Resolving P3000 EMAL Email Failures on Authenticated SMTP

Brian Holt8 min read
AutomationDirectIndustrial NetworkingTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

The alarm bit fires and the EMAL instruction executes, but nothing reaches the inbox. On a Productivity3000 (P3000), the usual cause is that the instruction does not support SMTP authentication or SSL/TLS. Nearly every mail server now refuses unauthenticated submission to block spam, so the controller is turned away before the message is accepted. Get it running, then fix it properly. The checks below take you from the reading that confirms the cause to a working mail path.

Skip the Quick Fixes That Don't Work

These get tried first and waste the shift:

  • Pointing EMAL at a public provider's submission server. Those servers require a login and usually TLS. With no credential fields, the P3000 is rejected at the handshake.
  • Retyping the server address, port, or recipient. If the server demands AUTH, no address or port change makes an unauthenticated client acceptable.
  • Reflashing and hoping. SMTP authentication for EMAL was a long-standing open request across the P-Series line. Read the release notes before assuming a firmware update fixes it (Check 2).
  • Buying a gateway before asking IT. A corporate mail server can often accept anonymous relay from one fixed internal IP address. That costs nothing and needs no new hardware.

Check 1: Find Out What the Mail Server Demands

Take this reading from a PC on the same subnet as the P3000, and use the same server address and port the PLC is configured with.

  1. Open a raw session: telnet <server-ip> 25 (or the port set in the PLC).
  2. Send EHLO test and read the capability list the server returns.
  3. Send MAIL FROM:<alarm@yourdomain>, then RCPT TO:<someone@external-domain>, and read the reply.
What you see What it means Next check
Connection times out or is refused Port blocked by a firewall, the ISP, or the server. This is a network problem, not an authentication problem. Fix the network path first, then repeat Check 1
EHLO lists AUTH; RCPT is rejected as relay denied or authentication required The server needs credentials the P3000 cannot send Check 2
EHLO lists STARTTLS and the server insists on it before accepting mail Encryption is required. EMAL lacks SSL/TLS support Check 2
RCPT accepted with no AUTH The server accepts anonymous mail from this subnet The fault is in the PLC setup (server IP, From address, gateway). Verify those, then go to the verification section

Stop here if the PC test succeeds but the PLC still fails. That points at the controller's IP settings, gateway, or EMAL parameters, not at authentication.

Check 2: Read the EMAL Capability on the Installed Firmware

Open the EMAL instruction help in the installed version of ProductivitySuite. Compare it with the current firmware release notes for your CPU.

  • If the instruction now has username, password, and encryption fields: update the CPU firmware to that release, enter the credentials, and go to verification. Back up the project first and test on a non-production CPU if you have one. Firmware updates on this family have been known to change communication behavior.
  • If there are no credential or TLS fields: the controller cannot talk to that server directly. Go to Check 3.

Register for AutomationDirect's software and firmware update notifications. You will then learn when an EMAL update ships instead of polling the release notes.

Check 3: Match the Workaround to What Is on Site

Every working fix follows one pattern. Put something between the P3000 and the mail server that the controller can reach without credentials, and let that device handle authentication and TLS upstream.

What you have Path Cost / dependency Failure point to watch
Corporate mail server, cooperative IT Anonymous relay connector restricted to the PLC's fixed IP None; one IT change PLC IP changes; connector removed during server upgrades
Always-on Windows PC or server on the controls network Local SMTP relay software Relay software plus a mailbox credential PC off, rebooted, or asleep when the alarm fires
Ethernet C-more panel already installed Panel sends the email, triggered by a PLC tag None if the panel exists Panel offline; tag mapping drift after edits
Outbound internet allowed, no on-site server Hosted SMTP relay service Subscription, metered per message Account lapses; From address not registered
Controller replacement is on the table Do-more CPU with native authenticated email Hardware plus program conversion Conversion effort and revalidation

Work down the table in order. The first row that fits your site is usually the cheapest fix that holds.

Branch: Let a Panel or Different Controller Send

Ethernet C-more panel. The C-more supports SMTP authentication even though the P3000 does not. Configure the panel's email settings with the server, credentials, and encryption. Then drive the send from an alarm tag the P3000 already writes, so the PLC logic stays the same. The drawback is that alarm email now depends on the panel being powered and connected. If the only purpose is email, a new Ethernet panel costs more than a relay PC you already own.

