<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.xmission.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Benjii</id>
	<title>XMission Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.xmission.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Benjii"/>
	<link rel="alternate" type="text/html" href="https://wiki.xmission.com/Special:Contributions/Benjii"/>
	<updated>2026-05-19T10:53:05Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=SIP_ALG&amp;diff=11538</id>
		<title>SIP ALG</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=SIP_ALG&amp;diff=11538"/>
		<updated>2023-05-30T20:06:11Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== XMission Voice and SIP ALG ==&lt;br /&gt;
&lt;br /&gt;
Using XMission Voice on a different Internet service or through your own router can create quality issues with your voice services. This is often caused by a software protocol called SIP ALG or SIP HELPER depending on the equipment being used. XMission requires this build in protocol to be disabled in order to ensure service is properly working. &lt;br /&gt;
&lt;br /&gt;
=== What is SIP ALG/HELPER? ===&lt;br /&gt;
&lt;br /&gt;
This protocol assists with rewriting voice traffic to show that it is being NATed. In other words, instead of headers being sent the call is coming from an IP address of:&lt;br /&gt;
&lt;br /&gt;
* 10.x.x.x&lt;br /&gt;
* 192.168.x.x&lt;br /&gt;
* 172.16.x.x&lt;br /&gt;
&lt;br /&gt;
This shows the public IP address when the call is coming from the router&#039;s public IP address (IE: 166.70.x.x)&lt;br /&gt;
&lt;br /&gt;
[[File:SIP-ALG-packets.png|600px]]&lt;br /&gt;
&lt;br /&gt;
Using the image above, you can see how Internet traffic sends voice calls with and without SIP ALG/HELPER. The highlighted area is where the traffic gets changed. &lt;br /&gt;
&lt;br /&gt;
=== Why SIP ALG/HELPER is not needed ===&lt;br /&gt;
&lt;br /&gt;
Most voice providers (including XMission) have a public switch or server that is a go-between. In other words, the Telephone Adapters (TAs) or IP Phones that are provided by XMission connect to this switch prior to reaching the actual voice system to make and receive phone calls. Because we are configured for this, calls are by default tagged with a public IP address and do not require one from your equipment. &lt;br /&gt;
&lt;br /&gt;
=== What happens with SIP ALG/HELPER? ===&lt;br /&gt;
&lt;br /&gt;
Having SIP ALG enabled on your equipment can make it so the onsite equipment drops the registered device (TA) during the ringing process of phone calls. When this happens the following could be true:&lt;br /&gt;
* One-way audio: The caller not using XMission Voice can be heard, but the XMission Voice user cannot be heard.&lt;br /&gt;
* Outgoing calls fail: Calls get 404 or dead air when trying to dial out. Most calls don&#039;t even reach call.xmission.com call history.&lt;br /&gt;
* Incoming calls fail to ring: The signal to tell the handset to ring on incoming calls is blocked and callers end up going to voicemail.&lt;br /&gt;
* Device registration fails entirely.&lt;br /&gt;
&lt;br /&gt;
=== How to disable SIP ALG/HELPER? ===&lt;br /&gt;
&lt;br /&gt;
This protocol is typically found inside the web interface of your personal router/firewall under the advanced settings. It can often be found under: &lt;br /&gt;
* NAT forwarding&lt;br /&gt;
* QoS&lt;br /&gt;
* Security&lt;br /&gt;
* Firewall&lt;br /&gt;
* WAN settings&lt;br /&gt;
&lt;br /&gt;
Please review the following to disable the protocol:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|TP-Link Archer Routers (Archer Series):&lt;br /&gt;
# Log in to routers web interface (tplinkwiki.net)&lt;br /&gt;
# Click on Advanced&lt;br /&gt;
# Locate NAT Forwarding (or Firewall)&lt;br /&gt;
# ALG&lt;br /&gt;
# Uncheck &amp;quot;Enable SIP ALG&amp;quot;&lt;br /&gt;
# Save&lt;br /&gt;
|-&lt;br /&gt;
|Netgear Router (with Genie):&lt;br /&gt;
# Log in to router web interface (routerlogin.net)&lt;br /&gt;
# Click on Advanced&lt;br /&gt;
# Locate the Setup Menu&lt;br /&gt;
# Click WAN Settings (or Setup)&lt;br /&gt;
# Uncheck the &amp;quot;Enable SIP ALG&amp;quot;&lt;br /&gt;
# Save&lt;br /&gt;
|-&lt;br /&gt;
|Asus Routers (with ZenWiFi):&lt;br /&gt;
# Log in to routers web interface (router.asus.com)&lt;br /&gt;
# Click on WAN under Advanced Settings&lt;br /&gt;
# Click on NAT Passthrough Tab&lt;br /&gt;
# Select Disabled on SIP Passthrough&lt;br /&gt;
# Apply&lt;br /&gt;
|-&lt;br /&gt;
|Linksys/Cisco Routers (with Smart Wifi):&lt;br /&gt;
# Log in to router web interface (192.168.0.1 unless otherwise LAN IP has been changed)&lt;br /&gt;
# Click on Administration&lt;br /&gt;
# Under the Management Tab&lt;br /&gt;
# Select the Disabled button&lt;br /&gt;
# Save&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* For unlisted routers, please contact XMission Support for additional help.&lt;br /&gt;
&lt;br /&gt;
[[Category:Troubleshooting]]&lt;br /&gt;
[[Category:VoIP]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11532</id>
		<title>SPF and DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11532"/>
		<updated>2023-05-23T19:29:20Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* Valid SPF for XMission */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SPF and DKIM are two important security methods domain owners have of &amp;quot;authorizing&amp;quot; specific email servers to send mail on their behalf. Besides providing greater deliverability of your messages, these mechanisms prevent fraudsters from sending spoofing emails as your domain. &lt;br /&gt;
&lt;br /&gt;
These TXT records are entered by the domain owner wherever the domain&#039;s DNS record is managed, which may be with the registrar or hosting provider. DKIM (Domain Key Identified Mail) also adds public key cryptography for deeper validation.&lt;br /&gt;
&lt;br /&gt;
XMission advises all [https://xmission.com/zimbra Zimbra clients] to configure SPF &amp;amp; DKIM. It may sound a bit daunting but is really not very complicated. This document will walk you through it. &lt;br /&gt;
&lt;br /&gt;
IMPORTANT NOTE ABOUT TXT RECORD ENTRY: Depending on the syntax requirements of your DNS system you may have to include or omit the quotation marks for the record to be properly enabled. Other DNS entries on your domain should provide quick visual guidance on protocol. XMission DNS systems do &#039;&#039;not&#039;&#039; use quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= SPF =&lt;br /&gt;
The following is the  most commonly applied SPF (Sender Policy Framework) record for XMission email customers but it is imperative you understand how and why this is applied. IMPORTANT: It is critical that you read and understand all SPF information below before applying the record to your domain as you could break email delivery.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How It Works ==&lt;br /&gt;
Any SPF record is a string of one more more potential mail sources, prefixed by a character indicating the policy for mail source. An example of a common SPF record:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Example Syntax&lt;br /&gt;
|-&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf a mx ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In this case, it says that the A and MX records for the domain are allowed to send, and all other mail fails (but with a &amp;quot;softfail&amp;quot;, so that mail isn&#039;t actually rejected). &amp;quot;a&amp;quot;, &amp;quot;mx&amp;quot; and &amp;quot;all&amp;quot;, are all individual mail sources. The &amp;quot;~&amp;quot; prefixed to the &amp;quot;all&amp;quot; source is a policy denoting that mail from the source should be considered a &amp;quot;SoftFail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Sources &amp;amp; Definitions&lt;br /&gt;
|-&lt;br /&gt;
! Flag !! Source Type&lt;br /&gt;
|-&lt;br /&gt;
| a || DNS A record&lt;br /&gt;
|-&lt;br /&gt;
| mx || MX record&lt;br /&gt;
|-&lt;br /&gt;
| ptr || PTR record&lt;br /&gt;
|-&lt;br /&gt;
| ip4 || IPv4 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| ip6 || IPv6 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| include || The contents of another domain&#039;s SPF record&lt;br /&gt;
|-&lt;br /&gt;
| all || Any mail source (generally used at the end to provide a default policy)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Prefix Characters&lt;br /&gt;
|-&lt;br /&gt;
! Prefix !! Definition&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;+&#039;&#039;&#039; || Pass (Valid for SPF)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;-&#039;&#039;&#039; || Fail (Invalid, and reject mail)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;~&#039;&#039;&#039; || SoftFail (Invalid, but still accept)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;?&#039;&#039;&#039; || Neutral (...whatever...)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
XMission Shared Hosting clients can [https://wiki.xmission.com/Adding/Managing_DNS_Records learn to manage DNS records here.]&lt;br /&gt;
&lt;br /&gt;
== Valid SPF for XMission ==&lt;br /&gt;
Any SPF record for a domain sending through XMission should contain &amp;quot;include:_spf.xmission.com&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
If you prefer a less identifiable entry then a minimum inclusion would have the following four sources:&lt;br /&gt;
* ip4:166.70.11.0/24&lt;br /&gt;
* ip4:166.70.13.0/24&lt;br /&gt;
* ip4:166.70.198.0/24&lt;br /&gt;
* ip4:198.60.22.0/24&lt;br /&gt;
&lt;br /&gt;
Note that the SPF record policy is a decision of the domain owner&#039;s. If they want to Fail or SoftFail on all, add other sources, etc., is up to them. We don&#039;t have a singular recommendation or requirement for SPF. If the customer &#039;&#039;&#039;only&#039;&#039;&#039; sends via XMission, the following SPF record is relatively safe:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===Valid SPF for XMission with additional sending services===&lt;br /&gt;
&lt;br /&gt;
Sometimes it is necessary to have mailing list or other services that need to send emails so having multiple SPF records be strung together becomes necessary. Fortunately the fairly lenient syntax of SPF records makes this easy to do, here is our default record compared to some merged records:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Hosts Generating Emails !! Example of Merged SPF Record&lt;br /&gt;
|-&lt;br /&gt;
| Default XMission || v=spf1 a mx include:_spf.xmission.com ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Mailchimp || v=spf1 include:_spf.xmission.com include:servers.mcsv.net ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Gmail, plus Constant Contact || v=spf1 include:_spf.xmission.com include:_spf.google.com include:spf.constantcontact.com -all&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Forwarding ==&lt;br /&gt;
&#039;&#039;&#039;Important note&#039;&#039;&#039; about forwarding (ie automatically redirecting mail from one email address to another, not hitting the forward button):&lt;br /&gt;
&lt;br /&gt;
Forwarding (under most circumstances) &amp;lt;em&amp;gt;BREAKS&amp;lt;/em&amp;gt; SPF. If a domain has a &amp;quot;-all&amp;quot; (&amp;quot;reject all other mail&amp;quot; aka &amp;quot;Fail&amp;quot;) policy in their SPF record, mail will be rejected by any servers respecting SPF after the server performing the forward. Users should keep this in mind when choosing a policy. This is why we suggest &amp;quot;~all&amp;quot; (&amp;quot;SoftFail&amp;quot;) when you initially configure SPF.&lt;br /&gt;
&lt;br /&gt;
== Alias Domains ==&lt;br /&gt;
Domain aliases that are used for sending email with &amp;quot;From:&amp;quot; addresses will need SPF &amp;amp; DKIM records configured. &lt;br /&gt;
&lt;br /&gt;
All customers are strongly encouraged to configure SPF &amp;amp; DKIM records for all alias domains and parked domains to prevent possible abuse.&lt;br /&gt;
&lt;br /&gt;
= DKIM = &lt;br /&gt;
DomainKeys Identified Mail (DKIM) is similar to SPF in that it uses a TXT record on the domain to define a sending policy for that domain. Where it differs is that it uses public key cryptography with this sending policy. A public key is added to that TXT record and any message that is signed with the private key (and thus validates with the public key) is then considered valid.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;DKIM will break automatic responders, like &#039;&#039;Out of Office&#039;&#039; or &#039;&#039;Vacation&#039;&#039; replies.&#039;&#039;&#039; This is due to how DKIM verifies the sender, and how automated replies are generated and sent.  This is intentional, and is a consideration that needs to be made when limiting sending from your domain via DKIM.&lt;br /&gt;
&lt;br /&gt;
== Adding DKIM to an XMission Domain ==&lt;br /&gt;
We have a single private key for XMission DKIM signing. We can sign DKIM with this key on any domain sending out through XMission. It works for Zimbra domains, virtmail, and SMTP relay. To enable this feature for a domain, two things need to happen:&lt;br /&gt;
&lt;br /&gt;
* The domain needs proper DNS for our domainkey key (see below)&lt;br /&gt;
* The domain needs to be added to XMission routing config as one with DKIM signing.&lt;br /&gt;
&lt;br /&gt;
== DKIM DNS ==&lt;br /&gt;
Add the following two TXT records to the domain.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note&#039;&#039;&#039;: Once added you must [https://xmission.com/contact contact] [mailto:support@xmission.com support@xmission.com] to add your domain to XMission&#039;s DKIM routing file and complete the process:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| xmission._domainkey || TXT || &amp;quot;v=DKIM1; t=y; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzWmoe0tzQkSUzMqliwcQQ5zY1HKk4z+Wgp+dRCRe7MmSBPftE9r5Lx1QfTfF/J8gl4k9tFsUvUBap0fk1VGMYUG/2LynVuzpkCI4JlUKF5fbx+MDNZrVi0aX73Edjd9trU6NKldVnhNg1RixDLa4aB04XJviy6+3P1h3IHNaZ0QIDAQAB&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| _domainkey || TXT || &amp;quot;t=y; o=~;&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Reminder: XMission DNS systems do not require entry of the quotation marks on the records above. External DNS system may require quotation marks.&lt;br /&gt;
&lt;br /&gt;
====Multiple Email Hosts with DKIM ====&lt;br /&gt;
&lt;br /&gt;
It is possible to use more than one host with DKIM, though this is only possible if the DNS records used to announce the public key for the security handshake don&#039;t share subdomains with each other.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11530</id>
		<title>Zimbra Email Client Configurations</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11530"/>
		<updated>2023-05-05T16:48:45Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__ &lt;br /&gt;
&lt;br /&gt;
These easy to follow instructions will help you configure your favorite client for use with your Zimbra email service.&amp;lt;br/&amp;gt;&lt;br /&gt;
For greater convenience, you can always access your mail at https://zimbra.xmission.com/&lt;br /&gt;
&lt;br /&gt;
