Platform:

Ubuntu
24.04 22.04 20.04 18.04 16.04 14.04
Channel Revision Published Runs on
latest/stable 11 01 Nov 2023
Ubuntu 22.04 Ubuntu 20.04 Ubuntu 18.04 Ubuntu 16.04 Ubuntu 14.04
latest/stable 0 01 Feb 2021
Ubuntu 22.04 Ubuntu 20.04 Ubuntu 18.04 Ubuntu 16.04 Ubuntu 14.04
latest/candidate 11 18 Oct 2023
Ubuntu 22.04 Ubuntu 20.04 Ubuntu 18.04 Ubuntu 16.04 Ubuntu 14.04
latest/candidate 0 25 Apr 2022
Ubuntu 22.04 Ubuntu 20.04 Ubuntu 18.04 Ubuntu 16.04 Ubuntu 14.04
latest/edge 13 08 Oct 2025
Ubuntu 24.04 Ubuntu 22.04 Ubuntu 20.04 Ubuntu 18.04
latest/edge 12 20 Jun 2025
Ubuntu 24.04 Ubuntu 22.04 Ubuntu 20.04 Ubuntu 18.04
3.8/edge 24 29 Sep 2026
Ubuntu 24.04
juju deploy postfix-relay --channel 3.8/edge

Learn about configurations >

  • additional_smtpd_recipient_restrictions | string

    YAML list of additional smtpd_recipient_restrictions.

    http://www.postfix.org/postconf.5.html#smtpd_recipient_restrictions

  • admin_email | string

    Administrator's email address where root@ emails will go.

  • allowed_relay_networks | string

    YAML list of allowed networks to relay without authenticating.

  • append_x_envelope_to | boolean

    Configure Postfix to append X-Envelope-To header consisting of the email address of the recipient, per the envelope.

    This is useful to allow end users filter by destination when they receive emails for multiple individual or shared aliases.

  • connection_limit | int

    Default: 100

    Maximum number of simultaneous SMTP connections allowed.

  • domain | string

    Primary domain for hostname generation, it will be $application-$unit.$domain. Set to '' to use the system FQDN.

  • enable_rate_limits | boolean

    Enable various rate limiting features.

    smtpd_client_auth_rate_limit 8 smtpd_client_connection_rate_limit 8 smtpd_client_new_tls_session_rate_limit 8

  • enable_reject_unknown_sender_domain | boolean

    Default: True

    Reject mail for when sender's domain cannot be resolved.

    http://www.postfix.org/postconf.5.html#reject_unknown_sender_domain

  • enable_smtp_auth | boolean

    Default: True

    Enable SMTP authentication.

  • enable_spf | boolean

    Enable SPF checking.

  • header_checks | string

    YAML list of header checks to perform on incoming emails and action on. See:

    http://www.postfix.org/header_checks.5.html

  • relay_domains | string

    YAML list of destination domains this system will relay mail to.

    http://www.postfix.org/postconf.5.html#relay_domains

  • relay_host | string

    SMTP relay host (or smart host) to forward mail to.

  • restrict_sender_access | string

    YAML list of domains, addresses, or hosts senders to restrict relay from.

  • smtp_auth_users | string

    YAML list of user and crypt password hashes (use mkpasswd to generate). e.g.

    myuser1:$1$bPb0IPiM$kmrSMZkZvICKKHXu66daQ.,myuser2:$6$3r//F36qLB/J8rUfIIndaDtkxeb5iR3gs1uBn9fNyJDD1

  • smtp_header_checks | string

    YAML list of header checks for outgoing email to perform and action on. See:

    http://www.postfix.org/header_checks.5.html

    NOTE: You almost always want to use header_checks instead of this.

  • spf_skip_addresses | string

    YAML list of CIDR addresses to skip SPF checks (allowlist).

  • tls_ciphers | string

    Default: HIGH

    The minimum TLS cipher grade that the Postfix SMTP server will use with TLS encryption. Cipher types listed in smtpd_tls_exclude_ciphers are excluded from the base definition of the selected cipher grade.

    This only applies to incoming connections to smtpd and not outbound to other MTAs as it may cause deliverability issues.

    http://www.postfix.org/postconf.5.html#smtpd_tls_ciphers

  • tls_exclude_ciphers | string

    Default: - aNULL - eNULL - DES - 3DES - MD5 - RC4 - CAMELLIA

    YAML list of ciphers or cipher types to exclude from the SMTP server cipher list at all TLS security levels. Excluding valid ciphers can create interoperability problems. DO NOT exclude ciphers unless it is essential to do so.

    This only applies to incoming connections to smtpd and not outbound to other MTAs as it may cause deliverability issues.

    http://www.postfix.org/postconf.5.html#smtpd_tls_exclude_ciphers

  • tls_policy_maps | string

    YAML map of free-form TLS policy map per:

    http://www.postfix.org/postconf.5.html#smtp_tls_policy_maps

  • tls_protocols | string

    Default: - '!SSLv2' - '!SSLv3'

    YAML list of TLS protocols accepted by the Postfix SMTP server with TLS encryption. If the list is empty, the server supports all available TLS protocol versions. A non-empty value is a list of protocol names to include or exclude, separated by whitespace, commas or colons.

    This only applies to incoming connections to smtpd and not outbound to other MTAs as it may cause deliverability issues.

    http://www.postfix.org/postconf.5.html#smtpd_tls_protocols

  • tls_security_level | string

    Default: may

    The SMTP TLS security level for the Postfix SMTP server; when a non-empty value is specified, this overrides the obsolete parameters smtpd_use_tls and smtpd_enforce_tls.

    This only applies to incoming connections to smtpd and not outbound to other MTAs as it may cause deliverability issues.

    http://www.postfix.org/postconf.5.html#smtpd_tls_security_level

  • virtual_alias_domains | string

    YAML list of domains for which all addresses are aliased to addresses in other local or remote domains.

    http://www.postfix.org/postconf.5.html#virtual_alias_domains

  • virtual_alias_maps_type | string

    Default: hash

    Specify the map type used for virtual aliases.

    https://www.postfix.org/DATABASE_README.html#types