← Back to Blog

Self-Hosted Mail Server on a VPS: Should You, Which Stack, and How to Reach the Inbox

Published · by RS Computers

Mail server Mailcow VPS

A self-hosted mail server on a VPS keeps your mailboxes on a server you rent and run, not with Google or Microsoft, and installing one is the easy part: mailcow, Mail-in-a-Box and Stalwart each give you a working server in an afternoon. Whether Gmail and Outlook accept your mail depends on things no installer controls: a clean IPv4 address, a reverse DNS (PTR) record that matches your mail hostname, open outbound port 25, and SPF, DKIM and DMARC records that pass.

Before you start: four facts decide most of the outcome.

Should you self-host email at all?

Plenty of experienced admins say no. Carlos Fenollosa ran his own mail from 1999 to 2022, with SPF, DKIM, DMARC, a correct PTR and a perfect mail-tester score, and gave up because large providers dropped his messages without a bounce. A mailcow issue about Microsoft junking mail from clean, authenticated servers has been collecting comments since August 2019. These are not beginner mistakes.

Still, for a household or small office that mostly writes to people who reply, a well-kept server can deliver reliably. Go ahead only if every line is true:

  1. Outbound port 25 works from the server (step 3 below tests it).
  2. You can set the PTR of the server's IP to your mail hostname.
  3. The IP is clean at check.spamhaus.org.
  4. You send conversations and app notifications, such as a contact form or a web shop's order emails, far below 5,000 messages a day to any big provider.
  5. Someone checks the server weekly and patches within days.
  6. Backups can go somewhere off the server.

It is a no-go for newsletters from the same IP, or for a business whose clients live on Microsoft 365, where one invoice in Junk costs real money. It is also a no-go if nobody will patch: mailcow alone shipped six security-related releases between May 12 and August 18, 2026. The middle road, often suggested in that mailcow issue, keeps mailboxes on your own server and sends outgoing mail through a relay service with an established reputation.

Why keep mail on your own server?

A self-hosted mail server on a VPS puts you in control of where the mail lives: one machine in Amsterdam or Dublin, inside the EU, with your own logs and backups, which helps when GDPR Article 33 or Kosovo's Law No. 06/L-082 gives you 72 hours to report a breach. Kosovo has no EU adequacy decision, though, so EU personal data on a Prishtina server needs safeguards such as Standard Contractual Clauses.

The other draw is freedom from seats. Microsoft 365 Business plans cap a user mailbox at 50 GB; on your own server the disk sets the limit, and another domain or alias costs nothing. Shared files are the other half of a hosted suite; our guide to Nextcloud as a private cloud covers that part. What hosted suites keep is sending IPs with years of good history.

Mailcow vs Mail-in-a-Box vs Stalwart: which one?

mailcow is a free mail suite that runs Postfix, Dovecot, Rspamd, SOGo and ClamAV as Docker containers behind one admin panel. Mail-in-a-Box is a one-command installer that turns a fresh Ubuntu server into a complete mail appliance. Stalwart is a single program, written in Rust, that speaks SMTP, IMAP, JMAP, CalDAV and CardDAV by itself. Pick mailcow unless memory is tight. Pick Mail-in-a-Box for an appliance with nothing to tune, if you can live on Ubuntu 22.04, whose standard support ends in May 2027. Pick Stalwart for a light, modern server, if version 0.x and no webmail do not bother you. Sources: the mailcow system requirements, Stalwart's requirements and the Mail-in-a-Box setup guide.