For more help, reference the video repository of helpful tips on the [https://www.youtube.com/channel/UCcB648SoNlCNvyIh4arcTGg Zimbra YouTube Channel].&lt;br /&gt;
&lt;br /&gt;
== Recommended Email Settings==&lt;br /&gt;
&amp;lt;p&amp;gt;XMission always recommends an IMAP email configuration [https://xmission.com/blog/2009/02/09/why-imap-rules heres why.]&amp;lt;/p&amp;gt;&lt;br /&gt;
{| style=&amp;quot;text-align: left; border: 1px solid #ccc;&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;2&amp;quot; &lt;br /&gt;
! style=&amp;quot;border-bottom:1px solid #ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Incoming Server Information:&lt;br /&gt;
! style=&amp;quot;border-style: solid; border-width: 0 0 1px 1px; border-color:#ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Outgoing Server Information:&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Server Type: || IMAP&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Server Type: || SMTP&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Hostname: || zimbra.xmission.com&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Hostname: || zimbra.xmission.com &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Port: || 993&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Port: || 587&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Enable encryption: || YES&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Enable encryption: || YES&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Authenticate Using: || Password&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Requires Authentication: || YES&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Login User Name: || Full email address &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |Login User Name || Full email address&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Alternate Port: || 143, SSL POP3 995 &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |Alternate Port: || 465 (For older systems, no longer supported)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
||Webmail Interface: |||[https://zimbra.xmission.com/ https://zimbra.xmission.com/]&lt;br /&gt;
|-&lt;br /&gt;
||Admin Interface: |||[https://zimbraadmin.xmission.com https://zimbraadmin.xmission.com]&lt;br /&gt;
|-&lt;br /&gt;
||Folders: ||| Sent Mail = &amp;quot;Sent&amp;quot;, Drafts = &amp;quot;Drafts&amp;quot;, Trash = &amp;quot;Trash&amp;quot;, Spam = &amp;quot;Junk&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
||MX Record: ||| mx.xmission.com&lt;br /&gt;
|-&lt;br /&gt;
||TXT Record: ||| v=spf1 a mx include:_spf.xmission.com ~all&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
- Please note that some free wireless hotspots may block SSL without an extra fee. If you cannot send or receive while on certain wifi networks (especially ones in airports or public spaces) please check their terms and conditions and ensure they are not blocking SSL connections.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Videos==&lt;br /&gt;
*[https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra Email on Mac using IMAP]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Windows 10 / 8.x / 7 / Vista==&lt;br /&gt;
*[[Hosted_Email:Outlook_2013|Outlook 2013/2016/365]]&lt;br /&gt;
*[[Hosted_Email:Outlook_2010|Outlook 2010]] &lt;br /&gt;
*[[Hosted_Email:Outlook_Connector|Outlook Connector for Zimbra Premium]] and Personal Premium Zimbra accounts&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Zimbra_41|Thunderbird 41]]&lt;br /&gt;
&lt;br /&gt;
====Archive Windows====&lt;br /&gt;
The following Microsoft Widows mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
* Windows XP - Mail applications on this OS will still work but are no longer supported&lt;br /&gt;
*[[Hosted_Email:Outlook_2007|Outlook 2007]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Outlook 2003]]  &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Windows_Mail|Windows Live Mail]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Outlook_Express|Outlook Express]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup|Thunderbird 3]] &amp;lt;-- Please upgrade your mail application to a current version.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Mac OS== &lt;br /&gt;
These settings are compatible across the bulk all OS X versions.&lt;br /&gt;
*[[Hosted_Email:Outlook_Exchange_on_Mac|Outlook Exchange on Mac]] - For Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:MacMail_16.x|Mac Mail 16.x]] - IMAP setup &lt;br /&gt;
** Video Tutorial - [https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra on Mac Mail]&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Mac|Thunderbird Mac]]&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]]&lt;br /&gt;
&lt;br /&gt;
====Archive Mac OS====&lt;br /&gt;
The following Mac mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
*[[Hosted_Email:MacMail_10.x|Mac Mail 10.x]] Same settings for Mail 11.X and 12.X.&lt;br /&gt;
*[[Hosted_Email:MacMail_9.x|Mac Mail 9.x]]&lt;br /&gt;
**[[Hosted_Email:Calendar_Sync_OSX|Calendar Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
**[[Hosted_Email:Contacts_Sync_OSX|Contacts Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:MacMail_7.x|Mac Mail 7.x]]&lt;br /&gt;
*[[Hosted_Email:MacMail_3|Mac Mail 3.x]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Linux==&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup_Linux|Thunderbird Linux]]&lt;br /&gt;
*[[Hosted_Email:Evolution|Evolution Mail]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Mobile==&lt;br /&gt;
*[[Hosted Email Base:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Base and Standard Accounts&lt;br /&gt;
*[[Hosted_Email:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Premium Account configuration with Profile&lt;br /&gt;
*[[Apple iOS Devices - iPhone iPad with Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra email, &amp;amp; Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Android|Android]]&lt;br /&gt;
*[[Android Portable Devices with Microsoft Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra, and Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Windows_Mobile|Windows Mobile &amp;amp; Windows Phone 8]]&lt;br /&gt;
*[[Hosted_Email:BlackBerry|BlackBerry IMAP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]] Terminal based. Works on Linux and Mac OS.&lt;br /&gt;
* Zimbra Desktop -  Zimbra deprecating at end of 2019. Use configuration settings provided at top of page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Convert from POP to IMAP ==&lt;br /&gt;
* Thunderbird POP to IMAP process: https://support.mozilla.org/en-US/kb/switch-pop-imap-account&lt;br /&gt;
* [[Windows Outlook 2007 POP to Zimbra IMAP]] Essentially same instructions for 2003.&lt;br /&gt;
* [[Outlook Express POP to Zimbra IMAP]]&lt;br /&gt;
* [[Windows Live Mail POP to Zimbra IMAP]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Client Email Configuration]]&lt;br /&gt;
[[Category:Email]]&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Shared_Hosting&amp;diff=11499</id>
		<title>Shared Hosting</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Shared_Hosting&amp;diff=11499"/>
		<updated>2023-03-29T20:59:17Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* Getting Started */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt; &lt;br /&gt;
== Getting Started == &lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*[[Administration/Logging in]]&lt;br /&gt;
*[[Adding a Domain]]&lt;br /&gt;
**[[Adding a Subdomain]]&lt;br /&gt;
**[[Adding a Domain Alias]]&lt;br /&gt;
**[[Adding a Domain Forwarder]]&lt;br /&gt;
*[[Adding MySQL Databases]]&lt;br /&gt;
**[[Managing MySQL]]&lt;br /&gt;
*[[Adding/Managing DNS Records]]&lt;br /&gt;
*[[Managing Domain/Users]]&lt;br /&gt;
*[[Managing FTP Access/Users]]&lt;br /&gt;
**[[About FTP and Shared Hosting]]&lt;br /&gt;
*[[PHP Settings]]&lt;br /&gt;
*[[Previewing the Website]]&lt;br /&gt;
*[[Secure Your Sites]]&lt;br /&gt;
*[[Web Statistics]]&lt;br /&gt;
Additional Development Help&lt;br /&gt;
*[[Changing your upload limits]]&lt;br /&gt;
*[[Password Protecting a Directory With &amp;quot;.htaccess&amp;quot;]]&lt;br /&gt;
Applications&lt;br /&gt;
*[https://wiki.xmission.com/Lets_Encrypt Let&#039;s Encrypt!]&lt;br /&gt;
*[http://wiki.xmission.com/WordPress Wordpress One-Click Install]&lt;br /&gt;
*[https://wiki.xmission.com/WordPress_Toolkit WordPress Toolkit]&lt;br /&gt;
Domain Management&lt;br /&gt;
*[[Domains]]&lt;br /&gt;
*[[Hosting a domain not registered with XMission]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Shared Hosting]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Shared_Hosting&amp;diff=11498</id>
		<title>Shared Hosting</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Shared_Hosting&amp;diff=11498"/>
		<updated>2023-03-28T15:30:05Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt; &lt;br /&gt;
== Getting Started == &lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*[[Administration/Logging in]]&lt;br /&gt;
*[[Adding a Domain]]&lt;br /&gt;
**[[Adding a Subdomain]]&lt;br /&gt;
**[[Adding a Domain Alias]]&lt;br /&gt;
**[[Adding a Domain Forwarder]]&lt;br /&gt;
*[[Adding MySQL Databases]]&lt;br /&gt;
**[[Managing MySQL]]&lt;br /&gt;
*[[Adding/Managing DNS Records]]&lt;br /&gt;
*[[Managing Domain/Users]]&lt;br /&gt;
*[[Managing FTP Access/Users]]&lt;br /&gt;
**[[About FTP and Shared Hosting]]&lt;br /&gt;
*[[PHP Settings]]&lt;br /&gt;
*[[Previewing the Website]]&lt;br /&gt;
*[[Web Statistics]]&lt;br /&gt;
*[[Secure Your Sites]]&lt;br /&gt;
Additional Development Help&lt;br /&gt;
*[[Changing your upload limits]]&lt;br /&gt;
*[[Password Protecting a Directory With &amp;quot;.htaccess&amp;quot;]]&lt;br /&gt;
Applications&lt;br /&gt;
*[https://wiki.xmission.com/Lets_Encrypt Let&#039;s Encrypt!]&lt;br /&gt;
*[http://wiki.xmission.com/WordPress Wordpress One-Click Install]&lt;br /&gt;
*[https://wiki.xmission.com/WordPress_Toolkit WordPress Toolkit]&lt;br /&gt;
Domain Management&lt;br /&gt;
*[[Domains]]&lt;br /&gt;
*[[Hosting a domain not registered with XMission]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Shared Hosting]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Shell_Access&amp;diff=11497</id>
		<title>Shell Access</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Shell_Access&amp;diff=11497"/>
		<updated>2023-03-22T14:35:43Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==How do I activate my shell account?==&lt;br /&gt;
To activate your shell account, contacting the [https://xmission.com/contact XMission Sales] team is necessary.&lt;br /&gt;
&lt;br /&gt;
===Why isn&#039;t shell access on by default?===&lt;br /&gt;
Having shell access enabled by default on all accounts presents a  security risk. A shell account gives the user a direct window into  our system. By minimizing the number of active shell accounts, we  minimize the risk of compromising our system.&lt;br /&gt;
&lt;br /&gt;
==Is there a way to transfer files to and from my XMission account other than FTP?==&lt;br /&gt;
Although FTP is the recommended way to transfer files to and from your XMission account, it&#039;s not the only way. SFTP (ssh ftp) works directly to shell.xmission.com.&lt;br /&gt;
&lt;br /&gt;
=What is SSH and how do I use it?=&lt;br /&gt;
SSH is a secure shell. Using it is differs, depending on the operating  system.  Mac OS X is probably the easiest. Nothing special has to be installed.  Simply open a terminal window and &amp;lt;tt&amp;gt;ssh username@shell.xmission.com&amp;lt;/tt&amp;gt;.  Accept the key and enter your password.  For most Windows operating systems, an SSH client must be used. There  are many SSH clients on the market and a few are &amp;quot;freeware&amp;quot;. PuTTY is a recommended free SSH client for Windows. Some places to look for additional SSH software would be Download.com and Tucows.com.  &lt;br /&gt;
&lt;br /&gt;
==Can I choose my shell type?==&lt;br /&gt;
Yes. You can choose from bash, tcsh, sh, zsh, csh, and ksh. We recommend using either bash or csh, at first, since they&#039;re the most user-friendly.&lt;br /&gt;
&lt;br /&gt;
==Why don&#039;t my screen and text work properly?==&lt;br /&gt;
There are two typical problems that occur during a telnet session.  The first and most common problem is incorrect terminal emulation.  The second problem occurs after a screen has been messed up by viewing  a binary file.&lt;br /&gt;
 &lt;br /&gt;
The most commonly used terminal emulation is vt100, though vt220  is supported and recommended. To change the terminal emulation of  your telnet application, view the preferences and choose either vt100  or vt220. However, even after specifying the terminal emulation for  your telnet application, you may still have problems correctly displaying  columns and rows. For this, you&#039;ll need to define the default size  of your window in your run commands (explained below]).  When trying to fix a screen after viewing a binary file, run &amp;lt;tt&amp;gt;fixvt&amp;lt;/tt&amp;gt; at a command prompt.&lt;br /&gt;
&lt;br /&gt;
==What are some common commands I&#039;ll need to know when using the UNIX shell?==&lt;br /&gt;
The most common commands you&#039;ll need to know are &amp;lt;tt&amp;gt;cd&amp;lt;/tt&amp;gt; (changes your directory), &amp;lt;tt&amp;gt;pwd&amp;lt;/tt&amp;gt; (shows your current directory path), and &amp;lt;tt&amp;gt;ls&amp;lt;/tt&amp;gt; (lists the contents of the current directory). For a more complete list of common commands, please see our Common Commands page. &lt;br /&gt;
&lt;br /&gt;
==Why do I get &amp;quot;command not found&amp;quot; when using a command I&#039;m sure should work? ==&lt;br /&gt;
It&#039;s possible that you don&#039;t have the paths to the command directories defined correctly in your run commands. For instructions on defining the correct paths, see below. &lt;br /&gt;
&lt;br /&gt;
===How do I edit my shell run commands (rc) file?===&lt;br /&gt;
Your shell run commands are found in a file named &#039;&#039;.cshrc&#039;&#039; (for c shell),  &#039;&#039;.bashrc&#039;&#039; (for borne shell), &#039;&#039;.kshrc&#039;&#039; (for korn shell), etc. This file  will be located in your home directory (/home/users/u/username). It  contains commands that are run when you first log on to set your  paths, environment variables, and aliases. Before changing ANY rc file, it&#039;s recommended you make a back-up copy.&lt;br /&gt;
&lt;br /&gt;
