Nixt Server
What Nixt Server is, what it includes, how it is built from roles, and how this documentation is organised.
Nixt Server is the mail server of the Nixt Office suite. It receives mail for your domains from the internet, filters it, stores it, and serves it to the people who use it over IMAP, POP3 and JMAP. It sends the mail they write, signs it with DKIM and delivers it to other servers. It also hosts calendars and contacts over CalDAV and CardDAV, runs each person’s Sieve filters and out-of-office replies, and gives you a command line and an API to administer all of it.
It is one program, versealx-server, that you run on your own Linux machine.
Get Nixt Server from the Download page.
Who these pages are for
- Administrators who install the server, publish its DNS records, create domains and accounts, and keep it running. Most of this documentation is for you.
- People whose mail the server hosts. Connecting mail apps, Sieve filters and vacation replies and Signing in cover what you need to know to use your account.
What it includes
| Area | What you get |
|---|---|
| Receiving mail | SMTP on port 25 with STARTTLS. Recipients are checked against your directory while the sender is still connected, so mail for an address that does not exist is refused rather than bounced later. |
| Sender authentication | SPF, DKIM, DMARC and ARC are checked on every incoming message, and the results are recorded in an Authentication-Results header. Mail that fails the sender’s DMARC reject policy is refused. |
| Filtering | A built-in stage that scores authentication results, and an attachment policy that refuses executables, dangerous archives and macro-carrying Office files. You can add ClamAV and any number of milters, such as Rspamd. |
| Mailboxes | IMAP4rev1 with a long list of extensions, POP3, and JMAP with push over EventSource and WebSocket. One message store answers all three, so a message read on one is read on the others. |
| Rules | Sieve scripts with 28 extensions, managed over ManageSieve, and out-of-office replies set from a mail app over JMAP. |
| Sending mail | Authenticated submission on ports 587 and 465, DKIM signing with an RSA and an Ed25519 key per domain, a retrying queue with delivery status notifications, and per-destination pacing. |
| Secure delivery | DANE and MTA-STS are enforced when the receiving domain publishes them, REQUIRETLS is honoured, and DNS answers are validated with DNSSEC. |
| Relaying | Send everything through a smart host, or send chosen domains through their own relay, when your connection cannot deliver mail directly. |
| Calendars and contacts | CalDAV and CardDAV on the HTTPS port, discovered at the well-known addresses. |
| Client setup | Mozilla autoconfig, Microsoft Autodiscover and SRV records, so mail apps configure themselves from an email address. |
| Your own policies | An MTA-STS policy for each domain, TLS reporting and DMARC aggregate reports, both received and sent. |
| Certificates | Certificate files you supply, or certificates obtained and renewed automatically over ACME (HTTP-01). A DANE key rollover command for ACME nodes. |
| Administration | versealx-server admin over a local socket, backed by a REST API with an OpenAPI document. Every change is written to an append-only audit log in the same transaction as the change. |
| Sign-in | Passwords stored as Argon2id hashes, SASL mechanisms PLAIN, LOGIN and SCRAM-SHA-256, account lockout, and an OAuth 2.0 authorisation server for JMAP apps such as Nixt Mail. |
| Operations | doctor, which checks DNS, certificates, reverse DNS and the store and tells you what to fix; Prometheus metrics with health and readiness endpoints; a message trace; and offline backup and restore. |
| Storage | SQLite and a directory of message files on a single machine, or PostgreSQL and an S3-compatible bucket. Message bodies are encrypted per tenant with AES-256-GCM. |
How the server is built: roles
Every part of the server is a role. A node runs all of them unless its configuration names a subset, which lets you split a larger installation across machines that share one store.
| Role | What it does | What it listens on by default |
|---|---|---|
mx | Receives mail from other servers. | 25 |
submission | Accepts mail from signed-in people. | 587 (STARTTLS), 465 (TLS) |
relay | Works through the queue: delivers to other servers and hands mail for local recipients to deliver. Also sends the daily TLS and DMARC reports and expires old message traces. | Nothing |
filter | The name of the filter pipeline. The pipeline runs inside mx and submission. | Nothing |
store | Serves mailboxes over IMAP, POP3, ManageSieve and JMAP, and the OAuth sign-in endpoints. | 143, 993, 110, 995, 4190, 443 |
deliver | Puts accepted mail into mailboxes, runs Sieve and sends vacation replies. | Nothing |
dav | Serves calendars and address books. | 443 |
admin | Serves the administrative API on a local socket, and over HTTPS when you configure it. | A local socket |
serve | Answers autoconfig, Autodiscover and MTA-STS policy requests, and obtains ACME certificates. | 443, and 80 when ACME is on |
A single machine normally runs every role. Configuration explains how to choose them.