FeaturemailcowMail-in-a-BoxStalwart
Memory6 GiB + 1 GiB swap minimum; 8 GiB for about 5 to 10 users512 MB minimum, 1 GB recommendedAbout 100 MB idle; 1 GB for 5 to 10 users
Operating systemDebian 11 to 13, Ubuntu 22.04 or newer, Alma 8/9, Rocky 9; KVM yes, OpenVZ and LXC noA fresh Ubuntu 22.04 x64 onlyLinux install script (used here on Debian 13) or Docker image
WebmailSOGoRoundcubeNone included
Calendars and phonesSOGo CalDAV/CardDAV, ActiveSyncNextcloud CalDAV/CardDAV, Z-Push ActiveSyncCalDAV, CardDAV, JMAP
DNSYou publish; the panel lists each domain's recordsIts own nameserver via glue records, or you copy its recordsManual, or published and kept current through a DNS provider's API, DKIM key rotation included (since 0.16.0)
MTA-STSPer-domain tab since 2025-09Published automatically (enforce)Built in, with DANE and TLS reporting
LicenceGPL-3.0CC0 1.0AGPL-3.0 or commercial Enterprise
Latest release before this article2026-09 (September 21, 2026)v77 (September 26, 2026), a Roundcube security updatev0.16.25 (October 5, 2026)

What do Gmail, Yahoo and Outlook.com require from senders?

Deliverability is the share of your mail that lands in the inbox rather than in spam or nowhere, and for a self-hosted server it is the whole game. Google's email sender guidelines have applied to every sender since February 1, 2024: SPF or DKIM, valid forward and reverse DNS, TLS, and a spam rate below 0.3% (Google advises staying under 0.1%). Anyone who comes close to 5,000 messages a day to personal Gmail accounts becomes a bulk sender for good and also needs SPF and DKIM together, DMARC (p=none is enough), an aligned From domain and one-click unsubscribe. Since November 2025 Gmail has enforced this with temporary and permanent rejections. Yahoo has enforced nearly the same list since February 2024, reverse DNS included.

Microsoft followed on April 2, 2025 with rules for Outlook.com, Hotmail.com and Live.com: domains sending more than 5,000 messages a day must pass SPF and DKIM and publish DMARC (at least p=none) aligned with one of them. Since May 5, 2025 failing mail bounces with 550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level.

A small server is not a bulk sender, but meet the bulk rules anyway; on your own server they cost nothing. Just know their limit. SPF, DKIM and DMARC prove who sent a message. They say nothing about whether anyone wants it.

Reverse DNS, port 25 and a clean IP

What is a PTR record for email?

A PTR record, also called reverse DNS, maps an IP address back to a name: ask about 203.0.113.10 and it answers mail.example.com. Receiving servers look it up when you connect, then check that mail.example.com points back to the same IP. Only the owner of the IP, your hosting provider, can set it. Your domain registrar cannot.

Gmail answers a missing or mismatched PTR with 451 4.7.23 or 550 5.7.25, and the PTR, the A record and your HELO name must agree. Every RS Computers plan has IPv6: give that address its own PTR and AAAA record too, or keep outbound mail on IPv4.

On an RS Computers server, set the PTR for the IPv4 address yourself with the reverse DNS setting in the client area. If that does not work, message us on Telegram with the IP address and the hostname you want. For a PTR on the IPv6 address, ask us there too.

Port 25: can your server send at all?

Servers deliver to each other on port 25, so it must be open outbound as well as inbound; 465 and 587 only serve your mail apps. DigitalOcean blocks it on all Droplets and documents no way to lift it, Hetzner Cloud blocks it until the account is a month old, the first invoice is paid and you ask, and AWS EC2 until you ask. On RS Computers, outbound port 25 is blocked on a new server and opened on request: message us on Telegram, then confirm it with the test in step 3.

Is your IP already on a blocklist?

A VPS address is second-hand, so check it at check.spamhaus.org first. Don't trust a quick dig against zen.spamhaus.org through 8.8.8.8 or 1.1.1.1: Spamhaus refuses queries from public resolvers and answers 127.255.255.254, which looks like a listing and is not one. If Microsoft 365 bounces you with 550 5.7.606 to 5.7.649 (banned sending IP), use Microsoft's delist portal at sender.office.com.

Which DNS records does a mail server need?

