PowerMTA is a high-performance, enterprise-grade mail transfer agent (MTA) software designed for high-volume email delivery, handling millions of messages per hour. It gives you control over how emails leave your server, which IP address is used, how many messages are delivered, and what happens when a recipient server temporarily rejects a message. It also provides a monitoring interface where you can check queues, delivery activity, and errors.
PowerMTA can be installed on its own or alongside a web hosting control panel. In this tutorial, we are going to install it with HestiaCP on Ubuntu 24.04. HestiaCP will help us manage the domain, mailboxes, and SSL certificate, while PowerMTA will handle the outgoing SMTP connection used by our sending application.
There is one thing to understand before we start. PowerMTA is a mail transfer agent. If you also want to receive replies and open them in webmail, you need a receiving mail service and a mailbox. HestiaCP can provide that part of the setup through its mail services and webmail interface.
We will go through the server connection, HestiaCP installation, PowerMTA installation, configuration file, DNS records, and SSL setup. After that, we will test the SMTP connection and send an email to Mail-Tester so you can check what is actually working.
Requirements
1. A Domain Name
If you already have a domain, you can use it for this tutorial. Otherwise, you can check the available domain offers through Namecheap.
Make sure you can edit the domain’s DNS records. We will need to point the domain to the server and add the records used for email authentication.
2. A VPS with Outbound Port 25 Open
You need a VPS or dedicated server with a fresh installation of Ubuntu 24.04. For this walkthrough, start with at least 2 vCPU and 4 GB RAM, and choose enough storage for your mailboxes and queued messages.
Before purchasing a server, confirm that the provider allows outbound connections on port 25. Opening a port in Ubuntu will not remove a restriction imposed by the hosting provider.
You can check the server options through OpenPort25. Whichever provider you use, confirm the port policy for the particular server you are ordering.
Our PowerMTA configuration will accept SMTP connections on port 587. That is the port your application connects to. PowerMTA still needs outbound port 25 when delivering directly to other mail servers, so these are two separate requirements.
3. PowerMTA Installation Files
Keep your PowerMTA package, with a valid license, and associated configuration files ready. You can access the PowerMTA files here.
Confirm that the supplied build supports your server environment before proceeding.
4. Tools to Access the Server
For the terminal connection on Windows, we will use PuTTY. For transferring files, you can use either FileZilla or WinSCP.
Keep the server’s IP address, SSH username, password or private key, and SSH port available. You will use the same server details in your terminal and file transfer client.
Deploy SERVER
Open your hosting provider’s control panel and deploy a server with Ubuntu 24.04. Start with a clean installation because HestiaCP installs and configures its own services.
Choose a hostname in the format server.yourdomain.com, and point that hostname to the server’s IP in your DNS settings. This is the server hostname; we will configure the sending domain and mail hostname separately as we move through the tutorial.
Once the server is ready, note its public IPv4 address. If you have ordered additional IP addresses, those must also be assigned and configured by your provider before you can use them in PowerMTA. One working sending IP is enough to follow the main steps here.
Access SERVER
Open PuTTY and enter your server’s public IP address in Host Name (or IP address). Select SSH as the connection type and enter your SSH port, normally 22 unless your provider has configured another port.
Click Open. On the first connection, compare the server’s host key with the information available from your provider before accepting it. Enter the username and password supplied with the server, or use your SSH key if that is how your server is configured.
While typing a password in the terminal, you will not see the characters appear. This is normal. Type the password and press Enter.
Enable Root Access If Required
Some server images, including certain OVHcloud images, initially provide a regular user with sudo access. If you already have root access, you can skip these root-login changes.
Set the root password by running:
sudo passwd root
Enter the new password and confirm it. Now open the SSH configuration file:
sudo nano /etc/ssh/sshd_config
Find the PermitRootLogin setting and set its value as follows:
PermitRootLogin yes
Save the file by pressing Ctrl + X, then Y, and Enter. Reload the SSH service:
sudo service sshd reload
>>How to Enable Root Access & Password Authentication
Keep the current terminal open while you check your root connection in a second session. Password access also depends on the other SSH authentication settings on your server. If Ubuntu reports that the sshd service does not exist, check the ssh service name used by your installation before continuing.
