Linux SysAdmin for Secure Email Server and MAILCOW + SOGO PERSONAL EMAIL SERVER
Budget / Salary$10–30
TypeFreelance project
LocationRemote
Posted2 hours ago
# Personal Mail Server + Secure Photo/Video Gallery
I am looking for an experienced Linux system administrator/developer to install, secure and fully configure a **personal email server and private photo/video gallery** on a new VPS.
This is strictly for personal/private use.
For privacy and security reasons, the real domain name, server IP and personal email address will only be provided to the selected freelancer.
## VPS
- Ubuntu Server 26.04 LTS
- 4 vCores
- 8 GB RAM
- 75 GB NVMe SSD
- 1 Gbit/s connection
- Daily VPS backup available
## PART 1 — MAILCOW + SOGO PERSONAL EMAIL SERVER
Install the latest stable and supported versions of:
- Mailcow
- SOGo Webmail
- Docker / Docker Compose
- Required SMTP/IMAP services
- HTTPS/SSL
Create and test my first personal mailbox.
The system must allow me to create additional mailboxes, aliases and additional domains later from the administration interface.
### DNS & Deliverability
Configure and test:
- MX
- SPF
- DKIM
- DMARC
- PTR / reverse DNS
- Correct hostname
- HELO/EHLO
- TLS
- Autodiscover/Autoconfig where appropriate
SPF, DKIM and DMARC must PASS final tests.
Test legitimate sending and receiving with major external email providers where practical.
This server will NOT be used for bulk email, marketing or unsolicited email.
## ANTIVIRUS & ANTI-SPAM
Configure the security functionality available with Mailcow, including where applicable:
- ClamAV
- Automatic antivirus signature updates
- Attachment malware scanning
- Rspamd
- Spam detection
- Phishing protection
- Reputation checks
- Spam scoring
- Junk handling
- Rate limiting
Perform a safe final antivirus and anti-spam functionality test.
## MAIL SERVER SECURITY
Configure:
- Firewall
- SSH hardening
- Brute-force protection
- Strong administrator authentication
- 2FA where supported
- Secure Docker configuration
- Security updates
- Correct permissions
- Open-relay protection
- SSL/TLS certificates with automatic renewal
Only necessary services and ports should be exposed.
## AUTOMATIC SECURITY ALERTS
Configure automatic alerts for important suspicious activity, including where technically possible:
- Repeated SSH login failures
- Privileged/root SSH login
- Mail administration login attempts
- Webmail authentication failures
- Repeated IMAP/SMTP authentication failures
- Brute-force attacks
- IP bans
- Serious security events
- Suspicious successful authentication events
Alerts should contain useful information such as:
- Date/time
- Source IP
- Targeted account
- Service
- Number of attempts
- Block/ban action
Do NOT send an alert for every random Internet bot request.
Use sensible thresholds and aggregation to avoid notification flooding.
No password, token or private key may appear in security notifications.
Perform a controlled test demonstrating that the security alert system works.
## ANDROID + IPHONE + PC
Configure and document access for:
- Android
- iPhone/iOS
- Standard desktop email clients
- SOGo Webmail
Provide the correct IMAP/SMTP settings, encryption requirements and synchronization information.
Verify SOGo functionality for:
- Email
- Contacts
- Calendar
- Address book
---
# PART 2 — PIWIGO PERSONAL PHOTO & VIDEO GALLERY
Install and configure the latest stable and supported version of **Piwigo**.
The gallery should use PHP and MariaDB/MySQL as appropriate.
Piwigo must be properly isolated from the mail infrastructure.
A security issue in the PHP gallery must not provide direct access to Mailcow, mailboxes or mail server administration.
## PHOTO & VIDEO FEATURES
The gallery should provide:
- Personal homepage
- Photo gallery
- Video support
- Albums
- Public albums
- Private albums
- Titles and descriptions
- Thumbnails
- Responsive mobile interface
- Full-screen media viewing
Install and configure a maintained video solution/plugin compatible with the selected Piwigo version where required.
## MOBILE PHOTO/VIDEO UPLOAD
I want to be able to publish photos from my phone without using SSH.
Configure and test uploading from:
- Android
- iPhone/iOS
Where supported by the selected mobile client and server configuration, configure photo/video uploads.
The workflow should be simple:
1. Open the mobile application or secure mobile interface.
2. Select photo/video.
3. Select album.
4. Add title/description if required.
5. Upload.
6. Media appears in the gallery.
## SECURE PIWIGO ADMINISTRATION
Configure:
- Private administrator account
- Strong authentication
- HTTPS only
- Brute-force/rate-limit protection
- 2FA if a maintained and compatible solution is available
- Secure PHP configuration
- Strict file permissions
- Secure upload directories
- File type validation
- Upload size limits
- Protection against executable script uploads
- Security headers where appropriate
- Regular update procedure
Mailcow, Piwigo, SSH and other administration services must NOT share the same passwords.
