Email Infrastructure & Deliverability

Postfix Configuration

Postfix is dependable and flexible, and its defaults are a starting point rather than an answer. We configure it for your real sending pattern and make it easy to diagnose.

What Postfix configuration involves

Postfix is one of the most widely used mail transfer agents on Linux. Its behaviour is controlled mainly by two files: main.cf for global settings and master.cf for the services and transports it runs. Lookup tables such as transport maps, sender-dependent relay maps and header checks add fine-grained control.

Configuration work is about making those settings reflect how you actually send: which mail goes where, how fast, how long it waits, how it’s encrypted and how it’s logged.

We also replace defaults that don’t suit modern receivers. Values that were reasonable for a small office server years ago can be wrong for a platform sending newsletters to thousands of opted-in subscribers, or for an application where a message older than a few minutes is useless.

Signs your Postfix needs attention

  • A large deferred queue after every campaign, dominated by one or two receiving domains.
  • Password reset emails stuck behind newsletter traffic.
  • Stale messages being delivered days after they were sent.
  • Log lines you can’t connect to a specific message or sender.
  • TLS warnings, or receivers reporting that your mail arrives unencrypted.

What we configure

AreaTypical settingsWhy it matters
TransportsSeparate transports in master.cf, transport_mapsDifferent rules for different receivers or mail types
Rate limitsPer-transport destination concurrency and rate delayStays within each receiver’s tolerance
Queue policymaximal_queue_lifetime, bounce_queue_lifetime, retry backoffRetries sensibly, gives up on time
Relay policysmtpd_relay_restrictions, SASL authenticationPrevents open relay abuse
TLSsmtp_tls_security_level, smtpd_tls settings, modern protocolsEncrypted delivery and trust
Headersheader_checks, smtp_header_checksRemoves internal details, fixes malformed headers
Sender routingsender_dependent_default_transport_mapsSends each domain from the right IP

How we approach it

  1. Read the current configuration and a representative slice of logs.
  2. Analyse the queue with tools such as qshape to see where mail is waiting and why.
  3. Agree the target design: transports, IP mapping, rate limits and lifetimes.
  4. Make changes incrementally, reloading and checking logs after each step.
  5. Test delivery to major providers and confirm TLS and authentication in the received headers.
  6. Document every non-default setting with the reason it exists.

Integrations and standards

Postfix usually works alongside a DKIM signer, such as OpenDKIM or Rspamd, and a policy service for inbound checks. We make sure signing covers every sending domain and aligns with the From address for DMARC. Reverse DNS and the myhostname setting are matched so the HELO greeting is consistent. For larger setups, see bulk email infrastructure; for day-to-day visibility, see email queue monitoring.

Tuning rate limits is about respecting receivers, not squeezing past them. If a provider is deferring your mail, the fix is usually in list quality or reputation, and we will tell you that rather than raise the throttle.

Making the logs useful

During a deliverability incident, the mail log is the primary evidence. Postfix records every message with a queue ID, and each delivery attempt with the receiving server’s response. We make sure logs are kept long enough to compare this week with last month, and we show your team how to follow one message from submission to final delivery.

  • Trace a message by its queue ID across every attempt.
  • Summarise deferrals by receiving domain and reason.
  • Separate transactional and marketing traffic in reports.
  • Spot sudden changes in bounce or deferral patterns.

What affects timeline and cost

  • How far the current configuration has drifted from a clean baseline.
  • Number of IPs, domains and transports involved.
  • Whether signing and filtering services also need work.
  • Volume and variety of mail passing through the server.
  • How much log history is available for analysis.

Common Postfix mistakes

Copying settings from old forum posts without understanding them. One global concurrency limit for every destination. Queue lifetimes left at several days for time-sensitive mail. mynetworks set so broadly that the server relays for anyone on the internet. Changes made without reloading or checking logs. We avoid all of these by working step by step and writing down why each change was made.

Browse our email infrastructure services, read the guide, or contact us for a Postfix review.

Frequently asked questions

Can you tune Postfix without downtime?

Usually yes. Most changes take effect on reload, and we make them one at a time so mail keeps flowing.

Why does mail to one provider pile up in the deferred queue?

That provider is asking you to slow down or has concerns about reputation. The log text tells us which, and we fix the cause rather than just the rate.

Can Postfix send different domains from different IPs?

Yes, using sender-dependent transports mapped to specific IP addresses and hostnames, each with matching reverse DNS.

Do you work on Postfix inside Mailcow or other suites?

Yes, while respecting how the suite manages its configuration so updates don’t overwrite changes.

Can Postfix keep OTPs moving during a big campaign?

Yes. Transactional mail can use its own transport, IP and limits, so it is never stuck behind newsletter traffic in the same queue.

Talk to us about postfix configuration

Queues, transport maps, TLS and relay rules configured for reliable delivery.

Let's talk

Have something you need built, hosted or fixed?

Tell us what you are trying to do. If we are not the right people for it, we will say so.