Use a root session for the remaining installation steps. Several of the supplied installation commands do not include sudo.
Check Port 25
Before spending time on the installation, check whether the server can make an outbound SMTP connection.
Install the Telnet client on Ubuntu:
sudo apt-get install telnet -y
If the package manager cannot find the package on a fresh image, refresh its package list first:
sudo apt-get update
Then repeat the Telnet installation command. Now test the connection:
telnet smtp.gmail.com 25
If the connection succeeds, the terminal should show a connection message followed by an SMTP greeting. If it times out, check the server firewall and ask the provider about its outbound SMTP restriction. A failed connection is a reason to investigate before continuing; it does not identify the cause by itself.
To leave Telnet, press Ctrl + ] to open its command prompt, then enter:
quit
Check IP REPUTATION
Open the IP Blacklist Check, enter your sending IP, and run the lookup. Review any listings before you begin sending.
A server that connects on port 25 can still have a listed IP address. Similarly, an IP that is not listed in the lookup is not a guarantee that every recipient will accept its messages. These checks help you understand the starting condition of the server.
Install HestiaCP
Now we can install the control panel. You can find HestiaCP’s installer and available options on its installation page.
Download the installation script:
wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh
Update the package list and install the CA certificates package:
apt-get update && apt-get install ca-certificates
If the download failed because of certificate validation, repeat the download after installing the certificate package.
Start the installer:
bash hst-install.sh
Read the installation summary, confirm that you want to continue, and enter the requested administrator details, email address, and hostname. Wait until the installer finishes. The time required will depend on the server and the packages being installed.
At the end, save the panel URL, username, and password shown in the terminal. Complete any restart requested by the installer, reconnect to SSH, and open the panel URL in your browser. HestiaCP normally uses port 8083 unless you chose another port.
Add Domain and Mailbox in HestiaCP
Log in to HestiaCP and open the Web section. Choose Add Web Domain, enter your domain, and save it.
The certificate command later in this article uses a path under /home/admin/, so its example assumes the web domain belongs to the HestiaCP user admin. If you place the domain under another user, use that user’s actual certificate path when adapting the example.
For receiving mail, open Mail, add the same domain, and open it. Choose Add Mail Account, enter mail as the account name, set a mailbox password, and save. This gives you an address such as mail@yourdomain.com for replies and reports.
Keep the mailbox password separate from the PowerMTA SMTP password. The PowerMTA user defined later is an SMTP submission account; creating it does not create a webmail mailbox.
HestiaCP can display suggested mail DNS records. If your DNS is hosted elsewhere, those records must be published with that provider. We will add the records explicitly below, including the DKIM record that matches the private key used by PowerMTA.
Check SMTP Listener
HestiaCP installs Exim as part of its default mail setup. Our PowerMTA sample uses the public IP on 587, and forwards messages for the local domain to 127.0.0.1:587.
That arrangement requires a receiving service on the loopback address and PowerMTA on the public address. Exim must not occupy all addresses on port 587, because that would prevent PowerMTA from binding its listener. Check the listener configuration on your server before starting PowerMTA; the default HestiaCP installation does not establish this separation automatically.
Upload PowerMTA Files
Open FileZilla or WinSCP and create a connection to the server. Choose SFTP, enter the server IP, root username and your password or SSH key, and use your SSH port.
In WinSCP, the connection type is SFTP. In FileZilla, use the SFTP protocol in Site Manager. Do not select ordinary FTP for this connection.
After connecting, open /root on the server side and upload PowerMTA-5.0r8.deb. Wait for the transfer to finish before running the installer.
In your terminal, switch to the same directory:
cd /root
Confirm that the uploaded file is present:
ls -lh PowerMTA-5.0r8.deb
You should see the filename and its size. If the file cannot be found, check the upload location and spelling before going further.
Install PowerMTA
First, install the packages used by this setup:
sudo apt-get install libc6 libssl-dev
Now install the PowerMTA package:
sudo dpkg -i PowerMTA-5.0r8.deb
Wait for the installation to finish. If the package manager reports a dependency or installation error, address that error before moving on to the configuration file.
