diff options
Diffstat (limited to 'content/mail')
| -rw-r--r-- | content/mail/dovecot.md | 112 | ||||
| -rw-r--r-- | content/mail/opendkim.md | 187 | ||||
| -rw-r--r-- | content/mail/rainloop.md | 117 | ||||
| -rw-r--r-- | content/mail/rdns.md | 35 | ||||
| -rw-r--r-- | content/mail/smtp.md | 70 |
5 files changed, 521 insertions, 0 deletions
diff --git a/content/mail/dovecot.md b/content/mail/dovecot.md new file mode 100644 index 0000000..df2b218 --- /dev/null +++ b/content/mail/dovecot.md @@ -0,0 +1,112 @@ +--- +title: "Dovecot Email Server" +draft: true +--- +In the article on [SMTP and Postfix](smtp.html), we set up a simple +Postfix server that we could use to programatically send mail with the +`mail` command. In order to have a true and fully-functional mail +server, we need Dovecot, which can store mails received by the server, +have and authenticate user accounts and interact with mail + +## Installation + + apt install dovecot-imapd dovecot-sieve + +## Certificate + +We will want a SSL certificate for the `mail.` subdomain. We can get +this with [Certbot](certbot.html). Assuming we are using Nginx for our +server otherwise, run: + + certbot --nginx certonly -d mail.example.org + +## DNS + +## Configuring Dovecot + +Dovecot\'s configuration file is in `/etc/dovecot/docevot.conf`. If you +open that file, you will this line: `!include conf.d/*.conf` which adds +all the `.conf` files in `/etc/dovecot/conf.d/` to the Dovecot +configuration. + +One can edit each of these files individually to get the needed +configuration, but to make things easy here, delete or backup the main +configuration file and we will replace it with one single config file +with all important settings in it. + +``` wide +ssl = required +ssl_cert = </etc/letsencrypt/live/mail.example.org/fullchain.pem +ssl_key = </etc/letsencrypt/live/mail.example.org/privkey.pem +ssl_min_protocol = TLSv1.2 +ssl_cipher_list = EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA256:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EDH+aRSA+AESGCM:EDH+aRSA+SHA256:EDH+aRSA:EECDH:!aNULL:!eNULL:!MEDIUM:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED +ssl_prefer_server_ciphers = yes +ssl_dh = </usr/share/dovecot/dh.pem +auth_mechanisms = plain login +auth_username_format = %n + +protocols = $protocols imap + +userdb { + driver = passwd +} +passdb { + driver = pam +} + +mail_location = maildir:~/Mail:INBOX=~/Mail/Inbox:LAYOUT=fs +namespace inbox { + inbox = yes + mailbox Drafts { + special_use = \Drafts + auto = subscribe +} + mailbox Junk { + special_use = \Junk + auto = subscribe + autoexpunge = 30d +} + mailbox Sent { + special_use = \Sent + auto = subscribe +} + mailbox Trash { + special_use = \Trash +} + mailbox Archive { + special_use = \Archive +} +} + +service auth { + unix_listener /var/spool/postfix/private/auth { + mode = 0660 + user = postfix + group = postfix +} +} +``` + +### Settings Explained + +Take a good look at the settings to understand what\'s going on. Some of +the settings include: + +1. SSL settings to allow encrypted connections. +2. Default directories for a mail account: Inbox, Sent, Drafts, Junk, + Trash and Archive. +3. The mail server will authenticate users against PAM/passwd, which + means users you create on the server (so long as they are part of + the `mail` group) will be able to receive and send mail. +4. Create a `unix_listener` that will allow Postfix to authenticate + users via Dovecot. + +```{=html} +<!-- --> +``` + echo "auth required pam_unix.so nullok + account required pam_unix.so" >> /etc/pam.d/dovecot + +## Connecting Postfix and Dovecot + +[[Next:\<++\>](%3C++%3E)]{.next} diff --git a/content/mail/opendkim.md b/content/mail/opendkim.md new file mode 100644 index 0000000..bd8eb5d --- /dev/null +++ b/content/mail/opendkim.md @@ -0,0 +1,187 @@ +--- +title: "Validating your emails with OpenDKIM" +draft: true +tags: ['email'] +--- +Email is a lot like real-life mail. You can send email to anyone, but +you can also write whatever return address you\'d like. That is, it\'s +pretty easy to pretend to be someone else via mail, and that was +originally the case with email as well: email is just text, and you +could just change your `From:` address to any email address you wanted! + +DKIM (Domain Keys Identified Mail) helps solve this issue. + +OpenDKIM will generate a public/private