summaryrefslogtreecommitdiff
path: root/content/mail
diff options
context:
space:
mode:
Diffstat (limited to 'content/mail')
-rw-r--r--content/mail/dovecot.md112
-rw-r--r--content/mail/opendkim.md187
-rw-r--r--content/mail/rainloop.md117
-rw-r--r--content/mail/rdns.md35
-rw-r--r--content/mail/smtp.md70
5 files changed, 521 insertions, 0 deletions
diff --git a/content/mail/dovecot.md b/content/mail/dovecot.md
new file mode 100644
index 0000000..df2b218
--- /dev/null
+++ b/content/mail/dovecot.md
@@ -0,0 +1,112 @@
+---
+title: "Dovecot Email Server"
+draft: true
+---
+In the article on [SMTP and Postfix](smtp.html), we set up a simple
+Postfix server that we could use to programatically send mail with the
+`mail` command. In order to have a true and fully-functional mail
+server, we need Dovecot, which can store mails received by the server,
+have and authenticate user accounts and interact with mail
+
+## Installation
+
+ apt install dovecot-imapd dovecot-sieve
+
+## Certificate
+
+We will want a SSL certificate for the `mail.` subdomain. We can get
+this with [Certbot](certbot.html). Assuming we are using Nginx for our
+server otherwise, run:
+
+ certbot --nginx certonly -d mail.example.org
+
+## DNS
+
+## Configuring Dovecot
+
+Dovecot\'s configuration file is in `/etc/dovecot/docevot.conf`. If you
+open that file, you will this line: `!include conf.d/*.conf` which adds
+all the `.conf` files in `/etc/dovecot/conf.d/` to the Dovecot
+configuration.
+
+One can edit each of these files individually to get the needed
+configuration, but to make things easy here, delete or backup the main
+configuration file and we will replace it with one single config file
+with all important settings in it.
+
+``` wide
+ssl = required
+ssl_cert = </etc/letsencrypt/live/mail.example.org/fullchain.pem
+ssl_key = </etc/letsencrypt/live/mail.example.org/privkey.pem
+ssl_min_protocol = TLSv1.2
+ssl_cipher_list = EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA256:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EDH+aRSA+AESGCM:EDH+aRSA+SHA256:EDH+aRSA:EECDH:!aNULL:!eNULL:!MEDIUM:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED
+ssl_prefer_server_ciphers = yes
+ssl_dh = </usr/share/dovecot/dh.pem
+auth_mechanisms = plain login
+auth_username_format = %n
+
+protocols = $protocols imap
+
+userdb {
+ driver = passwd
+}
+passdb {
+ driver = pam
+}
+
+mail_location = maildir:~/Mail:INBOX=~/Mail/Inbox:LAYOUT=fs
+namespace inbox {
+ inbox = yes
+ mailbox Drafts {
+ special_use = \Drafts
+ auto = subscribe
+}
+ mailbox Junk {
+ special_use = \Junk
+ auto = subscribe
+ autoexpunge = 30d
+}
+ mailbox Sent {
+ special_use = \Sent
+ auto = subscribe
+}
+ mailbox Trash {
+ special_use = \Trash
+}
+ mailbox Archive {
+ special_use = \Archive
+}
+}
+
+service auth {
+ unix_listener /var/spool/postfix/private/auth {
+ mode = 0660
+ user = postfix
+ group = postfix
+}
+}
+```
+
+### Settings Explained
+
+Take a good look at the settings to understand what\'s going on. Some of
+the settings include:
+
+1. SSL settings to allow encrypted connections.
+2. Default directories for a mail account: Inbox, Sent, Drafts, Junk,
+ Trash and Archive.
+3. The mail server will authenticate users against PAM/passwd, which
+ means users you create on the server (so long as they are part of
+ the `mail` group) will be able to receive and send mail.
+4. Create a `unix_listener` that will allow Postfix to authenticate
+ users via Dovecot.
+
+```{=html}
+<!-- -->
+```
+ echo "auth required pam_unix.so nullok
+ account required pam_unix.so" >> /etc/pam.d/dovecot
+
+## Connecting Postfix and Dovecot
+
+[[Next:\<++\>](%3C++%3E)]{.next}
diff --git a/content/mail/opendkim.md b/content/mail/opendkim.md
new file mode 100644
index 0000000..bd8eb5d
--- /dev/null
+++ b/content/mail/opendkim.md
@@ -0,0 +1,187 @@
+---
+title: "Validating your emails with OpenDKIM"
+draft: true
+tags: ['email']
+---
+Email is a lot like real-life mail. You can send email to anyone, but
+you can also write whatever return address you\'d like. That is, it\'s
+pretty easy to pretend to be someone else via mail, and that was
+originally the case with email as well: email is just text, and you
+could just change your `From:` address to any email address you wanted!
