Volume over time
Breakdown
| Receiving domain | Messages | Composition | Delivered | In flight | Bounced | Rejected | Settled rate | Volume |
|---|
What the far end said
| Event | Class | Code | Enhanced | Count | Domains | Last seen | Sample response |
|---|
From message_event, so this is why mail ended
where it did — not where it ended up. A deferral is a retry in
progress, not a loss.
| Received | Str | User | From domain | Recipient | Client IP | Egress | Egress IP | Status | Tries | Token |
|---|
| Address | Reason | Source | Code | Last event |
|---|
| Name | Status | Msgs/h | Msgs/day | Rcpt/msg | Max size | ID |
|---|
| Domain | Tenant | Status | Return-Path | Verified | DKIM | Outbound TLS | Sending |
|---|
| Username | Tenant | Stream | Status | SMTP | API | Actions |
|---|
| Name | Tenant | Prefix | Scopes | Status | Created |
|---|
Services
| Target | Kind | State | Unchanged for | Latency | Checked | Detail |
|---|
Asserted on the answer, not on
systemctl is-active. On 2026-08-15 the unit stayed active,
the port stayed open and the service answered nothing for a day.
DKIM publication
| Domain | Selector | State | Detail | Checked |
|---|
Banned addresses
| Address | Jail | Nodes | Where | Banned | Expires |
|---|
Egress reputation
| Egress IP |
|---|
unknown is not clean: a lookup that failed says nothing, and treating it as “not listed” is how a broken resolver reads as a clean bill of health.
Dependencies
dnf cannot see| Package | Installed | Latest | Advisories | Checked |
|---|
| Recipient domain | Level | Note | Added |
|---|
What these levels mean
- opportunistic
- TLS if the far end offers it, certificate not checked, plaintext fallback. What this stack did before any of this existed.
- required
- No delivery without STARTTLS. The certificate is not checked. This is what “enforce encryption” normally means for outbound mail.
- required + verify
- STARTTLS and the certificate must verify against the MX name. Strict, and it will fail against a large part of the internet — self-signed certificates and mismatched names are ordinary out there, and those failures look like the other side being broken. Right for a named partner, wrong as a blanket policy.
Rules here are keyed by destination. The sending side is set per domain on the Domains tab; when both apply, the stricter of the two wins. A change takes about seven minutes to reach the wire — the delivery nodes re-provision every five minutes and kumod re-reads the file on a two minute TTL. Mail already queued keeps the level it was queued at.
| Connected | Port | Client | Username | Auth | Message | Outcome |
|---|
What this shows, and what it deliberately does not
One row per submission connection, not one
per log line. Measured on smtp01: 157 322 syslog lines produced
11 252 real connections in a day, and Postfix’s
disconnect line already carries the whole session. Shipping
every line into a shared production cluster would be
fourteen times the entire message-event table every day.
Our own probes are excluded — keepalived on loopback is 85 % of all connections here, and the control worker probes both ports every two minutes. Both are already on the Health tab.
Auth reads ok/attempts.
0/0 and 0/3 are different clients: one never
tried, the other tried three times and failed. The link to a message is
Postfix’s queue id, taken from the Received header
the message kept — not the client address, which for a message is
a value the sender supplied.
Worker settings
These are stored in the database and read by the worker once per cycle, so a change takes effect without a restart. The set of settings is fixed by a migration — this form can change values and cannot add or remove one.
What is deliberately not here
Nothing that names a host. Probe targets — which URL, which SMTP port, which egress IP — live in the worker’s config file and change by deploy. A target list editable through this page would be a runtime-settable outbound-request list on the only internet-facing host in the stack. An interval cannot be pointed at an address, which is why intervals are safe to put here and addresses are not.
| When | Actor | Action | Object | Outcome | From | Detail |
|---|
Configuration changes only — mail is in Messages. Refused and failed attempts are recorded too, so a denied row means someone tried something and did not get it.