cryptographic key pair for your +server. The public key will be made available publicly in your server\'s +DNS records and the private key will be used to sign every single email +that leaves the server. This means that people receiving mail from your +server can now be absolutely sure that it originated from your server +because their servers can check the cryptographic signature on the email +with the public key! + +OpenDKIM ensures that email originated from the server it claims it did, +but it does not ensure that it originated from the user account it +claims it did. This easier problem is solved by server-side +authorization settings. + +## Installation + +```sh +apt install opendkim opendkim-tools +``` + +## The Keys and Files + +We have to generate the DKIM keys and create some secondary files that +will be required for our configuration. + +### Generate the DKIM key + +<!-- +TODO: Make a unique directory for each domain to later allow multiple domain +DKIM validation for servers serving more than one domain name. +--> + +Here we create directories for the OpenDKIM keys, generate them, and +ensure they have the right file permissions. + +```sh +mkdir -p /etc/postfix/dkim +opendkim-genkey -D /etc/postfix/dkim/ -d example.org -s mail +chgrp opendkim /etc/postfix/dkim/* +chmod g+r /etc/postfix/dkim/* +``` + +### Create the key table + +Now we\'ll tell OpenDKIM where the newly generated keys are on the file +system. + +```sh +echo "mail._domainkey.example.org example.org:mail:/etc/postfix/dkim/mail.private" > /etc/postfix/dkim/keytable +``` + +### Create the signing table + +```sh +echo "*@example.org mail._domainkey.example.org" > /etc/postfix/dkim/signingtable +``` + +### Adding trusted hosts + +```sh +echo "127.0.0.1 +10.1.0.0/16 +1.2.3.4/24" > /etc/postfix/dkim/trustedhosts +``` + +## Configuring opendkim.conf + +Now we have all the raw material, so open up `/etc/opendkim.conf` and we +can finalize our server settings. First, add these lines that will +source the files we just created. + +```yaml +KeyTable file:/etc/postfix/dkim/keytable +SigningTable refile:/etc/postfix/dkim/signingtable +InternalHosts refile:/etc/postfix/dkim/trustedhosts + +Canonicalization relaxed/simple +Socket inet:12301@localhost +``` + +There will already be an uncommented `Socket` directive, so delete, +comment out or replace it with the above. + +## Interfacing with Postfix + +There are a couple things we must add to the Postfix SMTP server +settings to interface it with OpenDKIM. Specifically, we have to set our +OpenDKIM server, which will be running on port `12301`, as a milter +(mail filter). This is easy to do with the four commands below: + +```sh +postconf -e "milter_default_action = accept" +postconf -e "milter_protocol = 6" +postconf -e "smtpd_milters = inet:localhost:12301" +postconf -e "non_smtpd_milters = inet:localhost:12301" +``` + +## Restart and reload Postfix and DKIM + +Now that we have all our settings in place: + +```sh +systemctl restart opendkim +systemctl enable opendkim +systemctl reload postfix +``` + +## Adding the DNS record! + +We are only one step away from having functioning OpenDKIM. We must add +the DKIM public key to our server\'s DNS settings, so go ahead and open +up [your registrar\'s site](https://www.epik.com/?affid=we2ro7sa6) or +wherever your site\'s DNS settings are. + +The public key is found in the file `/etc/postfix/dkim/mail.txt`, but it +will display as multiple lines and multiple quoted strings, which is +annoying and hard to copy-and-paste into your registrar. To make things +easier, run the following command to format the key in the way we need +it for the DNS TXT entry: + +```sh +echo -e " + +v=DKIM1; k=rsa; $(tr -d " +" </etc/postfix/dkim/mail.txt | sed "s/k=rsa.* \"p=/k=rsa; p=/;s/\"\s*\"//;s/\"\s*).*//" | grep -o "p=.