Skip to content

Bootstrap

Initial setup shown the first time the server starts. Configures the server's identity, storage, user accounts, logging, and DNS management.

Server Identity

Server Hostname

The public hostname this server answers to, for example mail.example.com. Used in SMTP greetings, outgoing message headers, and TLS certificate requests.

Text. Name in the API: serverHostname.

Default Email Domain

The primary email domain this installation will serve, for example example.com. Additional domains can be added at any time after setup.

Text. Name in the API: defaultDomain.

Automatically Obtain TLS Certificate

Automatically obtain a free TLS certificate for the server hostname from Let's Encrypt using the ACME protocol, so clients can connect securely out of the box. Turn this off if you plan to install a certificate manually.

On or off. Default: On. Name in the API: requestTlsCertificate.

Generate Email Signing Keys

Generate DKIM signing keys for the default domain. DKIM cryptographically signs outgoing mail and significantly improves the chances that messages reach the recipient's inbox instead of spam. Turn this off only if you plan to manage DKIM keys yourself.

On or off. Default: On. Name in the API: generateDkimKeys.

Storage

Main Data Storage

Where structured data is kept: email metadata, calendars, contacts, mailbox state, and server settings. RocksDB is recommended for single-node installations; PostgreSQL, MySQL, SQLite, and FoundationDB are also supported.

Settings of their own: see Data Store. Default: RocksDB. Name in the API: dataStore.

Attachment & File Storage

Where the raw content of email messages, attachments, and other large files is stored. Leave as default to reuse the data store, or point to an object storage service such as S3 for larger deployments.

Settings of their own: see Blob Store. Default: Use data store. Name in the API: blobStore.

Full-Text Search Index

Where the full-text search index is kept, so users can search across message bodies and attachments. Leave as default to reuse the data store, or point to a dedicated search backend for larger deployments.

Settings of their own: see Search Store. Default: Use data store. Name in the API: searchStore.

Cache & Temporary Data

Where short-lived data lives: session caches, rate-limit counters, and temporary tokens. Leave as default to reuse the data store, or point to Redis for faster lookups and multi-node deployments.

Settings of their own: see In-Memory Store. Default: Use data store. Name in the API: inMemoryStore.

Account Directory

Directory Type

Where user accounts and credentials come from. The internal directory is recommended for ease of setup and management through the WebUI, but external OIDC or LDAP directories can be used for single sign-on and user provisioning in larger organizations.

Settings of their own: see Directory bootstrap. Default: Use the internal directory. Name in the API: directory.

Logging

Log Destination

Where the server writes log messages, traces, and diagnostic events. Defaults to log files on disk; remote destinations such as OpenTelemetry or webhooks can be added after setup.

Settings of their own: see Logging & tracing methods. Default: Log file. Name in the API: tracer.

Automatic DNS Management

DNS Server Type

Optionally automate the DNS records your mail server needs (SPF, DKIM, DMARC, and more) by connecting to your DNS provider's API. Leave as manual unless your DNS is hosted by a supported provider; this can always be enabled later.

Settings of their own: see DNS server bootstrap. Default: Manual DNS server management. Name in the API: dnsServer.

Set by the server

Secret

The password for the administrator account, generated by the server.

A secret: stored, and never shown again once saved. Read only. Name in the API: secret.

Username

The email address of administrator, generated by the server.

An email address. Read only. Name in the API: username.