Requirements

The machine, operating system, network access, ports, DNS, reverse DNS and certificates Nixt Server needs before you install it.

Check this list before you install. Most first deployments that fail do so because of the network — a blocked port 25, or an address with no reverse DNS — rather than because of the server.

The machine

RequirementDetail
Operating systemLinux on x86-64 or ARM64. Packages are .deb and .rpm; a container image is also available.
Service managersystemd, for the packaged service. The container image runs without it.
Trust storeThe system’s CA certificates (the ca-certificates package, which the packages depend on). The server verifies every outbound TLS connection against it and will not run without one.
Accurate clockRun NTP. A wrong clock makes your DKIM signatures and certificates look invalid to other servers, and doctor reports a clock set before 2024 as broken.
Service accountThe server refuses to run as root. The packages create a versealx system user and group, and the service runs as that user with the one capability it needs to bind ports below 1024.
DiskSpace for the store and every message, under /var/lib/versealx-server by default. Messages are stored once however many mailboxes hold them.

Storage options

StoreUse it for
SQLite and a directory of message filesOne machine. This is what init sets up.
PostgreSQL 15 or later and an S3-compatible bucketSeveral nodes sharing one store. See Running the server.

You can mix them — SQLite with a bucket, or PostgreSQL with a directory. Several nodes can only share a directory of message files if every one of them can reach the same directory.

Network

Inbound ports

Open the ports for the roles you run. Every listener binds all IPv4 addresses (0.0.0.0) unless you set its address.

PortProtocolRoleWho connects
25SMTP with STARTTLSmxOther mail servers delivering to your domains. Must be reachable from the internet.
587SMTP submission with STARTTLSsubmissionMail apps sending mail.
465SMTP submission over TLSsubmissionMail apps sending mail.
143IMAP with STARTTLSstoreMail apps.
993IMAP over TLSstoreMail apps.
110POP3 with STLSstoreMail apps that use POP3.
995POP3 over TLSstoreMail apps that use POP3.
4190ManageSieve with STARTTLSstoreApps that edit Sieve filters.
443HTTPSstore, dav, serve, adminJMAP apps, OAuth sign-in, calendar and contacts apps, autoconfig, Autodiscover, MTA-STS policy fetches, and the admin API when you enable it.
80HTTPserveThe certificate authority, for ACME HTTP-01 challenges. Only when you use ACME.

Port 443 is one listener shared by every HTTPS service on the node. Nothing except the ACME challenge is ever served without TLS.

The metrics endpoint listens only where you tell it to. Keep it on a private network: it answers without authentication. See Monitoring.

Outbound access

DestinationWhy
TCP port 25 on other mail serversDelivering mail directly. Not needed if you send through a relay.
Your relay’s submission port (usually 587 or 465)Only if you send through a smart host.
HTTPS (443) to other domainsFetching MTA-STS policies before delivering, and talking to your ACME certificate authority.
DNSEvery delivery and every incoming message needs lookups: MX, SPF, DKIM, DMARC, TLSA, MTA-STS.
Your ClamAV or milter socketsOnly if you configure them.

Can this machine send mail directly?

Two things decide it, and neither is something the server can change:

  1. Outbound port 25. Most home and many business internet connections block it, and some hosting providers block it until you ask.
  2. Reputation. An address with no matching reverse DNS, or with no history of sending mail, is refused or filed as spam by the large mailbox providers.

If either applies, send through a relay that already has a reputation. Incoming mail is unaffected: other servers still deliver to your port 25. Run init with --relay or add an [outbound.relay] table, and see Sending through a relay.

Reverse DNS

The name your server greets other servers with (its hostname) must resolve to the machine’s public address, and that address must have a PTR record pointing back to the same name. Reverse DNS belongs to whoever owns the address — your ISP or hosting provider — not to your domain’s DNS provider. Ask them to set it before you start, because it can take days. doctor checks it.

DNS resolver

The server reads the resolvers in /etc/resolv.conf and validates DNSSEC itself. It works with any resolver, but it works best with one that passes DNSSEC records through — a local unbound or Knot Resolver, for example. With a resolver that strips them, answers saying a record does not exist cannot be cached, and the server asks again for every message. doctor reports which kind you have.

DNS for your domain

You need control of your domain’s DNS so you can publish:

  • an address record (A, and AAAA if you have IPv6) for the mail host,
  • an MX record naming it,
  • SPF, DMARC, DKIM, MTA-STS and TLS reporting TXT records,
  • the ownership token,
  • SRV records for automatic client setup.

init prints every record, and versealx-server dns prints them again at any time. DNS records explains each one.

To publish a DANE (TLSA) record you also need a DNS provider that offers the TLSA record type and a zone signed with DNSSEC. DANE is optional.

TLS certificate

Nothing is served in the clear, so the node will not start without a certificate. You need one certificate whose names cover:

NameNeeded for
The mail host, for example mail.example.comEvery protocol. Always required.
mta-sts.example.com for each domainServing the domain’s MTA-STS policy.
autoconfig.example.com for each domainThunderbird-style automatic setup, if you publish that name.
autodiscover.example.com for each domainOutlook-style automatic setup, if you publish that name.

You can supply the certificate and key as files, or let the server obtain one over ACME. For a first test, init --self-signed writes a certificate that nobody else will trust. See TLS certificates.

Checklist

Before you go on to the Quick start, make sure you have:

  1. A Linux machine with systemd and a correct clock.
  2. A public address that other servers reach on port 25.
  3. Either outbound port 25 open, or a relay you can authenticate to.
  4. A PTR record for the public address naming the mail host.
  5. Access to your domain’s DNS.
  6. A certificate for the mail host, or port 80 reachable from the internet for ACME.

Something unclear or out of date on this page? Tell us.