Updated: 28 September 2026 · Applies to: Postfix 3.8 (Ubuntu 24.04) and 3.10 (Ubuntu 26.04)

Postfix is the most widely used open-source mail server (MTA). This guide installs it on Ubuntu and configures it as a sending server for applications on the same machine: your website, scripts or a newsletter program deliver messages to Postfix on 127.0.0.1, and Postfix delivers them to the recipients' mail servers. Authentication (SPF, DKIM, DMARC) and per-address sending come in the following guides.

Before you start

  1. Outgoing port 25 works (How to check that outgoing port 25 works from your dedicated server?).
  2. You have a mail host name, for example mail1.example.com, with an A record to your sending address and a matching reverse DNS name (How to set reverse DNS (PTR) for many IP addresses and check forward-confirmed rDNS?).
  3. Ubuntu 24.04 LTS (Postfix 3.8) or 26.04 LTS (Postfix 3.10).

1. Set the host name

sudo hostnamectl set-hostname mail1.example.com
hostname -f

2. Install Postfix

sudo apt update
sudo apt install -y postfix mailutils

The installer asks two questions. Choose Internet Site, and enter your domain (for example example.com) as the system mail name.

3. Set the important options

sudo postconf -e "myhostname = mail1.example.com"
sudo postconf -e "myorigin = /etc/mailname"
sudo postconf -e "inet_interfaces = loopback-only"
sudo postconf -e "mydestination = \$myhostname, localhost.\$mydomain, localhost"
sudo postconf -e "smtp_tls_security_level = may"
sudo postconf -e "smtp_tls_loglevel = 1"
sudo postconf -e "smtpd_tls_security_level = may"
sudo systemctl restart postfix
  • inet_interfaces = loopback-only means that Postfix only accepts mail from programs on the same server, so nobody on the internet can use it to send mail. Change it only if you need to receive mail or offer authenticated sending to other computers (How to protect your mail-sending server from misuse?).
  • smtp_tls_security_level = may makes Postfix encrypt the connection to other servers whenever they offer it.

4. Send a test message

echo "Test from my dedicated server" | mail -s "Postfix test" -a "From: test@example.com" yourname@gmail.com

Use an address that you can read. Then watch what happens:

sudo journalctl -t postfix/smtp -t postfix/qmgr --since "10 minutes ago"
sudo tail -n 30 /var/log/mail.log      # if the file exists on your system

A line with status=sent means the message was accepted by the receiving server. Open the message and use "Show original" in Gmail to see whether SPF, DKIM and DMARC pass (they will not until you finish the next guides).

5. Useful commands

postqueue -p                 # list queued mail
postqueue -f                 # try to deliver the queue now
sudo postsuper -d ALL deferred   # delete deferred mail (be careful)
sudo postconf -n             # show your non-default settings
sudo postfix check           # check the configuration

Next steps

  1. SPF: How to write an SPF record for a server with several IP addresses?
  2. DKIM signing: How to set up DKIM signing with OpenDKIM and Postfix for several domains?
  3. DMARC: How to publish DMARC for your sending domains and tighten the policy safely?
  4. Send from a chosen address: How to make Postfix send from a specific IP address with a matching HELO name?

Common problems

Frequently asked questions

Can PHP scripts use it?
Yes. PHP's mail() and libraries such as PHPMailer can hand mail to the local Postfix (sendmail_path or SMTP on 127.0.0.1 port 25).

Do I need Dovecot?
Only for receiving mail into mailboxes or for authenticated sending. It is not needed for a sending-only server.

Source: Postfix configuration parameters.

Need a dedicated server, more IP addresses, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)