summaryrefslogtreecommitdiff
path: root/content
diff options
context:
space:
mode:
Diffstat (limited to 'content')
-rw-r--r--content/_index.md20
-rw-r--r--content/basic/certbot.md2
-rw-r--r--content/mail/dovecot.md112
-rw-r--r--content/mail/inbox.md214
-rw-r--r--content/mail/rdns.md6
-rw-r--r--content/mail/security.md69
-rw-r--r--content/mail/smtp.md28
-rw-r--r--content/mail/validate.md (renamed from content/mail/opendkim.md)40
-rw-r--r--content/rainloop.md (renamed from content/mail/rainloop.md)2
9 files changed, 360 insertions, 133 deletions
diff --git a/content/_index.md b/content/_index.md
index 19626da..aa43e1b 100644
--- a/content/_index.md
+++ b/content/_index.md
@@ -37,6 +37,26 @@ This is the basic "course." Follow these quick tutorials and you'll have a fully
Host your own services, social media and more.
+## Setup an Email Server
+
+<div>
+
+<div class=left>
+
+This is the email "course". Follow these modules to learn how to setup an email server headache free.
+
+⏳ This entire "email course" may take **about an hour**. The approval for opening email ports with your VPS should take **no less than a day**.
+
+</div>
+
+<div class=right>
+
+{{< mail >}}
+
+</div>
+<br>
+</div>
+
## Maintaining a Server
Tips and articles on mastering your server and learning about GNU/Linux systems administration.
diff --git a/content/basic/certbot.md b/content/basic/certbot.md
index 3b60ea7..f85c4db 100644
--- a/content/basic/certbot.md
+++ b/content/basic/certbot.md
@@ -5,7 +5,7 @@ tags: ['basic']
---
Once you have a website, it is extremely important to enable encrypted
connections over HTTPS/SSL. You might have no idea what that means, but
-it\'s easy to do now that we\'ve [set our web server up](nginx.html).
+it\'s easy to do now that we\'ve [set our web server up](/basic/nginx/).
Certbot is a program that automatically creates and deploys the
certificates that allow encrypted connections. It used to be painful
diff --git a/content/mail/dovecot.md b/content/mail/dovecot.md
deleted file mode 100644
index df2b218..0000000
--- a/content/mail/dovecot.md
+++ /dev/null
@@ -1,112 +0,0 @@
----
-title: "Dovecot Email Server"
-draft: true
----
-In the article on [SMTP and Postfix](smtp.html), we set up a simple
-Postfix server that we could use to programatically send mail with the
-`mail` command. In order to have a true and fully-functional mail
-server, we need Dovecot, which can store mails received by the server,
-have and authenticate user accounts and interact with mail
-
-## Installation
-
- apt install dovecot-imapd dovecot-sieve
-
-## Certificate
-
-We will want a SSL certificate for the `mail.` subdomain. We can get
-this with [Certbot](certbot.html). Assuming we are using Nginx for our
-server otherwise, run:
-
- certbot --nginx certonly -d mail.example.org
-
-## DNS
-
-## Configuring Dovecot
-
-Dovecot\'s configuration file is in `/etc/dovecot/docevot.conf`. If you
-open that file, you will this line: `!include conf.d/*.conf` which adds
-all the `.conf` files in `/etc/dovecot/conf.d/` to the Dovecot
-configuration.
-
-One can edit each of these files individually to get the needed
-configuration, but to make things easy here, delete or backup the main
-configuration file and we will replace it with one single config file
-with all important settings in it.
-
-``` wide
-ssl = required
-ssl_cert = </etc/letsencrypt/live/mail.example.org/fullchain.pem
-ssl_key = </etc/letsencrypt/live/mail.example.org/privkey.pem
-ssl_min_protocol = TLSv1.2
-ssl_cipher_list = EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA256:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EDH+aRSA+AESGCM:EDH+aRSA+SHA256:EDH+aRSA:EECDH:!aNULL:!eNULL:!MEDIUM:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED
-ssl_prefer_server_ciphers = yes
-ssl_dh = </usr/share/dovecot/dh.pem
-auth_mechanisms = plain login
-auth_username_format = %n
-
-protocols = $protocols imap
-
-userdb {
- driver = passwd
-}
-passdb {
- driver = pam
-}
-
-mail_location = maildir:~/Mail:INBOX=~/Mail/Inbox:LAYOUT=fs
-namespace inbox {
- inbox = yes
- mailbox Drafts {
- special_use = \Drafts
- auto = subscribe
-}
- mailbox Junk {
- special_use = \Junk
- auto = subscribe
- autoexpunge = 30d
-}
- mailbox Sent {
- special_use = \Sent
- auto = subscribe
-}
- mailbox Trash {
- special_use = \Trash
-}
- mailbox Archive {
- special_use = \Archive
-}
-}
-
-service auth {
- unix_listener /var/spool/postfix/private/auth {
- mode = 0660
- user = postfix
- group = postfix
-}
-}
-```
-
-### Settings Explained
-
-Take a good look at the settings to understand what\'s going on. Some of
-the settings include:
-
-1. SSL settings to allow encrypted connections.
