Blog/ Other providers

Mail-in-a-Box Setup Guide: What You Get and What You Own

Nafiul HasanNafiul Hasan· 9 min read
Mail-in-a-Box setup guide illustration: a single cloud server box connected to mail, DNS and backup services

The short answer

Mail-in-a-Box turns a fresh Ubuntu 22.04 VPS into a full mail server: Postfix, Dovecot, Roundcube webmail, Nextcloud contacts and calendar, spam filtering, and automatic DNS with SPF, DKIM, DMARC and MTA-STS plus Let's Encrypt certificates. Before production, confirm outbound port 25 is open, set reverse DNS, and configure off-box backups.

A Mail-in-a-Box setup guide from the project's own docs: VPS requirements, glue records, the install command, backups, and the deliverability caveats.

On this page
  1. 01What does Mail-in-a-Box actually install?
  2. 02Does Mail-in-a-Box handle SPF and DKIM automatically?
  3. 03Before you start: requirements and decisions
  4. 04The setup steps
  5. 05How setup differs by host and DNS choice
  6. 06What to do when it doesn't work
  7. 07The maintenance you have signed up for
  8. 08A faster way to handle the mail once it lands

Most of what people want from a Mail-in-a-Box setup guide is not the install command. The install command is one line. What they want is to know what that line builds, what it does not build, and which parts they are now personally responsible for at 2am.

This guide follows Mail-in-a-Box's own documentation at mailinabox.email, checked in September 2026 against the project's setup guide, maintenance page and release list. Where the project states a caveat about itself, that caveat is repeated here rather than smoothed over. The latest tagged release at the time of writing is v76, dated 24 May 2026.

What does Mail-in-a-Box actually install?#

Mail-in-a-Box is a setup script, not a hosted service. It configures a standard Linux mail stack on a server you rent and control, then gives you a web control panel on top of it.

The project describes itself as "a cooking recipe" rather than a mail service. That distinction matters legally and operationally: nobody else can suspend your box, and nobody else will fix it either.

LayerWhat the script installsWhat you get
SMTPPostfixSending and receiving mail for your domains
IMAP/POPDovecotMailbox access from any client, plus Sieve filters on port 4190
WebmailRoundcubeBrowser access to mail with no extra setup
Contacts and calendarNextcloudCardDAV/CalDAV sync alongside the mailboxes
Spam filteringSpamAssassin plus greylistingInbound filtering out of the box
DNSIts own nameserver, configured automaticallySPF, DKIM, DMARC and MTA-STS records generated for you
TLSLet's EncryptCertificates provisioned and renewed automatically
AdminWeb control panel with TOTP 2FA and an HTTP APIUsers, aliases, custom DNS, backups, status checks

Does Mail-in-a-Box handle SPF and DKIM automatically?#

Yes, and this is the single strongest reason to choose it over assembling Postfix and Dovecot yourself. The box runs its own nameserver and writes the SPF, DKIM, DMARC and MTA-STS records for every domain you host on it. DNSSEC with DANE TLSA records is available as well.

The catch is that this only happens automatically when the box is authoritative for your DNS. If you keep DNS at Cloudflare, Route 53 or your registrar, the control panel shows you the exact records and you copy them across by hand — and you re-copy them whenever the box changes something.

Automatic records are not automatic reputation

Correct SPF, DKIM and DMARC are the entry ticket, not the outcome. The project states plainly that other mail services might still block or spam-filter mail sent from your Mail-in-a-Box. A brand-new IP has no sending history, and large receivers treat that as a risk signal regardless of how clean your DNS is.

Before you start: requirements and decisions#

Mail-in-a-Box is strict about its environment on purpose. It rewrites system configuration files wholesale, so it expects a machine with nothing else on it.

  • Ubuntu 22.04 x64, server edition. Not a different distribution, not a newer Ubuntu, not a provider's customised image.
  • A cloud VPS. The project says containers and modified images are not supported.
  • 512 MB RAM minimum, 1 GB recommended. Nextcloud and SpamAssassin are the memory-hungry parts.
  • A fresh machine. Do not install it beside an existing web app or control panel.
  • A domain you can set glue records and nameservers on, and whose registrar you can reach quickly.
  • Outbound TCP 25 unblocked by your host. Many providers block it by default; the project specifically advises against AWS because its network is often blocked to prevent spam.

Pick the hostname before you touch anything

The documented convention is box.yourdomain.com. It cannot be a hostname you are also serving a website from elsewhere, and reverse DNS for the server's IP should be set to match it. Changing it after install is more work than choosing it correctly now.

The setup steps#

  1. 1

    Provision a clean Ubuntu 22.04 VPS

    Choose a provider that permits outbound port 25 and lets you set reverse DNS (PTR) on the IP. The guide suggests disabling IPv6 if your provider allows it. Note the IP address — you will need it in the next step.

  2. 2

    Create glue records at your registrar

    If the box will run your DNS, create two glue records, ns1.box.yourdomain.com and ns2.box.yourdomain.com, both pointing at the server's IP. Then set the domain's nameservers to those two names and disable the registrar's own. Some registrars ask for the short form without the domain suffix.

