Commit e58a7dbc60

e58a7dbc60f638026785d5227d458d267328556e

parent: 2fd717ab1b

Verified · cmc ci/build: success ci/test: skipped

cmc <hello@cleberg.net> · 2026-09-29 15:02 UTC

wiki: mail.inbound notes from configuring gitbay.org

Ref #307

Layout: unified · split

.gitbay/wiki/Admin.org +16 −5
@@ -171,10 +171,16 @@ trusted_authserv_id = "mx.example.org" # the mail host's Authentication-Result
171 one readable by group or others, stops the daemon at start. 171 one readable by group or others, stops the daemon at start.
172- =reply_address= is what each Reply-To is built from: 172- =reply_address= is what each Reply-To is built from:
173 =reply@gitbay.example= becomes =reply+<token>@gitbay.example=. The 173 =reply@gitbay.example= becomes =reply+<token>@gitbay.example=. The
174 mailbox must receive that: give it a plus-addressing (subaddress) 174 mailbox must receive that. Hosts that deliver subaddresses to the
175 mailbox, as most hosted mail does by default, or a catch-all for the 175 mailbox need nothing more; others need a wildcard rule. Migadu, for
176 domain. Point the domain's MX at the mail host as for any other 176 one, sent =threads+x@gitbay.org= nowhere until a rewrite from
177 mailbox; nothing about it involves gitbayd. 177 =threads+*= to =threads@gitbay.org= was added. A domain catch-all only
178 works if it points at this mailbox, which then also holds everything
179 else sent to the domain. Send a test to =<reply_address>+test= and
180 expect a =refused mail reply= audit row with "malformed reply token"
181 within a poll interval (=gitbay audit --action 'refused mail'=). Point
182 the domain's MX at the mail host as for any other mailbox; nothing
183 about it involves gitbayd.
178- Use a mailbox that holds nothing else. gitbayd reads every unseen 184- Use a mailbox that holds nothing else. gitbayd reads every unseen
179 message in it and marks each one =\Seen= when it is handled, posted 185 message in it and marks each one =\Seen= when it is handled, posted
180 or refused. A message that fails for a reason that may pass (the 186 or refused. A message that fails for a reason that may pass (the
@@ -201,7 +207,12 @@ trusted_authserv_id = "mx.example.org" # the mail host's Authentication-Result
201 as RFC 8601 asks; Gmail, Fastmail and Migadu do. Check yours before 207 as RFC 8601 asks; Gmail, Fastmail and Migadu do. Check yours before
202 relying on it. Unset, the daemon logs a warning at start and =admin 208 relying on it. Unset, the daemon logs a warning at start and =admin
203 mail inbound check= repeats it: without it, =From= is whatever the 209 mail inbound check= repeats it: without it, =From= is whatever the
204 sender wrote. 210 sender wrote. Mail between two addresses at the same host may carry
211 no =Authentication-Results= at all: at Migadu, mail from another
212 Migadu-hosted domain is delivered through its outbound path and gets
213 none, so setting the id refuses every reply from such users.
214 gitbay.org runs without it for that reason until gitbayd verifies
215 DKIM itself (#307).
205- =gitbay admin mail inbound check= logs in, opens the mailbox 216- =gitbay admin mail inbound check= logs in, opens the mailbox
206 read-only (EXAMINE) and reports the message and unseen counts, so a 217 read-only (EXAMINE) and reports the message and unseen counts, so a
207 check never marks a reply seen before the poller reads it. With 218 check never marks a reply seen before the poller reads it. With