GoDaddy SSL安装至Azure VM及PHP网站迁移后发信故障咨询
问题1:将GoDaddy SSL证书安装到Azure VM
首先从GoDaddy获取完整的证书文件包:登录GoDaddy账户,找到对应SSL证书并下载,包内包含域名证书(如yourdomain.crt)、中间证书(如gd_bundle-g2-g1.crt),同时确保你持有生成CSR时的私钥文件(yourdomain.key,若遗失需重新导出或生成)。
Linux服务器(Apache/Nginx)
Apache配置
- 将证书和私钥上传至VM指定目录,如
/etc/ssl/certs/(证书文件)和/etc/ssl/private/(私钥文件),设置私钥权限为600:chmod 600 /etc/ssl/private/yourdomain.key - 编辑Apache SSL配置文件(如
/etc/httpd/conf.d/ssl.conf或站点专属.conf文件),修改以下参数:SSLCertificateFile /etc/ssl/certs/yourdomain.crt SSLCertificateKeyFile /etc/ssl/private/yourdomain.key SSLCertificateChainFile /etc/ssl/certs/gd_bundle-g2-g1.crt - 重启Apache服务:
systemctl restart httpd
Nginx配置
- 将证书和私钥上传至VM指定目录,如
/etc/nginx/ssl/,设置私钥权限为600。 - 编辑Nginx站点配置文件,在
server块中添加SSL配置:listen 443 ssl; ssl_certificate /etc/nginx/ssl/yourdomain.crt; ssl_certificate_key /etc/nginx/ssl/yourdomain.key; ssl_trusted_certificate /etc/nginx/ssl/gd_bundle-g2-g1.crt; - 重启Nginx服务:
systemctl restart nginx
Windows服务器(IIS)
- 合并证书为
.pfx格式(若GoDaddy未提供):- 打开MMC,添加「证书」管理单元,选择「计算机账户」
- 将域名证书导入「个人」存储,中间证书导入「中级证书颁发机构」存储
- 右键域名证书,选择「所有任务 > 导出」,选择导出为
.pfx格式并包含私钥
- 在IIS管理器中,选择服务器节点,双击「服务器证书」,点击「导入」,选择生成的
.pfx文件并输入密码完成导入 - 打开目标网站,选择「绑定」,添加HTTPS绑定:端口设为443,SSL证书选择刚导入的证书,保存配置
- 重启IIS服务:打开命令提示符运行
iisreset
问题2:Azure VM上PHP网站无法发送邮件
核心排查方向及解决方案
1. 处理Azure SMTP端口限制
Azure多数VM默认禁用出站25端口,优先改用587(TLS)或465(SSL)端口,这两个端口默认开放。若必须使用25端口,需提交Azure支持请求申请解禁(仅部分订阅类型支持,如企业协议订阅)。
2. 修正PHP邮件配置
使用PHPMailer示例
确保配置正确指向SMTP服务器、端口及加密方式(推荐用GoDaddy SMTP或第三方邮件服务):
require 'PHPMailer/PHPMailer.php'; require 'PHPMailer/SMTP.php'; $mail = new PHPMailer\PHPMailer\PHPMailer(); $mail->isSMTP(); $mail->Host = 'smtp.godaddy.com'; $mail->SMTPAuth = true; $mail->Username = 'your-email@yourdomain.com'; $mail->Password = 'your-email-password'; $mail->SMTPSecure = 'tls'; $mail->Port = 587; $mail->setFrom('your-email@yourdomain.com', 'Your Name'); $mail->addAddress('recipient@example.com'); $mail->Subject = 'Test Email'; $mail->Body = 'This is a test email from Azure VM'; if(!$mail->send()) { echo 'Error: ' . $mail->ErrorInfo; } else { echo 'Email sent successfully'; }
使用mail()函数示例
编辑php.ini配置文件,设置SMTP参数:
SMTP = smtp.godaddy.com smtp_port = 587 sendmail_from = your-email@yourdomain.com
若使用sendmail工具,需确保其配置文件指向正确的SMTP服务器及端口。
3. 检查防火墙与NSG规则
- 确认Azure VM的网络安全组(NSG)出站规则允许访问587/465端口(默认允许所有出站流量,若有自定义规则需验证)
- 检查VM本地防火墙:Linux下确认
ufw/iptables允许出站SMTP端口,Windows下确认防火墙规则未拦截对应端口
4. 改用Azure集成邮件服务(推荐)
使用Azure SendGrid可规避端口限制,配置更可靠:
- 在Azure门户创建SendGrid资源,获取API密钥
- 使用SendGrid SDK发送邮件示例:
require 'vendor/autoload.php'; $sendgrid = new \SendGrid('your-sendgrid-api-key'); $email = new \SendGrid\Mail\Mail(); $email->setFrom('your-email@yourdomain.com', 'Your Name'); $email->setSubject('Test Email'); $email->addTo('recipient@example.com'); $email->addContent('text/plain', 'This is a test email via SendGrid'); try { $response = $sendgrid->send($email); echo 'Email sent successfully'; } catch (Exception $e) { echo 'Error: ' . $e->getMessage(); }
内容的提问来源于stack exchange,提问作者Vivek Bhadane
相关产品推荐
相关产品推荐