  3. 3

    Or plan for external DNS instead

    If you are keeping DNS elsewhere, skip the glue records and nameserver change entirely. You will copy the generated records out of the control panel after the install finishes.

  4. 4

    Set reverse DNS on the IP

    Point the PTR record at box.yourdomain.com. Some providers derive this from the instance name automatically; others expose a field in the control panel; some make you wait until forward DNS resolves first.

  5. 5

    Open the required ports

    The documented set is 22 (SSH), 25 (SMTP), 53 TCP and UDP (DNS), 80, 443, 465 (submission), 993 (IMAPS), 995 (POP3S) and 4190 (Sieve). A provider-level firewall that silently drops 53 will make the box look broken in ways that read like a DNS bug.

  6. 6

    Run the installer

    SSH in and run: curl -s https://mailinabox.email/setup.sh | sudo -E bash — the script asks for the email address and password of the first account, which is also your control-panel login. To keep mail data on a separate volume, export STORAGE_ROOT to that path before running it.

  7. 7

    Reach the control panel and verify

    Before DNS resolves, the panel is at https://your-ip/admin behind a self-signed certificate warning; verify the fingerprint the installer printed rather than clicking through blind. Once DNS is live, use https://box.yourdomain.com/admin and provision the real Let's Encrypt certificate from the TLS Certificates page.

  8. 8

    Work the System Status Checks page until it is green

    This page is the box's self-diagnosis and the first thing to read whenever something breaks later. DNS changes take time to propagate, so re-check periodically rather than assuming a red item is permanent.

  9. 9

    Configure backups and save the key

    Backups are encrypted with duplicity. The secret key lives at /home/user-data/backup/secret_key.txt and encrypted archives default to /home/user-data/backup/encrypted on the box itself. Point backups at S3 or an S3-compatible store, and copy the secret key somewhere that is not the server.

How setup differs by host and DNS choice#

Most of the variation in a Mail-in-a-Box install is not in the software. It is in what your hosting provider and DNS provider let you do.

Two routing paths for a self-hosted mail domain: one where the box itself answers DNS queries, one where an external DNS provider answers and the records are copied in manually
The DNS decision is the one that changes the shape of the whole install.
DecisionBox runs your DNSYou keep external DNS
Glue recordsRequired, two of them, at the registrarNot needed
NameserversPoint to ns1/ns2.box.yourdomain.comUnchanged
SPF, DKIM, DMARC, MTA-STSWritten and maintained automaticallyCopy from the control panel by hand, and re-copy after changes
Port 53 inboundMust be open, TCP and UDPNot required
Failure modeBox down means DNS down for the whole domainBox down affects mail only

What to do when it doesn't work#

Almost every Mail-in-a-Box problem falls into one of four buckets, and the System Status Checks page tells you which one you are in before you start guessing.

SymptomLikely causeWhere to look
Outbound mail never arrives anywhereHost blocks outbound TCP 25Ask the provider to unblock it; if they refuse, move hosts
Mail arrives but lands in spamNew IP with no reputation, or PTR not matching the hostnameReverse DNS, then warm the IP slowly with real correspondence
Status checks complain about DNSGlue records or nameservers not fully propagated, or port 53 filteredRegistrar settings and the provider firewall
Certificate errors after installLet's Encrypt cannot reach the box on port 80Firewall rules, then re-run provisioning from the TLS page
Something broke after an updateA component upgrade the release notes mentionThe release notes, then re-run setup to repair

The maintenance you have signed up for#

Updating is deliberately the same action as installing: SSH in and run setup again, or run sudo mailinabox from the terminal. Read the release notes first, and close other control-panel browser tabs before upgrading to avoid lock errors.

Two habits matter more than the rest. Test a restore before you need one, because an untested backup is a hypothesis. And upgrade an existing box before migrating it to a new machine, rather than after.

The project is honest about its own bus factor: its maintainers work on it in their limited free time, and it is explicitly not built to be customised by power users. If your plan involves patching Postfix configuration by hand, you want something with more knobs — mailcow is the usual comparison.

The backup key is the whole backup

Duplicity archives are useless without /home/user-data/backup/secret_key.txt. If the only copy of that file lives on the server it protects, you have a backup of your mail that dies with the machine.

A faster way to handle the mail once it lands#

Running your own box solves storage, transport and sovereignty. It does not solve volume: a self-hosted inbox fills up exactly as fast as a hosted one, and Roundcube is a competent webmail client rather than a triage system.

AI Emaily connects to a Mail-in-a-Box mailbox over plain IMAP and SMTP, so the server stays yours and the client does the reading. It triages, drafts replies from a Personal Context brain you write yourself and per-client profiles you set, and holds every send for your approval before it goes out, with undo and an audit trail. We build AI Emaily, so treat that as our pitch rather than a neutral survey.

What it is not: it is not a mail host and it will not run, patch or monitor your server. If port 25 is blocked, this does not help. It is a 7-day free trial on Pro and Autopilot, card required.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Your server, your mail, a better client

Connect a Mail-in-a-Box mailbox over IMAP and let AI Emaily triage and draft — with approval before every send.

  • 7-day free trial
  • Cancel anytime
  • Every provider