Start typing to search across invoices, services, domains, tickets, and more...
You can run a reliable self-hosted business or transactional mail server if three things are right: a dedicated IP with matching rDNS/PTR, correct SPF, DKIM and DMARC, and a slow, honest warm-up — and you have confirmed with your provider that outbound port 25 is available. IMIDC servers in Hong Kong, Tokyo, Japan and Los Angeles, USA come with dedicated IPv4 addresses and rDNS set up via ticket, so you can run Mailcow for company mailboxes or Postal for application email.
Use Mailcow when people need inboxes; use Postal when applications need to send receipts, password resets and notifications.
| Aspect | Mailcow (dockerized) | Postal |
|---|---|---|
| Main purpose | Company mailboxes, calendars, webmail | Outbound transactional email for apps |
| Key components | Postfix, Dovecot, Rspamd, SOGo, ClamAV | SMTP server, HTTP API, click/open tracking, webhooks |
| Inbound mail | Full IMAP/POP3 mailboxes | Routes to HTTP endpoints or other servers |
| Typical resources | About 6 GB RAM plus swap per the project docs | Several GB RAM plus MariaDB |
| Best IMIDC fit | VPS or entry dedicated server | VPS for low volume, dedicated for high volume |
Many teams run both: Mailcow on one IP for staff mail, Postal on a separate IP so a marketing or app issue never hurts staff deliverability.
Before installing anything, verify the three prerequisites that no software can fix later.
# 1. is outbound port 25 open? (should print "succeeded"/"open")
nc -vz -w 5 gmail-smtp-in.l.google.com 25
# 2. does the PTR match your mail hostname?
dig -x 203.0.113.25 +short # expect: mail.example.com.
dig +short mail.example.com A # expect: 203.0.113.25
# 3. set the server hostname to the same FQDN
sudo hostnamectl set-hostname mail.example.com
Both projects ship official Docker-based installers; install Docker and Docker Compose first.
Mailcow for business mailboxes:
# mailcow: full business mailbox suite (SMTP, IMAP, webmail, antispam)
cd /opt
git clone https://github.com/mailcow/mailcow-dockerized
cd mailcow-dockerized
./generate_config.sh # enter mail.example.com and your time zone
docker compose pull
docker compose up -d
# then log in at https://mail.example.com, add domain + mailboxes,
# and copy the DKIM public key from Configuration > ARC/DKIM keys
Postal for transactional email:
# Postal: transactional / app mail with an HTTP API, webhooks and tracking
git clone https://github.com/postalserver/install /opt/postal/install
sudo ln -s /opt/postal/install/bin/postal /usr/bin/postal
docker run -d --name postal-mariadb -p 127.0.0.1:3306:3306 --restart always \
-e MARIADB_DATABASE=postal -e MARIADB_ROOT_PASSWORD=change-me mariadb
postal bootstrap postal.example.com
# edit /opt/postal/config/postal.yml (DB password, DNS names), then:
postal initialize
postal make-user
postal start
Postal's installer runs Caddy for HTTPS on the web UI; Mailcow obtains Let's Encrypt certificates itself. Open only the ports you need: 25, 465/587 for submission, 993 for IMAPS and 443 for the web UI.
Authentication records tell Gmail, Outlook and Yahoo that your server is allowed to send for your domain and that messages were not altered.
; DNS zone for example.com (adapt names, IP and DKIM key)
mail.example.com. A 203.0.113.25
example.com. MX 10 mail.example.com.
