Connecting via SSH

Setting Up a Complete Mail Server Solution with Domain India's VPS

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (10 sections)

Running your own mail server gives you full control over mailboxes, storage and filtering, but it also makes you responsible for delivery, spam and security. This guide sets up a standard, current mail stack on your own Linux VPS: Postfix to send and receive, Dovecot for IMAP, Let's Encrypt for TLS, DKIM signing, and the DNS records that decide whether Gmail and Outlook accept your mail. It is not for shared hosting, which already includes email.

Key takeaways

Before you install anything, check that outbound port 25 works from your VPS and set the reverse DNS (PTR) of its IP to your mail hostname. Then install Postfix and Dovecot, get a certificate with Certbot, enable submission on port 587 (and 465) with Dovecot authentication, add DKIM signing, and publish MX, SPF, DKIM and DMARC records. Test with a real Gmail address and read the authentication results in the headers.

Consider whether you need your own mail server

A self-run mail server needs ongoing care: security updates, spam filtering, blocklist checks and backups. If you just want email at your domain, hosting plans include mailboxes, and Domain India Business Email is a managed service priced per mailbox. Self-hosting makes sense when you need full control or very large volumes of internal mail.

1. Plan the setup

This guide uses example.com for your domain and mail.example.com for the server. You need:

  • A VPS with a static public IP and root access. Commands are for Ubuntu 24.04; AlmaLinux or Rocky Linux equivalents are noted.
  • A domain whose DNS you can edit.
  • About 1 GB of RAM for Postfix and Dovecot alone, more if you add spam and virus scanning.
  1. Check outbound port 25.
    Run nc -vz gmail-smtp-in.l.google.com 25 on the VPS. If it doesn't connect, you can't deliver mail to other servers; ask your provider before going further.
  2. Set the hostname.
    Run sudo hostnamectl set-hostname mail.example.com.
  3. Create the A record.
    Point mail.example.com at your VPS IP.
  4. Set reverse DNS (PTR).
    The PTR record of your IP must return mail.example.com. Many receivers reject or junk mail from an IP without a matching PTR.

2. Install Postfix and Dovecot

bash
sudo apt update
sudo apt install postfix dovecot-imapd dovecot-lmtpd certbot
# AlmaLinux/Rocky: sudo dnf install postfix dovecot epel-release, then sudo dnf install certbot

When the Postfix installer asks, choose Internet Site and enter example.com as the mail name.

3. Get a TLS certificate

Mail clients and other servers expect encrypted connections. With nothing else on port 80, Certbot's standalone mode is simplest:

bash
sudo certbot certonly --standalone -d mail.example.com

The certificate lands in /etc/letsencrypt/live/mail.example.com/. Add a deploy hook so the mail services reload after each renewal:

bash
echo -e '#!/bin/sh\nsystemctl reload postfix dovecot' | sudo tee /etc/letsencrypt/renewal-hooks/deploy/mail.sh
sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/mail.sh

If a web server already uses port 80, use certbot --webroot or the web server plugin instead.

4. Configure Postfix

Set the essentials in /etc/postfix/main.cf (with sudo postconf -e or by editing the file):

ini
myhostname = mail.example.com
mydomain = example.com
myorigin = $mydomain
mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
inet_interfaces = all
home_mailbox = Maildir/

smtpd_tls_cert_file = /etc/letsencrypt/live/mail.example.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.example.com/privkey.pem
smtpd_tls_security_level = may
smtp_tls_security_level = may

smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
mailbox_transport = lmtp:unix:private/dovecot-lmtp
smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination

Then enable the submission ports for your mail apps in /etc/postfix/master.cf by uncommenting and adjusting the submission (587) and submissions (465) blocks:

ini
submission inet n - y - - smtpd
  -o syslog_name=postfix/submission
  -o smtpd_tls_security_level=encrypt
  -o smtpd_sasl_auth_enable=yes
  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
submissions inet n - y - - smtpd
  -o syslog_name=postfix/submissions
  -o smtpd_tls_wrappermode=yes
  -o smtpd_sasl_auth_enable=yes
  -o smtpd_client_restrictions=permit_sasl_authenticated,reject

reject_unauth_destination is what stops your server from becoming an open relay. Never remove it.

5. Configure Dovecot

These settings use Dovecot 2.3, the version in Ubuntu 24.04 and AlmaLinux 9. Dovecot 2.4 renamed several settings, so check dovecot --version and its documentation if yours is newer.

ini
# /etc/dovecot/conf.d/10-mail.conf
mail_location = maildir:~/Maildir

# /etc/dovecot/conf.d/10-ssl.conf
ssl = required
ssl_cert = </etc/letsencrypt/live/mail.example.com/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.example.com/privkey.pem

# /etc/dovecot/conf.d/10-auth.conf
disable_plaintext_auth = yes
auth_mechanisms = plain login

# /etc/dovecot/conf.d/20-lmtp.conf (system users log in without the domain)
protocol lmtp {
  auth_username_format = %Ln
}

In /etc/dovecot/conf.d/10-master.conf, let Postfix use Dovecot for authentication and delivery:

ini
service auth {
  unix_listener /var/spool/postfix/private/auth {
    mode = 0660
    user = postfix
    group = postfix
  }
}
service lmtp {
  unix_listener /var/spool/postfix/private/dovecot-lmtp {
    mode = 0600
    user = postfix
    group = postfix
  }
}

Create a mailbox user without shell access, then restart both services:

bash
sudo adduser --shell /usr/sbin/nologin info     # mailbox [email protected]
sudo systemctl restart postfix dovecot

This setup uses system accounts, which suits a handful of mailboxes. For many domains or users, move to virtual mailboxes stored in a database.

