Documentation
Security settings
Under Administration → Security you configure the server's security profile.
Security presets
- Balanced: balanced settings for production operation.
- Strict: shorter session lifetimes, stricter rate limiting, enforced TLS.
- Development: less strict limits for test environments.
Features
- IP blocking after repeated failed attempts
- Blacklist, also for network ranges (see below)
- View login attempts
- Manage DKIM keys
- Check TLS/MTA-STS policies
- Run audit checks manually
Blacklist with network ranges
The blacklist under Administration → Security accepts individual
addresses and whole network ranges — IPv4 and IPv6. Allowed is an address
like 203.0.113.7, a range in CIDR notation like 203.0.113.0/24 or
2001:db8::/32.
The server guards against locking yourself out: your own address cannot be
blocked, not even as part of a network range — and loopback addresses as
well as ranges that cover everything (0.0.0.0/0, ::/0) are rejected
outright.
Running behind a reverse proxy
If a reverse proxy such as nginx forwards the requests, the address the
server sees applies to login lockout, blacklist, rate limiting and logging.
It only accepts the forwarding header (X-Forwarded-For) from registered
proxies — if your own proxy is not entered in trusted_proxies, every
request counts as coming from it, and the blacklist blocks it in case of
doubt.
Therefore enter your proxy in config.yaml:
trusted_proxies:
- 192.168.1.5 # the address of the nginx forwarding to this server
- 10.0.0.0/24 # or a network that only proxies come from
In nginx, the matching line is:
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
If the entry is missing, the server writes a warning to the log, and the system status shows a finding with the proxy's address.
TLS
AnnexGroup supports its own TLS certificates, ACME (Let's Encrypt) and the certmagic-based TLS manager. ACME is recommended for automatic renewal.
Something unclear or described wrong? Tell us — we will fix it. Your question shows us where the text falls short.