Automate Mailbox Management with Dovecot Sieve: From Setup to Real‑World Scripts
Learn how to enable Dovecot’s Sieve filtering, write server‑side rules, and manage them via IMAP. A step‑by‑step example shows auto‑archiving newsletters and sending vacation replies, plus trade‑offs and best‑practice tips.
04 Sept 2025, 20:31 UTC

Problem: Manual Folder Management is a Pain
Most users rely on client‑side rules to move newsletters into a dedicated folder or reply automatically when away. This approach has two major drawbacks:
- Rules must be configured on every client, and clients may not support advanced filtering.
- When a user switches devices or loses a client, the rules vanish, leaving mail scattered.
For a mail administrator, the solution is to push the logic to the server so that all incoming mail is processed consistently, regardless of the client.
Thesis: Dovecot’s Sieve Plugin Provides a Robust, Server‑Side Solution
Dovecot ships with the sieve plugin, a mailbox filtering language that runs on the server before the message is delivered. It supports standard actions like fileinto, redirect, and discard, and extensions such as vacation and reject for advanced scenarios. Because the rules live on the server, they apply to every client, and administrators can manage them centrally.
1. Enabling Sieve in Dovecot
Open the global configuration file (usually
/etc/dovecot/dovecot.confor a file in/etc/dovecot/conf.d/). Add or verify the following lines:plugin = sieve sieve = /var/lib/dovecot/sieve sieve_global_path = /var/lib/dovecot/sieve/global.sieve•
plugin = sieveloads the module.
•sievepoints to the per‑user directory.
•sieve_global_pathallows a system‑wide default script.Restart Dovecot to apply the changes:
sudo systemctl restart dovecotVerify the plugin is loaded:
dovecot -n | grep sieve # Expected output: plugin = sieve
Permissions and Safety
Only root can edit dovecot.conf. The sieve directory should be owned by dovecot and readable by the service. Improper permissions can prevent the plugin from loading.
2. Writing and Deploying Sieve Scripts
Each user gets a default.sieve file in their mailbox directory (e.g., /var/mail/vhosts/example.com/alice/default.sieve). Dovecot compiles it to default.svbin automatically.
# Example: fileinto "News/"; keep;
To create a script:
- SSH into the mail server as the mail user or as root.
- Create or edit
default.sieve: - Set correct ownership (usually
alice:mail) and permissions (644). - Run
dovecot -nagain to confirm no syntax errors appear. Dovecot will re‑compile the script automatically on the next connection.
#!/usr/bin/env sieve
require ["fileinto", "vacation", "reject"];
# Auto‑archive newsletters
if header :contains "List-Id" "newsletter" {
fileinto "News/";
keep;
}
# Vacation auto‑reply
if address :is "to" "*" {
vacation "Out of office until 2026‑12‑31. I’ll reply when I return."
}
Key points:
requirelists extensions needed; omit it for plain Sieve.fileintomoves the message;keeppreserves a copy in the original folder.- Vacation replies are sent once per sender per day unless
vacationis configured withmax-per-dayormax-per-sender.
3. Managing Scripts via IMAP (X‑SIEVE)
Administrators can avoid SSH by using the IMAP X‑SIEVE extension. Many webmail interfaces expose a “Sieve” tab. Steps:
- Log in to the user’s mailbox via an IMAP client that supports
X‑SIEVE(e.g., Thunderbird, Outlook). - Navigate to the Sieve management section.
- Upload or edit
default.sievedirectly. - Dovecot validates the script and compiles it on the fly.
This method is convenient for users who prefer a web interface and keeps the server configuration untouched.
4. Worked Example: Auto‑Archive Newsletters & Auto‑Reply
Assume we have a user bob@example.com who receives a flood of newsletters. We want:
- All messages with a
List-Idheader containing “newsletter” to go intoNews/. - When Bob is away, automatically send a vacation reply.
Script (saved as bob/default.sieve):
require ["fileinto", "vacation"];
if header :contains "List-Id" "newsletter" {
fileinto "News/";
keep;
}
vacation "I’m away until 2026‑12‑31. I’ll get back to you then."
Deploy it by copying the file into Bob’s mailbox directory and ensuring ownership:
sudo chown bob:mail /var/mail/vhosts/example.com/bob/default.sieve
sudo chmod 644 /var/mail/vhosts/example.com/bob/default.sieve
Test:
- Send a test email with
List-Id: newsletter@example.comtobob@example.com. - Open an IMAP client and verify the message appears in
News/. - Send a second test email from a different address and confirm the vacation reply is received.
5. Trade‑Offs and Limitations
- Syntax Strictness: A single typo in a Sieve script will cause the entire file to be ignored. Always validate with
dovecot -nor an online Sieve validator before deploying. - Extension Dependencies: The
vacationandrejectextensions require the corresponding Dovecot plugins (e.g.,plugin = sieve-vacation). Missing plugins break the script. - Performance Impact: Complex scripts with many conditions can add latency to delivery. Keep scripts lean and test performance on a staging server.
- User Control: Some administrators may want to allow users to override or disable Sieve. Dovecot can be configured to disable the plugin per user via ACLs.
6. Actionable Next Steps
- Enable the Sieve plugin in
dovecot.confand restart Dovecot. - Create a global
global.sieveif you want system‑wide defaults. - Distribute a starter script to users or use
X‑SIEVEto let them create their own. - Monitor
/var/log/dovecot.logfor messages likescript compiled successfullyor syntax errors. - Periodically audit user scripts to ensure they still meet policy and performance requirements.
By centralizing filtering logic with Dovecot’s Sieve, you reduce client configuration drift, improve consistency, and free your users from repetitive manual sorting.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.