[{"data":1,"prerenderedAt":649},["ShallowReactive",2],{"search-en":3,"content-en-guide\u002Fsending-from-a-vps":4,"surround-en-\u002Fguide\u002Fsending-from-a-vps":640},[],{"id":5,"title":6,"body":7,"description":632,"extension":633,"meta":634,"navigation":635,"path":636,"seo":637,"stem":638,"__hash__":639},"content_en\u002F1.guide\u002F51.sending-from-a-vps.md","Sending from a VPS",{"type":8,"value":9,"toc":620},"minimark",[10,14,23,28,31,94,97,105,109,112,192,234,237,241,244,248,251,299,303,306,312,351,372,378,382,385,392,417,424,428,435,499,502,548,559,563,578,586,590,593,613],[11,12,13],"p",{},"Owlat's built-in MTA delivers directly to each recipient's mail server. That gives\nyou control, but it also makes the public IP address of your VPS part of your\nsending identity. A correct DNS record cannot erase a recycled IP's history or a\nprovider-wide SMTP block.",[11,15,16,17,22],{},"This guide helps you decide whether direct delivery is appropriate, prepare the\nserver, and understand what Owlat will do during the first four warming weeks.\nFor the DNS records themselves, keep ",[18,19,21],"a",{"href":20},"\u002Fdeveloper\u002Fself-hosting-dns-email","DNS & Email Setup","\nopen alongside this page.",[24,25,27],"h2",{"id":26},"choose-direct-relay-or-hybrid-delivery","Choose direct, relay, or hybrid delivery",[11,29,30],{},"There is no universal monthly-volume number where a dedicated VPS becomes more\ndeliverable or cheaper than a relay. List quality, traffic shape, operational\ntime, IP history, provider fees, and the cost of delayed mail matter more than a\nsingle threshold.",[32,33,34,50],"table",{},[35,36,37],"thead",{},[38,39,40,44,47],"tr",{},[41,42,43],"th",{},"Mode",[41,45,46],{},"Choose it when",[41,48,49],{},"Trade-off",[51,52,53,68,81],"tbody",{},[38,54,55,62,65],{},[56,57,58],"td",{},[59,60,61],"strong",{},"Relay",[56,63,64],{},"Your VPS provider blocks SMTP, you need reliable delivery immediately, or you do not want to operate reputation feedback and recovery",[56,66,67],{},"The relay owns the last-mile IP reputation and charges for that service",[38,69,70,75,78],{},[56,71,72],{},[59,73,74],{},"Direct to MX",[56,76,77],{},"Your provider permits outbound TCP\u002F25, gives you controllable PTR records, and you can tolerate a gradual reputation ramp",[56,79,80],{},"You own warm-up, blocklist recovery, feedback loops, and receiver-specific throttling",[38,82,83,88,91],{},[56,84,85],{},[59,86,87],{},"Hybrid",[56,89,90],{},"You want to build owned-IP reputation while keeping urgent mail moving",[56,92,93],{},"Owlat can keep eligible traffic direct and route affected receiver traffic through a verified relay",[11,95,96],{},"DigitalOcean's current Droplet policy makes the choice especially simple:\nits official documentation says SMTP ports 25, 465, and 587 are blocked on all\nDroplets, including traffic through a Reserved IP. Use a relay there rather than\nplanning direct-to-MX delivery.",[11,98,99,100,104],{},"See ",[18,101,103],{"href":102},"\u002Fdeveloper\u002Fproviders","Providers"," for relay configuration and domain\nverification. Relay credentials alone do not make a domain eligible: complete\nthe DNS proof shown by Owlat before enabling fallback.",[24,106,108],{"id":107},"vps-provider-comparison","VPS provider comparison",[11,110,111],{},"Provider policies can change. This table was verified against official provider\ndocumentation on July 26, 2026; recheck the linked source