Mail is the record of the business itself. Correspondence, contracts, history — all of it piles up there. By now the foundation, the gate, the code, and the documents are on your own side. This chapter takes back the inbox those records flow into every day. Receiving is easy; sending has conditions. Write the conditions down first, then stand it up.
Take control of the inbox back to your own side
- Control of the record — retention, search, and export of past mail by your own rules
- Step off per-seat billing — the monthly bill does not stack with mailbox count
- Names aligned with the gate — account names match the gate of 2-05. The login itself is Stalwart's (2-05)
Stand up Stalwart on one machine
The mail server is Stalwart. A Rust single server carries SMTP, IMAP, JMAP, spam defense, and DKIM signing. It is a replacement for Exchange. Storage can be pointed at the PostgreSQL from 2-03. The machine it stands up on is the one handed to the AI in 2-02.
The official install script sets up the binary (/usr/local/bin/stalwart), the
configuration (/etc/stalwart), the data (/var/lib/stalwart), a dedicated
stalwart user, and the systemd unit. As 2-02 decided, no Docker.
- The ports opened to the outside are 25, 465, 587, and 993. This chapter opens them for the first time, so it is an action the AI states before performing (2-02)
- The admin UI (8080) is not exposed. It listens on localhost only, reached from your own PC through ssh
- Storage is the PostgreSQL of 2-03, with one database and one role made for Stalwart
curl --proto '=https' --tlsv1.2 -sSf https://get.stalw.art/install.sh -o install.sh
sudo sh install.sh # the official installer; runs as a systemd service
In the admin UI, create the domain and the mailboxes. No code is written.
Get the DNS right — MX, SPF, DKIM, DMARC
With mail, the DNS is the real body of the work, more than the server. Set these four correctly.
example.com. MX 10 mail.example.com.
example.com. TXT "v=spf1 mx -all"
default._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=...(generated by Stalwart)"
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"
The reverse record (PTR) is what the receiving server uses to check the sender's IP. On a fixed-IP line the provider has already set it, so there is nothing for you to do (2-02).
Send it yourself when the conditions hold — the relay is the fallback
When you send from your own server, the receiving server asks whether the sender can be trusted. It looks at four things, and when all four hold, you can send yourself.
- A fixed IP (2-02)
- A reverse record (PTR) set for that IP
- SPF, DKIM, and DMARC in place, as in the previous section
- A line that does not block outbound port 25. Many lines block it as an anti-spam measure (OP25B); fixed-IP business lines usually let it through
When they hold, sending stays on your side too. Even then, a recipient's server may decide not to accept. This is not about OSS being inferior; it is the reality of how mail works. When a recipient cannot be reached, borrow an authenticated SMTP relay (a send-only service) for outbound sending only. What you borrow is deliverability; the inbox stays on your side.
The inbox on your side. Sending yourself, when the conditions hold. When a recipient cannot be reached, borrow the sending alone — stand it up with the line drawn.
Read and write with Thunderbird
Reading and writing work with any client that speaks IMAP. Thunderbird is free and runs the same on Windows, Mac, and Linux. Phones connect with the stock mail app over IMAP. The JMAP that Stalwart speaks is for the tools you write yourself (2-12).
Leave the current server as it is
No migration procedure is needed. New mail is received by Stalwart. Past mail stays inside the current server and is handled there. Thunderbird opens several accounts side by side, so when you look back, you see both there. Microsoft 365 and Gmail both open in Thunderbird (both sign in with OAuth2; Microsoft Learn and Mozilla's support pages, checked 2026-10-05).
Point the MX at Stalwart once receiving has been confirmed (2-12). When the old server is cancelled, drag only the folders worth keeping across to the new side in Thunderbird.
Retention and safety are a few lines of rules
Mail retention needs no dedicated archive product. All the mail already sits in the 2-03 PostgreSQL, and it is already inside the 2-01 rule "protect the data and the spec." How many years to keep is one line in the business-rules Markdown. That is the entire retention spec.
The safety side is one line too. Never open executable attachments. Spam is handled by Stalwart's built-in filter. For a suspicious mail, have the AI read the body before any attachment is opened, as input to your judgment.
How to check you are done
This chapter is done when these five hold.
- A mail sent from an outside address, such as Gmail, to your own domain can be read in Thunderbird
- A mail sent from Thunderbird to an outside address lands in that person's inbox (not in spam)
- Through ssh, you can log in to the admin UI and see the domain and mailboxes you created
- Queried from outside, all five records answer: MX, SPF, DKIM, DMARC, PTR
- In Thunderbird, both the old server's account and Stalwart's sit side by side
systemctl status stalwart # running under systemd
dig +short MX example.com # the MX answers
dig +short TXT default._domainkey.example.com # the DKIM key answers
dig +short -x <the server's IP> # the reverse record (PTR) answers
What the human holds
Values the human supplies
- The mail domain name and the mail server's hostname
- The server's fixed IP
- The name and password of the first administrator in the admin UI
- The PostgreSQL role name and password for Stalwart
- If a relay is borrowed, the account and credentials of that SMTP relay
- How many years mail is kept
Actions the AI states before performing
- Opening ports 25, 465, 587, and 993
- Changing a DNS record, above all switching the MX to Stalwart
- Sending mail to an outside address
- Deleting a mailbox
Versions checked, and when
- Stalwart 0.16.25 (2026-10-05, the official install script), Thunderbird 140 (Debian 13 package), PostgreSQL (2-03)
- This procedure was written on 2026-07-09 and reviewed on 2026-10-05
- If a version has moved, have the AI confirm the official procedure before proceeding
Summary
The inbox, on your own side.
- Stalwart — SMTP, IMAP, JMAP, spam defense, DKIM in one server (on the 2-03 PostgreSQL); the official script, under systemd
- DNS (MX, SPF, DKIM, DMARC) — the real body of mail is here; the reverse record is the line provider's, already set
- Send yourself when the conditions hold — fixed IP, PTR, SPF/DKIM/DMARC, a line that lets port 25 out. Borrow the sending alone when a recipient cannot be reached
- Thunderbird — a free IMAP client, identical across OSes
- Leave the current server — past mail is handled there. Thunderbird shows both; point the MX once receiving is confirmed
The next chapter stands up meetings and calendars (Jitsi, Radicale), bringing Teams and calendar sharing to our own side.