---
title: Charmhub | Deploy Postfix Relay using Charmhub - The Open Operator Collection
description: Deploy the latest version of Postfix Relay on any cloud.
url: https://charmhub.io/postfix-relay/configurations
---

# Postfix Relay

[Canonical IS DevOps](https://charmhub.io/publisher/canonical-is-devops "View all packages from Canonical IS DevOps")

* [Canonical IS DevOps](https://charmhub.io/publisher/canonical-is-devops "View all packages from Canonical IS DevOps")
* [Networking](https://charmhub.io/?filter=networking)

Platform:

24.04

22.04

20.04

18.04

16.04

14.04

3.8/edge 7ae33955

```
juju deploy postfix-relay --channel 3.8/edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [additional\_smtpd\_recipient\_restrictions](https://charmhub.io/postfix-relay/configurations#additional_smtpd_recipient_restrictions)
* [admin\_email](https://charmhub.io/postfix-relay/configurations#admin_email)
* [allowed\_relay\_networks](https://charmhub.io/postfix-relay/configurations#allowed_relay_networks)
* [append\_x\_envelope\_to](https://charmhub.io/postfix-relay/configurations#append_x_envelope_to)
* [connection\_limit](https://charmhub.io/postfix-relay/configurations#connection_limit)
* [domain](https://charmhub.io/postfix-relay/configurations#domain)
* [enable\_rate\_limits](https://charmhub.io/postfix-relay/configurations#enable_rate_limits)
* [enable\_reject\_unknown\_sender\_domain](https://charmhub.io/postfix-relay/configurations#enable_reject_unknown_sender_domain)
* [enable\_smtp\_auth](https://charmhub.io/postfix-relay/configurations#enable_smtp_auth)
* [enable\_spf](https://charmhub.io/postfix-relay/configurations#enable_spf)
* [header\_checks](https://charmhub.io/postfix-relay/configurations#header_checks)
* [relay\_domains](https://charmhub.io/postfix-relay/configurations#relay_domains)
* [relay\_host](https://charmhub.io/postfix-relay/configurations#relay_host)
* [restrict\_sender\_access](https://charmhub.io/postfix-relay/configurations#restrict_sender_access)
* [smtp\_auth\_users](https://charmhub.io/postfix-relay/configurations#smtp_auth_users)
* [smtp\_header\_checks](https://charmhub.io/postfix-relay/configurations#smtp_header_checks)
* [spf\_skip\_addresses](https://charmhub.io/postfix-relay/configurations#spf_skip_addresses)
* [tls\_ciphers](https://charmhub.io/postfix-relay/configurations#tls_ciphers)
* [tls\_exclude\_ciphers](https://charmhub.io/postfix-relay/configurations#tls_exclude_ciphers)
* [tls\_policy\_maps](https://charmhub.io/postfix-relay/configurations#tls_policy_maps)
* [tls\_protocols](https://charmhub.io/postfix-relay/configurations#tls_protocols)
* [tls\_security\_level](https://charmhub.io/postfix-relay/configurations#tls_security_level)
* [virtual\_alias\_domains](https://charmhub.io/postfix-relay/configurations#virtual_alias_domains)
* [virtual\_alias\_maps\_type](https://charmhub.io/postfix-relay/configurations#virtual_alias_maps_type)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* additional\_smtpd\_recipient\_restrictions | string

  YAML list of additional smtpd\_recipient\_restrictions.

  http://www.postfix.org/postconf.5.html#smtpd\_recipient\_restrictions
* admin\_email | string

  Administrator's email address where root@ emails will go.
* allowed\_relay\_networks | string

  YAML list of allowed networks to relay without authenticating.
* append\_x\_envelope\_to | boolean

  Configure Postfix to append X-Envelope-To header consisting of the
  email address of the recipient, per the envelope.

  This is useful to allow end users filter by destination when they
  receive emails for multiple individual or shared aliases.
* connection\_limit | int

  Default: 100

  Maximum number of simultaneous SMTP connections allowed.
* domain | string

  Primary domain for hostname generation, it will be
  $application-$unit.$domain. Set to '' to use the system FQDN.
* enable\_rate\_limits | boolean

  Enable various rate limiting features.