Tenants, domains and accounts
Everything the server hosts belongs to a tenant. A tenant holds domains, and a domain holds accounts (people with mailboxes), groups, aliases and resources. A small installation has one tenant; versealx-server init makes it for you. Tenants keep their data apart from each other, and each tenant’s messages are encrypted under its own key.
How this documentation is organised
Get started
| Page | What it covers |
|---|---|
| Requirements | The machine, the network, the ports, DNS and certificates you need before you start. |
| Quick start | From installing the package to receiving and sending your first message. |
| TLS certificates | Certificate files, self-signed certificates for testing, ACME, and changing a key that DANE pins. |
| DNS records | Every record a domain needs, what each one does, and how to enter them at a DNS provider. |
Configure
| Page | What it covers |
|---|---|
| Configuration | Every section and key of versealx-server.toml, with its type, default and meaning. |
| Runtime settings | The settings kept in the server’s store, which you change without a restart. |
| Domains and accounts | Tenants, domains, domain verification, accounts, groups, aliases and passwords. |
| Signing in | Passwords, SASL mechanisms, lockout, OAuth tokens and the sign-in pages. |
| Connecting mail apps | Settings for IMAP, POP3, SMTP, JMAP, ManageSieve, CalDAV and CardDAV, and automatic setup. |
| Provisioning with SCIM | Syncing accounts and groups from Entra ID, Okta or your own script, and the tokens a machine signs in with. |
| Single sign-on | Letting people sign in at your own identity provider instead of keeping a second password for mail. |
| Syncing from LDAP or Active Directory | Keeping mailboxes in step with the directory you already have, on a schedule. |
| Calendars and scheduling | Meeting invitations inside the organisation and out, busy time, sharing, calendar delegates and group address books. |
| Shared mailboxes | Team inboxes several people work in, their members and read state, and people sharing one folder. |
| Branding | The organisation’s name, logo, colour and help on the pages its people sign in on. |
| When somebody leaves | Offboarding in one reviewed, reversible step: sign-ins ended, mail kept, new mail answered. |
| Mailing lists and groups | Lists with owners, moderators and outside subscribers, and groups that follow a rule. |
| Plans | Storage, sending limits, protocols, forwarding and two-step sign-in for kinds of people at once. |
| Getting deleted mail back | Deleted mail waits for a window before it is gone, and Trash and Junk empty themselves. |
Mail flow
| Page | What it covers |
|---|---|
| Receiving mail | What happens while another server delivers to yours, and the replies it can get. |
| Spam and malware filtering | The filter pipeline, scores and thresholds, the attachment policy, ClamAV and milters. |
| Sieve filters and vacation replies | Personal rules, the supported Sieve extensions, ManageSieve, and out-of-office replies. |
| Sending and delivery | Submission, the queue and its retries, bounces, pacing, smart hosts, DANE and MTA-STS. |
| Email authentication | SPF, DKIM signing and key rotation, DMARC, ARC, and DMARC and TLS reports. |
| Reported phishing | People reporting phishing, removing it from everybody, and the server taking it back on its own. |
| Encryption keys | Publishing people’s OpenPGP keys and S/MIME certificates so mail apps find them. |
Operate
| Page | What it covers |
|---|---|
| Running the server | The service, the data it keeps, file permissions, logs, and several nodes on one store. |
| Roles and the audit log | Who may do what through the API, and the record of every change. |
| Approvals | A second administrator for changes that cannot be undone, and an operator who asks first. |
| Webhooks and log export | Events sent to your systems as they happen, and the security log streamed to your SIEM. |
| Who opened my mail | A record of what delegates, members, colleagues and administrators did in a mailbox. |
| Search | How search stays fast in a large mailbox, what it matches, and the index commands. |
| Message trace | Finding out what happened to a message, in the queue and after it left, and finding messages by what happened to them. |
| Monitoring | Metrics, health and readiness, logs, and doctor. |
| Backup and restore | Taking a snapshot, what it holds, the key you must keep separately, and a restore drill. |
Reference
| Page | What it covers |
|---|---|
| Command-line reference | Every versealx-server subcommand, flag, output and exit code. |
| Admin API | Authentication, every endpoint, request and answer shapes, and errors. |
| Protocols and limits | The SMTP, IMAP, POP3, JMAP and ManageSieve extensions offered, and every built-in ceiling. |
| JMAP recoverable mail | The JMAP extension apps use to list and put back deleted mail. |
| JMAP snooze | The JMAP extension apps use to snooze a message until a time. |
Help
| Page | What it covers |
|---|---|
| Troubleshooting | Start-up refusals, delivery problems, and the messages the server prints. |
Something unclear or out of date on this page? Tell us.