Nixt Server

What Nixt Server is, what it includes, how it is built from roles, and how this documentation is organised.

Nixt Server is the mail server of the Nixt Office suite. It receives mail for your domains from the internet, filters it, stores it, and serves it to the people who use it over IMAP, POP3 and JMAP. It sends the mail they write, signs it with DKIM and delivers it to other servers. It also hosts calendars and contacts over CalDAV and CardDAV, runs each person’s Sieve filters and out-of-office replies, and gives you a command line and an API to administer all of it.

It is one program, versealx-server, that you run on your own Linux machine.

Get Nixt Server from the Download page.

Who these pages are for

What it includes

AreaWhat you get
Receiving mailSMTP on port 25 with STARTTLS. Recipients are checked against your directory while the sender is still connected, so mail for an address that does not exist is refused rather than bounced later.
Sender authenticationSPF, DKIM, DMARC and ARC are checked on every incoming message, and the results are recorded in an Authentication-Results header. Mail that fails the sender’s DMARC reject policy is refused.
FilteringA built-in stage that scores authentication results, and an attachment policy that refuses executables, dangerous archives and macro-carrying Office files. You can add ClamAV and any number of milters, such as Rspamd.
MailboxesIMAP4rev1 with a long list of extensions, POP3, and JMAP with push over EventSource and WebSocket. One message store answers all three, so a message read on one is read on the others.
RulesSieve scripts with 28 extensions, managed over ManageSieve, and out-of-office replies set from a mail app over JMAP.
Sending mailAuthenticated submission on ports 587 and 465, DKIM signing with an RSA and an Ed25519 key per domain, a retrying queue with delivery status notifications, and per-destination pacing.
Secure deliveryDANE and MTA-STS are enforced when the receiving domain publishes them, REQUIRETLS is honoured, and DNS answers are validated with DNSSEC.
RelayingSend everything through a smart host, or send chosen domains through their own relay, when your connection cannot deliver mail directly.
Calendars and contactsCalDAV and CardDAV on the HTTPS port, discovered at the well-known addresses.
Client setupMozilla autoconfig, Microsoft Autodiscover and SRV records, so mail apps configure themselves from an email address.
Your own policiesAn MTA-STS policy for each domain, TLS reporting and DMARC aggregate reports, both received and sent.
CertificatesCertificate files you supply, or certificates obtained and renewed automatically over ACME (HTTP-01). A DANE key rollover command for ACME nodes.
Administrationversealx-server admin over a local socket, backed by a REST API with an OpenAPI document. Every change is written to an append-only audit log in the same transaction as the change.
Sign-inPasswords stored as Argon2id hashes, SASL mechanisms PLAIN, LOGIN and SCRAM-SHA-256, account lockout, and an OAuth 2.0 authorisation server for JMAP apps such as Nixt Mail.
Operationsdoctor, which checks DNS, certificates, reverse DNS and the store and tells you what to fix; Prometheus metrics with health and readiness endpoints; a message trace; and offline backup and restore.
StorageSQLite and a directory of message files on a single machine, or PostgreSQL and an S3-compatible bucket. Message bodies are encrypted per tenant with AES-256-GCM.

How the server is built: roles

Every part of the server is a role. A node runs all of them unless its configuration names a subset, which lets you split a larger installation across machines that share one store.

RoleWhat it doesWhat it listens on by default
mxReceives mail from other servers.25
submissionAccepts mail from signed-in people.587 (STARTTLS), 465 (TLS)
relayWorks through the queue: delivers to other servers and hands mail for local recipients to deliver. Also sends the daily TLS and DMARC reports and expires old message traces.Nothing
filterThe name of the filter pipeline. The pipeline runs inside mx and submission.Nothing
storeServes mailboxes over IMAP, POP3, ManageSieve and JMAP, and the OAuth sign-in endpoints.143, 993, 110, 995, 4190, 443
deliverPuts accepted mail into mailboxes, runs Sieve and sends vacation replies.Nothing
davServes calendars and address books.443
adminServes the administrative API on a local socket, and over HTTPS when you configure it.A local socket
serveAnswers autoconfig, Autodiscover and MTA-STS policy requests, and obtains ACME certificates.443, and 80 when ACME is on

A single machine normally runs every role. Configuration explains how to choose them.