To set or edit your paths, edit your run commands file with a text  editor (pico, vi, ed, etc.). Your paths will be defined after the  command &amp;lt;tt&amp;gt;set path =&amp;lt;/tt&amp;gt;. The default paths should be &amp;lt;tt&amp;gt;/bin /usr/local/bin  /usr/bin&amp;lt;/tt&amp;gt;. If you&#039;d like to add a path, simply add it to the end,  separated by a space. (e.g.: /home/users/u/username/morecommands/)  If you&#039;d like to edit what information is displayed in your prompt,  edit the &amp;lt;tt&amp;gt;set prompt=&amp;lt;/tt&amp;gt; variable. A useful way to define your prompt  is to have it display your current directory. To do this, remove the  default &amp;lt;tt&amp;gt;set prompt=&amp;lt;/tt&amp;gt; and enter this in its place:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;alias cd &#039;cd \!* ; set prompt=&amp;quot;&#039;hostname&#039;:&#039;pwd&#039;&amp;gt; &amp;quot;&#039;&amp;lt;/tt&amp;gt;  To edit your environment variables, first type &amp;lt;tt&amp;gt;env&amp;lt;/tt&amp;gt; at a command  prompt to show your current variables. If you&#039;d like to change any  of these, enter the definition after a new &amp;quot;setenv&amp;quot; line. The proper  syntax, as you&#039;ll see in the default settings, is:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;setenv VARIABLE_NAME path/or/command:/2nd/path/or/command/&amp;lt;/tt&amp;gt;  Adding an alias is fairly simple. If you&#039;d like a certain command  to be run when you type something in at the command prompt, you&#039;d  enter that here. The proper syntax is:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;alias aliasedcommand &#039;realcommand -options&#039;&amp;lt;/tt&amp;gt;  This is also where you define your terminal emulation settings.&lt;br /&gt;
&amp;lt;tt&amp;gt;setenv TERM vt100   &amp;lt;/tt&amp;gt;(sets terminal type)&lt;br /&gt;
&amp;lt;tt&amp;gt;/bin/stty rows 24   &amp;lt;/tt&amp;gt;(sets number of rows)&lt;br /&gt;
&amp;lt;tt&amp;gt;/bin/stty cols 80   &amp;lt;/tt&amp;gt;(sets number of columns)&lt;br /&gt;
&amp;lt;tt&amp;gt;/bin/stty erase ^H   &amp;lt;/tt&amp;gt;(sets backspace command)  &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What are all these files in my home directory, and what are they for?==&lt;br /&gt;
If you do a complete list, showing hidden files, of your home directory,  you will notice that there are several files already there. The files  are listed and explained in the table below. Some of these files will  not be there by default, but only appear if the application that uses  them is run. &lt;br /&gt;
&lt;br /&gt;
===Types===&lt;br /&gt;
rc run commands/preferences (usually, but not always)&lt;br /&gt;
&lt;br /&gt;
===Files===&lt;br /&gt;
.cshrc shell run commands(for csh or tcsh) .gopherrc gopher preferences .login shell preferences (read after run commands at login) .newsrc news preferences .nn Network News Reader preferences .pinerc Pine preferences (pine is primarily used for email) .tin Threaded Internetwork News preferences&lt;br /&gt;
&lt;br /&gt;
===Directories===&lt;br /&gt;
bin can contain scripts or binary executables ftp your personal directory for file transfer mail Email is stored here (used by pine and others) news articles are saved here by default public_html your web pages&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I alter the information shown in my prompt?==&lt;br /&gt;
If you use tcsh, changing the prompt is as simple as entering the command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;set prompt=&amp;quot;options&amp;quot;&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
However, with other shells, you will need to edit the &amp;lt;tt&amp;gt;set prompt=&amp;lt;/tt&amp;gt; line in your shell run commands file (shown above). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What program can I use to read email from a shell? ==&lt;br /&gt;
&lt;br /&gt;
Probably the most popular options are &#039;&#039;mutt&#039;&#039; (recommended) and &#039;&#039;pine&#039;&#039;, but &#039;&#039;elm&#039;&#039;, &#039;&#039;mail/rmail&#039;&#039;, and &#039;&#039;emacs&#039;&#039; are also available. At a command prompt, run the command &amp;lt;tt&amp;gt;mutt&amp;lt;/tt&amp;gt;, &amp;lt;tt&amp;gt;pine&amp;lt;/tt&amp;gt;, or &amp;lt;tt&amp;gt;elm&amp;lt;/tt&amp;gt; and the mail client will open, also creating either a /mail (pine and elm) or /Mail (mutt) directory. Using mail/rmail &lt;br /&gt;
or emacs isn&#039;t quite as intuitive. It&#039;s recommended that you read the manual before using. (Type &amp;lt;tt&amp;gt;man mail&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;man emacs&amp;lt;/tt&amp;gt; at a command prompt.) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What program can I use to read news (Usenet) from a shell?==&lt;br /&gt;
The newsreaders available on shell are slrn, tin, nn, pine, nmh, trn, and emacs. The most popular ones would be slrn, tin, nn, and pine. We recommend slrn, since it&#039;s the only one that still has development. For more information on how to use any of these programs, type &amp;quot;man&amp;quot; followed by the program name at the command prompt (e.g.: &amp;lt;tt&amp;gt;man tin&amp;lt;/tt&amp;gt;). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How do I kill a process? ==&lt;br /&gt;
Before you kill a processes, you have to have its processes ID. You get this by typing &amp;quot;ps&amp;quot; at the command prompt. Once you&#039;ve determined which one of your processes is the one you want to kill, type &amp;lt;tt&amp;gt;kill -9 PID&amp;lt;/tt&amp;gt; (where PID is the actual processes ID) at the command prompt. &lt;br /&gt;
&lt;br /&gt;
==How do I compress and decompress files? ==&lt;br /&gt;
The method you&#039;ll use to decompress a file is determined by looking at the file extension. The instructions below show how to decompress the file in the current directory. For further information, see the &lt;br /&gt;
manual for each program (tar, bzip, unzip, gzip, uncompress).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.tar    &amp;lt;/tt&amp;gt;&amp;lt;tt&amp;gt;tar xvf file.tar&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.Z   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;uncompress file.Z&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.gz   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;gzip -d file.gz&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.zip   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;unzip file.zip&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.bz2   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;bzip2 -d file.bz2&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If there is a combination of formats, such as file.tar.gz, you can &lt;br /&gt;
either pipe one command to the other (e.g. &amp;lt;tt&amp;gt;gzip -d file.tar.gz | tar &lt;br /&gt;
xvf&amp;lt;/tt&amp;gt;), or see if the option is supported by tar (&amp;lt;tt&amp;gt;man tar&amp;lt;/tt&amp;gt;&amp;gt;. Using the command &lt;br /&gt;
&amp;lt;tt&amp;gt;tar xvfz file.tar.gz&amp;lt;/tt&amp;gt; will handle both the gzip compression and the &lt;br /&gt;
tar compression. When piping a .Z file, however, be sure to use &amp;lt;tt&amp;gt;zcat &lt;br /&gt;
file.Z&amp;lt;/tt&amp;gt; (the equivalent of &amp;lt;tt&amp;gt;uncompress -c file.Z&amp;lt;/tt&amp;gt;, which writes to standard &lt;br /&gt;
output the files that were compressed). A similar rule applies to &lt;br /&gt;
bzip2, where you should use &amp;lt;tt&amp;gt;bzcat file.bz2&amp;lt;/tt&amp;gt; (equal to &amp;lt;tt&amp;gt;bzip2 -dc file.bz2&amp;lt;/tt&amp;gt;) &lt;br /&gt;
when piping the output to another command. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What are some basics on setting permissions with &amp;quot;chmod&amp;quot;?==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First, an understanding of file/directory ownership is needed. Each &lt;br /&gt;
file or directory has a user (also the owner) and a group. The owner &lt;br /&gt;
of your files should always be your XMission username. The groups &lt;br /&gt;
you&#039;ll need to know are www (which gives the web server access to &lt;br /&gt;
the files) and users (which gives any of XMission&#039;s users, from shell, &lt;br /&gt;
access to the files). There&#039;s also the category, others, that includes &lt;br /&gt;
any user or group.&lt;br /&gt;
&lt;br /&gt;
Permissions are based on those three categories: owner, group, and &lt;br /&gt;
others. When you do a long listing of the file (&amp;lt;tt&amp;gt;ls -l filename&amp;lt;/tt&amp;gt;), the &lt;br /&gt;
permissions will be displayed to the left. The format is shown as &lt;br /&gt;
such: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;-rw-r--r-- 1 acctname group 1949 Sep &lt;br /&gt;
19 2000 file.html&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first space defines weather the file is a simple file (shown with a hyphen) or a directory (shown with a d). The next three spaces represent the permissions (highlighted in red) &lt;br /&gt;
for the owner, the next three are for the group, and the last three &lt;br /&gt;
are for others. The letters represent what kind of permissions are &lt;br /&gt;
allowed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;r &#039;&#039;&#039; = Read (view and make copies)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;w &#039;&#039;&#039; = Write (make changes to or delete)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;x &#039;&#039;&#039; = Execute (run program/script) &lt;br /&gt;
When using &amp;quot;chmod&amp;quot; to change permissions, you will need to specify &lt;br /&gt;
the category by using one or a combination of the following letters:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;u &#039;&#039;&#039; = User (Owner)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;g &#039;&#039;&#039; = Group&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;o &#039;&#039;&#039; = Others&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;a &#039;&#039;&#039; = All (same as using &amp;quot;ugo&amp;quot;) &lt;br /&gt;
To change the permissions, execute &amp;quot;chmod&amp;quot; with the following parameters:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod who+/-/=permission file&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The plus (+) adds the following permission, the minus (-) removes &lt;br /&gt;
it, and the (=) adds it, discarding any previous permissions. Some &lt;br /&gt;
examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod g+r file.html&amp;lt;/tt&amp;gt; (adds read access for group)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod go-r file.html&amp;lt;/tt&amp;gt; (removes read access from group and &lt;br /&gt;
others)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod a=x file.html&amp;lt;/tt&amp;gt; (replaces existing permissions with read &lt;br /&gt;
access for all)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod g+rx file.html&amp;lt;/tt&amp;gt; (adds read and execute access for group) &lt;br /&gt;
There is another way to change permissions without having to write &lt;br /&gt;
out &amp;lt;tt&amp;gt;chmod who+/-/=permission file&amp;lt;/tt&amp;gt; every time. This method uses a 3-digit octal &lt;br /&gt;
number. Determining the octal number is fairly easy after some practice. &lt;br /&gt;
To start, refer to the chart below. &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
===Symbol Octal===&lt;br /&gt;
&lt;br /&gt;
 ---0 --x1 -w-2 -wx3 r--4 r-x5 rw-6 rwx7&lt;br /&gt;
&lt;br /&gt;
For example, if you&#039;d like to set the permissions on file.html &lt;br /&gt;
to be &amp;lt;tt&amp;gt;-rw-r--r--&amp;lt;/tt&amp;gt; you would determine the octal number &lt;br /&gt;
like this (skip the first space in the set): &lt;br /&gt;
&amp;lt;tt&amp;gt;rw-&amp;lt;/tt&amp;gt; = 6, &amp;lt;tt&amp;gt;r--&amp;lt;/tt&amp;gt; = 4, &amp;lt;tt&amp;gt;r--&amp;lt;/tt&amp;gt; = 4. The octal &lt;br /&gt;
number is 644. &lt;br /&gt;
&lt;br /&gt;
To execute the command, type:&lt;br /&gt;
&lt;br /&gt;
 chmod 644 file.html&lt;br /&gt;
&#039;&#039;&#039;Note&#039;&#039;&#039;: This would be the same as using:&lt;br /&gt;
&lt;br /&gt;
 chmod a+r file.html&lt;br /&gt;
&lt;br /&gt;
 chmod u+x file.html&lt;br /&gt;
&lt;br /&gt;
(if no permissions were previously set).&lt;br /&gt;
 &lt;br /&gt;
Changing ownership and the group of a file would normally be done with &amp;quot;chown&amp;quot; and &amp;quot;chgrp&amp;quot;. However, because these commands are restricted to the user and group being specified, you&#039;re unable to use them on XMission (because you&#039;re only one user and you&#039;re only a member of one group). However, if you&#039;d like a file to belong to the group www, you can either create it in or upload it to your public_html directory. This will set the group, by default, to www. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:FAQ|Shell Access]]&lt;br /&gt;
[[Category:Troubleshooting]]&lt;br /&gt;
[[Category:Getting Started]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Main_Page&amp;diff=11490</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Main_Page&amp;diff=11490"/>
		<updated>2023-03-20T21:23:28Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ __NOEDITSECTION__ &lt;br /&gt;
{| width=&amp;quot;100%&amp;quot; style=&amp;quot;vertical-align:top&amp;quot;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:10px; border: 2px solid 004,209,252; padding: 0 1em 1em 1em; background-color:#ffffff; text-align:left;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;h1 class=&amp;quot;superHeader blue&amp;quot;&amp;gt;[[File:support.png]]XMission Support Wiki&amp;lt;/h1&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Welcome to XMission Support Wiki. We have documentation for may of our products. If you cannot find what you need please feel free to check out our [http://wiki.xmission.com/Category:Troubleshooting Troubleshooting Page]. You can also [http://xmission.com/contact/ contact our technical support team].&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| width=&amp;quot;100%&amp;quot; class=&amp;quot;padding-control&amp;quot;&lt;br /&gt;
| width=&amp;quot;50%&amp;quot; style=&amp;quot;vertical-align:top&amp;quot; |&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#c0ebf4; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#03afd3; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Top Support Issues&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[Hosted_Email:_Admin_Panel#Change_Password | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Zimbra Password Change&amp;lt;/span&amp;gt;]] (Domain Admin)&lt;br /&gt;
* [[Zimbra Email Client Configurations | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Zimbra Email Client Configuration&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Spam | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Spam&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[SPF and DKIM | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;SPF and DKIM&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Passwords |&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;How do I change my password?&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Account_Home |&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;How do I pay my bill?&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[UTOPIA Setup | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;UTOPIA Router Configuration&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Speedtest | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Speed Concerns&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Router and Wireless Troubleshooting | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Router and Wireless Troubleshooting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#ffd9c4; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#ee4b00; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Popular Articles&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[General Email Settings | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;General Email Settings&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Hosted_Email:Zimbra_Self-Service_Account_Recovery | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt; Reset your forgotten Zimbra email password&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Zimbra Domain Email and Collaboration Suite | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Zimbra Domain Email and Collaboration Suite&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[XMission_Voice_Portal | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;XMission Voice Portal &amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[About_FTP_and_Shared_Hosting | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt; About FTP and Shared Hosting &amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Lets_Encrypt | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt; Let&#039;s Encrypt &amp;lt;/span&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#eff5ce; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#b3ca37; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Top Categories&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[Connections|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Connections&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Email|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Email&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Hosting|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Hosting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[XMission_Voice|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;XMission Voice&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[XMission_Services|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;XMission Services&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
| width=&amp;quot;50%&amp;quot; style=&amp;quot;vertical-align:top&amp;quot; |&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#eff5ce; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#b3ca37; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;About XMission&amp;lt;/div&amp;gt;==&lt;br /&gt;
If you&#039;re just starting out, these links are recommended reading:&lt;br /&gt;
* [[Announcements|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Announcements&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Account_Home|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Billing&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Domains|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Domains&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Recommended_Routers|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Recommended Routers&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Banners|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Banners&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Logos|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Logos&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#dddedf; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#717475; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Troubleshooting&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[Router_and_Wireless_Troubleshooting | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Slow speeds over Wifi?&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[How_to_use_ssh_keys|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;How to use ssh keys&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Cloud_Hosting|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Cloud Hosting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Shared Hosting| &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Shared Hosting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Router and Wireless Troubleshooting|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Router and Wireless Troubleshooting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#f1f2f2; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#acb0b2; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Contact Us&amp;lt;/div&amp;gt;==&lt;br /&gt;
{|&lt;br /&gt;
|[[File:Phone.png|link=]]  [[File:Mail.png|link=mailto:support@xmission.com|alt=&amp;quot;Contact us via E-Mail!&amp;quot;]]  [[File:Live-support-2.png|link=https://livesupport.xmission.com|alt=&amp;quot;Contact us via Live Support!&amp;quot;]]   [[File:Twitter.png|link=http://twitter.com/#!/xmission|alt=&amp;quot;Check out our Twitter feed!&amp;quot;]]  [[File:Facebook.png|link=https://www.facebook.com/pages/XMission/6155383019|alt=&amp;quot;Find us on Facebook!&amp;quot;]]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;div style=&amp;quot;font-size:13px; color:#777; line-height:160%; width:250px;&amp;quot;&amp;gt;Our live technical support is available for you 24/7 at &amp;lt;b&amp;gt;801.539.0852&amp;lt;/b&amp;gt; or&amp;lt;br /&amp;gt; &amp;lt;b&amp;gt;877.XMISSION&amp;lt;/b&amp;gt; (877.964.7746)&lt;br /&gt;
  &amp;lt;/div&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;position:absolute; top:475px; left:-194px; width:160px; height:420px;&amp;quot;&amp;gt;[[File:Zimbra-wiki-ad.png|link=http://xmission.com/email_collaboration?cid=wikibanner1]]&amp;lt;/div&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category: Getting Started]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Main_Page&amp;diff=11489</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Main_Page&amp;diff=11489"/>
		<updated>2023-03-17T22:00:42Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ __NOEDITSECTION__ &lt;br /&gt;
{| width=&amp;quot;100%&amp;quot; style=&amp;quot;vertical-align:top&amp;quot;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:10px; border: 2px solid 004,209,252; padding: 0 1em 1em 1em; background-color:#ffffff; text-align:left;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;h1 class=&amp;quot;superHeader blue&amp;quot;&amp;gt;[[File:support.png]]XMission Support Wiki&amp;lt;/h1&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Welcome to XMission Support Wiki. We have documentation for may of our products. If you cannot find what you need please feel free to check out our [http://wiki.xmission.com/Category:Troubleshooting Troubleshooting Page]. You can also [http://xmission.com/contact/ contact our technical support team].&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| width=&amp;quot;100%&amp;quot; class=&amp;quot;padding-control&amp;quot;&lt;br /&gt;
| width=&amp;quot;50%&amp;quot; style=&amp;quot;vertical-align:top&amp;quot; |&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#c0ebf4; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#03afd3; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Top Support Issues&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[Hosted_Email:_Admin_Panel#Change_Password | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Zimbra Password Change&amp;lt;/span&amp;gt;]] (Domain Admin)&lt;br /&gt;
* [[Zimbra Email Client Configurations | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Zimbra Email Client Configuration&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Spam | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Spam&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[SPF and DKIM | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;SPF and DKIM&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Passwords |&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;How do I change my password?&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Account_Home |&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;How do I pay my bill?&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[UTOPIA Setup | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;UTOPIA Router Configuration&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Speedtest | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Speed Concerns&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Router and Wireless Troubleshooting | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Router and Wireless Troubleshooting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#ffd9c4; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#ee4b00; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Popular Articles&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[General Email Settings | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;General Email Settings&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Hosted_Email:Zimbra_Self-Service_Account_Recovery | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt; Reset your forgotten Zimbra email password&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Zimbra Domain Email and Collaboration Suite | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Zimbra Domain Email and Collaboration Suite&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[XMission_Voice_Portal | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;XMission Voice Portal &amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[About_FTP_and_Shared_Hosting | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt; About FTP and Shared Hosting &amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Lets_Encrypt | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt; Let&#039;s Encrypt &amp;lt;/span&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#eff5ce; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#b3ca37; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Top Categories&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[Connections|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Connections&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Email|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Email&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Hosting|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Hosting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[XMission_Voice|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;XMission Voice&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[XMission_Services|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;XMission Services&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
| width=&amp;quot;50%&amp;quot; style=&amp;quot;vertical-align:top&amp;quot; |&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#eff5ce; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#b3ca37; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;About XMission&amp;lt;/div&amp;gt;==&lt;br /&gt;
If you&#039;re just starting out, these links are recommended reading:&lt;br /&gt;
* [[Announcements|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Announcements&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Banners|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Banners&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Account_Home|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Billing&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Domains|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Domains&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Logos|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Logos&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#dddedf; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#717475; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Troubleshooting&amp;lt;/div&amp;gt;==&lt;br /&gt;
* [[XMission_App | &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Slow speeds over Wifi?&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[How_to_use_ssh_keys|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;How to use ssh keys&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Cloud_Hosting|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Cloud Hosting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Shared Hosting| &amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Shared Hosting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
* [[Router and Wireless Troubleshooting|&amp;lt;span style=&amp;quot;color:#1c1f22;&amp;quot;&amp;gt;Router and Wireless Troubleshooting&amp;lt;/span&amp;gt;]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin: 0; margin-right:15px; padding: 17px; background-color:#f1f2f2; height:auto;&amp;quot;&amp;gt;&lt;br /&gt;
==&amp;lt;div style=&amp;quot;background-color:#acb0b2; color:white; margin:-1em; padding:1em; font-family:Arvo;&amp;quot;&amp;gt;Contact Us&amp;lt;/div&amp;gt;==&lt;br /&gt;
{|&lt;br /&gt;
|[[File:Phone.png|link=]]  [[File:Mail.png|link=mailto:support@xmission.com|alt=&amp;quot;Contact us via E-Mail!&amp;quot;]]  [[File:Live-support-2.png|link=https://livesupport.xmission.com|alt=&amp;quot;Contact us via Live Support!&amp;quot;]]   [[File:Twitter.png|link=http://twitter.com/#!/xmission|alt=&amp;quot;Check out our Twitter feed!&amp;quot;]]  [[File:Facebook.png|link=https://www.facebook.com/pages/XMission/6155383019|alt=&amp;quot;Find us on Facebook!&amp;quot;]]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;div style=&amp;quot;font-size:13px; color:#777; line-height:160%; width:250px;&amp;quot;&amp;gt;Our live technical support is available for you 24/7 at &amp;lt;b&amp;gt;801.539.0852&amp;lt;/b&amp;gt; or&amp;lt;br /&amp;gt; &amp;lt;b&amp;gt;877.XMISSION&amp;lt;/b&amp;gt; (877.964.7746)&lt;br /&gt;
  &amp;lt;/div&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;position:absolute; top:475px; left:-194px; width:160px; height:420px;&amp;quot;&amp;gt;[[File:Zimbra-wiki-ad.png|link=http://xmission.com/email_collaboration?cid=wikibanner1]]&amp;lt;/div&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category: Getting Started]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Lets_Encrypt&amp;diff=11488</id>
		<title>Lets Encrypt</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Lets_Encrypt&amp;diff=11488"/>
		<updated>2023-03-17T21:59:38Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Let&#039;s Encrypt!=&lt;br /&gt;
Securing your website is a key step increasing your site&#039;s visibility to search engines and during marketing campaigns. While a free SSL certificate doesn&#039;t offer the same liability coverage that a paid SSL certificate can offer, it is still useful for websites that don&#039;t collect data. Should your site need to collect customer information, please reach out to [https://xmission.com/contact XMission&#039;s Sales team] for more information about ordering a paid SSL certificate.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt is a free SSL/CA service created by the Internet Security Research Group (ISRG). It allows its users to create their own SSL/TLS certificate to have secure HTTPS connections to their websites through a free service in their Shared Hosting panel. If you would like to know more about the ISRG or the Let&#039;s Encrypt product, please see [https://letsencrypt.org/about/ letsencrypt].&lt;br /&gt;
&lt;br /&gt;
==How to create your own SSL certificate using Let&#039;s Encrypt==&lt;br /&gt;
