Updated: 28 September 2026 · Applies to: Postfix 3.8 (Ubuntu 24.04) and 3.10 (Ubuntu 26.04) with fail2ban

A server that sends mail is a target: attackers look for open relays and stolen passwords to send their own mail through it. One incident can put your IP addresses on blocklists and stop your legitimate mail. These steps keep your Postfix server closed to strangers and let you notice misuse early.

1. Do not be an open relay

An open relay accepts mail from anyone for anyone. Postfix is closed by default, and this line in main.cf keeps it that way:

smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, defer_unauth_destination

This is Postfix's default. It says: relay for trusted networks and authenticated users, and refuse everything else. Keep mynetworks small:

sudo postconf mynetworks smtpd_relay_restrictions inet_interfaces

mynetworks should contain only 127.0.0.0/8 and, if needed, the addresses of your own servers. Never add a large public network.

Test from another computer (install swaks with sudo apt install -y swaks):

swaks --to someone@gmail.com --from test@example.org --server YOUR-SERVER-IP

If your server listens to the internet, the answer must be a refusal such as Relay access denied. If the mail is accepted, fix the settings above at once.

2. Listen only where you need to

A sending-only server needs inet_interfaces = loopback-only (How to install and configure Postfix for sending on Ubuntu?). Check what listens: sudo ss -ltnp | grep -E ':(25|465|587)\b'.

3. Authenticated sending for other computers

If applications on other servers must send through this one, do not open the server with IP allow-lists that change often. Use authenticated submission on port 587 with TLS and a login for each application, so that you can see and revoke each user. This needs SASL authentication (Postfix with Dovecot or Cyrus SASL); the configuration depends on the Dovecot version and is best done once and documented. Our engineers can set it up for you. Always set smtpd_tls_auth_only = yes so that passwords are never sent without encryption.

4. Protect the logins with fail2ban

sudo apt install -y fail2ban
sudo tee /etc/fail2ban/jail.d/postfix.local >/dev/null <<'EOF'
[postfix]
enabled = true
[postfix-sasl]
enabled = true
EOF
sudo systemctl restart fail2ban
sudo fail2ban-client status

The jails block addresses that try to guess passwords or that behave badly. Check the result with sudo fail2ban-client status postfix-sasl.

5. Limit what your own programs can do

  • Websites: contact forms need protection against automatic posting (CAPTCHA or a hidden field, and a limit per visitor). Unprotected forms are a common way to send spam through a server.
  • Keep WordPress, plugins and other scripts updated. Hacked sites are used to send mail.
  • Use a strong password for every mail user and change it when people leave.

6. Rate limits that protect you

Postfix can limit how much one client may send to your server per minute, for example smtpd_client_message_rate_limit and smtpd_client_recipient_rate_limit. The Postfix manual says the purpose of these is to limit abuse and that they must not be used to regulate legitimate traffic, so set them well above your normal use:

sudo postconf -e "anvil_rate_time_unit = 60s"
sudo postconf -e "smtpd_client_message_rate_limit = 300"
sudo systemctl reload postfix

A hacked account then cannot send thousands of messages in a few minutes. Your outgoing speed to other providers is controlled separately (How to set delivery rate limits per provider in Postfix and handle deferrals?).

7. Notice misuse early

If your server was misused

  1. Stop Postfix: sudo systemctl stop postfix.
  2. Find the entry point (the account, the script or the website) and close it.
  3. Look at what was sent: postqueue -p | head -100. Delete the abusive mail: sudo postsuper -d ALL if nothing in the queue is legitimate.
  4. Change all passwords involved and restart. Then follow What to do when your IP address is on a blocklist or your mail is rejected? if you are on a list.

Ucartz's Acceptable Use Policy says that outbound mail of a compromised account may be suspended until it is fixed.

Frequently asked questions

Is my server safe if it only listens on localhost?
The mail server itself, yes. Your websites and scripts can still be used to send mail, so protect them as well.

Can Ucartz look after this for me?
Yes. Managed dedicated servers include monitoring and security work, and engineers are available by the task or the hour.

Need a dedicated server, more IP addresses, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)