Back to articles
Technology Insight

Professional Mail Server Configuration on VPS: Complete Guide with Postfix, Dovecot, and Roundcube

May 17, 2026

Introduction: Why Build Your Own Professional Mail Server?

In an era dominated by cloud-based email services, the decision to host your own mail server on a Virtual Private Server (VPS) represents a strategic move toward enhanced control, security, and cost efficiency. A professionally configured mail server grants you complete sovereignty over your communication data, eliminates recurring subscription fees for user accounts, and allows for deep customization of security policies and spam filtering. While services like Google Workspace or Microsoft 365 offer convenience, they come with ongoing costs and place your sensitive correspondence on third-party infrastructure.

This guide provides a comprehensive, production-ready blueprint for deploying a robust email system using the industry-standard open-source stack: Postfix as the Mail Transfer Agent (MTA), Dovecot as the IMAP/POP3 server, and Roundcube as the webmail interface. When correctly configured, this trio delivers performance and reliability that rivals commercial offerings.

Prerequisites and Initial VPS Setup

Before beginning the mail server installation, ensure your VPS environment meets the necessary requirements and is properly secured.

System Requirements

  • Operating System: A recent, stable release of Ubuntu Server (22.04 LTS or 24.04 LTS) or Debian (11 or 12). This guide uses Ubuntu for command examples.
  • VPS Specifications: Minimum 1 GB RAM (2 GB recommended), 20 GB SSD storage, and a static public IP address.
  • Domain Name: A registered domain (e.g., yourcompany.com) with full DNS management access.
  • Network: Open ports in the VPS firewall: 25 (SMTP), 465 (SMTPS), 587 (Submission), 143 (IMAP), 993 (IMAPS), 80 (HTTP), and 443 (HTTPS).

Essential Preliminary Steps

Connect to your VPS via SSH and execute the following foundational commands:

  1. System Update: sudo apt update && sudo apt upgrade -y
  2. Set Hostname: Configure the server's hostname to match your mail domain (e.g., mail.yourcompany.com) using sudo hostnamectl set-hostname mail.yourcompany.com and update the /etc/hosts file accordingly.
  3. Configure DNS Records: This is a critical step for email deliverability. Create the following records for your domain:
    • A Record: mail.yourcompany.com pointing to your VPS's IP address.
    • MX Record: Point yourcompany.com to mail.yourcompany.com with a priority of 10.
    • PTR Record (Reverse DNS): Request your VPS provider to set a PTR record for your IP address that resolves back to mail.yourcompany.com. This is vital for passing spam filters.
    • SPF Record: A TXT record like v=spf1 mx a:mail.yourcompany.com -all to authorize your server to send mail for your domain.
    • DKIM Record: A DNS TXT record containing a public key, which we will generate later during Postfix configuration.
    • DMARC Record: A TXT record for _dmarc.yourcompany.com with a policy, e.g., v=DMARC1; p=none; rua=mailto:[email protected].

Installing and Configuring Postfix (SMTP Server)

Postfix handles the sending and receiving of email between servers (SMTP). We will configure it for security and authentication.

Installation and Basic Configuration

Install Postfix and choose "Internet Site" during the package configuration dialog. Set the system mail name to your primary domain (e.g., yourcompany.com).

Next, edit the main configuration file /etc/postfix/main.cf. The following directives are essential for a professional setup:

myhostname = mail.yourcompany.com
mydomain = yourcompany.com
myorigin = $mydomain
mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
inet_interfaces = all
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
home_mailbox = Maildir/
smtpd_banner = $myhostname ESMTP
# Security & Authentication
smtpd_tls_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem
smtpd_tls_key_file=/etc/ssl/private/ssl-cert-snakeoil.key
smtpd_use_tls=yes
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination

Enabling SMTP Submission and Authentication

Modern email clients use port 587 (Submission) with STARTTLS for secure authentication. Configure this in /etc/postfix/master.cf by uncommenting and modifying the submission service lines:

submission inet n       -       y       -       -       smtpd
  -o syslog_name=postfix/submission
  -o smtpd_tls_security_level=encrypt
  -o smtpd_sasl_auth_enable=yes
  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
  -o milter_macro_daemon_name=ORIGINATING

This configuration mandates encryption and SASL authentication for client connections on port 587.

Installing and Configuring Dovecot (IMAP/POP3 Server)

Dovecot provides secure IMAP and POP3 access, allowing users to retrieve their mail using clients like Thunderbird or mobile apps.

Installation and Core Setup

Install Dovecot and its SASL module: sudo apt install dovecot-core dovecot-imapd dovecot-lmtpd dovecot-sqlite.

The primary configuration is split across files in /etc/dovecot/conf.d/. Key edits include:

  • In 10-mail.conf, ensure mail_location = maildir:~/Maildir to match Postfix.
  • In 10-auth.conf, set auth_mechanisms = plain login and disable insecure authentication: disable_plaintext_auth = yes.
  • In 10-ssl.conf, specify paths to SSL certificates (ssl_cert and ssl_key). For production, replace the self-signed snakeoil certificates with ones from Let's Encrypt.

