Mailcow+jwilder反向代理遇Error526,请求排查配置问题
Let's break down that 526 error and get your setup working properly. First, remember: Error 526 happens when Cloudflare can't verify the SSL certificate your origin server (your jwilder reverse proxy) is sending. Usually this is due to a misconfigured certificate, mismatched settings between Cloudflare and your proxy, or a routing issue in Mailcow.
1. Check Cloudflare's SSL/TLS Mode First
Head to your Cloudflare dashboard for example.com, go to SSL/TLS > Overview:
- Make sure your SSL mode is set to "Full" or "Strict":
- "Full" works if your proxy uses a valid Let's Encrypt certificate (which you are)
- "Strict" is even better, as it enforces full trust chain validation
- If you were using "Flexible" mode, switch to "Full" immediately—Flexible tells Cloudflare to connect to your server over HTTP, but your proxy is listening on HTTPS (443), which causes a mismatch.
2. Fix Mailcow's HTTP_BIND Configuration
Your mailcow.conf has HTTP_BIND=proxy—that's a mistake. This makes Mailcow's nginx container only listen on an IP tied to the proxy hostname, which your reverse proxy can't reach properly. Update it to:
# In mailcow.conf HTTP_BIND=0.0.0.0 # You can also comment out HTTPS_BIND entirely since your reverse proxy handles HTTPS # HTTPS_BIND=0.0.0.0
3. Clean Up Invalid YAML in docker-compose-override.yml
You have an empty ports: line under nginx-mailcow in your override file—this will cause YAML parsing errors. Delete that line entirely:
# docker-compose-override.yml (fixed) version: '2.1' services: nginx-mailcow: networks: proxy-tier: environment: - VIRTUAL_HOST=${MAILCOW_HOSTNAME},${ADDITIONAL_SAN} - VIRTUAL_PORT=8080 - VIRTUAL_PROTO=http - LETSENCRYPT_HOST=${MAILCOW_HOSTNAME},${ADDITIONAL_SAN} volumes: - ${DOCKERDIR}/reverse_proxy/certs/${MAILCOW_HOSTNAME}:/etc/ssl/mail/ - ${DOCKERDIR}/reverse_proxy/certs/dhparam.pem:/etc/ssl/mail/dhparams.pem:ro dovecot-mailcow: volumes: - ${DOCKERDIR}/reverse_proxy/certs/${MAILCOW_HOSTNAME}:/etc/ssl/mail/ - ${DOCKERDIR}/reverse_proxy/certs/dhparam.pem:/etc/ssl/mail/dhparams.pem:ro postfix-mailcow: volumes: - ${DOCKERDIR}/reverse_proxy/certs/${MAILCOW_HOSTNAME}:/etc/ssl/mail/ - ${DOCKERDIR}/reverse_proxy/certs/dhparam.pem:/etc/ssl/mail/dhparams.pem:ro networks: proxy-tier:
4. Verify Let's Encrypt Certificates Are Generated
Your jwilder le container should have created a certificate for mail.example.com. Check if the files exist:
cd ${DOCKERDIR}/reverse_proxy/certs/mail.example.com ls -la
You should see fullchain.pem (the complete certificate chain) and privkey.pem (the private key). If they're missing:
- Make sure your
nginx-mailcowcontainer is running (thelecontainer needs to detect itsLETSENCRYPT_HOSTlabel) - Restart the
lecontainer:docker restart le
5. Test Routing Locally
Before checking Cloudflare, confirm your proxy is working correctly from your server:
- Test direct access to Mailcow's HTTP port:
You should see the Mailcow login page HTML.curl http://localhost:8080 - Test your proxy's HTTPS service:
Look for lines mentioning the SSL certificate—verify it's issued by Let's Encrypt and matchescurl -v https://mail.example.com --resolve mail.example.com:443:127.0.0.1mail.example.com.
6. Double-Check Cloudflare DNS Records
- Ensure
mail.example.comis a CNAME pointing toexample.com, with the orange cloud (proxy) enabled - Confirm
example.com's A/AAAA records point to your server's public IP (no typos here!)
Final Step: Restart All Containers
Apply all changes by restarting your proxy and Mailcow stacks:
# Restart reverse proxy docker restart proxy le # Restart Mailcow cd ${DOCKERDIR}/mailcow docker-compose down docker-compose up -d
After a minute or two, visit mail.example.com again—the 526 error should be gone.
内容的提问来源于stack exchange,提问作者vonAlenberg