Place Associated Files
Return to your file transfer client and open the following directories. Place the license and configuration files there, and use matching replacement daemon files only if they are supplied as part of your authorized installation package.
| File | Directory on the server |
|---|---|
pmtad |
/usr/sbin/ |
pmtahttpd |
/usr/sbin/ |
license |
/etc/pmta/ |
config |
/etc/pmta/ |
The filename config has no .txt extension. If you edit it on Windows, check that the editor has not saved it as config.txt.
Keep a backup of the installed files before replacing them, and preserve the ownership and permissions required by the package. We will now edit the configuration with the settings for our domain and sending IP.
Generate DKIM Key
The configuration we are about to use refers to a DKIM private-key file. Prepare that file before restarting PowerMTA so the configured path exists.
Open the DKIM Record Generator, enter your domain name, and use dkim as the selector. Generate the key pair and keep both outputs available.
The private key stays on the server and is used by PowerMTA to sign messages. The public key is published in DNS so a receiving server can verify those signatures. Do not put the private key in a DNS record.
Using your file transfer client, create a file inside /etc/pmta/ named dkim.yourdomain.com.pem. Paste the complete private key into that file, including its opening and closing lines, and save it as plain text.
For the domain used in our example, the path is:
/etc/pmta/dkim.technicalsahil.com.pem
The filename in the domain-key directive must match this file. Set its ownership and permissions so the PowerMTA service account can read the private key while access remains restricted to the accounts that need it.
Keep the generated DNS record ready. We will publish it in the DNS section.
Configure PowerMTA
Open the PowerMTA configuration file:
# Edit configuration file with your IP and domain
sudo nano /etc/pmta/config
Use the following sample configuration, replacing the example domain, IP addresses, username, and password with the values for your server.
Before copying, understand the two different IP addresses in this example:
| Example value | What you should put there |
|---|---|
107.152.135.238 |
Your server’s sending IPv4 address |
185.254.238.226 |
The public IP of the connection from which you will administer the PowerMTA console |
technicalsahil.com |
Your sending domain |
mail@technicalsahil.com |
Your postmaster or contact mailbox |
sahil |
Your chosen SMTP username |
YOUR_SMTP_PASSWORD |
A strong password for that SMTP user |
/etc/pmta/dkim.technicalsahil.com.pem |
The matching DKIM private-key file created above |
The second IP is an administration access rule. Do not automatically replace it with the server’s IP; use the public client IP from which you intend to open the console.
postmaster mail@technicalsahil.com
#smtp-port 587
smtp-listener 107.152.135.238:587
<source 0/0>
log-connections yes
log-commands yes # WARNING: verbose!
allow-unencrypted-plain-auth yes
</source>
sync-msg-create false
sync-msg-update false
run-as-root no
log-file /var/log/pmta/log # logrotate is used for rotation
<acct-file /var/log/pmta/acct.csv>
# move-to /opt/myapp/pmta-acct # configure as fit for your application
# move-interval 5m
max-size 50M
</acct-file>
# transient errors (soft bounces)
<acct-file /var/log/pmta/diag.csv>
move-interval 1d
delete-after never
records t
</acct-file>
#
# spool directories
#
spool /var/spool/pmta
http-mgmt-port 1983
http-access 127.0.0.1 admin
http-access 0/0 monitor
http-access 185.254.238.226 admin
# BEGIN: USERS/VIRTUAL-MTA / VIRTUAL-MTA-POOL / VIRTUAL-PMTA-PATTERN
#<spool /var/spool/pmta>
#</spool>
<smtp-user sahil>
password YOUR_SMTP_PASSWORD
source {smtpuser-auth}
</smtp-user>
<source {smtpuser-auth}>
smtp-service yes
always-allow-relaying yes
require-auth true
process-x-virtual-mta yes
default-virtual-mta pmta-pool
remove-received-headers true
add-received-header false
hide-message-source true
</source>
#BEGIN VIRTUAL MTAS
<virtual-mta pmta-vmta1>
smtp-source-host 107.152.135.238 technicalsahil.com
domain-key dkim,*,/etc/pmta/dkim.technicalsahil.com.pem
<domain *>
dkim-sign yes
max-msg-rate 400/h
use-starttls yes
</domain>
</virtual-mta>
<domain technicalsahil.com>
smtp-hosts [127.0.0.1]:587
</domain>
#END VIRTUAL MTAS
<virtual-mta-pool pmta-pool>
virtual-mta pmta-vmta1
</virtual-mta-pool>
# END: USERS/VIRTUAL-MTA / VIRTUAL-MTA-POOL / VIRTUAL-PMTA-PATTERN
<source 127.0.0.1>
always-allow-api-submission yes
add-message-id-header yes
retain-x-job yes
retain-x-virtual-mta yes
verp-default yes
process-x-envid yes
process-x-job yes
jobid-header X-Mailer-RecptId
process-x-virtual-mta yes
allow-starttls yes
</source>
<domain technicalsahil.com>
smtp-hosts [127.0.0.1]:587
</domain>
Save the file by pressing Ctrl + X, then Y, and Enter.
Understand Main Settings
The postmaster line identifies the contact address for the setup. Use a real mailbox that you can access.
The smtp-listener line tells PowerMTA which IP and port to accept SMTP connections on. In this example, your application connects to the server’s public IP on port 587.
The <smtp-user sahil> section defines the SMTP username and password. These are the credentials we will enter in the SMTP test tool later. They are separate from your root login and HestiaCP login.
The {smtpuser-auth} source applies the authenticated user’s settings and selects pmta-pool. The pool contains pmta-vmta1, which defines the sending IP, hostname, and DKIM key. If you rename a virtual MTA or pool, update every reference to that name.
Inside the virtual MTA, max-msg-rate 400/h supplies the wildcard domain delivery rate for this example. It is a configuration value for that delivery scope, not a promise that recipient providers will accept that volume.
The smtp-hosts [127.0.0.1]:587 entries route mail for your own domain to a local receiving service. That service needs to exist and accept mail for the domain. This route is not the connection used to deliver messages to every external recipient.
The web console port is set by http-mgmt-port 1983. The example grants monitor access to all source IPs and admin access to localhost and the specified client IP. Restrict console access to the audience you intend to allow.
Finally, this sample allows plaintext authentication. Complete the TLS section below and use STARTTLS when supplying credentials from a remote application.
Restart PowerMTA
Restart the PowerMTA service:
# Restart PowerMTA service
service pmta restart
If it fails to start, check the reported error. A missing DKIM key, invalid license, incorrect configuration entry, or another service already using the listener can prevent startup.
For a stopped or failed PowerMTA daemon, you can use the following diagnostic command:
# Debug any issues
pmtad --debug
Read the output and correct the specific issue it reports. Do not continue to the SMTP test while the daemon is failing to start.
Connect Domain and Configure DNS
Now open the DNS settings for your domain. If the domain uses your registrar’s nameservers, edit the records there. If you use another DNS provider, make the changes with that provider instead.
Adding records in a HestiaCP DNS zone does not publish them through a different provider’s nameservers. Work in the authoritative zone for your domain.
ADD A Records
Add the following records and replace your.server.ip with the public IPv4 address of your server:
| Type | Name | Value |
|---|---|---|
| A | @ |
your.server.ip |
| A | www |
your.server.ip |
| A | mail |
your.server.ip |
| A | www.mail |
your.server.ip |
| A | webmail |
your.server.ip |
The @ record points the root domain to the server. The other records provide the hostnames used for the website, mail service, and webmail in this example. Use your DNS provider’s default or automatic TTL unless you have a reason to set another value.
If you are using Cloudflare, hostnames used for SMTP and other mail protocols should resolve directly to the mail server rather than through the ordinary web proxy.
Add MX
Create an MX record using these details:
Name: @
Value: mail.yourdomain.com
Priority: 10
For the sample domain, the destination would be mail.technicalsahil.com. Make sure that hostname has the corresponding A record and that the receiving service accepts mail for your domain.
An MX record tells other servers where to deliver incoming messages. It does not create a mailbox, which is why we prepared the receiving side in HestiaCP earlier.
Add SPF
Create a TXT record at the root of the domain:
Name: @
Value: v=spf1 a mx ip4:YOUR.SERVER.IP ~all
Replace YOUR.SERVER.IP with the actual sending IP. The ip4: part authorizes that IPv4 address to send mail for the domain.
You can also use the SPF Generator to prepare the record for your own setup. If you use more than one sending service, their authorizations need to be combined into one SPF record for that hostname.
