Proxmox, known for developing the Proxmox Virtual Environment distribution for deploying virtual server infrastructures, has announced the release of Proxmox Mail Gateway 8.0. Proxmox Mail Gateway is presented as a ready-made solution for quickly establishing a system to monitor email traffic and protect the internal mail server.
The installation ISO image is available for free download. Distribution-specific components are open under the AGPLv3 license. For updates, there is both a paid Enterprise repository and two free repositories that differ in the level of update stabilization. The system component of the distribution is based on the Debian package base. Components of Proxmox Mail Gateway can be installed on top of already running servers Debian-based systems.
Proxmox Mail Gateway operates as a proxy server, serving as a gateway between the external network and the internal mail proxy server systems based on MS Exchange, Lotus Domino, or Postfix. It allows management of all incoming and outgoing email flows. All correspondence logs are analyzed and available for review through a web interface. Both graphs to assess overall dynamics and various reports and forms for obtaining information about specific emails and delivery status are provided. Cluster configurations are supported for high availability (operating a synchronized backup server, with data synchronized through an SSH tunnel) or load balancing.

A complete set of tools is provided to ensure protection, spam filtering, phishing, and virus prevention. ClamAV and Google Safe Browsing are used to block malicious attachments, and a comprehensive approach based on SpamAssassin is offered to combat spam, including support for sender verification, SPF, DNSBL, greylisting, Bayesian classification, and blocking based on spammer URI databases. For legitimate correspondence, a flexible filtering system is provided, allowing rules to be set for mail processing based on domain, recipient/sender, time of receipt, and content type.
Key innovations:
- Transition to Debian 12 package base has been completed. The Linux kernel has been updated to version 6.2. Updated versions of OpenZFS 2.1.12 and PostgreSQL 15.3 are available.
- An alternative installer with a text interface has been proposed, which can be used on very new or very old hardware where issues arise in launching the graphical installer based on the GTK library. The installer is written in Rust using the Cursive library.
- A script pmg7to8 has been added to identify incompatibilities in settings before upgrading from the 7.x branch.
- The spam filtering system has been updated to SpamAssassin 4.0.0, and the antivirus package has been updated to ClamAV 1.0.1. In new installations of SpamAssassin, Bayesian classification and automatic whitelisting plugins are disabled by default.
- The ability to block an account after too many unsuccessful attempts at two-factor authentication or entering incorrect one-time passwords (TOTP) has been added. The blocking is implemented to protect against situations where attackers have managed to learn the user’s password and are attempting to guess the verification code in the second stage of authentication. For two-factor authentication, the block is enabled for one hour, while for TOTP, it is permanent. To unblock, you can use the recovery access code or send a request to the administrator.
- The ethtool utility has been included.
- The dark theme implementation has been improved in the web interface. By default, advanced statistics filters are disabled. Protection against XSS attacks has been strengthened.
Source: opennet.ru
