Mail-in-a-Box Setup Guide: What You Get and What You Own

The short answer
Mail-in-a-Box turns a fresh Ubuntu 22.04 VPS into a full mail server: Postfix, Dovecot, Roundcube webmail, Nextcloud contacts and calendar, spam filtering, and automatic DNS with SPF, DKIM, DMARC and MTA-STS plus Let's Encrypt certificates. Before production, confirm outbound port 25 is open, set reverse DNS, and configure off-box backups.
A Mail-in-a-Box setup guide from the project's own docs: VPS requirements, glue records, the install command, backups, and the deliverability caveats.
On this page
- 01What does Mail-in-a-Box actually install?
- 02Does Mail-in-a-Box handle SPF and DKIM automatically?
- 03Before you start: requirements and decisions
- 04The setup steps
- 05How setup differs by host and DNS choice
- 06What to do when it doesn't work
- 07The maintenance you have signed up for
- 08A faster way to handle the mail once it lands
Most of what people want from a Mail-in-a-Box setup guide is not the install command. The install command is one line. What they want is to know what that line builds, what it does not build, and which parts they are now personally responsible for at 2am.
This guide follows Mail-in-a-Box's own documentation at mailinabox.email, checked in September 2026 against the project's setup guide, maintenance page and release list. Where the project states a caveat about itself, that caveat is repeated here rather than smoothed over. The latest tagged release at the time of writing is v76, dated 24 May 2026.
What does Mail-in-a-Box actually install?#
Mail-in-a-Box is a setup script, not a hosted service. It configures a standard Linux mail stack on a server you rent and control, then gives you a web control panel on top of it.
The project describes itself as "a cooking recipe" rather than a mail service. That distinction matters legally and operationally: nobody else can suspend your box, and nobody else will fix it either.
| Layer | What the script installs | What you get |
|---|---|---|
| SMTP | Postfix | Sending and receiving mail for your domains |
| IMAP/POP | Dovecot | Mailbox access from any client, plus Sieve filters on port 4190 |
| Webmail | Roundcube | Browser access to mail with no extra setup |
| Contacts and calendar | Nextcloud | CardDAV/CalDAV sync alongside the mailboxes |
| Spam filtering | SpamAssassin plus greylisting | Inbound filtering out of the box |
| DNS | Its own nameserver, configured automatically | SPF, DKIM, DMARC and MTA-STS records generated for you |
| TLS | Let's Encrypt | Certificates provisioned and renewed automatically |
| Admin | Web control panel with TOTP 2FA and an HTTP API | Users, aliases, custom DNS, backups, status checks |
Does Mail-in-a-Box handle SPF and DKIM automatically?#
Yes, and this is the single strongest reason to choose it over assembling Postfix and Dovecot yourself. The box runs its own nameserver and writes the SPF, DKIM, DMARC and MTA-STS records for every domain you host on it. DNSSEC with DANE TLSA records is available as well.
The catch is that this only happens automatically when the box is authoritative for your DNS. If you keep DNS at Cloudflare, Route 53 or your registrar, the control panel shows you the exact records and you copy them across by hand — and you re-copy them whenever the box changes something.
Automatic records are not automatic reputation
Before you start: requirements and decisions#
Mail-in-a-Box is strict about its environment on purpose. It rewrites system configuration files wholesale, so it expects a machine with nothing else on it.
- Ubuntu 22.04 x64, server edition. Not a different distribution, not a newer Ubuntu, not a provider's customised image.
- A cloud VPS. The project says containers and modified images are not supported.
- 512 MB RAM minimum, 1 GB recommended. Nextcloud and SpamAssassin are the memory-hungry parts.
- A fresh machine. Do not install it beside an existing web app or control panel.
- A domain you can set glue records and nameservers on, and whose registrar you can reach quickly.
- Outbound TCP 25 unblocked by your host. Many providers block it by default; the project specifically advises against AWS because its network is often blocked to prevent spam.
Pick the hostname before you touch anything
The setup steps#
- 1
Provision a clean Ubuntu 22.04 VPS
Choose a provider that permits outbound port 25 and lets you set reverse DNS (PTR) on the IP. The guide suggests disabling IPv6 if your provider allows it. Note the IP address — you will need it in the next step.
- 2
Create glue records at your registrar
If the box will run your DNS, create two glue records, ns1.box.yourdomain.com and ns2.box.yourdomain.com, both pointing at the server's IP. Then set the domain's nameservers to those two names and disable the registrar's own. Some registrars ask for the short form without the domain suffix.
