Backup & migration
Full backup
Download a self-contained backup — data/ (database, DKIM keys, credentials, Postfix queue), docker-compose.yml, .env, and certs/. Extract into an empty project directory on a new machine, adjust hostname if needed, and start the same SelfPost version before first boot. The reverse-proxy vhost is not included.
The backup file is a secret. Encrypting it is the simplest way to store it: the download is then a .spbk that only the password opens.
Keep this password: without it the file cannot be opened.
Import a domain
Move a single domain here from another SelfPost instance — plain .json or encrypted .spde. Its DKIM key and application passwords come across, so the published DNS record needs no change. The export file is a secret, like a full backup.
Needed for a .spde file. Leave empty for plain .json.