## USERS & PRIVACY
Configure and demonstrate:
- Users
- Groups
- Public/private albums
- Album permissions
- Private media access
- Administrator permissions
Private albums must not be publicly accessible without authorization.
## BACKUPS
Configure or document backups covering:
### Mail system
- Mailboxes
- Mailcow configuration
- Databases
- DKIM keys/configuration
- Important configuration files
### Gallery
- Piwigo database
- Photos
- Videos
- Albums
- Configuration
- Required plugins/themes
Provide a clear restoration procedure.
The VPS provider already provides a daily infrastructure backup, but an application-level backup/restore procedure is still required.
## FINAL TESTING
Before delivery, verify:
### Email
- Sending works
- Receiving works
- SPF passes
- DKIM passes
- DMARC passes
- PTR is correct
- SSL/TLS works
- Antivirus works
- Anti-spam works
- Webmail works
- Android/iPhone configuration works or is correctly verified
- Security alerts work
### Gallery
- Homepage works
- Admin login works
- Photo upload works
- Video functionality works
- Android upload works
- iPhone upload works
- Public/private albums work
- Permissions work
- HTTPS works
- Backup procedure works
## DOCUMENTATION
Provide short documentation covering:
- Mail server administration
- Webmail
- Mobile mail configuration
- Creating mailboxes
- Creating aliases
- Adding another email domain
- DNS configuration
- Backup/restore
- Updating Mailcow
- Security alerts
- Blocking/unblocking IP addresses
- Piwigo administration
- Uploading photos/videos
- Creating albums
- Managing private albums
- Creating gallery users
- Updating Piwigo/plugins
- Restoring the gallery
## PRIVACY
Do not publish or include my real domain, server IP, personal email address, passwords, private keys or other credentials in public project messages.
Real technical information will be provided privately to the selected freelancer.
## FINAL REQUIREMENT
I require a **complete, secure and tested installation**, not simply software installation.
Please apply only if you have experience with:
- Mailcow
- SOGo
- Linux/Ubuntu server administration
- Docker
- Email deliverability
- SPF/DKIM/DMARC/PTR
- ClamAV
- Rspamd
- Server security
- PHP
- MariaDB/MySQL
- Piwigo
- Secure file uploads
- Backup and recovery
Please briefly describe previous experience with similar mail server and Piwigo installations in your bid.
I am looking for an experienced Linux system administrator/developer to install, secure and fully configure a **personal email server and private photo/video gallery** on a new VPS.
This is strictly for personal/private use.
For privacy and security reasons, the real domain name, server IP and personal email address will only be provided to the selected freelancer.
## VPS
- Ubuntu Server 26.04 LTS
- 4 vCores
- 8 GB RAM
- 75 GB NVMe SSD
- 1 Gbit/s connection
- Daily VPS backup available
## PART 1 — MAILCOW + SOGO PERSONAL EMAIL SERVER
Install the latest stable and supported versions of:
- Mailcow
- SOGo Webmail
- Docker / Docker Compose
- Required SMTP/IMAP services
- HTTPS/SSL
Create and test my first personal mailbox.
The system must allow me to create additional mailboxes, aliases and additional domains later from the administration interface.
### DNS & Deliverability
Configure and test:
- MX
- SPF
- DKIM
- DMARC
- PTR / reverse DNS
- Correct hostname
- HELO/EHLO
- TLS
- Autodiscover/Autoconfig where appropriate
SPF, DKIM and DMARC must PASS final tests.
Test legitimate sending and receiving with major external email providers where practical.
This server will NOT be used for bulk email, marketing or unsolicited email.
## ANTIVIRUS & ANTI-SPAM
Configure the security functionality available with Mailcow, including where applicable:
- ClamAV
- Automatic antivirus signature updates
- Attachment malware scanning
- Rspamd
- Spam detection
- Phishing protection
- Reputation checks
- Spam scoring
- Junk handling
- Rate limiting
Perform a safe final antivirus and anti-spam functionality test.
## MAIL SERVER SECURITY
Configure:
- Firewall
- SSH hardening
- Brute-force protection
- Strong administrator authentication
- 2FA where supported
- Secure Docker configuration
- Security updates
- Correct permissions
- Open-relay protection
- SSL/TLS certificates with automatic renewal
Only necessary services and ports should be exposed.