- 3
Or plan for external DNS instead
If you are keeping DNS elsewhere, skip the glue records and nameserver change entirely. You will copy the generated records out of the control panel after the install finishes.
- 4
Set reverse DNS on the IP
Point the PTR record at box.yourdomain.com. Some providers derive this from the instance name automatically; others expose a field in the control panel; some make you wait until forward DNS resolves first.
- 5
Open the required ports
The documented set is 22 (SSH), 25 (SMTP), 53 TCP and UDP (DNS), 80, 443, 465 (submission), 993 (IMAPS), 995 (POP3S) and 4190 (Sieve). A provider-level firewall that silently drops 53 will make the box look broken in ways that read like a DNS bug.
- 6
Run the installer
SSH in and run: curl -s https://mailinabox.email/setup.sh | sudo -E bash — the script asks for the email address and password of the first account, which is also your control-panel login. To keep mail data on a separate volume, export STORAGE_ROOT to that path before running it.
- 7
Reach the control panel and verify
Before DNS resolves, the panel is at https://your-ip/admin behind a self-signed certificate warning; verify the fingerprint the installer printed rather than clicking through blind. Once DNS is live, use https://box.yourdomain.com/admin and provision the real Let's Encrypt certificate from the TLS Certificates page.
- 8
Work the System Status Checks page until it is green
This page is the box's self-diagnosis and the first thing to read whenever something breaks later. DNS changes take time to propagate, so re-check periodically rather than assuming a red item is permanent.
- 9
Configure backups and save the key
Backups are encrypted with duplicity. The secret key lives at /home/user-data/backup/secret_key.txt and encrypted archives default to /home/user-data/backup/encrypted on the box itself. Point backups at S3 or an S3-compatible store, and copy the secret key somewhere that is not the server.
How setup differs by host and DNS choice#
Most of the variation in a Mail-in-a-Box install is not in the software. It is in what your hosting provider and DNS provider let you do.

| Decision | Box runs your DNS | You keep external DNS |
|---|---|---|
| Glue records | Required, two of them, at the registrar | Not needed |
| Nameservers | Point to ns1/ns2.box.yourdomain.com | Unchanged |
| SPF, DKIM, DMARC, MTA-STS | Written and maintained automatically | Copy from the control panel by hand, and re-copy after changes |
| Port 53 inbound | Must be open, TCP and UDP | Not required |
| Failure mode | Box down means DNS down for the whole domain | Box down affects mail only |
What to do when it doesn't work#
Almost every Mail-in-a-Box problem falls into one of four buckets, and the System Status Checks page tells you which one you are in before you start guessing.
| Symptom | Likely cause | Where to look |
|---|---|---|
| Outbound mail never arrives anywhere | Host blocks outbound TCP 25 | Ask the provider to unblock it; if they refuse, move hosts |
| Mail arrives but lands in spam | New IP with no reputation, or PTR not matching the hostname | Reverse DNS, then warm the IP slowly with real correspondence |
| Status checks complain about DNS | Glue records or nameservers not fully propagated, or port 53 filtered | Registrar settings and the provider firewall |
| Certificate errors after install | Let's Encrypt cannot reach the box on port 80 | Firewall rules, then re-run provisioning from the TLS page |
| Something broke after an update | A component upgrade the release notes mention | The release notes, then re-run setup to repair |
The maintenance you have signed up for#
Updating is deliberately the same action as installing: SSH in and run setup again, or run sudo mailinabox from the terminal. Read the release notes first, and close other control-panel browser tabs before upgrading to avoid lock errors.
Two habits matter more than the rest. Test a restore before you need one, because an untested backup is a hypothesis. And upgrade an existing box before migrating it to a new machine, rather than after.
The project is honest about its own bus factor: its maintainers work on it in their limited free time, and it is explicitly not built to be customised by power users. If your plan involves patching Postfix configuration by hand, you want something with more knobs — mailcow is the usual comparison.
The backup key is the whole backup
A faster way to handle the mail once it lands#
Running your own box solves storage, transport and sovereignty. It does not solve volume: a self-hosted inbox fills up exactly as fast as a hosted one, and Roundcube is a competent webmail client rather than a triage system.
AI Emaily connects to a Mail-in-a-Box mailbox over plain IMAP and SMTP, so the server stays yours and the client does the reading. It triages, drafts replies from a Personal Context brain you write yourself and per-client profiles you set, and holds every send for your approval before it goes out, with undo and an audit trail. We build AI Emaily, so treat that as our pitch rather than a neutral survey.
What it is not: it is not a mail host and it will not run, patch or monitor your server. If port 25 is blocked, this does not help. It is a 7-day free trial on Pro and Autopilot, card required.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.