You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多域名多IP的Postfix服务器配置SSL/TLS方案咨询

Postfix Multi-IP/Multi-Domain SSL/TLS Configuration Guide

Great question—this is a common scenario for multi-IP/multi-domain Postfix setups, and the answer depends on your certificate coverage needs and how granular you want the configuration to be. Let’s break it down:

Option 1: Single Certificate (Simplest Setup)

You can absolutely use a single certificate if all your sending domains can be covered by it. This works best with:

  • SAN Certificates: These allow you to list multiple distinct domains (e.g., domain1.com, domain2.net, mail.domain3.org) in a single certificate.
  • Wildcard Certificates: If all your domains are subdomains of a single parent domain (e.g., *.example.com covers mail.example.com, app.example.com), this is a good fit.

Configuration Steps

Update /etc/postfix/main.cf with these settings:

# Enable TLS for outgoing connections
smtp_tls_security_level = may
# Path to your combined certificate file (includes end-entity cert + intermediate CAs)
smtp_tls_cert_file = /etc/ssl/postfix/combined-cert.pem
# Path to your private key file
smtp_tls_key_file = /etc/ssl/postfix/private-key.pem
# Path to trusted CA bundle (for verifying remote servers)
smtp_tls_CAfile = /etc/ssl/certs/ca-certificates.crt

Key Note: Make sure the EHLO/HELO domain Postfix uses for each outgoing message matches a domain in your certificate. Most receiving servers validate that the HELO domain is present in the certificate’s subject or SAN fields. For multi-domain setups, you can use sender-dependent HELO settings if needed, but a well-covered SAN certificate usually avoids this extra work.

Option 2: Multiple Certificates (Granular Control)

If you have exclusive IPs tied to specific domains that need their own certificates (e.g., brand-specific domains, compliance requirements), you’ll need to configure Postfix to use different certificates based on the sending domain or IP.

Step 1: Create a TLS Chain Map

Create a file /etc/postfix/smtp_tls_chain_maps to map sending contexts to their respective certificate chains:

# Map by sender domain
domain1.com /etc/ssl/postfix/domain1-cert-chain.pem
sender@domain2.net /etc/ssl/postfix/domain2-cert-chain.pem
# Map by outgoing IP address
[192.168.1.10] /etc/ssl/postfix/ip1-cert-chain.pem

Each certificate chain file should contain your end-entity certificate followed by any intermediate CA certificates (in order, top to bottom).

Step 2: Update Postfix Configuration

Add these lines to /etc/postfix/main.cf:

smtp_tls_security_level = may
# Enable the chain map
smtp_tls_chain_files = hash:/etc/postfix/smtp_tls_chain_maps

Then compile the map file:

postmap /etc/postfix/smtp_tls_chain_maps

Step 3 (Optional): Bind Domains to Specific IPs

If you want to ensure a domain always sends from its exclusive IP, use a transport map:

  1. Create /etc/postfix/transport:
    domain1.com smtp-domain1:
    domain2.net smtp-domain2:
    
  2. Add these settings to main.cf:
    transport_maps = hash:/etc/postfix/transport
    # Define dedicated SMTP instances for each IP
    smtp-domain1 = smtp
    smtp-domain1_inet_interfaces = 192.168.1.10
    smtp-domain2 = smtp
    smtp-domain2_inet_interfaces = 192.168.1.11
    
  3. Compile the transport map:
    postmap /etc/postfix/transport
    

Critical Best Practices

  • Always use trusted CA-issued certificates (e.g., Let’s Encrypt, Sectigo). Self-signed certificates will trigger spam filters or outright rejection from most receiving servers.
  • Ensure every outgoing IP has a reverse DNS (PTR) record pointing to a domain that’s present in your certificate. This is a key factor in email deliverability, even if it’s not directly tied to TLS validation.
  • Test your setup with tools like swaks to verify certificate selection:
    swaks --to test@recipient.com --from sender@domain1.com --server localhost --tls --ehlo domain1.com
    

内容的提问来源于stack exchange,提问作者Bob5421

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:44:55