting email for a given domain. When an SMTP server needs to deliver an email to example.com, it queries DNS for the MX record of example.com to find the address of example.com's mail server. Without MX records, SMTP servers would have no way to find each other, and email routing would fail.

Why do email spam filters exist and what do they do?

Because SMTP was designed for simplicity and trust, it was easily abused for spam and phishing as email use grew. Spam filters use techniques including sender reputation databases (blacklists), SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) records to verify that a sending server is authorised by the domain it claims to represent, and machine learning classifiers to detect suspicious content. Without these layers, essentially all email would be flooded with spam.


Master networking protocols and computer systems with Professor Turing at aitutors.me.