Secure Mail Server Setup on Ubuntu: Postfix, Dovecot, SpamAssassin Guide

Secure and Spam-Free Mail Server Setup Guide for Ubuntu: Postfix, Dovecot, SpamAssassin

Are you seeking to set up a secure and spam-free mail server on Ubuntu? This comprehensive guide will walk you through the step-by-step process of configuring a mail server using Postfix, Dovecot, and SpamAssassin. Whether you’re managing a small business or a personal project, our detailed instructions will help you achieve a robust email system with advanced spam filtering and cloud storage capabilities. Follow along to ensure your email communications are secure and efficient.

Prerequisites:

  • A server running Ubuntu.
  • A domain name (e.g., example.com).
  • DNS records for your domain.
  • SSL certificates for your domain (you can use Let’s Encrypt).

Step 1: Update the System

First, make sure your system is up-to-date.

sudo apt update
sudo apt upgrade -y

Step 2: Install Postfix, Dovecot, and SpamAssassin

Install the necessary packages.

sudo apt install postfix dovecot-core dovecot-imapd dovecot-pop3d spamassassin spamc -y

Step 3: Configure Postfix

Edit the Postfix main configuration file.

sudo nano /etc/postfix/main.cf

Add or modify the following settings:

# Basic settings
myhostname = mail.example.com
mydomain = example.com
myorigin = /etc/mailname
mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
relayhost =
mynetworks = 127.0.0.0/8
inet_interfaces = all
inet_protocols = ipv4

# Mailbox settings
home_mailbox = Maildir/
mailbox_command =

# SASL authentication
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
broken_sasl_auth_clients = yes
smtpd_recipient_restrictions = permit_sasl_authenticated, permit_mynetworks, reject_unauth_destination

# TLS settings
smtpd_tls_cert_file = /etc/ssl/certs/mail.example.com.crt
smtpd_tls_key_file = /etc/ssl/private/mail.example.com.key
smtpd_use_tls = yes
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache

# SpamAssassin integration
content_filter = spamassassin

# SPF and DKIM settings (optional, if you use them)
# smtpd_sender_restrictions = check_sender_access hash:/etc/postfix/sender_access
# smtpd_recipient_restrictions = reject_unknown_sender_domain, reject_unknown_recipient_domain, reject_unverified_recipient, check_policy_service unix:private/policyd-spf

Step 4: Configure Dovecot

Edit the Dovecot main configuration file.

sudo nano /etc/dovecot/dovecot.conf

Add or modify the following settings:

protocols = imap pop3 lmtp
mail_location = maildir:~/Maildir
namespace inbox {
  inbox = yes
}

auth_mechanisms = plain login
disable_plaintext_auth = yes

ssl = yes
ssl_cert = </etc/ssl/certs/mail.example.com.crt
ssl_key = </etc/ssl/private/mail.example.com.key

service auth {
  unix_listener /var/spool/postfix/private/auth {
    mode = 0666
    user = postfix
    group = postfix
  }
}

userdb {
  driver = passwd
}

passdb {
  driver = pam
}

Step 5: Configure SpamAssassin

Edit the SpamAssassin configuration file.

sudo nano /etc/spamassassin/local.cf

Add or modify the following settings:

required_score 5.0
rewrite_header Subject *****SPAM*****
report_safe 0
use_bayes 1
bayes_auto_learn 1
skip_rbl_checks 0
use_razor2 1
use_pyzor 1
use_dcc 1

Enable and start SpamAssassin:

sudo systemctl enable spamassassin
sudo systemctl start spamassassin

Step 6: Integrate SpamAssassin with Postfix

Create a filter script for SpamAssassin:

sudo nano /etc/postfix/master.cf

Add the following content at the end of the file:

spamassassin unix - n n - - pipe
  user=nobody argv=/usr/bin/spamc -f -e /usr/sbin/sendmail -oi -f ${sender} ${recipient}

Step 7: Setup SSL/TLS Certificates with Let’s Encrypt

Install Certbot:

sudo apt install certbot python3-certbot-nginx -y

Obtain and install a certificate:

sudo certbot certonly --standalone -d mail.example.com

Configure automatic certificate renewal:

sudo crontab -e

Add the following line:

0 0 * * * /usr/bin/certbot renew --quiet

Step 8: Configure Cloud Storage for Mail

To store mail in the cloud, you can use an object storage service like AWS S3, Google Cloud Storage, or similar. Here, we’ll outline an example using AWS S3.

8.1 Install s3fs

sudo apt install s3fs -y

8.2 Configure s3fs

Create a credentials file:

echo "ACCESS_KEY_ID:SECRET_ACCESS_KEY" > ~/.passwd-s3fs
chmod 600 ~/.passwd-s3fs

Mount your S3 bucket:

sudo mkdir /mnt/s3
sudo s3fs your-bucket-name /mnt/s3 -o passwd_file=~/.passwd-s3fs

8.3 Configure Dovecot to use S3

Edit the Dovecot configuration to store mail in the mounted S3 bucket.

sudo nano /etc/dovecot/conf.d/10-mail.conf

Modify the mail_location setting:

mail_location = maildir:/mnt/s3/%u/Maildir

Step 9: Restart Services

Restart Postfix and Dovecot to apply the changes:

sudo systemctl restart postfix
sudo systemctl restart dovecot

Step 10: Test the Configuration

  1. Send a test email to verify that Postfix and Dovecot are working correctly.
  2. Check the logs for any errors or issues:
   sudo tail -f /var/log/mail.log

Additional Considerations

  • DNS Settings: Ensure your DNS records (A, MX, SPF, DKIM, and DMARC) are properly configured for your domain.
  • Security: Implement additional security measures such as fail2ban to protect against brute force attacks.
  • Backups: Regularly backup your configuration files and email data.

By following these steps, you should have a secure and spam-free mail server using Postfix and Dovecot on Ubuntu, with emails stored in the cloud. Adjustments might be needed based on your specific requirements and environment.

Sources

https://www.postfix.org

https://www.postfix.org/postfix-manuals.html

https://spamassassin.apache.org

174

Discover more from CONTEXT EDUCATION

Subscribe to get the latest posts sent to your email.

Leave a Reply