Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Mail flow

Mail flow, relays and the queue

How mail moves

  • Incoming: other mail servers find this server through your domain's MX record and deliver on port 25. The server accepts mail only for your domains and only for addresses that exist (unless a domain is shared with another server).
  • Between your own people: delivered straight into the mailbox, without leaving the server.
  • Outgoing: the server looks up the recipient domain's MX record and delivers directly, encrypting whenever the other side supports it. An outgoing route changes where mail goes (below).
  • From apps: mail apps send on port 587 (or 465) after signing in.

Global administrators manage outgoing routes and the queue under Mail flow & queue.

Sending through a relay

Send outgoing mail through another server (a smart host) when:

  • your internet provider blocks outgoing port 25 (common on home and small business lines),
  • your IP address has a poor reputation and mail lands in spam,
  • all outgoing mail must pass a filtering or archiving service.

Under Mail flow & queue, choose Add a route:

FieldEnter
NameAnything, for example Provider relay
Use for* for all outgoing mail, or specific domains (see below)
Relay serversThe relay's name, with a port if it is not the one below, for example smtp.provider.example:587. Several relays, separated by commas, are tried in order. Leave empty to deliver directly by MX.
PortUsually 587 for providers that need a sign-in, 25 for relays inside your network
Sign in withThe username and password the provider gave you, if any
Only send encryptedRefuse to send unless the connection is encrypted with a valid certificate. Recommended whenever you sign in.

New and changed routes are used within 30 seconds.

Routes for one domain

Use for accepts a list of domains, and the most specific match wins. With one route for * and another for partner.example, mail to partner.example takes the second route and everything else the first. *.example.org matches example.org and all its subdomains.

This is also how a domain shared with another server works: add a route for that domain whose relay server is the other mail server (for example the old Exchange server during a migration). Mail to addresses that exist here is delivered here; everything else goes to the other server.

Internal apps and devices

Applications, printers and scanners inside your network can send through the server without signing in if you allow their IP addresses to relay. This is set in the configuration file, on the port 25 listener:

sudo nano /etc/obsidian-mailserver/appsettings.json

Find the listener named Default Frontend under Transport > ReceiveConnectors and add a RelayFrom list of addresses or ranges:

{ "Name": "Default Frontend", "Bind": "[::]:25", "Usage": "Internet", "RelayFrom": [ "192.168.1.20/32", "10.0.5.0/24" ] }

Then sudo systemctl restart obsidian-mailserver. Those addresses may now send to any destination on port 25.

Keep the list as small as possible. Anything that can send from those addresses can use the server to send mail anywhere, which is how servers end up on spam blocklists.

Size and recipient limits

  • Messages up to 36 MB are accepted (the size includes attachments, which grow by about a third when sent).
  • A message sent by an app may have up to 200 recipients; mail arriving from other servers up to 5,000.

Both can be changed per listener in the configuration file (MaxMessageSize, MaxRecipientsPerMessage); see Configuration.

The queue

When the receiving server is down or busy, the message waits in the queue and the server tries again, with longer gaps between attempts:

  • After 4 hours the sender gets a notice that delivery is delayed and still being tried.
  • After 2 days the server gives up and returns the message to the sender with the reason.

Mail flow & queue lists everything waiting, with the last answer from the other server. Retry all now tries every waiting message immediately, for example after fixing a network problem. The header's Queue counter shows the number of waiting deliveries at all times.

Track a message

Track a message shows what happened to mail, newest first. Search by sender, recipient or message ID (the ID is in the message's headers). The steps mean:

StepMeaning
ReceivedArrived from another server
Sent by userSent by someone here, from webmail, a phone or an app
DeliveredPut into a mailbox on this server
Sent onHanded to another mail server, which accepted it
DelayedThe other side was not reachable or said "try later"; the server will retry
FailedThe other side refused it; the sender gets a notice with the reason
Gave upStill undeliverable after 2 days; returned to the sender
Notice sentA delivery report (delay or failure notice) was sent to the sender

The Details column has the other server's exact answer, which usually says what is wrong (for example 550 5.1.1 user unknown for a mistyped address).

Spam and virus filtering

The server does not filter spam or viruses itself. Put a filtering gateway or service in front of it (see DNS). If the filter marks spam with Exchange's spam-confidence header (X-MS-Exchange-Organization-SCL of 5 or more), the server files it in the person's Junk Email folder.