A fullstack but simple mail server (smtp, imap, antispam, antivirus...). Only configuration files, no SQL database. Keep it simple and versioned. Easy to deploy and upgrade.
Includes:
[email protected] go to [email protected]Why I created this image: Simple mail server with Docker
Before you open an issue, please have a look this README, the Wiki and Postfix/Dovecot documentation.
Recommended:
Minimum:
Note: You'll need to deactivate some services like ClamAV to be able to run on a host with 512MB of RAM. Even with 1G RAM you may run into problems without swap, see FAQ.
docker pull tvial/docker-mailserver:latest
Download the docker-compose.yml, the .env and the setup.sh files:
curl -o setup.sh https://raw.githubusercontent.com/tomav/docker-mailserver/master/setup.sh; chmod a+x ./setup.sh
curl -o docker-compose.yml https://raw.githubusercontent.com/tomav/docker-mailserver/master/docker-compose.yml.dist
curl -o .env https://raw.githubusercontent.com/tomav/docker-mailserver/master/.env.dist
curl -o env-mailserver https://raw.githubusercontent.com/tomav/docker-mailserver/master/env-mailserver.dist
.env and env-mailserver to your liking:
.env contains the configuration for docker-composeenv-mailserver contains the configuration for the mailserver containerVAR=VAL lines (see Documentation).OVERRIDE_HOSTNAME=$HOSTNAME.$DOMAINNAME).1.7 or higher.Note: If you want to use a bare domain (host name equals domain name) see FAQ.
docker-compose up -d mail
./setup.sh email add <user@domain> [<password>]
./setup.sh config dkim
Now the keys are generated, you can configure your DNS server by just pasting the content of config/opendkim/keys/domain.tld/mail.txt in your domain.tld.hosts zone.
docker-compose down
docker pull tvial/docker-mailserver:latest
docker-compose up -d mail
You're done!
And don't forget to have a look at the remaining functions of the setup.sh script
If you got any problems with SPF and/or forwarding mails, give SRS a try. You enable SRS by setting ENABLE_SRS=1. See the variable description for further information.
Your config folder will be mounted in /tmp/docker-mailserver/. To understand how things work on boot, please have a look at start-mailserver.sh
restart: always ensures that the mail server container (and ELK container when using the mail server together with ELK stack) is automatically restarted by Docker in cases like a Docker service or host restart or container exit.
Note: Port 25 is only for receiving email from other mailservers and not for submitting email. You need to use port 465 or 587 for this.
version: '2'
services:
mail:
image: tvial/docker-mailserver:latest
hostname: mail
domainname: domain.com
container_name: mail
ports:
- "25:25"
- "143:143"
- "587:587"
- "993:993"
volumes:
- maildata:/var/mail
- mailstate:/var/mail-state
- maillogs:/var/log/mail
- ./config/:/tmp/docker-mailserver/
environment:
- ENABLE_SPAMASSASSIN=1
- ENABLE_CLAMAV=1
- ENABLE_FAIL2BAN=1
- ENABLE_POSTGREY=1
- ONE_DIR=1
- DMS_DEBUG=0
cap_add:
- NET_ADMIN
- SYS_PTRACE
volumes:
maildata:
driver: local
mailstate:
driver: local
maillogs:
driver: local
for ldap setup:
version: '2'
services:
mail:
image: tvial/docker-mailserver:latest
hostname: mail
domainname: domain.com
container_name: mail
ports:
- "25:25"
- "143:143"
- "587:587"
- "993:993"
volumes:
- maildata:/var/mail
- mailstate:/var/mail-state
- maillogs:/var/log/mail
- ./config/:/tmp/docker-mailserver/
environment:
- ENABLE_SPAMASSASSIN=1
- ENABLE_CLAMAV=1
- ENABLE_FAIL2BAN=1
- ENABLE_POSTGREY=1
- ONE_DIR=1
- DMS_DEBUG=0
- ENABLE_LDAP=1
- LDAP_SERVER_HOST=ldap # your ldap container/IP/ServerName
- LDAP_SEARCH_BASE=ou=people,dc=localhost,dc=localdomain
- LDAP_BIND_DN=cn=admin,dc=localhost,dc=localdomain
- LDAP_BIND_PW=admin
- LDAP_QUERY_FILTER_USER=(&(mail=%s)(mailEnabled=TRUE))
- LDAP_QUERY_FILTER_GROUP=(&(mailGroupMember=%s)(mailEnabled=TRUE))
- LDAP_QUERY_FILTER_ALIAS=(|(&(mailAlias=%s)(objectClass=PostfixBookMailForward))(&(mailAlias=%s)(objectClass=PostfixBookMailAccount)(mailEnabled=TRUE)))
- LDAP_QUERY_FILTER_DOMAIN=(|(&(mail=*@%s)(objectClass=PostfixBookMailAccount)(mailEnabled=TRUE))(&(mailGroupMember=*@%s)(objectClass=PostfixBookMailAccount)(mailEnabled=TRUE))(&(mailalias=*@%s)(objectClass=PostfixBookMailForward)))
- DOVECOT_PASS_FILTER=(&(objectClass=PostfixBookMailAccount)(uniqueIdentifier=%n))
- DOVECOT_USER_FILTER=(&(objectClass=PostfixBookMailAccount)(uniqueIdentifier=%n))
- ENABLE_SASLAUTHD=1
- SASLAUTHD_MECHANISMS=ldap
- SASLAUTHD_LDAP_SERVER=ldap
- SASLAUTHD_LDAP_BIND_DN=cn=admin,dc=localhost,dc=localdomain
- SASLAUTHD_LDAP_PASSWORD=admin
- SASLAUTHD_LDAP_SEARCH_BASE=ou=people,dc=localhost,dc=localdomain
- [email protected]
- POSTFIX_MESSAGE_SIZE_LIMIT=100000000
cap_add:
- NET_ADMIN
- SYS_PTRACE
volumes:
maildata:
driver: local
mailstate:
driver: local
maillogs:
driver: local
Please check how the container starts to understand what's expected. Also if an option doesn't work as documented here, check if you are running the latest image!
Value in bold is the default value.
/var/mail-state) to allow persistence using docker volumesIf you enable Fail2Ban, don't forget to add the following lines to your docker-compose.yml:
cap_add:
- NET_ADMIN
Otherwise, iptables won't be able to ban IPs.
Please read the SSL page in the wiki for more information.
Configures the handling of creating mails with forged sender addresses.
Enables the Sender Rewriting Scheme. SRS is needed if your mail server acts as forwarder. See postsrsd for further explanation.
Set different options for mynetworks option (can be overwrite in postfix-main.cf) WARNING: Adding the docker network's gateway to the list of trusted hosts, e.g. using the network or connected-networks option, can create an open relay, for instance if IPv6 is enabled on the host machine but not in Docker.
docker-compose might use others (e.g. 192.168.0.0/16) use PERMIT_DOCKER=connected-networks in this caseSet how many days a virusmail will stay on the server before being deleted
This Option is activating the Usage of POSTFIX_DAGENT to specify a ltmp client different from default dovecot socket.
Enabled by ENABLE_POSTFIX_VIRTUAL_TRANSPORT. Specify the final delivery of postfix
lmtp:unix:private/dovecot-lmtp (use socket)lmtps:inet:<host>:<port> (secure lmtp with starttls, take a look at https://sys4.de/en/blog/2014/11/17/sicheres-lmtp-mit-starttls-in-dovecot/)lmtp:<kopano-host>:2003 (use kopano as mailstore)Set the mailbox size limit for all users. If set to zero, the size will be unlimited (default).
Set the message size limit for all users. If set to zero, the size will be unlimited (not recommended!)
hostname command to get the mail server's canonical hostnameThis option has been added in November 2019. Using other format than Maildir is considered as experimental in docker-mailserver and should only be used for testing purpose. For more details, please refer to Dovecot Documentation.
Enables regular pflogsumm mail reports.
This is a new option. The old REPORT options are still supported for backwards compatibility. If this is not set and reports are enabled with the old options, logrotate will be used.
Recipient address for pflogsumm reports.
From address for pflogsumm reports.
Interval for logwatch report.
Recipient address for logwatch reports if they are enabled.
Enables a report being sent (created by pflogsumm) on a regular basis.
Change the sending address for mail report
changes the interval in which logs are rotated and a report is being sent (deprecated).
Note: This variable used to control logrotate inside the container and sent the pflogsumm report when the logs were rotated. It is still supported for backwards compatibility, but the new option LOGROTATE_INTERVAL has been added that only rotates the logs.
Defines the interval in which the mail log is being rotated.
Note that only the log inside the container is affected.
The full log output is still available via docker logs mail (or your respective container name).
If you want to control logrotation for the docker generated logfile see: Docker Logging Drivers.
Also note that by default the logs are lost when the container is recycled. To keep the logs, mount a volume.
Finally the logrotate interval may affect the period for generated reports. That is the case when the reports are triggered by log rotation.
Note: this spamassassin setting needs ENABLE_SPAMASSASSIN=1
Note: this spamassassin setting needs ENABLE_SPAMASSASSIN=1
Note: this spamassassin setting needs ENABLE_SPAMASSASSIN=1. By default, the mailserver is configured to quarantine spam emails. If emails are quarantined, they are compressed and stored in a location dependent on the ONE_DIR setting above. If ONE_DIR=1 the location is /var/mail-state/lib-amavis/virusmails/. If ONE_DIR=0 it is /var/lib/amavis/virusmails/. These paths are inside the docker container. To inhibit this behaviour and deliver spam emails, set this to a very high value e.g. 100.0.
Note: this spamassassin setting needs ENABLE_SPAMASSASSIN=1
This will uncomment the respective line in /etc/spamassasin/local.cf
Note: activate this only if you are confident in your bayes database for identifying spam.
This will uncomment the respective line in /etc/spamassasin/local.cf
Note: activate this only if you are confident in your bayes database for identifying ham.
fetchmail disabledfetchmail enabledfetchmail The number of seconds for the interval(&(mail=%s)(mailEnabled=TRUE))(&(mailGroupMember=%s)(mailEnabled=TRUE))(&(mailAlias=%s)(mailEnabled=TRUE))(&(|(mail=*@%s)(mailalias=*@%s)(mailGroupMember=*@%s))(mailEnabled=TRUE))The following variables overwrite the default values for /etc/dovecot/dovecot-ldap.conf.ext.
(&(objectClass=PostfixBookMailAccount)(uniqueIdentifier=%n))homeDirectory=home,qmailUID=uid,qmailGID=gid,mailMessageStore=mail(&(objectClass=PostfixBookMailAccount)(uniqueIdentifier=%n))uid=user,userPassword=passwordpostgrey is disabledpostgrey is enabledNote: This postgrey setting needs ENABLE_POSTGREY=1
Note: This postgrey setting needs ENABLE_POSTGREY=1
Note: This postgrey setting needs ENABLE_POSTGREY=1
Note: This postgrey setting needs ENABLE_POSTGREY=1
saslauthd is disabledsaslauthd is enabledldap => authenticate against ldap servershadow => authenticate against local user dbmysql => authenticate against mysql dbrimap => authenticate against imap serverldap:// will be usedldaps:// will be usedContent type
Image
Digest
Size
291.5 MB
Last updated
over 6 years ago
docker pull onemancrew/docker-mailserver:v6.2.2