Status Domains example.com Deliveries Message Mail queue System log Inbound lists.example.com backup.example.net DMARC Backup Users Help Settings

Status

Overall warn

Running, with warnings below.

Mail queue warn

3 Kbytes in 3 Requests.

View queue

TLS certificate ok

2026-11-02 12:00 UTC

Valid for another 78 day(s).

Milter sockets ok

MilterStateDetail
OpenDKIM ok Listening
send-log ok Listening

Hostname and reverse DNS ok

mail.example.org 203.0.113.10 → mail.example.org

mail.example.org resolves to 203.0.113.10 and the reverse lookup points back at it.

Inbound warn

INBOUND_RELAY_ENABLE is on. Port 25 accepts mail for 2 domains and forwards it upstream — not to local mailboxes.

One domain has no MX pointing at this server. Recipients are a list or any address at the domain. Open Inbound for the list, MX checks, upstream, and recipient maps.

Inbound domains

Machine ok

ResourceUsageDetail
CPU 12% 12% 4 cores · 4 threads
Memory 41% 41% 1.6 GiB used of 4.0 GiB.
Network ↓ 2.0 KiB/s
↑ 1.0 KiB/s
eth0: 1.0 MiB in, 512.0 KiB out

Processes ok

ProgramStateDetail
opendkim RUNNING pid 21, uptime 3 days, 4:12:01
panel RUNNING pid 18, uptime 3 days, 4:12:03
postfix RUNNING pid 42, uptime 3 days, 4:11:58
postfix-reload STOPPED Not started
cert-reload STOPPED Not started
logrotate STOPPED Not started

Configuration

Regenerates the OpenDKIM and Postfix configuration from the database and reloads both daemons. Use it if you edited the files by hand, restored a backup, or the running configuration looks out of step with the domain and application lists. It does not touch the mail queue or the TLS certificate, and it is safe to run at any time.

SelfPost 1.2.3 · © Mixeme · License (AGPL-3.0)

SelfPost

Sign in

© Mixeme · License (AGPL-3.0)

SelfPost

Create administrator

This one-time link creates the single panel administrator. After you submit, the link stops working for good.

Domains

Add a sending domain

Domains

DomainDNSSelectorApps
example.com ok mail 2 Delete
alerts.example.com warn mail 1 Delete

The DNS badge is the worst of DKIM, SPF and DMARC. Open a domain for details.

example.com

← All domains

New application password

Shown once only and not stored. Copy it now.

newsletter
xK.9fQ2m-pL7wR

DNS status ok

mail._domainkey.example.com
TXT
example.com
TXT
_dmarc.example.com
TXT

p=none; rua points at SelfPost ingest.

Not required (rua= is on a domain SelfPost accepts).

DKIM and SPF records

DKIM

mail._domainkey.example.com
TXT
v=DKIM1; k=rsa; p=MIIBIjANBgkqh…

SPF

v=spf1 ip4:203.0.113.10 -all

DMARC record

_dmarc.example.com
TXT
v=DMARC1; p=none; rua=mailto:dmarc@mail.example.org

Open DMARC reports for this domain.

Connection settings

mail.example.org
465 — SSL/TLS (implicit) 587 — STARTTLS (submission)

Add an application

Applications

  • Any address of the domain — *@example.com

    Address mode

    Trusted-IP override active

  • Fixed list — invoices@example.com

Domain settings

DMARC reports

Level-2 rate limit active

Export domain

Secret file — transfer securely, or encrypt as .spde.

Danger zone

Deletes the DKIM key and every application on this domain.

Delete domain

Delete example.com

← Back to example.com

Confirm deletion

You are about to delete example.com. This will:

  • permanently delete its DKIM signing key;
  • delete all 2 bound applications, including their SASL credentials;
  • reload OpenDKIM so the domain is no longer signed.

This cannot be undone.

Deliveries

TimeFromToSubjectStatus
2026-08-15 20:14:02 billing@example.com ada@example.net Invoice #4412 deferred Details
2026-08-15 20:11:40 news@example.com list-bounces@example.net August digest delivered Details
2026-08-15 19:02:11 alerts@alerts.example.com noreply@blocked.example Disk 92% on web-3 bounced Details
2026-08-15 18:44:09 news@example.com sam@example.org August digest delivered Details

Page 1 of 4 · Older →

Invoice #4412

billing@example.com ada@example.net deferred

← Back to deliveries

Message

Domainexample.com
Applicationbilling
Accepted2026-08-15 20:14:02 UTC
Status reported2026-08-15 20:14:08 UTC
Queue id4C3A1E2F1A
Journal id1842

History

  1. 2026-08-15 20:14:02 UTC

    accepted Received by the relay

    SASL login billing, queued as 4C3A1E2F1A.

  2. 2026-08-15 20:14:08 UTC

    deferred Receiving MX asked to try later

    Postfix retries: first after 5 minutes, then with increasing gaps up to 1 hour 7 minutes, for up to 5 days. There is no fixed attempt count — a deferred message stays in the queue until it is delivered or that lifetime runs out.

