Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A working Mailcow server is a full groupware stack, not a lightweight mail relay. It runs in Docker on a dedicated virtual machine, answers on a public mail hostname, publishes the DNS records that receiving servers check, and has a backup and update routine in place before real mail arrives. Getting there takes four stages: prepare a host that Mailcow supports, install Docker and start the stack, publish and verify DNS and authentication records, and then set up backups and a stable update path. Running your own mail also means ongoing work on DNS, sending reputation, updates, and recovery, and this guide covers that work alongside the install.

Before you start: what a Mailcow host must provide

Mailcow bundles webmail, IMAP and POP3 access, SMTP submission, spam and virus filtering, and other groupware components into one Docker-based deployment. Its official minimum is modest for a stack of that size, but it is a floor, not a comfortable target. The figures below come from Mailcow’s own prerequisite page and its examples, not from an independent benchmark.

Scenario CPU Memory Disk Source and qualification
Official minimum 1 GHz 6 GiB RAM plus 1 GiB swap 20 GiB before email storage Mailcow prerequisite page; x86_64 or ARM64
Small example (about 5 to 10 users) Not stated 8 GiB recommended Not stated Mailcow example in its prerequisite documentation
Company example (15 phones, about 50 concurrent IMAP connections) Not stated 16 GiB recommended Not stated Mailcow example in its prerequisite documentation

Mail volume, the number of mailboxes, and enabled features all push memory use upward. Antivirus scanning and full-text search are the two components most likely to consume memory beyond the floor, so size above the minimum wherever your budget allows. Storage needs depend on how much mail each user keeps, so plan the disk separately from the 20 GiB system figure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a host that Mailcow supports

Virtualization type

Mailcow runs on Docker, but Docker alone does not make a platform suitable. The documentation names KVM, ESX, and Hyper-V full virtualization as supported. It warns against Synology and QNAP NAS devices, OpenVZ, LXC, and other container-based platforms. A container host can look cheaper on paper, but it is outside what Mailcow documents as a supported environment, so treat it as a non-starter for a production mail server.

Operating system

The supported operating system table on the Mailcow prerequisite page is labelled “as of August 2025.” Check the current page before you build the machine, because the list can change.

Operating system Status in the reviewed documentation
Debian 11 to 13 Supported
Ubuntu 22.04 or newer Supported
AlmaLinux 8 and 9 Supported
Rocky Linux 9 Supported
Alpine Linux 3.19 or newer Supported with manual adjustments

Ports, egress, and reverse DNS

Mailcow needs its service ports free on the host and reachable from the internet. Before you order a server, confirm three things with your provider: that inbound mail ports are not blocked, that outbound port 25 is permitted (many providers restrict it by default), and that you can set the reverse DNS (PTR) record for the server’s IP address. Not every hosting provider allows mail traffic, so check the policy rather than assuming it.

Service Ports
SMTP 25
SMTPS 465
Submission 587
IMAP 143 and 993
POP3 110 and 995
ManageSieve 4190
Web (HTTP and HTTPS) 80 and 443

The host also needs correct time synchronization. Mailcow’s documentation lists the full prerequisites on its Prepare your system page, and that page is the reference to check against your provider’s live policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure DNS before you install

Mailcow’s own documentation puts it plainly: “A correct DNS setup is crucial to every good mailserver setup, so please make sure you got at least the basics covered before you begin!” Set up the records below before the first start, or at least before you test delivery. The DNS setup page is the reference for the exact records.

Mail hostname and A record

Choose a stable fully qualified hostname for the server, for example mail.example.org, and create an A record pointing it at the server’s IP address. This hostname is also what you use to reach the web interface, so it must be the name the browser opens.

Rank #2
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform

MX, autodiscover, and autoconfig

Point the domain’s MX record at the mail hostname so inbound mail for the domain is routed to the server. Mailcow’s example also includes autodiscover and autoconfig CNAME records, which let mail clients find the server settings without manual entry. Each hosted domain needs its own relevant records, so repeat this for every domain you add.