For example.com, served by mail.example.com at 203.0.113.10 (mailcow's DNS button shows your exact values):

  1. A: mail IN A 203.0.113.10. Add AAAA only once the IPv6 address has a PTR.
  2. MX: @ IN MX 10 mail.example.com. tells other servers where to deliver.
  3. SPF (RFC 7208), the servers allowed to send: @ IN TXT "v=spf1 mx a -all". More than 10 DNS lookups and the check fails with a permanent error (permerror).
  4. DKIM (RFC 6376), the public key for your signatures: dkim._domainkey IN TXT "v=DKIM1; k=rsa; p=...". Some DNS hosts need a long key split into quoted strings.
  5. DMARC, your policy for mail that fails authentication, plus a report address: _dmarc IN TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com".
  6. MTA-STS (RFC 8461), which makes senders use verified TLS: _mta-sts IN TXT "v=STSv1; id=20260611T000000" plus a policy file.
  7. TLS-RPT (RFC 8460), where senders report TLS failures: _smtp._tls IN TXT "v=TLSRPTv1; rua=mailto:tlsrpt@example.com".
  8. autoconfig and autodiscover: CNAMEs to mail.example.com, so Thunderbird and Outlook set themselves up.

DMARC: start at none, end at reject

mailcow's documentation example starts at p=reject. Don't. Begin with p=none, read the aggregate reports for a few weeks to find every service sending as your domain, then move to quarantine and finally reject, the gradual path Microsoft recommends too. A tutorial that adds pct=100 predates RFC 9989, the May 2026 DMARC standard that replaced RFC 7489 and dropped the pct tag.

The MTA-STS policy file

Senders fetch it from https://mta-sts.example.com/.well-known/mta-sts.txt, so add an mta-sts CNAME to the mail host. mailcow builds it from a per-domain MTA-STS tab; Mail-in-a-Box and Stalwart publish their own:

version: STSv1
mode: testing
mx: mail.YOUR_DOMAIN
max_age: 86400

Stay in testing until the TLS-RPT reports are clean, then switch to enforce and change the id in the TXT record.

What RS Computers gives a mail server

mailcow does not support OpenVZ or LXC containers, and every RS Computers server is a full KVM virtual machine, in Amsterdam (Netherlands), Dublin (Ireland) or Prishtina (Kosovo). Check the plans page for locations currently accepting orders. For mail, what counts most is the IPv4 and IPv6 address every plan gets for itself: Google's sender guidelines say the activity of every sender on a shared IP affects the reputation of all of them. Mailboxes sit on NVMe storage, and traffic is unmetered on a 1 Gb/s port (VPS) or 10 Gb/s (VDS).

Pick Debian 13 from the Linux distributions offered, or Ubuntu 22.04 for Mail-in-a-Box (ask us if it is missing); Windows Server, on VPS Mini and all VDS plans, is not needed. Our free weekly backup copies the whole server and can be restored from the client area; treat it as the floor under your own daily mail backups. When the mail outgrows the plan, the bigger plan is an upgrade in the client area and a short reboot, on the same server.

Which plan for which mail stack?

Figures come from each project's docs; the VDS Large row is our judgement.

PlanMailboxes it carries
VPS Nano (1 vCPU, 1 GB, 20 GB NVMe, 1 Gb/s)A household's few mailboxes on Stalwart, which its docs size at 1 GB for 5 to 10 users, or Mail-in-a-Box at its recommended 1 GB.
VPS Micro (2 vCPU, 2 GB, 40 GB NVMe, 1 Gb/s)A small office on Stalwart, or Mail-in-a-Box with headroom for SpamAssassin's memory spikes when junk is moved in bulk.
VPS Mini (4 vCPU, 4 GB, 80 GB NVMe, 1 Gb/s)A busier office on Stalwart or Mail-in-a-Box. Below mailcow's 6 GiB minimum.
VDS Small (4 vCPU, 8 GB, 240 GB NVMe, 10 Gb/s)About 5 to 10 mailboxes on mailcow as shipped, SOGo and ClamAV included; that is the load its docs give 8 GiB for.
VDS Medium (8 vCPU, 16 GB, 480 GB NVMe, 10 Gb/s)A mailcow office with phones on ActiveSync; the docs plan 16 GiB for 15 phones and about 50 IMAP connections.
VDS Large (16 vCPU, 32 GB, 960 GB NVMe, 10 Gb/s)Many client domains on one mailcow, or years of shared mailboxes and archives.

