From 7e74a039122aef922d1619e636de3497ffcf7c60 Mon Sep 17 00:00:00 2001 From: Luke Smith Date: Sat, 25 Jun 2022 10:56:36 -0400 Subject: convert to hugo --- content/mail/dovecot.md | 112 ++++++++++++++++++++++++++++ content/mail/opendkim.md | 187 +++++++++++++++++++++++++++++++++++++++++++++++ content/mail/rainloop.md | 19 +++++ content/mail/rdns.md | 35 +++++++++ content/mail/smtp.md | 70 ++++++++++++++++++ 5 files changed, 423 insertions(+) create mode 100644 content/mail/dovecot.md create mode 100644 content/mail/opendkim.md create mode 100644 content/mail/rainloop.md create mode 100644 content/mail/rdns.md create mode 100644 content/mail/smtp.md (limited to 'content/mail') diff --git a/content/mail/dovecot.md b/content/mail/dovecot.md new file mode 100644 index 0000000..df2b218 --- /dev/null +++ b/content/mail/dovecot.md @@ -0,0 +1,112 @@ +--- +title: "Dovecot Email Server" +draft: true +--- +In the article on [SMTP and Postfix](smtp.html), we set up a simple +Postfix server that we could use to programatically send mail with the +`mail` command. In order to have a true and fully-functional mail +server, we need Dovecot, which can store mails received by the server, +have and authenticate user accounts and interact with mail + +## Installation + + apt install dovecot-imapd dovecot-sieve + +## Certificate + +We will want a SSL certificate for the `mail.` subdomain. We can get +this with [Certbot](certbot.html). Assuming we are using Nginx for our +server otherwise, run: + + certbot --nginx certonly -d mail.example.org + +## DNS + +## Configuring Dovecot + +Dovecot\'s configuration file is in `/etc/dovecot/docevot.conf`. If you +open that file, you will this line: `!include conf.d/*.conf` which adds +all the `.conf` files in `/etc/dovecot/conf.d/` to the Dovecot +configuration. + +One can edit each of these files individually to get the needed +configuration, but to make things easy here, delete or backup the main +configuration file and we will replace it with one single config file +with all important settings in it. + +``` wide +ssl = required +ssl_cert = +``` + echo "auth required pam_unix.so nullok + account required pam_unix.so" >> /etc/pam.d/dovecot + +## Connecting Postfix and Dovecot + +[[Next:\<++\>](%3C++%3E)]{.next} diff --git a/content/mail/opendkim.md b/content/mail/opendkim.md new file mode 100644 index 0000000..bd8eb5d --- /dev/null +++ b/content/mail/opendkim.md @@ -0,0 +1,187 @@ +--- +title: "Validating your emails with OpenDKIM" +draft: true +tags: ['email'] +--- +Email is a lot like real-life mail. You can send email to anyone, but +you can also write whatever return address you\'d like. That is, it\'s +pretty easy to pretend to be someone else via mail, and that was +originally the case with email as well: email is just text, and you +could just change your `From:` address to any email address you wanted! + +DKIM (Domain Keys Identified Mail) helps solve this issue. + +OpenDKIM will generate a public/private cryptographic key pair for your +server. The public key will be made available publicly in your server\'s +DNS records and the private key will be used to sign every single email +that leaves the server. This means that people receiving mail from your +server can now be absolutely sure that it originated from your server +because their servers can check the cryptographic signature on the email +with the public key! + +OpenDKIM ensures that email originated from the server it claims it did, +but it does not ensure that it originated from the user account it +claims it did. This easier problem is solved by server-side +authorization settings. + +## Installation + +```sh +apt install opendkim opendkim-tools +``` + +## The Keys and Files + +We have to generate the DKIM keys and create some secondary files that +will be required for our configuration. + +### Generate the DKIM key + + + +Here we create directories for the OpenDKIM keys, generate them, and +ensure they have the right file permissions. + +```sh +mkdir -p /etc/postfix/dkim +opendkim-genkey -D /etc/postfix/dkim/ -d example.org -s mail +chgrp opendkim /etc/postfix/dkim/* +chmod g+r /etc/postfix/dkim/* +``` + +### Create the key table + +Now we\'ll tell OpenDKIM where the newly generated keys are on the file +system. + +```sh +echo "mail._domainkey.example.org