全新安装的iRedMail可接收邮件但无法发送
Hey there, let's work through this issue step by step—since you can receive external emails but can't send to Gmail or Yahoo, the problem almost certainly ties back to deliverability checks those large providers enforce. Here's what to prioritize checking:
1. Validate SPF, DKIM, and DMARC DNS Records
Big email services reject or flag emails that lack proper authentication records. These are non-negotiable:
- SPF Record: Run
dig yourdomain.com TXTin your server's terminal. Look for a record starting withv=spf1that includes your server's public IP (e.g.,v=spf1 ip4:192.168.1.1 -all). If it's missing or incorrect, add/update it in your domain's DNS settings. - DKIM Record: iRedMail auto-generates a DKIM key during installation. Use
amavisd-new showkeysto view your domain's DKIM configuration. Compare this to the TXT record in your domain's DNS—they must match exactly. If not, update the DNS record. - DMARC Record: Add a DMARC TXT record to your domain (e.g.,
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:dmarc@yourdomain.com). This tells providers how to handle unauthenticated emails from your domain, which helps build trust over time.
2. Confirm Reverse DNS (PTR) Record
Gmail and Yahoo require a valid PTR record that maps your server's IP back to your mail server hostname (e.g., mail.yourdomain.com):
- Log into your Vultr dashboard, navigate to your server's details, and locate the PTR record setting. Set it to match your mail server's fully qualified domain name (FQDN). Without this, your emails will almost certainly be rejected.
3. Check Server Hostname and Postfix HELO/EHLO Settings
Ensure your server's hostname matches what Postfix uses for HELO/EHLO communications:
- Run
hostname -fto get your server's FQDN—it should be something likemail.yourdomain.com. - Open
/etc/postfix/main.cfand verify themyhostnamevalue matches this FQDN. If not, update it, then restart Postfix withsystemctl restart postfix.
4. Analyze Mail Logs for Specific Errors
The logs will tell you exactly why delivery is failing. Run these commands to spot issues:
- Tail live logs:
tail -f /var/log/mail.log - Search for rejection messages:
grep -i "reject\|fail\|error" /var/log/mail.log
Common errors include:550 5.7.1 Unauthenticated email is not accepted: Missing or invalid SPF/DKIM records.554 5.7.1 Service unavailable: Invalid PTR record or blacklisted IP.
5. Check for IP Blacklisting
New VPS IPs sometimes end up on spam databases. Use a free blacklist checking tool to see if your server's IP is listed. If it is:
- Request removal from the relevant blacklists.
- Contact Vultr support to see if they can assign you a clean, unlisted IP.
6. Verify Port 25 is Open
Port 25 is required for outbound email delivery. Confirm it's accessible:
- Run
telnet gmail-smtp-in.l.google.com 25on your server. If you get a connection response (e.g.,220 mx.google.com ESMTP), the port is open. - If not, check your server firewall with
ufw statusto ensure port 25 is allowed, and verify Vultr's cloud firewall settings don't block it.
Start with these checks—most delivery issues to major providers stem from one of these areas. Let me know what you find in the logs or DNS records, and we can troubleshoot further if needed.
内容的提问来源于stack exchange,提问作者ScioMind

