- Language
- Go — one static binary,
linux/amd64 and linux/arm64
- Executable
guemail — the on-disk name of the GU.Email binary and its command line
- Requires
- Linux with systemd, PostgreSQL 16 or newer. Migrations run on upgrade
- Manages
- Postfix · Dovecot · Rspamd — through SQL views they read directly, not generated config files
- Email authentication
- DKIM generation and rotation · SPF inside the ten-lookup budget · DMARC policy and reporting address
- DNS checks
- MX, A, AAAA, PTR, SPF, DKIM, DMARC, TLS-RPT, MTA-STS — on demand and on a schedule, each with its evidence
- Sign-in
- OIDC with PKCE, plus a local break-glass login. Emailed two-factor codes and single-use recovery codes
- Interfaces
- Server-rendered web UI, REST API with scoped bearer tokens, and a CLI
- Network
- Binds
127.0.0.1:9322, behind your own TLS terminator
- Licensing
- Applied by the software itself — Startup on first start, a paid plan issued to the installation over Scandium's licensing endpoint. No key to enter on any plan
- Telemetry
- No usage reporting, ever. GU.Email contacts Scandium only to check its licence and fetch updates — server identifier, product version and the time of the check. Never your mail, mailboxes, logs or keys