Integrating Dovecot SASL with Postfix

To allow Postfix to use Dovecot for user authentication, configure the Dovecot SASL socket. In /etc/dovecot/conf.d/10-master.conf, uncomment or add the following service listener:

service auth {
  unix_listener /var/spool/postfix/private/auth {
    mode = 0660
    user = postfix
    group = postfix
  }
}

Then, instruct Postfix to use this socket by adding these lines to /etc/postfix/main.cf:

smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_auth_enable = yes

Managing Virtual Users and Domains

For a professional server hosting multiple domains and users without creating system accounts, we use a virtual user system. The simplest method is using dovecot and postfix with a passwd-like file.

  1. Create a file to store virtual users and their encrypted passwords, e.g., /etc/dovecot/users.
  2. Add users in the format [email protected]:{PLAIN}password. For better security, use {SHA512-CRYPT} with a hashed password generated by doveadm pw -s SHA512-CRYPT.
  3. Configure Dovecot to use this file in /etc/dovecot/conf.d/10-auth.conf:
    auth_mechanisms = plain login
    passdb {
      driver = passwd-file
      args = scheme=SHA512-CRYPT username_format=%u /etc/dovecot/users
    }
    userdb {
      driver = static
      args = uid=vmail gid=vmail home=/var/mail/vhosts/%d/%n
    }
    
  4. Create a corresponding user database for Postfix (e.g., /etc/postfix/virtual_mailbox_domains and /etc/postfix/virtual_mailbox_maps) and map them in main.cf.

This approach cleanly separates mail accounts from system accounts, enhancing security.

Installing and Securing Roundcube Webmail

Roundcube provides a modern, browser-based interface for users to access their email.

Installation via Package Manager

The easiest method is using the distribution's package: sudo apt install roundcube roundcube-core roundcube-mysql roundcube-plugins. During installation, configure it to use the existing database (if any) or set up a new one.

Manual Configuration for Control

For more control, you can download the latest version from the Roundcube website, extract it to your web root (e.g., /var/www/roundcube), and run the installer via browser at https://mail.yourcompany.com/installer/. Key configuration points in /var/www/roundcube/config/config.inc.php include:

$config['db_dsnw'] = 'mysql://roundcubeuser:password@localhost/roundcubedb';
$config['default_host'] = 'ssl://localhost';
$config['default_port'] = 993;
$config['smtp_server'] = 'tls://localhost';
$config['smtp_port'] = 587;
$config['smtp_user'] = '%u';
$config['smtp_pass'] = '%p';
$config['support_url'] = '';
$config['product_name'] = 'YourCompany Webmail';
$config['plugins'] = array('managesieve', 'password');

Securing the Webmail Interface

  • Force HTTPS by configuring your web server (Apache2 or Nginx) to redirect all HTTP traffic.
  • Set up HTTP security headers (HSTS, CSP) in your web server configuration.
  • Change the default /installer directory name or restrict access to it via IP after setup.
  • Keep Roundcube and its plugins updated regularly via the package manager or the built-in update mechanism.

Advanced Security and Spam Protection

A professional mail server must be fortified against abuse and spam.

Implementing DKIM Signing

DomainKeys Identified Mail (DKIM) cryptographically signs outgoing emails, proving they originated from your domain and were not tampered with. Install OpenDKIM and integrate it with Postfix:

  1. Install: sudo apt install opendkim opendkim-tools.
  2. Edit /etc/opendkim.conf to set your domain, selector (e.g., mail), and key file locations.
  3. Generate a DKIM key pair: sudo opendkim-genkey -s mail -d yourcompany.com.
  4. Add the public key (from the .txt file) to your DNS as a TXT record for mail._domainkey.yourcompany.com.
  5. Configure Postfix to sign mail via the milter protocol by adding milter_protocol = 2 and milter_default_action = accept to main.cf.

Deploying SpamAssassin

To filter incoming spam, install SpamAssassin and integrate it with Postfix as a milter or content filter.

  1. Install: sudo apt install spamassassin spamc.
  2. Enable and start the spamassassin service.
  3. Configure Postfix to pipe incoming mail through spamc by adding a content filter in master.cf and adjusting main.cf settings.
  4. Train the Bayesian filter by moving false positives/negatives to the appropriate folders, improving accuracy over time.

Ongoing Maintenance and Monitoring

Deployment is only the beginning. A professional setup requires vigilant maintenance.

  • Log Monitoring: Regularly check /var/log/mail.log for errors, authentication failures, or signs of abuse.
  • SSL Certificate Renewal: If using Let's Encrypt, automate renewal with a cron job for certbot renew.
  • Software Updates: Apply security updates for Postfix, Dovecot, Roundcube, and the operating system promptly.
  • Backup Strategy: Implement regular backups of mail data (/var/mail/vhosts), configuration files, and database contents.
  • Performance Tuning: Monitor resource usage. Adjust Postfix process limits and Dovecot worker counts in their configuration files based on your server's load.

Conclusion: Achieving Email Independence

Building a professional mail server on a VPS is a significant undertaking that pays substantial dividends in control, security, and long-term cost savings. By meticulously following this guide—configuring Postfix for secure SMTP, Dovecot for robust IMAP, and Roundcube for accessible webmail—you establish a private, reliable communication hub for your organization. The initial investment in setup and security hardening creates a resilient infrastructure that you own outright, free from the constraints and policies of external providers. Remember, the key to success lies not just in the initial deployment but in the commitment to ongoing monitoring, updates, and security practices. Your professional mail server is now ready to serve as the cornerstone of your independent digital communication strategy.