Set up a self-hosted mail server on a VPS with mailcow (Debian 13)

Log in as root on a fresh Debian 13 server (or run sudo -i) and replace YOUR_DOMAIN, YOUR_IPV4 and YOUR_IPV6 with your values. Our Debian 13 template accepts root logins with a password, and the guessing starts early: a fresh test server we started from that template logged its first SSH password guess less than six minutes after boot. So put your SSH key on the server and switch password login off before you install anything; week 2 of our guide to a Linux practice lab on a VPS shows the order that avoids a lockout. Sharing ports 80 and 443 with websites? See our reverse proxy guide for Caddy, Nginx and Traefik.

Step 1: Prepare Debian

Start by updating the system, installing the tools used later, naming the server and adding the 1 GiB of swap that mailcow's minimum includes.

# as root
apt update && apt full-upgrade -y
apt install -y curl git ca-certificates bind9-dnsutils netcat-openbsd openssl gawk coreutils grep jq
hostnamectl set-hostname mail.YOUR_DOMAIN
fallocate -l 1G /swapfile && chmod 600 /swapfile && mkswap /swapfile && swapon /swapfile
echo '/swapfile none swap sw 0 0' >> /etc/fstab
swapon --show
timedatectl status

swapon --show should list /swapfile with a size of 1G; on an RS Computers server our Debian 13 template's 1 GB swap partition is listed above it, so you end up with 2 GiB. timedatectl should show System clock synchronized: yes. If NTP is inactive, run timedatectl set-ntp true; if that says NTP is not supported, install systemd-timesyncd with apt first. Ubuntu 24.04 works the same.

Step 2: Create the DNS records and the PTR

Create the A record for mail.YOUR_DOMAIN, the MX record and the autoconfig and autodiscover CNAMEs now: mailcow requests its Let's Encrypt certificate for mail.YOUR_DOMAIN on first start and adds autoconfig and autodiscover once your domain exists in mailcow. Skip the AAAA record until the IPv6 PTR exists, and set the PTR to mail.YOUR_DOMAIN.

Step 3: Run the checks that decide everything

Five commands: the first tests outbound port 25 over IPv4, the next three read back the PTR and A records, and the last lists anything already using the mail ports. The dig lines ask a public resolver (@1.1.1.1) on purpose: once step 1 has named the server, its own resolver answers for that name with the server's local addresses, and for its own IP with the hostname, even when no real A or PTR record exists.

# as root
nc -4 -vz -w 5 gmail-smtp-in.l.google.com 25
dig @1.1.1.1 -x YOUR_IPV4 +short
dig @1.1.1.1 +short A mail.YOUR_DOMAIN
dig @1.1.1.1 -x YOUR_IPV6 +short
ss -tlpn | grep -E ':(25|80|110|143|443|465|587|993|995|4190)\s'

Good output ends the first line with 25 port [tcp/smtp] succeeded!, shows mail.YOUR_DOMAIN. and then your IPv4 address for the first two dig lines, and nothing from ss. If nc times out, port 25 is blocked: on RS Computers it stays blocked on a new server until you ask, so message us on Telegram and run the test again; with a provider that will not open it, stop here. If the IPv6 lookup is empty, follow mailcow's "Disable IPv6" page after installing. If ss shows exim4, remove it with systemctl disable --now exim4 and apt purge -y 'exim4*'.

Step 4: Install Docker from Docker's repository

mailcow needs Docker 24.0.0 and Compose 2.0 or newer from Docker's own packages, not Debian's, so add Docker's apt repository and install both from there.