+
+DKIM (Domain Keys Identified Mail) helps solve this issue.
+
+OpenDKIM will generate a public/private cryptographic key pair for your
+server. The public key will be made available publicly in your server\'s
+DNS records and the private key will be used to sign every single email
+that leaves the server. This means that people receiving mail from your
+server can now be absolutely sure that it originated from your server
+because their servers can check the cryptographic signature on the email
+with the public key!
+
+OpenDKIM ensures that email originated from the server it claims it did,
+but it does not ensure that it originated from the user account it
+claims it did. This easier problem is solved by server-side
+authorization settings.
+
+## Installation
+
+```sh
+apt install opendkim opendkim-tools
+```
+
+## The Keys and Files
+
+We have to generate the DKIM keys and create some secondary files that
+will be required for our configuration.
+
+### Generate the DKIM key
+
+<!--
+TODO: Make a unique directory for each domain to later allow multiple domain
+DKIM validation for servers serving more than one domain name.
+-->
+
+Here we create directories for the OpenDKIM keys, generate them, and
+ensure they have the right file permissions.
+
+```sh
+mkdir -p /etc/postfix/dkim
+opendkim-genkey -D /etc/postfix/dkim/ -d example.org -s mail
+chgrp opendkim /etc/postfix/dkim/*
+chmod g+r /etc/postfix/dkim/*
+```
+
+### Create the key table
+
+Now we\'ll tell OpenDKIM where the newly generated keys are on the file
+system.
+
+```sh
+echo "mail._domainkey.example.org example.org:mail:/etc/postfix/dkim/mail.private" > /etc/postfix/dkim/keytable
+```
+
+### Create the signing table
+
+```sh
+echo "*@example.org mail._domainkey.example.org" > /etc/postfix/dkim/signingtable
+```
+
+### Adding trusted hosts
+
+```sh
+echo "127.0.0.1
+10.1.0.0/16
+1.2.3.4/24" > /etc/postfix/dkim/trustedhosts
+```
+
+## Configuring opendkim.conf
+
+Now we have all the raw material, so open up `/etc/opendkim.conf` and we
+can finalize our server settings. First, add these lines that will
+source the files we just created.
+
+```yaml
+KeyTable file:/etc/postfix/dkim/keytable
+SigningTable refile:/etc/postfix/dkim/signingtable
+InternalHosts refile:/etc/postfix/dkim/trustedhosts
+
+Canonicalization relaxed/simple
+Socket inet:12301@localhost
+```
+
+There will already be an uncommented `Socket` directive, so delete,
+comment out or replace it with the above.
+
+## Interfacing with Postfix
+
+There are a couple things we must add to the Postfix SMTP server
+settings to interface it with OpenDKIM. Specifically, we have to set our
+OpenDKIM server, which will be running on port `12301`, as a milter
+(mail filter). This is easy to do with the four commands below:
+
+```sh
+postconf -e "milter_default_action = accept"
+postconf -e "milter_protocol = 6"
+postconf -e "smtpd_milters = inet:localhost:12301"
+postconf -e "non_smtpd_milters = inet:localhost:12301"
+```
+
+## Restart and reload Postfix and DKIM
+
+Now that we have all our settings in place:
+
+```sh
+systemctl restart opendkim
+systemctl enable opendkim
+systemctl reload postfix
+```
+
+## Adding the DNS record!
+
+We are only one step away from having functioning OpenDKIM. We must add
+the DKIM public key to our server\'s DNS settings, so go ahead and open
+up [your registrar\'s site](https://www.epik.com/?affid=we2ro7sa6) or
+wherever your site\'s DNS settings are.
+
+The public key is found in the file `/etc/postfix/dkim/mail.txt`, but it
+will display as multiple lines and multiple quoted strings, which is
+annoying and hard to copy-and-paste into your registrar. To make things
+easier, run the following command to format the key in the way we need
+it for the DNS TXT entry:
+
+```sh
+echo -e "
+
+v=DKIM1; k=rsa; $(tr -d "
+" </etc/postfix/dkim/mail.txt | sed "s/k=rsa.* \"p=/k=rsa; p=/;s/\"\s*\"//;s/\"\s*).*//" | grep -o "p=.*")
+
+"
+```
+
+Take the very long output of that command, which will start with
+`v=DKIM1` and add it as a TXT entry in your DNS settings as below. The
+host we put it for is `mail._domainkey`.
+
+{{< img alt="Adding the OpenDKIM TXT entry in DNS settings" src="/pix/dkim-01.png" link="/pix/dkim-01.png" >}}
+
+On my registrar, Epik, this is how it is input, but on some registrars,
+it may be required to include your domain name as well as
+`mail._domainkey.example.org`.