before buying a server.",[32,113,114,130],{},[35,115,116],{},[38,117,118,121,124,127],{},[41,119,120],{},"Provider\u002Fproduct",[41,122,123],{},"Outbound SMTP",[41,125,126],{},"IPv4 reverse DNS",[41,128,129],{},"IPv6 reverse DNS",[51,131,132,152,168],{},[38,133,134,139,142,149],{},[56,135,136],{},[59,137,138],{},"Hetzner Cloud",[56,140,141],{},"Ports 25 and 465 are blocked by default. After the account is at least one month old and its first invoice is paid, you may submit a limit request; approval is case-by-case. Port 587 remains available for an external relay.",[56,143,144,145,148],{},"In Console, open the server, choose ",[59,146,147],{},"Networking",", and edit rDNS beside the address.",[56,150,151],{},"The same rDNS screen accepts the IPv6 interface identifier; Hetzner already holds the network prefix.",[38,153,154,159,162,165],{},[56,155,156],{},[59,157,158],{},"DigitalOcean Droplets",[56,160,161],{},"Ports 25, 465, and 587 are blocked on all Droplets. The documented path is a third-party mail service.",[56,163,164],{},"Rename the Droplet to a valid FQDN; DigitalOcean generates its PTR. PTR cannot be created manually in the DNS control panel.",[56,166,167],{},"Only the first assigned IPv6 address gets a PTR from the FQDN Droplet name. The other addresses have no documented manual PTR path.",[38,169,170,175,178,189],{},[56,171,172],{},[59,173,174],{},"OVHcloud VPS",[56,176,177],{},"Outbound port 25 is blocked by default. Use a relay on 587 or ask support to review an unblock request.",[56,179,180,181,184,185,188],{},"Under ",[59,182,183],{},"Network → Public IP Addresses",", choose ",[59,186,187],{},"Configure reverse DNS",". The forward A record must already point back to the address.",[56,190,191],{},"The VPS rDNS workflow supports IPv6 and checks the matching AAAA record before accepting the PTR.",[11,193,194,195,201,202,201,207,201,212,201,217,201,222,227,228,233],{},"Sources: ",[18,196,200],{"href":197,"rel":198},"https:\u002F\u002Fdocs.hetzner.com\u002Fcloud\u002Fservers\u002Ffaq\u002F",[199],"nofollow","Hetzner Cloud mail-port policy",",\n",[18,203,206],{"href":204,"rel":205},"https:\u002F\u002Fdocs.hetzner.com\u002Fcloud\u002Fservers\u002Fcloud-server-rdns\u002F",[199],"Hetzner Cloud rDNS",[18,208,211],{"href":209,"rel":210},"https:\u002F\u002Fdocs.digitalocean.com\u002Fsupport\u002Fwhy-is-smtp-blocked\u002F",[199],"DigitalOcean SMTP policy",[18,213,216],{"href":214,"rel":215},"https:\u002F\u002Fdocs.digitalocean.com\u002Fproducts\u002Fnetworking\u002Fdns\u002Fhow-to\u002Fmanage-records\u002F",[199],"DigitalOcean PTR records",[18,218,221],{"href":219,"rel":220},"https:\u002F\u002Fdocs.digitalocean.com\u002Fproducts\u002Fnetworking\u002Fipv6\u002Fdetails\u002Flimits\u002F",[199],"DigitalOcean IPv6 limits",[18,223,226],{"href":224,"rel":225},"https:\u002F\u002Fdocs.ovhcloud.com\u002Fen\u002Fguides\u002Fbare-metal-cloud\u002Fvirtual-private-servers\u002Fvps-faq",[199],"OVHcloud VPS FAQ",",\nand ",[18,229,232],{"href":230,"rel":231},"https:\u002F\u002Fdocs.ovhcloud.com\u002Fen\u002Fguides\u002Fbare-metal-cloud\u002Fvirtual-private-servers\u002Fconfiguring-reverse-dns",[199],"OVHcloud VPS reverse DNS",".",[11,235,236],{},"The Deliverability Center renders these same canonical provider instructions inline:",[238,239],"deliverability-provider-guidance",{"kind":240},"vps",[11,242,243],{},"Those product guides do not document reverse-zone delegation to your own name\nservers. Use the