Skip to content

Service · done-for-you

PowerMTA setup service,
done right the first time.

Hand us the server and the license; we hand back a clean, authenticated, hardened PowerMTA you can send from the same day — with SPF, DKIM, DMARC, virtual MTAs and a verified test. For legitimate, opt-in senders only.

The PowerMTA setup service is a done-for-you install and configuration of your own licensed PowerMTA, on your server, handed back working — authenticated, hardened, and proven with a verified test send — typically within one to two business days. It starts from €249 per server, you bring your own license, and it's strictly for legitimate, opt-in senders. If you'd rather run the deploy yourself, the same clean build is available as the one-time €799 Auto PMTA Configurator.

Why have it done for you

Installing PowerMTA is easy. Configuring it correctly is not.

Getting the PowerMTA binary onto a server takes minutes. Turning it into a setup that actually lands in the inbox is the part that defeats most people, because a production configuration touches a couple of hundred settings spread across the engine, DNS, authentication, transport security, the firewall, bounce and feedback handling, and per-provider throttling. Each of those is a place to be subtly wrong, and a subtle mistake — an SPF record over its lookup limit, a missing IPv6 reverse-DNS entry, a throttle set too high for a cold IP — usually doesn't throw an error. It just quietly sends your mail to spam.

That's the gap a done-for-you setup closes. Instead of spending a week reading documentation and learning which of those settings matter by watching your own deliverability suffer, you hand the build to someone who has done it many times and gets a server that's already authenticated, hardened and verified. The learning curve stops being your problem, and the cost of the mistakes you'd have made along the way — burned IPs, a damaged domain, weeks of recovery — never lands.

It's the same calculation behind any specialist work. You could read enough to wire your own building, but the value of an electrician isn't the wiring — it's knowing, from experience, every place it goes wrong. PowerMTA configuration is the same: the worth of the service is the failures it quietly prevents, not the commands it runs.

What's included

Everything to a verified first send

Not "we ran the installer." A reviewed, hardened configuration tuned to your IPs and domains, with authentication proven before you scale.

The work runs from a readiness check — confirming the OS, that outbound port 25 is open, and that your IPs aren't already listed — through the install on your license, a hardened configuration baseline mapped to your actual sending IPs, full authentication published and verified in DNS, and bounce and feedback-loop handling wired up. It ends where it should: a blacklist check and a guided test send whose headers we read together to confirm SPF, DKIM and DMARC all pass. You finish with a working server and a short operating doc, not a login and a shrug.

  • Server readiness check (OS, port 25, IP reputation)
  • PowerMTA installed on your license, on a clean supported server
  • Hardened /etc/pmta/config baseline — reviewed, not pasted
  • Virtual MTAs and IP pools mapped to your sending IPs
  • SPF, DKIM, DMARC and reverse DNS published and verified
  • Bounce / FBL handling wired up
  • Blacklist check + guided test send with header verification
  • A short handover doc so your team can operate it

What you keep

You own the result, not a rented box

A lot of "setup" offers leave you renting a server you can't see into — the configuration lives on someone else's terms, and if you leave, you start over. This service is built the other way around. At handover the server is yours, on your license, with a configuration that was reviewed rather than pasted, and a short doc your team can actually operate from. You can read it, audit it, change it, or hand it to a managed provider later without being locked to us.

That ownership matters more than it sounds. Email infrastructure tends to outlive the person who built it, and a configuration only one party understands becomes a liability the day something breaks or that party disappears. A clean, documented setup that any competent engineer can pick up is the difference between an asset and a dependency. The point of the handover doc is exactly that: to keep the platform operable by your own team rather than dependent on ours.

What the engineer catches

The mistakes a first-time setup makes

The reason a done-for-you setup pays off isn't mystery — it's pattern recognition. The same handful of mistakes sink most first-time builds, and an engineer who has seen them avoids each one before it costs you anything.

An SPF record built by hand tends to grow past its lookup limit and break alignment — the SPF PermError that quietly fails DMARC. DKIM gets generated but the published record doesn't match what's signing, so it fails on a body-hash mismatch nobody notices. IPv6 goes live without a reverse-DNS record, and strict receivers reject it on sight. Throttles get left at defaults that are far too high for a cold IP, so the first real send collects 421 deferrals. DMARC is flipped to p=reject before the sources are aligned, and the domain starts blocking its own mail. TLS is left half-configured and fails against receivers that now require it.

Individually each looks small. Together they're why a self-built server so often ends up in spam with no obvious reason, and why the symptom — mail going to spam — is so hard to diagnose after the fact. The setup service closes each one at build time, verifies the result with a real send, and hands you a server where these failures simply never had the chance to happen.

The path

Setup → tuning → managed

Start with a clean install. Grow into deliverability tuning and managed only if and when you need it — no lock-in.

