Back to articles
Technology Insight

Deploying Stalwart Mail Server on a VPS: The Ultimate Secure, Rust-Powered, AI-Anti-Spam All-in-One Email Solution

May 30, 2026

Introduction: The Evolution of Enterprise Email Infrastructure

For over two decades, setting up a self-hosted email server has been notoriously complicated. System administrators have traditionally been forced to stitch together fragmented software suites: Postfix for routing, Dovecot for IMAP delivery, Rspamd for filtering, and separate databases for user management. This legacy approach introduces significant configuration friction, security vulnerabilities, and heavy resource consumption.

Enter Stalwart Mail Server, a revolutionary, next-generation email server written entirely in Rust. Designed from the ground up as a secure, all-in-one (AoI) solution, Stalwart unifies SMTP, IMAP, and JMAP services into a single binary. It boasts cutting-edge enterprise features, including native AI-driven anti-spam filtering, automated encryption, and cryptographic identity verification. In this comprehensive guide, we will walk through the architectural benefits of Stalwart and provide a step-by-step blueprint for configuring it on a Virtual Private Server (VPS).

---

Why Stalwart Mail Server? The Rust Advantage

Choosing a mail server infrastructure requires balancing reliability, security, and performance. Stalwart stands out by addressing the structural flaws of older mail daemons through modern software engineering:

  • Memory Safety via Rust: Legacy mail servers written in C/C++ are inherently prone to buffer overflows and memory leaks. Rust's strict compile-time guarantees eliminate these vulnerabilities, rendering Stalwart highly resilient against remote code execution (RCE) attacks.
  • Ultra-Lightweight Footprint: Unlike Java or heavy Python-based mail stacks, Stalwart operates with minimal CPU and RAM overhead, making it ideal for cost-effective VPS environments.
  • Native JMAP Support: Alongside traditional IMAP and SMTP, Stalwart natively implements JMAP (JSON Meta Application Protocol), offering a faster, mobile-friendly, and stateless alternative for modern email clients.
  • AI-Powered Anti-Spam: Instead of relying solely on rigid rule-based filtering, Stalwart features a built-in spam filter equipped with statistical classifiers and machine learning capabilities to adapt dynamically to emerging phishing and spam techniques.
---

Prerequisites for VPS Deployment

Before initiating the installation, ensure your environment meets the following baseline requirements:

  1. VPS OS: A clean installation of Linux (Ubuntu 22.04 LTS or Debian 12 recommended).
  2. Network Specifications: A dedicated public IPv4 and/or IPv6 address. Crucially, verify with your VPS provider that Port 25 (SMTP) is unblocked for outbound traffic.
  3. Domain Name: A registered domain name with full access to DNS management records.
  4. Hardware Allocations: Minimum 1 vCPU, 1 GB RAM, and SSD storage (scale according to your anticipated mailbox volumes).
---

Step 1: Preparing DNS Records (The Foundation of Email Deliverability)

Proper DNS configuration is the single most critical factor in ensuring your emails bypass receiver spam folders. Before running the Stalwart installer, configure the following records within your DNS zone file:

A and AAAA Records

Map your mail server's Fully Qualified Domain Name (FQDN) to your VPS IP addresses:

mail.yourdomain.com. IN A 192.0.2.55
mail.yourdomain.com. IN AAAA 2001:db8::55

MX Record

Direct incoming mail traffic to your Stalwart server:

yourdomain.com. IN MX 10 mail.yourdomain.com.

SPF, DKIM, and DMARC (Email Authentication)

To establish cryptographic trust and protect your domain from spoofing, deploy these security TXT records:

  • SPF (Sender Policy Framework): Authorizes your VPS IP to send mail on behalf of your domain.
    yourdomain.com. IN TXT "v=spf1 mx ip4:192.0.2.55 ~all"
  • DKIM (DomainKeys Identified Mail): Stalwart automatically generates a public key during setup. You will add this as a TXT record (e.g., stalwart._domainkey.yourdomain.com) to sign outgoing emails digitally.
  • DMARC: Instructs receiving servers how to handle emails that fail SPF/DKIM checks.
    _dmarc.yourdomain.com. IN TXT "v=DMARC1; p=quarantine; pct=100;"
---

Step 2: Installing Stalwart Mail Server via Docker

While Stalwart can be compiled directly from source or run via binary scripts, deploying via Docker Compose offers the highest level of isolation, portability, and ease of maintenance.

1. Install Docker and Docker Compose

Connect to your VPS via SSH and update your system packages:

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose-plugin -y

2. Create the Configuration Directory

mkdir -p /opt/stalwart-mail
cd /opt/stalwart-mail

3. Configure the docker-compose.yml File

Create a new docker-compose.yml file using your preferred text editor:

version: '3.8'

services:
  stalwart-mail:
    image: stalwartlabs/mail-server:latest
    container_name: stalwart-mail
    restart: unless-stopped
    ports:
      - "25:25"
      - "143:143"
      - "465:465"
      - "587:587"
      - "993:993"
      - "443:443"
    volumes:
      - ./data:/opt/stalwart-mail/data
      - ./etc:/opt/stalwart-mail/etc

Launch the container in detached mode:

sudo docker compose up -d
---

Step 3: Initial Setup and Web Administrator Console

Upon initial launch, Stalwart generates a secure, randomized administrator password within its container logs. Retrieve this credential by executing:

sudo docker logs stalwart-mail | grep "Admin password"

Navigate to https://your-vps-ip or [https://mail.yourdomain.com](https://mail.yourdomain.com) in your browser. Stalwart includes an automated ACME client that provisions Let's Encrypt TLS certificates dynamically. Log into the administrative dashboard using the username admin and the retrieved password.

Inside the dashboard, follow the intuitive setup wizard to:

  1. Verify your primary domain name.
  2. Extract the generated DKIM public key and append it to your DNS records.
  3. Create your primary organization accounts and administrator mailboxes.
---

Step 4: Activating the AI-Driven Anti-Spam Filter

One of Stalwart's crown jewels is its integrated anti-spam system. Unlike legacy filters that require complex third-party configurations, Stalwart integrates Bayesian learning, automated heuristics, and machine learning structures out-of-the-box.

How to Train the Filter

To achieve peak accuracy, navigate to the Anti-Spam Settings within the administrative UI. Enable the automated training pipelines:

  • Ham Learning: Outgoing emails or messages manually marked as safe by authenticated users train the model on standard communication patterns.
  • Spam Learning: Moving unwanted emails into the "Junk" folder automatically triggers an internal analysis, extracting metadata, headers, and NLP signals to reinforce the local AI model.
  • DNSBL Integration: Supplement the AI filter by toggling verified Real-time Blackhole Lists (RBLs) to block known malicious IP ranges at the connection phase.
---

Conclusion: Future-Proofing Your Email Infrastructure

By transitioning from a cumbersome legacy mail stack to Stalwart Mail Server, you elevate your organization's communication infrastructure. The unique intersection of Rust's memory safety, streamlined single-binary architecture, and intelligent AI-driven threat mitigation offers a enterprise-grade environment on a modest VPS budget.

As privacy regulations tighten and email-borne security threats mature, self-hosting with modern tooling is no longer a luxury—it is a strategic asset. Deploy Stalwart today to reclaim total sovereignty over your corporate data.