在 CentOS 上搭建“邮件服务器”并实现加密,通常包含三个层面:
下面按**最常见方案(Postfix + Dovecot)**说明。
推荐用 Let’s Encrypt(免费):
yum install -y certbot
certbot certonly --standalone -d mail.example.com
证书路径:
/etc/letsencrypt/live/mail.example.com/fullchain.pem/etc/letsencrypt/live/mail.example.com/privkey.pem编辑 /etc/postfix/main.cf:
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.example.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.example.com/privkey.pem
smtpd_use_tls = yes
smtpd_tls_auth_only = yes
smtp_tls_security_level = may
smtpd_tls_security_level = encrypt
重启:
systemctl restart postfix
✅ 效果:
编辑 /etc/dovecot/conf.d/10-ssl.conf:
ssl = required
ssl_cert = </etc/letsencrypt/live/mail.example.com/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.example.com/privkey.pem
禁用明文登录:
/etc/dovecot/conf.d/10-auth.conf
disable_plaintext_auth = yes
重启:
systemctl restart dovecot
✅ 效果:
只要满足:
✅ 密码已经是加密的
❌ 不要使用:
适合物理机 / 私有云:
cryptsetup luksFormat /dev/sdb
cryptsetup open /dev/sdb maildata
mkfs.ext4 /dev/mapper/maildata
挂载到 /var/mail
⚠️ 重启需手动输入密码(或密钥文件)
openssl s_client -connect mail.example.com:465
openssl s_client -connect mail.example.com:993
❌ 只装 Postfix 没开 TLS
❌ 用 25 端口收邮件
❌ 自签证书没在客户端信任
❌ 明文 auth 没关
| 项目 | 建议 |
|---|---|
| SMTP | 465 + TLS |
| IMAP | 993 + SSL |
| 认证 | 禁止明文 |
| 证书 | Let’s Encrypt |
| 协议 | 禁用 SSLv3 / TLSv1.0 |
如果你愿意,可以告诉我:
我可以直接给你可复制的完整配置。