Hermes Mail Suite

Your entire mail stack.
One hardened daemon.

Hermes replaces Postfix, Dovecot, rspamd, and ClamAV with a single privilege-separated mail server written in C. SMTP, IMAP, anti-spam, and antivirus in one suite. Its only dependency is OpenSSL.

Hermes Mail Suite: a winged unicorn carrying mail past Greek columns, a nod to Hermes the messenger god of fast, reliable delivery.
4-in-1SMTP · IMAP · anti-spam · AV
1dependency (OpenSSL)
seccompon every network parser
Ed25519DKIM, MTA-STS, DANE built in

You should not need a gigabyte of RAM to scan an attachment. Hermes reads ClamAV's signature databases directly, with no clamd daemon running.

The problem

Running mail should not mean running five servers.

A self-hosted mail server is usually four or five daemons glued together: an MTA, an IMAP server, an anti-spam service, an antivirus daemon, and the wiring between them. Each has its own config language, its own attack surface, and its own appetite for memory. Antivirus alone can eat a gigabyte. One upgrade breaks the chain, and you are debugging milters at midnight.

  • Four or five configs to learn and keep in sync
  • Four or five attack surfaces to patch and harden
  • clamd alone can hold roughly a gigabyte of RAM
# a traditional mail box: four daemons to run and patch
$ ps -o rss,comm --sort=-rss
1048576 clamd        ; ~1 GB just to scan attachments
  58220 rspamd
  41008 dovecot
  33704 master       ; postfix

# four configs to learn, four attack surfaces to harden

One suite, not five

The whole stack, collapsed

Hermes is one privilege-separated daemon family instead of a tower of separate services. Fewer moving parts to run, patch, and harden.

The traditional stack Postfix SMTP / MTA Dovecot IMAP + ManageSieve rspamd anti-spam ClamAV (clamd) antivirus, ~1 GB resident milters / glue the wiring between them
Hermes Mail Suite Hermes SMTP · IMAP · anti-spam · AV one dependency: OpenSSL

Four or five separate services, each with its own config and attack surface, become one privilege-separated suite.

CapabilityHermes Mail SuiteTraditional stack
Services to runOne suite (one process family)4 to 5 daemons (MTA + IMAP + spam + AV + glue)
Runtime dependenciesOpenSSL onlyMany, across four projects
Antivirus footprintNo separate daemon; reads ClamAV signatures directlyclamd resident, ~1 GB RAM
Privilege separation● root supervisor, seccomp on every childVaries; bolted on, not uniform
Config surfacesOne coherent modelPostfix maps + Dovecot conf + rspamd + ClamAV
LanguageC (Alpine / musl), hand-rolled parsersMixed: C / C++ / Lua / scripts
Ed25519 DKIM●Add-on / often unavailable
MTA-STS + DANE/TLSA● built inExtra tooling / manual
ContainerOne small Alpine imageMultiple images or packages

"Traditional stack" means Postfix plus Dovecot plus rspamd plus ClamAV, the common self-hosted combination. The ~1 GB clamd figure is the well-known resident footprint of the ClamAV daemon and is illustrative, not a benchmark. Each of those projects is mature and capable: the difference is how many moving parts you run and harden.

A complete mail stack

Everything a mail server needs, in one suite

One suite speaks every protocol a mail server needs, on the ports you already know.

:25 SMTP :587 submission :465 submission TLS :143 IMAP :993 IMAP TLS :4190 ManageSieve

SMTP + submission

Inbound SMTP on :25, authenticated submission on :587, and implicit-TLS submission on :465. The full sending and receiving path in one place.

IMAP + ManageSieve

IMAP on :143 and :993 for mailbox access, with ManageSieve on :4190 so users manage their own server-side filters.

Anti-spam engine

Greylisting, RBL/DNSBL and URIBL checks, FCrDNS, DKIM, SPF, and DMARC verification, heuristics, and a scoring engine. No rspamd to run alongside.

Antivirus, no clamd

Reads ClamAV signature databases directly and scans attachments as hash signatures, with a built-in auto-updater. Efficient known-malware blocking without the ~1 GB daemon.

Modern sender auth

DKIM signing with RSA and Ed25519, multi-signature DKIM verification so forwarded mail keeps passing DMARC, plus SPF and DMARC alignment and policy.

Modern transport security

MTA-STS and DANE/TLSA for authenticated, encrypted delivery, with SNI on outbound HTTPS fetches. Current-decade transport security without add-ons.

Antivirus without the daemon

Scan attachments without a gigabyte of clamd

Hermes consumes ClamAV’s official signature databases directly and scans attachments against them as hash signatures, so there is no ~1 GB clamd process running. A built-in auto-updater refreshes the signatures and hot-reloads the scanners. This is efficient blocking of exact, known-bad files. It is not heuristic detection of polymorphic or document malware, and you choose what happens on a match.

  • Reads ClamAV main.cvd and daily.cvd directly
  • No ~1 GB clamd daemon to run and feed
  • Built-in auto-updater hot-reloads the scanners
  • Per-match action: reject, quarantine, or tag
Auto-updater fetches signaturesClamAV main.cvd + daily.cvd, no clamd running
an attachment arrives
Hash-match against known-bad filesexact, known-malware signatures
Rejectbounce it
Quarantinehold it
Tagmark + deliver

Modern deliverability

Current-decade standards, on by default

The authentication and transport security that decides whether your mail lands, built in rather than bolted on.

