Mail rules and limits
Set up forwarders, catch-all, autoreplies, Sieve filters, sender block and allow lists, spam levels, mailing lists, mailbox quotas and hourly sending limits in ZoPanel.
Beyond plain mailboxes, ZoPanel can forward mail, answer it automatically, sort it into folders, distribute it to a list of people and limit how much each account sends. Everything on this page is managed on Email → the domain, except the sending limits, which the administrator sets for the whole server. For mailbox basics and DNS, see Email.
How a message is handled
When a message for one of your domains arrives, the server handles it in this order:
- Spam filter (Rspamd). Messages above the domain's reject score are refused before delivery. Messages above the "spam" score get a spam header.
- Forwarders and mailing lists. If the address is a forwarder or a list, the message goes to its destinations instead.
- Mailbox rules (Sieve), in this order: Block list → spam to Junk → Filters, top to bottom → Autoreply.
- Quota. If the mailbox is full, the message is refused and the sender gets a bounce.
Forwarders
A forwarder sends mail for an address of your domain to one or more other addresses, on this server or elsewhere.
- Open Email, choose the domain and click New forwarder in the Forwarders card.
- Enter the part before
@in Address, for examplesales. - In Forward to, enter 1 to 20 addresses, separated by commas.
- Click Save.
Notes:
- To change the destinations, create the forwarder again with the same address. The new list replaces the old one. The trash icon deletes a forwarder.
- A forwarder can use the address of an existing mailbox. Its mail then goes only to the destinations. To also keep a copy in the mailbox, add the mailbox's own address to Forward to.
- A forwarder cannot use the address of a mailing list: saving fails with "… is already a mailing list". Delete the list first, or choose another address.
- ZoPanel has no separate "alias" type: an alias is a forwarder whose destination is another mailbox on the same domain.
- Mail forwarded to outside addresses counts toward the account's sending limit.
- Forwarded mail keeps the original sender's address, so the SPF check at the receiving server fails and delivery relies on the original sender's DKIM signature. Mail from senders without DKIM may land in spam or be rejected at Gmail, Outlook.com and similar providers. For important addresses, prefer a mailbox read with a mail app.
The package's Forwarders field limits how many forwarders an account can create (0 = unlimited). Over the limit, saving fails with "the package allows N forwarders".
Catch-all
A catch-all receives mail sent to addresses of the domain that do not exist. Create it like a forwarder, but leave Address empty or enter *. It appears as *@example.com in the list.
Mail to an address that has a mailbox still goes to that mailbox. Catch-alls attract a lot of spam sent to random addresses, and spam they forward to outside addresses counts toward the sending limit. Use one only if you need it.
Mailbox rules: autoreply, filters and senders
Click the filter icon (Rules and autoreply) on a mailbox's row. The dialog has three tabs. Rules run on the server when mail is delivered, so they work whatever mail app is used, even when no app is open. Click Save to apply all three tabs.
Autoreply
| Field | Use |
|---|---|
| Send an automatic reply | Turns the autoreply on or off. Your text is kept while it is off. |
| Subject | Up to 200 characters, for example "Out of office". |
| Message | Required, up to 8,000 characters, plain text. |
| From (optional) / Until (optional) | First and last day on which replies are sent. Both days are included. Leave empty to reply until you turn it off. |
| Reply to the same sender once every N days | 1 to 30, default 1. |
The reply is sent from the mailbox's address. It is not sent to messages filed as spam, to mail from mailing lists or bulk senders, or to messages that a filter moved or deleted.
Filters
Click Add filter and set one condition and one action per row:
| Part | Options |
|---|---|
| Field | From, To / Cc (matches either header), Subject |
| Comparison | contains, is (the whole value) |
| Value | Required, up to 200 characters |
| Action | Move to folder, Forward a copy, Mark as read, Delete |
- Move to folder needs a Folder name of letters, digits, spaces,
.,_or-(up to 64 characters). The folder is created if it does not exist. Processing stops after a move. - Forward a copy sends a copy to one address and still delivers the message. Copies sent outside count toward the sending limit.
- Mark as read delivers the message as already read and continues with the next filter.
- Delete discards the message silently and stops.
Filters run top to bottom. A mailbox can have up to 100 filters.
Senders & spam
- Move spam to the Junk folder (on by default) files messages that the spam filter marked into Junk. Turn it off to keep them in the inbox.
