LINUXOR.SK ... open source notes ...

Postfix Mail Server - from a basic installation to a filtered mail system

category: learnz/postfix · date: 2010-04-21 · updated: 2026-10-04 · author: LALA · theme: github

This Learning collects my Postfix notes from 2007 to 2010 in one order: a basic installation, authenticated and encrypted submission, three complete mail systems with different back ends, and the tools around the server that filter, deliver and report.

noteThis is historical material, kept as it was written. The articles are working notes, mostly commands and configuration files with short comments, for Debian 4 and its contemporaries. Postfix itself has changed little in how it is configured; package names, TLS settings and the companion software have. Read it for the structure of a mail system, and check current documentation before you copy a setting.

Every article ends with a section Current practice, which says what has changed since and what to do instead today.

The levels

Each level ends with a small check. There is no time limit: when you can do what the check asks, go on to the next level.

LevelYou practiceYou have passed the level when
1 · InstallA basic Postfix with virus scanning, and everyday queue commandsYou can say what main.cf sets in the basic installation and how to look into the queue
2 · SecureSASL authentication, TLS certificates, relaying through another serverYou can explain what SASL adds and what TLS adds, and why a server wants both
3 · BuildComplete systems: for an ISP, with Dovecot and MailScanner, with Cyrus and MySQLYou can name, for one of the three systems, which program accepts mail, which stores it and which lets the user read it
4 · Filter and observebody_checks and header_checks, procmail and maildrop, a mail gateway, pflogsummYou can write one header check and one procmail rule, and say where in the path of a message each one runs

Level 1 is article 1, level 2 is article 2, level 3 is articles 3 to 5, and level 4 is articles 6 to 9.

The articles

Read them in this order. Articles 1 to 8 also exist in Slovak, the language they were written in; the (SK) link is at the top of each.

#ArticleWhat it is
1A basic installationLevel 1: installation, ClamAV, working with the queue
2Debian 4 - Postfix + SASL + TLSLevel 2: authentication and encryption, with client setup and relaying over stunnel
3Debian 4 - A mail server for an ISPLevel 3: a mail system for an ISP
4Postfix + Dovecot + SquirrelMail + MailScanner + ClamAVLevel 3: a complete system with webmail and content scanning
5Postfix + Cyrus + MySQLLevel 3: virtual domains and users in MySQL, with Cyrus
6Body_checks and header_checksLevel 4: rejecting mail by its content
7Notes on MDAs (procmail and maildrop)Level 4: delivery agents and their filter languages
8EnGarde Secure Linux - installing a mail gatewayLevel 4: a filtering gateway in front of the mail server
9PflogsummLevel 4: daily reports from the mail log

What you will be able to do

Final check

Draw the path of one incoming message through the system of article 4, from the SMTP connection to the user's mailbox, and name the program responsible at each step.