+
+If you have your own DNS server, add a TXT entry as follows:
+
+```txt
+mail._domainkey.example.org TXT v=DKIM1; k=rsa; p=ThatLongRandomSequenceOfLettersAndNumbersOfYours
+```
+
+## Testing it out!
+
+Now we want to send an email to make sure that your emails will now be
+signed with OpenDKIM.
+
+### Hostname
+
+If you\'ve followed these instructions, all emails from the domain
+**example.org** will now have a DKIM signature on them. If we send mail
+via the `mail` command, however, their domain of origin will be whatever
+your server\'s hostname is, which you may have set to something
+different than your domain.
+
+You can permanently change your hostname by changing it in
+`/etc/hostname` and rebooting, or you can just run
+`hostname example.org` to change it temporarily for testing. Either way,
+this will allow us to run the `mail` command as in [the SMTP
+article](smtp.html).
+
+```sh
+echo "Hi there.
+
+This is the text." | mail -s "Email from the server" your@emailaddress.com
+```
+
+### More helpful troubleshooting.
+
+You can also go to [this site](https://appmaildev.com/en/dkim), which
+will help you troubleshoot any other DKIM problems if you mistyped
+something.
diff --git a/content/mail/rainloop.md b/content/mail/rainloop.md
new file mode 100644
index 0000000..f43dbb5
--- /dev/null
+++ b/content/mail/rainloop.md
@@ -0,0 +1,117 @@
+---
+title: "Rainloop"
+tags: ['service']
+icon: 'rainloop.png'
+short_desc: 'A graphical website for accessing a mail server.'
+---
+
+
+[Rainloop](https://www.rainloop.net/)
+is a webmail client, a program that allows you to access your email
+online like Gmail. It is useful to be able to access you email from a
+web browser because it allows you to easily access your email from any
+device with a web browser without any additional setup.
+
+If you set up
+[![logo](/pix/nextcloud.svg)Nextcloud](/nextcloud)
+then you do not need to install Rainloop because Nextcloud comes with a
+webmail client. However, if all you want is a webmail client and you do
+not need all of the extra things that Nextcloud provides, Rainloop would
+be the better choice out of the two since it is less bloated and simpler
+to install.
+
+## Instructions
+
+First we will install the required packages for Rainloop with the
+following command:
+
+```sh
+apt-get install php7.4 php7.4-common php7.4-curl php7.4-xml php7.4-fpm php7.4-json php7.4-dev php7.4-mysql unzip -y
+```
+
+Then we will download the community version of Rainloop, unzip it into
+an appropriate directory and fix all of the file permissions:
+
+```sh
+curl -L "https://www.rainloop.net/repository/webmail/rainloop-community-latest.zip" -o "rainloop.zip"
+unzip rainloop.zip -d /var/www/mail
+chown -R www-data: /var/www/mail
+```
+
+We have installed Rainloop itself, but now we need Nginx to serve the
+client. We do that by adding the following text into the file
+`/etc/nginx/sites-available/mail` (you can replace the bold text with
+whatever is appropriate for your server).
+
+```nginx
+server {
+
+ listen 80;
+
+ server_name mail.example.org ;
+ root /var/www/mail;
+
+ index index.php;
+
+ access_log /var/log/nginx/rainloop_access.log;
+ error_log /var/log/nginx/rainloop_error.log;
+
+ location / {
+ try_files $uri $uri/ /index.php?$query_string;
+ }
+
+ location ~ \.php$ {
+ fastcgi_index index.php;
+ fastcgi_split_path_info ^(.+\.php)(.*)$;
+ fastcgi_keep_conn on;
+ fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
+ include /etc/nginx/fastcgi_params;
+ fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
+ }
+ location ~ /\.ht {
+ deny all;
+ }
+
+ location ^~ /data {
+ deny all;
+ }
+}
+```
+
+Then enable the site by linking it to the sites-enabled directory:
+
+```sh
+ln -s /etc/nginx/sites-available/mail /etc/nginx/sites-enabled/
+```
+
+Reload nginx:
+
+```sh
+systemctl reload nginx
+```
+
+Finally get certifications if you are using a new subdomain:
+
+```sh
+certbot --nginx
+```
+
+After that go to `mail.example.org/?admin` and login with the default
+username and password: admin, 12345. Now you are in the admin panel and
+the first thing you do should be to change the adminsitrator password by
+looking in the security tab on the left.
+
+{{< img alt="rainloop" src="/pix/rainloop-1.png" >}}
+
+After securing the admin account you can go to domains and add your own
+email address.
+
+{{< img alt="rainloop" src="/pix/rainloop-2.png" >}}
+
+Finally, go to `mail.example.org` and login with your email address and
+password.
