Postfix 01 - a basic installation
Postfix Mail Server Learning · Next: Debian 4 - Postfix + SASL + TLS
The Slovak original of this document: Postfix 01 - základná inštalácia (slovensky).
****************************************************************
********* install postfix **************************************
****************************************************************
#apt-get install postfix
# /etc/init.d/postfix [start|stop|restart]
#cat /var/log/mail.log
****************************************************************
********* install courier-imap *********************************
****************************************************************
# apt-get install courier-imap
# /etc/init.d/courier-imap [start|stop|restart]
****************************************************************
********* install courier-pop **********************************
****************************************************************
# apt-get install courier-pop
# /etc/init.d/courier-pop [start|stop|restart]
# /etc/init.d/courier-authdaemon [start|stop|restart]
****************************************************************
********* config postfix ***************************************
****************************************************************
# nano /etc/postfix/main.cf
myhostname = mail.client02.example
mydomain = client02.example
myorigin = $mydomain
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
mydestination = $mydomain, $myhostname, localhost.$mydomain
relayhost =
mynetworks = 127.0.0.0/8 10.10.1.0/24 192.168.0.0/24
mailbox_size_limit = 51200000
recipient_delimiter = +
inet_interfaces = all
home_mailbox = Maildir/
****************************************************************
********* creating the mail directory for the users ************
****************************************************************
#cd /home/user
#maildirmake Maildir
#chown user.user Maildir/ -Rf
****************************************************************
********* automatic creation of Maildir for adduser ************
****************************************************************
# cd /etc/skel
# maildirmake Maildir
****************************************************************
********* install ClamaV ***************************************
****************************************************************
## adding the sources to apt
# nano /etc/apt/sources.list
## clamav
deb http://ftp2.de.debian.org/debian-volatile etch/volatile main
# apt-get install clamav clamav-base
****************************************************************
********* install MailScanner **********************************
****************************************************************
# apt-get install mailscanner
# nano /etc/postfix/main.cf
header_checks = regexp:/etc/postfix/header_checks
# nano /etc/postfix/header_checks
/^Received:/ HOLD
# nano /etc/MailScanner/MailScanner.conf
%org-name% = BigCorp2
%org-long-name% = BigCorp2
%web-site% = www.bigcorp2.example
%report-dir% = /etc/MailScanner/reports/sk
Run As User = postfix
Run As Group = postfix
Incoming Queue Dir = /var/spool/postfix/hold
Outgoing Queue Dir = /var/spool/postfix/incoming
MTA = postfix
Virus Scanners = clamav
Quarantine Silent Viruses = yes
Still Deliver Silent Viruses = yes
Notify Senders = yes
Filename Subject Text = {Zly nazov suboru?}
Content Subject Text = {Nebezpecny obsah}
Size Subject Text = {Velkost emailu}
Phishing Modify Subject = yes
Phishing Subject Text = {Podvodny mail?}
Attachment Encoding Charset = ISO-8859-2
Log Silent Viruses = yes
# nano /etc/default/mailscanner
run_mailscanner=1
# chown postfix:postfix /var/lock/subsys/MailScanner/
# chown postfix:postfix /var/run/MailScanner/
# chown postfix:postfix /var/lib/MailScanner/
# chown postfix:postfix -R /var/spool/MailScanner/
****************************************************************
********* useful commands **************************************
****************************************************************
## removing several messages at once
mailq | grep 'hladanyretazec' | awk '{print substr($1,1,10)}' | postsuper -d -
****************************************************************
****************************************************************Current practice (checked 2026-10)
noteThe article above is kept as it was written in 2009. This section lists what has changed since and what to do instead today.
- Service control: the article uses
/etc/init.d/postfix [start|stop|restart]. Debian has used systemd since Debian 8, so the same is done withsystemctl restart postfix,systemctl restart courier-imapand so on. - No TLS anywhere: the
main.cfshown has no TLS settings and Courier POP3/IMAP is installed without TLS, so mail and passwords cross the network in cleartext. Setsmtpd_tls_security_level = mayandsmtp_tls_security_level = maywith a real certificate, and offer POP3/IMAP only over TLS; RFC 8314 asks for TLS 1.2 or later between mail clients and servers and treats cleartext access as obsolete. - Relaying by
mynetworksonly: this is still fine for a trusted LAN. Users outside those networks should not be added tomynetworks; they send through an authenticated submission service on port 587 (STARTTLS) or 465 (implicit TLS), which RFC 6409 and RFC 8314 define for that purpose. hash:tables:alias_maps = hash:/etc/aliasesneeds Berkeley DB, which some Linux distributions are removing. The Postfix 3.11 release announcement points toNON_BERKELEYDB_READMEfor migratinghash:tolmdb:orcdb:; checkpostconf default_database_typeon your system.- debian-volatile: the
etch/volatilesource no longer exists. The volatile suite was replaced bystable-updatesstarting with Debian squeeze, and ClamAV updates for a stable release arrive through that suite. - MailScanner: the
mailscannerpackage was removed from Debian in 2011, soapt-get install mailscannerno longer works; upstream continues as MailScanner v5 on GitHub and has to be installed from there. The interfaces Postfix itself documents for content inspection arecontent_filter(after-queue),smtpd_proxy_filter(before-queue) and Milter. Notify Senders = yes: sender addresses of viruses and spam are forged, so these notices go to people who never sent the message. Set it tono.- Removing messages from the queue:
substr($1,1,10)assumes 10-character queue IDs, which is not guaranteed (queue IDs vary in length, andenable_long_queue_ids = yesmakes them longer). Since Postfix 3.1 the queue can be listed as JSON and filtered safely, as below.
$ # postqueue -j | jq -r 'select(.sender | test("searched-string")) | .queue_id' | postsuper -d -
Sources: