Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungThe Model Got Better. Your Judgment Got Worse.(22.09.2026 um 03:02 Uhr)
Sichere ProgrammierungAIFeed - signed content permissions for AI web crawlers(22.09.2026 um 03:10 Uhr)
Sichere ProgrammierungThanks, glad you liked it!(22.09.2026 um 03:15 Uhr)
Sichere ProgrammierungA request for /.env shouldn't render your React app(22.09.2026 um 03:17 Uhr)
Sichere ProgrammierungAI-Agent Marketplaces Need Verifiable Delivery, Not More Listings(22.09.2026 um 03:20 Uhr)
AI & KI NachrichtenBeyond Bigger Models: Toward a Modular Cognitive Architecture(22.09.2026 um 03:21 Uhr)
Sichere ProgrammierungMasa Depan Manajemen Data: Mengenal Konsep Data Mesh yang Revolusioner(22.09.2026 um 03:22 Uhr)
Sichere ProgrammierungHow to Search Your Claude Code Conversation History(22.09.2026 um 03:22 Uhr)
Sichere ProgrammierungThe Model Got Better. Your Judgment Got Worse.(22.09.2026 um 03:02 Uhr)
Sichere ProgrammierungAIFeed - signed content permissions for AI web crawlers(22.09.2026 um 03:10 Uhr)
Sichere ProgrammierungThanks, glad you liked it!(22.09.2026 um 03:15 Uhr)
Sichere ProgrammierungA request for /.env shouldn't render your React app(22.09.2026 um 03:17 Uhr)
Sichere ProgrammierungAI-Agent Marketplaces Need Verifiable Delivery, Not More Listings(22.09.2026 um 03:20 Uhr)
AI & KI NachrichtenBeyond Bigger Models: Toward a Modular Cognitive Architecture(22.09.2026 um 03:21 Uhr)
Sichere ProgrammierungMasa Depan Manajemen Data: Mengenal Konsep Data Mesh yang Revolusioner(22.09.2026 um 03:22 Uhr)
Sichere ProgrammierungHow to Search Your Claude Code Conversation History(22.09.2026 um 03:22 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Pull the official KumoMTA image

Prerequisites Before installing KumoMTA, ensure you have: Linux server (Ubuntu 22.04+ or RHEL 9+ recommended) Docker (for containerized deployment) or kubectl (for Kubernetes) Domain names with DNS access for MX, SPF, DKIM, and…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




Prerequisites



Before installing KumoMTA, ensure you have:





  • Linux server (Ubuntu 22.04+ or RHEL 9+ recommended)


  • Docker (for containerized deployment) or kubectl (for Kubernetes)


  • Domain names with DNS access for MX, SPF, DKIM, and DMARC records


  • Dedicated IP addresses (at least 2 for warmup rotation)


  • PostgreSQL or SQLite for delivery tracking (optional but recommended)


  • Prometheus + Grafana for metrics (optional but strongly recommended)

  • Root or sudo access









Installation Methods






Option 1: Docker (Recommended for Most Teams)






# Pull the official KumoMTA image
docker pull ghcr.io/prozesshell/kumomta:latest

# Create configuration directory
mkdir -p /opt/kumomta/{config,data,log}

# Start KumoMTA with basic configuration
docker run -d \
--name kumomta \
-p 25:25 \
-p 587:587 \
-p 465:465 \
-v /opt/kumomta/config:/etc/kumomta \
-v /opt/kumomta/data:/var/lib/kumomta \
-v /opt/kumomta/log:/var/log/kumomta \
ghcr.io/prozesshell/kumomta:latest









Option 2: Kubernetes with Helm






# Add the KumoMTA Helm repository
helm repo add kumomta https://charts.kumomta.com
helm repo update

# Install with custom values
helm install kumomta kumomta/kumomta \
--set replicaCount=3 \
--set config.mail.tls.enabled=true \
--set resources.requests.cpu=500m \
--set resources.requests.memory=1Gi












Basic Configuration



KumoMTA's main configuration file lives at /etc/kumomta/kumomta.conf. Here's a production-ready baseline:




-- KumoMTA Configuration
kumo.start_server()

-- SMTP Listener
kumo:define_smtp_listener({
listen = '[::]:25',
relay_hosts = { '127.0.0.1' },
-- Allow authenticated relays
submission = true,
})

-- DKIM Signing
kumo:define_dkim_signer({
domain = 'yourdomain.com',
selector = 'mail',
key_path = '/etc/kumomta/keys/dkim.pem',
headers = { 'From', 'To', 'Subject' },
})

-- Traffic Shaping (per tenant)
kumo:define_traffic_shaper({
name = 'default',
max_message_rate = 1000, -- per second
max_connection_rate = 100,
max_outbound_connections = 1000,
})

-- Prometheus Metrics
kumo:define_source({
name = 'prometheus',
protocol = 'prometheus',
listen = '[::]:8000',
})

-- Logging
kumo:define_log({
path = '/var/log/kumomta/smtp.log',
level = 'info',
})






After saving, validate and reload:




kumomta config validate /etc/kumomta/kumomta.conf
kumomta reload












DKIM and DMARC Setup






Generate DKIM Keys






# Generate a 2048-bit DKIM key pair
openssl genrsa -out /etc/kumomta/keys/dkim.pem 2048
openssl rsa -in /etc/kumomta/keys/dkim.pem -pubout > /etc/kumomta/keys/dkim.pub
chmod 600 /etc/kumomta/keys/dkim.pem









DNS Records



Add these records in your DNS provider:



DKIM Record (TXT record at mail._domainkey.yourdomain.com):




v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY_HERE






SPF Record (TXT at your domain root):




v=SPF1 include:_spf.yourdomain.com ~all






DMARC Record (TXT at _dmarc.yourdomain.com):




v=DMARC1; p=quarantine; rua=mailto:[email protected]; pct=100












IP Warmup Strategy



Never send high volume from a cold IP. Use this rotation schedule:






































Week Daily Volume Cap Notes
1 1,000 emails/day Warmup phase — monitor bounces
2 10,000 emails/day Watch complaint rates
3 50,000 emails/day Check inbox placement
4 200,000 emails/day Observe reputation
5+ Scale as reputation builds Add second IP, repeat


KumoMTA's multi-tenant traffic shaping makes rotating warmup easy — assign each tenant a specific IP pool and let the shaping policies enforce the warmup schedule.









Monitoring with Prometheus and Grafana



KumoMTA exposes metrics at http://yourserver:8000/metrics. Add this to your Prometheus config:




scrape_configs:
- job_name: 'kumomta'
static_configs:
- targets: ['your-kumomta-host:8000']






Key metrics to watch:





  • kumomta_smtp_messages_total — total messages processed


  • kumomta_smtp_delivery_latency_seconds — delivery latency histogram


  • kumomta_smtp_bounce_rate — bounce percentage by type


  • kumomta_tls_connections_total — TLS vs plaintext ratio



Import the official KumoMTA Grafana dashboard (ID: 19876) for instant visibility.









Common Pitfalls





  1. Skipping IP warmup — Cold IPs get blacklisted fast. Follow the rotation schedule strictly.


  2. Missing DKIM keys — Without DKIM, Gmail and Outlook will junk your mail.


  3. No DMARC monitoring — You won't know you're failing authentication until inbox placement drops.


  4. Insufficient connection limits — KumoMTA's default limits are conservative; tune them for your volume.


  5. Ignoring bounce codes — Hard bounces damage reputation; process them within hours, not days.









Conclusion



KumoMTA's modern architecture, Lua configuration flexibility, and AI-assisted deployment make it a powerful choice for high-volume senders ready to leave legacy MTA solutions behind.



Getting it right the first time matters — misconfigured DKIM, inadequate warmup, or missing monitoring will cost you inbox placement that takes months to rebuild.



Need a production-ready KumoMTA deployment without the guesswork? PostMTA's engineering team specializes in KumoMTA setup, IP warmup, and deliverability optimization. We'll have you sending at full volume within weeks, not months.



👉 Get a free KumoMTA setup consultation →






Ready to improve your email deliverability? postmta.com provides enterprise email infrastructure consulting, MTA setup, IP warmup, and deliverability optimization for high-volume senders.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Pull the official KumoMTA image

Thematisch verwandte Begriffe: Pull, official, KumoMTA, image · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-49449 | Joplin is an open source note-taking and to-do application that organise…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick