Hermes Mail Suite
Your entire mail stack.
One hardened daemon.
Hermes replaces Postfix, Dovecot, rspamd, and ClamAV with a single privilege-separated mail server written in C. SMTP, IMAP, anti-spam, and antivirus in one suite. Its only dependency is OpenSSL.

You should not need a gigabyte of RAM to scan an attachment. Hermes reads ClamAV's signature databases directly, with no clamd daemon running.
The problem
Running mail should not mean running five servers.
A self-hosted mail server is usually four or five daemons glued together: an MTA, an IMAP server, an anti-spam service, an antivirus daemon, and the wiring between them. Each has its own config language, its own attack surface, and its own appetite for memory. Antivirus alone can eat a gigabyte. One upgrade breaks the chain, and you are debugging milters at midnight.
- Four or five configs to learn and keep in sync
- Four or five attack surfaces to patch and harden
- clamd alone can hold roughly a gigabyte of RAM
# a traditional mail box: four daemons to run and patch $ ps -o rss,comm --sort=-rss 1048576 clamd ; ~1 GB just to scan attachments 58220 rspamd 41008 dovecot 33704 master ; postfix # four configs to learn, four attack surfaces to harden
One suite, not five
The whole stack, collapsed
Hermes is one privilege-separated daemon family instead of a tower of separate services. Fewer moving parts to run, patch, and harden.
Four or five separate services, each with its own config and attack surface, become one privilege-separated suite.
| Capability | Hermes Mail Suite | Traditional stack |
|---|---|---|
| Services to run | One suite (one process family) | 4 to 5 daemons (MTA + IMAP + spam + AV + glue) |
| Runtime dependencies | OpenSSL only | Many, across four projects |
| Antivirus footprint | No separate daemon; reads ClamAV signatures directly | clamd resident, ~1 GB RAM |
| Privilege separation | ● root supervisor, seccomp on every child | Varies; bolted on, not uniform |
| Config surfaces | One coherent model | Postfix maps + Dovecot conf + rspamd + ClamAV |
| Language | C (Alpine / musl), hand-rolled parsers | Mixed: C / C++ / Lua / scripts |
| Ed25519 DKIM | ● | Add-on / often unavailable |
| MTA-STS + DANE/TLSA | ● built in | Extra tooling / manual |
| Container | One small Alpine image | Multiple images or packages |
"Traditional stack" means Postfix plus Dovecot plus rspamd plus ClamAV, the common self-hosted combination. The ~1 GB clamd figure is the well-known resident footprint of the ClamAV daemon and is illustrative, not a benchmark. Each of those projects is mature and capable: the difference is how many moving parts you run and harden.
A complete mail stack
Everything a mail server needs, in one suite
One suite speaks every protocol a mail server needs, on the ports you already know.
SMTP + submission
Inbound SMTP on :25, authenticated submission on :587, and implicit-TLS submission on :465. The full sending and receiving path in one place.
IMAP + ManageSieve
IMAP on :143 and :993 for mailbox access, with ManageSieve on :4190 so users manage their own server-side filters.
Anti-spam engine
Greylisting, RBL/DNSBL and URIBL checks, FCrDNS, DKIM, SPF, and DMARC verification, heuristics, and a scoring engine. No rspamd to run alongside.
Antivirus, no clamd
Reads ClamAV signature databases directly and scans attachments as hash signatures, with a built-in auto-updater. Efficient known-malware blocking without the ~1 GB daemon.
Modern sender auth
DKIM signing with RSA and Ed25519, multi-signature DKIM verification so forwarded mail keeps passing DMARC, plus SPF and DMARC alignment and policy.
Modern transport security
MTA-STS and DANE/TLSA for authenticated, encrypted delivery, with SNI on outbound HTTPS fetches. Current-decade transport security without add-ons.
Antivirus without the daemon
Scan attachments without a gigabyte of clamd
Hermes consumes ClamAV’s official signature databases directly and scans attachments against them as hash signatures, so there is no ~1 GB clamd process running. A built-in auto-updater refreshes the signatures and hot-reloads the scanners. This is efficient blocking of exact, known-bad files. It is not heuristic detection of polymorphic or document malware, and you choose what happens on a match.
- Reads ClamAV main.cvd and daily.cvd directly
- No ~1 GB clamd daemon to run and feed
- Built-in auto-updater hot-reloads the scanners
- Per-match action: reject, quarantine, or tag
Modern deliverability
Current-decade standards, on by default
The authentication and transport security that decides whether your mail lands, built in rather than bolted on.
Secure by construction
Hardened, and built for operators
Privilege separation
A root supervisor owns the listening sockets and TLS keys, forks one child per service, then drops every network-facing child to an unprivileged user. The privsep boundary is the primary security control.
seccomp on every parser
Each child is confined with seccomp, so a bug in a protocol or MIME parser stays inside a sandboxed, unprivileged process instead of becoming a host compromise.
Per-domain metrics
A simple rolling metrics.json with sent and received counts per domain over a 7-day window. Trivially read by a control panel, with no API to call.
Per-flow split logs
Separate auth.log, incoming.log, and outbound.log, so authentication, inbound, and outbound each have their own readable trail when you are diagnosing a problem.
Per-mailbox allowlists
Let specific senders or domains bypass filtering per mailbox, so the invoices from a known sender always land while everything else stays filtered.
Outbound abuse containment
Outbound spam detection with rate-based auto-suspend on an account, so a single compromised mailbox is contained before it burns your sending reputation.
How it stays safe
A bug in a parser is not a compromised host
Hermes is built OpenSMTPD-style around a privilege-separation boundary. The root supervisor holds the privileged sockets and the TLS keys and never parses untrusted input. Each network-facing service runs as its own unprivileged child under seccomp, so the most exposed code runs with the least power.
- Root supervisor owns sockets and TLS keys only
- One unprivileged child per service, dropped from root
- seccomp confines every child that touches the network
- The privsep boundary is the primary control, not an add-on
See the config
One model for the whole suite
No Postfix maps, no Dovecot conf, no rspamd rules, no ClamAV setup to stitch together. This is illustrative, and inside Unicorn Panel it is written and reloaded for you.
# mail.conf · the whole suite, one config model hostname mx.acme.com listen smtp :25 listen submission :587 :465 listen imap :143 :993 mailbox sully@domain.com { active yes password $scram-sha-256... alias sales quota 512m allow-domain stripe.com }
Metrics without an API
A file your control panel can just read
Hermes writes a simple metrics.json with per-domain sent and received counts over a rolling 7-day window. No exporter to run, no API to call.
# metrics.json · per-domain, rolling 7-day window { "acme.com": { "sent": 1240, "received": 8392 }, "example.net": { "sent": 312, "received": 1507 }, "updated": "2026-06-25T11:00:00Z" }
Who it is for
Full control, without the operational bloat
Self-hosters and homelabs
Run real mail for your own domains without standing up and babysitting five separate daemons.
Small hosting providers
Multi-domain hosting, per-domain DKIM and metrics, and outbound abuse containment, in one suite that is easy to reason about.
Privacy-focused operators
A tiny attack surface and one dependency mean fewer moving parts to trust and fewer things to patch.
How to get it
Hermes ships with Unicorn Panel
Hermes Mail Suite is exclusive to Unicorn Panel. Enable the email role and the panel installs it, writes the config, manages mailboxes and domains from the UI, and keeps it updated. There is nothing separate to download or babysit.
Get Unicorn Panel Explore the Unicorn Stack See email in the panel
Questions
Straight answers
Is it production-ready?
Yes. Hermes runs real mail in production: inbound SMTP, authenticated submission, IMAP, ManageSieve, anti-spam, and antivirus, all from one privilege-separated suite.
What does it depend on?
OpenSSL, and nothing else. The DNS stub resolver, every protocol parser, the key-value store, and MIME handling are all hand-rolled. There is no Python, no Lua, and no separate milters to wire together.
How does antivirus work without ClamAV’s daemon?
Hermes reads ClamAV’s official signature databases (main.cvd and daily.cvd) directly and scans attachments against them as hash signatures, so there is no ~1 GB clamd process running. A built-in auto-updater refreshes the signatures and hot-reloads the scanners. This is efficient blocking of exact, known-bad files. It is not heuristic detection of polymorphic, macro, or document malware. You choose the action: reject, quarantine, or tag.
How does the anti-spam engine compare to rspamd?
Hermes has a built-in scoring engine: greylisting, RBL/DNSBL and URIBL checks, FCrDNS, DKIM, SPF, and DMARC verification, and heuristics. It covers the same job in one suite instead of a separate rspamd service. Per-mailbox allowlists let trusted senders bypass filtering.
Does it do DNSSEC?
Not itself. Hermes delegates DNSSEC validation to a local validating resolver by design, which keeps the suite small. Pair it with a validating resolver on the host for validated lookups.
Can it host multiple domains?
Yes. Multi-domain hosting is built in through a simple config tree, with per-domain DKIM keys and per-domain rolling metrics.
How do I migrate from Postfix and Dovecot?
Hermes speaks standard SMTP and IMAP, and inside Unicorn Panel the email role handles cross-server mailbox migration with live progress and an atomic cut-over. You point it at your domains and mailboxes rather than rebuilding four configs by hand.
What platforms does it run on?
Alpine Linux and musl. It is container-native: it ships as a small Alpine image, runs on host networking, binds the privileged ports as root, and drops every network-facing child to an unprivileged user.
One suite for the mail you trust people with.
SMTP, IMAP, anti-spam, and antivirus in one privilege-separated C daemon. One dependency: OpenSSL.