You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决ThunderBird收发邮件失败与Postfix服务器配置问题?

问题描述

我在DigitalOcean上重新安装了Postfix,参考《how-to-install-and-configure-postfix-on-ubuntu-20-04》教程完成配置并添加了用户。尝试用ThunderBird访问用户邮箱时直接失败,手动配置后仍无法与其他用户及Gmail账户收发邮件。已按照YouTube教程安装dovecot-imapd和dovecot-pop3d,在DigitalOcean控制台可正常收发邮件;此前ThunderBird仅能实现内部用户间邮件收发,无法与Gmail交互。以下是main.cf配置信息,请问是否需要调整Postfix配置?该如何解决此问题?

# Debian specific:  Specifying a file name will cause the first
# line of that file to be used as the name.  The Debian default
# is /etc/mailname.
#myorigin = /etc/mailname

smtpd_banner = $myhostname ESMTP $mail_name (Ubuntu)
biff = no

# appending .domain is the MUA's job.
append_dot_mydomain = no

# Uncomment the next line to generate "delayed mail" warnings
#delay_warning_time = 4h

readme_directory = no

# See http://www.postfix.org/COMPATIBILITY_README.html -- default to 3.6 on
# fresh installs.
compatibility_level = 3.6



# TLS parameters
smtpd_tls_cert_file = /etc/ssl/certs/server.crt
smtpd_tls_key_file = /etc/ssl/private/server.key
smtpd_tls_security_level = may

smtp_tls_CApath=/etc/ssl/certs
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache


smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination
myhostname = mail.example.com
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
myorigin = /etc/mailname
relayhost =
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
mailbox_size_limit = 0
recipient_delimiter = +
inet_interfaces = all
inet_protocols = all
home_mailbox = Maildir/
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_local_domain =
smtpd_sasl_security_options = noanonymous
smtpd_sasl_tls_security_options = noanonymous
broken_sasl_auth_clients = yes
smtpd_sasl_auth_enable = yes
smtpd_recipient_restrictions = permit_sasl_authenticated,permit_mynetworks,reject_unauth_destination
smtp_tls_note_starttls_offer = yes
smtpd_tls_loglevel = 4
smtpd_tls_received_header = yes
smtpd_sasl_security_options = noanonymous
smtpd_sasl_authenticated_header = yes

smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination
smtpd_tls_auth_only = no
debug_peer_list = problem.domain
解决方案

一、Postfix配置调整

  1. 清理重复配置项
    你的main.cf中重复定义了smtpd_relay_restrictions和smtpd_sasl_security_options,删除重复条目,保留一组即可:

    # 保留这组smtpd_relay_restrictions,删除第二组重复项
    smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination
    
    # 保留这组smtpd_sasl_security_options,删除第二组重复项
    smtpd_sasl_security_options = noanonymous
    
  2. 强化TLS安全设置
    将smtpd_tls_security_level从may改为encrypt,强制客户端使用TLS连接,避免明文认证失败:

    smtpd_tls_security_level = encrypt
    

    同时添加出站SMTP的TLS配置,确保与外部邮箱交互时用加密连接:

    smtp_tls_security_level = may
    smtp_tls_loglevel = 1
    
  3. 验证myorigin配置
    检查/etc/mailname文件内容,确保值为你的根域名(如example.com),而非mail.example.com。错误的发件人域名会被Gmail等服务商标记为垃圾邮件或拒收。

二、ThunderBird手动配置修正

  1. 接收服务器设置

    • 协议选IMAP或POP3,服务器地址填mail.example.com
    • IMAP端口用993(SSL/TLS),POP3用995(SSL/TLS)
    • 认证方式选正常密码,用户名填完整邮箱地址(如user@example.com)
  2. 发送服务器设置

    • SMTP服务器地址填mail.example.com,端口用587(STARTTLS)
    • 勾选使用用户名和密码,用户名填完整邮箱地址,认证方式选正常密码
  3. 关闭自动配置
    手动配置时禁用ThunderBird的自动检测功能,避免自动生成错误参数。

三、外部邮件交互关键配置

  1. 反向DNS与SPF记录

    • 在DigitalOcean控制面板为服务器IP设置反向DNS(PTR记录),指向mail.example.com
    • 为域名添加SPF记录,格式为v=spf1 mx a:mail.example.com -all,明确合法发件源
  2. 防火墙端口放行
    确保DigitalOcean防火墙和服务器UFW放行以下端口:

    • 25(SMTP)
    • 587(SMTP STARTTLS)
    • 993(IMAP SSL)
    • 995(POP3 SSL)
  3. 日志排查
    查看Postfix日志定位错误:

    tail -f /var/log/mail.log
    

    重点关注TLS handshake failed、SASL authentication failed等关键词,排查证书或认证配置问题。

四、Dovecot配置验证

  1. SASL认证配置
    编辑/etc/dovecot/conf.d/10-auth.conf:

    disable_plaintext_auth = yes
    auth_mechanisms = plain login
    
  2. Postfix-SASL连接配置
    编辑/etc/dovecot/conf.d/10-master.conf:

    service auth {
      unix_listener /var/spool/postfix/private/auth {
        mode = 0666
        user = postfix
        group = postfix
      }
    }
    
  3. 重启服务
    修改后重启Dovecot和Postfix:

    systemctl restart dovecot postfix
    

内容的提问来源于stack exchange,提问作者Princess23

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 05:50:19