Setup

Install & configure

One-time, per server. We stand up a clean, authenticated, hardened PowerMTA you can send from the same day.

from €249 / server

Tune

Configuration & deliverability

Per-provider throttling, stream separation, warm-up plan and accounting-log review once you're sending real volume.

scoped per engagement

Manage

Managed deliverability

Ongoing: clean IPs, real-time blacklist monitoring and tuning so mail keeps landing. The recurring layer.

monthly retainer

⌁ Tuning and managed continue into managed deliverability.

The honest difference

What separates this from the cheap setup sellers

Search for PowerMTA setup and the results fill with sellers promising "unlimited" sending, "100% inbox", cold-email infrastructure and cheap rotating IPs. We're a different thing on purpose. We require your own valid license, we set up permission-based sending only, and we won't attach our name to the kind of volume that gets IP ranges blocked. The configuration is built to keep a legitimate sender in the inbox for years, which is the opposite of what a blast-and-rebuild operation needs.

The honesty extends to what we'll promise. No setup, ours included, can guarantee the inbox — anyone claiming a "100% deliver rate" is selling a number that doesn't exist. What a correct setup guarantees is that you're authenticated and accepted, which is the entry ticket; placement after that is earned through reputation, list quality and engagement. We'd rather tell you that plainly than sell you a guarantee you'd later watch fail.

It's also why the constraint is a feature. A service that only works with licensed software and opt-in sending attracts the senders who plan to be around in a year, and the whole configuration is tuned for them. If you're looking for a way to send to a bought list without consequences, this isn't it — and that's deliberate.

What handover looks like

A finished server, proven before you scale

Handover isn't a login emailed over with a note saying it's done. It's a server in a known, verified state. Before we call a setup complete, a real message has gone out and we've read its headers together to confirm SPF, DKIM and DMARC all pass and align; every IP has been checked against the major blacklists and is clean; the reverse-DNS records resolve on both IPv4 and IPv6; and the firewall, TLS and bounce handling are in place rather than on a to-do list.

Alongside the server you get a short operating document: where the configuration lives, how the virtual MTAs and IP pools are laid out, how to add a domain, and what the warm-up plan looks like for the IPs that are new. It's written to be read by your team, not to impress — enough that whoever operates the platform next can do so without reverse-engineering someone else's work. The goal of the whole engagement is a server you could hand to a new hire next month and have them understand it.

Who it's for

ESPs & platforms

Standing up or replacing PowerMTA nodes without downtime or guesswork.

SaaS with transactional mail

Resets, receipts and confirmations that must reach the inbox — set up on isolated streams.

Legitimate B2B senders

Permission-based programs that need a clean, authenticated infrastructure.

Setup, do-it-yourself, or fully managed

Which route fits you

There are three ways to get a clean PowerMTA into production, and they differ only in who does the work. This setup service is the done-for-you, one-time route: an engineer builds it on your server and hands it over. The Auto PMTA Configurator is the do-it-yourself route — a one-time €799 tool that runs the same deploy for you to operate. And managed deliverability is the hand-it-off route, where we run the platform on an ongoing basis rather than just standing it up.

A simple way to choose: take the Configurator if you have the technical comfort to run a deploy and want to own the process end to end; take the setup service if you'd rather an engineer do the build once and leave you with a finished, documented server; take managed if you don't want to operate the MTA at all. Already running elsewhere and moving over? A migration handles the move without resetting the reputation you've built, and a deliverability audit is the quickest way to see where you stand first.

Before we begin

What you bring to the table

The prerequisites are short, and confirming them up front is what keeps a setup to one or two days rather than a back-and-forth. You provide root or SSH access to a clean, supported server — AlmaLinux 8 or 9, Rocky, or Ubuntu — with the sending IPs you intend to use. You provide a valid PowerMTA license; we install and configure on it, and we won't proceed on a nulled or shared copy. You give us control of the sending domain's DNS, or someone on your side who can publish records quickly, since authentication has to be verified before the server goes live. And you confirm with your host that outbound port 25 is open, because a surprising number of providers block it by default and it's the one thing we can't configure around.

Getting those four things lined up before intake is most of the difference between a smooth setup and a stalled one. If any of them is uncertain — you're not sure whether port 25 is open, or whether your IPs are already listed somewhere — say so at intake and we'll check it as part of the readiness step rather than discovering it halfway through.

It's worth being clear about why the authentication and reverse-DNS pieces are non-negotiable now. Over 2024 and 2025 the major mailbox providers moved their sending requirements from advice to enforcement — Gmail shifted from temporary deferrals to outright rejections for persistently non-compliant senders, and Microsoft began rejecting non-compliant bulk mail to its consumer domains. A server that skips proper SPF, DKIM, DMARC, reverse DNS or TLS doesn't just risk the spam folder anymore; it risks being refused at the door. Setting those correctly from the first send is the whole point of having it done right.