*") + +" +``` + +Take the very long output of that command, which will start with +`v=DKIM1` and add it as a TXT entry in your DNS settings as below. The +host we put it for is `mail._domainkey`. + +{{< img alt="Adding the OpenDKIM TXT entry in DNS settings" src="/pix/dkim-01.png" link="/pix/dkim-01.png" >}} + +On my registrar, Epik, this is how it is input, but on some registrars, +it may be required to include your domain name as well as +`mail._domainkey.example.org`. + +If you have your own DNS server, add a TXT entry as follows: + +```txt +mail._domainkey.example.org TXT v=DKIM1; k=rsa; p=ThatLongRandomSequenceOfLettersAndNumbersOfYours +``` + +## Testing it out! + +Now we want to send an email to make sure that your emails will now be +signed with OpenDKIM. + +### Hostname + +If you\'ve followed these instructions, all emails from the domain +**example.org** will now have a DKIM signature on them. If we send mail +via the `mail` command, however, their domain of origin will be whatever +your server\'s hostname is, which you may have set to something +different than your domain. + +You can permanently change your hostname by changing it in +`/etc/hostname` and rebooting, or you can just run +`hostname example.org` to change it temporarily for testing. Either way, +this will allow us to run the `mail` command as in [the SMTP +article](smtp.html). + +```sh +echo "Hi there. + +This is the text." | mail -s "Email from the server" your@emailaddress.com +``` + +### More helpful troubleshooting. + +You can also go to [this site](https://appmaildev.com/en/dkim), which +will help you troubleshoot any other DKIM problems if you mistyped +something. diff --git a/content/mail/rainloop.md b/content/mail/rainloop.md new file mode 100644 index 0000000..f43dbb5 --- /dev/null +++ b/content/mail/rainloop.md @@ -0,0 +1,117 @@ +--- +title: "Rainloop" +tags: ['service'] +icon: 'rainloop.png' +short_desc: 'A graphical website for accessing a mail server.' +--- + + +[Rainloop](https://www.rainloop.net/) +is a webmail client, a program that allows you to access your email +online like Gmail. It is useful to be able to access you email from a +web browser because it allows you to easily access your email from any +device with a web browser without any additional setup. + +If you set up +[Nextcloud](/nextcloud) +then you do not need to install Rainloop because Nextcloud comes with a +webmail client. However, if all you want is a webmail client and you do +not need all of the extra things that Nextcloud provides, Rainloop would +be the better choice out of the two since it is less bloated and simpler +to install. + +## Instructions + +First we will install the required packages for Rainloop with the +following command: + +```sh +apt-get install php7.4 php7.4-common php7.4-curl php7.4-xml php7.4-fpm php7.4-json php7.4-dev php7.4-mysql unzip -y +``` + +Then we will download the community version of Rainloop, unzip it into +an appropriate directory and fix all of the file permissions: + +```sh +curl -L "https://www.rainloop.net/repository/webmail/rainloop-community-latest.zip" -o "rainloop.zip" +unzip rainloop.zip -d /var/www/mail +chown -R www-data: /var/www/mail +``` + +We have installed Rainloop itself, but now we need Nginx to serve the +client. We do that by adding the following text into the file +`/etc/nginx/sites-available/mail` (you can replace the bold text with +whatever is appropriate for your server). + +```nginx +server { + + listen 80; + + server_name mail.example.org ; + root /var/www/mail; + + index index.php; + + access_log /var/log/nginx/rainloop_access.log; + error_log /var/log/nginx/rainloop_error.log; + + location / { + try_files $uri $uri/ /index.php?$query_string; + } + + location ~ \.php$ { + fastcgi_index index.php; + fastcgi_split_path_info ^(.+\.php)(.*)$; + fastcgi_keep_conn on; + fastcgi_pass unix:/var/run/php/php7.4-fpm.sock; + include /etc/nginx/fastcgi_params; + fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; + } + location ~ /\.ht { + deny all; + } + + location ^~ /data { + deny all; + } +} +``` + +Then enable the site by linking it to the sites-enabled directory: + +```sh +ln -s /etc/nginx/sites-available/mail /etc/nginx/sites-enabled/ +``` + +Reload nginx: + +```sh +systemctl reload nginx +``` + +Finally get certifications if you are using a new subdomain: + +```sh +certbot --nginx +``` + +After that go to `mail.example.org/?admin` and login with the default +username and password: admin, 12345. Now you are in the admin panel and +the first thing you do should be to change the adminsitrator password by +looking in the security tab on the left. + +{{< img alt="rainloop" src="/pix/rainloop-1.png" >}} + +After securing the admin account you can go to domains and add your own +email address. + +{{< img alt="rainloop" src="/pix/rainloop-2.png" >}} + +Finally, go to `mail.example.org` and login with your email address