6. Sign your mail with DKIM

DKIM adds a signature that proves the mail came from your domain. OpenDKIM is the common choice with Postfix:

bash
sudo apt install opendkim opendkim-tools
sudo mkdir -p /etc/opendkim/keys
sudo opendkim-genkey -b 2048 -d example.com -s mail -D /etc/opendkim/keys/
sudo chown -R opendkim:opendkim /etc/opendkim/keys

Configure OpenDKIM to sign for example.com with selector mail, connect it to Postfix with smtpd_milters and non_smtpd_milters, and publish the public key from mail.txt as a TXT record at mail._domainkey.example.com. Rspamd is an alternative that handles DKIM signing and spam filtering in one service.

7. Publish the DNS records

RecordNameValue (example)
MXexample.commail.example.com, priority 10
Amail.example.comYour VPS IP
TXT (SPF)example.comv=spf1 mx -all
TXT (DKIM)mail._domainkey.example.comThe v=DKIM1 key from mail.txt
TXT (DMARC)_dmarc.example.comv=DMARC1; p=none; rua=mailto:[email protected]
PTRYour VPS IPmail.example.com

Start DMARC at p=none, read the reports for a few weeks, then move to quarantine and reject. If another service also sends as your domain, include it in SPF.

8. Firewall, test and maintain

Open only the ports the stack uses:

bash
sudo ufw allow 25,465,587,993/tcp
# AlmaLinux/Rocky: sudo firewall-cmd --permanent --add-service={smtp,smtps,smtp-submission,imaps} && sudo firewall-cmd --reload

Then test:

  • Add the account to a mail app: IMAP on 993 (SSL/TLS), SMTP on 587 (STARTTLS) or 465 (SSL/TLS), username info, full server name mail.example.com.
  • Send to a Gmail address, open Show original, and check that SPF, DKIM and DMARC all say PASS.
  • Watch the log while you test: sudo journalctl -u postfix -f (or /var/log/maillog on AlmaLinux).

To keep it healthy, apply security updates, add spam filtering (Rspamd or SpamAssassin), install Fail2ban to block password-guessing, check your IP on public blocklists, and back up /home/*/Maildir and your configuration. For more depth, see the advanced mail server management guide.

9. Running this on Domain India

A Domain India VPS is self-managed, with full root access, so you install and run the whole mail stack yourself. The live VPS page says you can set custom PTR records for your IPs in the client area; if you can't find the option, open a support ticket. Check port 25 as in section 1 before you build.

If you'd rather not run a mail server, there are two managed options:

  • Hosting mailboxes. Every shared hosting plan includes email accounts. See how to log in to webmail.
  • Business Email. A managed service priced per mailbox, with webmail, IMAP and SMTP over TLS, DKIM signing and the SPF and DMARC records provided for your domain. See Business Email.
Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details
VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Domain India list prices on 19 September 2026, excluding 18% GST, are on the cards above.

Frequently asked questions

What software do I need for a mail server on a VPS?

A mail transfer agent to send and receive (Postfix is the common choice), an IMAP server so mail apps can read mail (Dovecot), a TLS certificate (Let's Encrypt via Certbot), DKIM signing (OpenDKIM or Rspamd), and spam filtering. Webmail such as Roundcube is optional.

Why is my mail going to spam?

Usually a missing or wrong PTR record, SPF, DKIM or DMARC, or an IP on a blocklist. Send a test to Gmail, open Show original, and check that SPF, DKIM and DMARC all pass and that your IP's reverse DNS matches your mail hostname.

Which ports does a mail server need?

Port 25 for server-to-server mail, 587 (STARTTLS) and 465 (SSL/TLS) for sending from mail apps, and 993 for IMAP over SSL. Add 995 only if you offer POP3.

Can I set reverse DNS for my Domain India VPS?

The Domain India VPS page says custom PTR records can be set for your IP addresses in the client area. If you can't find the option, open a support ticket with the IP and the hostname you want.

Can I run my own mail server on shared hosting?

No. Shared hosting doesn't give you root access to install mail server software, but it already includes email accounts at your domain. A self-run mail server needs a VPS.

Is running my own mail server cheaper than a managed service?

Not always. The VPS costs money, and the time spent on updates, spam filtering and deliverability problems adds up. For a few mailboxes, hosting email or a managed service like Business Email is usually simpler.

Ready to decide? Compare VPS plans to run your own mail server, see Business Email for managed mailboxes, or open a ticket to ask which fits.

Want email without running a server?

Mailboxes at your own domain with webmail, IMAP and SMTP over TLS, and DKIM signing on every message.

See Business Email

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Set Up a Mail Server on a VPS: Postfix, Dovecot, DKIM