Configuring Dovecot Sieve for Server‑Side Email Filtering
Learn how to enable Dovecot’s Sieve plugin, write a simple filter script, and verify its execution while avoiding common pitfalls.
17 Jul 2026, 19:16 UTC

Useful answer
Dovecot includes the Sieve language for server‑side email filtering. When enabled, the local delivery agent (LDA) runs each incoming message through a user‑defined Sieve script that can file, forward, discard, or rewrite mail without requiring the client to process it.
Worked configuration example
First, make sure the sieve plugin is loaded in dovecot.conf:
plugin {
sieve = ~/.dovecot.sieve
sieve_dir = ~/sieve
}
The sieve setting points to the active script file; sieve_dir is where Dovecot looks for compiled .svbin binaries.
Create a simple script that moves messages from a mailing list to a folder named MailingList:
# ~/.dovecot.sieve
require ["fileinto"];
if header :contains "List-Id" "" {
fileinto "MailingList";
stop;
}
Set the file owned by the dovecot user (or the user’s UID) and readable:
chown dovecot:dovecot ~/.dovecot.sieve
chmod 600 ~/.dovecot.sieve
Reload Dovecot to apply the change:
sudo systemctl reload dovecot
Limits and considerations
- Sieve runs at delivery time only; it cannot act on mail already stored in the mailbox.
- Complex scripts with many regular expressions or nested loops increase CPU usage and can add latency to message delivery.
- The interpreter sandbox blocks file system access outside the script, preventing direct reads or writes to arbitrary files.
- Only one active script per user is used by default; additional scripts must be included via
includedirectives.
Common mistakes and verification
- Forgetting to enable the sieve plugin – delivery will bypass filtering and messages stay in the inbox.
- Incorrect file permissions – if dovecot cannot read the script, logs show “permission denied” and the message is deferred or bounced.
- Syntax errors in the script – Dovecot logs a sieve compile error and silently fails to file the message.
To verify that Sieve is working:
- Check that the plugin appears in
dovecot -noutput: - Send a test message that matches the rule (e.g., with a List-Id header) and confirm it appears in the
MailingListfolder via an IMAP client. - Inspect the mail log for entries like:
- If the message is not filed, look for “sieve: script not found” or “sieve: permission denied” in
/var/log/maillogor/var/log/dovecot.log.
dovecot -n | grep sieve
sieve: script executed: ~/.dovecot.sieve
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.