chore(mail): pinned-version update check off, Gmail postscreen whitelist, docs
- compose: ENABLE_UPDATE_CHECK=0 (image intentionally pinned to DMS v15.1.0). - postscreen: permit Google SMTP outbound ranges (Gmail retries from rotating IPs, '450 PASS NEW' never completes) — keeps LinkedIn/Gmail mail out of the tarpit. - README: DNS/ops notes; user-patches: whitelist copy path.
This commit is contained in:
@@ -169,3 +169,50 @@ see the `gitea` repo): forward `http://172.17.0.1:19944`, Let's Encrypt cert
|
||||
|
||||
DMS uses a Let's Encrypt certificate for `mail.produktor.io` mounted from
|
||||
`tls/letsencrypt/mail.produktor.io/` (`SSL_TYPE=letsencrypt`).
|
||||
|
||||
## DNS (live zone, arc-01)
|
||||
|
||||
Outbound IP is dynamic (Orange residential). SPF follows the Dynu hostname
|
||||
instead of a fixed `ip4:` — `ddclient` on arc-01 keeps
|
||||
`produktor.mywire.org` pointed at the current address
|
||||
(`produktor/duckdns/dyndns/config/ddclient.conf`).
|
||||
|
||||
### produktor.io — Dynadot
|
||||
|
||||
| Type | Host | Value |
|
||||
|------|------|-------|
|
||||
| CNAME | `mail` | `produktor.mywire.org` |
|
||||
| MX | `@` | `10 mail.produktor.io` |
|
||||
| TXT | `@` | `v=spf1 a:produktor.mywire.org ~all` |
|
||||
| TXT | `_dmarc` | `v=DMARC1; p=quarantine; adkim=r; aspf=r; pct=100` |
|
||||
| TXT | `mail._domainkey` | `v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8P5kdq57uAD9r9XSxvDViVbvOaQfVEIHwS99G5PYFHcoLdhm6sAHaE94pw27BBVweed+TjevhoEaD77RV+uwsE9E+zHepnoLYcCql7vLtRy7QLrSKzNJonCin6g+kzw/2swZ+022w1W27kZgLc3LwUFaTerRI8xDOtbEUmcWGsMPW52JaKVmU3UhFMDVLpH/t1OrbZeCEReM8iK5Cc1jPno9nf3F7ang9x9o0Gyw1CP6takDQiS4X6UK23vjymaauO9PrQQpkAydhkHODq3Sxm3rgSnYjWgPl7BrVr9ujN+K12OObzquj0/Zol1Da1d0IPdzEOAa4SkpLt5FUOgQ7wIDAQAB` |
|
||||
|
||||
DKIM private key: `config/opendkim/keys/produktor.io/mail.private` (gitignored
|
||||
on live host). Re-publish the TXT from `mail.txt` after key rotation:
|
||||
`docker exec mailserver cat /etc/opendkim/keys/produktor.io/mail.txt`.
|
||||
|
||||
ACME DNS-01 for `mail.produktor.io` uses `scripts/dynadot-dns.sh` (Dynadot API).
|
||||
|
||||
### produktor.mywire.org — Dynu (dynamic A)
|
||||
|
||||
| Type | Host | Value |
|
||||
|------|------|-------|
|
||||
| A | `@` | current WAN IP (ddclient → Dynu API, ~5 min) |
|
||||
|
||||
As of last check: `90.169.228.16`.
|
||||
|
||||
### Verify
|
||||
|
||||
```bash
|
||||
dig @1.1.1.1 +short A mail.produktor.io
|
||||
dig @1.1.1.1 +short MX produktor.io
|
||||
dig @1.1.1.1 +short TXT produktor.io
|
||||
dig @1.1.1.1 +short TXT _dmarc.produktor.io
|
||||
dig @1.1.1.1 +short TXT mail._domainkey.produktor.io
|
||||
dig @1.1.1.1 +short A produktor.mywire.org
|
||||
```
|
||||
|
||||
External deliverability smoke test: `scripts/mail-outlook-test.sh`.
|
||||
|
||||
**PTR** is not under our control (Orange pool) — expected mismatch; see
|
||||
`~/.config/opencode/skill/mails/SKILL.md`.
|
||||
|
||||
Reference in New Issue
Block a user