-2. Default directories for a mail account: Inbox, Sent, Drafts, Junk,
- Trash and Archive.
-3. The mail server will authenticate users against PAM/passwd, which
- means users you create on the server (so long as they are part of
- the `mail` group) will be able to receive and send mail.
-4. Create a `unix_listener` that will allow Postfix to authenticate
- users via Dovecot.
-
-```{=html}
-<!-- -->
-```
- echo "auth required pam_unix.so nullok
- account required pam_unix.so" >> /etc/pam.d/dovecot
-
-## Connecting Postfix and Dovecot
-
-[[Next:\<++\>](%3C++%3E)]{.next}
diff --git a/content/mail/inbox.md b/content/mail/inbox.md
new file mode 100644
index 0000000..dcc071a
--- /dev/null
+++ b/content/mail/inbox.md
@@ -0,0 +1,214 @@
+---
+title: "Setting up an E-mail Inbox"
+tags: ['mail']
+weight: 3
+---
+In the article on [SMTP and Postfix](/mail/smtp), we set up a simple
+Postfix server that we could use to programatically send mail with the
+`mail` command. In order to have a true and fully-functional mail
+server, users should be able to login to a mail client where they
+can read their inbox and send mail remotely. In order to achieve this we need Dovecot,
+which can store mails received by the server,
+authenticate user accounts and interact with mail.
+
+If we're setting up an inbox we will also want spam detection software, such
+as spam assassin.
+
+## Dovecot and Spamassassin
+
+ apt install dovecot-imapd dovecot-sieve spamassassin spamc
+
+Unblock the imap port:
+
+ ufw allow 993
+
+## Certificate
+
+We will want a SSL certificate for the `mail.` subdomain. We can get
+this with [Certbot](/basic/certbot/). Assuming we are using Nginx for our
+server otherwise, run:
+
+ certbot --nginx certonly -d mail.example.org
+
+## DNS
+
+We also need two little DNS records set on your domain registrar's site/DNS server:
+
+1. An MX record. Just put your domain, **example.org**, in the "Points to" field.
+2. A CNAME record. Host field: **mail.example.org**. "Points to" field: **example.org.**
+
+## Configuring Dovecot
+
+Dovecot\'s configuration file is in `/etc/dovecot/docevot.conf`. If you
+open that file, you will see this line: `!include conf.d/*.conf` which adds
+all the `.conf` files in `/etc/dovecot/conf.d/` to the Dovecot
+configuration.
+
+One can edit each of these files individually to get the needed
+configuration, but to make things easy here, delete or backup the main
+configuration file and we will replace it with one single config file
+with all important settings in it. Make sure you change `ssl_cert`
+and `ssl_key` accordingly.
+
+``` wide
+# Note that in the dovecot conf, you can use:
+# %u for username
+# %n for the name in name@domain.tld
+# %d for the domain
+# %h the user's home directory
+
+# Connections between the mail client and Dovecot needs to be encrypted
+ssl = required
+ssl_cert = </etc/letsencrypt/live/mail.example.org/fullchain.pem
+ssl_key = </etc/letsencrypt/live/mail.example.org/privkey.pem
+ssl_min_protocol = TLSv1.2
+ssl_cipher_list = EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA256:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EDH+aRSA+AESGCM:EDH+aRSA+SHA256:EDH+aRSA:EECDH:!aNULL:!eNULL:!MEDIUM:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED
+ssl_prefer_server_ciphers = yes
+ssl_dh = </usr/share/dovecot/dh.pem
+auth_mechanisms = plain login
+auth_username_format = %n
+
+protocols = $protocols imap
+
+# Search for valid users in /etc/passwd
+userdb {
+ driver = passwd
+}
+#Fallback: Use plain old PAM to find user passwords
+passdb {
+ driver = pam
+}
+
+# Our mail for each user will be in ~/Mail, and the inbox will be ~/Mail/Inbox
+mail_location = maildir:~/Mail:INBOX=~/Mail/Inbox:LAYOUT=fs
+namespace inbox {
+ inbox = yes
+ mailbox Drafts {
+ special_use = \Drafts
+ auto = subscribe
+}
+ mailbox Junk {
+ special_use = \Junk
+ auto = subscribe
+ autoexpunge = 30d
+}
+ mailbox Sent {
+ special_use = \Sent
+ auto = subscribe
+}
+ mailbox Trash {
+ special_use = \Trash
+}
+ mailbox Archive {
+ special_use = \Archive
+}
+}
+
+# Here we let Postfix use Dovecot's authetication system.
