Running your own mail server gives you full control over mailboxes, storage and filtering, but it also makes you responsible for delivery, spam and security. This guide sets up a standard, current mail stack on your own Linux VPS: Postfix to send and receive, Dovecot for IMAP, Let's Encrypt for TLS, DKIM signing, and the DNS records that decide whether Gmail and Outlook accept your mail. It is not for shared hosting, which already includes email.
Before you install anything, check that outbound port 25 works from your VPS and set the reverse DNS (PTR) of its IP to your mail hostname. Then install Postfix and Dovecot, get a certificate with Certbot, enable submission on port 587 (and 465) with Dovecot authentication, add DKIM signing, and publish MX, SPF, DKIM and DMARC records. Test with a real Gmail address and read the authentication results in the headers.
A self-run mail server needs ongoing care: security updates, spam filtering, blocklist checks and backups. If you just want email at your domain, hosting plans include mailboxes, and Domain India Business Email is a managed service priced per mailbox. Self-hosting makes sense when you need full control or very large volumes of internal mail.
1. Plan the setup
This guide uses example.com for your domain and mail.example.com for the server. You need:
- A VPS with a static public IP and root access. Commands are for Ubuntu 24.04; AlmaLinux or Rocky Linux equivalents are noted.
- A domain whose DNS you can edit.
- About 1 GB of RAM for Postfix and Dovecot alone, more if you add spam and virus scanning.
- Check outbound port 25.Run
nc -vz gmail-smtp-in.l.google.com 25on the VPS. If it doesn't connect, you can't deliver mail to other servers; ask your provider before going further. - Set the hostname.Run
sudo hostnamectl set-hostname mail.example.com. - Create the A record.Point
mail.example.comat your VPS IP. - Set reverse DNS (PTR).The PTR record of your IP must return
mail.example.com. Many receivers reject or junk mail from an IP without a matching PTR.
2. Install Postfix and Dovecot
sudo apt update
sudo apt install postfix dovecot-imapd dovecot-lmtpd certbot
# AlmaLinux/Rocky: sudo dnf install postfix dovecot epel-release, then sudo dnf install certbotWhen the Postfix installer asks, choose Internet Site and enter example.com as the mail name.
3. Get a TLS certificate
Mail clients and other servers expect encrypted connections. With nothing else on port 80, Certbot's standalone mode is simplest:
sudo certbot certonly --standalone -d mail.example.comThe certificate lands in /etc/letsencrypt/live/mail.example.com/. Add a deploy hook so the mail services reload after each renewal:
echo -e '#!/bin/sh\nsystemctl reload postfix dovecot' | sudo tee /etc/letsencrypt/renewal-hooks/deploy/mail.sh
sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/mail.shIf a web server already uses port 80, use certbot --webroot or the web server plugin instead.
4. Configure Postfix
Set the essentials in /etc/postfix/main.cf (with sudo postconf -e or by editing the file):
myhostname = mail.example.com
mydomain = example.com
myorigin = $mydomain
mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
inet_interfaces = all
home_mailbox = Maildir/
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.example.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.example.com/privkey.pem
smtpd_tls_security_level = may
smtp_tls_security_level = may
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
mailbox_transport = lmtp:unix:private/dovecot-lmtp
smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destinationThen enable the submission ports for your mail apps in /etc/postfix/master.cf by uncommenting and adjusting the submission (587) and submissions (465) blocks:
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
submissions inet n - y - - smtpd
-o syslog_name=postfix/submissions
-o smtpd_tls_wrappermode=yes
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,rejectreject_unauth_destination is what stops your server from becoming an open relay. Never remove it.
5. Configure Dovecot
These settings use Dovecot 2.3, the version in Ubuntu 24.04 and AlmaLinux 9. Dovecot 2.4 renamed several settings, so check dovecot --version and its documentation if yours is newer.
# /etc/dovecot/conf.d/10-mail.conf
mail_location = maildir:~/Maildir
# /etc/dovecot/conf.d/10-ssl.conf
ssl = required
ssl_cert = </etc/letsencrypt/live/mail.example.com/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.example.com/privkey.pem
# /etc/dovecot/conf.d/10-auth.conf
disable_plaintext_auth = yes
auth_mechanisms = plain login
# /etc/dovecot/conf.d/20-lmtp.conf (system users log in without the domain)
protocol lmtp {
auth_username_format = %Ln
}In /etc/dovecot/conf.d/10-master.conf, let Postfix use Dovecot for authentication and delivery:
service auth {
unix_listener /var/spool/postfix/private/auth {
mode = 0660
user = postfix
group = postfix
}
}
service lmtp {
unix_listener /var/spool/postfix/private/dovecot-lmtp {
mode = 0600
user = postfix
group = postfix
}
}Create a mailbox user without shell access, then restart both services:
sudo adduser --shell /usr/sbin/nologin info # mailbox [email protected]
sudo systemctl restart postfix dovecotThis setup uses system accounts, which suits a handful of mailboxes. For many domains or users, move to virtual mailboxes stored in a database.