&#039;&#039;&#039;1.&#039;&#039;&#039; Log in to your [https://hosting.xmission.com Shared Hosting panel].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.&#039;&#039;&#039; Click on &amp;quot;&#039;&#039;&#039;SSL/TLS Certificate&#039;&#039;&#039;&amp;quot; under &#039;&#039;&#039;Security&#039;&#039;&#039; from the dashboard of the site you want to install Lets Encrypt&lt;br /&gt;
&lt;br /&gt;
[[File:pleskSSL-1.png|600px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.&#039;&#039;&#039; Click on &#039;&#039;&#039;Install a free basic certificate provided by Let&#039;s Encrypt&#039;&#039;&#039; located at the bottom of the page. &lt;br /&gt;
* &#039;&#039;&#039;NOTE&#039;&#039;&#039; In order for Let&#039;s Encrypt to successfully install your domain&#039;s Names Servers need to be hosted by XMission and the &amp;quot;A&amp;quot; and &amp;quot;AAAA&amp;quot; Records must point to the server&#039;s IP Address. If you need any help with Name Servers and A Records please visit [[Hosting_a_domain_not_registered_with_XMission | Domain not with XMission]].&lt;br /&gt;
&lt;br /&gt;
[[File:PleskLE-1.png|600px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.&#039;&#039;&#039; Fill in a contact email in case of a lost key, renewal failures, or if you are in need of recovery.&lt;br /&gt;
* &#039;&#039;&#039;Secure the domain name&#039;&#039;&#039; - Keep this checked to secure your base domain.&lt;br /&gt;
* &#039;&#039;&#039; Secure the wildcard domain&#039;&#039;&#039; - If you have subdomains you wish to have covered by the certificate, check this box.&lt;br /&gt;
* &#039;&#039;&#039;Include a &#039;www&#039; subdomain for the domain&#039;&#039;&#039; - If you wish to have your www website covered by the certificate, check this box.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;5.&#039;&#039;&#039; Click &amp;quot;&#039;&#039;&#039;Get it free&#039;&#039;&#039;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:PleskLE-2.png|600px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;6.&#039;&#039;&#039; Let&#039;s Encrypt verifies the certificate by using DNS, so waiting on propagation is necessary. It is possible to review your domain&#039;s DNS propagation using various online services such as [https://whatsmydns.net WhatsMyDNS.Net] and then searching the &#039;&#039;&#039;_acme-challenge.&#039;&#039;&#039;&#039;&#039;yourdomain.tld&#039;&#039; TXT record to see if the rest of the world can see the record.&lt;br /&gt;
: &#039;&#039;&#039;Note&#039;&#039;&#039;: DNS commonly goes live in under an hour, but potentially can take up to 24-48 hours to go live globally. Especially if there was a previous record it is replacing and the previous records TTL needs to expire.&lt;br /&gt;
* Once the &#039;&#039;&#039;_acme-challenge.&#039;&#039;&#039;&#039;&#039;yourdomain.tld&#039;&#039; TXT record has been confirmed serving, click &#039;&#039;&#039;Reload&#039;&#039;&#039; to finalize the Let&#039;s Encrypt certificate generation.&lt;br /&gt;
&lt;br /&gt;
[[File:LetsEncrypt-Reload.png|600px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;7.&#039;&#039;&#039; Return to the Websites &amp;amp; Domains home page and under the &#039;&#039;&#039;Hosting &amp;amp; DNS&#039;&#039;&#039; tab, select the listing for &#039;&#039;&#039;Hosting Settings&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[File:HostingSettings.png|600px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;8.&#039;&#039;&#039; You will find the &#039;&#039;&#039;Security&#039;&#039;&#039; section where we can ensure the Let&#039;s Encrypt certificate is properly in place.&lt;br /&gt;
* &#039;&#039;&#039;SSL/TLS support&#039;&#039;&#039;: Allows the website to be able to use the certificate.&lt;br /&gt;
* &#039;&#039;&#039;Permanent SEO-safe 301 redirect from HTTP to HTTPS&#039;&#039;&#039;: Any attempts to load the site without the SSL certificate (over HTTP) will be automatically redirected to the secure version of the page. (over HTTPS)&lt;br /&gt;
* &#039;&#039;&#039;Certificate&#039;&#039;&#039;: The default repository is for the certificate Plesk loads which &#039;&#039;will not work for general purposes&#039;&#039;. Select the name matching your Let&#039;s Encrypt installation process.&lt;br /&gt;
: Once completed, select &#039;&#039;&#039;Ok&#039;&#039;&#039; at the bottom of the page to save and return to the previous page.&lt;br /&gt;
&lt;br /&gt;
[[File:HostingSettings-SaveCertificate.png|600px]]&lt;br /&gt;
&lt;br /&gt;
The Let&#039;s Encrypt Certificate has been fully generated and installed!&lt;br /&gt;
&lt;br /&gt;
[[File:HostingSettings-SettingSuccessfullySaved.png|600px]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note&#039;&#039;&#039;: After completion you will be given a message that states it has saved properly. This indicates the server has marked the change to be implanted to your Apache &amp;amp; Nginx configuration. A regularly occurring CRON job will implement the change within five minutes. You will notice the website briefly give an HTTP 502 error, then it will load the new certificate properly. In case it gets stuck, please contact our 24/7 support team for assistance restarting the related server processes to force it to go live.&lt;br /&gt;
&lt;br /&gt;
{{:Shared_Hosting}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Shared Hosting]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:HostingSettings-SettingSuccessfullySaved.png&amp;diff=11487</id>
		<title>File:HostingSettings-SettingSuccessfullySaved.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:HostingSettings-SettingSuccessfullySaved.png&amp;diff=11487"/>
		<updated>2023-03-17T21:53:34Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Success message after saving the changes in Hosting Settings.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Success message after saving the changes in Hosting Settings.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:HostingSettings-SaveCertificate.png&amp;diff=11486</id>
		<title>File:HostingSettings-SaveCertificate.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:HostingSettings-SaveCertificate.png&amp;diff=11486"/>
		<updated>2023-03-17T21:38:51Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Withing the Plesk interface&amp;#039;s Hosting Settings section, you can review the SSL certificate settings for the website we are installing Let&amp;#039;s Encrypt on.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Withing the Plesk interface&#039;s Hosting Settings section, you can review the SSL certificate settings for the website we are installing Let&#039;s Encrypt on.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:HostingSettings.png&amp;diff=11485</id>
		<title>File:HostingSettings.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:HostingSettings.png&amp;diff=11485"/>
		<updated>2023-03-17T21:38:13Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Selecting Hosting Settings on Plesk.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Selecting Hosting Settings on Plesk.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:LetsEncrypt-Reload.png&amp;diff=11484</id>
		<title>File:LetsEncrypt-Reload.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:LetsEncrypt-Reload.png&amp;diff=11484"/>
		<updated>2023-03-17T21:36:37Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Benjii uploaded a new version of File:LetsEncrypt-Reload.png&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Displaying the reload button for the Let&#039;s Encrypt registration process.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:LetsEncrypt-Reload.png&amp;diff=11483</id>
		<title>File:LetsEncrypt-Reload.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:LetsEncrypt-Reload.png&amp;diff=11483"/>
		<updated>2023-03-17T20:49:15Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Displaying the reload button for the Let&amp;#039;s Encrypt registration process.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Displaying the reload button for the Let&#039;s Encrypt registration process.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11482</id>
		<title>Zimbra Email Client Configurations</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11482"/>
		<updated>2023-03-17T18:34:31Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__ &lt;br /&gt;
&lt;br /&gt;
These easy to follow instructions will help you configure your favorite client for use with your Zimbra email service.&amp;lt;br/&amp;gt;&lt;br /&gt;
For greater convenience, you can always access your mail at https://zimbra.xmission.com/&lt;br /&gt;
&lt;br /&gt;
For more help, reference the video repository of helpful tips on the [https://www.youtube.com/channel/UCcB648SoNlCNvyIh4arcTGg Zimbra YouTube Channel].&lt;br /&gt;
&lt;br /&gt;
== Recommended Email Settings==&lt;br /&gt;
&amp;lt;p&amp;gt;XMission always recommends an IMAP email configuration [https://xmission.com/blog/2009/02/09/why-imap-rules heres why.]&amp;lt;/p&amp;gt;&lt;br /&gt;
{| style=&amp;quot;text-align: left; border: 1px solid #ccc;&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;2&amp;quot; &lt;br /&gt;
! style=&amp;quot;border-bottom:1px solid #ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Incoming Server Information:&lt;br /&gt;
! style=&amp;quot;border-style: solid; border-width: 0 0 1px 1px; border-color:#ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Outgoing Server Information:&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Server Type: || IMAP&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Server Type: || SMTP&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Hostname: || zimbra.xmission.com&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Hostname: || zimbra.xmission.com &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Port: || 993&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Port: || 587&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Enable encryption: || YES&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Enable encryption: || YES&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Authenticate Using: || Password&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Requires Authentication: || YES&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Login User Name: || Full email address &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |Login User Name || Full email address&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Alternate Port: || 143, SSL POP3 995 &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |Alternate Port: || 465 (For older systems, no longer supported)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
||Webmail Interface: |||[https://zimbra.xmission.com/ https://zimbra.xmission.com/]&lt;br /&gt;
|-&lt;br /&gt;
||Admin Interface: |||[https://zimbraadmin.xmission.com https://zimbraadmin.xmission.com]&lt;br /&gt;
|-&lt;br /&gt;
||Folders: ||| Sent Mail = &amp;quot;Sent&amp;quot;, Drafts = &amp;quot;Drafts&amp;quot;, Trash = &amp;quot;Trash&amp;quot;, Spam = &amp;quot;Junk&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
||MX Record: ||| mx.xmission.com&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
- Please note that some free wireless hotspots may block SSL without an extra fee. If you cannot send or receive while on certain wifi networks (especially ones in airports or public spaces) please check their terms and conditions and ensure they are not blocking SSL connections.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Videos==&lt;br /&gt;
*[https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra Email on Mac using IMAP]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Windows 10 / 8.x / 7 / Vista==&lt;br /&gt;
*[[Hosted_Email:Outlook_2013|Outlook 2013/2016/365]]&lt;br /&gt;
*[[Hosted_Email:Outlook_2010|Outlook 2010]] &lt;br /&gt;
*[[Hosted_Email:Outlook_Connector|Outlook Connector for Zimbra Premium]] and Personal Premium Zimbra accounts&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Zimbra_41|Thunderbird 41]]&lt;br /&gt;
&lt;br /&gt;
====Archive Windows====&lt;br /&gt;
The following Microsoft Widows mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
* Windows XP - Mail applications on this OS will still work but are no longer supported&lt;br /&gt;
*[[Hosted_Email:Outlook_2007|Outlook 2007]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Outlook 2003]]  &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Windows_Mail|Windows Live Mail]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Outlook_Express|Outlook Express]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup|Thunderbird 3]] &amp;lt;-- Please upgrade your mail application to a current version.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Mac OS== &lt;br /&gt;
These settings are compatible across the bulk all OS X versions.&lt;br /&gt;
*[[Hosted_Email:Outlook_Exchange_on_Mac|Outlook Exchange on Mac]] - For Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:MacMail_16.x|Mac Mail 16.x]] - IMAP setup &lt;br /&gt;
** Video Tutorial - [https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra on Mac Mail]&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Mac|Thunderbird Mac]]&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]]&lt;br /&gt;
&lt;br /&gt;
====Archive Mac OS====&lt;br /&gt;
The following Mac mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
*[[Hosted_Email:MacMail_10.x|Mac Mail 10.x]] Same settings for Mail 11.X and 12.X.&lt;br /&gt;
*[[Hosted_Email:MacMail_9.x|Mac Mail 9.x]]&lt;br /&gt;
**[[Hosted_Email:Calendar_Sync_OSX|Calendar Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
**[[Hosted_Email:Contacts_Sync_OSX|Contacts Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:MacMail_7.x|Mac Mail 7.x]]&lt;br /&gt;
*[[Hosted_Email:MacMail_3|Mac Mail 3.x]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Linux==&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup_Linux|Thunderbird Linux]]&lt;br /&gt;
*[[Hosted_Email:Evolution|Evolution Mail]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Mobile==&lt;br /&gt;
*[[Hosted Email Base:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Base and Standard Accounts&lt;br /&gt;
*[[Hosted_Email:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Premium Account configuration with Profile&lt;br /&gt;
*[[Apple iOS Devices - iPhone iPad with Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra email, &amp;amp; Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Android|Android]]&lt;br /&gt;
*[[Android Portable Devices with Microsoft Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra, and Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Windows_Mobile|Windows Mobile &amp;amp; Windows Phone 8]]&lt;br /&gt;
*[[Hosted_Email:BlackBerry|BlackBerry IMAP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]] Terminal based. Works on Linux and Mac OS.&lt;br /&gt;
* Zimbra Desktop -  Zimbra deprecating at end of 2019. Use configuration settings provided at top of page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Convert from POP to IMAP ==&lt;br /&gt;
* Thunderbird POP to IMAP process: https://support.mozilla.org/en-US/kb/switch-pop-imap-account&lt;br /&gt;
* [[Windows Outlook 2007 POP to Zimbra IMAP]] Essentially same instructions for 2003.&lt;br /&gt;