+service auth {
+ unix_listener /var/spool/postfix/private/auth {
+ mode = 0660
+ user = postfix
+ group = postfix
+}
+}
+
+protocol lda {
+ mail_plugins = \$mail_plugins sieve
+}
+protocol lmtp {
+ mail_plugins = \$mail_plugins sieve
+}
+plugin {
+ sieve = ~/.dovecot.sieve
+ sieve_default = /var/lib/dovecot/sieve/default.sieve
+ sieve_dir = ~/.sieve
+ sieve_global_dir = /var/lib/dovecot/sieve/
+}
+```
+
+### Settings Explained
+
+Take a good look at the above settings to understand what\'s going on. Some of
+the settings include:
+
+1. SSL settings to allow encrypted connections.
+2. The mail server will authenticate users against PAM/passwd, which
+ means users you create on the server (so long as they are part of
+ the `mail` group) will be able to receive and send mail.
+3. Default directories for a mail account: Inbox, Sent, Drafts, Junk,
+ Trash and Archive.
+4. Create a `unix_listener` that will allow Postfix to authenticate
+ users via Dovecot.
+5. Setup the Dovecot sieve plugin, which provides mail filtering facilities
+ at time of final message delivery. Sieve scripts can be used to
+ customize how messages are delivered, whether they're forwarded
+ or stored in special folders.
+
+Next, we can tell sieve to automatically move mail flagged as spam to
+the junk folder:
+
+ echo "require [\"fileinto\", \"mailbox\"];
+ if header :contains \"X-Spam-Flag\" \"YES\"
+ {
+ fileinto \"Junk\";
+ }" > /var/lib/dovecot/sieve/default.sieve
+
+After that, we should create the `vmail` user and group, which will
+access the mails, and then update the sieve configuration:
+
+ grep -q '^vmail:' /etc/passwd || useradd vmail
+ chown -R vmail:vmail /var/lib/dovecot
+ sievec /var/lib/dovecot/sieve/default.sieve
+
+Then, enable pam authentication for Dovecot:
+
+ echo "auth required pam_unix.so nullok
+ account required pam_unix.so" >> /etc/pam.d/dovecot
+
+## Connecting Postfix and Dovecot
+
+We need to tell Postfix to look to Dovecot for authenticating users/passwords.
+Dovecot will be putting an authentication socket in `/var/spool/postfix/private/auth`.
+
+ postconf -e 'smtpd_sasl_auth_enable = yes'
+ postconf -e 'smtpd_sasl_type = dovecot'
+ postconf -e 'smtpd_sasl_path = private/auth'
+ postconf -e 'mailbox_command = /usr/lib/dovecot/deliver'
+
+## Connecting Postfix and Spamassassin
+
+We will change `/etc/postifx/master.cf` so postfix can route mail through spamassassin. First
+we can cleanup the default configuration. Feel free to make a backup.
+
+ sed -i '/^\s*-o/d;/^\s*submission/d;/^\s*smtp/d' /etc/postfix/master.cf
+
+Finally, run this command to finish the configuration for spamassassin.
