Status Domains example.com Deliveries Message Mail queue System log Inbound DMARC Backup Users Help Settings

Status warn

3 messages deferred — first retry in about 4 minutes. Everything else is up.

Mail queue warn

3 deferred, 0 bounce-hold. Oldest 18 minutes.

View queue

Inbound ok

Accepting on port 25 for 1 domain. Last forward 2 minutes ago.

Inbound domains

Inbound

Module off (INBOUND_RELAY_ENABLE=false). The outbound path is unchanged.

Machine ok

CPU12%
Memory41%
Network↓ 48 KiB/s · ↑ 12 KiB/s

Processes ok

postfixRUNNING
opendkimRUNNING
panelRUNNING

TLS certificate ok

2026-11-02 12:00 UTC

Let’s Encrypt, 78 days left. Mounted for port 465.

Milter sockets ok

opendkimok
journalok

Hostname / rDNS ok

mail.example.org mail.example.org → 203.0.113.10 → mail.example.org

SelfPost 1.2.3 · © Mixeme · License (AGPL-3.0)

SelfPost

Sign in

© Mixeme · License (AGPL-3.0)

SelfPost

Create administrator

This one-time link creates the single panel administrator. After you submit, the link stops working for good.

Domains

Add a sending domain

Domains

DomainDNSSelectorApps
example.com ok mail 2 Delete
alerts.example.com warn mail 1 Delete

The DNS badge is the worst of DKIM, SPF and DMARC. Open a domain for details.

example.com

← All domains

New application password

Shown once only and not stored. Copy it now.

newsletter
xK.9fQ2m-pL7wR

DNS status ok

mail._domainkey.example.com
TXT
example.com
TXT
_dmarc.example.com
TXT

p=none; rua points at SelfPost ingest.

Not required (rua= is on a domain SelfPost accepts).

DKIM and SPF records

DKIM

mail._domainkey.example.com
TXT
v=DKIM1; k=rsa; p=MIIBIjANBgkqh…

SPF

v=spf1 ip4:203.0.113.10 -all

DMARC record

_dmarc.example.com
TXT
v=DMARC1; p=none; rua=mailto:dmarc@mail.example.org

Open DMARC reports for this domain.

Connection settings

mail.example.org
465 — SSL/TLS (implicit) 587 — STARTTLS (submission)

Add an application

Applications

  • Any address of the domain — *@example.com

    Address mode

    Trusted-IP override active

  • Fixed list — invoices@example.com

Domain settings

DMARC reports

Level-2 rate limit active

Export domain

Secret file — transfer securely, or encrypt as .spde.

Danger zone

Deletes the DKIM key and every application on this domain.

Delete domain

Delete example.com

← Back to example.com

Confirm deletion

You are about to delete example.com. This will:

  • permanently delete its DKIM signing key;
  • delete all 2 bound applications, including their SASL credentials;
  • reload OpenDKIM so the domain is no longer signed.

This cannot be undone.

Deliveries

TimeFromToSubjectStatus
2026-08-15 20:14:02 billing@example.com ada@example.net Invoice #4412 deferred Details
2026-08-15 20:11:40 news@example.com list-bounces@example.net August digest delivered Details
2026-08-15 19:02:11 alerts@alerts.example.com noreply@blocked.example Disk 92% on web-3 bounced Details
2026-08-15 18:44:09 news@example.com sam@example.org August digest delivered Details

Page 1 of 4 · Older →

Invoice #4412

billing@example.com ada@example.net deferred

← Back to deliveries

Message

Domainexample.com
Applicationbilling
Accepted2026-08-15 20:14:02 UTC
Status reported2026-08-15 20:14:08 UTC
Queue id4C3A1E2F1A
Journal id1842

History

  1. 2026-08-15 20:14:02 UTC

    accepted Received by the relay

    SASL login billing, queued as 4C3A1E2F1A.

  2. 2026-08-15 20:14:08 UTC

    deferred Receiving MX asked to try later

    Postfix retries: first after 5 minutes, then with increasing gaps up to 1 hour 7 minutes, for up to 5 days. There is no fixed attempt count — a deferred message stays in the queue until it is delivered or that lifetime runs out.

  3. not yet

    delivery Waiting on the next retry

Delivery log

TimeMessage
20:14:02postfix/smtpd[221]: 4C3A1E2F1A: client=203.0.113.40, sasl_username=billing
20:14:02postfix/cleanup[224]: 4C3A1E2F1A: message-id=<4412@example.com>
20:14:08postfix/smtp[230]: 4C3A1E2F1A: to=<ada@example.net>, relay=mx.example.net[198.51.100.20]:25, delay=6, status=deferred (450 4.2.1 mailbox busy)

20:14:08

status=deferred (450 4.2.1 mailbox busy)

20:14:02

client=203.0.113.40, sasl_username=billing

Mail queue

How delivery retries work

This Postfix’s policy, read once at panel start. There is no maximum attempt count — only time.