How engagement works

Three steps, no surprises

01

Intake

You share server access, your license and your sending domains. We confirm scope and prerequisites.

02

Deploy

We install, configure, authenticate and harden — then run blacklist and test-send verification.

03

Handover

You get a working server, a short operating doc, and a clear path to tuning or managed if you want it.

The whole engagement is scoped before it starts, so there are no open-ended hours. A standard single server is one to two business days from access to a verified send; a multi-server or multi-IP environment is quoted up front once we understand the IP layout and warm-up sequence. You always know what's being done and what it costs before any work begins. And if a setup ever needs more than the scoped time through no fault of yours — a host that turns out to block port 25, say — we tell you and re-scope rather than quietly running the clock. The figure you agree to at the start is the figure you pay.

Ready when you are

Send us your server details and license, and we'll have a clean, authenticated PowerMTA ready — typically within one to two business days.

Request setup →

Setup service FAQ

Do you provide the PowerMTA license?+

No. This is a configuration service for senders who already hold, or are buying, a valid PowerMTA license from Port25/Bird or an authorized reseller. We install and configure on your license; we never resell, bundle or crack the software.

How long does a setup take?+

A standard single-server setup is typically completed within one to two business days of receiving access, your license and DNS control. Multi-server or multi-IP environments are scoped individually.

What do I need to provide before you start?+

Root/SSH access to a supported server (AlmaLinux, Rocky or Ubuntu), a valid PowerMTA license, control over your sending domain's DNS, and confirmation that outbound port 25 is open with your host.

Will this guarantee my emails reach the inbox?+

No honest provider guarantees the inbox. A correct setup gets you accepted and authenticated — the entry ticket. Placement then depends on reputation, list quality and engagement, which is what the tuning and managed tiers address over time.

Do you work with bulk or cold-email senders?+

Only legitimate, permission-based programs. We don't support unsolicited bulk mail, 'unlimited' sending claims, nulled software or filter evasion — that work burns IPs and isn't something we put our name on.

How is the setup service different from the €799 Configurator?+

Same clean build, different hands. The Auto PMTA Configurator is a one-time €799 tool you run yourself to deploy the platform; the setup service is where we run that deploy for you on your server and hand it over working. Choose the Configurator if you want to own and operate the process; choose the setup service if you'd rather hand the build to an engineer and start from a finished server.

Which operating systems do you set up on?+

AlmaLinux 8/9, Rocky Linux, and Ubuntu — a clean box, no control panel required. If you're unsure which to run, AlmaLinux or Rocky are the common choices for PowerMTA and the ones we test against most.

Can you set up multiple servers or a multi-IP environment?+

Yes. Single-server is the standard engagement; multi-server fleets and large multi-IP setups are scoped individually because the IP segmentation, warm-up sequencing and routing need planning. Because the configuration is built the same way each time, a fleet comes out consistent rather than hand-varied.

I don't have a license yet — can you still help?+

We can advise on what to buy and set up once you hold a valid license, but we won't proceed on a nulled or 'no-license' copy. If you're still deciding, the PowerMTA pricing and license guide explains how that side works, and the alternatives roundup covers the open-source options if a commercial engine isn't right for you.

Do you set up authentication, IPv6 and MailWizz too?+

Yes — authentication (SPF, DKIM, DMARC) with reverse DNS is part of every setup, and dual-stack IPv6 and a MailWizz connection are included where your environment uses them. The aim is a server that's complete on handover, not one missing the pieces you'd discover later.

Does the price change for more IPs or domains?+

The €249 starting point is per server for a standard single-server build. A setup with a large number of IPs, many sending domains, or multi-server topology takes more planning — IP segmentation, warm-up sequencing, routing — so it's scoped and quoted up front. You'll know the figure before any work begins; there are no open-ended hours.

Can you set up the monitoring and dashboards too?+

Yes, where your environment uses them. Blacklist checks and a delivery view are part of confirming the server is healthy at handover, and a per-client dashboard can be included so you can watch delivered, deferred and bounced volume yourself. If you want monitoring run for you on an ongoing basis, that's the managed tier rather than the one-time setup.

What happens if something breaks after handover?+

Because you own the server and a documented configuration, a competent engineer on your side can operate and repair it — that's the point of the handover doc. If you'd rather not, the tuning and managed tiers exist precisely for ongoing care, and a one-off troubleshooting engagement is available too. We're honest that infrastructure needs maintenance; what we won't do is leave you unable to maintain your own server.

Prefer to run it yourself? See the Auto PMTA Configurator. Moving from another platform? See migration.