Do not add a second SPF record just because another one already exists. Edit the existing record to include the sending sources you actually use.
Add DMARC
Create a TXT record with _dmarc as its name:
Name: _dmarc
Value: "v=DMARC1;p=none;sp=none;pct=100;adkim=r;aspf=r;rua=mailto:mail@yourdomain.com;ruf=mailto:mail@yourdomain.com;ri=86400;fo=1"
Replace the example reporting address with a mailbox you control. In this example, p=none requests monitoring rather than quarantine or rejection based on a DMARC failure.
If you want to prepare the value through a form, use the DMARC Generator. Publish one DMARC record for the domain and make sure you are editing the record in the correct DNS zone.
Add DKIM
Return to the public-key record generated earlier. Create the TXT record using this format:
Name: dkim._domainkey
Value: "v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY"
Replace YOUR_PUBLIC_KEY with the public key from that same key pair. The selector is dkim, matching the selector at the beginning of our PowerMTA domain-key directive.
The completed record name for the sample domain is dkim._domainkey.technicalsahil.com. Some DNS panels append the domain automatically, so enter only dkim._domainkey when that is how your provider handles record names.
If HestiaCP has also generated a DKIM record for its own mail service, do not assume it matches PowerMTA’s separate private key. The public key published for this selector must match the private key PowerMTA is actually using.
Save all the records and allow time for propagation. If you test immediately, a receiving server may still see an earlier cached value.
Set Reverse DNS
Open the IP or network settings in your VPS provider’s panel and check the reverse DNS, also called the PTR record. Set it to the hostname used to identify the sending IP, and make sure that hostname resolves back to the same IP.
In the sample configuration, smtp-source-host pairs the sending IP with technicalsahil.com. Your own sending hostname, its A record, and the IP’s PTR record should form a consistent setup. Reverse DNS is normally changed through the IP provider, not by adding an ordinary record at your domain registrar.
Install SSL Certificate
Once the domain resolves to the server, return to HestiaCP and open Web. Edit the domain, enable SSL, select the option to obtain a Let’s Encrypt certificate, and save the changes.
Wait for the certificate to be issued. If issuance fails, check the hostname’s DNS records and whether the validation request can reach your server. Do not run the file-combination command until the certificate and key files exist.
The example below uses the web domain’s certificate under the HestiaCP user admin. The certificate must cover the hostname you will enter in your SMTP application. Giving a PEM file a particular name does not add that name to the certificate.
Create the SSL directory for PowerMTA:
# Create SSL directory
sudo mkdir -p /etc/pmta/ssl
Now combine the certificate and its private key into one PEM file:
# Combine certificate and key (replace with your domain)
cat /home/admin/conf/web/yourdomain.com/ssl/yourdomain.com.crt \
/home/admin/conf/web/yourdomain.com/ssl/yourdomain.com.key \
> /etc/pmta/ssl/pmta.yourdomain.com.pem
Replace yourdomain.com in all three paths with your actual domain. Copy the complete multiline command, including the two backslashes.
For example, when using technicalsahil.com as the HestiaCP web domain, the input files must exist in that domain’s SSL directory. The output is the combined PEM file PowerMTA will read. Restrict access to the resulting file because it contains the private key, while allowing the PowerMTA service account to read it.
Connect Certificate
Open /etc/pmta/config again:
sudo nano /etc/pmta/config
Add this directive at the top level of the configuration, outside a <source>, <domain>, or <virtual-mta> section:
smtp-server-tls-certificate /etc/pmta/ssl/pmta.yourdomain.com.pem
Update its domain placeholder so the path matches the PEM file created above.
Inside the existing <source 0/0> section, add the following line if it is not already present:
allow-starttls yes
Use the existing section rather than pasting another catch-all source block. The localhost source in the sample already enables STARTTLS, but a remote SMTP client also needs it available on the source settings that apply to that client.
Save the file. We will restart the services below and then select STARTTLS in the SMTP test tool.
The combined PEM file is a separate file from HestiaCP’s certificate files. When the certificate is renewed, refresh that combined file and have PowerMTA load the renewed certificate as well.
