Postfix + Dovecot with Virtual Mailboxes on Ubuntu - 夜莺博客

Postfix + Dovecot with Virtual Mailboxes on Ubuntu

Running your own mail server teaches you how the internet actually works — SMTP, IMAP, TLS, SPF, DKIM and reverse DNS all intersect the moment you try to deliver a message to Gmail. The good news is that the core stack is only two daemons: Postfix moves mail between servers, Dovecot stores it and authenticates users for both IMAP and authenticated submission. This guide builds that pair with virtual mailboxes, so mail accounts do not need to be Linux users, on Ubuntu.

The Traffic Map

Traffic Port Handled by
Mail from other servers 25 Postfix, then LMTP to Dovecot
Mail sent by your users 587 STARTTLS Postfix, password checked by Dovecot SASL
Clients reading mail 993 IMAPS Dovecot IMAP
Postfix to Dovecot delivery unix socket private/dovecot-lmtp Dovecot LMTP
Postfix to Dovecot auth unix socket private/auth Dovecot auth

DNS and Reverse DNS Come First

Before touching the packages, publish these records. Receiving servers reject mail when HELO does not resolve or the PTR does not match:

mail.example.com.      A     203.0.113.10
example.com.           MX 10 mail.example.com.
example.com.           TXT   "v=spf1 mx ~all"
_dmarc.example.com.    TXT   "v=DMARC1; p=none; rua=mailto:postmaster@example.com"
; PTR for 203.0.113.10 -> mail.example.com  (set at the VPS provider, not in DNS)

Also verify your provider does not block outbound port 25 — most clouds do by default.

Install and Set the Hostname

sudo hostnamectl set-hostname mail.example.com
sudo apt update
sudo apt install postfix dovecot-core dovecot-imapd dovecot-lmtpd
# When Postfix asks: choose "Internet Site" and mail.example.com

Create the Storage User and Layout

sudo groupadd -g 5000 vmail
sudo useradd -g vmail -u 5000 -d /var/mail/vhosts -m vmail
sudo mkdir -p /var/mail/vhosts/example.com
sudo chown -R vmail:vmail /var/mail/vhosts

Mail for admin@example.com lands in /var/mail/vhosts/example.com/admin/ in Maildir format; Dovecot creates the per-user folders on first delivery.

Postfix: Virtual Domains over LMTP

sudo postconf -e 'myhostname = mail.example.com'
sudo postconf -e 'mydestination = mail.example.com, localhost.localdomain, localhost'
sudo postconf -e 'virtual_mailbox_domains = /etc/postfix/vdomains'
sudo postconf -e 'virtual_mailbox_maps = hash:/etc/postfix/vmailbox'
sudo postconf -e 'virtual_alias_maps = hash:/etc/postfix/valias'
sudo postconf -e 'virtual_transport = lmtp:unix:private/dovecot-lmtp'
sudo postconf -e 'smtpd_tls_cert_file = /etc/letsencrypt/live/mail.example.com/fullchain.pem'
sudo postconf -e 'smtpd_tls_key_file = /etc/letsencrypt/live/mail.example.com/privkey.pem'
sudo postconf -e 'smtpd_tls_security_level = may'
sudo postconf -e 'smtpd_sasl_type = dovecot'
sudo postconf -e 'smtpd_sasl_path = private/auth'
sudo postconf -e 'smtpd_sasl_auth_enable = yes'
sudo postconf -e 'smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination'

Critically, do not list example.com in mydestination: that would make Postfix deliver to local Linux users instead of handing mail to Dovecot.

echo example.com | sudo tee /etc/postfix/vdomains
sudo tee /etc/postfix/vmailbox <<'EOF'
admin@example.com    example.com/admin/Maildir/
sales@example.com    example.com/sales/Maildir/
EOF
sudo tee /etc/postfix/valias <<'EOF'
postmaster@example.com   admin@example.com
abuse@example.com        admin@example.com
EOF
sudo postmap /etc/postfix/vmailbox
sudo postmap /etc/postfix/valias

Enable Authenticated Submission on 587

sudo tee -a /etc/postfix/master.cf <<'EOF'
submission inet n - y - - smtpd
  -o syslog_name=postfix/submission
  -o smtpd_tls_security_level=encrypt
  -o smtpd_sasl_auth_enable=yes
  -o smtpd_sender_login_maps=hash:/etc/postfix/vmailbox
  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
  -o smtpd_relay_restrictions=permit_sasl_authenticated,reject
EOF

reject_sender_login_mismatch plus the vmailbox map prevents an authenticated user from sending as someone else — an open-relay-by-impersonation bug that shows up as spam complaints.

Dovecot: Mail Location, Auth Sockets, LMTP

# /etc/dovecot/conf.d/10-mail.conf
mail_location = maildir:/var/mail/vhosts/%d/%n
mail_privileged_group = vmail

# /etc/dovecot/conf.d/10-auth.conf
disable_plaintext_auth = yes
auth_username_format = %{user | lower}
!include auth-passwdfile.conf.ext

# /etc/dovecot/conf.d/auth-passwdfile.conf.ext
passdb {
  driver = passwd-file
  args = scheme=SHA512-CRYPT username_format=%u /etc/dovecot/users
}
userdb {
  driver = static
  args = uid=vmail gid=vmail home=/var/mail/vhosts/%d/%n
}
# /etc/dovecot/conf.d/10-master.conf - expose sockets to Postfix
service lmtp {
  unix_listener /var/spool/postfix/private/dovecot-lmtp {
    mode = 0600
    user = postfix
    group = postfix
  }
}
service auth {
  unix_listener /var/spool/postfix/private/auth {
    mode = 0660
    user = postfix
    group = postfix
  }
}

Create the First Mailbox and Start Everything

sudo doveadm pw -s SHA512-CRYPT
sudo tee /etc/dovecot/users <<'EOF'
admin@example.com:{SHA512-CRYPT}$6$...yourhash...
EOF
sudo chmod 640 /etc/dovecot/users
sudo chown root:dovecot /etc/dovecot/users
sudo doveconf -n
sudo systemctl restart dovecot
sudo systemctl restart postfix
sudo postfix check

Restart Dovecot before Postfix so the unix sockets exist when Postfix comes up — the reverse order produces a startup race that looks like LMTP is broken.

Verify the Whole Chain

postmap -q admin@example.com hash:/etc/postfix/vmailbox
doveadm auth test admin@example.com
swaks --to admin@example.com --server 127.0.0.1:587 --auth LOGIN --auth-user admin@example.com --tls
openssl s_client -connect mail.example.com:993 -quiet

If Dovecot 2.4 logs Plugin '$mail_plugins' not found, your LMTP protocol block still uses 2.3 syntax — write mail_plugins = sieve instead of mail_plugins = $mail_plugins sieve.

Do Not Skip

  • DKIM signing (OpenDKIM) — without it, Gmail treats valid SPF mail as suspicious.
  • Fail2ban jails for Postfix SASL and Dovecot — password guessing starts within hours.
  • A monitoring check on port 25 and 993 from outside your network.

Related Reading

Deeper dives on the same topics from our archive:

原文链接:https://cubepath.com/docs/email-server/postfix-dovecot-complete-configuration