What Is Dovecot and What Role Does It Play in a Mail Server?

Dovecot is the IMAP and POP3 server in a mail stack: it stores users' mail in mailboxes and serves that mail to mail clients, and it usually also handles local delivery (via LMTP), authentication lookups, and server-side filtering (Sieve). It does not move mail between servers — that is the MTA's job, typically Postfix. In a dockerized suite like mailcow, Dovecot runs as its own container next to Postfix, SOGo, and Rspamd, which is why it appears in both feature discussions and troubleshooting threads.

The split of duties: MTA vs. IMAP/POP3 server

A mail server is not one program but a chain of specialized components. The two you will see most often are Postfix and Dovecot, and confusing their roles is the most common source of misunderstanding.

Job Handled by Protocol
Accept mail from other servers and from your users' clients MTA (Postfix) SMTP
Move mail between servers on the internet MTA (Postfix) SMTP
Store mail in a user's mailbox Dovecot — (local storage)
Deliver mail from the MTA into that mailbox Dovecot LMTP
Serve the mailbox to a mail client Dovecot IMAP, POP3
Check a user's password / look up the account Dovecot (auth) —
Filter or file incoming mail by rule Dovecot (Sieve) —

The short version: Postfix decides where mail goes; Dovecot decides what a mailbox is and who may read it. When you send a message, Postfix receives it over SMTP, then hands it to Dovecot over LMTP for final delivery into the recipient's mailbox. When you open your mail app, the app talks to Dovecot over IMAP or POP3 — Postfix is not involved at that point.

What Dovecot actually does in practice

Mailbox access: IMAP and POP3

IMAP is the protocol most clients use. It keeps mail on the server and synchronizes state — folders, read/unread flags, deletions — across every device you connect. POP3 is the older alternative: it typically downloads messages to one device and can remove them from the server. If you have ever set up a phone and a laptop and expected both to show the same inbox, that is IMAP doing the work.

Local delivery: LMTP

LMTP (Local Mail Transfer Protocol) is how the MTA hands a message to Dovecot for storage. It looks like SMTP but is designed for final delivery to a mailbox rather than relaying onward. This is the handoff point where a message stops being "in transit" and becomes "in a mailbox."

Authentication

Dovecot can verify credentials against a backend — a database, LDAP, or a passwd-style file — and tell the client whether the login is valid. In a suite like mailcow, this is also how account data is shared with the rest of the stack, so a single account works for both sending and reading mail.

Sieve filtering

Sieve is a mail filtering language. Rules such as "file messages from this sender into that folder" or "reject mail matching this pattern" are evaluated by Dovecot at delivery time, before the message lands in the inbox. This is server-side filtering, so it applies no matter which client you use.

Quotas

Dovecot tracks and enforces per-mailbox storage limits. When a mailbox is full, delivery can be rejected or deferred, which is one reason quota settings show up in delivery-failure investigations.

How Dovecot fits into a dockerized suite like mailcow

mailcow packages the whole stack as containers, and Dovecot is one of them rather than something you install and configure by hand. The mailcow project describes itself as "the mailserver suite with the 'moo'" and lists Dovecot alongside Postfix, SOGo, Rspamd, and others as core components. In that arrangement:

  • Postfix handles SMTP in and out.
  • Dovecot handles mailbox storage, IMAP/POP3 access, LMTP delivery, authentication, and Sieve.
  • SOGo provides the webmail and groupware front end that talks to Dovecot on the user's behalf.
  • Rspamd filters spam and can influence what reaches delivery.

Because each piece is a separate container, an update to one component ships independently — mailcow's release notes routinely bump individual components (for example, a 2026 update that raised Redis, SOGo, and ClamAV versions, and another that fixed a CVE in Unbound and bumped Nginx). Dovecot's own version moves on its own schedule within that model, which is worth knowing when you read a changelog and wonder why Dovecot is not mentioned in a given release.

Why Dovecot shows up in troubleshooting

Most Dovecot-related problems fall into a few recognizable categories:

  • Authentication failures. The client cannot log in even though the password is correct. Causes range from a backend lookup problem to a mismatch between the username format the client sends and what the auth backend expects.
  • Mailbox permission problems. Mail is delivered but cannot be read, or delivery fails outright, because the process serving the mailbox does not have the right ownership or access to the mail directory.
  • TLS certificate issues. Clients refuse to connect, or warn about an untrusted certificate, because the certificate Dovecot presents is expired, mismatched to the hostname, or not the one the client expects.
  • Delivery and quota errors. A message bounces or is deferred because the mailbox is over quota or the LMTP handoff failed.

The useful habit is to ask which side of the chain the symptom belongs to. If sending fails, look at Postfix. If reading, logging in, or filing mail fails, look at Dovecot. That single question usually cuts the search space in half before you touch any configuration.

mailcow.email
The mailserver suite with the 'moo' – 🐮 + 🐋 = 💕 | Official Blog Page
modoboa.org
Modoboa is an open source email server including a modern and simplified Web User Interface.