Sign inSign up

mimedefang/postfix

By mimedefang

•Updated 3 months ago

MIMEDefang postfix images

Image
Networking
Security
Integration & delivery
0

616

mimedefang/postfix repository overview

⁠mimedefang/postfix

MIMEDefang⁠ email filter running alongside Postfix as the MTA, maintained by The McGrail Foundation⁠.

MIMEDefang hooks into Postfix via the Milter protocol (smtpd_milters) and lets you express your mail-filtering policy in Perl — stripping attachments, adding headers, calling SpamAssassin, querying external APIs, and more.


⁠Tags

TagPurpose
latestCurrent stable release – production image (no build tools)
vX.YPinned release, e.g. v3.7
ciCI/CD image – full build toolchain kept

⁠Quick start

docker run -d \
  -e MAIL_DOMAIN=example.com \
  -e MAIL_HOST=mail.example.com \
  -v /path/to/my-filter:/etc/mail/mimedefang-filter:ro \
  -p 25:25 \
  mimedefang/postfix:latest

If no filter is bind-mounted, a built-in pass-through filter is used so the container starts cleanly out of the box.


⁠Docker Compose (production)

services:
  postfix:
    image: mimedefang/postfix:latest
    hostname: mail.example.com
    restart: unless-stopped
    environment:
      MAIL_DOMAIN: "example.com"
      MAIL_HOST:   "mail.example.com"
      TZ:          "Europe/Rome"
    ports:
      - "25:25"
    volumes:
      - ./mimedefang-filter:/etc/mail/mimedefang-filter:ro
      - postfix-spool:/var/spool/MIMEDefang
      - postfix-quarantine:/var/spool/MD-Quarantine

volumes:
  postfix-spool:
  postfix-quarantine:

⁠Environment variables

All variables have sensible defaults; override only what you need.

⁠Identity
VariableDefaultDescription
MAIL_DOMAINexample.commydomain in main.cf
MAIL_HOSTmail.example.commyhostname in main.cf
RELAY_HOST(empty)Optional relayhost, e.g. [smtp.isp.com]:587
RELAY_NETS127.0.0.0/8 [::1]/128mynetworks — hosts allowed to relay
⁠MIMEDefang multiplexor
VariableDefaultDescription
MIN_WORKERS2Minimum number of Perl worker processes
MAX_WORKERS10Maximum number of Perl worker processes
MAX_IDLE2Workers to keep alive when idle
SPOOL_DIR/var/spool/MIMEDefangMultiplexor and milter socket directory
⁠Postfix / SMTP
VariableDefaultDescription
SMTP_PORT25SMTP listen port (informational; also set in ports:)
ENABLE_SUBMISSIONnoSet to yes to enable port 587 submission service
⁠System
VariableDefaultDescription
TZUTCContainer timezone, e.g. Europe/Rome

⁠Volumes

Mount pathPurpose
/etc/mail/mimedefang-filterYour Perl filter — bind-mount required for non-trivial use
/etc/postfix/extra.cfOptional: extra key = value lines appended to main.cf at startup
/var/spool/MIMEDefangMilter socket + spool — persist to survive container restarts
/var/spool/MD-QuarantineQuarantine directory
/etc/pki/tls/mimedefangTLS certificates (key.pem + cert.pem)
⁠Injecting extra Postfix settings

For any main.cf directive not covered by an environment variable, create a plain text file with one key = value per line and bind-mount it:

# extra.cf
message_size_limit = 52428800
smtpd_helo_required = yes
volumes:
  - ./extra.cf:/etc/postfix/extra.cf:ro

⁠Build-time arguments

When building the image yourself (see GitHub⁠):

ARGDefaultDescription
BASE_IMAGEalmalinux:9Base OS — any RHEL-compatible image works
MIMEDEFANG_VERv3.7Git tag to build from
docker build \
  --build-arg MIMEDEFANG_VER=v3.7 \
  --target prod \
  -t mimedefang/postfix:v3.7 .

⁠Build targets

# Build the CI image
docker build --target ci -t mimedefang/postfix:ci .

# Run the test suite
docker compose -f docker-compose-postfix.yml --profile ci \
  up --build --exit-code-from mimedefang-postfix-ci

⁠Writing a filter

The filter is a plain Perl file. A minimal example:

use strict;
use warnings;

sub filter_begin  { }
sub filter        { return action_accept(); }
sub filter_end    { }

1;

Mount it at /etc/mail/mimedefang-filter and restart the container. Full documentation: mimedefang-filter(5)⁠ and the examples directory⁠ in the source tree.


Tag summary

Content type

Image

Digest

sha256:ec0f13e0f…

Size

257.7 MB

Last updated

3 months ago

docker pull mimedefang/postfix