provider-managed PTR workflow they document. If your\nchosen product or IPv6 address does not appear in that workflow, get written\nconfirmation from the provider before treating the address as send-capable.",[24,245,247],{"id":246},"preflight-the-server-before-setup","Preflight the server before setup",[11,249,250],{},"Do these checks before enabling the built-in MTA:",[252,253,254,258,266,269,272,287,292],"ol",{},[255,256,257],"li",{},"Confirm the exact VPS product permits outbound TCP\u002F25. Submission ports 465\nand 587 do not replace port 25 for direct delivery to recipient MX servers.",[255,259,260,261,265],{},"Allocate a stable public IPv4 address and choose a dedicated hostname such as\n",[262,263,264],"code",{},"mail.example.com",". Do not share the hostname with the web application.",[255,267,268],{},"Publish an A record from that hostname to the sending IPv4 address.",[255,270,271],{},"Set the address's PTR to exactly the same hostname in the VPS provider's\ncontrol panel.",[255,273,274,275,278,279,282,283,286],{},"Put the address in the appropriate ",[262,276,277],{},"IP_POOLS_*"," value and set\n",[262,280,281],{},"EHLO_HOSTNAME"," (or its per-IP ",[262,284,285],{},"EHLO_HOSTNAMES"," entry) to the same hostname.",[255,288,289,290,233],{},"Complete SPF, DKIM, DMARC, and return-path setup in\n",[18,291,21],{"href":20},[255,293,294,295,298],{},"Run ",[262,296,297],{},"owlat doctor",". Do not interpret “containers are running” as “the IP is\nready to send.”",[24,300,302],{"id":301},"the-outbound-ip-readiness-checklist","The outbound-IP readiness checklist",[11,304,305],{},"Owlat treats readiness as live state, not a setup checkbox. A new address starts\ninactive, the MTA verifies it before workers begin, and the check repeats hourly.\nA hard failure quarantines the address and invalidates its pooled SMTP sockets.\nIf no eligible address remains, mail stays queued instead of leaking through an\nunverified source.",[11,307,308,309,311],{},"For every IPv4 sending address, ",[262,310,297],{}," must report:",[313,314,315,321,327,333,339,345],"ul",{},[255,316,317,320],{},[59,318,319],{},"PTR exists"," — the address resolves to a hostname.",[255,322,323,326],{},[59,324,325],{},"PTR is a valid FQDN"," — not an IP literal or malformed local name.",[255,328,329,332],{},[59,330,331],{},"Forward confirmation passes"," — that hostname's A records contain the exact\nsending address.",[255,334,335,338],{},[59,336,337],{},"EHLO matches"," — the MTA announces the same hostname.",[255,340,341,344],{},[59,342,343],{},"The PTR is meaningful"," — a provider-default or address-shaped PTR is\neligible only with a warning; replace it before building reputation.",[255,346,347,350],{},[59,348,349],{},"No critical DNSBL block is active"," — a critical listing independently\nremoves the address from rotation.",[11,352,353,354,357,358,361,362,366,367,371],{},"The live details are available in ",[59,355,356],{},"Delivery health → Outbound IPs"," and in the\nauthenticated MTA ",[262,359,360],{},"GET \u002Fip-reputation"," endpoint. For every verdict field and\npool rule, see ",[18,363,365],{"href":364},"\u002Fdeveloper\u002Fmta-system","MTA System",". If a DNSBL check fails, use\nthe ",[18,368,370],{"href":369},"\u002Fdeveloper\u002Fdnsbl-delisting","DNSBL recovery runbook",", not an override.",[11,373,374,377],{},[262,375,376],{},"MTA_ALLOW_UNVERIFIED_FCRDNS=true"," exists only for private IPv4 lab experiments.