+
+## Contribution
+
+[Deniz Telci](https://deniz.telci.org/) - XMR:
+`4AcKbpTUc3QX2zHYdh9HZwJAQyexdybFhF1WhXTFhxAcV9jgzB6kroqGZDgeW3rQqXEMYJioYo61kaLBqstwecty9Bjbr4v`
diff --git a/content/mail/rdns.md b/content/mail/rdns.md
new file mode 100644
index 0000000..6571d8c
--- /dev/null
+++ b/content/mail/rdns.md
@@ -0,0 +1,35 @@
+---
+title: "rDNS and PTR Records"
+draft: true
+tags: ['email']
+---
+While [DNS records](dns.html) refer a domain name to the IP address
+where the the website is hosted, there is also rDNS (reverse DNS) and
+specifically PTR (pointer) records which do the reverse: link a
+server\'s IP to a domain name.
+
+This is important for many things, but especially email. Many email
+servers require that other servers that send them mail have PTR records
+to prevent spam.
+
+## Setting your PTR Record
+
+DNS settings are set with your registrar, while rDNS settings are set
+with your server or VPS provider. **Remember to set records for both
+IPv4 and IPv6!**
+
+In [Vultr](https://www.vultr.com/?ref=8384069-6G) we want to set the
+IPv4 record, click on the server, then \"Settings,\" and make sure the
+\"IPv4\" tab is selected. We can then edit the \"Reverse DNS\" blank
+shown below.
+
+{{< img alt="IPv4 rDNS PTR record set in Vultr" src="/pix/rdns-01.png" >}}
+
+The setting for IPv6 is obviosuly under the IPv6 tab. Note here that we
+copy the full IPv6 address from above and create a new rDNS entry by
+pasting that and the domain name in the blanks below. Then just select
+\"Add.\"
+
+{{< img alt="IPv6 rDNS PTR record set in Vultr" src="/pix/rdns-02.png" >}}
+
+That\'s it!
diff --git a/content/mail/smtp.md b/content/mail/smtp.md
new file mode 100644
index 0000000..6ce92f2
--- /dev/null
+++ b/content/mail/smtp.md
@@ -0,0 +1,70 @@
+---
+title: "Setting up a Postfix SMTP server"
+draft: true
+---
+The first step to setting up an email server is having an SMTP server.
+SMTP sends and receives email. Whether we want a full email server or
+just the ability to send automated email by script, we will need SMTP,
+and Postfix is the standard SMTP server.
+
+Here let\'s set a server up. Note that our goal is to be able to send
+emails from our server. If you want a full email server, this is the
+first step, and we will address the rest later.
+
+## Before beginning!
+
+Whatever VPS ([Vultr](https://www.vultr.com/?ref=8384069-6G) or
+[Frantech](https://my.frantech.ca/aff.php?aff=3886)) or IPS you are
+using, it is a very common policy to **automatically block all email
+ports by default**. VPS providers do this to prevent spammers from using
+their services.
+
+If you want to start an email server, therefore, go to your VPS\'s site
+and open a ticket or make a request to open up email ports. This is a
+simple process that requires nothing too special. One of the wagies at
+your VPS will kindly do the needful and open your ports for you. Note
+that this is not the same as unblocking a port with [ufw](ufw.html).
+
+## Installation
+
+First, we install Postfix and also `mailutils`, which comes with some
+mail programs we will use.
+
+ apt install -y mailutils postfix
+
+Installing Postfix for the first time will give us some graphical
+options.
+
+![SMTP Postfix internet site choice](pix/smtp-01.png)
+
+When asked for a \"mail name\", give your full domain name from which
+you would like mail to come and go, e.g. [example.org]{.dfn} or
+[landchad.net]{.dfn}.
+
+![SMTP Postfix fully qualified domain name](pix/smtp-02.png)
+
+## Test the email
+
+That is actually all you need to have set up to have a barebones,
+send-only email server. We can test our server by running a `mail`
+command like that below.
+
+ echo "Hi there.
+
+ This is the text." | mail -s "Email from the server" your@emailaddress.com
+
+And that is simply enough the command your server can run to send mail.
+Note that we use the `-s` option to specify the email\'s subject while
+we pipe the email content into the `mail` command via standard input. In
+this example I use a quoted multiline email as an example.
+
+## Do you see your message?
+
+If you sent the above test message to an account on Gmail or another
+major email provider, there is **very high** chance of the message you
+sent above being marked as spam or not appearing at all!
+
+Don\'t worry, we\'ll take care of that in the next two articles where we
+set up rDNS and OpenDKIM to validate the emails you send.
+
+[[Next: rDNS and PTR Records](rdns.html)]{.next}