DocsEmail

Email

Host email for your domains with mailboxes, forwarders, catch-all, one-click webmail, Sieve filters and autoreplies, mailing lists, CalDAV/CardDAV, DKIM and per-account sending limits.

ZoPanel's mail server is built on Postfix, Dovecot (IMAP/POP3) and Rspamd, with DKIM signing, spam filtering and Sieve rules. Customers manage their own domains and mailboxes on the Email page; the administrator controls the server-wide settings.

Install the mail server (administrator)

  1. Open Email and fill in Mail hostname, a fully qualified name such as mail.example.com. It must resolve to this server.
  2. Click Install mail server. You can also install it from Components, together with Webmail and Calendars & contacts (CalDAV/CardDAV).
  3. Ask your VPS provider to set the server IP's reverse DNS (PTR) to the mail hostname. Without it, much of your mail lands in spam.
  4. Click Install webmail if it was not installed with the components.

The installer opens the mail ports in the firewall. If ZoPanel detects that your provider blocks outgoing port 25, the Email page warns you: incoming mail works, but sending to other servers fails until the provider opens the port, or until you configure Outgoing mail relay (smarthost) (SendGrid, Mailgun, Amazon SES, Brevo…).

Mail services use the panel's certificate: set Settings → Panel domain & SSL so mail clients see a trusted certificate.

Enable email for a domain

  1. On the Email page, click Enable email for a domain.
  2. Choose one of your websites' domains and click Enable.
  3. Publish the records shown in the DNS records card at your DNS provider. If you host the domain's DNS on this server and create its zone after enabling email, the zone is created with these records already in it; for an existing zone, add them on the DNS page.
Record Name Value
MX example.com the mail hostname, priority 10
TXT (SPF) example.com v=spf1 mx a ~all
TXT (DKIM) zp._domainkey.example.com the public key shown in the panel
TXT (DMARC) _dmarc.example.com v=DMARC1; p=quarantine; rua=mailto:postmaster@example.com

Then click Run check in Mail delivery check. It compares public DNS with the expected MX, SPF, DKIM and DMARC records, checks reverse DNS (PTR) and outgoing port 25, and looks up the server IP on the Spamhaus, SpamCop and Barracuda blocklists, with a hint for each problem.

Mailboxes

  1. Open the domain and click New mailbox.
  2. Enter the address, a password (a strong one is generated) and the Quota (MB) (default 1024, 0 = unlimited).
  3. Copy the password from the confirmation: it is not shown again.

The key icon changes a mailbox's password or quota. The number of mailboxes is limited by the account's package.

Mail client settings

The username is always the full email address.

Protocol Port Security
IMAP 993 SSL/TLS
IMAP 143 STARTTLS
POP3 995 SSL/TLS
POP3 110 STARTTLS
SMTP (sending) 465 SSL/TLS
SMTP (sending) 587 STARTTLS

Login always requires encryption. The server name is shown in Email client settings on the domain page.

Webmail without a password

Webmail (SnappyMail) runs on port 2096. In the mailbox list, the envelope icon Open webmail (no password needed) signs you in to that mailbox in a new tab. The panel never knows mailbox passwords: it uses a single-use link (valid for seconds) with a login code that opens only that mailbox. Users can also sign in directly at https://<server>:2096 with their address and password.

Forwarders and catch-all

In Forwarders, click New forwarder, enter the local part of the Address and one or more destinations in Forward to, separated by commas.

To catch all mail sent to unknown addresses of the domain, leave the address empty (or enter *). The catch-all appears as *@example.com in the list.

Rules and autoreply (Sieve)

Click the filter icon next to a mailbox to open Rules and autoreply. Rules run when mail is delivered, before it reaches the inbox.

  • Autoreply: turn on Send an automatic reply, set the Subject and Message, an optional From and Until date, and how often the same sender gets a reply.
  • Filters: match From, To / Cc or Subject that contains or is a value, then Move to folder, Forward a copy, Mark as read or Delete.
  • Senders & spam: Move spam to the Junk folder, lists of senders to Always allow and to Block (deleted silently), one address or domain per line.

The Spam filter card sets how strict filtering is for the whole domain: Low, Medium (recommended) or High.

Mailing lists

A mailing list is one address that delivers to every member. In Mailing lists, click New list, enter the List address and the Members. Turn on Only members (and the senders below) can send to the list to keep it closed, and list extra allowed senders. The original sender's signature is kept, so messages reach inboxes instead of spam.

Calendars and contacts

When Calendars & contacts (CalDAV/CardDAV) is installed, every mailbox gets its own calendars and address books at https://<server>:2080/. Sign in with the mailbox address and password in your phone, Thunderbird or Outlook. Each user only sees their own collections.

Sending limits

Hacked websites are the usual source of spam on a hosting server, and one bad night can get the server's IP blocklisted for every customer. ZoPanel counts every recipient each account sends per hour, whether the mail comes from PHP mail() or from an SMTP login, and temporarily refuses mail over the limit.

  • Administrators set Default per hour in Email → Sending limits (500 by default; 0 = unlimited). The table shows each account's mail in the last hour, its limit and refusals in the last 24 hours.
  • Each package can override the limit with Emails per hour in Packages (empty = server default, -1 = unlimited).
  • Customers see Emails sent this hour under Resources, and can be notified when the limit is reached.

Why port 25 from a website or script is refused

With Block direct SMTP from accounts on (the default), website code cannot connect to other mail servers on port 25, and unauthenticated SMTP from the server itself is refused. All mail must go through this server, where it is counted, DKIM-signed and logged, like cPanel's SMTP Restrictions.

To send from an application, use PHP mail() or SMTP with a mailbox login:

Host: <mail hostname>   Port: 587   Encryption: STARTTLS
Username: noreply@example.com   Password: the mailbox password

Queue, logs and blocklists

  • Delivery log on each domain page lists recent mail sent and received, searchable by address or status.
  • Administrators also see the server-wide Delivery log and the Mail queue, where they can Retry, Hold, Release, view Message headers, Retry all or Delete all deferred.
  • ZoPanel alerts the administrator when the queue builds up (300 messages or more) and checks once a day whether the server IP is on a blocklist. If it is, find the sending account in Sending limits, stop the source, then request delisting on the list's website.

← Website tools DNS →