# Managed by Ansible — do not edit manually protocols = imap lmtp # Plaintext auth is fine — connections come from within Docker or via # Traefik TLS termination, never plain from the internet disable_plaintext_auth = no auth_mechanisms = plain login passdb { driver = passwd-file args = /etc/dovecot/passwd } userdb { driver = passwd-file args = /etc/dovecot/passwd default_fields = uid=5000 gid=5000 home=/var/mail/%u } mail_location = maildir:/var/mail/%u/Maildir mail_uid = 5000 mail_gid = 5000 service imap-login { inet_listener imap { port = 143 } # IMAPS disabled — Traefik terminates TLS on port 993 and forwards plain IMAP inet_listener imaps { port = 0 } } # LMTP listener for fetchmail delivery — reachable on mail_internal network only service lmtp { inet_listener lmtp { address = * port = 24 } } # Strip domain from LMTP recipient so fetchmail's "ml@dovecot" resolves to user "ml" protocol lmtp { auth_username_format = %Ln } # SSL disabled — Traefik handles TLS ssl = no