ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Use Cases & Solutions

Run Your Own Business or Transactional Mail Server (Mailcow or Postal) on a Dedicated IP: PTR, SPF/DKIM/DMARC, MTA-STS and IP Warm-Up

8 steps 23 min read 2 views 0
On this page

You can run a reliable self-hosted business or transactional mail server if three things are right: a dedicated IP with matching rDNS/PTR, correct SPF, DKIM and DMARC, and a slow, honest warm-up — and you have confirmed with your provider that outbound port 25 is available. IMIDC servers in Hong Kong, Tokyo, Japan and Los Angeles, USA come with dedicated IPv4 addresses and rDNS set up via ticket, so you can run Mailcow for company mailboxes or Postal for application email.

Key facts
  • Confirm the outbound port 25 policy with IMIDC support before you buy; do not assume it is open.
  • Locations: Hong Kong (VPS from $18/mo, dedicated from $139/mo), Tokyo, Japan (VPS from $28/mo), Los Angeles, USA (dedicated from $499/mo).
  • Dedicated IPv4, PTR/rDNS configured via ticket; native local IPs in Japan and the USA.
  • Software: Mailcow (mailboxes, webmail, antispam) or Postal (transactional API and webhooks), both on Docker.
  • Bulk unsolicited mail and spam are not permitted; abuse can lead to suspension.

Mailcow or Postal: pick by use case

Use Mailcow when people need inboxes; use Postal when applications need to send receipts, password resets and notifications.

AspectMailcow (dockerized)Postal
Main purposeCompany mailboxes, calendars, webmailOutbound transactional email for apps
Key componentsPostfix, Dovecot, Rspamd, SOGo, ClamAVSMTP server, HTTP API, click/open tracking, webhooks
Inbound mailFull IMAP/POP3 mailboxesRoutes to HTTP endpoints or other servers
Typical resourcesAbout 6 GB RAM plus swap per the project docsSeveral GB RAM plus MariaDB
Best IMIDC fitVPS or entry dedicated serverVPS for low volume, dedicated for high volume

Many teams run both: Mailcow on one IP for staff mail, Postal on a separate IP so a marketing or app issue never hurts staff deliverability.

Step 1: confirm port 25, IP reputation and PTR

Before installing anything, verify the three prerequisites that no software can fix later.

  • Port 25: open a ticket with IMIDC support, describe your use (business mailboxes or transactional mail, expected daily volume) and confirm outbound SMTP is permitted on your plan.
  • IP reputation: check the assigned IP on Spamhaus, Barracuda and other blocklists before go-live (see our IP blacklist check guide).
  • rDNS/PTR: ask IMIDC to set the PTR of your IP to your mail hostname, for example mail.example.com, and make sure the A record points back (forward-confirmed rDNS). Our rDNS guide covers the details.
# 1. is outbound port 25 open? (should print "succeeded"/"open")
nc -vz -w 5 gmail-smtp-in.l.google.com 25

# 2. does the PTR match your mail hostname?
dig -x 203.0.113.25 +short          # expect: mail.example.com.
dig +short mail.example.com A       # expect: 203.0.113.25

# 3. set the server hostname to the same FQDN
sudo hostnamectl set-hostname mail.example.com

Step 2: install Mailcow or Postal with Docker

Both projects ship official Docker-based installers; install Docker and Docker Compose first.

Mailcow for business mailboxes:

# mailcow: full business mailbox suite (SMTP, IMAP, webmail, antispam)
cd /opt
git clone https://github.com/mailcow/mailcow-dockerized
cd mailcow-dockerized
./generate_config.sh        # enter mail.example.com and your time zone
docker compose pull
docker compose up -d
# then log in at https://mail.example.com, add domain + mailboxes,
# and copy the DKIM public key from Configuration > ARC/DKIM keys

Postal for transactional email:

# Postal: transactional / app mail with an HTTP API, webhooks and tracking
git clone https://github.com/postalserver/install /opt/postal/install
sudo ln -s /opt/postal/install/bin/postal /usr/bin/postal
docker run -d --name postal-mariadb -p 127.0.0.1:3306:3306 --restart always \
  -e MARIADB_DATABASE=postal -e MARIADB_ROOT_PASSWORD=change-me mariadb
postal bootstrap postal.example.com
# edit /opt/postal/config/postal.yml (DB password, DNS names), then:
postal initialize
postal make-user
postal start

Postal's installer runs Caddy for HTTPS on the web UI; Mailcow obtains Let's Encrypt certificates itself. Open only the ports you need: 25, 465/587 for submission, 993 for IMAPS and 443 for the web UI.

Step 3: SPF, DKIM, DMARC and MTA-STS

Authentication records tell Gmail, Outlook and Yahoo that your server is allowed to send for your domain and that messages were not altered.

