Installing Postfix takes minutes; getting the mail to reach other people’s inboxes is the real work. A new mail server, on an IP with no history, is treated with suspicion by whoever receives. So the right question before installing is: do I really need to run the mail myself? For most websites the answer is no, and the mailboxes of a mail service built for the purpose give less trouble. This article explains what is at stake and the case where Postfix makes sense.
Why it is hard
| What |
Why it weighs |
| IP reputation |
The receiver judges the sending IP. A new IP, or one that sent spam before it was yours, may be on blocklists: your server IP on a blocklist. |
| Reverse DNS (PTR) |
The IP has to answer with a coherent name. On a VPS you ask us: PTR and reverse DNS. |
| SPF, DKIM and DMARC |
Without them mail goes to junk or is refused: SPF, DKIM and DMARC. |
| Security |
A badly configured Postfix is an “open relay”: anyone sends spam through you, and your IP is burned within hours. |
| Receiving is work too |
Mailboxes (usually with Dovecot), spam filtering, viruses, quotas, backups and recovery tools. |
| Ongoing upkeep |
Updates, certificates, queues, logs. A mail server is a service that is never “done”. |
The alternative that usually does the job
If what you want is for the site to send messages (forms, orders, password resets) and for the company to have mailboxes on its own domain, use a mail service built for that and connect your site to it over SMTP, with an authenticated account. Here that is the Professional E-mail plan (see the plan), and connecting PHP to SMTP is explained in sending e-mail from PHP. If the site is elsewhere and the e-mail here, that is the case in e-mail with us and the site elsewhere.
If you still want Postfix
| 1 |
Decide what it will do. Only send messages from the machine itself (alerts, the local application)? Or receive for a domain? The first case is far simpler and safer.
|
|
| 2 |
Install it. On Debian and Ubuntu, sudo apt install postfix; the wizard asks the type, and for a send-only server you pick “Internet Site” with the server’s name. On AlmaLinux or Rocky, sudo dnf install postfix. Depending on your system, follow the distribution’s documentation.
|
|
| 3 |
If it only sends, accept no connections from outside. In /etc/postfix/main.cf set inet_interfaces = loopback-only. Confirm everything you changed with postconf -n.
|
|
| 4 |
Ask for the PTR and create the SPF. Open a ticket with the name you want on the VPS IP’s PTR, and publish the domain’s SPF record (creating your SPF record). Then DKIM.
|
|
| 5 |
Test from outside. Send to a mailbox of yours at another service and see whether it reached the inbox and what the header says about SPF and DKIM. The queue is seen with postqueue -p and the log is in /var/log/mail.log (Debian and Ubuntu) or /var/log/maillog (AlmaLinux and Rocky).
|
|
|
Never leave Postfix open to everybody. A mail server that agrees to relay to any destination is used for spam within hours. If your IP lands on a blocklist or the machine is suspended for abuse, the cleanup is slow: signs of a compromise.
|
|
There may be restrictions on the network side. Sending mail directly from a server over port 25 is limited by some providers. Ask what your service allows before planning around it.
|
|
Even with everything right, do not promise yourself perfect delivery. The receiver decides. Reputation builds slowly and is lost fast. A professional mail service already comes with the reputation built.
|
|
Want reverse DNS set up for the VPS IP, or to know what your service allows for sending? Tell us the name you want and the service.
Open a support ticket
|
RECOMMENDED PRODUCT VPS server with root access Resources of your own, the OS you choose, reinstall whenever you like. from $8.39/mo (3-year plan, with coupon) See plans |