]> git.proxmox.com Git - pmg-docs.git/blob - pmg-administration.adoc
add pmg specifics to resolv.conf documentation
[pmg-docs.git] / pmg-administration.adoc
1 Administration
2 ==============
3
4 The Administration GUI allows you to do common tasks
5 such as updating software packages, managing quarantine, viewing service
6 status, and managing mail queues. It also provides server statistics in
7 order to verify server health.
8
9
10 Server Administration
11 ---------------------
12
13 Server status
14 ~~~~~~~~~~~~~
15
16 [thumbnail="pmg-gui-server-status.png", big=1]
17
18 This page shows server statistics about CPU, memory, disk and network
19 usage. You can select the displayed time span on the upper right.
20
21 Administrators can open a terminal window using the 'Console'
22 button. It is also possible to trigger a server 'Restart' or
23 'Shutdown'.
24
25
26 Services
27 ~~~~~~~~
28
29 [thumbnail="pmg-gui-service-status.png", big=1]
30
31 This panel lists all major services used for mail processing and
32 cluster synchronization. If necessary, you can start, stop or restart
33 them. The 'Syslog' button shows the system log filtered for the
34 selected service.
35
36 Please note that {pmg} uses {systemd} to manage services, so you can
37 also use the standard `systemctl` command line tool to manage or view
38 service status, for example:
39
40 -----
41 systemctl status postfix
42 -----
43
44
45 Updates
46 ~~~~~~~
47
48 [thumbnail="pmg-gui-updates.png", big=1]
49
50 We release software updates on a regular basis, and it is recommended
51 to always run the latest available version. This page shows the
52 available updates, and administrators can run an upgrade by pressing
53 the 'Upgrade' button.
54
55 See section xref:pmg_package_repositories[Package Repositories] for
56 details abaout available package repositories.
57
58
59 Syslog and Tasks
60 ~~~~~~~~~~~~~~~~
61
62 [thumbnail="pmg-gui-syslog.png", big=1]
63
64 The syslog page gives you a quick real-time log view. You can use the
65 xref:pmg_tracking_center[Tracking Center] to search the logs.
66
67
68 Quarantine
69 ----------
70
71 Spam
72 ~~~~
73
74 [thumbnail="pmg-gui-spam-quarantine.png", big=1]
75
76 This panel lets you inspect the mail quarantine. Emails can be safely
77 previewed and if desired, delivered to the original user.
78
79 The email preview on the web interface is very secure as malicious
80 code (attacking your operating system or email client) is removed by
81 {pmg}.
82
83
84 Virus
85 ~~~~~
86
87 Allows administrators to inspect quarantined virus mails.
88
89
90 Attachment
91 ~~~~~~~~~~
92
93 Allows administrators to inspect quarantined mails and download their
94 attachments or deliver/delete them.
95
96 NOTE: Use the options of the 'Remove attachment' action to control the Attachment Quarantine.
97
98
99 [[pmg_userblackwhitelist]]
100 User White- and Blacklist
101 ~~~~~~~~~~~~~~~~~~~~~~~~~
102
103 This is mostly useful to debug or verify white- and blacklist user
104 settings. The administrator should not change these values because
105 users can manage this themselves.
106
107
108 [[pmg_tracking_center]]
109 Tracking Center
110 ---------------
111
112 [thumbnail="pmg-gui-tracking-center.png", big=1]
113
114 Email processing is a complex task and involves several service
115 daemons. Each daemon logs information to the syslog service. The
116 problem is that a server analyzes many emails in parallel, so it is
117 usually very hard to find all logs corresponding to a specific mail.
118
119 The Tracking Center simplifies the search for
120 emails dramatically. We use highly optimized and safe Rust footnote:[A language
121 empowering everyone to build reliable and efficient software.
122 https://www.rust-lang.org/] code to search the available syslog data. This is
123 very fast and powerful, and works for sites processing several million emails
124 per day.
