Skip to main content

OpenSMTPD

Outbound mail relay for environments not using a hosted provider

Outbound mail relay. Every site gets one, and it is what talks to the outside world, so an application only has to know where it is (SMTP_HOST — see Variables).

A Drupal site using settings.vallic.php is pointed at it already and needs nothing.

Two ports, two hops

Your site to the relay: port 25, inside the stack. That hop never leaves the environment's private network, and nothing blocks it.

The relay to the world: port 587, through your provider. Set a relay host and mail goes there over STARTTLS on 587 — the submission port every sending provider takes. Without one, the relay tries to deliver straight to each recipient's mail server, which is always port 25 — and outbound port 25 is blocked by default at most cloud providers, the ones this platform runs on included. Mail then waits in the queue and never arrives. Set a relay host for any environment that sends mail.

It is the better answer anyway. Sending straight from a cloud address is the thing most likely to put your mail in a spam folder — the address has no reputation and often sits in a range that has.

Relaying through your own provider

version: 1
type: drupal

services:
  - mariadb: '11.8'
  - opensmtpd:
      version: '7.8'
      environment:
        RELAY_HOST: smtp.sendgrid.net
        RELAY_PORT: '587'
        RELAY_USER: apikey

The password does not go here. Anything set on a service is written into the environment the platform renders, and that is stored where a task can be read from. Add RELAY_PASSWORD as a secret project variable instead: it is encrypted at rest, never shown again, and every container is given the whole environment — so the relay receives it without your manifest naming it.

That split is the general rule on this platform, not a quirk of mail: what is safe to read belongs in the repository, and what is not belongs in the console.

RELAY_PORT defaults to 587 and RELAY_PROTO to smtp+tls (STARTTLS), so for most providers RELAY_HOST and RELAY_USER are all there is to write.

Provider RELAY_HOST RELAY_USER RELAY_PASSWORD
SendGrid smtp.sendgrid.net apikey, literally An API key
Mailgun smtp.mailgun.org (smtp.eu.mailgun.org in the EU) The domain's SMTP login Its SMTP password
Postmark smtp.postmarkapp.com A server API token The same token
Amazon SES email-smtp.<region>.amazonaws.com SMTP credentials made in SES — not an IAM access key Their password
Brevo smtp-relay.brevo.com Your SMTP login An SMTP key
Mailjet in-v3.mailjet.com An API key Its secret key
MailerSend smtp.mailersend.net The domain's SMTP user Its password

Check the values against your provider's own page; these are where each publishes its relay today. A provider that offers only implicit TLS on 465 takes RELAY_PROTO: smtps and RELAY_PORT: '465'.

Deliverability is still yours

The relay sends what it is given. Whether it arrives depends on SPF, DKIM and DMARC records on the domain you send from, and those live in your DNS. A provider will tell you which records it needs; nothing here can publish them for you, because it is your domain.

Versions

Version Status
7.8 Supported, and the default
7.6 Deprecated — still runs, but move to something newer
7.5 Deprecated — still runs, but move to something newer

A deprecated version still runs and is still what some sites are on. It is listed so you can move before it goes, rather than finding out on the morning a build stops resolving it.

Pin the version, not the build: name 7.8 and the platform matches it to the current build, so a security rebuild reaches you without anybody editing a repository.

What you can change

In vallic.yaml — what each one does is on Service settings:

services:
  - opensmtpd:
      version: '7.8'
      environment:
        RELAY_HOST: …
        RELAY_PORT: …
        RELAY_PROTO: …
        RELAY_USER: …
        OPENSMTPD_MAX_MESSAGE_SIZE: …
        OPENSMTPD_EXPIRE: …
        OPENSMTPD_BOUNCE_WARN: …

Anything not on this list refuses the deploy, naming the variable — rather than being accepted and quietly ignored.