How it works

Observe first, prove abuse, then throttle with control.

AegisMX is built around transparent evidence collection and deliberate enforcement, so operators can protect reputation without guessing.

1. Route or mirror telemetry

Send outbound mail through the relay profile or collect events from AegisWatch agents on hosting nodes.

2. Score sender behavior

Track spikes, direct-to-MX attempts, authentication failures, bounces, high-risk senders, and reputation changes.

3. Keep mail transparent

Transparent relay mode avoids sender-visible and recipient-visible modifications while evidence is collected.

4. Review audit trails

Use delivery logs, message traces, policy events, and tenant context to confirm what happened.

5. Apply rate limits

Throttle by tenant, source IP, sender, route, or agent when abuse is confirmed.

6. Enforce when needed

Queue firewall, SMTP limiter, or bypass-blocking actions with dry-run before enforce mode.

Deployment model

AegisMX runs with Docker Compose, PostgreSQL, a secure web console, Postfix relay, Rspamd, ClamAV, and optional observability. The production pipeline includes tests and security scanners before deploy.

First-login safe

Admins can deploy with HTTPS on 443 using ACME or self-signed TLS, then sign in through the secure browser login and finish hostname or proxy configuration.