; DNS zone for example.com (adapt names, IP and DKIM key)
mail.example.com.             A     203.0.113.25
example.com.                  MX    10 mail.example.com.
example.com.                  TXT   "v=spf1 mx ip4:203.0.113.25 ~all"
dkim._domainkey.example.com.  TXT   "v=DKIM1; k=rsa; p=MIIBIjANBgkq...IDAQAB"
_dmarc.example.com.           TXT   "v=DMARC1; p=none; rua=mailto:[email protected]; adkim=s; aspf=s"
_mta-sts.example.com.         TXT   "v=STSv1; id=20261008"
_smtp._tls.example.com.       TXT   "v=TLSRPTv1; rua=mailto:[email protected]"
mta-sts.example.com.          A     203.0.113.25
  • SPF lists the IPs allowed to send; keep one record per domain and stay under the 10-DNS-lookup limit.
  • DKIM signs each message; publish the public key generated by Mailcow or Postal and use 2048-bit keys.
  • DMARC starts at p=none to collect reports, then moves to quarantine and reject once all legitimate sources pass.
  • MTA-STS and TLS-RPT tell other servers to require TLS when delivering to you and send you failure reports.
# served at https://mta-sts.example.com/.well-known/mta-sts.txt
version: STSv1
mode: testing
mx: mail.example.com
max_age: 86400

Start MTA-STS in testing mode, switch to enforce after a few clean weeks, and change the id whenever you edit the policy. Verify everything:

dig +short TXT example.com | grep spf1
dig +short TXT dkim._domainkey.example.com
dig +short TXT _dmarc.example.com
curl -s https://mta-sts.example.com/.well-known/mta-sts.txt
# TLS on submission and inbound SMTP
openssl s_client -starttls smtp -connect mail.example.com:25 -servername mail.example.com </dev/null | head -5

Major mailbox providers now expect SPF, DKIM and DMARC alignment, low spam-complaint rates and, for marketing mail, one-click unsubscribe; treat these as the minimum.

Step 4: warm up the new IP

A new IP has no reputation, so increase volume gradually and send only to engaged, opted-in recipients.

PeriodDaily volume (per provider)What to sendWatch
Days 1-320-50Internal and known contacts who will replyInbox vs spam placement
Days 4-750-200Transactional mail, most engaged customersBounces under 2%
Week 2200-1,000Regular transactional flowComplaints, Postmaster Tools
Weeks 3-41,000-5,000Normal operational volumeDeferrals (4xx), blocklists
After week 4Grow 20-30% per week if metrics stay cleanSteady volumeAll of the above

These are conservative starting points, not guarantees. If you see deferrals or spam-folder placement, hold volume flat until it clears. Register with Google Postmaster Tools and Microsoft SNDS to watch reputation.

Step 5: monitor blocklists and queues

Catching a listing or a stuck queue within hours keeps a small problem from becoming a week of lost mail.

#!/bin/sh
# rbl-check.sh 203.0.113.25 - run daily from cron, alert on any hit
IP="$1"; REV=$(echo "$IP" | awk -F. '{print $4"."$3"."$2"."$1}')
for BL in zen.spamhaus.org b.barracudacentral.org bl.spamcop.net; do
  if dig +short "$REV.$BL" A | grep -q '^127\.'; then
    echo "LISTED on $BL"
  else
    echo "clean   $BL"
  fi
done
# note: Spamhaus refuses queries via large public resolvers; use your own resolver
  • Run the check daily via cron and alert by a channel that does not depend on the same server.
  • Watch the mail queue (postqueue -p inside the Postfix container in Mailcow) and Postal's message log.
  • Read DMARC aggregate reports weekly to spot unknown senders spoofing your domain.
  • If listed, fix the cause first (compromised account, open form, bad list), then request delisting.

Choosing the location by recipient

Host the mail server close to where most recipients are and where your IP looks local.

IMIDC locationBest for recipients inNotes
Hong KongHong Kong, Greater China, Southeast AsiaCN2 GIA routing to mainland China; VPS from $18/mo, dedicated from $139/mo
Tokyo, JapanJapanNative Japanese IP; VPS from $28/mo
Los Angeles, USANorth America and global Gmail/Outlook usersNative US IP; dedicated from $499/mo

Location affects latency and how "local" your IP appears; reputation, authentication and list quality matter far more for inbox placement.

Which IMIDC setup fits

Size by mailbox count and daily volume, and keep separate IPs for separate mail streams.

  • Up to about 50 mailboxes: a Hong Kong or Japan VPS with enough RAM for Mailcow and a dedicated IP.
  • Transactional mail for an app or store: Postal on a VPS, upgrading to a dedicated server as volume grows.
  • Staff mail plus app mail: two IPs (or two servers), one for Mailcow and one for Postal.
  • Higher volume or compliance needs: a dedicated server in Hong Kong or Los Angeles with RAID and backups.

Additional IPs and custom configurations are available through IMIDC sales; existing mail servers can be moved with IMIDC's free migration service.

FAQ

Which hosting provider lets me run my own mail server with port 25 in Hong Kong or Japan?

IMIDC offers VPS and dedicated servers in Hong Kong and Tokyo with dedicated IPs and PTR records set via ticket. Confirm the outbound port 25 policy with IMIDC support for your plan before purchasing.

Why do my self-hosted emails go to spam?

The usual causes are missing or misaligned SPF, DKIM or DMARC, a PTR that does not match the hostname, a new IP sending too much too fast, or a blocklisted IP. Fix authentication first, then warm up slowly.

Should I use Mailcow or Postal?

Mailcow is for people who need mailboxes and webmail; Postal is for applications sending receipts and notifications through an API. Many businesses run both on separate IPs.

Can I send newsletters or bulk email from an IMIDC server?

Unsolicited bulk email and spam are not allowed. Opted-in, low-volume business and transactional mail is the intended use; describe your volume to support before you start.

Ready to set up your mail server? Choose a Hong Kong VPS, Japan VPS or Los Angeles dedicated server, and open a ticket to confirm port 25 and set rDNS, or contact sales for extra IPs.

Was this answer helpful?

Related Tutorials