example.com. TXT "v=spf1 mx ip4:203.0.113.25 ~all"
dkim._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq...IDAQAB"
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:[email protected]; adkim=s; aspf=s"
_mta-sts.example.com. TXT "v=STSv1; id=20261008"
_smtp._tls.example.com. TXT "v=TLSRPTv1; rua=mailto:[email protected]"
mta-sts.example.com. A 203.0.113.25
p=none to collect reports, then moves to quarantine and reject once all legitimate sources pass.# served at https://mta-sts.example.com/.well-known/mta-sts.txt
version: STSv1
mode: testing
mx: mail.example.com
max_age: 86400
Start MTA-STS in testing mode, switch to enforce after a few clean weeks, and change the id whenever you edit the policy. Verify everything:
dig +short TXT example.com | grep spf1
dig +short TXT dkim._domainkey.example.com
dig +short TXT _dmarc.example.com
curl -s https://mta-sts.example.com/.well-known/mta-sts.txt
# TLS on submission and inbound SMTP
openssl s_client -starttls smtp -connect mail.example.com:25 -servername mail.example.com </dev/null | head -5
Major mailbox providers now expect SPF, DKIM and DMARC alignment, low spam-complaint rates and, for marketing mail, one-click unsubscribe; treat these as the minimum.
A new IP has no reputation, so increase volume gradually and send only to engaged, opted-in recipients.
| Period | Daily volume (per provider) | What to send | Watch |
|---|---|---|---|
| Days 1-3 | 20-50 | Internal and known contacts who will reply | Inbox vs spam placement |
| Days 4-7 | 50-200 | Transactional mail, most engaged customers | Bounces under 2% |
| Week 2 | 200-1,000 | Regular transactional flow | Complaints, Postmaster Tools |
| Weeks 3-4 | 1,000-5,000 | Normal operational volume | Deferrals (4xx), blocklists |
| After week 4 | Grow 20-30% per week if metrics stay clean | Steady volume | All of the above |
These are conservative starting points, not guarantees. If you see deferrals or spam-folder placement, hold volume flat until it clears. Register with Google Postmaster Tools and Microsoft SNDS to watch reputation.
Catching a listing or a stuck queue within hours keeps a small problem from becoming a week of lost mail.
#!/bin/sh
# rbl-check.sh 203.0.113.25 - run daily from cron, alert on any hit
IP="$1"; REV=$(echo "$IP" | awk -F. '{print $4"."$3"."$2"."$1}')
for BL in zen.spamhaus.org b.barracudacentral.org bl.spamcop.net; do
if dig +short "$REV.$BL" A | grep -q '^127\.'; then
echo "LISTED on $BL"
else
echo "clean $BL"
fi
done
# note: Spamhaus refuses queries via large public resolvers; use your own resolver
postqueue -p inside the Postfix container in Mailcow) and Postal's message log.Host the mail server close to where most recipients are and where your IP looks local.
| IMIDC location | Best for recipients in | Notes |
|---|---|---|
| Hong Kong | Hong Kong, Greater China, Southeast Asia | CN2 GIA routing to mainland China; VPS from $18/mo, dedicated from $139/mo |
| Tokyo, Japan | Japan | Native Japanese IP; VPS from $28/mo |
| Los Angeles, USA | North America and global Gmail/Outlook users | Native US IP; dedicated from $499/mo |
Location affects latency and how "local" your IP appears; reputation, authentication and list quality matter far more for inbox placement.
Size by mailbox count and daily volume, and keep separate IPs for separate mail streams.
Additional IPs and custom configurations are available through IMIDC sales; existing mail servers can be moved with IMIDC's free migration service.
IMIDC offers VPS and dedicated servers in Hong Kong and Tokyo with dedicated IPs and PTR records set via ticket. Confirm the outbound port 25 policy with IMIDC support for your plan before purchasing.
The usual causes are missing or misaligned SPF, DKIM or DMARC, a PTR that does not match the hostname, a new IP sending too much too fast, or a blocklisted IP. Fix authentication first, then warm up slowly.
Mailcow is for people who need mailboxes and webmail; Postal is for applications sending receipts and notifications through an API. Many businesses run both on separate IPs.
Unsolicited bulk email and spam are not allowed. Opted-in, low-volume business and transactional mail is the intended use; describe your volume to support before you start.
Ready to set up your mail server? Choose a Hong Kong VPS, Japan VPS or Los Angeles dedicated server, and open a ticket to confirm port 25 and set rDNS, or contact sales for extra IPs.