Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Start here

Domains and DNS

A domain is the part of an address after the @. The server only accepts mail for domains you add, and the internet only sends that mail here once DNS says so.

Add a domain

Go to Domains and choose Add a domain. Adding domains needs a global administrator.

  • Domain: for example example.com. Add the bare domain, not mail.example.com.
  • How is it used?
    • All its addresses are on this server (most common). Mail to an address that does not exist here is

    refused, so the sender learns right away that they mistyped.

    • Shared with another mail server. Some addresses live here and the rest on another server, for example while

    you move from Exchange or Google. Mail to addresses that are not here is passed on. Add an outgoing route for the domain that points at the other server (see Mail flow), otherwise that mail has nowhere to go.

    • Relay only. No mailboxes here; the server accepts the domain's mail and passes all of it on, again through an

    outgoing route. Useful for a backup MX or a gateway role.

  • Make default: new mailboxes get addresses in the default domain unless you pick another.

You can host many domains. Each belongs to one organization; a person can have addresses in several domains of their organization (see Users).

Records to create

Create these records at whoever hosts DNS for the domain: your registrar, Cloudflare, your ISP, or your own DNS server. The table below is live: it lists every domain of this organization with the exact values for this server (mail.example.com) and shows which records the server can already see.

In the admin center this section lists the exact records for your server and domains, and checks each one live.

What each record does:

RecordWhy
A for mail.example.comThe server's own name, pointing at its public IP address. Everything else refers to this name.
MX for the domainWhere other mail servers deliver mail for the domain. Without it, nobody can email you.
CNAME autodiscoverLets iPhones, Android phones, Macs and Outlook find the server when someone types only their email address.
CNAME autoconfigThe same for Thunderbird and many other IMAP apps. Optional.
TXT SPF v=spf1 mx -allSays this server may send mail for the domain. Without it, big providers (Gmail, Outlook.com) often put your mail in spam.

If mail for the domain already works somewhere else (Microsoft 365, Google Workspace, an old Exchange), change the MX record last, after the mailboxes exist here. Mail follows the MX record within minutes to hours.

Using Cloudflare

Set the autodiscover and autoconfig records and the A record of mail.example.com to DNS only (grey cloud). Cloudflare's proxy only carries web traffic, so mail servers and IMAP or SMTP apps cannot reach a proxied name.

Behind a filtering gateway

If incoming mail should first pass a spam and virus filter (for example the Obsidian email gateway or another service), point the MX record at the filter instead, and have the filter deliver to mail.example.com on port 25. The Domains page then shows the MX as Points elsewhere, which is expected.

DMARC

DMARC tells receiving servers what to do with mail that fails SPF. Start with a monitoring-only policy:

Name:  _dmarc.example.com
Type:  TXT
Value: v=DMARC1; p=none; rua=mailto:[email protected]

Create a postmaster address (for example as an extra address on an administrator's mailbox) to receive the reports. Once reports show only your own servers sending, you can tighten p=none to p=quarantine.

DKIM

The server signs outgoing mail with DKIM once you create a key and publish it: see Email signing (DKIM). With both SPF and DKIM in place, DMARC passes even when mail is forwarded.

Reverse DNS (PTR)

Many mail servers check that the server's IP address points back to its name. Ask whoever gives you the public IP address (your ISP or cloud provider) to set the reverse DNS of that address to mail.example.com. You cannot set this at your normal DNS provider.

Checking your records

The Domains page and the Setup guide re-check the records every time you open them. The check uses this server's own DNS resolver: if your network uses internal DNS that answers differently from the internet (split DNS), the result reflects the internal answers. To see what the internet sees, use a public tool such as MXToolbox, or on any computer:

nslookup -type=mx example.com 1.1.1.1
nslookup autodiscover.example.com 1.1.1.1

Changes at your DNS provider can take from a few minutes to a few hours to be visible everywhere.