Reverse DNS (PTR)

Set the server IP’s PTR record to match the Mailcow hostname, the value of MAILCOW_HOSTNAME in your configuration. Your server provider usually controls PTR records, while your domain’s DNS host controls the zone records. A mismatch here is one of the most common reasons outgoing mail is rejected or flagged.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SPF, DKIM, and DMARC

  • SPF lists the servers allowed to send mail for the domain. It must include every service that sends mail as that domain, not just Mailcow. If the mail server is the only sender, a minimal record is v=spf1 mx -all, but add any other senders before you use it.
  • DKIM is a signing key. Generate it in Mailcow’s configuration, then publish the matching public key as a TXT record at the selector name Mailcow gives you.
  • DMARC is a TXT record at _dmarc under your domain that states how receivers should handle mail failing SPF or DKIM. A monitoring-only starting point is v=DMARC1; p=none; rua=mailto:postmaster@example.org, and you can tighten the policy once reports show that legitimate mail passes.

Treat the strings above as starting points. Mailcow’s documentation labels its own SPF and DMARC values as examples, and the correct policy depends on every service that sends mail for your domain.

Certificates: HTTP-01 or DNS-01

Mailcow obtains TLS certificates through ACME. The default HTTP-01 method works when port 80 is reachable from the internet. If you need DNS-01 validation instead, your DNS provider must be supported by acme.sh, and you must configure its API credentials in the DNS challenge configuration. DNS-01 applies to every domain in the installation, and the two methods cannot be mixed. Confirm the current provider list and the setup steps on the SSL with DNS Challenge page before you commit to a DNS host.

Install Mailcow with Docker

The current Install mailcow page requires Git, OpenSSL, curl, awk, sha1sum, grep, cut, and jq (jq was added to the requirements in September 2025), along with Docker Engine 24.0 or later and Docker Compose 2.0 or later.

Install and check Docker

Install Docker Engine from Docker’s current packages rather than relying on the convenience script, which the Mailcow page says is unreliable on RHEL and Alpine. On Debian and Ubuntu, install the Compose plugin package. With the plugin, the command is docker compose, without a hyphen. Confirm both versions before you continue:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
docker --version
docker compose version

The output should show Docker Engine 24.0 or later and Compose 2.0 or later.

Run the installation

  1. Change to the directory where the project will live. Mailcow’s examples use /opt:
    cd /opt
  2. Clone the project repository:
    git clone https://github.com/mailcow/mailcow-dockerized
  3. Enter the project directory:
    cd mailcow-dockerized
  4. Generate the configuration. The script prompts for your mail hostname, so enter the FQDN you configured in DNS:
    ./generate_config.sh
  5. Open mailcow.conf and review it before starting. Confirm MAILCOW_HOSTNAME and the timezone setting, and any other deployment-specific values.
  6. Pull the container images:
    docker compose pull
  7. Start the stack in the background:
    docker compose up -d

    The first start takes a while because Mailcow initializes its containers, volumes, and certificates. Check progress with docker compose ps and wait until the services report as running or healthy.

First login

Open https://mail.example.org/admin using your own hostname. The installation page documents a default administrator login, admin with the password moohoo, at the time it was reviewed. Change that password as the first task after logging in, and check the installation page for the current default, since credential guidance can change.