125
126 The result is a list of received mails, including the following data:
127
128 [cols="s,5d"]
129 |====
130 |Time | Timestamp of first found syslog entry.
131 |From | Envelope 'From' address (the sender).
132 |To | The email receiver address.
133 |Status | Delivery status.
134 |Syslog | The corresponding syslog entries are shown if you double click such
135 entry, or if you press the '+' button on the left.
136 |====
137
138 You can specify filters, and most importantly you can set
139 a 'Start' and 'End' time. By default the start time is set to one hour
140 ago. If you still get too many entries, you can try to restrict
141 the search to a specific sender or receiver address, or search for a
142 specific text in the logs ('Filter' entry).
143
144 NOTE: Search is faster if you use a shorter time interval.
145
146 The 'Status' field summarizes what happened with an email. {pmg} is a
147 mail proxy, meaning that the proxy receives mails from outside,
148 processes them and finally sends the result to the receiver.
149
150 The first phase is receiving the mail. The proxy may reject the mail
151 early, or instead accepts the mail and feeds it into the filter. The filter
152 rules can block or accept the mail.
153
154 In the second phase, accepted mails need to be delivered to the
155 receiver. This action may also fail or succeed. 'Status'
156 combines the result from the first and second phase.
157
158 [options="header",cols="2s,1d,5d"]
159 |====
160 |Status |Phase |Description
161 |rejected |1 | Email rejected (e.g. sender IP is listed on a IP blacklist)
162 |greylisted |1 | Email temporarily rejected by greylisting
163 |queued/deferred |1 | Internal Email was queued, still trying to deliver
164 |queued/bounced |1 | Internal Email was queued but not accepted by the target email server (for example user unknown)
165 |queued/delivered |1 | Internal Email was queued and delivered
166 |quarantine |1 | Email was moved to quarantine
167 |blocked |1 | Email was blocked by filter rules
168 |accepted/deferred |2 | Email accepted, still trying to deliver
169 |accepted/bounced |2 | Email accepted but not accepted by the target email server (for example user unknown)
170 |accepted/delivered |2 | Email accepted and delivered
171 |====
172
173 [[postfix_queue_administration]]
174 Postfix Queue Administration
175 ----------------------------
176
177 [thumbnail="pmg-gui-queue-admin-summary.png", big=1]
178
179 Mail-queues are one of the central concepts of the SMTP protocol. Once a
180 mailserver accepts a mail for further processing it saves it to a queue.
181 After the mail is either relayed to another system, stored locally
182 or discarded, it is deleted from the local mail-queue.
183
184 If immediate processing is not possible, for example because a downstream
185 mailserver is not reachable, the mail remains on the queue for later
186 processing.
187
188 The 'Queue Administration' panel provides a summary about the current state
189 of the postfix mail-queue, similar to the 'qshape (1)' command-line utility.
190
191 It shows domains for which mails were not delivered, and how long they have
192 been queued.
193
194 The three Action Buttons on top provide the most common queue operations:
195
196 'Flush Queue'::
197
198 Attempt to deliver all currently queued mail, for example if a downstream
199 server has become available again.
200
201 'Delete All Messages'::
202
203 Delete all currently queued mail, for example if the queue contains only spam.
204
205 'Discard address verification database'::
206
207 Clear the recipient verification cache.
208
209 A sudden increase of queued mails should be checked out closely. It can
210 indicate issues connecting to downstream servers.
211 This can also mean that one of the servers for which you relay emails sends
212 spam itself.
213
214 Deferred Mail
215 ~~~~~~~~~~~~~
216 [thumbnail="pmg-gui-queue-admin-deferred.png"]
217
218 In the 'Deferred Mail' tab you can examine each deferred email separately.
219 Besides providing the contact information about sender and receiver you can
220 also check the reason for an email being still queued.
221
222 You can view the complete headers and filter by sender or receiver of queued up
223 mails.
224
225 Here you can also flush or delete each deferred email independently.