# as root
install -m 0755 -d /etc/apt/keyrings
curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc
chmod a+r /etc/apt/keyrings/docker.asc
tee /etc/apt/sources.list.d/docker.sources <<EOF
Types: deb
URIs: https://download.docker.com/linux/debian
Suites: $(. /etc/os-release && echo "$VERSION_CODENAME")
Components: stable
Architectures: $(dpkg --print-architecture)
Signed-By: /etc/apt/keyrings/docker.asc
EOF
apt update
apt install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
systemctl enable --now docker
docker run hello-world
docker compose version

Expect Hello from Docker! and a Compose version of 2 or higher. On Ubuntu 24.04, use https://download.docker.com/linux/ubuntu as the URI and first remove Ubuntu's docker.io, containerd and runc packages.

Step 5: Download mailcow and generate the configuration

mailcow lives in /opt/mailcow-dockerized. Clone it there and run its configuration script, which asks a few questions.

# as root
umask 0022
cd /opt
git clone https://github.com/mailcow/mailcow-dockerized
cd mailcow-dockerized
./generate_config.sh

Answer the hostname question with mail.YOUR_DOMAIN, not the bare domain, accept the detected time zone, and choose 1 for the stable branch. On a server with working IPv6, which every RS Computers server has, it then asks /etc/docker/daemon.json not found. Create it with IPv6 settings? [Y/n]: press Enter, because answering n stops the script. If the Spamhaus ASN check at the start prints Check failed!, carry on; that check only informs. Afterwards ls shows a new mailcow.conf. If the script stops with Cannot find Docker with a Version higher or equals 24.0.0, go back to step 4.

Step 6: Start mailcow and check the certificate

Docker publishes mailcow's ports (25, 465, 587, 993, 4190, 80, 443, plus 110, 143 and 995) straight past ufw's rules, so ufw cannot filter them and would only guard SSH here; our Debian 13 template does not include it anyway. That firewall trap is explained in more detail in our guide to Docker on a VPS. Now pull the images, start them in the background and list them.

# as root
cd /opt/mailcow-dockerized
docker compose pull
docker compose up -d
docker compose ps

Every -mailcow container should show Up, and those with health checks turn healthy after a short while. bind: address already in use means another program holds a port. This command then shows the certificate log.

# as root
cd /opt/mailcow-dockerized
docker compose logs --tail=200 acme-mailcow

Success reads Certificates successfully requested and renewed where required, sleeping one day. On a clean test server on our network (8 vCPU, 16 GB RAM), the pull took 39 seconds and that line appeared about a minute after docker compose up -d. If you see HTTP validation failed, port 80 is not reaching the server. When port 80 has to stay closed or belongs to another web server, mailcow 2026-03 and newer can prove the name through your DNS provider's API instead: the DNS-01 challenge, set up with ACME_DNS_CHALLENGE=y and your provider's API details in mailcow.conf, needs no port 80. If you see Found AAAA record without working IPv6, delete that AAAA record. After fixing DNS, run docker compose restart acme-mailcow.

Step 7: Log in, publish SPF, DKIM and DMARC, and test

Open https://mail.YOUR_DOMAIN/admin, log in as admin with the documented default password moohoo, change it at once and set up two-factor login. Under E-Mail > Configuration add your domain and a mailbox, then publish the SPF, DKIM and DMARC records listed under the domain's DNS button. Run docker compose restart acme-mailcow in /opt/mailcow-dockerized so the certificate takes in autoconfig and autodiscover now rather than on its next daily run. Webmail is SOGo at https://mail.YOUR_DOMAIN/SOGo/so/. Then mail a Gmail address you own, choose Show original and look for PASS next to all three; a failing DKIM usually means the TXT record got cut at your DNS host.

Stalwart or Mail-in-a-Box instead

Stalwart runs natively, so ufw works. Open the mail ports and the setup wizard's port 8080 first, then install Stalwart (it runs as an unprivileged stalwart user) and read the one-time admin login from the journal.

