温馨提示×

Ubuntu邮件服务器怎么开启加密

小樊
45
2026-08-27 02:38:52
栏目: 云计算

在 Ubuntu 上搭建或配置邮件服务器并开启加密(TLS/SSL),通常是指让 SMTP(25/587/465)、IMAP(143/993)、POP3(110/995) 都支持加密传输。下面给你一套通用、生产可落地的做法,适合你用 Postfix + Dovecot 这类最常见的组合。


一、整体思路(先看这个)

  1. 申请 SSL 证书
    • 推荐:Let’s Encrypt(免费、自动续期)
  2. 配置 Postfix(SMTP)启用 TLS
  3. 配置 Dovecot(IMAP/POP3)启用 TLS
  4. 测试端口加密是否生效

二、申请 SSL 证书(必须)

1️⃣ 安装 certbot

sudo apt update
sudo apt install certbot

2️⃣ 申请证书(示例域名 mail.example.com)

sudo certbot certonly --standalone -d mail.example.com

成功后证书路径一般为:

/etc/letsencrypt/live/mail.example.com/
├── fullchain.pem
└── privkey.pem

✅ 建议同时申请:

-d example.com
-d mail.example.com

三、Postfix(SMTP)开启加密

1️⃣ 安装 Postfix

sudo apt install postfix

2️⃣ 编辑主配置

sudo nano /etc/postfix/main.cf

3️⃣ 启用 TLS(核心配置)

# TLS 证书
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.example.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.example.com/privkey.pem

# 启用 TLS
smtpd_tls_security_level = may
smtpd_tls_loglevel = 1
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache

# 可选:强制加密(推荐)
smtpd_tls_security_level = encrypt

# 提交端口(587)加密
smtpd_tls_auth_only = yes

4️⃣ 启用 587(Submission)

submission inet n - y - - smtpd
  -o syslog_name=postfix/submission
  -o smtpd_tls_security_level=encrypt
  -o smtpd_sasl_auth_enable=yes

5️⃣ 重启 Postfix

sudo systemctl restart postfix

四、Dovecot(IMAP/POP3)开启加密

1️⃣ 安装 Dovecot

sudo apt install dovecot-core dovecot-imapd dovecot-pop3d

2️⃣ 配置 SSL

sudo nano /etc/dovecot/conf.d/10-ssl.conf
ssl = required
ssl_cert = </etc/letsencrypt/live/mail.example.com/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.example.com/privkey.pem

3️⃣ 启用 IMAPS / POP3S

sudo nano /etc/dovecot/conf.d/10-master.conf

确保包含:

service imap-login {
  inet_listener imap {
    port = 143
  }
  inet_listener imaps {
    port = 993
    ssl = yes
  }
}

service pop3-login {
  inet_listener pop3 {
    port = 110
  }
  inet_listener pop3s {
    port = 995
    ssl = yes
  }
}

4️⃣ 重启 Dovecot

sudo systemctl restart dovecot

五、防火墙放行端口

sudo ufw allow 25
sudo ufw allow 587
sudo ufw allow 465
sudo ufw allow 143
sudo ufw allow 993
sudo ufw allow 995

六、测试是否开启加密

✅ 测试 SMTP TLS

openssl s_client -connect mail.example.com:587 -starttls smtp

✅ 测试 IMAPS

openssl s_client -connect mail.example.com:993

看到:

Verify return code: 0 (ok)

✅ 表示加密成功


七、常见问题

❓ 一定要用 465 吗?

  • 587 + STARTTLS(推荐)
  • 465 是 SMTPS(旧标准,但仍可用)

❓ 证书过期怎么办?

sudo certbot renew

✅ 可配置 cron 自动续期


八、进阶(强烈推荐)

  • ✅ SPF / DKIM / DMARC
  • ✅ 禁用 25 端口明文认证
  • ✅ 启用 DANE / MTA-STS
  • ✅ Postfix + Dovecot SASL 认证

如果你愿意,可以告诉我:

  • ✅ 你用的是 Postfix / Exim / Sendmail?
  • ✅ 是否有 现成域名
  • ✅ 是 内网还是公网服务器

我可以直接给你一套完整可复制的配置模板(生产级)。

0 踩