Mail Operations
What the relay did, for whom, and what needs a decision. Read-only; nothing on this page sends mail.
Needs a decision
Last 7 days
Daily outcome, last 14 days
sentdeferredbounced
Queue now
Senders (one row per SMTP login)
| Product | Health | Messages | Outcome mix | Sent | Deferred | Bounced | Discarded |
|---|
Recent messages
| Time | Product | To | Outcome | Queue id |
|---|
Rejected at the door
Relay traffic
Every message that passed through the relay, per product. Click a row for recipients, responses and every delivery attempt.
Messages
| Time (UTC) | Product | From | To | Outcome | Queue id | Attempts | DKIM |
|---|
Queue
Messages the relay accepted but has not delivered yet. Postfix retries each for up to 5 days, then returns it to the sender as a bounce. Nothing is deleted from this page.
Why they are stuck
Who and where to
Purge request
0 selected
Queued messages
| Arrived | Queue id | Sender | Recipient | Size | Reason |
|---|
Security
Who is knocking on the relay, and what the door looks like from outside.
Failed SMTP logins, 7 days
Unauthorized relay attempts, 7 days
Daily pressure
failed loginsrelay attempts
| Day | Failed logins | Relay attempts | Bar |
|---|
Hardening checklist
Products
One row per product connected to the relay: its SMTP login, what it signs as, and how it is doing. Adding a product creates the credential, the DKIM key and the DNS records in one flow.
| Product | SMTP login | Status | Signs as | Bounces | 7-day msgs | Delivery | Owner | Created |
|---|
What "Add product" does on the server
- Creates a Dovecot SASL user
<name>@tutanti.comwith a 32-char alphanumeric password (safe in any URL or docker-compose file). - Runs
tutanti-add-sender send.<domain> <selector>: RSA-2048 DKIM key, wired into OpenDKIM. - Adds the bounce address to the accept-and-discard map for that domain (or leaves bounces to be collected).
- Shows the 4 DNS records to paste into the product's zone; "Check DNS" marks the domain verified when they resolve.
- Shows the credential once. The only copy on the server is
/root/<name>-relay-credentials.txt.
Per-product actions
Rotate — new password takes effect immediately; hand it over before the product restarts.
Suspend — login refused at once; nothing else changes. Resume restores it.
Remove — not offered here. Deletion is an operator action with the owner's explicit approval.
Suspend — login refused at once; nothing else changes. Resume restores it.
Remove — not offered here. Deletion is an operator action with the owner's explicit approval.
Domains & DKIM
Every domain the relay signs for, and whether the receiving side can verify it.
| Domain | Selector | Used by | A | SPF | DMARC | DKIM | MX (bounces) | Verified |
|---|
DNS checklist per sending domain
A send.DOMAIN 185.241.7.40 (DNS-only, no proxy)
TXT send.DOMAIN v=spf1 ip4:185.241.7.40 ~all
TXT _dmarc.send.DOMAIN v=DMARC1; p=none; rua=mailto:dmarc@DOMAIN; adkim=r; aspf=r
TXT SELECTOR._domainkey.send.DOMAIN v=DKIM1; h=sha256; k=rsa; p=<public key from tutanti>
MX bounce.send.DOMAIN 10 mail.tutanti.com (only if bounces are collected)
Publishing
_dmarc.send.DOMAIN overrides DMARC for that sub-domain only. A product already at p=reject on its apex can onboard without loosening anything.Server-side signing
signerOpenDKIM (rspamd scans only, does not sign)
fallbacktutanti.com, selector agura, for every product
TLSLet's Encrypt, mail.tutanti.com, auto-renew
rDNS185.241.7.40 → mail.tutanti.com (FCrDNS pass)
Campaigns
Bulk sends run from this dashboard. Separate from product relay traffic, and gated by consent and warm-up caps.
Campaigns
0
none created yet
Warm-up day
—
starts with the first campaign
Today's cap
20
day-1 schedule
Unsubscribes
0
list-unsubscribe honoured
All campaigns
Campaign API not connectedThe campaign backend behind tutanti.com/api answers 404 on every path. Product relay traffic is unaffected. Restoring or retiring the campaign backend is listed under Settings → Connections.
IP warm-up schedule
Compose
Send a single email or a test through the relay, from any domain the relay signs for. Limited to 20 a day from here.
Test sends are logged like any other message and show up in Relay traffic under the chosen login.
Before you send
Only domains with a DKIM key on the relay are offered. A domain whose DNS is not verified yet will be signed but may fail at the receiver.
Lead lists
Lists imported from LeadMiner or uploaded as CSV. Consent state travels with each lead.
Not connectedLead lists live in the campaign backend, which is not connected. The LeadMiner token can be set under Settings → Connections once it is.
Segments
Saved filters over lead lists, reused across campaigns.
Not connectedSegments depend on lead lists. Available once the campaign backend is restored.
Analytics
Campaign performance over time. Product relay traffic lives under Overview and Relay traffic.
Delivered
—
no campaigns sent
Open rate
—
pixel tracking off
Click rate
—
link tracking off
Bounce rate
—
Complaints
—
no feedback loop yet
Nothing to chart yetThis page fills in after the first campaign. Tracking links were disabled on the server (the old /track endpoint was broken); re-enabling needs a signed-link implementation first.
Send logs
Campaign-level history: which campaign sent what, to whom, with which result. Kept separate from relay traffic so bulk and transactional never mix.
No campaign sendsEvery campaign send will appear here with campaign, recipient, outcome and the relay queue id, linking to the full trace in Relay traffic.
Unsubscribes
People who opted out. Suppressed from every campaign, never from transactional mail (a password reset still has to arrive).
Suppressed
0
all time
Via one-click
0
RFC 8058 header
Via reply / manual
0
No unsubscribesAddresses land here automatically from the List-Unsubscribe header once campaigns run.
Settings
Server, connections, alert thresholds and who can sign in.
Relay
hostmail.tutanti.com · 185.241.7.40
submission:587 STARTTLS required · SASL PLAIN/LOGIN via Dovecot
inbound:25 · rspamd + SPF policy · not an open relay
rate limitsnone enforced by the relay. Caps are the caller's job.
log ingest…
Alert thresholds
Sent through the relay itself, from send@tutanti.com.
Connections
Sign-in
account
methodserver-side session · scrypt · 12 h · 5 attempts per 10 min