# as root
apt install -y ufw
ufw allow OpenSSH
ufw allow proto tcp from any to any port 25,80,443,465,587,993,4190
ufw allow 8080/tcp
ufw --force enable
curl --proto '=https' --tlsv1.2 -sSf https://get.stalw.art/install.sh -o install.sh
sh install.sh
journalctl -u stalwart -n 200 | grep -A8 'bootstrap mode'

The installer prints Installation complete!, and the journal lines show username: admin and a password:; copy it, as it is printed once. Finish the wizard at http://mail.YOUR_DOMAIN:8080/admin, run systemctl restart stalwart, then ufw delete allow 8080/tcp. A 404 there means no HTTPS access to GitHub, where the web UI comes from. Since version 0.16.0 (April 20, 2026), Stalwart can publish its MX, SPF, DKIM, DMARC, MTA-STS and TLS-RPT records through your DNS provider's API and rotate DKIM keys by itself; with DNS left on manual, View DNS Zone file in the domain's menu gives you the records to paste in.

Mail-in-a-Box needs a fresh Ubuntu 22.04 server; this command runs its installer with sudo.

# as the YOUR_USER user (any account with sudo rights)
curl -s https://mailinabox.email/setup.sh | sudo -E bash

It asks for your email address and hostname, near the end for a password for that address (your control panel login), and finishes with Your Mail-in-a-Box is running. and the control panel address. If it stops saying your hostname or IP is listed in the Spamhaus lists while check.spamhaus.org shows you clean, your server asks a public resolver, Spamhaus answers 127.255.255.254, and the installer reads any answer as a listing. Once the step 3 port 25 test passes, run it again as curl -s https://mailinabox.email/setup.sh | SKIP_NETWORK_CHECKS=1 sudo -E bash. Copy /home/user-data/backup/secret_key.txt off the box at once; its encrypted backups are unreadable without it.

The first weeks: warm-up without a schedule

Nobody publishes a warm-up schedule. Google says to start with low volume to people who engage and grow without spikes; Amazon's SES documentation says a new IP needs about two weeks to build reputation with some mailbox providers and up to six with others. What works in practice, not as a rule:

  1. Start with real conversations, and ask a few Gmail and Outlook.com contacts to move anything that lands in spam back to the inbox.
  2. Move existing mailboxes over a few at a time.
  3. Send newsletters through a separate sending service, never from this IP.
  4. Watch Google Postmaster Tools and Microsoft SNDS, which moved to a new portal in June 2026; register your IP there, not at the address older guides give. Keep the Gmail spam rate under 0.1% and never let it reach 0.3%.
  5. If Gmail answers 421 4.7.28, do what Google says: stop sending for at least 10 minutes, then resume from a single connection.

Updates, backups and monitoring

mailcow ships roughly monthly, faster when it matters. The May 2026 run included SOGo 5.12.8 for four known vulnerabilities, release 2026-07a of July 30 fixed an Nginx CVE and asked everyone to update as soon as possible, and 2026-07b of August 18 updated Redis, SOGo and ClamAV for security issues. Before every update, back up all mailcow components with its own helper script, then check whether a new release is out.

# as root
mkdir -p /opt/backup
cd /opt/mailcow-dockerized
MAILCOW_BACKUP_LOCATION=/opt/backup ./helper-scripts/backup_and_restore.sh backup all --delete-days 3
./update.sh --check

ls /opt/backup now shows a mailcow- folder named after the date and time, and the check prints No updates available. or announces new code or a new tag, in which case you run ./update.sh. For a nightly copy at 03:30 that keeps three days, install cron if the image lacks it (--no-install-recommends stops apt from adding the exim4 mail server, which would fight mailcow for port 25) and add one line to /etc/cron.d.

