infratuzilma · devops
Biotact Mail
biotact.uz uchun self-hosted korporativ pochta. Stalwart Mail + Snappymail + Caddy. To'liq autentifikatsiya: SPF, DKIM (RSA + Ed25519), DMARC, PTR.
Rol
Full-Stack
Davr
2025–2026
Holat
Production
Biotact Mail — biotact.uz domeni uchun Contabo VPS'da self-hosted korporativ pochta serveri.
Docker Compose'da uchta konteyner: Stalwart Mail Server v0.15.5, Snappymail v2.38.2 va Caddy 2.11 (Let's Encrypt bilan avtomatik TLS).
To'liq email autentifikatsiya: SPF hard fail (-all), ikki DKIM imzo (RSA-2048 + Ed25519), DMARC quarantine siyosati, PTR/rDNS. mail-tester.com natijasi — 8.7/10.
Caddy marshrutlash: /admin*, /api/* → Stalwart, /jmap* → JMAP, qolganlari → Snappymail. DKIM kalitlari RocksDB'da, akkauntlar REST API orqali boshqariladi.
Asosiy yechimlar
Ikki DKIM imzo — RSA-2048 + Ed25519 maksimal yetkazib berish uchun
SPF hard fail + DMARC quarantine + PTR/rDNS — mail-tester.com'da 8.7/10
Caddy reverse proxy auto TLS bilan — admin, API, JMAP, webmail marshrutlash
To'liq Docker stek: Stalwart (SMTP/IMAP/JMAP) + Snappymail + Caddy
Texnologiya steki
Stalwart Snappymail Caddy Docker RocksDB DNS
Galereya

