Skip to content
Chris edited this page Sep 5, 2026 · 4 revisions

first, install this service. on windows, you can run the following command in an elevated powershell prompt to automatically download and install the service.

irm https://raw.githubusercontent.com/shadow578/PostGraph-rs/refs/heads/main/scripts/Install-PostGraphService.ps1 | iex

on linux, you may use the sample systemd service in scripts/postgraph.service.

once installed, configure the service using the config cli: postgraph config <...>

Configure the SMTP Server

by default, the service will listen on port 25 of the loopback interface (127.0.0.1:25). unless your smtp client is running on the same machine, you'll need to change the listen address such that all interfaces are listened to (0.0.0.0:25). to do so, run postgraph config smtp setup --address "0.0.0.0:25". if you want to use a differnt port, the same command can be used, simply change the port number in the address.

Note: NEVER make PostGraph accessible over the internet! PostGraph should only be reachable from a trusted private network!

Configure TLS

if you want to use TLS, you'll need to provide a certificate and private key in PEM format. use this command to generate a self-signed certificate and private key:

openssl req -newkey rsa:2048 -x509 -sha256 -days 3650 -nodes -subj "/CN=localhost" -addext "subjectAltName=DNS:localhost,IP:127.0.0.1" -out my_cert.crt -keyout my_cert.key

then, configure the service to use the certificate and private key: postgraph config tls setup --certificate my_cert.crt --private-key my_cert.key. to update the certificate and private key, simply run the same command again with the new files.

Configure Authentication

by default, the procy does not require authentication, and will accept mail from any client. to change this, you can add users via the config cli: postgraph config auth user add <username> [password]. if you don't provide a password, a random one will be generated and printed to the console.

the username used during authentication must match the sender address of the mail being sent, and must be a valid mailbox in your tenant.

Configure Microsoft Entra App

create a new app registration in Microsoft Entra ID, give it a name ("postgraph" or whatever), and note the application (client) and directory (tenant) id. now, create a new client secret and note the value. to configure the service, use postgraph config graph setup --tenant-id <tenant_id> --client-id <client_id> --client-secret <client_secret>. if you need to update the client secret, run postgraph config graph setup --client-secret <new_client_secret>. the tenant and client id will remain the same.

for the simplest setup, simply grant the application the Mail.Send application permission, and then grant admin consent for the permission. this will allow the application to send mail as any user in the tenant. for more fine-grained control, use Exchange Online's RBAC for Applications to restrict the application to only send mail as specific users.

Configuring RBAC for Applications

to use RBAC for Applications, do not grant the Mail.Send application permission to the application. instead, run these commands to create a new service principal, assign it a management scope, and assign the Mail.Send role:

Connect-ExchangeOnline

# create a new service principal for the application
# you need to supply the application id and object id as they are listed under enterprise apps, not the app registration
New-ServicePrincipal -AppId "<app_id>" -ObjectId "<object_id>" -DisplayName "postgraph"
$sp = Get-ServicePrincipal -Identity "postgraph"

# create a new management scope.
# this command will simply include all mailboxes, but you can also restrict it to specific mailboxes or groups if you want.
New-ManagementScope -Name "postgraph-scope" -RecipientRestrictionFilter { RecipientTypeDetails -eq "UserMailbox" -or RecipientTypeDetails -eq "SharedMailbox" }

# now, we assign postgraphthe Mail.Send role for the management scope we just created
New-ManagementRoleAssignment -Name "postgraph-role" -Role "Application SMTP.SendAsApp" -App $sp -CustomResourceScope "postgraph-scope"

# you can verify if a mailbox is in-scope with this command.
# it should show InScope = true.
Test-ServicePrincipalAuthorization -Identity $sp -Resource "you@example.com"

Clone this wiki locally