First retry5 minutes
Later retriesdoubling, cap 1 h 7 min
Kept in queue5 days
Thenbounced

Pending messages

Queue idAgeFromToSize
4C3A1E2F1A18 minbilling@example.comada@example.net12 KiB
4C3A1E301011 minnews@example.compat@slow.example48 KiB
4C3A1E31024 minbilling@example.comada@example.net9 KiB
-Queue ID- --Size-- ----Arrival Time---- -Sender/Recipient------- 4C3A1E2F1A* 12288 Sat Aug 15 20:14:02 billing@example.com ada@example.net 4C3A1E3010 49152 Sat Aug 15 20:21:18 news@example.com pat@slow.example -- 3 Kbytes in 3 Requests.

System log

Recent log entries

Aug 15 20:14:08 mail postfix/smtp[230]: 4C3A1E2F1A: to=<ada@example.net>, relay=mx.example.net[198.51.100.20]:25, delay=6, delays=0.2/0.1/0.4/5.3, dsn=4.2.1, status=deferred (450 4.2.1 mailbox busy) Aug 15 20:14:02 mail postfix/qmgr[119]: 4C3A1E2F1A: from=<billing@example.com>, size=12288, nrcpt=1 (queue active) Aug 15 20:14:02 mail postfix/smtpd[221]: 4C3A1E2F1A: client=203.0.113.40[203.0.113.40], sasl_method=PLAIN, sasl_username=billing Aug 15 20:11:40 mail postfix/smtp[228]: 4B19D0AA01: to=<list-bounces@example.net>, relay=mx.example.net[198.51.100.20]:25, delay=0.9, status=sent (250 2.0.0 Ok) Aug 15 20:02:11 mail postfix/smtp[226]: 4B19C0BB12: to=<noreply@blocked.example>, status=bounced (host mx.blocked.example[203.0.113.99] said: 550 5.7.1 rejected)

Backup & migration

Full backup

Download a full backup of all persistent state. Restore into a container of the same SelfPost version. TLS certificates and the mail queue are not included. The file is a secret.

Keep this password: without it the file cannot be opened.

Import a domain

Plain .json or encrypted .spde.

Users

Create user

UsernameRoleDomains
adminGlobalAllEdit
ops-alertsDomain adminalerts.example.comEdit

Edit user

← Back to users
Assigned domains

Required for domain administrators.

Delete user

Delete ops-alerts

← Back to ops-alerts

Confirm deletion

You are about to delete the panel user ops-alerts. A signed-in session for this user stops working immediately.

Settings

Panel credentials

These are the credentials for this control panel only. Applications keep their own logins.

DMARC aggregate reports

Default rua= for every sending domain. When ingest is on, this can be an address SelfPost accepts.

DMARC reports in the panel.

Sending rate limits

Level 1 is set in Compose. Domain and application ceilings live on each domain’s page.

Level 1 / IP100 / 60s
Level 2 domainoptional, ≤ L1
App overridetrusted IPs only

Inbound 1.x

Backup-MX / forwarder. Accepts on port 25 only for listed domains; unknown recipients are rejected at RCPT. Off by default in Compose.

Add inbound domain

Forwarding

DomainUpstreamRecipientsTLS
lists.example.com 10.0.0.8:25 12 listed required Edit

lists.example.com

← All inbound domains

Upstream

Where accepted mail is handed off. Not a mailbox.

DNS — MX

Unlike outbound, inbound needs an MX pointing at this server.

lists.example.com
10 mail.example.org.

Valid recipients

Unknown recipients are rejected at RCPT so this relay does not generate backscatter. One address per line; empty means reject all until listed.

Danger zone

Stops accepting mail for this domain. Does not touch outbound sending domains.

DMARC reports candidate

Aggregate reports SelfPost accepted for rua=. Forensic (ruf=) is out of scope.

Ingest ok

Last report 6 hours ago. 14 kept, 0 parse failures this week.

example.com pass

98% aligned last 7 days. Tightening p= looks reasonable.

alerts.example.com fail

A third-party sender is not in SPF/DKIM. See sources.

Sources · last 7 days

DomainSourcePassFailDisposition
example.com203.0.113.10 (this relay)4122none
example.comgoogle.com / 66.102.0.0/2006none
alerts.example.com203.0.113.10 (this relay)880none
alerts.example.comunknown / 198.51.100.80019none

Help candidate

Short operator notes inside the panel — not a second copy of the full guide. Seeded from the Status blurbs that left the cards.

On this panel

The same texts open in the drawer from a card’s «?» — so a Status page can stay dense.

Machine

CPU and memory are the container’s own readings, not the host’s spare capacity. Network is a short window, not a daily total. High CPU with an empty queue usually means something else on the box — not SelfPost “being slow to send”.

TLS certificate

Port 465 presents the certificate the reverse proxy (or the image) mounted. The panel does not issue certificates. A warn here is “expires soon”; an error is “missing or unreadable”, and clients will refuse submission.

Hostname / reverse DNS

Forward-confirmed reverse DNS: the A/AAAA for SELFPOST_HOSTNAME must reverse to that same name. PTR is set at the hosting provider, not in this panel. Receiving networks use this pair as a cheap reputation check.