example.org:mail:/etc/postfix/dkim/mail.private" > /etc/postfix/dkim/keytable +``` + +### Create the signing table + +```sh +echo "*@example.org mail._domainkey.example.org" > /etc/postfix/dkim/signingtable +``` + +### Adding trusted hosts + +```sh +echo "127.0.0.1 +10.1.0.0/16 +1.2.3.4/24" > /etc/postfix/dkim/trustedhosts +``` + +## Configuring opendkim.conf + +Now we have all the raw material, so open up `/etc/opendkim.conf` and we +can finalize our server settings. First, add these lines that will +source the files we just created. + +```yaml +KeyTable file:/etc/postfix/dkim/keytable +SigningTable refile:/etc/postfix/dkim/signingtable +InternalHosts refile:/etc/postfix/dkim/trustedhosts + +Canonicalization relaxed/simple +Socket inet:12301@localhost +``` + +There will already be an uncommented `Socket` directive, so delete, +comment out or replace it with the above. + +## Interfacing with Postfix + +There are a couple things we must add to the Postfix SMTP server +settings to interface it with OpenDKIM. Specifically, we have to set our +OpenDKIM server, which will be running on port `12301`, as a milter +(mail filter). This is easy to do with the four commands below: + +```sh +postconf -e "milter_default_action = accept" +postconf -e "milter_protocol = 6" +postconf -e "smtpd_milters = inet:localhost:12301" +postconf -e "non_smtpd_milters = inet:localhost:12301" +``` + +## Restart and reload Postfix and DKIM + +Now that we have all our settings in place: + +```sh +systemctl restart opendkim +systemctl enable opendkim +systemctl reload postfix +``` + +## Adding the DNS record! + +We are only one step away from having functioning OpenDKIM. We must add +the DKIM public key to our server\'s DNS settings, so go ahead and open +up [your registrar\'s site](https://www.epik.com/?affid=we2ro7sa6) or +wherever your site\'s DNS settings are. + +The public key is found in the file `/etc/postfix/dkim/mail.txt`, but it +will display as multiple lines and multiple quoted strings, which is +annoying and hard to copy-and-paste into your registrar. To make things +easier, run the following command to format the key in the way we need +it for the DNS TXT entry: + +```sh +echo -e " + +v=DKIM1; k=rsa; $(tr -d " +" }} + +On my registrar, Epik, this is how it is input, but on some registrars, +it may be required to include your domain name as well as +`mail._domainkey.example.org`. + +If you have your own DNS server, add a TXT entry as follows: + +```txt +mail._domainkey.example.org TXT v=DKIM1; k=rsa; p=ThatLongRandomSequenceOfLettersAndNumbersOfYours +``` + +## Testing it out! + +Now we want to send an email to make sure that your emails will now be +signed with OpenDKIM. + +### Hostname + +If you\'ve followed these instructions, all emails from the domain +**example.org** will now have a DKIM signature on them. If we send mail +via the `mail` command, however, their domain of origin will be whatever +your server\'s hostname is, which you may have set to something +different than your domain. + +You can permanently change your hostname by changing it in +`/etc/hostname` and rebooting, or you can just run +`hostname example.org` to change it temporarily for testing. Either way, +this will allow us to run the `mail` command as in [the SMTP +article](smtp.html). + +```sh +echo "Hi there. + +This is the text." | mail -s "Email from the server" your@emailaddress.com +``` + +### More helpful troubleshooting. + +You can also go to [this site](https://appmaildev.com/en/dkim), which +will help you troubleshoot any other DKIM problems if you mistyped +something. diff --git a/content/mail/rainloop.md b/content/mail/rainloop.md new file mode 100644 index 0000000..fcd1c06 --- /dev/null +++ b/content/mail/rainloop.md @@ -0,0 +1,19 @@ +--- +title: "Rainloop" +tags: ['service'] +icon: 'rainloop.png' +draft: true +short_desc: 'A graphical website for accessing a mail server.' +--- +## Dependencies + +First, we make sure we have all Rainloop\'s basic dependencies +installed. It requires PHP and some other modules. + + apt install -y nginx curl mariadb-server php php-cli php-fpm php-curl php-json php-mbstring php-mysql php-common php-xml unzip + +## Installation + + mkdir /var/www/rainloop + cd /var/www/rainloop + wget https://www.rainloop.net/repository/webmail/rainloop-community-latest.zip