Docs / Obsidian Mail Server / Start here
Installing the server
Obsidian Mail Server is its own small operating system, built on Ubuntu Server 24.04 LTS. You install it on a physical machine or a virtual machine; there is nothing else to install first. It is currently running version 0.9.0.
What to download
| File | Use it for |
|---|---|
obsidian-mail-server-<version>-installer.iso | A physical server, or any hypervisor you prefer to install into |
obsidian-mail-server-<version>.vhdx + New-ObsidianVM.ps1 | Hyper-V (Generation 2, Secure Boot) |
obsidian-mail-server-<version>.ova | VMware ESXi, Workstation or Fusion |
SHA256SUMS | Checksums, to verify the download |
How big a server
4 CPU cores, 8 GB of memory and 64 GB of disk are enough for a few hundred mailboxes. Mail takes most of the disk, so size the disk for how much mail people keep. The virtual machine images start with a 64 GB disk; enlarge the virtual disk before the first start and the server grows into it automatically.
Install from the ISO
- Start the machine from the ISO. The first menu entry, Install Obsidian Mail Server, is the default.
- The installer asks only two things: the network and the disk. The whole disk is used. Everything it needs is on the disc, so no internet connection is required.
- The machine restarts into the first-boot setup (below).
Hyper-V
Copy the .vhdx and New-ObsidianVM.ps1 to the Hyper-V host and run, in an administrator PowerShell:
.\New-ObsidianVM.ps1 -Vhdx .\obsidian-mail-server-<version>.vhdx -Name MAIL01 -SwitchName "LAN"
Add -VlanId 25 (your VLAN) if the network needs one. The script creates a Generation 2 VM with Secure Boot set to the Microsoft UEFI Certificate Authority template (the Windows template cannot start Linux), 4 CPUs and 8 GB, and starts it. Open the VM's console to run the setup.
VMware
Deploy the OVA (Deploy OVF Template in vSphere, File > Open in Workstation or Fusion), choose the network and start it. Open the console to run the setup.
First-boot setup
The console shows Obsidian Mail Server setup instead of a login prompt. It asks, in order:
- Host name: the full public name of the server, for example
mail.example.com. Other mail servers greet it by this name and apps connect to it, so it should be the name your MX record will point to. - Network: keep DHCP (with a reservation, so the address never changes) or enter a fixed address, gateway and DNS servers.
- Time zone.
- Password for the
obsidianaccount, used on the console and over SSH. It can usesudo. There is no default password. - Firewall: opens only the ports the server uses (SSH 22, SMTP 25, 465 and 587, HTTP and HTTPS 80 and 443, IMAP 143 and 993, POP3 110 and 995).
- First organization (optional but recommended): your email domain, your organization's name, and an administrator mailbox with its password. That mailbox can sign in to this admin center.
The last screen lists the DNS records to create. To change any answer later, sign in on the console or over SSH and run:
sudo obsidian-setup
Changing the host name later also changes the name in the certificate apps expect. Plan the name before you create DNS records and certificates.
Firewalls and port forwarding
If the server sits behind a router or firewall, forward these ports from your public address to it:
| Port | Needed for |
|---|---|
| 25 | Receiving mail from the internet. Required. |
| 443 | Phones, Macs, Outlook, webmail and this admin center |
| 80 | Let's Encrypt certificates, and automatic setup in Thunderbird |
| 587 and 465 | Apps that send mail with SMTP (Thunderbird, Apple Mail with IMAP, printers) |
| 993 | Apps that read mail with IMAP |
| 995 | Apps that download mail with POP3 (rarely needed) |
The server itself also needs to reach other mail servers on port 25 outbound. Some internet providers block that port on home and small-business lines; in that case send outgoing mail through your provider's relay (see Mail flow).
After installing
Continue with Domains and DNS, then Certificates.