AnnexGroup

Documentation

Security settings

Under Administration → Security you configure the server's security profile.

Security presets

  • Balanced: balanced settings for production operation.
  • Strict: shorter session lifetimes, stricter rate limiting, enforced TLS.
  • Development: less strict limits for test environments.

Features

  • IP blocking after repeated failed attempts
  • Blacklist, also for network ranges (see below)
  • View login attempts
  • Manage DKIM keys
  • Check TLS/MTA-STS policies
  • Run audit checks manually

Blacklist with network ranges

The blacklist under Administration → Security accepts individual addresses and whole network ranges — IPv4 and IPv6. Allowed is an address like 203.0.113.7, a range in CIDR notation like 203.0.113.0/24 or 2001:db8::/32.

The server guards against locking yourself out: your own address cannot be blocked, not even as part of a network range — and loopback addresses as well as ranges that cover everything (0.0.0.0/0, ::/0) are rejected outright.

Running behind a reverse proxy

If a reverse proxy such as nginx forwards the requests, the address the server sees applies to login lockout, blacklist, rate limiting and logging. It only accepts the forwarding header (X-Forwarded-For) from registered proxies — if your own proxy is not entered in trusted_proxies, every request counts as coming from it, and the blacklist blocks it in case of doubt.

Therefore enter your proxy in config.yaml:

trusted_proxies:
  - 192.168.1.5      # the address of the nginx forwarding to this server
  - 10.0.0.0/24      # or a network that only proxies come from

In nginx, the matching line is: proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

If the entry is missing, the server writes a warning to the log, and the system status shows a finding with the proxy's address.

TLS

AnnexGroup supports its own TLS certificates, ACME (Let's Encrypt) and the certmagic-based TLS manager. ACME is recommended for automatic renewal.

Something unclear or described wrong? Tell us — we will fix it. Your question shows us where the text falls short.