Do-more CPU. Do-more controllers send email to servers that require authentication. One older limitation involved providers that used POP-before-SMTP login and put the POP and SMTP services on different IP addresses. That case was fixed as of Do-more v1.4, so run v1.4 or later if your provider works that way. Only choose this path if the controller is already due for replacement. It is not worth a conversion just for email.

Branch: Hosted Relay Service or Mail API

Hosted SMTP relay. Commercial relay services such as AuthSMTP exist for devices that cannot meet modern authentication requirements. Field rules from running one:

  • Populate the From address in EMAL with the sender registered on the account. The service rejects mail without it.
  • Each CC or duplicate recipient counts as a separate message against the monthly quota. Size the plan for the worst alarm storm multiplied by the recipient count.
  • Service timestamps may be in UTC. Put local time from the PLC clock in the subject or body so the night shift reads correct times.
  • Confirm with the provider how it authorizes a sender that cannot present credentials, for example by registered sender, static source IP, or both. Also confirm which unencrypted port it accepts. That answer decides whether the P3000 can use it directly.

HTTP mail API. Services such as Mailgun accept a message as an HTTPS POST with an API key. That removes SMTP from the picture, but the P3000 still has to issue the request. Check the P3000 instruction set for anything that sends an HTTP request. If there is nothing, this route needs an intermediate device that reads PLC tags (for example over Modbus) and makes the POST itself. Free tiers limit message counts, so treat them as test accounts, not production alarm paths.

Build the Local SMTP Relay (Resolving Branch)

This is the most common fix when an always-on PC exists on the controls network.

  1. Give the P3000 a static IP address. The relay's allow-list depends on it.
  2. Install SMTP relay software on the always-on Windows machine. Set it to listen on port 25 on the controls-network interface only.
  3. Restrict inbound relay to the P3000's IP address. Never leave an open relay on the network.
  4. Configure the upstream smart host: your real mail server's address, the submission port it requires, the mailbox username and password, and TLS as required. Use the results of Check 1 to pick these.
  5. Disable sleep, hibernation, and unattended update reboots on that machine. Set the relay service to start automatically.
  6. In the EMAL setup, enter the relay PC's IP address as the mail server. An IP address avoids a DNS dependency on the PLC. Use a From address that the upstream mailbox is allowed to send as.
  7. From another PC, repeat the Check 1 telnet session against the relay. It should now accept an external recipient without AUTH.
  8. Download the project and trigger EMAL from a spare test bit, not from a live alarm.

Verify Delivery and Monitor the Path

  1. In the relay log, confirm an inbound connection from the P3000's IP address and a successful upstream hand-off.
  2. Confirm the message arrives. Open the headers and check that the relay sent it through the authenticated mailbox, not through a fallback route.
  3. Check the EMAL status or error outputs in Data View. Latch the failure indication into an alarm on the HMI so a failed send is visible locally.
  4. Test each recipient, including CC addresses. A spam filter can quarantine one address while delivering to the others.
  5. Add a daily heartbeat email from the PLC. If it stops arriving, the mail path is broken before a real alarm needs it.
  6. Power-cycle the relay PC once and confirm that email works again without anyone logging in.

A relay adds a single point of failure. If the relay machine is down when an alarm fires, that email is lost. Keep local annunciation (horn, stack light, HMI alarm) as the primary alarm path, with email as the secondary.

FAQ

What happens if the SMTP server requires authentication and the P3000 EMAL instruction has no login fields?

The server rejects the message during the SMTP exchange and nothing is delivered. Route the mail through a device that can authenticate, such as a local relay, an Ethernet C-more panel, or a hosted relay service.

What happens if the relay PC is off when an alarm fires?

The P3000 cannot hand off the message, so that alarm email is lost. Watch the EMAL error status, send a daily heartbeat email, and keep a local horn or HMI alarm as the primary alarm path.

What happens if I leave the From address blank when using a hosted SMTP relay service?

The service rejects the message. Set the From address in EMAL to the sender registered on your relay account.

Can an Ethernet C-more panel send authenticated email for a Productivity3000?

Yes. The C-more supports SMTP authentication, so configure its email settings with the server credentials and trigger the send from a P3000 alarm tag. Delivery then depends on the panel staying powered and connected.

What happens if none of the workarounds are allowed on my network?

Stop there and contact AutomationDirect technical support through its official channels. Ask whether current P3000 firmware adds EMAL authentication and TLS, and give them your mail server's EHLO capability list from Check 1. Also register for AutomationDirect firmware update notifications so you learn when an update ships.

Back to blog