OpenSMTPD
Outbound mail relay for environments not using a hosted provider
Outbound mail relay. Every site gets one, and it is what talks to the
outside world, so an application only has to know where it is
(SMTP_HOST — see Variables).
A Drupal site using settings.vallic.php is pointed at
it already and needs nothing.
Two ports, two hops
Your site to the relay: port 25, inside the stack. That hop never leaves the environment's private network, and nothing blocks it.
The relay to the world: port 587, through your provider. Set a relay host and mail goes there over STARTTLS on 587 — the submission port every sending provider takes. Without one, the relay tries to deliver straight to each recipient's mail server, which is always port 25 — and outbound port 25 is blocked by default at most cloud providers, the ones this platform runs on included. Mail then waits in the queue and never arrives. Set a relay host for any environment that sends mail.
It is the better answer anyway. Sending straight from a cloud address is the thing most likely to put your mail in a spam folder — the address has no reputation and often sits in a range that has.
Relaying through your own provider
version: 1
type: drupal
services:
- mariadb: '11.8'
- opensmtpd:
version: '7.8'
environment:
RELAY_HOST: smtp.sendgrid.net
RELAY_PORT: '587'
RELAY_USER: apikey
The password does not go here. Anything set on a service is written into
the environment the platform renders, and that is stored where a task can be
read from. Add RELAY_PASSWORD as a secret project variable instead: it is
encrypted at rest, never shown again, and every container is given the whole
environment — so the relay receives it without your manifest naming it.
That split is the general rule on this platform, not a quirk of mail: what is safe to read belongs in the repository, and what is not belongs in the console.
RELAY_PORT defaults to 587 and RELAY_PROTO to smtp+tls (STARTTLS), so
for most providers RELAY_HOST and RELAY_USER are all there is to write.
| Provider | RELAY_HOST |
RELAY_USER |
RELAY_PASSWORD |
|---|---|---|---|
| SendGrid | smtp.sendgrid.net |
apikey, literally |
An API key |
| Mailgun | smtp.mailgun.org (smtp.eu.mailgun.org in the EU) |
The domain's SMTP login | Its SMTP password |
| Postmark | smtp.postmarkapp.com |
A server API token | The same token |
| Amazon SES | email-smtp.<region>.amazonaws.com |
SMTP credentials made in SES — not an IAM access key | Their password |
| Brevo | smtp-relay.brevo.com |
Your SMTP login | An SMTP key |
| Mailjet | in-v3.mailjet.com |
An API key | Its secret key |
| MailerSend | smtp.mailersend.net |
The domain's SMTP user | Its password |
Check the values against your provider's own page; these are where each
publishes its relay today. A provider that offers only implicit TLS on 465
takes RELAY_PROTO: smtps and RELAY_PORT: '465'.
Deliverability is still yours
The relay sends what it is given. Whether it arrives depends on SPF, DKIM and DMARC records on the domain you send from, and those live in your DNS. A provider will tell you which records it needs; nothing here can publish them for you, because it is your domain.
Versions
| Version | Status |
|---|---|
7.8 |
Supported, and the default |
7.6 |
Deprecated — still runs, but move to something newer |
7.5 |
Deprecated — still runs, but move to something newer |
A deprecated version still runs and is still what some sites are on. It is listed so you can move before it goes, rather than finding out on the morning a build stops resolving it.
Pin the version, not the build: name 7.8 and the platform matches it to the
current build, so a security rebuild reaches you without anybody editing a
repository.
What you can change
In vallic.yaml — what each one does is on Service settings:
services:
- opensmtpd:
version: '7.8'
environment:
RELAY_HOST: …
RELAY_PORT: …
RELAY_PROTO: …
RELAY_USER: …
OPENSMTPD_MAX_MESSAGE_SIZE: …
OPENSMTPD_EXPIRE: …
OPENSMTPD_BOUNCE_WARN: …
Anything not on this list refuses the deploy, naming the variable — rather than being accepted and quietly ignored.