Hardening a Self-Hosted Mail Server: fail2ban, Postfix, and Dovecot

Update (2026-06-05): the action = firewallcmd-rich-rules shown below has since been replaced with fail2ban’s native nftables action. With ~2000 banned addresses the firewalld variant needed 90 seconds to stop and was killed with SIGABRT — it removes each ban as an individual rich rule, and any that firewalld had already dropped during a reload wait for a timeout. See the homelab guide for the current configuration. Everything else here still applies.

[Read More]