Postfix Engineering Center · Version 3.9
Postfix Engineering Center
Production-focused guides, configuration downloads, and browser tools for secure Postfix submission, routing, delivery, filtering, queues and incident response.
Interactive tools
Build relay restrictions, transports, TLS policies, source-IP services and incident commands.
Configuration library
Download editable main.cf, master.cf, maps, runbooks and integration templates.
Existing Postfix library
Continue into the portal's earlier Postfix tutorials and troubleshooting references.
Engineering guides
Postfix Architecture and Message Flow
Understand smtpd, cleanup, queue manager, trivial-rewrite, smtp, local, virtual and LMTP services.
Production main.cf Baseline
A conservative starting configuration for identity, relay safety, TLS, queues and logging.
Production master.cf Baseline
Safely configure SMTP, submission, smtps, pickup, cleanup and transport services.
Relay Restrictions and Open Relay Prevention
Build an auditable relay policy using permit_mynetworks, SASL and reject_unauth_destination.
SMTP AUTH with Dovecot SASL
Configure authenticated submission without exposing an open relay.
Inbound TLS Configuration
Deploy certificates, protocol policy, ciphers and useful TLS logging.
Outbound TLS Policy
Use opportunistic TLS, per-domain policy maps and mandatory TLS where required.
Transport Maps in Production
Route domains and destinations through specific nexthops and transports.
Sender-dependent Relay Routing
Select relayhosts and credentials by envelope sender.
Sender-dependent Default Transport
Route senders through isolated transports and source IPs.
Multiple Source IP Addresses
Create named smtp transports bound to distinct IPv4 addresses.
Virtual Mailbox Domains
Implement virtual domains, aliases, mailbox maps and LMTP delivery.
Dovecot LMTP Delivery
Deliver virtual mail reliably over a Unix socket with correct ownership.
OpenDKIM Integration
Connect Postfix to OpenDKIM, define signing scope and verify results.
OpenDMARC Integration
Evaluate inbound DMARC and preserve useful authentication evidence.
SRS for Forwarding
Preserve SPF alignment behavior when forwarding mail with postsrsd.
Header Checks and Cleanup
Apply safe header_checks without damaging authentication or traceability.
Client, Sender and Recipient Access Maps
Use access maps for explicit allow, reject, hold, discard and routing decisions.
Restriction Ordering
Avoid dangerous permit placement and understand short-circuit evaluation.
Postscreen Deployment
Reduce abusive pre-greeting traffic while protecting legitimate clients.
Anvil and Connection Rate Controls
Apply connection and message controls without harming trusted submission.
Queue Management
Inspect, hold, release, requeue and delete messages safely.
Deferred Queue Troubleshooting
Diagnose why mail is deferred using logs, queue records, DNS and remote responses.
Queue Recovery Runbook
Recover from transport failure, DNS incidents, credential problems and disk pressure.
Logging with rsyslog and journald
Preserve searchable Postfix evidence and correlate queue IDs end to end.
Common Log Patterns
Interpret connect, reject, status=sent, status=deferred, bounced and warning events.
DSN and Bounce Handling
Understand enhanced status codes, double bounces and notification controls.
Content Filter Integration
Integrate milters, before-queue and after-queue filters with clear failure policy.
Amavis and SpamAssassin Integration
Plan a stable after-queue filtering path and avoid mail loops.
Rspamd Integration
Use the Rspamd milter for scoring, DKIM signing and policy controls.
MailWizz Integration
Connect MailWizz to Postfix with authenticated submission and safe throughput limits.
Postfix to PowerMTA Relay
Use Postfix for submission and policy while PowerMTA handles outbound delivery.
Submission Service Hardening
Require authentication and encryption on ports 587 or 465.
Chroot, Sockets and Permissions
Troubleshoot missing sockets, maps and certificate access in chrooted services.
Map Databases and postmap
Choose hash, lmdb, regexp, pcre, mysql and proxy maps and rebuild them correctly.
MySQL-backed Maps
Configure connection pooling, least privilege and resilient SQL queries.
High Availability Patterns
Design active-passive and horizontally scaled Postfix roles without duplicate delivery.
Performance and Concurrency Tuning
Tune process limits, destination concurrency, cache behavior and disk-sensitive queues.
Security Hardening Checklist
Reduce attack surface, protect credentials and validate every relay path.
Upgrade and Rollback Runbook
Prepare, test, upgrade, verify and roll back Postfix safely.