- Always allow (never treated as spam): addresses or domains, one per line. Their mail is not moved to Junk. It is still refused if it scores above the reject level.
- Block (deleted silently): addresses or domains, one per line. Their mail is deleted without a bounce.
Each list holds up to 500 entries. An entry is either a full address (boss@example.net) or a domain (example.net, which matches only that exact domain).
If you clear every setting of a mailbox, the server default applies: spam goes to Junk.
Spam filter level
The Spam filter card on the domain page sets how strict filtering is for every mailbox of the domain:
| Level | Marked as spam from score | Refused from score |
|---|---|---|
| Low (fewer false positives) | 10 | 25 |
| Medium (recommended) | 6 | 15 |
| High (catches more) | 4 | 10 |
At Medium, the server default, messages from unknown senders scoring 4 or more may also be greylisted (temporarily deferred once), which delays the first message from them by a few minutes. Low and High turn greylisting off for the domain.
Mailing lists
A mailing list is one address that delivers each message to every member.
- In the Mailing lists card, click New list.
- Enter the List address (the part before
@). - Enter the Members, one address per line (1 to 1,000).
- Keep Only members (and the senders below) can send to the list on to stop outsiders from writing to the list. Add other permitted senders in Also allowed to send (up to 200).
- Click Save.
Messages are delivered unchanged, so the sender's DKIM signature stays valid and replies go to the original sender, not to the list. The list address cannot be a member of itself, and it cannot be the address of an existing mailbox ("a mailbox with this address exists") or forwarder ("… is already a forwarder"). With Only members on, mail from anyone else is refused when it arrives. The check uses the sender's envelope address, which is normally the From address.
The package's Mailing lists field limits how many lists an account can create (0 = unlimited). Members outside the server count toward the list owner's sending limit, including for mail that outsiders send to the list.
Quotas
| Limit | Value | Where |
|---|---|---|
| Mailbox size | Quota (MB), default 1024, 0 = unlimited, at most 102400 |
Mailbox dialog (key icon) |
| Grace above the quota | 10% | Server |
| Message size | 50 MB, including attachments | Server |
| Mailboxes per account | Email field of the package (0 = unlimited) |
Packages |
The Usage column shows the space each mailbox uses. Over the quota, new mail is refused and senders get a bounce. Free space by deleting mail and emptying Trash and Junk, or raise the quota.
Sending limits
To keep a hacked website from getting the server's IP blocklisted, ZoPanel counts the recipients each hosting account sends per hour (a rolling hour). The count includes PHP mail(), SMTP logins, and copies that forwarders, mailing lists and Forward a copy filters send outside the server.
Administrators manage this in Email → Sending limits:
- Default per hour: the limit for packages without their own (500 by default;
0= unlimited). - Block direct SMTP from accounts (on by default): website code cannot connect to other mail servers on port 25, and unauthenticated SMTP from the server itself is refused. Mail must go through this server, where it is counted, DKIM-signed and logged.
- A table of accounts with mail in the last hour: Last hour, Limit and Refused (24 h).
A package can set its own Emails per hour in Packages (empty = server default, -1 = unlimited). Over the limit, SMTP clients get 450 4.7.1 Sending limit reached (N recipients per hour), try again later and PHP mail() returns false. The account owner and the administrator are notified, at most once an hour per account.
Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
| "1-20 destinations required" / "invalid destination …" | A forwarder needs 1 to 20 valid email addresses. |
| "every filter needs a value" | Fill in the value of each filter, or delete the empty row. |
| "invalid folder …" | Use only letters, digits, spaces, ., _ and - in folder names. |
| "invalid forward address …" | Forward a copy needs one full email address. |
| "the autoreply needs a message" | Fill in Message before turning on the autoreply. |
| "… is not an address or a domain" | Correct the line in Always allow or Block. |
| "a list has 1 to 1000 members" / "invalid member …" | Check the member list; the list's own address is not allowed as a member. |
| "… is already a mailing list" | A forwarder cannot replace a mailing list. Use another address, or delete the list first. |
| "the package allows N forwarders / mailboxes / mailing lists" | The account's package limit is reached. Ask the administrator. |
| An autoreply is not sent | Check the dates, the "once every N days" setting and that the message was not spam or list mail. |
| Mail to a forwarder goes to spam at Gmail | See the note on SPF and DKIM under Forwarders. |
Related
- Email clients
- Webmail, calendars and contacts
- Packages and limits
- Dovecot Pigeonhole Sieve
- Rspamd