## AUTOMATIC SECURITY ALERTS
Configure automatic alerts for important suspicious activity, including where technically possible:
- Repeated SSH login failures
- Privileged/root SSH login
- Mail administration login attempts
- Webmail authentication failures
- Repeated IMAP/SMTP authentication failures
- Brute-force attacks
- IP bans
- Serious security events
- Suspicious successful authentication events
Alerts should contain useful information such as:
- Date/time
- Source IP
- Targeted account
- Service
- Number of attempts
- Block/ban action
Do NOT send an alert for every random Internet bot request.
Use sensible thresholds and aggregation to avoid notification flooding.
No password, token or private key may appear in security notifications.
Perform a controlled test demonstrating that the security alert system works.
## ANDROID + IPHONE + PC
Configure and document access for:
- Android
- iPhone/iOS
- Standard desktop email clients
- SOGo Webmail
Provide the correct IMAP/SMTP settings, encryption requirements and synchronization information.
Verify SOGo functionality for:
- Contacts
- Calendar
- Address book
---
# PART 2 — PIWIGO PERSONAL PHOTO & VIDEO GALLERY
Install and configure the latest stable and supported version of **Piwigo**.
The gallery should use PHP and MariaDB/MySQL as appropriate.
Piwigo must be properly isolated from the mail infrastructure.
A security issue in the PHP gallery must not provide direct access to Mailcow, mailboxes or mail server administration.
## PHOTO & VIDEO FEATURES
The gallery should provide:
- Personal homepage
- Photo gallery
- Video support
- Albums
- Public albums
- Private albums
- Titles and descriptions
- Thumbnails
- Responsive mobile interface
- Full-screen media viewing
Install and configure a maintained video solution/plugin compatible with the selected Piwigo version where required.
## MOBILE PHOTO/VIDEO UPLOAD
I want to be able to publish photos from my phone without using SSH.
Configure and test uploading from:
- Android
- iPhone/iOS
Where supported by the selected mobile client and server configuration, configure photo/video uploads.
The workflow should be simple:
1. Open the mobile application or secure mobile interface.
2. Select photo/video.
3. Select album.
4. Add title/description if required.
5. Upload.
6. Media appears in the gallery.
## SECURE PIWIGO ADMINISTRATION
Configure:
- Private administrator account
- Strong authentication
- HTTPS only
- Brute-force/rate-limit protection
- 2FA if a maintained and compatible solution is available
- Secure PHP configuration
- Strict file permissions
- Secure upload directories
- File type validation
- Upload size limits
- Protection against executable script uploads
- Security headers where appropriate
- Regular update procedure
Mailcow, Piwigo, SSH and other administration services must NOT share the same passwords.
## USERS & PRIVACY
Configure and demonstrate:
- Users
- Groups
- Public/private albums
- Album permissions
- Private media access
- Administrator permissions
Private albums must not be publicly accessible without authorization.
## BACKUPS
Configure or document backups covering:
### Mail system
- Mailboxes
- Mailcow configuration
- Databases
- DKIM keys/configuration
- Important configuration files
### Gallery
- Piwigo database
- Photos
- Videos
- Albums
- Configuration
- Required plugins/themes
Provide a clear restoration procedure.
The VPS provider already provides a daily infrastructure backup, but an application-level backup/restore procedure is still required.
## FINAL TESTING
Before delivery, verify:
- Sending works
- Receiving works
- SPF passes
- DKIM passes
- DMARC passes
- PTR is correct
- SSL/TLS works
- Antivirus works
- Anti-spam works
- Webmail works
- Android/iPhone configuration works or is correctly verified
- Security alerts work
### Gallery
- Homepage works
- Admin login works
- Photo upload works
- Video functionality works
- Android upload works
- iPhone upload works
- Public/private albums work
- Permissions work
- HTTPS works
- Backup procedure works
## DOCUMENTATION
Provide short documentation covering:
- Mail server administration
- Webmail
- Mobile mail configuration
- Creating mailboxes
- Creating aliases
- Adding another email domain
- DNS configuration
- Backup/restore
- Updating Mailcow
- Security alerts
- Blocking/unblocking IP addresses
- Piwigo administration
- Uploading photos/videos
- Creating albums
- Managing private albums
- Creating gallery users
- Updating Piwigo/plugins
- Restoring the gallery
## PRIVACY
Do not publish or include my real domain, server IP, personal email address, passwords, private keys or other credentials in public project messages.
Real technical information will be provided privately to the selected freelancer.
## FINAL REQUIREMENT
I require a **complete, secure and tested installation**, not simply software installation.
Please apply only if you have experience with:
- Mailcow
- SOGo
- Linux/Ubuntu server administration
- Docker
- Email deliverability
- SPF/DKIM/DMARC/PTR
- ClamAV
- Rspamd
- Server security
- PHP
- MariaDB/MySQL
- Piwigo
- Secure file uploads
- Backup and recovery
Please briefly describe previous experience with similar mail server and Piwigo installations in your bid.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.