# Mail-in-a-Box: a one-click mail server for Ubuntu 22.04, and what it refuses to be

> Mail-in-a-Box turns a fresh Ubuntu 22.04 LTS machine into a complete mail stack with one script. It is deliberately not configurable, which is the strongest thing about it and the reason some teams should walk away.

**mail-in-a-box/mailinabox** — Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server in a box.

- Repository: https://github.com/mail-in-a-box/mailinabox
- Website: https://mailinabox.email/
- Stars: 15,421 · Forks: 1,548
- Language: Python
- License: CC0-1.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/mail-in-a-box-mailinabox

## The problem Mail-in-a-Box solves, and who it is actually for

Running your own mail server is not one installation. It is Postfix, Dovecot, a webmail client, a spam filter, a greylister, an authoritative DNS server, DKIM signing, TLS certificates that renew, a firewall, and a backup job. Each has its own configuration format, and each has to agree with the others about hostnames, certificates and ports. Mail-in-a-Box exists to collapse that list into one script.

The README states the goals plainly: make deploying a good mail server easy, and explicitly not make something customizable by power users. That second goal is the design. The README says the project is a one-click email appliance with no user-configurable setup options, and that it just works. If you are the kind of operator who wants to choose a different IMAP server or swap out the DNS daemon, this is the wrong project, and the README says so before you install anything.

The audience is an individual or a small organization with a domain, a fresh 64-bit Ubuntu 22.04 LTS machine, and no interest in maintaining a mail stack by hand. The README also notes that internationalized domain names are supported, while SMTPUTF8 is not.

## What the installer actually puts on the machine

The box is a bundle, not a single daemon. According to the README, the components installed are SMTP through postfix, IMAP through Dovecot, CardDAV and CalDAV through Nextcloud, and Exchange ActiveSync through z-push. Webmail is Roundcube, with mail filter rules handled by Roundcube and Dovecot, and email client autoconfig served by nginx.

Spam filtering is spamassassin and greylisting is postgrey. DNS is nsd4, and the box writes SPF, DKIM through OpenDKIM, DMARC, DNSSEC, DANE TLSA, MTA-STS and SSHFP policy records automatically. TLS certificates come from Let's Encrypt and cover https and the other services. Backups use duplicity, the firewall is ufw, intrusion protection is fail2ban, and basic monitoring is munin.

On top of that sit the management tools: a daily health check that verifies services are running, ports are open, certificates are valid and DNS records are correct, plus a control panel for adding and removing mail users, aliases and custom DNS records, configuring backups, and an API for all of the actions on the control panel. The repository layout reflects this split: api/, conf/, management/, setup/ and tests/ at the top level.

## Installing Mail-in-a-Box on a fresh Ubuntu 22.04 LTS machine

The README points to the setup guide at mailinabox.email for user-friendly instructions and gives the expert path directly. The requirement is a completely fresh Ubuntu 22.04 LTS 64-bit machine, and the README repeats the word fresh for emphasis. Clone the repository and check out the tag for the most recent release, which the README says you can find in the tags or releases lists on GitHub.

```bash
git clone https://github.com/mail-in-a-box/mailinabox
cd mailinabox
git checkout TAGNAME
```

Replace TAGNAME with the release tag you selected. After that, the installation itself is one command, run with sudo:

```bash
sudo setup/start.sh
```

The README states that the installation will install, uninstall and configure packages to turn the machine into a working mail server. Expect it to modify the system broadly rather than drop a single service into place. Once it finishes, the control panel is where you add mail users, aliases and custom DNS records, and the same actions are available through the API.

For help, the README is direct: do not contact the maintainer by email or tweet, with no exceptions. Questions go to the discussion forum at discourse.mailinabox.email.

## The limitation the README admits: you do not control the rest of the Internet

The README is unusually honest here. It says that while the project wants everything to just work, it cannot control the rest of the Internet, and that other mail services might block or spam-filter email sent from your Mail-in-a-Box. It calls this a challenge faced by everyone who runs their own mail server, with or without Mail-in-a-Box. That is the correct framing, and it means a successful install is not the same as deliverable mail.

The harder constraint is the appliance model itself. There are no user-configurable setup options, by design. If your host already runs a web application, or if you need to tune Postfix policy per domain, or if you want a mail server alongside other workloads on the same machine, Mail-in-a-Box is the wrong tool. It expects to own the box.

SMTPUTF8 is another stated gap. The README says internationalized domain names are supported and configured easily, but SMTPUTF8 is not supported. If your users need internationalized local parts in addresses, that limitation is on the README, not on your configuration.

The README does not document rollback. There is no described uninstall path, and setup/start.sh is described as installing and uninstalling packages as it goes. Treat the machine as disposable before you begin.