\nIt is not a production bypass and cannot admit IPv6.",[24,379,381],{"id":380},"add-outbound-ipv6-only-after-ipv4-is-green","Add outbound IPv6 only after IPv4 is green",[11,383,384],{},"IPv6 is optional and disabled by default. It does not automatically improve\nplacement. Every IPv6-containing pool must retain an IPv4 fallback, and all\nconfigured IPv4 identities must remain ready.",[11,386,387,388,391],{},"Before setting ",[262,389,390],{},"MTA_IPV6_ENABLED=true",", Owlat requires:",[252,393,394,397,400,403,414],{},[255,395,396],{},"A stable public IPv6 address that passes the MTA's source-bound TCP\u002F25 probe.",[255,398,399],{},"A PTR to the same EHLO hostname.",[255,401,402],{},"An AAAA record from that hostname back to the exact IPv6 address.",[255,404,405,406,409,410,413],{},"One SPF record on ",[262,407,408],{},"RETURN_PATH_DOMAIN"," containing the exact positive\n",[262,411,412],{},"ip6:"," mechanism for that address.",[255,415,416],{},"No critical DNSBL block.",[11,418,419,420,233],{},"The same hourly readiness pass quarantines IPv6 if one of those confirmed facts\nregresses; eligible IPv4 continues. Follow the detailed, ordered procedure in\n",[18,421,423],{"href":422},"\u002Fdeveloper\u002Fself-hosting-dns-email#optional-outbound-ipv6","Optional outbound IPv6",[24,425,427],{"id":426},"what-warming-weeks-14-look-like","What warming weeks 1–4 look like",[11,429,430,431,434],{},"The table below is Owlat's checked-in ",[59,432,433],{},"base schedule per IP",". “Warming day” is\nstate, not a guaranteed calendar date: a day with no sends does not advance it,\nand delivery signals can accelerate, slow, or pause the ramp. Each cap remains\nin force until the next listed checkpoint.",[32,436,437,447],{},[35,438,439],{},[38,440,441,444],{},[41,442,443],{},"Warming period",[41,445,446],{},"Base daily-cap checkpoints",[51,448,449,459,469,479,489],{},[38,450,451,456],{},[56,452,453],{},[59,454,455],{},"Week 1 — days 1–7",[56,457,458],{},"Day 1: 50 → day 2: 100 → day 3: 200 → day 5: 700 → day 7: 1,500",[38,460,461,466],{},[56,462,463],{},[59,464,465],{},"Week 2 — days 8–14",[56,467,468],{},"Starts at 1,500 → day 10: 3,000 → day 14: 7,500",[38,470,471,476],{},[56,472,473],{},[59,474,475],{},"Week 3 — days 15–21",[56,477,478],{},"Starts at 7,500 → day 18: 15,000 → day 21: 20,000",[38,480,481,486],{},[56,482,483],{},[59,484,485],{},"Week 4 — days 22–28",[56,487,488],{},"Starts at 20,000 → day 25: 30,000",[38,490,491,496],{},[56,492,493],{},[59,494,495],{},"Day 30+",[56,497,498],{},"Graduation removes the warming cap only after the health gate passes",[11,500,501],{},"Send first to recent, explicit opt-ins who expect the message. Keep volume\nsteady rather than exhausting the cap in a burst.",[32,503,504,514],{},[35,505,506],{},[38,507,508,511],{},[41,509,510],{},"Daily result",[41,512,513],{},"MTA response",[51,515,516,524,532,540],{},[38,517,518,521],{},[56,519,520],{},"Bounce below 1%, deferral below 5%, and at least 80% of cap used",[56,522,523],{},"Advance the schedule faster",[38,525,526,529],{},[56,527,528],{},"Bounce above 3% or deferral above 10%",[56,530,531],{},"Move the schedule day back and reduce the cap by 30%, never below 50",[38,533,534,537],{},[56,535,536],{},"Bounce above 8% or deferral above 25%",[56,538,539],{},"Plateau the IP and alert",[38,541,542,545],{},[56,543,544],{},"Schedule day 30+ with bounce below 2%",[56,546,547],{},"Graduate and remove the warming cap",[11,549,550,551,554,555,233],{},"These