Andrew Savinykh
sorry, no idea
it should be in some doco either for postfix or for rspamd I figure...


reject = null;
Do you really need a dns entry with the ip
Andrew Savinykh
some people do some people don't. It's similar to asking if you really need umbrella when raining ;)
Many people use it because it accomplishes what they need. If you don't need it then don't use it.
Could someone tell me how to configure the postfix server to use an external SMTP relay.
Andrew Savinykh
@chrismrutherford there is not many people active here you probably will get more help in postix documentation and/or postfix related communities (if any)
Marco Aceti
Hi! One question: which is the http port of rainloop? I'm using nginx-proxy
Andrew Savinykh
Don't remember offhand, but you should be able to look up in the docker-compose file pretty easily. @MarcoBuster
are the containers running with least privilege? ex. no root unless absolutely necessary?
im considering migrating from mailu just for the sieve support
mailu has some minor issues still running certain parts of the system as root, despite not needing t. ex. rspamd
Andrew Savinykh
@vogelfreiheit unless you can qualify your question I'd suggest you read up on docker security in general. That is it is up to you how you run your containers. If this is mailserver specific question, then you need to clarify what exactly is running with which priveledge.
@AndrewSav ? docker security except for some cases is abysmal as containers effectively run uid=0, regardless of what capabilities might be dropped, the kernel ABI is exposed as-is, unlike with LXC, which is not panacea but still goes the extra mile by using namespaces and unpriv uid/gid mapping by default. the vast majority of docker containers i see, still run their entrypoints and processes as root
and yes it is very much mailserver specific. I asked which services are ran as root and what kind of approach is used to run the containers as non-root user/group, see linuxserver.io containers for an approach that does the same but implemented before docker actually had support for user/group arguments
maybe I need to name drop and mention where exactly my name is mentioned in the contributor list of the linux kernel... if that 'qualifies'. I know a thing or two about ABI exposure to containers since I wrote the ioctl permission model in the LSM framework, among other things...
i have multiple people asking about 'off the shelf' mail server solutions and would like to know the internals before recommending anything to them, or just telling them to roll their own postfix setup manually. they will learn more that way but these are folks with limited experience setting up MTAs.
Andrew Savinykh
@vogelfreiheit mailserver uses s6 as init process, most of the user processes, e.g postfix, dovecot, rspamd are running under their own accounts
These are the s6 services that it runs: https://github.com/hardware/mailserver/tree/master/rootfs/services you can see yourself there how this is set up
And thank you for clearing up what exactly you are after ;)
I'm happy to help in any way I can, ftr
@AndrewSav looking at it now
I wonder how much you could lockdown with seccomp too, if at all
it makes sense for small things only
note that docker's support for apparmor is super wonky, so i would not bother with that :-)
@AndrewSav i might test an instance to work with using real data from an actual install i had with mailu, are standard gz maildirs supported or you suggest setting up a temporary server somewhere else and imapsync'ing the two?
Hi, is it possible to deploy this on a Raspberry Pi?
anyone integrated mailing list solutions with mailserver?
probs not mailman as it is ancient at this point
Hi, I'd like to know how to backup data properly and how to migrate the installation on a new server.
Andrew Savinykh
Backing up / moving the volumes should do it
Does mail.domain.tld have to point to the traefik container , or is the point to just direct the mail subdomain to the server in some capacity?
Hi there, new to this stuff. I have a reverse proxy server that I already use that all my external connections go through (how I serve websites on 80 and 443) that forwards the request to the specific vm the domain/hostname entered was. I personally use NGINX. How would I deal with this integrating these containers into this? normally I proxypass to the servername:port I specified in the container would it be the pretty much the same here? direect the domains mail. , spam. etc to the container's serverip:80 ?
Hi! Is it possible to increase message size limit, for example, to 100MB both in Postfix and Rainloop?
Andrew Savinykh
@brettinternet as I understand traefik container is not mandatory in that setup, so it's up to you
@D347HxD if you talking about web ui then yes, but then you also have the rest of protocols to deal with, e.g imap, smtp, pop, and optionally sieve, etc
@n9net from what I remember postfix does not care, in rainloop there is a setting to do that you need to google it. there is also a php setting to go with that
Hello, do you know how can I allow an account (like admin@mydomain?tld) to send an email as any other user?
hi, what is the best way/place to override postfix configuration with docker env vars ? Do I need to use a volume and edit main.cf, etc... ? I have to add an external relay MTA to relay my emails.
Do you already have something for that ?
Bong Aquino
Hello guys!
Ian Sim


Where do you have your mailserver hosted? i have tried to have them on OVH and Digital Ocean. but my email for hotmail and gmail ends in SPAM? MY PTR record is correct, and i have configure SPF, DKIM and DMARC, there are all passed when i come to ex. Gmail. but still ends in spam? The IP adresses i get assigned from OVH and Digital Ocean are not presented on any blacklist? I'm not sure how Google or Microsoft handle spam, but my last thought was my mail volumes wasnt high enough or it could be the hole range there are "Blacklisted" ??

Enjoy Wallpapers
Hello guys, is there a quick and easy way to whitelist a sender "x@y.com" so that it's never treated as spam from the rspamd webgui?
@philipleit I have the same problem but only with Microsoft, I contacted them, joined JMRP,SDNS, added unsubscribe header and my datacenter send them a email confirming the date where the IP was assigned to my server. Nothing changed, still ending in spam even if I whitelist the sender...
Microsoft is not replying to my ticket since many days.