Ubuntu 16.04服务器Postfix MTA发送邮件进垃圾箱求助
Hey there, let's dig into why your Postfix emails are landing in spam instead of the inbox. Since you mentioned your domain isn't blacklisted and this worked on another server before, we can focus on configuration gaps and deliverability checks specific to your current Ubuntu 16.04 setup.
1. Validate SPF, DKIM, and DMARC Records (Critical!)
Missing or misconfigured authentication records are the top culprit for spam filtering, even if your domain isn't blacklisted.
- SPF: Run
dig yourdomain.com txtto check if your domain has an SPF TXT record that includes your server's public IP. A valid entry looks likev=spf1 ip4:YOUR_SERVER_IP -all(use~allfor testing if you're still tweaking). - DKIM: It’s likely your old server had DKIM set up, but your new one doesn’t. Install OpenDKIM with
sudo apt-get install opendkim opendkim-tools, then configure it to sign outgoing emails (you’ll need to generate keys and add a DKIM TXT record to your domain’s DNS). - DMARC: Add a DMARC TXT record to guide receivers on handling unauthenticated emails. A basic testing entry is
v=DMARC1; p=none; sp=none; rua=mailto:dmarc@yourdomain.com—you can adjustptoquarantineorrejectonce authentication is working.
2. Audit Your Postfix main.cf Configuration
Here are key settings to verify (share the full main.cf content if you want a deeper dive):
- myhostname: Must be a fully qualified domain name (FQDN) like
mail.yourdomain.com, not just your server’s local hostname. - mydomain: Should match your actual domain (e.g.,
yourdomain.com). - myorigin: Set to
$mydomainso emails appear to originate from your domain, not the server’s local address (likeroot@server-local). - inet_interfaces: Ensure it’s set to
allor your public IP (avoid limiting it tolocalhostonly). - smtpd_banner: Include your FQDN, e.g.,
$myhostname ESMTP $mail_name (Ubuntu)—generic banners trigger spam filters. - Header checks: Confirm Postfix generates essential headers like
Message-IDandDate(default behavior, but misconfigs can break this).
3. Test Spam Score and Authentication
- Local spam check: Install SpamAssassin with
sudo apt-get install spamassassin, send a test email to a local file, then runspamassassin -t < test_email.txtto see the score. Scores over 5 will almost always land in spam. - External deliverability analysis: Use a free web-based deliverability checker (search for "email deliverability test" to find options) to get a breakdown of authentication failures, spam triggers, and header issues.
- Header inspection: Send a test email to your own account (e.g., Gmail), view the full headers, and look for lines like
SPF: PASS,DKIM: PASS,DMARC: PASS. AnyFAILorNEUTRALentries indicate a problem.
4. Check Reverse DNS (PTR Record)
Your server’s public IP must have a PTR record pointing to your FQDN (e.g., mail.yourdomain.com). Most cloud providers or ISPs let you set this in their control panel. Verify with dig -x YOUR_SERVER_IP—the output should show your FQDN.
5. Verify IP Reputation
Even if your domain is clean, your server’s IP might have a bad reputation. Install blookup with sudo apt-get install blookup, then run blookup YOUR_SERVER_IP to check common blacklists.
6. Fix Command-Line Email Sending
When testing via command line, avoid generic sender addresses (like root@server-hostname). Use proper headers instead:
mail -s "Test Deliverability" recipient@example.com <<EOF From: Your Name <you@yourdomain.com> To: Recipient <recipient@example.com> This is a test email to check if it lands in the inbox. EOF
7. Compare with Your Old Server’s Setup
Since this worked on another server, cross-reference the two:
- Compare
main.cfconfigurations line by line - Check if the old server had DKIM/SPF/DMARC records set up
- Verify reverse DNS and IP reputation for both servers
If you share your full /etc/postfix/main.cf content, I can pinpoint exact misconfigurations. Let me know what you find from these checks!
内容的提问来源于stack exchange,提问作者Martin AJ