  3. not yet

    delivery Waiting on the next retry

Delivery log

TimeMessage
20:14:02postfix/smtpd[221]: 4C3A1E2F1A: client=203.0.113.40, sasl_username=billing
20:14:02postfix/cleanup[224]: 4C3A1E2F1A: message-id=<4412@example.com>
20:14:08postfix/smtp[230]: 4C3A1E2F1A: to=<ada@example.net>, relay=mx.example.net[198.51.100.20]:25, delay=6, status=deferred (450 4.2.1 mailbox busy)

20:14:08

status=deferred (450 4.2.1 mailbox busy)

20:14:02

client=203.0.113.40, sasl_username=billing

Mail queue

How delivery retries work

This Postfix’s policy, read once at panel start. There is no maximum attempt count — only time.

First retry5 minutes
Later retriesdoubling, cap 1 h 7 min
Kept in queue5 days
Thenbounced

Pending messages

Queue idAgeFromToSize
4C3A1E2F1A18 minbilling@example.comada@example.net12 KiB
4C3A1E301011 minnews@example.compat@slow.example48 KiB
4C3A1E31024 minbilling@example.comada@example.net9 KiB
-Queue ID- --Size-- ----Arrival Time---- -Sender/Recipient------- 4C3A1E2F1A* 12288 Sat Aug 15 20:14:02 billing@example.com ada@example.net 4C3A1E3010 49152 Sat Aug 15 20:21:18 news@example.com pat@slow.example -- 3 Kbytes in 3 Requests.

System log

Recent log entries

Aug 15 20:14:08 mail postfix/smtp[230]: 4C3A1E2F1A: to=<ada@example.net>, relay=mx.example.net[198.51.100.20]:25, delay=6, delays=0.2/0.1/0.4/5.3, dsn=4.2.1, status=deferred (450 4.2.1 mailbox busy) Aug 15 20:14:02 mail postfix/qmgr[119]: 4C3A1E2F1A: from=<billing@example.com>, size=12288, nrcpt=1 (queue active) Aug 15 20:14:02 mail postfix/smtpd[221]: 4C3A1E2F1A: client=203.0.113.40[203.0.113.40], sasl_method=PLAIN, sasl_username=billing Aug 15 20:11:40 mail postfix/smtp[228]: 4B19D0AA01: to=<list-bounces@example.net>, relay=mx.example.net[198.51.100.20]:25, delay=0.9, status=sent (250 2.0.0 Ok) Aug 15 20:02:11 mail postfix/smtp[226]: 4B19C0BB12: to=<noreply@blocked.example>, status=bounced (host mx.blocked.example[203.0.113.99] said: 550 5.7.1 rejected)

Backup & migration

Full backup

Download a full backup of all persistent state — the database, every domain’s DKIM key and the application credentials. Restore into a container of the same SelfPost version, with the same data mount, before first start. TLS certificates and the mail queue are not included.

The backup file is a secret. Encrypting it is the simplest way to store it: the download is then a .spbk that only the password opens.

Keep this password: without it the file cannot be opened.

Import a domain

Move a single domain here from another SelfPost instance — plain .json or encrypted .spde. Its DKIM key and application passwords come across, so the published DNS record needs no change. The export file is a secret, like a full backup.

Needed for a .spde file. Leave empty for plain .json.

Users

Create user

UsernameRoleDomains
adminGlobalAllEdit
ops-alertsDomain adminalerts.example.comEdit

Edit user

← Back to users
Assigned domains

Required for domain administrators.

Delete ops-alerts

← Back to ops-alerts

Confirm deletion

You are about to delete the panel user ops-alerts. A signed-in session for this user stops working immediately.

Settings

Panel credentials

These are the credentials for this control panel only. Applications keep their own logins and passwords, which are not affected.

DMARC aggregate reports

Default rua= for every sending domain (overridable per domain). When ingest is on, this can be an address SelfPost accepts.

When rua= points at another domain, that hub must publish a report-authorisation record. DMARC reports in the panel.

mail.example.org._report._dmarc.example.com
TXT
v=DMARC1;

Published at mail.example.org._report._dmarc.example.com — aggregate reports addressed to dmarc@mail.example.org are authorised.

Leave both new-password fields empty to change the username or DMARC address only. Changing the password signs out every other session; this one stays signed in.

Sending rate limits

Level 1 is set in Compose; restart the container to change it. Domain and application ceilings live on each domain’s page.

Level 1 — per client IP

100 messages / 60 seconds

RATE_LIMIT_MESSAGES_PER_IP / RATE_LIMIT_WINDOW_SECONDS. Hard ceiling for every connecting IP; the panel cannot raise a domain or application limit above this.

Level 2 — domain

Optional ceiling for all senders on a domain. When unset, only level 1 applies. Must be ≤ level 1.

Level 2 — application

Optional override for trusted IPs: a ceiling strictly above the domain limit (still ≤ level 1). Those IPs skip the domain check; everyone else stays under the domain (or level 1).