+
+ echo "smtp unix - - n - - smtp
+ smtp inet n - y - - smtpd
+ -o content_filter=spamassassin
+ submission inet n - y - - smtpd
+ -o syslog_name=postfix/submission
+ -o smtpd_tls_security_level=encrypt
+ -o smtpd_sasl_auth_enable=yes
+ -o smtpd_tls_auth_only=yes
+ smtps inet n - y - - smtpd
+ -o syslog_name=postfix/smtps
+ -o smtpd_tls_wrappermode=yes
+ -o smtpd_sasl_auth_enable=yes
+ spamassassin unix - n n - - pipe
+ user=debian-spamd argv=/usr/bin/spamc -f -e /usr/sbin/sendmail -oi -f \${sender} \${recipient}" >> /etc/postfix/master.cf
+
+## Make new mail accounts
+
+This is the easy part. Let's say we want to add a user Billy and let him
+receive mail, run this:
+
+ useradd -m -G mail billy
+ passwd billy
+
+Any user added to the `mail` group will be able to receive mail. Suppose a user
+Cassie already exists and we want to let her receive mail too. Just run:
+
+ usermod -a -G mail cassie
diff --git a/content/mail/rdns.md b/content/mail/rdns.md
index 6571d8c..874449d 100644
--- a/content/mail/rdns.md
+++ b/content/mail/rdns.md
@@ -1,7 +1,7 @@
---
-title: "rDNS and PTR Records"
-draft: true
-tags: ['email']
+title: "Setup rDNS"
+tags: ['mail']
+weight: 5
---
While [DNS records](dns.html) refer a domain name to the IP address
where the the website is hosted, there is also rDNS (reverse DNS) and
diff --git a/content/mail/security.md b/content/mail/security.md
new file mode 100644
index 0000000..876c40a
--- /dev/null
+++ b/content/mail/security.md
@@ -0,0 +1,69 @@
+---
+title: "Harden your E-mail Server"
+tags: ['mail']
+weight: 2
+---
+
+## Hardening Postfix
+
+Put restrictions on servers sending mail to you.
+
+ postconf -e 'smtpd_recipient_restrictions = permit_sasl_authenticated, permit_mynetworks, reject_unauth_destination, reject_unknown_recipient_domain'
+
+## Anonymize Headers
+
+Use some regular expressions to prevent some meta data like a client's ip address
+from being leaked.
+
+ echo "/^Received:.*/ IGNORE
+ /^X-Originating-IP:/ IGNORE"
+ /^User-Agent:/ IGNORE
+ /^X-Mailer:/ IGNORE >> /etc/postfix/header_checks
+
+Add this file to the postfix configuration:
+
+ postconf -e "header_checks = regexp:/etc/postfix/header_checks"
+
+## Fail2Ban
+
+If you're not familiar with fail2Ban, it's essentially a program which
+blocks bot's and hacker's login requests after a few invalid attempts.
+
+ apt-get install fail2ban
+
+Make a local copy of the configuration file:
+
+ cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
+
+Go down to the `# Mail servers` line and paste this:
+
+ [postfix]
+
+ enabled = true
+ port = smtp,ssmtp,submission
+ filter = postfix
+ logpath = /var/log/mail.log
+
+
+ [sasl]
+
+ enabled = true
+ port = smtp,ssmtp,submission,imap2,imap3,imaps,pop3,pop3s
+ filter = postfix-sasl
+ # You might consider monitoring /var/log/mail.warn instead if you are
+ # running postfix since it would provide the same log lines at the
+ # "warn" level but overall at the smaller filesize.
+ logpath = /var/log/mail.warn
+ maxretry = 1
+ bantime = 21600
+
+ [dovecot]
+
+ enabled = true
+ port = smtp,ssmtp,submission,imap2,imap3,imaps,pop3,pop3s
+ filter = dovecot
+ logpath = /var/log/mail.log
+
+This will only grant 2 login attempts and then block the requester for 6 hours. Now restart `fail2ban`:
+
+ systemctl restart fail2ban
diff --git a/content/mail/smtp.md b/content/mail/smtp.md
index 6ce92f2..2039907 100644
--- a/content/mail/smtp.md
+++ b/content/mail/smtp.md
@@ -1,7 +1,9 @@
---
-title: "Setting up a Postfix SMTP server"
-draft: true
+title: "Sending and Receiving Email"
+tags: ['mail']
+weight: 6
---
+
The first step to setting up an email server is having an SMTP server.
SMTP sends and receives email. Whether we want a full email server or
just the ability to send automated email by script, we will need SMTP,
@@ -20,10 +22,13 @@ ports by default**. VPS providers do this to prevent spammers from using
their services.
If you want to start an email server, therefore, go to your VPS\'s site
-and open a ticket or make a request to open up email ports. This is a
+and open a ticket or make a request to open up email ports, notably port `25`. This is a
simple process that requires nothing too special. One of the wagies at
your VPS will kindly do the needful and open your ports for you. Note
-that this is not the same as unblocking a port with [ufw](ufw.html).
+that this is not the same as unblocking a port with [ufw](ufw.html),
+which still needs to be done for SMTP to work.
+
+ ufw allow 25,587 proto tcp
## Installation
@@ -35,13 +40,13 @@ mail programs we will use.
Installing Postfix for the first time will give us some graphical
options.
-![SMTP Postfix internet site choice](pix/smtp-01.png)
+{{< img alt="SMTP Postfix internet site choice" src="/pix/smtp-01.png" link="/pix/smtp-01.png" >}}
When asked for a \"mail name\", give your full domain name from which
-you would like mail to come and go, e.g. [example.org]{.dfn} or
-[landchad.net]{.dfn}.