6. Sign your mail with DKIM
DKIM adds a signature that proves the mail came from your domain. OpenDKIM is the common choice with Postfix:
sudo apt install opendkim opendkim-tools
sudo mkdir -p /etc/opendkim/keys
sudo opendkim-genkey -b 2048 -d example.com -s mail -D /etc/opendkim/keys/
sudo chown -R opendkim:opendkim /etc/opendkim/keysConfigure OpenDKIM to sign for example.com with selector mail, connect it to Postfix with smtpd_milters and non_smtpd_milters, and publish the public key from mail.txt as a TXT record at mail._domainkey.example.com. Rspamd is an alternative that handles DKIM signing and spam filtering in one service.
7. Publish the DNS records
| Record | Name | Value (example) |
|---|---|---|
| MX | example.com | mail.example.com, priority 10 |
| A | mail.example.com | Your VPS IP |
| TXT (SPF) | example.com | v=spf1 mx -all |
| TXT (DKIM) | mail._domainkey.example.com | The v=DKIM1 key from mail.txt |
| TXT (DMARC) | _dmarc.example.com | v=DMARC1; p=none; rua=mailto:[email protected] |
| PTR | Your VPS IP | mail.example.com |
Start DMARC at p=none, read the reports for a few weeks, then move to quarantine and reject. If another service also sends as your domain, include it in SPF.
8. Firewall, test and maintain
Open only the ports the stack uses:
sudo ufw allow 25,465,587,993/tcp
# AlmaLinux/Rocky: sudo firewall-cmd --permanent --add-service={smtp,smtps,smtp-submission,imaps} && sudo firewall-cmd --reloadThen test:
- Add the account to a mail app: IMAP on 993 (SSL/TLS), SMTP on 587 (STARTTLS) or 465 (SSL/TLS), username
info, full server namemail.example.com. - Send to a Gmail address, open Show original, and check that SPF, DKIM and DMARC all say PASS.
- Watch the log while you test:
sudo journalctl -u postfix -f(or/var/log/maillogon AlmaLinux).
To keep it healthy, apply security updates, add spam filtering (Rspamd or SpamAssassin), install Fail2ban to block password-guessing, check your IP on public blocklists, and back up /home/*/Maildir and your configuration. For more depth, see the advanced mail server management guide.
9. Running this on Domain India
A Domain India VPS is self-managed, with full root access, so you install and run the whole mail stack yourself. The live VPS page says you can set custom PTR records for your IPs in the client area; if you can't find the option, open a support ticket. Check port 25 as in section 1 before you build.
If you'd rather not run a mail server, there are two managed options:
- Hosting mailboxes. Every shared hosting plan includes email accounts. See how to log in to webmail.
- Business Email. A managed service priced per mailbox, with webmail, IMAP and SMTP over TLS, DKIM signing and the SPF and DMARC records provided for your domain. See Business Email.
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Domain India list prices on 19 September 2026, excluding 18% GST, are on the cards above.
Frequently asked questions
What software do I need for a mail server on a VPS?
A mail transfer agent to send and receive (Postfix is the common choice), an IMAP server so mail apps can read mail (Dovecot), a TLS certificate (Let's Encrypt via Certbot), DKIM signing (OpenDKIM or Rspamd), and spam filtering. Webmail such as Roundcube is optional.
Why is my mail going to spam?
Usually a missing or wrong PTR record, SPF, DKIM or DMARC, or an IP on a blocklist. Send a test to Gmail, open Show original, and check that SPF, DKIM and DMARC all pass and that your IP's reverse DNS matches your mail hostname.
Which ports does a mail server need?
Port 25 for server-to-server mail, 587 (STARTTLS) and 465 (SSL/TLS) for sending from mail apps, and 993 for IMAP over SSL. Add 995 only if you offer POP3.
Can I set reverse DNS for my Domain India VPS?
The Domain India VPS page says custom PTR records can be set for your IP addresses in the client area. If you can't find the option, open a support ticket with the IP and the hostname you want.
Can I run my own mail server on shared hosting?
No. Shared hosting doesn't give you root access to install mail server software, but it already includes email accounts at your domain. A self-run mail server needs a VPS.
Is running my own mail server cheaper than a managed service?
Not always. The VPS costs money, and the time spent on updates, spam filtering and deliverability problems adds up. For a few mailboxes, hosting email or a managed service like Business Email is usually simpler.
Ready to decide? Compare VPS plans to run your own mail server, see Business Email for managed mailboxes, or open a ticket to ask which fits.
Mailboxes at your own domain with webmail, IMAP and SMTP over TLS, and DKIM signing on every message.
See Business Email