## Mail-in-a-Box compared with iRedMail and Modoboa

The README names its own neighbours: Mail-in-a-Box is similar to iRedMail and Modoboa. The difference is in the degree of control each one hands back to the operator. Mail-in-a-Box is the appliance: one script, no setup options, a fixed component list, and a control panel and API for the day-to-day actions. iRedMail and Modoboa are the other end of that trade, aimed at administrators who want to assemble and tune the stack rather than accept a fixed one.

That distinction matters more than any feature list. With Mail-in-a-Box you get a known-good combination of postfix, Dovecot, Nextcloud, z-push, Roundcube, spamassassin, postgrey, nsd4, OpenDKIM, nginx, duplicity, ufw, fail2ban and munin, wired together and checked daily. You give up the ability to swap any of them out without leaving the supported path.

The README also credits the project's lineage: it was inspired in part by Drew Crawford's NSA-proof your email in 2 hours blog post and by Sovereign by Alex Payne. It states outright that the goal is not a totally unhackable, NSA-proof server. Anyone choosing this for a threat model that requires hardening beyond a standard mail stack should read that sentence twice.

## Maintenance, upgrades and the licence

The repository is not archived, and the last push was on 2026-09-01. The most recent releases are v76 on 2026-05-24, v75 on 2026-04-20 and v74 on 2026-01-04. That cadence is visible in the releases list, and it is the thing to check before you commit to a long-lived deployment: the upgrade path you will actually use is the one between these tags.

The README does not describe an upgrade procedure. It describes installation from a fresh machine and checkout of a release tag. The related search phrase mailinabox upgrade points at a question the README does not answer, so verify the current guidance on the project site before assuming an in-place upgrade is supported.

The project is licensed CC0-1.0, which is a public domain dedication rather than a permissive software licence like MIT or Apache-2.0. That is unusual for a server stack and worth noting if your organization has a policy about which licence identifiers are acceptable. This is not legal advice; check what CC0-1.0 means for your own distribution and modification plans.

Operationally, the box includes duplicity for backups, ufw for the firewall, fail2ban for intrusion protection and munin for monitoring, and the daily health check verifies services, ports, certificates and DNS records. Those are the maintenance surfaces the project gives you.

## Conclusion

Adopt Mail-in-a-Box if you want a single-domain or small multi-domain mail server on a fresh Ubuntu 22.04 LTS machine and you accept that the box owns the whole system. Do not adopt it if you need SMTPUTF8, per-service tuning, or a host that already runs other workloads. Before installing, confirm the machine is genuinely clean, that you have the release tag from the tags or releases list, and that you can rebuild the host from scratch if setup/start.sh fails partway.

## FAQ

### What is Mail-in-a-Box?

It is a one-click email appliance that turns a fresh Ubuntu 22.04 LTS 64-bit machine into a working mail server, installing and configuring SMTP, IMAP, webmail, spam filtering, DNS and TLS certificates. The README describes it as a mail server in a box with no user-configurable setup options.

### How do I install Mail-in-a-Box?

Start with a completely fresh Ubuntu 22.04 LTS 64-bit machine, clone the repository, check out the tag for the most recent release, and run sudo setup/start.sh. The README points to the setup guide at mailinabox.email for detailed instructions.

### How does Mail-in-a-Box compare with iRedMail?

The README states that Mail-in-a-Box is similar to iRedMail and Modoboa. The distinction it draws is its own appliance model: a fixed component list with no user-configurable setup options, rather than a stack an administrator assembles and tunes.

### How does Mail-in-a-Box compare with Modoboa?

The README lists Modoboa alongside iRedMail as a similar project. Mail-in-a-Box differs in that it installs and configures a fixed set of components from one script, while the README describes its own model as an appliance with no user-configurable setup options.

### How does Mail-in-a-Box compare with Stalwart?

The README does not mention Stalwart, so no comparison can be made from the project's own documentation. The README only names iRedMail and Modoboa as similar projects.

### How does Mail-in-a-Box compare with Postfix?

Postfix is one of the components Mail-in-a-Box installs and configures, not an alternative to it. The README lists postfix as the SMTP server inside the box, alongside Dovecot for IMAP and the other bundled services.

## Sources

- [License: CC0-1.0](https://github.com/mail-in-a-box/mailinabox/blob/main/LICENSE)
- [mail-in-a-box/mailinabox on GitHub](https://github.com/mail-in-a-box/mailinabox)
- [Project website](https://mailinabox.email/)
- [README](https://github.com/mail-in-a-box/mailinabox/blob/main/README.md)
- [Releases](https://github.com/mail-in-a-box/mailinabox/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/mail-in-a-box-mailinabox
