Simple and complete declarative NixOS Mailserver setups
Find a file
emilylange b47decd71a
docs: update roundcube example to use implicit TLS
instead of explicit TLS (STARTTLS).

We disabled STARTTLS for IMAP by default in 54f37811dd
and we will likely do the same for (client) SMTP in the future.
2025-11-28 21:53:41 +01:00
.hydra Release 25.11 2025-11-25 13:56:52 +01:00
docs docs: update roundcube example to use implicit TLS 2025-11-28 21:53:41 +01:00
mail-server rspamd: fix DKIM signing for subdomains 2025-11-16 19:29:16 +01:00
migrations migrations: strongly indicate dry runs 2025-11-26 20:21:56 +01:00
scripts scripts/generate-options: prefer defaultText over default 2025-11-11 13:45:03 +01:00
tests Use postfix-tlspol for DANE/MTA-STS policy lookups 2025-11-08 15:49:34 +01:00
.editorconfig Remove makefile section from editorconfig 2017-11-11 09:47:25 +00:00
.envrc Provide direnv integration for flake devshell 2025-05-15 16:29:03 +02:00
.gitignore Provide direnv integration for flake devshell 2025-05-15 16:29:03 +02:00
.gitlab-ci.yml ci: use hydra-cli from pinned nixpkgs 2025-05-10 21:18:17 +02:00
.readthedocs.yaml docs: fix Read the Docs by using portable-nix 2025-11-05 01:10:52 +01:00
default.nix Add support for sender rewriting using postsrsd 2025-11-11 13:45:03 +01:00
flake.lock flake.lock: Update 2025-11-25 14:05:20 +01:00
flake.nix Add support for sender rewriting using postsrsd 2025-11-11 13:45:03 +01:00
LICENSE Initial commit 2016-07-21 18:09:04 +02:00
pyproject.toml ruff: reject implicit string concat 2025-07-09 03:59:54 +02:00
README.md Release 25.11 2025-11-25 13:56:52 +01:00
shell.nix treewide: reformat with nixfmt-rfc-style 2025-06-15 03:39:44 +02:00

Simple Nixos MailServer

license pipeline status

Release branches

For each NixOS release, we publish a branch. You then have to use the SNM branch corresponding to your NixOS version.

Features

  • Continous Integration Testing
  • Multiple Domains
  • Postfix
    • SMTP on port 25
    • Submission TLS on port 465
    • Submission StartTLS on port 587
    • LMTP with Dovecot
    • DANE and MTA-STS validation
    • SMTP TLS Reports (RFC 8460)
  • Dovecot
    • Maildir folders
    • IMAP with TLS on port 993
    • POP3 with TLS on port 995
    • IMAP with StartTLS on port 143
    • POP3 with StartTLS on port 110
  • Certificates
    • ACME
    • Custom certificates
  • Spam Filtering
    • Via Rspamd
  • Virus Scanning
    • Via ClamAV
  • DKIM Signing
    • Via Rspamd
  • User Management
    • Declarative user management
    • Declarative password management
    • LDAP users
  • Sieve
    • Allow user defined sieve scripts
    • Moving mails from/to junk trains the Bayes filter
    • ManageSieve support
  • User Aliases
    • Regular aliases
    • Catch all aliases
  • Improve the Forwarding Experience

In the future

  • Automatic client configuration
  • DKIM Signing
    • Allow per domain selectors
    • Allow passing DKIM signing keys
  • Improve the Forwarding Experience
  • User management
    • Allow local and LDAP user to coexist
  • OpenID Connect
    • Depends on relevant clients adding support, e.g. Thunderbird

Get in touch

How to Set Up a 10/10 Mail Server Guide

Check out the Setup Guide in the project's documentation.

For a complete list of options, see in readthedocs.

Development

See the How to Develop SNM documentation page.

Contributors

See the contributor tab

Alternative Implementations

Credits