Recommended Free Tools
To forward mail from a self-hosted server, configure the rule at the layer that handles the recipient: use a Postfix virtual alias for a hosted address, a .forward file for a locally delivered Unix account, or a Dovecot Sieve redirect for mailbox-level rules. These are distinct delivery paths, not interchangeable settings. Identify the path first, then configure one forwarding layer and test delivery to the destination.
Choose where forwarding should happen
The right method depends on whether you want to forward an address across a hosted domain, a local Unix user’s mail, or messages processed in a Dovecot mailbox.
| Need | Likely mechanism | Scope and considerations |
|---|---|---|
| Forward selected addresses for a hosted domain | Postfix virtual alias map | Address/domain mapping. Rebuild the indexed map after editing and classify the domain as virtual rather than listing it in mydestination. Postfix Virtual Domain Hosting Howto. |
| Forward a locally delivered Unix user’s mail | User’s .forward file |
Applies to local-account delivery, not the virtual-domain mapping route. Postfix Address Rewriting. |
| Filter or redirect messages at mailbox delivery | Dovecot Sieve | Requires Dovecot LDA or LMTP delivery and Sieve/Pigeonhole integration; external forwarding can affect SPF evaluation. Dovecot Sieve and Dovecot Sieve how-to. |
There is no universally best method: each operates at a different scope, and the available project documentation does not establish that one is preferable for every installation.
Forward a hosted address with a Postfix virtual alias
Postfix documents virtual alias domains for setups whose main purpose is forwarding mail elsewhere. In its Virtual Domain Hosting Howto, it describes that purpose directly: “The main purpose of these domains is to forward mail elsewhere.”
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
A simplified example, with a domain-specific virtual map, looks like this:
# /etc/postfix/main.cf
virtual_alias_domains = example.com
virtual_alias_maps = lmdb:/etc/postfix/virtual
# /etc/postfix/virtual
postmaster@example.com postmaster
joe@example.com joe@somewhere.example
The right-hand side can be a local or remote address. This example uses lmdb: only to illustrate a map backend; use the backend configured and supported by your Postfix installation rather than copying it blindly.
Rank #2
- Edit the configured virtual map to add only the recipient mappings you want.
- Rebuild its indexed database with the appropriate
postmapcommand for that map type. Consult the Postfix guide for the virtual-alias configuration. - When changing relevant
main.cfsettings, reload Postfix so it reads the changes.
Do not put a virtual alias domain in mydestination; Postfix’s documented virtual-domain setup treats that as conflicting classification. If you need to accept mail for named recipients only, explicit mappings also let unknown recipients be rejected instead of redirected.
Why a catch-all can be risky
An entry such as @example.com destination@example.net sends mail for otherwise unlisted names to one destination. Postfix warns that catch-alls can attract spam and bounces for messages forged from guessed addresses. Use one only when you intend to accept that behavior, and check how your server handles unknown recipients.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteForward mail for a local Unix account with .forward
If Postfix delivers to a local account, its local delivery agent supports a user-controlled forwarding file named .forward in that account’s home directory. This is separate from a virtual-domain alias map: it affects the local account’s delivery path. See Postfix Address Rewriting for the documented mechanism.
Use this approach when the recipient is a local Unix user and local delivery is what you want to change. If the address is handled as a virtual alias or the message is delivered through Dovecot for mailbox processing, configure the rule at that layer instead.
Rank #4
Redirect messages with Dovecot Sieve
When mail is delivered through Dovecot LDA or LMTP and Pigeonhole Sieve is installed, Sieve can apply mailbox-level filtering or redirect rules. Dovecot’s Sieve documentation and autoforward guidance describe this route.
Follow the Sieve example’s rule order: the relevant header changes must occur in the right place relative to the redirect. Configuration details can vary between Dovecot and Pigeonhole releases, so check documentation for the versions installed rather than pasting a rule from a different release.
Account for SPF when forwarding externally
Dovecot warns that forwarding a message with its original envelope sender unchanged can cause SPF checks to fail farther along the delivery path. A destination provider may therefore treat a forwarded message differently from one sent directly by its original sender. The cited guidance does not establish a single fix that works for every mail flow; the appropriate handling depends on your setup and the receiving provider’s authentication behavior.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Set up and verify forwarding safely
- Trace the delivery path. Determine whether the address is handled by a Postfix virtual alias, delivered to a local Unix user, or processed by Dovecot LDA/LMTP with Sieve. Avoid configuring two forwarding layers unintentionally, which can result in duplicate delivery or a forwarding loop.
- Add only intended recipients. Prefer explicit address mappings when you do not want to accept mail for every unlisted address. For a Postfix indexed map, rebuild the database after changing its source file; reload Postfix after relevant
main.cfedits. - Keep relay permissions constrained. Postfix documents controlling which client networks and destinations are authorized for relay. Do not widen those permissions without understanding their effect. If direct Internet delivery is blocked or unsuitable, Postfix documents configuring a
relayhost; check the relevant Postfix Basic Configuration guidance and the relay provider’s mail policies. - Test from outside your server. Send a message from an external account to each forwarded address. Confirm receipt at the destination, then inspect its delivery and authentication results, particularly for mail forwarded to an external provider.
- Check unknown-recipient handling. If you use a catch-all, test an unlisted address and monitor the destination for unwanted mail and bounces.
What DNS does—and does not do
Forwarding is normally configured in the mail server’s recipient or mailbox delivery rules, not by changing a domain’s DNS records to name the final destination for each individual address. DNS still participates in mail routing, but a Postfix alias, local .forward, or Dovecot Sieve rule determines what your server does with mail after it reaches the relevant delivery path. The cited configuration guides describe those server-side mechanisms; they do not provide a universal DNS-only forwarding setup.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

