Fedora Postfix Mail Server Setup Guide
Running a mail server on Fedora is a useful administration exercise, but reliable email requires more than installing one package. Postfix handles SMTP delivery, while DNS, reverse DNS, TLS, authentication, spam controls, and mailbox software determine whether messages arrive successfully.
Australian network conditions deserve attention. Many NBN connections use dynamic addresses, residential providers may block outbound port 25, and an IP address without matching reverse DNS is often distrusted by Gmail and Microsoft. A VPS in Sydney, Melbourne, or Brisbane is usually a better starting point than a home connection.
This guide builds a practical Postfix server for a domain such as example.com. Replace the sample hostnames with your own values, and check the requirements of your registrar and hosting provider before sending production mail.
Prepare Fedora And DNS
Set a fully qualified hostname before installing services. In this example, the server is mail.example.com.
sudo hostnamectl set-hostname mail.example.com
hostname --fqdn
Create an A record for mail.example.com that points to the server address. Add an MX record for example.com pointing to that hostname, then ask the VPS provider to set reverse DNS, or PTR, to the same name. Australian providers often call reverse DNS “rDNS”; it may need to be changed in a control panel rather than with your domain registrar.
Check the records from Fedora:
dig +short A mail.example.com
dig +short MX example.com
dig +short -x SERVER_IP
If you manage several Linux hosts, document the mail server alongside other infrastructure. A practical NFS file share guide can help when storing configuration backups on a separate internal system.
Install Postfix And Supporting Tools
Install Postfix, a mail client for testing, and firewall utilities:
sudo dnf install postfix s-nail firewalld
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=smtp
sudo firewall-cmd --reload
When Fedora asks for the mail configuration type, choose Internet Site and enter the system mail name. You can revise the important values directly with postconf, which is easier to audit than editing a large configuration file manually.
sudo postconf -e 'myhostname = mail.example.com'
sudo postconf -e 'mydomain = example.com'
sudo postconf -e 'myorigin = $mydomain'
sudo postconf -e 'inet_interfaces = all'
sudo postconf -e 'mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain'
sudo postconf -e 'mynetworks = 127.0.0.0/8 [::1]/128'
sudo systemctl enable --now postfix
mynetworks is deliberately restricted to the local machine. Never replace it with a broad public network, because that can turn the server into an open relay. For larger Fedora deployments, keep package and configuration backups on controlled storage rather than an exposed share.
Add Mailbox Delivery And Transport Security
Postfix can receive and transfer SMTP messages, but it is not a complete mailbox platform. Add Dovecot when users need IMAP access, local mailbox authentication, or Maildir delivery:
sudo dnf install dovecot
sudo systemctl enable --now dovecot
For a production service, obtain a certificate for mail.example.com and configure Postfix and Dovecot to use it. A basic Postfix TLS configuration might include:
sudo postconf -e 'smtpd_tls_cert_file = /etc/pki/tls/certs/mail.example.com.fullchain.pem'
sudo postconf -e 'smtpd_tls_key_file = /etc/pki/tls/private/mail.example.com.key'
sudo postconf -e 'smtpd_tls_security_level = may'
sudo postconf -e 'smtpd_tls_auth_only = yes'
sudo systemctl reload postfix
Use submission port 587 for authenticated clients instead of asking users to send mail through port 25. Configure Dovecot SASL carefully, create individual accounts, and apply file permissions to private keys. Test certificate renewal before the first expiry, especially if the server supports staff working across AEST and other Australian time zones.
Publish Authentication Records
Modern receiving systems expect several DNS controls. SPF identifies permitted sending hosts, DKIM signs messages, and DMARC tells receiving servers how to handle failures. A simple SPF record for one server is:
example.com. IN TXT "v=spf1 mx -all"
DKIM normally requires an additional signing service, such as OpenDKIM or Rspamd. Publish the public key at a selector name such as mail._domainkey.example.com, then add a cautious DMARC policy while monitoring reports:
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
For Australian organisations, outbound marketing and customer messages should also respect the Spam Act and consent requirements overseen by ACMA. Authentication improves reputation, but it does not make unsolicited mail acceptable. A small business in Perth or Adelaide should also verify that its VPS provider permits SMTP traffic before moving a domain’s mail flow.
Useful records and checks include:
- A matching A, MX, and PTR record
- SPF covering every authorised sender
- DKIM signatures that pass verification
- DMARC reports sent to a monitored mailbox
Keep operational notes in a plain-text repository; even a compact editor such as Magik Emacs can be useful for reviewing Postfix maps and DNS snippets without changing them accidentally.
Test Delivery And Maintain The Service
Start with local delivery and inspect the queue:
echo "Fedora mail test" | mail -s "Postfix test" admin@example.com
mailq
sudo journalctl -u postfix -n 50 --no-pager
Test from an external mailbox and inspect the full headers for SPF, DKIM, DMARC, TLS, and the receiving server’s response. Use dig, openssl s_client, and a reputable mail diagnostic service rather than assuming that a successful SMTP connection means the message reached the inbox.
| Area | Basic setup | Production expectation |
|---|---|---|
| Host identity | Hostname and MX record | Matching forward and reverse DNS |
| Transport | SMTP on port 25 | TLS plus submission on port 587 |
| User access | Local delivery | Dovecot IMAP and authenticated accounts |
| Trust | SPF record | SPF, DKIM, and monitored DMARC |
| Operations | Manual log checks | Updates, backups, queue alerts, and abuse monitoring |
Review logs for deferred mail, authentication failures, and repeated connection attempts. Fedora’s dnf update should be part of a scheduled maintenance window, and firewall rules should expose only services that users genuinely need.
Before accepting real mail, confirm that the hostname resolves correctly, PTR matches the hostname, port 25 is permitted by the provider, and a test message passes authentication checks. The next concrete step is to create the mail.example.com A, MX, and PTR records, then verify them with dig before changing Postfix settings.