are control thresholds, not targets. Keep bounces and complaints far below\nthem. Watch ",[59,552,553],{},"Delivery health"," and the receiver dashboards described in\n",[18,556,558],{"href":557},"\u002Fdeveloper\u002Fexternal-reputation-feedback","External reputation feedback",[24,560,562],{"id":561},"know-the-mailbox-provider-floor","Know the mailbox-provider floor",[11,564,565,566,569,570,573,574,577],{},"Warm-up does not waive receiver requirements. Gmail and Yahoo expect valid\nforward and reverse DNS for all senders. Gmail's operational guidance is to\nkeep its Postmaster Tools spam rate below ",[59,567,568],{},"0.10%"," and avoid ever reaching\n",[59,571,572],{},"0.30% or higher",". Yahoo requires its own complaint rate below ",[59,575,576],{},"0.3%"," and\ncalculates that rate from messages delivered to the inbox. Those denominators\nare different, so Owlat's rolling internal rate is an early warning rather than\na reproduction of either provider's private calculation.",[11,579,580,581,585],{},"Bulk marketing mail also needs aligned authentication and working unsubscribe.\nSee the current ",[18,582,584],{"href":583},"\u002Fguide\u002Fdeliverability#current-mailbox-provider-requirements","mailbox-provider requirement table","\nbefore increasing volume.",[24,587,589],{"id":588},"operate-the-ramp","Operate the ramp",[11,591,592],{},"During the first month:",[313,594,595,601,604,607,610],{},[255,596,597,598,600],{},"Check ",[59,599,553],{}," each day for warm-up state, deferrals, breaker state,\nidentity regressions, and DNSBL results.",[255,602,603],{},"Check Google Postmaster Tools, Yahoo Sender Hub\u002FCFL, and Microsoft SNDS where\nthe provider exposes data. Owlat cannot infer a provider's private reputation\nverdict from its own counters.",[255,605,606],{},"Stop importing or mailing old lists. One complaint at low volume is a strong\nsignal even when a minimum-sample guard prevents automatic enforcement.",[255,608,609],{},"Treat sustained deferrals as a request to reduce rate. Do not retry rapidly or\nmove the same unwanted traffic to another IP.",[255,611,612],{},"Keep transactional and campaign streams separate where you have multiple\naddresses; do not sacrifice password-reset delivery to warm a marketing list.",[11,614,615,616,233],{},"For production networking, backups, and monitoring outside the MTA, continue\nwith ",[18,617,619],{"href":618},"\u002Fdeveloper\u002Fself-hosting-production","Production Deployment",{"title":621,"searchDepth":622,"depth":622,"links":623},"",2,[624,625,626,627,628,629,630,631],{"id":26,"depth":622,"text":27},{"id":107,"depth":622,"text":108},{"id":246,"depth":622,"text":247},{"id":301,"depth":622,"text":302},{"id":380,"depth":622,"text":381},{"id":426,"depth":622,"text":427},{"id":561,"depth":622,"text":562},{"id":588,"depth":622,"text":589},"Choose a VPS that can send mail, pass Owlat's outbound-IP readiness gate, and warm a new IP without guessing.","md",{},true,"\u002Fguide\u002Fsending-from-a-vps",{"title":6,"description":632},"1.guide\u002F51.sending-from-a-vps","7kUtIiDv82314mX_fyPk8j9VRBeEsRM4NSuJ21_z10c",[641,645],{"title":642,"path":643,"stem":644,"children":-1},"Sealed Mail Recovery Kit","\u002Fguide\u002Fsealed-mail-recovery-kit","1.guide\u002F50.sealed-mail-recovery-kit",{"title":646,"path":647,"stem":648,"children":-1},"Secure Email, Explained","\u002Fguide\u002Fsecure-email","1.guide\u002F52.secure-email",1786915098503]