Mail server : IMAP, SMTP, SSL and multidomains based on LDAP architecture (still in development)
967
Main features:
Mail: postfix, dovecot - Docker Hub
docker run -d --name mail \
-v /home/mail/mailboxes:/vmail \
-v /home/mail/ssl/smtp.domain.com:/ssl/smtp.domain.com:ro \
-v /home/mail/ssl/imap.domain.com:/ssl/imap.domain.com:ro \
-v /home/mail/dkim:/etc/opendkim \
-p 25:25 -p 587:587 -p 993:993 \
--link ldap
-e TZ=Etc/UTC -e MAIL_DOMAIN=domain.com \
-e LDAP_DOMAIN_BASE=ldapdomain.com -e LDAP_ADMIN_PASSWORD=password \
-e LDAP_USE_TLS=0
-e DKIM_KEY_SIZE=2048 \
sealeo/mail-openldap
version: '2'
services:
mail:
container_name: mail
image: sealeo/mail-openldap
volumes:
- /home/mail/mailboxes:/vmail
- /home/mail/ssl/smtp.domain.com:/ssl/smtp.domain.com:ro
- /home/mail/ssl/imap.domain.com:/ssl/imap.domain.com:ro
- /home/mail/dkim:/etc/opendkim
ports:
- "25:25"
- 587:587
- 993:993
external_links:
- ldap
environment:
- TZ=Etc/UTC
- MAIL_DOMAIN=domain.com
- LDAP_DOMAIN_BASE=domain.com
- LDAP_ADMIN_PASSWORD=password
- LDAP_USE_TLS=0
- DKIM_KEY_SIZE=2048
Minimal DNS zone configuration for the MAIL_DOMAIN (e.g. domain.com as above)
smtp 300 IN A x.x.x.x
imap 300 IN A x.x.x.x
mail 10800 IN A x.x.x.x
@ 10800 IN MX 10 mail.domain.com.
Where x.x.x.x is the IP address of your mail server.
@ 10800 IN MX 10 mail.domain.com.
autoconfig IN CNAME autoconfig.domain.com
Where domain.com is the main domain. The autoconfig line is for Thunderbird (see section below).
You will also need to configure each new domain for SPF, DKIM, ... (see below)
See: SPF on Wikipedia See: SPF Wizard
Example of possible configuration:
domain.com. IN TXT "v=spf1 mx a ptr ip4:x.x.x.x ~all"
Where x.x.x.x is the IP address of your mail server.
See: DKIM on Wikipedia See the Add domain section that explains what is required in DNS for DKIM
See: DMARC on Wikipedia
Example of possible configuration:
_dmarc IN TXT "v=DMARC1; p=none"
autoconfig IN A x.x.x.x
and you must have a running webserver on autoconfig.domain.com which serves the content of https://github.com/sealeo-org/mail-openldap/tree/master/etc/autoconfig.domain.com (you must adapt the mail/config-v1.1.xml content to match your configuration).
You need to provide SSL certificates for SMTPS and IMAPS in /ssl, in directories smtp.domain.com and imap.domain.com respectively.
Minimal files are fullchain.pem and privkey.pem. Any other file will be ignored.
You must ensure that these certificates are up to date.
Examples below are with Let's Encrypt but they must be easy to adapt to anything. Note: this configuration is to be done on the host.
/config/catchall can contain one e-mail address per domain to enable a catchall for this domain.
Example:
existing e-mail addresses will still be sent only to that specific recipient.
if you have any service listening on port 80: (example: nginx)
certbot certonly --pre-hook 'systemctl stop nginx' --post-hook 'systemctl start nginx' --standalone --agree-tos --rsa-key-size 4096 -d smtp.domain.com
certbot certonly --pre-hook 'systemctl stop nginx' --post-hook 'systemctl start nginx' --standalone --agree-tos --rsa-key-size 4096 -d imap.domain.com
else
certbot certonly --standalone --agree-tos --rsa-key-size 4096 -d smtp.domain.com
certbot certonly --standalone --agree-tos --rsa-key-size 4096 -d imap.domain.com
You now have certificates in /etc/letsencrypt/live/
To copy these for the container, you can run the two lines below.
Note: /container/ssl must be replaced by the mountpoint corresponding to inner /ssl
cp -TLrf /etc/letsencrypt/live/smtp.domain.com /container/ssl/smtp.domain.com
cp -TLrf /etc/letsencrypt/live/imap.domain.com /container/ssl/imap.domain.com
This section will describe a way to keep easily up to date the certificates
apt update
apt install -y incron
cat>/etc/incron.d/certs.mail.domain.com<<EOF
/etc/letsencrypt/live/smtp.domain.com/fullchain.pem IN_CLOSE_WRITE cp -LTrf /etc/letsencrypt/live/smtp.domain.com /data/containers/email/ssl/smtp.domain.com && docker exec mail update_smtp_ssl
/etc/letsencrypt/live/imap.domain.com/fullchain.pem IN_CLOSE_WRITE cp -LTrf /etc/letsencrypt/live/imap.domain.com /data/containers/email/ssl/imap.domain.com && docker exec mail update_imap_ssl
EOF
Scripts are available in the container to add a new domain, email address or alias.
docker exec -it mail add_domain
Domain? mydomain2.com
It will eventually show the required additional DNS zone configuration to enable DKIM for the new domain.
You will find it in you /home/mail/dkim/keys/mydomain2.com/mail.txt also, if you mounted like described above.
Note: your main domain DKIM key is automatically generated at container boot if non-existant.
docker exec -it mail add_alias
Domain? domain.com
User? admins
Recipient list? CTRL+D to finish
[email protected]
[email protected]
docker exec -it mail add_email
Domain? domain.com
User? bob
Password?
docker exec -it mail gen_dkim
Domain? domain.com
See Add domain.
Content type
Image
Digest
Size
80 MB
Last updated
over 6 years ago
docker pull sealeo/mail-openldap