Update IP Addresses in HestiaCP
If your provider has assigned additional IP addresses and configured them on the server, update HestiaCP’s system IP information:
v-update-sys-ip
This updates HestiaCP’s view of the server addresses. To send through additional IPs, you would also need the corresponding virtual MTA configuration. The sample in this article uses one virtual MTA and one sending IP.
Restart Services
After completing the domain and SSL configuration, restart PowerMTA again:
service pmta restart
Restart the PowerMTA web management service:
service pmtahttp restart
Open PowerMTA Console
The sample configuration uses 1983 as the management port. Open the following address in your browser:
http://your-server-ip:1983
Replace your-server-ip with your server’s IP address. This address uses HTTP because the supplied configuration defines a management port without configuring HTTPS for the management interface. The SMTP certificate we added does not automatically turn the web console into an HTTPS service.
If the console does not open, check that the management service is running and that your firewall allows the intended client to reach port 1983. If the console opens with monitoring access only, check the public client IP in the http-access admin rule.
The access rules in this example are based on source IP. The SMTP username and password are not a universal login for the web console.
Find SMTP Details
It is time to test the server. The SMTP details come from the configuration file we edited; you do not need to guess them from the control panel login.
| SMTP field | Value for the sample setup | Where it comes from |
|---|---|---|
| Server or hostname | technicalsahil.com |
A hostname resolving to the listener IP and covered by the certificate |
| Port | 587 |
smtp-listener |
| Username | sahil |
<smtp-user sahil> |
| Password | The password you set | The password line in that SMTP user section |
| From email | mail@technicalsahil.com |
The sender address selected for the test |
| Encryption | STARTTLS | The certificate and source settings added above |
Use your own domain and credentials in place of these example values. The From address should use the domain whose SPF and DKIM you configured. The postmaster setting does not automatically force every application’s From address to that value.
The three main interfaces use different ports: HestiaCP normally uses 8083, this PowerMTA console uses 1983, and SMTP submission uses 587. Enter the SMTP port in your email application, not either control panel port.
Test SMTP Connection
Open the SMTP Connection Test. Enter your SMTP hostname, port 587, SMTP username, password, and From address. Select STARTTLS as the security mode for the TLS setup completed above.
For the first test, enter a mailbox you control as the recipient, then run the test. Read the conversation shown by the tool to see whether the connection, TLS negotiation, authentication, and message submission succeed.
If authentication fails, compare the username and password with the SMTP user section. If the connection times out, check the listener and firewall. For a certificate error, compare the hostname entered in the test with the names covered by the certificate.
A successful submission means PowerMTA has accepted the message. Check the recipient mailbox and PowerMTA’s delivery information to confirm what happened after acceptance.
Check Mail Spam Score
Now open Mail-Tester. Copy the temporary recipient address it displays and keep that page open.
Return to the SMTP test tool and use that address as the recipient. Submit a new message through your PowerMTA server, then go back to Mail-Tester and check the result.
Read the individual findings as well as the score. In particular, check whether the received message passes SPF and DKIM, whether DMARC aligns, and whether the report identifies an IP listing or hostname problem.
If SPF fails, compare the IP in the received message with the IP authorized in your SPF record. If DKIM fails, check the selector, public key, private-key path, and whether PowerMTA actually signed the message. A DNS record can exist while a message remains unsigned.
For a reverse DNS issue, check the PTR record with the VPS provider. For a blacklist result, use the earlier IP lookup link to examine the specific listing. Fix the reported issue, allow for DNS propagation where needed, and send a fresh test message.
Check Again
After making a correction, repeat the test with the same sending domain and SMTP settings. Compare the new result with the previous one so you can see which change resolved the problem.
A better score is useful feedback, but it does not guarantee inbox placement with every provider. Also send a message to a normal mailbox you control, check where it arrives, and confirm that you can receive a reply through the mailbox prepared in HestiaCP.
Conclusion
We have covered installing HestiaCP, uploading and installing PowerMTA, preparing the configuration and DKIM key, publishing DNS records, adding the SMTP certificate, and testing the server with an actual email.
Once those checks pass on your server, you can use the same SMTP hostname, port, username, password, and STARTTLS setting in your sending application. Keep the PowerMTA console available while testing so you can see delivery activity and investigate messages that remain in the queue.
Start with a small number of messages, check the results, and increase usage according to what your server and recipient providers can handle.