Back to articles
Technology Insight

Deploying Stalwart Mail Server on a VPS: The Ultimate Secure, All-in-One Rust-Based Email Solution

May 30, 2026

Introduction: The Evolution of Modern Email Infrastructure

For years, setting up a self-hosted email server felt like assembling a complex puzzle in the dark. System administrators had to string together disparate open-source components: Postfix for SMTP, Dovecot for IMAP, SpamAssassin for filtering, and OpenDKIM for signing. Managing this fragile stack required significant overhead, and a single configuration drift could break mail delivery or expose vulnerabilities.

Enter Stalwart Mail Server. Written entirely in Rust, Stalwart is a modern, all-in-one open-source email server designed for security, blazing-fast performance, and memory safety. By consolidating SMTP, IMAP, and JMAP into a single unified binary, it drastically simplifies deployment while offering next-generation security features out of the box. In this guide, we will walk you through deploying and configuring Stalwart Mail Server on a Virtual Private Server (VPS) to achieve maximum deliverability and enterprise-grade data privacy.

Why Choose Stalwart Mail Server?

Before diving into the installation, it is crucial to understand why Stalwart represents a paradigm shift for self-hosted email infrastructure:

  • Memory Safety with Rust: Email servers are prime targets for remote code execution attacks. Rust’s strict compile-time checks eliminate common vulnerabilities like buffer overflows and memory leaks.
  • All-in-One Architecture: It natively handles SMTP (sending/receiving), IMAP/JMAP (client access), and internal identity management, eliminating the need to stitch multiple tools together.
  • Next-Gen Protocols: Full native support for JMAP (JSON Meta Application Protocol), offering a faster, mobile-friendly, and more efficient alternative to legacy IMAP.
  • Advanced Security Frameworks: Built-in support for SPF, DKIM, DMARC, ARC, DANE, and MTA-STS to ensure your emails land in the inbox, not the spam folder.
---

Prerequisites and Environment Setup

To follow this guide successfully, you will need the following baseline infrastructure:

  1. A Cloud VPS: Running a clean installation of Ubuntu 22.04 LTS or Debian 12. Ensure your provider does not block outbound port 25 (e.g., Linode, DigitalOcean, or Hetzner usually require a request to unblock it).
  2. A Fully Qualified Domain Name (FQDN): For this guide, we will use mail.yourdomain.com.
  3. Root or Sudo Access: A non-root user with administrative privileges.

Step 1: System Update and Hostname Configuration

First, update your package lists and ensure your server’s hostname matches your mail domain. Log into your VPS via SSH and execute:

sudo apt update && sudo apt upgrade -y
sudo hostnamectl set-hostname mail.yourdomain.com

Verify the change by running hostname -f. It should output your exact FQDN.

---

Installing Stalwart Mail Server

Stalwart offers multiple installation methods, including Docker and pre-compiled binaries. For optimal control and performance, we will use the automated shell script installation, which sets up Stalwart as a systemd service.

Step 2: Run the Official Installer

Execute the official installation script to download the latest stable release of Stalwart:

sudo bash -c "$(curl -fsSL [https://stalwart.io/arch.sh](https://stalwart.io/arch.sh))"

The installer will automatically detect your architecture, download the binary, create a dedicated stalwart-mail user, and set up the default directory structures. By default, configuration files reside in /opt/stalwart-mail/etc/ and data is stored in /opt/stalwart-mail/data/.

Step 3: Managing the Stalwart Service

Enable and start the Stalwart service using systemd:

sudo systemctl enable --now stalwart-mail
sudo systemctl status stalwart-mail

Ensure the status shows as active (running) before proceeding.

---

Crucial Network and DNS Configuration

An email server is only as good as its DNS reputation. Without accurate records, major providers like Google and Microsoft will reject your emails immediately.

1. Configure the Reverse DNS (PTR Record)

Log into your VPS provider's control panel and locate the networking section. Set the Reverse DNS (PTR) record for your server's public IP address to map back exactly to your mail domain: mail.yourdomain.com. This proves your server is legitimate.

2. Add Core DNS Records

Navigate to your domain registrar’s DNS management dashboard and create the following records:

TypeHost / NameValue / TargetTTL
Amail[Your VPS Public IP]Automatic/1 Hour
MX@mail.yourdomain.com (Priority: 10)Automatic/1 Hour
TXT@v=spf1 mx ip4:[Your VPS Public IP] -allAutomatic/1 Hour
Security Note: The -all mechanism in the SPF record indicates a strict fail policy, advising receiving servers to reject any emails originating from IPs not explicitly listed here.
---

Configuring TLS Certificates via Let's Encrypt

Modern email communication requires absolute encryption. We will use Certbot to provision a free, automated TLS certificate from Let's Encrypt to secure SMTP over TLS and web management interfaces.

sudo apt install certbot -y
sudo certbot certonly --standalone -d mail.yourdomain.com

Once generated, grant the stalwart-mail user permission to read the certificates:

sudo chown -R root:stalwart-mail /etc/letsencrypt/live/
sudo chown -R root:stalwart-mail /etc/letsencrypt/archive/
---

Accessing the Management Interface & Fine-Tuning Authentication

Stalwart features a state-of-the-art built-in web administrator console. By default, it binds to localhost or protected ports. During the initial setup, you can access the setup wizard via your browser at [https://mail.yourdomain.com:8443](https://mail.yourdomain.com:8443) or via the port configured during script execution.

Step 4: DKIM and DMARC Implementation

Inside the Stalwart web management console:

  • Navigate to Settings > Keys > DKIM.
  • Generate a new 2048-bit DKIM key for your domain using the selector stalwart.
  • Copy the generated public key text and publish it as a TXT record in your DNS zone: stalwart._domainkey.yourdomain.com.

Finally, publish your DMARC policy to monitor and enforce email authentication:

Type: TXT
Host: _dmarc.yourdomain.com
Value: v=DMARC1; p=quarantine; pct=100; rua=mailto:[email protected]
---

Conclusion and Verification

You have now successfully deployed an enterprise-grade, memory-safe Stalwart Mail Server on your VPS. With its integrated Rust-driven architecture, your system uses fewer resources while boasting superior defense against modern security threats. Before sending broad marketing materials or enterprise communications, use tools like Mail-Tester to verify your SPF, DKIM, and network configuration to guarantee a perfect 10/10 deliverability score.

Deploying Stalwart Mail Server on a VPS: The Ultimate Secure, All-in-One Rust-Based Email Solution | DPTCloud