Skip to main content

Network and sending email

Your addresses​

Your server's card, VPS section of your client area, shows two addresses:

AddressIts role
IPv4 addressthe address at which your visitors reach your sites over IPv4 (ports 80 and 443, under your domain names) and you reach your server over SSH, on the port from your card
IPv6 addressyour server's public address, which belongs to it alone

These two addresses are the ones for your A and AAAA DNS records (see Putting a site or an application online).

Your server's ports​

PortWhat arrives there
80 and 443your sites and your APIs, over HTTP and HTTPS, under your server's name and the domains you have added to it
the SSH connection port from your cardyour SSH access, over IPv4
all ports, over IPv6whatever you choose to open on your IPv6 address

Your IPv6 address belongs entirely to you: your firewall decides what it exposes.

Your firewall​

Open only what your services expose to the public. With ufw, shipped with Ubuntu:

apt install ufw
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp # SSH
ufw allow 80/tcp # HTTP
ufw allow 443/tcp # HTTPS
ufw enable
ufw status verbose

Keep port 22 open: it is through this port that your SSH connection arrives on your server, whatever port is shown in your card. Your databases stay listening on localhost, and you reach them through an SSH tunnel.

Anti-DDoS protection​

Always-on network filtering stops flood attacks before they reach your server. It works continuously, with no setup on your part.

Traffic​

Your VPS Pro has no monthly traffic limit: your visitors, your downloads and your outbound backups flow without a meter.

Sending email from your server​

Your applications send their email (sign-up, forgotten password, notifications, invoices) through an authenticated SMTP relay, on port 587 with STARTTLS. This is also what gives your email the best deliverability: it leaves from a service that carries your domain's reputation and signatures.

Two ways to do it:

  • from an address you already have, with your current email provider;
  • from Simafri Suite, the professional email at your own domain name, when your volumes grow (see the Simafri Suite documentation).

The settings in your application, for example for a .env file:

MAIL_HOST=smtp.your-provider.com
MAIL_PORT=587
MAIL_ENCRYPTION=tls
MAIL_USERNAME=notifications@my-company.com
MAIL_PASSWORD=...

For the system tools (cron alerts, unattended-upgrades), a small relay such as msmtp, or Postfix configured as a "satellite", forwards everything to the same SMTP relay.

Frequently asked questions​

My application cannot send email.​

Set it to port 587 with the authentication of your email account. To test the relay from your server:

openssl s_client -starttls smtp -connect smtp.your-provider.com:587

A banner that starts with 220 shows that the connection goes through; all that remains is to check the username and the password in your application.

How do my emails stay out of spam?​

By leaving from your SMTP relay with an address on your domain, whose DNS zone publishes the SPF, DKIM and DMARC records of that relay. Simafri Suite gives you these records when you set up your domain.

Can my server reach external services?​

Yes: your applications call APIs, package repositories and services all over the world, over IPv4 as well as IPv6.