  smtpd\_client\_auth\_rate\_limit 8
  smtpd\_client\_connection\_rate\_limit 8
  smtpd\_client\_new\_tls\_session\_rate\_limit 8
* enable\_reject\_unknown\_sender\_domain | boolean

  Default: True

  Reject mail for when sender's domain cannot be resolved.

  http://www.postfix.org/postconf.5.html#reject\_unknown\_sender\_domain
* enable\_smtp\_auth | boolean

  Default: True

  Enable SMTP authentication.
* enable\_spf | boolean

  Enable SPF checking.
* header\_checks | string

  YAML list of header checks to perform on incoming emails and action on. See:

  http://www.postfix.org/header\_checks.5.html
* relay\_domains | string

  YAML list of destination domains this system will relay mail to.

  http://www.postfix.org/postconf.5.html#relay\_domains
* relay\_host | string

  SMTP relay host (or smart host) to forward mail to.
* restrict\_sender\_access | string

  YAML list of domains, addresses, or hosts senders to restrict relay from.
* smtp\_auth\_users | string

  YAML list of user and crypt password hashes (use mkpasswd to
  generate). e.g.

  myuser1:$1$bPb0IPiM$kmrSMZkZvICKKHXu66daQ.,myuser2:$6$3r//F36qLB/J8rUfIIndaDtkxeb5iR3gs1uBn9fNyJDD1
* smtp\_header\_checks | string

  YAML list of header checks for outgoing email to perform and action on. See:

  http://www.postfix.org/header\_checks.5.html

  NOTE: You almost always want to use `header_checks` instead of this.
* spf\_skip\_addresses | string

  YAML list of CIDR addresses to skip SPF checks (allowlist).
* tls\_ciphers | string

  Default: HIGH

  The minimum TLS cipher grade that the Postfix SMTP server will
  use with TLS encryption. Cipher types listed in
  smtpd\_tls\_exclude\_ciphers are excluded from the base definition
  of the selected cipher grade.

  This only applies to incoming connections to smtpd and not
  outbound to other MTAs as it may cause deliverability issues.

  http://www.postfix.org/postconf.5.html#smtpd\_tls\_ciphers
* tls\_exclude\_ciphers | string

  Default: - aNULL
  - eNULL
  - DES
  - 3DES
  - MD5
  - RC4
  - CAMELLIA

  YAML list of ciphers or cipher types to exclude from the SMTP server
  cipher list at all TLS security levels. Excluding valid ciphers
  can create interoperability problems. DO NOT exclude ciphers
  unless it is essential to do so.

  This only applies to incoming connections to smtpd and not
  outbound to other MTAs as it may cause deliverability issues.

  http://www.postfix.org/postconf.5.html#smtpd\_tls\_exclude\_ciphers
* tls\_policy\_maps | string

  YAML map of free-form TLS policy map per:

  http://www.postfix.org/postconf.5.html#smtp\_tls\_policy\_maps
* tls\_protocols | string

  Default: - '!SSLv2'
  - '!SSLv3'

  YAML list of TLS protocols accepted by the Postfix SMTP server with TLS
  encryption. If the list is empty, the server supports all
  available TLS protocol versions. A non-empty value is a list of
  protocol names to include or exclude, separated by whitespace,
  commas or colons.

  This only applies to incoming connections to smtpd and not
  outbound to other MTAs as it may cause deliverability issues.

  http://www.postfix.org/postconf.5.html#smtpd\_tls\_protocols
* tls\_security\_level | string

  Default: may

  The SMTP TLS security level for the Postfix SMTP server; when a
  non-empty value is specified, this overrides the obsolete
  parameters smtpd\_use\_tls and smtpd\_enforce\_tls.

  This only applies to incoming connections to smtpd and not
  outbound to other MTAs as it may cause deliverability issues.

  http://www.postfix.org/postconf.5.html#smtpd\_tls\_security\_level
* virtual\_alias\_domains | string

  YAML list of domains for which all addresses are aliased to
  addresses in other local or remote domains.

  http://www.postfix.org/postconf.5.html#virtual\_alias\_domains
* virtual\_alias\_maps\_type | string

  Default: hash

  Specify the map type used for virtual aliases.

  https://www.postfix.org/DATABASE\_README.html#types