and +password. + +## Contribution + +[Deniz Telci](https://deniz.telci.org/) - XMR: +`4AcKbpTUc3QX2zHYdh9HZwJAQyexdybFhF1WhXTFhxAcV9jgzB6kroqGZDgeW3rQqXEMYJioYo61kaLBqstwecty9Bjbr4v` diff --git a/content/mail/rdns.md b/content/mail/rdns.md new file mode 100644 index 0000000..6571d8c --- /dev/null +++ b/content/mail/rdns.md @@ -0,0 +1,35 @@ +--- +title: "rDNS and PTR Records" +draft: true +tags: ['email'] +--- +While [DNS records](dns.html) refer a domain name to the IP address +where the the website is hosted, there is also rDNS (reverse DNS) and +specifically PTR (pointer) records which do the reverse: link a +server\'s IP to a domain name. + +This is important for many things, but especially email. Many email +servers require that other servers that send them mail have PTR records +to prevent spam. + +## Setting your PTR Record + +DNS settings are set with your registrar, while rDNS settings are set +with your server or VPS provider. **Remember to set records for both +IPv4 and IPv6!** + +In [Vultr](https://www.vultr.com/?ref=8384069-6G) we want to set the +IPv4 record, click on the server, then \"Settings,\" and make sure the +\"IPv4\" tab is selected. We can then edit the \"Reverse DNS\" blank +shown below. + +{{< img alt="IPv4 rDNS PTR record set in Vultr" src="/pix/rdns-01.png" >}} + +The setting for IPv6 is obviosuly under the IPv6 tab. Note here that we +copy the full IPv6 address from above and create a new rDNS entry by +pasting that and the domain name in the blanks below. Then just select +\"Add.\" + +{{< img alt="IPv6 rDNS PTR record set in Vultr" src="/pix/rdns-02.png" >}} + +That\'s it! diff --git a/content/mail/smtp.md b/content/mail/smtp.md new file mode 100644 index 0000000..6ce92f2 --- /dev/null +++ b/content/mail/smtp.md @@ -0,0 +1,70 @@ +--- +title: "Setting up a Postfix SMTP server" +draft: true +--- +The first step to setting up an email server is having an SMTP server. +SMTP sends and receives email. Whether we want a full email server or +just the ability to send automated email by script, we will need SMTP, +and Postfix is the standard SMTP server. + +Here let\'s set a server up. Note that our goal is to be able to send +emails from our server. If you want a full email server, this is the +first step, and we will address the rest later. + +## Before beginning! + +Whatever VPS ([Vultr](https://www.vultr.com/?ref=8384069-6G) or +[Frantech](https://my.frantech.ca/aff.php?aff=3886)) or IPS you are +using, it is a very common policy to **automatically block all email +ports by default**. VPS providers do this to prevent spammers from using +their services. + +If you want to start an email server, therefore, go to your VPS\'s site +and open a ticket or make a request to open up email ports. This is a +simple process that requires nothing too special. One of the wagies at +your VPS will kindly do the needful and open your ports for you. Note +that this is not the same as unblocking a port with [ufw](ufw.html). + +## Installation + +First, we install Postfix and also `mailutils`, which comes with some +mail programs we will use. + + apt install -y mailutils postfix + +Installing Postfix for the first time will give us some graphical +options. + + + +When asked for a \"mail name\", give your full domain name from which +you would like mail to come and go, e.g. [example.org]{.dfn} or +[landchad.net]{.dfn}. + + + +## Test the email + +That is actually all you need to have set up to have a barebones, +send-only email server. We can test our server by running a `mail` +command like that below. + + echo "Hi there. + + This is the text." | mail -s "Email from the server" your@emailaddress.com + +And that is simply enough the command your server can run to send mail. +Note that we use the `-s` option to specify the email\'s subject while +we pipe the email content into the `mail` command via standard input. In +this example I use a quoted multiline email as an example. + +## Do you see your message? + +If you sent the above test message to an account on Gmail or another +major email provider, there is **very high** chance of the message you +sent above being marked as spam or not appearing at all! + +Don\'t worry, we\'ll take care of that in the next two articles where we +set up rDNS and OpenDKIM to validate the emails you send. + +[[Next: rDNS and PTR Records](rdns.html)]{.next} |