* [[Outlook Express POP to Zimbra IMAP]]&lt;br /&gt;
* [[Windows Live Mail POP to Zimbra IMAP]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Client Email Configuration]]&lt;br /&gt;
[[Category:Email]]&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Hosted_Email:Zimbra_Self-Service_Account_Recovery&amp;diff=11481</id>
		<title>Hosted Email:Zimbra Self-Service Account Recovery</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Hosted_Email:Zimbra_Self-Service_Account_Recovery&amp;diff=11481"/>
		<updated>2023-03-17T16:10:18Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Zimbra business email users can recover their account by resetting their own passwords by using the &amp;quot;Forgot Password&amp;quot; link on Zimbra webmail login page. The process utilizes a recovery email address of the users choice; it doesn&#039;t have to be under the Zimbra domain, and can be a valid third party email address. &lt;br /&gt;
&lt;br /&gt;
== Setting Up Password Recovery Email ==&lt;br /&gt;
There are two parts to the account recovery using Zimbra&#039;s password reset functionality. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Step One:&#039;&#039;&#039; Establish the recovery email address. &lt;br /&gt;
: In the Zimbra web client ([https://zimbra.xmission.com zimbra.xmission.com]), go to &#039;&#039;&#039;Preferences &amp;gt; Accounts&#039;&#039;&#039;, and you&#039;ll find a new section called &#039;&#039;&#039;Password Recovery Account Settings&#039;&#039;&#039;. Enter a valid email for password recovery address and click &amp;quot;Add Recovery Email.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Step Two:&#039;&#039;&#039; Validate the recovery email address and save.&lt;br /&gt;
: Open your recovery address mailbox and retrieve the verification code. This verification code is only valid for 10 minutes. Return to the Zimbra webmail and enter the verification code in its field under the &amp;quot;Password Recovery Account Settings&amp;quot; section within 10 minutes of clicking the &amp;quot;Add Recovery Email&amp;quot; button. This should confirm the setting. Remember to hit &amp;quot;Save&amp;quot; when existing Zimbra webmail preferences.&lt;br /&gt;
&lt;br /&gt;
Your recovery process is now validated and established.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note&#039;&#039;&#039;: If you have a personal Zimbra email address ending @XMission.com you will not be able to use this feature to recover your account and instead will need to update your password using the tools found at [https://xmission.com/control the XMission Control Panel].&lt;br /&gt;
&lt;br /&gt;
== Using Forgot Password to Reset Your Password ==&lt;br /&gt;
Once a recovery email is setup, the Zimbra self-service password recovery can be used. &lt;br /&gt;
* To recover your Zimbra mailbox account you can click on the &amp;quot;&#039;&#039;&#039;Forgot Password&#039;&#039;&#039;&amp;quot; link on the Zimbra web client login page ([https://zimbra.xmission.com zimbra.xmission.com]).&lt;br /&gt;
[[File:Zimbrapwrecov1.png]]&lt;br /&gt;
* Enter the full email address of the account you are trying to recover, then click the &amp;quot;&#039;&#039;&#039;Submit&#039;&#039;&#039;&amp;quot; button.&lt;br /&gt;
[[File:Zimbrapwrecov2.png]]&lt;br /&gt;
* On the following page, click the &amp;quot;&#039;&#039;&#039;Request Code&#039;&#039;&#039;&amp;quot; button at the bottom of the box. This will send a code to your recovery email address. Like the verification code, this reset code is only valid for 10 minutes. &lt;br /&gt;
[[File:Zimbrapwrecov3.png]]&lt;br /&gt;
* Open that address mailbox and retrieve the reset code which you will enter on the Zimbra webmail recovery form. The email will look like this:&lt;br /&gt;
[[File:Zimbrapwrecov4.png]]&lt;br /&gt;
* Go back to the Zimbra webmail recovery form, and enter the reset code within 10 minutes of clicking the &amp;quot;&#039;&#039;&#039;Request Code&#039;&#039;&#039;&amp;quot; button from the previous page. Then click the &amp;quot;&#039;&#039;&#039;Verify Code&#039;&#039;&#039;&amp;quot; button. &lt;br /&gt;
[[File:Zimbrapwrecov5.png]]&lt;br /&gt;
* On this page you can either choose to log into the web client directly, or you can choose to reset your password. We&#039;ll want to choose &amp;quot;&#039;&#039;&#039;Reset Password&#039;&#039;&#039;&amp;quot; for this example. &lt;br /&gt;
[[File:Zimbrapwrecov6.png]]&lt;br /&gt;
* At this point you will be prompted to establish a new password.&lt;br /&gt;
: &#039;&#039;&#039;Note&#039;&#039;&#039;: Always create new secure passwords, never re-use passwords from other sites as they are likely compromised. Password managers make this process easy and will generate secure passwords for you.&lt;br /&gt;
* Once you have entered and confirmed your new password, click the &amp;quot;&#039;&#039;&#039;Submit&#039;&#039;&#039;&amp;quot; button to set it. &lt;br /&gt;
[[File:Zimbrapwrecov7.png]]&lt;br /&gt;
* With that, your password has been reset! &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important&#039;&#039;&#039;: Remember to update all devices and applications that were using the previous password. This can include; email, calendars, contacts, tasks, notes, and files.&lt;br /&gt;
&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11480</id>
		<title>SPF and DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11480"/>
		<updated>2023-03-09T21:33:21Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* DKIM DNS */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SPF and DKIM are two important security methods domain owners have of &amp;quot;authorizing&amp;quot; specific email servers to send mail on their behalf. Besides providing greater deliverability of your messages, these mechanisms prevent fraudsters from sending spoofing emails as your domain. &lt;br /&gt;
&lt;br /&gt;
These TXT records are entered by the domain owner wherever the domain&#039;s DNS record is managed, which may be with the registrar or hosting provider. DKIM (Domain Key Identified Mail) also adds public key cryptography for deeper validation.&lt;br /&gt;
&lt;br /&gt;
XMission advises all [https://xmission.com/zimbra Zimbra clients] to configure SPF &amp;amp; DKIM. It may sound a bit daunting but is really not very complicated. This document will walk you through it. &lt;br /&gt;
&lt;br /&gt;
IMPORTANT NOTE ABOUT TXT RECORD ENTRY: Depending on the syntax requirements of your DNS system you may have to include or omit the quotation marks for the record to be properly enabled. Other DNS entries on your domain should provide quick visual guidance on protocol. XMission DNS systems do &#039;&#039;not&#039;&#039; use quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= SPF =&lt;br /&gt;
The following is the  most commonly applied SPF (Sender Policy Framework) record for XMission email customers but it is imperative you understand how and why this is applied. IMPORTANT: It is critical that you read and understand all SPF information below before applying the record to your domain as you could break email delivery.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How It Works ==&lt;br /&gt;
Any SPF record is a string of one more more potential mail sources, prefixed by a character indicating the policy for mail source. An example of a common SPF record:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Example Syntax&lt;br /&gt;
|-&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf a mx ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In this case, it says that the A and MX records for the domain are allowed to send, and all other mail fails (but with a &amp;quot;softfail&amp;quot;, so that mail isn&#039;t actually rejected). &amp;quot;a&amp;quot;, &amp;quot;mx&amp;quot; and &amp;quot;all&amp;quot;, are all individual mail sources. The &amp;quot;~&amp;quot; prefixed to the &amp;quot;all&amp;quot; source is a policy denoting that mail from the source should be considered a &amp;quot;SoftFail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Sources &amp;amp; Definitions&lt;br /&gt;
|-&lt;br /&gt;
! Flag !! Source Type&lt;br /&gt;
|-&lt;br /&gt;
| a || DNS A record&lt;br /&gt;
|-&lt;br /&gt;
| mx || MX record&lt;br /&gt;
|-&lt;br /&gt;
| ptr || PTR record&lt;br /&gt;
|-&lt;br /&gt;
| ip4 || IPv4 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| ip6 || IPv6 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| include || The contents of another domain&#039;s SPF record&lt;br /&gt;
|-&lt;br /&gt;
| all || Any mail source (generally used at the end to provide a default policy)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Prefix Characters&lt;br /&gt;
|-&lt;br /&gt;
! Prefix !! Definition&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;+&#039;&#039;&#039; || Pass (Valid for SPF)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;-&#039;&#039;&#039; || Fail (Invalid, and reject mail)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;~&#039;&#039;&#039; || SoftFail (Invalid, but still accept)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;?&#039;&#039;&#039; || Neutral (...whatever...)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
XMission Shared Hosting clients can [https://wiki.xmission.com/Adding/Managing_DNS_Records learn to manage DNS records here.]&lt;br /&gt;
&lt;br /&gt;
== Valid SPF for XMission ==&lt;br /&gt;
Any SPF record for a domain sending through XMission should contain &amp;quot;include:_spf.xmission.com&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
If you prefer a less identifiable entry then a minimum inclusion would have the following two sources:&lt;br /&gt;
&lt;br /&gt;
* ip4:166.70.13.0/24&lt;br /&gt;
* ip4:198.60.22.0/24&lt;br /&gt;
&lt;br /&gt;
Note that the SPF record policy is a decision of the domain owner&#039;s. If they want to Fail or SoftFail on all, add other sources, etc., is up to them. We don&#039;t have a singular recommendation or requirement for SPF. If the customer &#039;&#039;&#039;only&#039;&#039;&#039; sends via XMission, the following SPF record is relatively safe:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===Valid SPF for XMission with additional sending services===&lt;br /&gt;
&lt;br /&gt;
Sometimes it is necessary to have mailing list or other services that need to send emails so having multiple SPF records be strung together becomes necessary. Fortunately the fairly lenient syntax of SPF records makes this easy to do, here is our default record compared to some merged records:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Hosts Generating Emails !! Example of Merged SPF Record&lt;br /&gt;
|-&lt;br /&gt;
| Default XMission || v=spf1 a mx include:_spf.xmission.com ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Mailchimp || v=spf1 include:_spf.xmission.com include:servers.mcsv.net ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Gmail, plus Constant Contact || v=spf1 include:_spf.xmission.com include:_spf.google.com include:spf.constantcontact.com -all&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Forwarding ==&lt;br /&gt;
&#039;&#039;&#039;Important note&#039;&#039;&#039; about forwarding (ie automatically redirecting mail from one email address to another, not hitting the forward button):&lt;br /&gt;
&lt;br /&gt;
Forwarding (under most circumstances) &amp;lt;em&amp;gt;BREAKS&amp;lt;/em&amp;gt; SPF. If a domain has a &amp;quot;-all&amp;quot; (&amp;quot;reject all other mail&amp;quot; aka &amp;quot;Fail&amp;quot;) policy in their SPF record, mail will be rejected by any servers respecting SPF after the server performing the forward. Users should keep this in mind when choosing a policy. This is why we suggest &amp;quot;~all&amp;quot; (&amp;quot;SoftFail&amp;quot;) when you initially configure SPF.&lt;br /&gt;
&lt;br /&gt;
== Alias Domains ==&lt;br /&gt;
Domain aliases that are used for sending email with &amp;quot;From:&amp;quot; addresses will need SPF &amp;amp; DKIM records configured. &lt;br /&gt;
&lt;br /&gt;
All customers are strongly encouraged to configure SPF &amp;amp; DKIM records for all alias domains and parked domains to prevent possible abuse.&lt;br /&gt;
&lt;br /&gt;
= DKIM = &lt;br /&gt;
DomainKeys Identified Mail (DKIM) is similar to SPF in that it uses a TXT record on the domain to define a sending policy for that domain. Where it differs is that it uses public key cryptography with this sending policy. A public key is added to that TXT record and any message that is signed with the private key (and thus validates with the public key) is then considered valid.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;DKIM will break automatic responders, like &#039;&#039;Out of Office&#039;&#039; or &#039;&#039;Vacation&#039;&#039; replies.&#039;&#039;&#039; This is due to how DKIM verifies the sender, and how automated replies are generated and sent.  This is intentional, and is a consideration that needs to be made when limiting sending from your domain via DKIM.&lt;br /&gt;
&lt;br /&gt;
== Adding DKIM to an XMission Domain ==&lt;br /&gt;
We have a single private key for XMission DKIM signing. We can sign DKIM with this key on any domain sending out through XMission. It works for Zimbra domains, virtmail, and SMTP relay. To enable this feature for a domain, two things need to happen:&lt;br /&gt;
&lt;br /&gt;
* The domain needs proper DNS for our domainkey key (see below)&lt;br /&gt;
* The domain needs to be added to XMission routing config as one with DKIM signing.&lt;br /&gt;
&lt;br /&gt;
== DKIM DNS ==&lt;br /&gt;
Add the following two TXT records to the domain.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note&#039;&#039;&#039;: Once added you must [https://xmission.com/contact contact] [mailto:support@xmission.com support@xmission.com] to add your domain to XMission&#039;s DKIM routing file and complete the process:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| xmission._domainkey || TXT || &amp;quot;v=DKIM1; t=y; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzWmoe0tzQkSUzMqliwcQQ5zY1HKk4z+Wgp+dRCRe7MmSBPftE9r5Lx1QfTfF/J8gl4k9tFsUvUBap0fk1VGMYUG/2LynVuzpkCI4JlUKF5fbx+MDNZrVi0aX73Edjd9trU6NKldVnhNg1RixDLa4aB04XJviy6+3P1h3IHNaZ0QIDAQAB&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| _domainkey || TXT || &amp;quot;t=y; o=~;&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Reminder: XMission DNS systems do not require entry of the quotation marks on the records above. External DNS system may require quotation marks.&lt;br /&gt;
&lt;br /&gt;
====Multiple Email Hosts with DKIM ====&lt;br /&gt;
&lt;br /&gt;
It is possible to use more than one host with DKIM, though this is only possible if the DNS records used to announce the public key for the security handshake don&#039;t share subdomains with each other.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11479</id>
		<title>SPF and DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11479"/>
