This documentation is for Dovecot v1.x, see wiki2 for v2.x documentation.


Compiling Dovecot From Sources

For most people it is enough to do:

sudo make install 

That installs Dovecot under the /usr/local directory. The configuration file is in /usr/local/etc/dovecot.conf. Logging goes to syslog's mail facility by default, which typically goes to /var/log/mail.log or something similar. If you are in a hurry, you can then jump to QuickConfiguration.

Anchor(nonstdpaths) If you have installed some libraries into locations which require special include or library paths, you can pass them in the CPPFLAGS and LDFLAGS environment variables. For example:

CPPFLAGS=-I/opt/openssl/include LDFLAGS=-L/opt/openssl/lib ./configure 

Solaris 10 includes a bundled OpenSSL that does not function correctly with Dovecot 1.0beta8 when attempting to use TLS/SSL. The bundled version of OpenSSL cannot be removed. Installing a newer OpenSSL from source or package (for instance, from will enable Dovecot to work correctly as long as you link against the new OpenSSL. Assuming you are building with the built-in ld, make and gcc, then your build should go something like this (notice the -R required by Sun's linker that sets the runtime linking path in the resulting programs so the OpenSSL libraries load from /usr/local/ssl/lib):

export PATH
CPPFLAGS=-I/usr/local/ssl/include LDFLAGS='-L/usr/local/ssl/lib -R/usr/local/ssl/lib' ./configure --with-ssl=openssl
make install 

Compiling Dovecot From CVS

If you got Dovecot from CVS, you will first need to run ./ to generate the configure script. This also requires that you have the pkg-config package installed (its /usr/share/aclocal/pkg.m4 file is needed).

SSL/TLS Support

Dovecot was initially built to support both OpenSSL and GNUTLS. GNUTLS has however had some problems and nowadays it does not work any more. Patches to fix it are welcome.

OpenSSL is used by default now, and it should be automatically detected. If it is not, you are missing some header files or libraries, or they are just in a non-standard path. Make sure you have the openssl-dev or a similar package installed, and if it is not in the standard location, set CPPFLAGS and LDFLAGS as shown in [#nonstdpaths the first section above.]

By default the SSL certificate is read from /etc/ssl/certs/dovecot.pem and the private key from /etc/ssl/private/dovecot.pem. The /etc/ssl directory can be changed using the --with-ssldir=DIR configure option. Both can of course be overridden from the configuration file.


Notify method


Note that current inotify is in the Linux kernel since version 2.6.13 and it is preferred over dnotify. If your distribution does not have the required inotify header file, you can get it from the inotify maintainer (this example requires [ cURL]):

mkdir -p /usr/local/include/sys
cd /usr/local/include/sys
curl -O
curl >> inotify.h 

Optional Configure Options

gives a full list of available options
just lists the options added by the particular package (= Dovecot)

Options are usually listed as --with-something or --enable-something. If you want to disable them, do it as --without-something or --disable-something. There are many default options that come from autoconf, automake or libtool. They are explained elsewhere.

Here is a list of options that Dovecot adds. You should not usually have to change these, but they are described here just for completeness:

Enable IPv6 support. This is enabled by default if the system is detected to support it.
Enables some extra checks for debugging. This is mostly useful for developers. It does quite a lot of unnecessary work but should catch some programming mistakes more quickly.
Enable assertion checks, enabled by default. Disabling them may slightly save some CPU, but if there are bugs they can cause more problems since they are not detected as early.
Specifies if we use 32bit or 64bit file offsets. 64bit is the default if the system supports it (Linux and Solaris do). Dropping this to 32bit may save some memory, but it prevents accessing any file larger than 2 GB.
Specifies memory alignment used for memory allocations. It is needed with many non-x86 systems and it should speed up x86 systems too. Default is 8, to make sure 64bit memory accessing works.

Specifies what I/O loop method to use. Possibilities are select, poll, epoll and kqueue. Default is to use poll if possible and fallback to select. epoll is faster than either of them, but it works only on Linux 2.6 kernels. kqueue is also faster, but works only on BSDs.


Specifies what file system notification method to use. Possibilities are dnotify, inotify (both on Linux), kqueue (FreeBSD) and none. Default is to use dnotify if it is compilable, otherwise none. See [#notify Notify method] above for more information.

Build POP3 server binary as well as IMAP server. It still has to be separately enabled from the configuration file before it is actually used.
Build Local Delivery Agent binary.

Specifies what mailbox formats to support. Default is maildir,mbox.

SQL Driver Options

SQL drivers are typically used only for authentication, but they may be used as a lib-dict backend too, which can be used by plugins for different purposes.

  --with-sql-drivers      Build with specified SQL drivers. Defaults to all that were found with autodetection.
  --with-pgsql            Build with PostgreSQL support
  --with-mysql            Build with MySQL support
  --with-sqlite           Build with SQLite3 driver support

Authentication Backend Options

The basic backends are built if the system is detected to support them:

  --with-passwd           Build with /etc/passwd support
  --with-passwd-file      Build with passwd-like file support
  --with-shadow           Build with shadow password support
  --with-pam              Build with PAM support
  --with-checkpassword    Build with checkpassword support
  --with-bsdauth          Build with BSD authentication support
  --with-static-userdb    Build with static userdb support
  --with-prefetch-userdb  Build with prefetch userdb support

Some backends require extra libraries and are not necessarily wanted, so they are built only if specifically enabled:

  --with-sql              Build with generic SQL support (drivers are enabled separately)
  --with-ldap             Build with LDAP support
  --with-gssapi           Build with GSSAPI authentication support
  --with-vpopmail         Build with vpopmail support

Dynamic Authentication Modules

Dovecot can also dynamically load authentication modules from the $prefix/lib/dovecot/auth/ directory. Binary packages builders should use them for authentication modules which require external libraries (e. g. LDAP and vpopmail). There is no standard way to build them as modules currently, but something like this should work:

-I../.. -I../lib -I../lib-settings \
db-ldap.c userdb-ldap.c passdb-ldap.c -o -lldap

-I../.. -I../lib userdb-vpopmail.c passdb-vpopmail.c -o \

Including libsettings.a in and is kind of annoying, but it is not needed elsewhere in dovecot-auth.

Dynamic IMAP and POP3 Modules

mail_plugins setting lists all plugins that Dovecot loads at startup from mail_plugin_dir directory. These plugins can do anything they want. They are only expected to contain <plugin name>_init and <plugin name>_deinit functions which are called at startup and at exit.

The plugin filename is prefixed with a number which specifies the order in which the plugins are loaded. This is important if one plugin depends on another.

Dynamic SQL drivers

The SQL drivers can be used by dovecot-auth, but also by lib-dict. lib-dict then can be used by some plugins, for example enabling dict quota backend to keep the quota information in SQL database.

You could place the SQL drivers into main plugin directory and create symlinks for them into auth/, imap/, pop3/ and lda/.

cd src/lib-sql

-I../.. -I../lib -I../lib-settings -I/usr/include/postgresql \
driver-pgsql.c -o -L/usr/lib/postgresql -lpq

-I../.. -I../lib -I../lib-settings -I/usr/include/mysql \
driver-mysql.c -o -lmysqlclient