Inbound 1.x

Backup-MX / forwarder. Accepts on port 25 only for listed domains. Recipients are either an allow-list or any address at that domain. Off by default in Compose.

Add inbound domain

Forwarding

DomainDNSUpstreamRecipientsTLS
lists.example.com ok 10.0.0.8:25 12 listed required Delete
backup.example.net error 192.0.2.20:25 any off Delete

The DNS badge is the MX check: at least one MX must point at this server. Results are cached for a few minutes; open a domain for the lookup and a Re-check button.

lists.example.com

← All inbound domains

DNS status ok

Cached a few minutes — use Re-check after publishing. Unlike outbound, inbound needs an MX pointing at this server.

lists.example.com
MX
10 mail.example.org. 20 mail.primary.example.net.

An MX points at mail.example.org (this server). Other MX values are the domain’s own primaries — they are not an error.

Upstream

Where accepted mail is handed off. Not a mailbox.

MX record to publish

Add this MX so the internet delivers here. Keep any existing primary MX if this is backup-MX.

lists.example.com
MX
10 mail.example.org.

Valid recipients

Who this domain accepts on port 25. Same idea as an application’s address mode: a list, or any address at the domain.

Unknown recipients are rejected at RCPT so this relay does not generate backscatter.

Every address at this domain is accepted and forwarded. Prefer a list unless the upstream rejects unknowns — otherwise this relay may generate backscatter.

Danger zone

Stops accepting mail for this domain. Does not touch outbound sending domains.

Delete inbound domain

backup.example.net

← All inbound domains

DNS status error

Cached a few minutes — use Re-check after publishing. Unlike outbound, inbound needs an MX pointing at this server.

backup.example.net
MX
10 mail.primary.example.net.

No MX points at mail.example.org (this server). Publish the record below, or wait for DNS to propagate and Re-check.

Upstream

Where accepted mail is handed off. Not a mailbox.

MX record to publish

Add this MX so the internet delivers here. Keep any existing primary MX if this is backup-MX.

backup.example.net
MX
20 mail.example.org.

Valid recipients

Who this domain accepts on port 25. Same idea as an application’s address mode: a list, or any address at the domain.

Unknown recipients are rejected at RCPT so this relay does not generate backscatter.

Every address at this domain is accepted and forwarded. Prefer a list unless the upstream rejects unknowns — otherwise this relay may generate backscatter.

Danger zone

Stops accepting mail for this domain. Does not touch outbound sending domains.

Delete inbound domain

Delete lists.example.com

← Back to lists.example.com

Confirm deletion

You are about to stop accepting inbound mail for lists.example.com. This will:

  • remove it from relay_domains and the recipient map;
  • stop forwarding to 10.0.0.8:25;
  • leave outbound sending domains untouched.

This cannot be undone from a backup of inbound maps alone unless you restore one. Remove the MX if you do not plan to re-add the domain.

DMARC reports candidate

Aggregate reports SelfPost accepted for rua=. Forensic (ruf=) is out of scope.

Ingest ok

Last report 6 hours ago. 14 kept, 0 parse failures this week.

example.com pass

98% aligned last 7 days. Tightening p= looks reasonable.

alerts.example.com fail

A third-party sender is not in SPF/DKIM. See sources.

Sources · last 7 days

DomainSourcePassFailDisposition
example.com203.0.113.10 (this relay)4122none
example.comgoogle.com / 66.102.0.0/2006none
alerts.example.com203.0.113.10 (this relay)880none
alerts.example.comunknown / 198.51.100.80019none

Help candidate

Short operator notes inside the panel — not a second copy of the full guide. Seeded from the Status explanations that do not belong on the cards (what a kernel counter is, why PTR is set at the host, what Reload does not touch). The cards themselves keep their readings, Detail columns, and the Configuration control.

On this panel

  • Machine — kernel counters and the rate window
  • TLS certificate — port 465, reverse-proxy mount
  • Hostname / reverse DNS — forward-confirmed PTR at the hosting provider
  • Mail queue retries — time-based, no attempt budget
  • Inbound — not mailboxes; listed recipients or any address at the domain
  • Domain page — DNS, records, connection, applications, export (drawer from each card’s «?»)

The same texts open in the drawer from Status’s «?» — so a card can stay a reading, not a paragraph, without throwing the reading away.

Machine

CPU and memory are the container’s own readings, not the host’s spare capacity. Network is a short window, not a daily total. High CPU with an empty queue usually means something else on the box — not SelfPost “being slow to send”.

TLS certificate

Port 465 presents the certificate the reverse proxy (or the image) mounted. The panel does not issue certificates. A warn here is “expires soon”; an error is “missing or unreadable”, and clients will refuse submission.

Hostname / reverse DNS

Forward-confirmed reverse DNS: the A/AAAA for SELFPOST_HOSTNAME must reverse to that same name. PTR is set at the hosting provider, not in this panel. Receiving networks use this pair as a cheap reputation check.