Secure and Spam-Free Mail Server Setup Guide for Ubuntu: Postfix, Dovecot, SpamAssassin
Are you seeking to set up a secure and spam-free mail server on Ubuntu? This comprehensive guide will walk you through the step-by-step process of configuring a mail server using Postfix, Dovecot, and SpamAssassin. Whether you’re managing a small business or a personal project, our detailed instructions will help you achieve a robust email system with advanced spam filtering and cloud storage capabilities. Follow along to ensure your email communications are secure and efficient.
Prerequisites:
- A server running Ubuntu.
- A domain name (e.g., example.com).
- DNS records for your domain.
- SSL certificates for your domain (you can use Let’s Encrypt).
Step 1: Update the System
First, make sure your system is up-to-date.
sudo apt update
sudo apt upgrade -y
Step 2: Install Postfix, Dovecot, and SpamAssassin
Install the necessary packages.
sudo apt install postfix dovecot-core dovecot-imapd dovecot-pop3d spamassassin spamc -y
Step 3: Configure Postfix
Edit the Postfix main configuration file.
sudo nano /etc/postfix/main.cf
Add or modify the following settings:
# Basic settings
myhostname = mail.example.com
mydomain = example.com
myorigin = /etc/mailname
mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
relayhost =
mynetworks = 127.0.0.0/8
inet_interfaces = all
inet_protocols = ipv4
# Mailbox settings
home_mailbox = Maildir/
mailbox_command =
# SASL authentication
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
broken_sasl_auth_clients = yes
smtpd_recipient_restrictions = permit_sasl_authenticated, permit_mynetworks, reject_unauth_destination
# TLS settings
smtpd_tls_cert_file = /etc/ssl/certs/mail.example.com.crt
smtpd_tls_key_file = /etc/ssl/private/mail.example.com.key
smtpd_use_tls = yes
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
# SpamAssassin integration
content_filter = spamassassin
# SPF and DKIM settings (optional, if you use them)
# smtpd_sender_restrictions = check_sender_access hash:/etc/postfix/sender_access
# smtpd_recipient_restrictions = reject_unknown_sender_domain, reject_unknown_recipient_domain, reject_unverified_recipient, check_policy_service unix:private/policyd-spf
Step 4: Configure Dovecot
Edit the Dovecot main configuration file.
sudo nano /etc/dovecot/dovecot.conf
Add or modify the following settings:
protocols = imap pop3 lmtp
mail_location = maildir:~/Maildir
namespace inbox {
inbox = yes
}
auth_mechanisms = plain login
disable_plaintext_auth = yes
ssl = yes
ssl_cert = </etc/ssl/certs/mail.example.com.crt
ssl_key = </etc/ssl/private/mail.example.com.key
service auth {
unix_listener /var/spool/postfix/private/auth {
mode = 0666
user = postfix
group = postfix
}
}
userdb {
driver = passwd
}
passdb {
driver = pam
}
Step 5: Configure SpamAssassin
Edit the SpamAssassin configuration file.
sudo nano /etc/spamassassin/local.cf
Add or modify the following settings:
required_score 5.0
rewrite_header Subject *****SPAM*****
report_safe 0
use_bayes 1
bayes_auto_learn 1
skip_rbl_checks 0
use_razor2 1
use_pyzor 1
use_dcc 1
Enable and start SpamAssassin:
sudo systemctl enable spamassassin
sudo systemctl start spamassassin
Step 6: Integrate SpamAssassin with Postfix
Create a filter script for SpamAssassin:
sudo nano /etc/postfix/master.cf
Add the following content at the end of the file:
spamassassin unix - n n - - pipe
user=nobody argv=/usr/bin/spamc -f -e /usr/sbin/sendmail -oi -f ${sender} ${recipient}
Step 7: Setup SSL/TLS Certificates with Let’s Encrypt
Install Certbot:
sudo apt install certbot python3-certbot-nginx -y
Obtain and install a certificate:
sudo certbot certonly --standalone -d mail.example.com
Configure automatic certificate renewal:
sudo crontab -e
Add the following line:
0 0 * * * /usr/bin/certbot renew --quiet
Step 8: Configure Cloud Storage for Mail
To store mail in the cloud, you can use an object storage service like AWS S3, Google Cloud Storage, or similar. Here, we’ll outline an example using AWS S3.
8.1 Install s3fs
sudo apt install s3fs -y
8.2 Configure s3fs
Create a credentials file:
echo "ACCESS_KEY_ID:SECRET_ACCESS_KEY" > ~/.passwd-s3fs
chmod 600 ~/.passwd-s3fs
Mount your S3 bucket:
sudo mkdir /mnt/s3
sudo s3fs your-bucket-name /mnt/s3 -o passwd_file=~/.passwd-s3fs
8.3 Configure Dovecot to use S3
Edit the Dovecot configuration to store mail in the mounted S3 bucket.
sudo nano /etc/dovecot/conf.d/10-mail.conf
Modify the mail_location setting:
mail_location = maildir:/mnt/s3/%u/Maildir
Step 9: Restart Services
Restart Postfix and Dovecot to apply the changes:
sudo systemctl restart postfix
sudo systemctl restart dovecot
Step 10: Test the Configuration
- Send a test email to verify that Postfix and Dovecot are working correctly.
- Check the logs for any errors or issues:
sudo tail -f /var/log/mail.log
Additional Considerations
- DNS Settings: Ensure your DNS records (A, MX, SPF, DKIM, and DMARC) are properly configured for your domain.
- Security: Implement additional security measures such as fail2ban to protect against brute force attacks.
- Backups: Regularly backup your configuration files and email data.
By following these steps, you should have a secure and spam-free mail server using Postfix and Dovecot on Ubuntu, with emails stored in the cloud. Adjustments might be needed based on your specific requirements and environment.
Sources
https://www.postfix.org/postfix-manuals.html
https://spamassassin.apache.org
174
Discover more from CONTEXT EDUCATION
Subscribe to get the latest posts sent to your email.

