Hardening¶
In the console: Settings › Security › Hardening
What leaves this server more open than it needs to be, most serious first, checked each time the page opens.
SS-1 · Plain-text passwords over unencrypted IMAP¶
Critical when IMAP accepts a password on a connection that isn’t encrypted. Fix turns that off; mail apps then sign in over TLS, as nearly all do already.
SS-2 · The relaying rule¶
Critical when the rule for who may send mail on to other servers differs from the default (only people who signed in). An edit may be deliberate, so this is a Review: both rules are shown side by side, and nothing is reset for you.
SS-3 · Domains that relay for anyone¶
Critical when a domain passes on mail without a sign-in. That’s for a domain split between two mail systems; anywhere else it lets strangers send through this server. Review lists the domains.
SS-4 · Sign-in for sending¶
Critical when the rule for when sending needs a sign-in differs from the default (everywhere but port 25). Review shows both rules.
SS-5 · Certificates expired or expiring within 7 days¶
Critical for each certificate that has expired or will within a week. Review opens the certificate; renewing isn’t a one-click fix, and a certificate the server gets itself renews on its own well before this.
SS-6 · Automatic bans¶
Important when any of the three automatic IP bans (failed sign-ins, abuse, port scans) is switched off. Fix puts back the default rate for each one that’s off.
SS-7 · Rate limits for people who aren’t signed in¶
Important when requests from people who aren’t signed in have no rate limit. Fix puts back the default.
SS-8 · OAuth client registration¶
Important when apps may register themselves, or sign people in without being registered. Fix turns off anonymous registration and requires registration again; apps you registered keep working.
SS-9 · Password rules¶
Important when the minimum password strength or length is below the default. Fix raises whichever is lower. Existing passwords aren’t touched; the rules apply the next time each one changes.
SS-10 · Certificate checks on outgoing mail¶
Important for each TLS strategy that accepts invalid certificates when delivering. Review opens the strategy: a relay with a self-signed certificate may need it, nothing else does.
SS-11 · DMARC checks on incoming mail¶
Important when the DMARC check no longer runs on port 25, where other servers deliver. A stricter rule than the default is fine and isn’t flagged. Review shows the rule and the default.
SS-12 · Metrics access¶
Important when Prometheus metrics are on with no password. Review opens the page where Make a password sets one; the password is yours to keep, so it’s never set for you.
SS-13 · Mail records in DNS¶
Important for each enabled domain missing its MX, SPF, DKIM or DMARC record in public DNS, as seen through Cloudflare’s resolver from your browser. Review opens the domain’s records. DNS is never written from this page.
SS-14 · Certificates expiring within 30 days¶
Important for each certificate that expires within a month but not within a week (that’s SS-5).
SS-15 · Legacy mail protocols¶
Good practice while any of IMAP, POP3 or ManageSieve is on. The switch further down this page shows who used each one lately; it’s never a one-click fix, since it closes ports.
SS-16 · Password hashing¶
Good practice when new passwords are hashed with PBKDF2. Fix switches to Argon2id; existing hashes stay as they are until each password changes.
SS-17 · MTA-STS¶
Good practice until MTA-STS is enforced. It starts in testing on purpose: move to enforce once the TLS reports other servers send you look clean. Review opens the setting.
SS-18 · DMARC policies¶
Good practice for each domain whose DMARC record says p=none. Once DMARC reports show your own mail passing, move to quarantine or reject at your DNS host.