Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Reference

Configuration file

Most things are set in this admin center. The rest (host name, listening ports, certificates, limits) lives in one file on the server:

/etc/obsidian-mailserver/appsettings.json

Edit it with sudo nano /etc/obsidian-mailserver/appsettings.json, then apply the change with sudo systemctl restart obsidian-mailserver. The file is JSON: keep the quotes, braces and commas intact, and check it with python3 -m json.tool /etc/obsidian-mailserver/appsettings.json before restarting. Updates add new sections with their defaults but never change what you set.

Durations are written as "days.hours:minutes:seconds", for example "2.00:00:00" for two days or "00:05:00" for five minutes. Sizes are in bytes (37748736 is 36 MB).

General (Oms)

SettingDefaultMeaning
Hostnameset by the setupThe server's public name (mail.example.com), used in greetings, message headers and certificates
Databaseset by the setupPostgreSQL connection. Leave as is.
DataRoot/var/lib/obsidian-mailserverWhere mail content and generated certificates are kept
Tls.CertificatePathnone (self-signed)Certificate: a PEM file with the chain, or a .pfx file. See Certificates.
Tls.KeyPathnonePrivate key, when the certificate is a PEM file
Tls.PfxPasswordnonePassword of a .pfx file

Listeners for mail from other servers and apps

Oms.Transport.ReceiveConnectors is a list; each entry opens one SMTP port. The installed defaults are:

"ReceiveConnectors": [
  { "Name": "Default Frontend", "Bind": "[::]:25", "Usage": "Internet" },
  { "Name": "Client Frontend", "Bind": "[::]:587", "Usage": "Client", "MaxRecipientsPerMessage": 200 },
  { "Name": "Client Proxy TLS", "Bind": "[::]:465", "Usage": "Client", "ImplicitTls": true, "MaxRecipientsPerMessage": 200 }
]
SettingDefaultMeaning
NameA label, shown in logs and on the home page
Bind0.0.0.0:25Address and port. [::]:25 listens on all IPv4 and IPv6 addresses.
UsageInternetInternet: mail from other servers, no sign-in, only for your domains. Client: apps, sign-in required, sender must be the signed-in person (or someone they may send as).
ImplicitTlsfalseEncrypt from the first byte (port 465) instead of upgrading with STARTTLS
AllowPlaintextAuthfalseAllow sign-in without encryption. Only for listeners on 127.0.0.1.
RelayFromemptyIP ranges that may send to any destination without signing in (see Mail flow)
RemoteRangesempty (everyone)IP ranges allowed to connect at all
MaxMessageSize37748736 (36 MB)Largest message accepted
MaxRecipientsPerMessage5000Recipients per message
MaxConnectionsPerIp20Simultaneous connections from one address
MaxProtocolErrors10Errors before the connection is closed
CommandTimeout00:05:00Idle time before the connection is closed
BannerObsidian Mail Server readyText in the greeting after the host name

Delivery and the queue (Oms.Transport)

SettingDefaultMeaning
MessageExpiration2.00:00:00How long to keep retrying before returning mail to the sender
DelayNotification04:00:00When to tell the sender that delivery is delayed
QueueWorkers4Deliveries in parallel
OutboundTimeout00:02:00Time to wait for another mail server
OpportunisticTlsAcceptAnyCertificatetrueEncrypt to servers with invalid certificates rather than send unencrypted (standard for mail servers). Routes with Only send encrypted always check certificates.
MaxHopCount60Mail that passed through more servers than this is treated as a loop

IMAP and POP3 (Oms.Imap, Oms.Pop3)

Each has an Endpoints list. The installed defaults listen on 143 and 993 (IMAP) and 110 and 995 (POP3):

"Imap": { "Endpoints": [ { "Name": "IMAP4", "Bind": "[::]:143" }, { "Name": "IMAP4 SSL", "Bind": "[::]:993", "ImplicitTls": true } ] }
SettingDefaultMeaning
Endpoints[].Bind, ImplicitTls, AllowPlaintextAuth, RemoteRangesAs for SMTP listeners above
Endpoints[].MaxConnectionsPerIp50Simultaneous connections from one address
Imap.MaxMessageSize37748736Largest message an app may upload
Imap.IdleTimeout00:30:00Idle time before an IMAP connection is closed
Pop3.IdleTimeout00:10:00Idle time before a POP3 connection is closed

To switch POP3 off, empty its list: "Pop3": { "Endpoints": [] }, and set ClientAccess.AdvertisePop3 to false.

Web, phones and automatic setup (Oms.ClientAccess)

SettingDefaultMeaning
HttpEndpoints[::]:443 (HTTPS) and [::]:80 (HTTP)Web listeners: { "Bind": "[::]:443", "Https": true }
PublicHostthe host nameThe name apps are told to connect to, if it differs from Hostname
ImapPort, Pop3Port, SmtpPort, HttpsPort993, 995, 587, 443Ports apps are told to use, for example when a firewall forwards other port numbers
AdvertisePop3trueOffer POP3 in automatic setup

Outlook sign-in (Oms.Ntlm)

Whether NTLM is offered at all is switched with sudo oms ntlm enable|disable (see NTLM sign-in for Outlook).

SettingDefaultMeaning
ChannelBindingWhenSuppliedExtended Protection. WhenSupplied: when Outlook ties its sign-in to the certificate (it always does over HTTPS), it must be this server's. Required: refuse clients that do not. None: only when a proxy in front of the server handles HTTPS.

Phones (Oms.ActiveSync)

SettingDefaultMeaning
RequireProvisioningtruePhones must accept the security rules before syncing
MinHeartbeatSeconds, MaxHeartbeatSeconds60, 3540Range for push connections. Lower the maximum if a firewall closes idle connections sooner.
MaxWindowSize512Items per sync request

Logging

"Logging": { "LogLevel": { "Default": "Information" } }

Set Default to Debug temporarily when investigating a problem, and back to Information afterwards. Logs go to the system journal: sudo journalctl -u obsidian-mailserver -f.