+you would like mail to come and go, e.g. **example.org** or
+**landchad.net**
-![SMTP Postfix fully qualified domain name](pix/smtp-02.png)
+{{< img alt="SMTP Postfix fully qualified domain name" src="/pix/smtp-02.png" link="/pix/smtp-02.png" >}}
## Test the email
@@ -53,7 +58,7 @@ command like that below.
This is the text." | mail -s "Email from the server" your@emailaddress.com
-And that is simply enough the command your server can run to send mail.
+This type of command is sufficient enough for your server to send mail.
Note that we use the `-s` option to specify the email\'s subject while
we pipe the email content into the `mail` command via standard input. In
this example I use a quoted multiline email as an example.
@@ -65,6 +70,5 @@ major email provider, there is **very high** chance of the message you
sent above being marked as spam or not appearing at all!
Don\'t worry, we\'ll take care of that in the next two articles where we
-set up rDNS and OpenDKIM to validate the emails you send.
-
-[[Next: rDNS and PTR Records](rdns.html)]{.next}
+set up rDNS with your VPS provider and various other DNS
+records to validate the emails you send.
diff --git a/content/mail/opendkim.md b/content/mail/validate.md
index bd8eb5d..f4f8769 100644
--- a/content/mail/opendkim.md
+++ b/content/mail/validate.md
@@ -1,14 +1,13 @@
---
-title: "Validating your emails with OpenDKIM"
-draft: true
-tags: ['email']
+title: "Validate Email with DNS Records"
+tags: ['mail']
+weight: 4
---
Email is a lot like real-life mail. You can send email to anyone, but
you can also write whatever return address you\'d like. That is, it\'s
pretty easy to pretend to be someone else via mail, and that was
originally the case with email as well: email is just text, and you
could just change your `From:` address to any email address you wanted!
-
DKIM (Domain Keys Identified Mail) helps solve this issue.
OpenDKIM will generate a public/private cryptographic key pair for your
@@ -101,6 +100,7 @@ OpenDKIM server, which will be running on port `12301`, as a milter
(mail filter). This is easy to do with the four commands below:
```sh
+postconf -e "myhostname = $(cat /etc/mailname)"
postconf -e "milter_default_action = accept"
postconf -e "milter_protocol = 6"
postconf -e "smtpd_milters = inet:localhost:12301"
@@ -185,3 +185,35 @@ This is the text." | mail -s "Email from the server" your@emailaddress.com
You can also go to [this site](https://appmaildev.com/en/dkim), which
will help you troubleshoot any other DKIM problems if you mistyped
something.
+
+## DMARC
+
+DMARC (Domain-based Message Authentication Protocol) is a protocol designed
+to give email domain owners the ability to protect their domain from
+unauthorized use.
+
+Add the dmarc user:
+
+ useradd -m -G mail dmarc
+
+Open up your registrar or DNS settings again, and make a new TXT record like
+we did with DKIM, except now use the output from the following command:
+
+ echo "_dmarc.$(cat /etc/mailname)"
+ echo "v=DMARC1; p=reject; rua=mailto:dmarc@$(cat /etc/mailname); fo=1"
+
+The first line is the Host field. The latter is the TXT value.
+
+### Sender Policy Framework
+
+Saving the easiest for last, we should add a TXT record for SPF,
+an email-authentication standard used to prevent spammers from sending messages
+that appear to come from a spoofed domain.
+
+ cat /etc/mailname
+ echo "v=spf1 mx a:mail.$(cat /etc/mailname) -all"
+
+The output of `cat /etc/mailname` is the Host field. The output of the second command is the TXT value.
+
+Again, you can check [that site](https://appmaildev.com/en/spf)
+to make sure your DKIM, DMARC, and SPF entries are valid. That's it!
diff --git a/content/mail/rainloop.md b/content/rainloop.md
index f43dbb5..b1d92e3 100644
--- a/content/mail/rainloop.md
+++ b/content/rainloop.md
@@ -33,7 +33,7 @@ Then we will download the community version of Rainloop, unzip it into
an appropriate directory and fix all of the file permissions:
```sh
-curl -L "https://www.rainloop.net/repository/webmail/rainloop-community-latest.zip" -o "rainloop.zip"
+curl -L "https://www.rainloop.net/repository/webmail/rainloop-latest.zip" -o "rainloop.zip"
unzip rainloop.zip -d /var/www/mail
chown -R www-data: /var/www/mail
```