# as root
apt install -y --no-install-recommends cron
echo '30 3 * * * root cd /opt/mailcow-dockerized && MAILCOW_BACKUP_LOCATION=/opt/backup ./helper-scripts/backup_and_restore.sh backup all --delete-days 3' > /etc/cron.d/mailcow-backup
cat /etc/cron.d/mailcow-backup

cat prints the line back, and each morning brings a new folder. Keep the crypt component with vmail, since mailcow encrypts mail at rest and needs those keys, and copy the folder off the server as in our restic off-site backup guide. Restore with ./helper-scripts/backup_and_restore.sh restore on a running mailcow, and test it once. For Stalwart, copy /var/lib/stalwart and /etc/stalwart while the service is stopped; Mail-in-a-Box backs up nightly to its own disk until you add an S3 or rsync target.

Watch ports 25, 587 and 993 and the certificate expiry from a second server, as in our Uptime Kuma and Grafana monitoring guide. A growing mail queue (docker compose exec postfix-mailcow postqueue -p) is usually the first sign of trouble.

Security: the web panels are the soft spot

Attackers go for the web side. CISA's Known Exploited Vulnerabilities catalog lists 11 Roundcube Webmail flaws, two of them added in February 2026, and none for Postfix, Dovecot, SOGo or Rspamd. Mail-in-a-Box ships Roundcube, and three of its four 2026 releases (v74, v75 and v77) patched Roundcube security holes; its contacts and calendars still run on Nextcloud 27.1.11, from a branch that Nextcloud stopped supporting in June 2024. mailcow's admin panel had six CVEs published on April 16, 2026, a critical one among them.

Frequently asked questions

Why do emails from my own server go to spam in Gmail or Outlook?

Check Gmail's Show original for PASS on SPF, DKIM and DMARC, then check the PTR and look the IP up at check.spamhaus.org. If everything passes, it is reputation: a new IP has none, so send less, to people who reply, and give it weeks. Microsoft is often the slowest to come round.

Should I use port 465 or 587 for sending mail?

Both work for mail apps on all three stacks. RFC 8314 (January 2018) prefers 465, where TLS starts immediately, over 587, which upgrades a plain connection with STARTTLS. Neither replaces port 25, which servers use to deliver to each other.

How much RAM does mailcow need?

mailcow's documentation sets the minimum at 6 GiB of RAM plus 1 GiB of swap, recommends 8 GiB for about 5 to 10 users and plans 16 GiB for 15 ActiveSync phones and about 50 IMAP connections. On a clean test server on our network (8 vCPU, 16 GB RAM), a fresh mailcow with no mailboxes idled at about 2.3 GB, 1 GB of it ClamAV; the rest of the minimum is headroom for real mail. A SOGo worker can grow to about 350 MiB before it is recycled, and 20 run by default; SKIP_CLAMD=y and SKIP_FTS=y in mailcow.conf save memory.

Is Stalwart mail server free and ready for production?

The community edition is free under AGPL-3.0 with no mailbox limit; Enterprise features such as masked addresses are licensed per mailbox, from 25 mailboxes up. It is still version 0.x: its FAQ warns that data layout and configuration may change before 1.0, 0.16.0 in April 2026 brought breaking changes, and 0.16.25 on October 5 fixed DKIM rotation bugs that could leave outgoing mail unsigned. Stalwart reports that a 2023 audit by Radically Open Security found no vulnerabilities. Fine for a small server, if you read the release notes before every upgrade.

Can RS Computers set up the mail server for me?

Yes. Message us on Telegram or email info@rscomputers-ks.com with your domain and the number of mailboxes, and we will suggest a stack and a plan and quote the setup.

Where to start

Not with mailcow. Order the plan from the table above and spend its first hour on the checks: ask us on Telegram to open port 25, set the PTR in the client area, run the step 3 checks and look the IP up at Spamhaus. If something fails, you have lost an hour rather than a weekend. If everything passes, install your stack and give the server a few quiet weeks before trusting it with invoices. All VPS and VDS plans are KVM, with NVMe storage, their own IPv4 and IPv6 and free weekly backups.

← All articles

Chat on Telegram