Tenants, domains and accounts

Everything the server hosts belongs to a tenant. A tenant holds domains, and a domain holds accounts (people with mailboxes), groups, aliases and resources. A small installation has one tenant; versealx-server init makes it for you. Tenants keep their data apart from each other, and each tenant’s messages are encrypted under its own key.

How this documentation is organised

Get started

PageWhat it covers
RequirementsThe machine, the network, the ports, DNS and certificates you need before you start.
Quick startFrom installing the package to receiving and sending your first message.
TLS certificatesCertificate files, self-signed certificates for testing, ACME, and changing a key that DANE pins.
DNS recordsEvery record a domain needs, what each one does, and how to enter them at a DNS provider.

Configure

PageWhat it covers
ConfigurationEvery section and key of versealx-server.toml, with its type, default and meaning.
Runtime settingsThe settings kept in the server’s store, which you change without a restart.
Domains and accountsTenants, domains, domain verification, accounts, groups, aliases and passwords.
Signing inPasswords, SASL mechanisms, lockout, OAuth tokens and the sign-in pages.
Connecting mail appsSettings for IMAP, POP3, SMTP, JMAP, ManageSieve, CalDAV and CardDAV, and automatic setup.
Provisioning with SCIMSyncing accounts and groups from Entra ID, Okta or your own script, and the tokens a machine signs in with.
Single sign-onLetting people sign in at your own identity provider instead of keeping a second password for mail.
Syncing from LDAP or Active DirectoryKeeping mailboxes in step with the directory you already have, on a schedule.
Calendars and schedulingMeeting invitations inside the organisation and out, busy time, sharing, calendar delegates and group address books.
Shared mailboxesTeam inboxes several people work in, their members and read state, and people sharing one folder.
BrandingThe organisation’s name, logo, colour and help on the pages its people sign in on.
When somebody leavesOffboarding in one reviewed, reversible step: sign-ins ended, mail kept, new mail answered.
Mailing lists and groupsLists with owners, moderators and outside subscribers, and groups that follow a rule.
PlansStorage, sending limits, protocols, forwarding and two-step sign-in for kinds of people at once.
Getting deleted mail backDeleted mail waits for a window before it is gone, and Trash and Junk empty themselves.

Mail flow

PageWhat it covers
Receiving mailWhat happens while another server delivers to yours, and the replies it can get.
Spam and malware filteringThe filter pipeline, scores and thresholds, the attachment policy, ClamAV and milters.
Sieve filters and vacation repliesPersonal rules, the supported Sieve extensions, ManageSieve, and out-of-office replies.
Sending and deliverySubmission, the queue and its retries, bounces, pacing, smart hosts, DANE and MTA-STS.
Email authenticationSPF, DKIM signing and key rotation, DMARC, ARC, and DMARC and TLS reports.
Reported phishingPeople reporting phishing, removing it from everybody, and the server taking it back on its own.
Encryption keysPublishing people’s OpenPGP keys and S/MIME certificates so mail apps find them.

Operate

PageWhat it covers
Running the serverThe service, the data it keeps, file permissions, logs, and several nodes on one store.
Roles and the audit logWho may do what through the API, and the record of every change.
ApprovalsA second administrator for changes that cannot be undone, and an operator who asks first.
Webhooks and log exportEvents sent to your systems as they happen, and the security log streamed to your SIEM.
Who opened my mailA record of what delegates, members, colleagues and administrators did in a mailbox.
SearchHow search stays fast in a large mailbox, what it matches, and the index commands.
Message traceFinding out what happened to a message, in the queue and after it left, and finding messages by what happened to them.
MonitoringMetrics, health and readiness, logs, and doctor.
Backup and restoreTaking a snapshot, what it holds, the key you must keep separately, and a restore drill.

Reference

PageWhat it covers
Command-line referenceEvery versealx-server subcommand, flag, output and exit code.
Admin APIAuthentication, every endpoint, request and answer shapes, and errors.
Protocols and limitsThe SMTP, IMAP, POP3, JMAP and ManageSieve extensions offered, and every built-in ceiling.
JMAP recoverable mailThe JMAP extension apps use to list and put back deleted mail.
JMAP snoozeThe JMAP extension apps use to snooze a message until a time.

Help

PageWhat it covers
TroubleshootingStart-up refusals, delivery problems, and the messages the server prints.

Something unclear or out of date on this page? Tell us.