diff --git a/content/mail/rdns.md b/content/mail/rdns.md new file mode 100644 index 0000000..6571d8c --- /dev/null +++ b/content/mail/rdns.md @@ -0,0 +1,35 @@ +--- +title: "rDNS and PTR Records" +draft: true +tags: ['email'] +--- +While [DNS records](dns.html) refer a domain name to the IP address +where the the website is hosted, there is also rDNS (reverse DNS) and +specifically PTR (pointer) records which do the reverse: link a +server\'s IP to a domain name. + +This is important for many things, but especially email. Many email +servers require that other servers that send them mail have PTR records +to prevent spam. + +## Setting your PTR Record + +DNS settings are set with your registrar, while rDNS settings are set +with your server or VPS provider. **Remember to set records for both +IPv4 and IPv6!** + +In [Vultr](https://www.vultr.com/?ref=8384069-6G) we want to set the +IPv4 record, click on the server, then \"Settings,\" and make sure the +\"IPv4\" tab is selected. We can then edit the \"Reverse DNS\" blank +shown below. + +{{< img alt="IPv4 rDNS PTR record set in Vultr" src="/pix/rdns-01.png" >}} + +The setting for IPv6 is obviosuly under the IPv6 tab. Note here that we +copy the full IPv6 address from above and create a new rDNS entry by +pasting that and the domain name in the blanks below. Then just select +\"Add.\" + +{{< img alt="IPv6 rDNS PTR record set in Vultr" src="/pix/rdns-02.png" >}} + +That\'s it! diff --git a/content/mail/smtp.md b/content/mail/smtp.md new file mode 100644 index 0000000..6ce92f2 --- /dev/null +++ b/content/mail/smtp.md @@ -0,0 +1,70 @@ +--- +title: "Setting up a Postfix SMTP server" +draft: true +--- +The first step to setting up an email server is having an SMTP server. +SMTP sends and receives email. Whether we want a full email server or +just the ability to send automated email by script, we will need SMTP, +and Postfix is the standard SMTP server. + +Here let\'s set a server up. Note that our goal is to be able to send +emails from our server. If you want a full email server, this is the +first step, and we will address the rest later. + +## Before beginning! + +Whatever VPS ([Vultr](https://www.vultr.com/?ref=8384069-6G) or +[Frantech](https://my.frantech.ca/aff.php?aff=3886)) or IPS you are +using, it is a very common policy to **automatically block all email +ports by default**. VPS providers do this to prevent spammers from using +their services. + +If you want to start an email server, therefore, go to your VPS\'s site +and open a ticket or make a request to open up email ports. This is a +simple process that requires nothing too special. One of the wagies at +your VPS will kindly do the needful and open your ports for you. Note +that this is not the same as unblocking a port with [ufw](ufw.html). + +## Installation + +First, we install Postfix and also `mailutils`, which comes with some +mail programs we will use. + + apt install -y mailutils postfix + +Installing Postfix for the first time will give us some graphical +options. + +![SMTP Postfix internet site choice](pix/smtp-01.png) + +When asked for a \"mail name\", give your full domain name from which +you would like mail to come and go, e.g. [example.org]{.dfn} or +[landchad.net]{.dfn}. + +![SMTP Postfix fully qualified domain name](pix/smtp-02.png) + +## Test the email + +That is actually all you need to have set up to have a barebones, +send-only email server. We can test our server by running a `mail` +command like that below. + + echo "Hi there. + + This is the text." | mail -s "Email from the server" your@emailaddress.com + +And that is simply enough the command your server can run to send mail. +Note that we use the `-s` option to specify the email\'s subject while +we pipe the email content into the `mail` command via standard input. In +this example I use a quoted multiline email as an example. + +## Do you see your message? + +If you sent the above test message to an account on Gmail or another +major email provider, there is **very high** chance of the message you +sent above being marked as spam or not appearing at all! + +Don\'t worry, we\'ll take care of that in the next two articles where we +set up rDNS and OpenDKIM to validate the emails you send. + +[[Next: rDNS and PTR Records](rdns.html)]{.next} -- cgit v1.2.3