Commit e58a7dbc60

e58a7dbc60f638026785d5227d458d267328556e

parent: 2fd717ab1b

Verified · cmc ci/build: success ci/test: skipped

cmc <hello@cleberg.net> · 2026-09-29 15:02 UTC

wiki: mail.inbound notes from configuring gitbay.org

Ref #307

Layout: unified · split

.gitbay/wiki/Admin.org +16 −5
@@ -171,10 +171,16 @@ trusted_authserv_id = "mx.example.org" # the mail host's Authentication-Result
171171 one readable by group or others, stops the daemon at start.
172172- =reply_address= is what each Reply-To is built from:
173173 =reply@gitbay.example= becomes =reply+<token>@gitbay.example=. The
174 mailbox must receive that: give it a plus-addressing (subaddress)
175 mailbox, as most hosted mail does by default, or a catch-all for the
176 domain. Point the domain's MX at the mail host as for any other
177 mailbox; nothing about it involves gitbayd.
174 mailbox must receive that. Hosts that deliver subaddresses to the
175 mailbox need nothing more; others need a wildcard rule. Migadu, for
176 one, sent =threads+x@gitbay.org= nowhere until a rewrite from
177 =threads+*= to =threads@gitbay.org= was added. A domain catch-all only
178 works if it points at this mailbox, which then also holds everything
179 else sent to the domain. Send a test to =<reply_address>+test= and
180 expect a =refused mail reply= audit row with "malformed reply token"
181 within a poll interval (=gitbay audit --action 'refused mail'=). Point
182 the domain's MX at the mail host as for any other mailbox; nothing
183 about it involves gitbayd.
178184- Use a mailbox that holds nothing else. gitbayd reads every unseen
179185 message in it and marks each one =\Seen= when it is handled, posted
180186 or refused. A message that fails for a reason that may pass (the
@@ -201,7 +207,12 @@ trusted_authserv_id = "mx.example.org" # the mail host's Authentication-Result
201207 as RFC 8601 asks; Gmail, Fastmail and Migadu do. Check yours before
202208 relying on it. Unset, the daemon logs a warning at start and =admin
203209 mail inbound check= repeats it: without it, =From= is whatever the
204 sender wrote.
210 sender wrote. Mail between two addresses at the same host may carry
211 no =Authentication-Results= at all: at Migadu, mail from another
212 Migadu-hosted domain is delivered through its outbound path and gets
213 none, so setting the id refuses every reply from such users.
214 gitbay.org runs without it for that reason until gitbayd verifies
215 DKIM itself (#307).
205216- =gitbay admin mail inbound check= logs in, opens the mailbox
206217 read-only (EXAMINE) and reports the message and unseen counts, so a
207218 check never marks a reply seen before the poller reads it. With