Docs / Obsidian Mail Server / Running the server
Security notes
What the server does
- Encryption everywhere. Webmail, this admin center, phones and apps connect over TLS. Mail between servers is encrypted whenever the other side supports it. Passwords are never accepted over an unencrypted connection.
- Passwords are stored as Argon2id hashes, never in readable form. For NTLM, an encrypted NTLM hash is kept too.
- Guessing is throttled. After 10 wrong passwords within 15 minutes, further attempts for that account and from that IP address are refused for a while.
- Web sessions end after 8 hours without activity and after 24 hours at most, and are protected against cross-site request forgery. Resetting a password signs the person out of webmail everywhere.
- Mail content is sanitized before webmail shows it: scripts are removed, and pictures from the internet stay blocked until the reader allows them, so senders cannot track opens.
- Administrator roles limit who can change what, and Change history records every change.
- Updates are signed and checked by
aptbefore installing (see Updates). - Outgoing mail can be DKIM-signed per domain (see Email signing); mail from the internet that is forwarded on is never signed, so the server cannot vouch for a spoofed sender.
- The firewall set up at installation opens only the ports the server uses.
NTLM sign-in for Outlook
Outlook for Windows prefers NTLM (Windows sign-in) over sending the password with every request. The server supports it for Outlook's connections (automatic setup, Exchange Web Services, MAPI over HTTP and the offline address book), not for phones, which keep using the password. It is off until you turn it on:
sudo oms ntlm status # is it on, and how many accounts are ready
sudo oms ntlm enable
sudo oms ntlm disable
sudo oms ntlm purge # forget every stored NTLM hash
- Accounts become ready as people sign in. NTLM needs the account's NTLM hash, which the server can only compute from the password: it is stored whenever a password is set, and at the next sign-in with the password (webmail, a phone, IMAP, or Outlook itself before NTLM is on). Accounts that are not ready yet fail NTLM, and the log says why. Turn it on once
oms ntlm statusshows most accounts ready, or reset the passwords of the others. - The NTLM hash works like a password for NTLM, so it is encrypted with a key kept outside the database (
/var/lib/obsidian-mailserver/keys/credential.key). A database backup alone does not reveal it; back up the key file with the server's other data.oms ntlm purgeremoves all of them. - Only NTLMv2 is accepted, only over HTTPS, and only after the same guessing limits as passwords.
- Extended Protection (
Oms.Ntlm.ChannelBinding, see Configuration) ties each sign-in to the server's certificate, so it cannot be relayed through another server. If a proxy in front of the server handles HTTPS, set it toNone. - Signing in as
DOMAIN\nameworks when the domain is written as the email domain (example.com\name); otherwise sign in with the email address.
What to add
| Gap | Recommendation |
|---|---|
| No spam or virus filter | Put a filtering gateway or service in front of the server (see DNS). |
| No two-factor sign-in yet | Use long, unique passwords. Consider keeping webmail and the admin center reachable only from your network or a VPN, and publishing only what phones need. |
| Admin center reachable wherever webmail is | Restrict port 443 at your firewall or reverse proxy if only some networks should reach /admin. |
Good habits
- Give each administrator their own account and the lowest role that does the job; use Helpdesk for password resets.
- Keep the
RelayFromlist for internal apps short (see Mail flow). - Install updates promptly:
sudo apt update && sudo apt upgrade. - Keep backups off the server and test a restore (see Backups).
- Protect the
obsidianconsole account: it can change everything. Prefer SSH keys over passwords for remote access. - Block or erase lost phones promptly (see Phones and tablets).