You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Hetzner VPS上Postfix无法发送邮件的问题求助

Hetzner VPS上Postfix无法发送邮件的问题求助

Hey there, let's work through this Hetzner VPS email issue step by step—since Hetzner's port restrictions are a common gotcha, but there are definitely fixes!

First, let's confirm the basics: Hetzner does block outbound 25 and 465 by default, so switching to 587 is the right move, but there's more to configuring Postfix for this port than just changing a single setting. Here's what to check:

  • Ensure Postfix is actually listening on port 587
    Open up your master.cf file (usually at /etc/postfix/master.cf) and look for the submission section. By default, this might be commented out. You need to uncomment it so it looks like this:

    submission inet n       -       y       -       -       smtpd
      -o syslog_name=postfix/submission
      -o smtpd_tls_security_level=encrypt
      -o smtpd_sasl_auth_enable=yes
      -o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
      -o milter_macro_daemon_name=ORIGINATING
    

    After making changes, restart Postfix with systemctl restart postfix to apply them.

  • Verify your SMTP authentication setup
    Port 587 (submission port) requires sender authentication for most mail providers these days. Make sure your main.cf has these settings enabled:

    smtpd_sasl_type = dovecot
    smtpd_sasl_path = private/auth
    smtpd_sasl_auth_enable = yes
    smtpd_sasl_security_options = noanonymous
    

    (If you're not using Dovecot, adjust the sasl type/path to match your auth provider.)

  • Set up critical DNS records
    Even if your port is correct, most email services will reject your mail without proper DNS records:

    • PTR record: Head to Hetzner's Robot panel, find your VPS, and set a reverse DNS record pointing your server's IP to your domain (e.g., mail.yourdomain.com).
    • SPF record: Add a TXT record to your domain that allows your VPS IP to send mail (e.g., v=spf1 ip4:YOUR_VPS_IP -all).
    • DKIM/DMARC: These add extra validation—set up DKIM with Postfix (using opendkim is common) and add a DMARC TXT record to enforce delivery rules.
  • Use Hetzner's official SMTP relay (a reliable shortcut)
    Hetzner provides their own SMTP relay service that bypasses the port 25/465 blocks. To use it:

    1. Add this line to your main.cf: relayhost = relay.hetzner.com
    2. Ensure your server has a valid PTR record (Hetzner's relay uses this to authenticate you without extra credentials).
    3. Restart Postfix and test sending again.
  • Check firewall rules
    Don't forget to allow port 587 on both your VPS's local firewall (e.g., ufw allow 587/tcp or adjust iptables) and Hetzner's cloud firewall (if you've enabled it in their panel).

  • Dig into Postfix logs for specific errors
    If you're still stuck, check the mail logs to see exactly what's failing. Run:

    tail -f /var/log/mail.log
    

    Look for lines with error, rejected, or connection refused—these will tell you if it's an auth issue, DNS problem, or something else.

If you can share the relevant log snippets, we can narrow it down even further!

备注:内容来源于stack exchange,提问作者EAK TEAM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 16:24:34