		<updated>2023-03-09T21:29:43Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* DKIM */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SPF and DKIM are two important security methods domain owners have of &amp;quot;authorizing&amp;quot; specific email servers to send mail on their behalf. Besides providing greater deliverability of your messages, these mechanisms prevent fraudsters from sending spoofing emails as your domain. &lt;br /&gt;
&lt;br /&gt;
These TXT records are entered by the domain owner wherever the domain&#039;s DNS record is managed, which may be with the registrar or hosting provider. DKIM (Domain Key Identified Mail) also adds public key cryptography for deeper validation.&lt;br /&gt;
&lt;br /&gt;
XMission advises all [https://xmission.com/zimbra Zimbra clients] to configure SPF &amp;amp; DKIM. It may sound a bit daunting but is really not very complicated. This document will walk you through it. &lt;br /&gt;
&lt;br /&gt;
IMPORTANT NOTE ABOUT TXT RECORD ENTRY: Depending on the syntax requirements of your DNS system you may have to include or omit the quotation marks for the record to be properly enabled. Other DNS entries on your domain should provide quick visual guidance on protocol. XMission DNS systems do &#039;&#039;not&#039;&#039; use quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= SPF =&lt;br /&gt;
The following is the  most commonly applied SPF (Sender Policy Framework) record for XMission email customers but it is imperative you understand how and why this is applied. IMPORTANT: It is critical that you read and understand all SPF information below before applying the record to your domain as you could break email delivery.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How It Works ==&lt;br /&gt;
Any SPF record is a string of one more more potential mail sources, prefixed by a character indicating the policy for mail source. An example of a common SPF record:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Example Syntax&lt;br /&gt;
|-&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf a mx ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In this case, it says that the A and MX records for the domain are allowed to send, and all other mail fails (but with a &amp;quot;softfail&amp;quot;, so that mail isn&#039;t actually rejected). &amp;quot;a&amp;quot;, &amp;quot;mx&amp;quot; and &amp;quot;all&amp;quot;, are all individual mail sources. The &amp;quot;~&amp;quot; prefixed to the &amp;quot;all&amp;quot; source is a policy denoting that mail from the source should be considered a &amp;quot;SoftFail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Sources &amp;amp; Definitions&lt;br /&gt;
|-&lt;br /&gt;
! Flag !! Source Type&lt;br /&gt;
|-&lt;br /&gt;
| a || DNS A record&lt;br /&gt;
|-&lt;br /&gt;
| mx || MX record&lt;br /&gt;
|-&lt;br /&gt;
| ptr || PTR record&lt;br /&gt;
|-&lt;br /&gt;
| ip4 || IPv4 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| ip6 || IPv6 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| include || The contents of another domain&#039;s SPF record&lt;br /&gt;
|-&lt;br /&gt;
| all || Any mail source (generally used at the end to provide a default policy)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Prefix Characters&lt;br /&gt;
|-&lt;br /&gt;
! Prefix !! Definition&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;+&#039;&#039;&#039; || Pass (Valid for SPF)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;-&#039;&#039;&#039; || Fail (Invalid, and reject mail)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;~&#039;&#039;&#039; || SoftFail (Invalid, but still accept)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;?&#039;&#039;&#039; || Neutral (...whatever...)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
XMission Shared Hosting clients can [https://wiki.xmission.com/Adding/Managing_DNS_Records learn to manage DNS records here.]&lt;br /&gt;
&lt;br /&gt;
== Valid SPF for XMission ==&lt;br /&gt;
Any SPF record for a domain sending through XMission should contain &amp;quot;include:_spf.xmission.com&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
If you prefer a less identifiable entry then a minimum inclusion would have the following two sources:&lt;br /&gt;
&lt;br /&gt;
* ip4:166.70.13.0/24&lt;br /&gt;
* ip4:198.60.22.0/24&lt;br /&gt;
&lt;br /&gt;
Note that the SPF record policy is a decision of the domain owner&#039;s. If they want to Fail or SoftFail on all, add other sources, etc., is up to them. We don&#039;t have a singular recommendation or requirement for SPF. If the customer &#039;&#039;&#039;only&#039;&#039;&#039; sends via XMission, the following SPF record is relatively safe:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===Valid SPF for XMission with additional sending services===&lt;br /&gt;
&lt;br /&gt;
Sometimes it is necessary to have mailing list or other services that need to send emails so having multiple SPF records be strung together becomes necessary. Fortunately the fairly lenient syntax of SPF records makes this easy to do, here is our default record compared to some merged records:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Hosts Generating Emails !! Example of Merged SPF Record&lt;br /&gt;
|-&lt;br /&gt;
| Default XMission || v=spf1 a mx include:_spf.xmission.com ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Mailchimp || v=spf1 include:_spf.xmission.com include:servers.mcsv.net ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Gmail, plus Constant Contact || v=spf1 include:_spf.xmission.com include:_spf.google.com include:spf.constantcontact.com -all&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Forwarding ==&lt;br /&gt;
&#039;&#039;&#039;Important note&#039;&#039;&#039; about forwarding (ie automatically redirecting mail from one email address to another, not hitting the forward button):&lt;br /&gt;
&lt;br /&gt;
Forwarding (under most circumstances) &amp;lt;em&amp;gt;BREAKS&amp;lt;/em&amp;gt; SPF. If a domain has a &amp;quot;-all&amp;quot; (&amp;quot;reject all other mail&amp;quot; aka &amp;quot;Fail&amp;quot;) policy in their SPF record, mail will be rejected by any servers respecting SPF after the server performing the forward. Users should keep this in mind when choosing a policy. This is why we suggest &amp;quot;~all&amp;quot; (&amp;quot;SoftFail&amp;quot;) when you initially configure SPF.&lt;br /&gt;
&lt;br /&gt;
== Alias Domains ==&lt;br /&gt;
Domain aliases that are used for sending email with &amp;quot;From:&amp;quot; addresses will need SPF &amp;amp; DKIM records configured. &lt;br /&gt;
&lt;br /&gt;
All customers are strongly encouraged to configure SPF &amp;amp; DKIM records for all alias domains and parked domains to prevent possible abuse.&lt;br /&gt;
&lt;br /&gt;
= DKIM = &lt;br /&gt;
DomainKeys Identified Mail (DKIM) is similar to SPF in that it uses a TXT record on the domain to define a sending policy for that domain. Where it differs is that it uses public key cryptography with this sending policy. A public key is added to that TXT record and any message that is signed with the private key (and thus validates with the public key) is then considered valid.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;DKIM will break automatic responders, like &#039;&#039;Out of Office&#039;&#039; or &#039;&#039;Vacation&#039;&#039; replies.&#039;&#039;&#039; This is due to how DKIM verifies the sender, and how automated replies are generated and sent.  This is intentional, and is a consideration that needs to be made when limiting sending from your domain via DKIM.&lt;br /&gt;
&lt;br /&gt;
== Adding DKIM to an XMission Domain ==&lt;br /&gt;
We have a single private key for XMission DKIM signing. We can sign DKIM with this key on any domain sending out through XMission. It works for Zimbra domains, virtmail, and SMTP relay. To enable this feature for a domain, two things need to happen:&lt;br /&gt;
&lt;br /&gt;
* The domain needs proper DNS for our domainkey key (see below)&lt;br /&gt;
* The domain needs to be added to XMission routing config as one with DKIM signing.&lt;br /&gt;
&lt;br /&gt;
== DKIM DNS ==&lt;br /&gt;
Add the following two TXT records to the domain. Once added you must [https://xmission.com/contact contact] [mailto:support@xmission.com support@xmission.com] to add your domain to XMission&#039;s DKIM routing file and complete the process:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| xmission._domainkey || TXT || &amp;quot;v=DKIM1; t=y; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzWmoe0tzQkSUzMqliwcQQ5zY1HKk4z+Wgp+dRCRe7MmSBPftE9r5Lx1QfTfF/J8gl4k9tFsUvUBap0fk1VGMYUG/2LynVuzpkCI4JlUKF5fbx+MDNZrVi0aX73Edjd9trU6NKldVnhNg1RixDLa4aB04XJviy6+3P1h3IHNaZ0QIDAQAB&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| _domainkey || TXT || &amp;quot;t=y; o=~;&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Reminder: XMission DNS systems do not require entry of the quotation marks on the records above. External DNS system may require quotation marks.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Multiple Email Hosts with DKIM&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
It is possible to use more than one host with DKIM, though this is only possible if the DNS records used to announce the public key for the security handshake don&#039;t share subdomains with each other.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11478</id>
		<title>SPF and DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11478"/>
		<updated>2023-03-09T21:22:41Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* How It Works */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SPF and DKIM are two important security methods domain owners have of &amp;quot;authorizing&amp;quot; specific email servers to send mail on their behalf. Besides providing greater deliverability of your messages, these mechanisms prevent fraudsters from sending spoofing emails as your domain. &lt;br /&gt;
&lt;br /&gt;
These TXT records are entered by the domain owner wherever the domain&#039;s DNS record is managed, which may be with the registrar or hosting provider. DKIM (Domain Key Identified Mail) also adds public key cryptography for deeper validation.&lt;br /&gt;
&lt;br /&gt;
XMission advises all [https://xmission.com/zimbra Zimbra clients] to configure SPF &amp;amp; DKIM. It may sound a bit daunting but is really not very complicated. This document will walk you through it. &lt;br /&gt;
&lt;br /&gt;
IMPORTANT NOTE ABOUT TXT RECORD ENTRY: Depending on the syntax requirements of your DNS system you may have to include or omit the quotation marks for the record to be properly enabled. Other DNS entries on your domain should provide quick visual guidance on protocol. XMission DNS systems do &#039;&#039;not&#039;&#039; use quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= SPF =&lt;br /&gt;
The following is the  most commonly applied SPF (Sender Policy Framework) record for XMission email customers but it is imperative you understand how and why this is applied. IMPORTANT: It is critical that you read and understand all SPF information below before applying the record to your domain as you could break email delivery.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How It Works ==&lt;br /&gt;
Any SPF record is a string of one more more potential mail sources, prefixed by a character indicating the policy for mail source. An example of a common SPF record:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Example Syntax&lt;br /&gt;
|-&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf a mx ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In this case, it says that the A and MX records for the domain are allowed to send, and all other mail fails (but with a &amp;quot;softfail&amp;quot;, so that mail isn&#039;t actually rejected). &amp;quot;a&amp;quot;, &amp;quot;mx&amp;quot; and &amp;quot;all&amp;quot;, are all individual mail sources. The &amp;quot;~&amp;quot; prefixed to the &amp;quot;all&amp;quot; source is a policy denoting that mail from the source should be considered a &amp;quot;SoftFail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Sources &amp;amp; Definitions&lt;br /&gt;
|-&lt;br /&gt;
! Flag !! Source Type&lt;br /&gt;
|-&lt;br /&gt;
| a || DNS A record&lt;br /&gt;
|-&lt;br /&gt;
| mx || MX record&lt;br /&gt;
|-&lt;br /&gt;
| ptr || PTR record&lt;br /&gt;
|-&lt;br /&gt;
| ip4 || IPv4 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| ip6 || IPv6 address or subnet&lt;br /&gt;
|-&lt;br /&gt;
| include || The contents of another domain&#039;s SPF record&lt;br /&gt;
|-&lt;br /&gt;
| all || Any mail source (generally used at the end to provide a default policy)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Prefix Characters&lt;br /&gt;
|-&lt;br /&gt;
! Prefix !! Definition&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;+&#039;&#039;&#039; || Pass (Valid for SPF)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;-&#039;&#039;&#039; || Fail (Invalid, and reject mail)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;~&#039;&#039;&#039; || SoftFail (Invalid, but still accept)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;?&#039;&#039;&#039; || Neutral (...whatever...)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
XMission Shared Hosting clients can [https://wiki.xmission.com/Adding/Managing_DNS_Records learn to manage DNS records here.]&lt;br /&gt;
&lt;br /&gt;
== Valid SPF for XMission ==&lt;br /&gt;
Any SPF record for a domain sending through XMission should contain &amp;quot;include:_spf.xmission.com&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
If you prefer a less identifiable entry then a minimum inclusion would have the following two sources:&lt;br /&gt;
&lt;br /&gt;
* ip4:166.70.13.0/24&lt;br /&gt;
* ip4:198.60.22.0/24&lt;br /&gt;
&lt;br /&gt;
Note that the SPF record policy is a decision of the domain owner&#039;s. If they want to Fail or SoftFail on all, add other sources, etc., is up to them. We don&#039;t have a singular recommendation or requirement for SPF. If the customer &#039;&#039;&#039;only&#039;&#039;&#039; sends via XMission, the following SPF record is relatively safe:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===Valid SPF for XMission with additional sending services===&lt;br /&gt;
&lt;br /&gt;
Sometimes it is necessary to have mailing list or other services that need to send emails so having multiple SPF records be strung together becomes necessary. Fortunately the fairly lenient syntax of SPF records makes this easy to do, here is our default record compared to some merged records:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Hosts Generating Emails !! Example of Merged SPF Record&lt;br /&gt;
|-&lt;br /&gt;
| Default XMission || v=spf1 a mx include:_spf.xmission.com ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Mailchimp || v=spf1 include:_spf.xmission.com include:servers.mcsv.net ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Gmail, plus Constant Contact || v=spf1 include:_spf.xmission.com include:_spf.google.com include:spf.constantcontact.com -all&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Forwarding ==&lt;br /&gt;
&#039;&#039;&#039;Important note&#039;&#039;&#039; about forwarding (ie automatically redirecting mail from one email address to another, not hitting the forward button):&lt;br /&gt;
