Task #2257


Added by Guilhem Moulin over 1 year ago. Updated 4 days ago.

Mail system
Target version:
Team - Q4/2018
Start date:
Due date:
% Done:


Estimated time:


This issue is about refactoring the main mail server. Possible improvements include:

Dovecot (IMAP):
  • Use the "passwd-file" driver for passdb and userdb to avoid using PAM or the passwd(5)/shadow(5) database
  • Replace the LDA with an LMTP server to receive mails from Postfix
  • Change mail storage format from maildir to mdbox, possibly compressed
Postfix (SMTP):
  • Use virtual users
  • Set smtpd_sasl_type=dovecot (instead of cyrus)
  • Move amavis to a milter or an after-queue content filter
  • replace postgrey by a tighter postscreen(8)
  • consider setting Postfix' notify_classes to empty
  • switch to Milter
  • set -o smtpd_proxy_options=speed_adjust as default
  • Guilhem proposed to use systemd
    Assuming you're using systemd as PID 1, a
    quick and dirty fix would be to tell it to auto restart the service.
    Rather than editing the unit file shipped by the package (which would be
    overridden by the next amavis update), I'd go for an override
    systemd.unit(5) file instead:
        $ mkdir /etc/systemd/system/amavis.service.d
        $ tee /etc/systemd/system/amavis.service.d/override.conf <<- EOF
            #Restart=on-abnormal might be more appropriate, see
            #systemd.service(5) for details
        $ systemctl daemon-reload
        $ systemctl restart amavis
    You can see if the override systemd.unit(5) file is taken into account
    with `sudo systemctl show amavis.service | grep ^Restart`.
hostmaster alias
  • consider switching to local mailbox only in case of too many notifications
  • switch to DNSSEC and TLSA records if feasible
  • consider rspamd, incl. ARC signing


#1 Updated by Guilhem Moulin over 1 year ago

oops, forgot something

Postfix (SMTP):
- replace postgrey by a tighter postscreen(8)

#2 Updated by Florian Effenberger over 1 year ago

  • Description updated (diff)
  • Target version changed from Qlater to Q4/2017

Aiming for Q4, but of course we can improve the setup gradually already earlier

#3 Updated by Florian Effenberger 7 months ago

  • Description updated (diff)

consider rspamd, incl. ARC signing

#4 Updated by Florian Effenberger 6 months ago

  • Target version changed from Q4/2017 to Q3/2018

With all that's on the table atm, and the fact that this is not super urgent, I propose to not look into this before end-June, unless you see it more urgent

#5 Updated by Florian Effenberger 3 months ago

Guilhem, can you remove/strike through from the list of tasks what's been done already?
I propose to shift the rest to Q4 then, what do you think?

#6 Updated by Guilhem Moulin 4 days ago

  • Description updated (diff)
  • Target version changed from Q3/2018 to Q4/2018

Ack, will get back to this when upgrading the box to Stretch.

Also available in: Atom PDF