Verify delivery and authentication

Once the stack is running, confirm that each record resolves as you intended, then test in both directions:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Mymazn Black Server Books for Waitress Book Waiter Book Server Booklet Restaurant Waitstaff Organizer, Serving Book Guest Check Book Holder Money Pocket Fits Server Apron (Black)
  • Compact Size: Measuring 4.7 x 7.6 inches, this server book is slim, lightweight, and fits effortlessly into your apron pocket. It's designed to hold a standard guest check book (not included), making it an ideal tool for busy waitstaff.
  • Ample Storage and Functionality: Featuring 7 pockets and compartments, this server book provides plenty of space to keep all your essentials organized. The tiny front pocket is perfect for holding guest credit cards, while see-through pockets on both sides offer quick access to reference lists. Plus, it even holds a pen when closed without adding bulk.
  • Premium Material with a Stylish Touch: Crafted from high-quality PU faux leather with classic solid black, this server book feels luxurious in your hand. It’s waterproof exterior and interior are resistant to water, scratches, punctures, and heat, ensuring durability and easy cleaning.
  • Professional Appearance: The smooth, rich black finish and meticulously crafted seams and stitching give this server book a polished, professional look, making it a reliable companion for any server.
  • Durable and Easy to Clean: Designed to withstand the demands of the job, this server book is built to last. The waterproof material not only protects against spills and stains but also wipes clean easily, maintaining its pristine appearance even with regular use.
  • Check the A record for the mail hostname, the MX record for the domain, the PTR record for the server IP, and the SPF, DKIM, and DMARC TXT records.
  • Send a message from a mailbox on the server to an external address, and another from the external address back to the server.
  • Inspect the message headers for SPF, DKIM, and DMARC results. A pass on all three is the outcome you want.
  • If delivery fails, check the Mailcow logs first, then your provider’s port 25 and reverse DNS restrictions.

The Mailcow DNS page links several third-party DNS and email-authentication checkers. These are diagnostics. They show whether your records are published correctly, but they do not guarantee inbox placement, which depends on recipient filtering and the reputation of the sending IP.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Back up before you go live

Mailcow strongly recommends regular backups, and exporting them off the host. A backup that lives only on the same server is lost along with the server. The Export page describes the options.

What must be in the backup

Mailcow stores mail and related state in Docker volumes. Mail is compressed and encrypted, and the key pair lives in the crypt-vol-1 volume. A backup of the mail data without the key material cannot be decrypted, so the crypt volume is not optional. Include all volumes the stack needs, not just the mailbox store.

Backup tools

  • Built-in backup and restore script: the Mailcow project ships a script for backing up and restoring its volumes.
  • Borgmatic: the Mailcow documentation also describes Borgmatic as a backup option.
  • Export extension (community-developed): a community extension sends backups to WebDAV, FTP or SFTP, NAS, or S3-compatible targets. It is not an official Mailcow component, so verify it against your own restore tests.

For offsite copies, use encryption and a secure transfer method. Compare destinations on encryption, transfer security, retention, restoration access, and how well each fits your backup workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test the restore

A completed backup job does not prove anything. Restore into a separate VM at least once, confirm that mailboxes open and that mail can be read and sent, and write the procedure down while you have the steps fresh. The first real restore should not be the first time you have tried it.

Update on the stable track

The Update page documents ./update.sh as the update entry point, run from the project directory. Production installations should stay on the stable branch, which the documentation describes as suitable for production use and updated at least monthly.

The nightly branch is for testing only. Mailcow recommends running it on a separate VM or machine, not on the production server, and taking a backup before switching to it. Do not treat nightly as an ordinary update path.

Mailcow’s documentation states that legacy support ended in February 2026. Do not run the legacy branch on a production server, and move any legacy installation to a supported track before you rely on it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ongoing maintenance checklist

  • Apply stable Mailcow updates at least monthly, after a fresh backup.
  • Keep the host operating system patched and the time synchronized.
  • Check that SPF, DKIM, and DMARC still cover every service that sends mail for the domain, and review DMARC reports if you publish them.
  • Renew and watch certificates, and confirm the renewal method still works if your DNS provider or credentials change.
  • Test a restore on a schedule, not only after a failure.
  • Monitor sending reputation and the server’s presence on blocklists.

Self-run or managed: how to decide

Running Mailcow yourself gives you full control of configuration and data, but you own the operating system, updates, backups, restores, and any port or PTR issue with the provider. The Mailcow documentation describes two support routes: community support, which it describes as best-effort, and commercial support subscriptions from Servercow, plus a fully managed Mailcow service. The documentation does not publish pricing or service-level terms, so compare those directly with the vendor. The comparison points that matter are who handles operating system and Mailcow updates, who controls PTR and ports, who owns backups and restore responsibility, and how much administration time you can realistically commit.

If you start self-run, keep the stable update track and the restore test on your calendar from the first day. That routine matters more than any single setup step.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.