You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mailcow+jwilder反向代理遇Error526,请求排查配置问题

Fixing Error 526: Invalid SSL Certificate for Mailcow + Cloudflare + Nginx Proxy

Let's break down that 526 error and get your setup working properly. First, remember: Error 526 happens when Cloudflare can't verify the SSL certificate your origin server (your jwilder reverse proxy) is sending. Usually this is due to a misconfigured certificate, mismatched settings between Cloudflare and your proxy, or a routing issue in Mailcow.

1. Check Cloudflare's SSL/TLS Mode First

Head to your Cloudflare dashboard for example.com, go to SSL/TLS > Overview:

  • Make sure your SSL mode is set to "Full" or "Strict":
    • "Full" works if your proxy uses a valid Let's Encrypt certificate (which you are)
    • "Strict" is even better, as it enforces full trust chain validation
  • If you were using "Flexible" mode, switch to "Full" immediately—Flexible tells Cloudflare to connect to your server over HTTP, but your proxy is listening on HTTPS (443), which causes a mismatch.

2. Fix Mailcow's HTTP_BIND Configuration

Your mailcow.conf has HTTP_BIND=proxy—that's a mistake. This makes Mailcow's nginx container only listen on an IP tied to the proxy hostname, which your reverse proxy can't reach properly. Update it to:

# In mailcow.conf
HTTP_BIND=0.0.0.0
# You can also comment out HTTPS_BIND entirely since your reverse proxy handles HTTPS
# HTTPS_BIND=0.0.0.0

3. Clean Up Invalid YAML in docker-compose-override.yml

You have an empty ports: line under nginx-mailcow in your override file—this will cause YAML parsing errors. Delete that line entirely:

# docker-compose-override.yml (fixed)
version: '2.1'
services:
  nginx-mailcow:
    networks:
      proxy-tier:
    environment:
      - VIRTUAL_HOST=${MAILCOW_HOSTNAME},${ADDITIONAL_SAN}
      - VIRTUAL_PORT=8080
      - VIRTUAL_PROTO=http
      - LETSENCRYPT_HOST=${MAILCOW_HOSTNAME},${ADDITIONAL_SAN}
    volumes:
      - ${DOCKERDIR}/reverse_proxy/certs/${MAILCOW_HOSTNAME}:/etc/ssl/mail/
      - ${DOCKERDIR}/reverse_proxy/certs/dhparam.pem:/etc/ssl/mail/dhparams.pem:ro
  dovecot-mailcow:
    volumes:
      - ${DOCKERDIR}/reverse_proxy/certs/${MAILCOW_HOSTNAME}:/etc/ssl/mail/
      - ${DOCKERDIR}/reverse_proxy/certs/dhparam.pem:/etc/ssl/mail/dhparams.pem:ro
  postfix-mailcow:
    volumes:
      - ${DOCKERDIR}/reverse_proxy/certs/${MAILCOW_HOSTNAME}:/etc/ssl/mail/
      - ${DOCKERDIR}/reverse_proxy/certs/dhparam.pem:/etc/ssl/mail/dhparams.pem:ro
    networks:
      proxy-tier:

4. Verify Let's Encrypt Certificates Are Generated

Your jwilder le container should have created a certificate for mail.example.com. Check if the files exist:

cd ${DOCKERDIR}/reverse_proxy/certs/mail.example.com
ls -la

You should see fullchain.pem (the complete certificate chain) and privkey.pem (the private key). If they're missing:

  1. Make sure your nginx-mailcow container is running (the le container needs to detect its LETSENCRYPT_HOST label)
  2. Restart the le container:
    docker restart le
    

5. Test Routing Locally

Before checking Cloudflare, confirm your proxy is working correctly from your server:

  1. Test direct access to Mailcow's HTTP port:
    curl http://localhost:8080
    
    You should see the Mailcow login page HTML.
  2. Test your proxy's HTTPS service:
    curl -v https://mail.example.com --resolve mail.example.com:443:127.0.0.1
    
    Look for lines mentioning the SSL certificate—verify it's issued by Let's Encrypt and matches mail.example.com.

6. Double-Check Cloudflare DNS Records

  • Ensure mail.example.com is a CNAME pointing to example.com, with the orange cloud (proxy) enabled
  • Confirm example.com's A/AAAA records point to your server's public IP (no typos here!)

Final Step: Restart All Containers

Apply all changes by restarting your proxy and Mailcow stacks:

# Restart reverse proxy
docker restart proxy le

# Restart Mailcow
cd ${DOCKERDIR}/mailcow
docker-compose down
docker-compose up -d

After a minute or two, visit mail.example.com again—the 526 error should be gone.

内容的提问来源于stack exchange,提问作者vonAlenberg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 14:27:35