How to secure mail server

Hii,

Disclaimer: I know there were similar threads on this topic as well. But I didn’t get satisfying response on them. So starting a new thread on this topic.

As a not so technical guy who is using hestiacp as control panel.

I always have a fear before going to sleep that a single hacked wordpress site could ruin my IP reputation and next day I could start getting calls of 100 clients for their mails not working.

Can anyone guide me step by step what measures could I take so that I can sleep peacefully? Also, how can I identify if any user account is sending a lot of emails continuously, that could help me to identify bot sending spams.

Please enlighten me on this topic. I have limited knowledge of emails and how they work. How can I properly monitor and run an email server successfully? If someone has some experience here, please feel free to suggest methods. I know people here would have been running mail servers from years and they would definitely have something to share with people who are going to start running mail server.

I would love to thank Marcus, Raphael, Sahsanu and many other fellows who have worked really hard on this project and made it easy for people like us to manage servers at no cost. Really guys, I appreciate your efforts and commitment to open source. You are doing a lot for open source community.

Thanks & Regards
Surya

On my part, install wordfence and keep wordpress and its plugins up to date, then all will be fine.

  • WAF for sites (eg. Wordfence)
  • Monitor mail queue (I use grafana which notifies me when Exim queue goes above a certain level)
  • Monitor blacklists (using something like hetrixtools or mxtoolbox)

Hii,

How do you setup grafana to monitor exim queue in HestaiCp? Could you please guide us?

Thanks