DKIM RSA + Ed25519 Multi-signature DKIM verify SPF DMARC alignment + policy MTA-STS DANE / TLSA

Secure by construction

Hardened, and built for operators

Privilege separation

A root supervisor owns the listening sockets and TLS keys, forks one child per service, then drops every network-facing child to an unprivileged user. The privsep boundary is the primary security control.

seccomp on every parser

Each child is confined with seccomp, so a bug in a protocol or MIME parser stays inside a sandboxed, unprivileged process instead of becoming a host compromise.

Per-domain metrics

A simple rolling metrics.json with sent and received counts per domain over a 7-day window. Trivially read by a control panel, with no API to call.

Per-flow split logs

Separate auth.log, incoming.log, and outbound.log, so authentication, inbound, and outbound each have their own readable trail when you are diagnosing a problem.

Per-mailbox allowlists

Let specific senders or domains bypass filtering per mailbox, so the invoices from a known sender always land while everything else stays filtered.

Outbound abuse containment

Outbound spam detection with rate-based auto-suspend on an account, so a single compromised mailbox is contained before it burns your sending reputation.

How it stays safe

A bug in a parser is not a compromised host

Hermes is built OpenSMTPD-style around a privilege-separation boundary. The root supervisor holds the privileged sockets and the TLS keys and never parses untrusted input. Each network-facing service runs as its own unprivileged child under seccomp, so the most exposed code runs with the least power.

  • Root supervisor owns sockets and TLS keys only
  • One unprivileged child per service, dropped from root
  • seccomp confines every child that touches the network
  • The privsep boundary is the primary control, not an add-on
Root supervisorowns the listening sockets and TLS keys
forks one child per service
SMTP:25
Submission:587 / :465
IMAP:143 / :993
Filtersspam · AV
Each child drops privileges, then seccomp confines ita bug in a parser stays in an unprivileged, sandboxed process

See the config

One model for the whole suite

No Postfix maps, no Dovecot conf, no rspamd rules, no ClamAV setup to stitch together. This is illustrative, and inside Unicorn Panel it is written and reloaded for you.

# mail.conf · the whole suite, one config model
hostname    mx.acme.com
listen      smtp :25
listen      submission :587 :465
listen      imap :143 :993

mailbox sully@domain.com {
    active       yes
    password     $scram-sha-256...
    alias        sales
    quota        512m
    allow-domain stripe.com
}

Metrics without an API

A file your control panel can just read

Hermes writes a simple metrics.json with per-domain sent and received counts over a rolling 7-day window. No exporter to run, no API to call.

# metrics.json · per-domain, rolling 7-day window
{
  "acme.com":    { "sent": 1240, "received": 8392 },
  "example.net": { "sent": 312,  "received": 1507 },
  "updated":     "2026-06-25T11:00:00Z"
}

Who it is for

Full control, without the operational bloat

Self-hosters and homelabs

Run real mail for your own domains without standing up and babysitting five separate daemons.

Small hosting providers

Multi-domain hosting, per-domain DKIM and metrics, and outbound abuse containment, in one suite that is easy to reason about.

Privacy-focused operators

A tiny attack surface and one dependency mean fewer moving parts to trust and fewer things to patch.

How to get it

Hermes ships with Unicorn Panel

Hermes Mail Suite is exclusive to Unicorn Panel. Enable the email role and the panel installs it, writes the config, manages mailboxes and domains from the UI, and keeps it updated. There is nothing separate to download or babysit.

Get Unicorn Panel Explore the Unicorn Stack See email in the panel

Questions

Straight answers

Is it production-ready?

Yes. Hermes runs real mail in production: inbound SMTP, authenticated submission, IMAP, ManageSieve, anti-spam, and antivirus, all from one privilege-separated suite.

What does it depend on?

OpenSSL, and nothing else. The DNS stub resolver, every protocol parser, the key-value store, and MIME handling are all hand-rolled. There is no Python, no Lua, and no separate milters to wire together.

How does antivirus work without ClamAV’s daemon?

Hermes reads ClamAV’s official signature databases (main.cvd and daily.cvd) directly and scans attachments against them as hash signatures, so there is no ~1 GB clamd process running. A built-in auto-updater refreshes the signatures and hot-reloads the scanners. This is efficient blocking of exact, known-bad files. It is not heuristic detection of polymorphic, macro, or document malware. You choose the action: reject, quarantine, or tag.

How does the anti-spam engine compare to rspamd?

Hermes has a built-in scoring engine: greylisting, RBL/DNSBL and URIBL checks, FCrDNS, DKIM, SPF, and DMARC verification, and heuristics. It covers the same job in one suite instead of a separate rspamd service. Per-mailbox allowlists let trusted senders bypass filtering.

Does it do DNSSEC?

Not itself. Hermes delegates DNSSEC validation to a local validating resolver by design, which keeps the suite small. Pair it with a validating resolver on the host for validated lookups.

Can it host multiple domains?

Yes. Multi-domain hosting is built in through a simple config tree, with per-domain DKIM keys and per-domain rolling metrics.

How do I migrate from Postfix and Dovecot?

Hermes speaks standard SMTP and IMAP, and inside Unicorn Panel the email role handles cross-server mailbox migration with live progress and an atomic cut-over. You point it at your domains and mailboxes rather than rebuilding four configs by hand.

What platforms does it run on?

Alpine Linux and musl. It is container-native: it ships as a small Alpine image, runs on host networking, binds the privileged ports as root, and drops every network-facing child to an unprivileged user.

One suite for the mail you trust people with.

SMTP, IMAP, anti-spam, and antivirus in one privilege-separated C daemon. One dependency: OpenSSL.