&lt;br /&gt;
Forwarding (under most circumstances) &amp;lt;em&amp;gt;BREAKS&amp;lt;/em&amp;gt; SPF. If a domain has a &amp;quot;-all&amp;quot; (&amp;quot;reject all other mail&amp;quot; aka &amp;quot;Fail&amp;quot;) policy in their SPF record, mail will be rejected by any servers respecting SPF after the server performing the forward. Users should keep this in mind when choosing a policy. This is why we suggest &amp;quot;~all&amp;quot; (&amp;quot;SoftFail&amp;quot;) when you initially configure SPF.&lt;br /&gt;
&lt;br /&gt;
== Alias Domains ==&lt;br /&gt;
Domain aliases that are used for sending email with &amp;quot;From:&amp;quot; addresses will need SPF &amp;amp; DKIM records configured. &lt;br /&gt;
&lt;br /&gt;
All customers are strongly encouraged to configure SPF &amp;amp; DKIM records for all alias domains and parked domains to prevent possible abuse.&lt;br /&gt;
&lt;br /&gt;
= DKIM = &lt;br /&gt;
&lt;br /&gt;
== How DKIM Works ==&lt;br /&gt;
DKIM is similar to SPF in that it uses a TXT record on the domain to define a sending policy for that domain. Where it differs is that it uses public key cryptography with this sending policy. A public key is added to that TXT record and any message that is signed with the private key (and thus validates with the public key) is then considered valid.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;DKIM will break automatic responders, like &#039;&#039;Out of Office&#039;&#039; or &#039;&#039;Vacation&#039;&#039; replies.&#039;&#039;&#039; This is due to how DKIM verifies the sender, and how automated replies are generated and sent.  This is intentional, and is a consideration that needs to be made when limiting sending from your domain via DKIM.&lt;br /&gt;
&lt;br /&gt;
== Adding DKIM to an XMission Domain ==&lt;br /&gt;
We have a single private key for XMission DKIM signing. We can sign DKIM with this key on any domain sending out through XMission. It works for Zimbra domains, virtmail, and SMTP relay. To enable this feature for a domain, two things need to happen:&lt;br /&gt;
&lt;br /&gt;
* The domain needs proper DNS for our domainkey key (see below)&lt;br /&gt;
* The domain needs to be added to XMission routing config as one with DKIM signing.&lt;br /&gt;
&lt;br /&gt;
== DKIM DNS ==&lt;br /&gt;
Add the following two TXT records to the domain. Once added you must [https://xmission.com/contact contact] [mailto:support@xmission.com support@xmission.com] to add your domain to XMission&#039;s DKIM routing file and complete the process:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| xmission._domainkey || TXT || &amp;quot;v=DKIM1; t=y; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzWmoe0tzQkSUzMqliwcQQ5zY1HKk4z+Wgp+dRCRe7MmSBPftE9r5Lx1QfTfF/J8gl4k9tFsUvUBap0fk1VGMYUG/2LynVuzpkCI4JlUKF5fbx+MDNZrVi0aX73Edjd9trU6NKldVnhNg1RixDLa4aB04XJviy6+3P1h3IHNaZ0QIDAQAB&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| _domainkey || TXT || &amp;quot;t=y; o=~;&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Reminder: XMission DNS systems do not require entry of the quotation marks on the records above. External DNS system may require quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Multiple Email Hosts with DKIM&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
It is possible to use more than one host with DKIM, though this is only possible if the DNS records used to announce the public key for the security handshake don&#039;t share subdomains with each other.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11477</id>
		<title>SPF and DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11477"/>
		<updated>2023-03-09T19:11:30Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* Valid SPF for XMission */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SPF and DKIM are two important security methods domain owners have of &amp;quot;authorizing&amp;quot; specific email servers to send mail on their behalf. Besides providing greater deliverability of your messages, these mechanisms prevent fraudsters from sending spoofing emails as your domain. &lt;br /&gt;
&lt;br /&gt;
These TXT records are entered by the domain owner wherever the domain&#039;s DNS record is managed, which may be with the registrar or hosting provider. DKIM (Domain Key Identified Mail) also adds public key cryptography for deeper validation.&lt;br /&gt;
&lt;br /&gt;
XMission advises all [https://xmission.com/zimbra Zimbra clients] to configure SPF &amp;amp; DKIM. It may sound a bit daunting but is really not very complicated. This document will walk you through it. &lt;br /&gt;
&lt;br /&gt;
IMPORTANT NOTE ABOUT TXT RECORD ENTRY: Depending on the syntax requirements of your DNS system you may have to include or omit the quotation marks for the record to be properly enabled. Other DNS entries on your domain should provide quick visual guidance on protocol. XMission DNS systems do &#039;&#039;not&#039;&#039; use quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= SPF =&lt;br /&gt;
The following is the  most commonly applied SPF (Sender Policy Framework) record for XMission email customers but it is imperative you understand how and why this is applied. IMPORTANT: It is critical that you read and understand all SPF information below before applying the record to your domain as you could break email delivery.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How It Works ==&lt;br /&gt;
Any SPF record is a string of one more more potential mail sources, prefixed by a character indicating the policy for mail source. An example of a common SPF record:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Example Syntax&lt;br /&gt;
|-&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf a mx ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In this case, it says that the A and MX records for the domain are allowed to send, and all other mail fails (but with a &amp;quot;softfail&amp;quot;, so that mail isn&#039;t actually rejected). &amp;quot;a&amp;quot;, &amp;quot;mx&amp;quot; and &amp;quot;all&amp;quot;, are all individual mail sources. The &amp;quot;~&amp;quot; prefixed to the &amp;quot;all&amp;quot; source is a policy denoting that mail from the source should be considered a &amp;quot;SoftFail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The sources are:&lt;br /&gt;
&lt;br /&gt;
* a - A DNS A record&lt;br /&gt;
* mx - An MX record&lt;br /&gt;
* ptr - A PTR record&lt;br /&gt;
* ip4 - An ipv4 address or subnet&lt;br /&gt;
* ip6 - An ipv6 address or subnet&lt;br /&gt;
* include - The contents of another domain&#039;s SPF record&lt;br /&gt;
* all - Any mail source (generally used at the end to provide a default policy)&lt;br /&gt;
&lt;br /&gt;
The prefix characters are:&lt;br /&gt;
&lt;br /&gt;
* + - Pass (Valid for SPF)&lt;br /&gt;
* - - Fail (Invalid, and reject mail)&lt;br /&gt;
* ~ - SoftFail (Invalid, but still accept)&lt;br /&gt;
* ? - Neutral (...whatever...)&lt;br /&gt;
&lt;br /&gt;
XMission shared hosting clients can [https://wiki.xmission.com/Adding/Managing_DNS_Records learn to manage DNS records here.]&lt;br /&gt;
&lt;br /&gt;
== Valid SPF for XMission ==&lt;br /&gt;
Any SPF record for a domain sending through XMission should contain &amp;quot;include:_spf.xmission.com&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
If you prefer a less identifiable entry then a minimum inclusion would have the following two sources:&lt;br /&gt;
&lt;br /&gt;
* ip4:166.70.13.0/24&lt;br /&gt;
* ip4:198.60.22.0/24&lt;br /&gt;
&lt;br /&gt;
Note that the SPF record policy is a decision of the domain owner&#039;s. If they want to Fail or SoftFail on all, add other sources, etc., is up to them. We don&#039;t have a singular recommendation or requirement for SPF. If the customer &#039;&#039;&#039;only&#039;&#039;&#039; sends via XMission, the following SPF record is relatively safe:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===Valid SPF for XMission with additional sending services===&lt;br /&gt;
&lt;br /&gt;
Sometimes it is necessary to have mailing list or other services that need to send emails so having multiple SPF records be strung together becomes necessary. Fortunately the fairly lenient syntax of SPF records makes this easy to do, here is our default record compared to some merged records:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Hosts Generating Emails !! Example of Merged SPF Record&lt;br /&gt;
|-&lt;br /&gt;
| Default XMission || v=spf1 a mx include:_spf.xmission.com ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Mailchimp || v=spf1 include:_spf.xmission.com include:servers.mcsv.net ~all&lt;br /&gt;
|-&lt;br /&gt;
| XMission plus Gmail, plus Constant Contact || v=spf1 include:_spf.xmission.com include:_spf.google.com include:spf.constantcontact.com -all&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Forwarding ==&lt;br /&gt;
&#039;&#039;&#039;Important note&#039;&#039;&#039; about forwarding (ie automatically redirecting mail from one email address to another, not hitting the forward button):&lt;br /&gt;
&lt;br /&gt;
Forwarding (under most circumstances) &amp;lt;em&amp;gt;BREAKS&amp;lt;/em&amp;gt; SPF. If a domain has a &amp;quot;-all&amp;quot; (&amp;quot;reject all other mail&amp;quot; aka &amp;quot;Fail&amp;quot;) policy in their SPF record, mail will be rejected by any servers respecting SPF after the server performing the forward. Users should keep this in mind when choosing a policy. This is why we suggest &amp;quot;~all&amp;quot; (&amp;quot;SoftFail&amp;quot;) when you initially configure SPF.&lt;br /&gt;
&lt;br /&gt;
== Alias Domains ==&lt;br /&gt;
Domain aliases that are used for sending email with &amp;quot;From:&amp;quot; addresses will need SPF &amp;amp; DKIM records configured. &lt;br /&gt;
&lt;br /&gt;
All customers are strongly encouraged to configure SPF &amp;amp; DKIM records for all alias domains and parked domains to prevent possible abuse.&lt;br /&gt;
&lt;br /&gt;
= DKIM = &lt;br /&gt;
&lt;br /&gt;
== How DKIM Works ==&lt;br /&gt;
DKIM is similar to SPF in that it uses a TXT record on the domain to define a sending policy for that domain. Where it differs is that it uses public key cryptography with this sending policy. A public key is added to that TXT record and any message that is signed with the private key (and thus validates with the public key) is then considered valid.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;DKIM will break automatic responders, like &#039;&#039;Out of Office&#039;&#039; or &#039;&#039;Vacation&#039;&#039; replies.&#039;&#039;&#039; This is due to how DKIM verifies the sender, and how automated replies are generated and sent.  This is intentional, and is a consideration that needs to be made when limiting sending from your domain via DKIM.&lt;br /&gt;
&lt;br /&gt;
== Adding DKIM to an XMission Domain ==&lt;br /&gt;
We have a single private key for XMission DKIM signing. We can sign DKIM with this key on any domain sending out through XMission. It works for Zimbra domains, virtmail, and SMTP relay. To enable this feature for a domain, two things need to happen:&lt;br /&gt;
&lt;br /&gt;
* The domain needs proper DNS for our domainkey key (see below)&lt;br /&gt;
* The domain needs to be added to XMission routing config as one with DKIM signing.&lt;br /&gt;
&lt;br /&gt;
== DKIM DNS ==&lt;br /&gt;
Add the following two TXT records to the domain. Once added you must [https://xmission.com/contact contact] [mailto:support@xmission.com support@xmission.com] to add your domain to XMission&#039;s DKIM routing file and complete the process:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| xmission._domainkey || TXT || &amp;quot;v=DKIM1; t=y; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzWmoe0tzQkSUzMqliwcQQ5zY1HKk4z+Wgp+dRCRe7MmSBPftE9r5Lx1QfTfF/J8gl4k9tFsUvUBap0fk1VGMYUG/2LynVuzpkCI4JlUKF5fbx+MDNZrVi0aX73Edjd9trU6NKldVnhNg1RixDLa4aB04XJviy6+3P1h3IHNaZ0QIDAQAB&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| _domainkey || TXT || &amp;quot;t=y; o=~;&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Reminder: XMission DNS systems do not require entry of the quotation marks on the records above. External DNS system may require quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Multiple Email Hosts with DKIM&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
It is possible to use more than one host with DKIM, though this is only possible if the DNS records used to announce the public key for the security handshake don&#039;t share subdomains with each other.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11474</id>
		<title>SPF and DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=SPF_and_DKIM&amp;diff=11474"/>
		<updated>2023-03-01T19:31:05Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SPF and DKIM are two important security methods domain owners have of &amp;quot;authorizing&amp;quot; specific email servers to send mail on their behalf. Besides providing greater deliverability of your messages, these mechanisms prevent fraudsters from sending spoofing emails as your domain. &lt;br /&gt;
&lt;br /&gt;
These TXT records are entered by the domain owner wherever the domain&#039;s DNS record is managed, which may be with the registrar or hosting provider. DKIM (Domain Key Identified Mail) also adds public key cryptography for deeper validation.&lt;br /&gt;
&lt;br /&gt;
XMission advises all [https://xmission.com/zimbra Zimbra clients] to configure SPF &amp;amp; DKIM. It may sound a bit daunting but is really not very complicated. This document will walk you through it. &lt;br /&gt;
&lt;br /&gt;
IMPORTANT NOTE ABOUT TXT RECORD ENTRY: Depending on the syntax requirements of your DNS system you may have to include or omit the quotation marks for the record to be properly enabled. Other DNS entries on your domain should provide quick visual guidance on protocol. XMission DNS systems do &#039;&#039;not&#039;&#039; use quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= SPF =&lt;br /&gt;
The following is the  most commonly applied SPF (Sender Policy Framework) record for XMission email customers but it is imperative you understand how and why this is applied. IMPORTANT: It is critical that you read and understand all SPF information below before applying the record to your domain as you could break email delivery.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== How It Works ==&lt;br /&gt;
Any SPF record is a string of one more more potential mail sources, prefixed by a character indicating the policy for mail source. An example of a common SPF record:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Example Syntax&lt;br /&gt;
|-&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf a mx ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In this case, it says that the A and MX records for the domain are allowed to send, and all other mail fails (but with a &amp;quot;softfail&amp;quot;, so that mail isn&#039;t actually rejected). &amp;quot;a&amp;quot;, &amp;quot;mx&amp;quot; and &amp;quot;all&amp;quot;, are all individual mail sources. The &amp;quot;~&amp;quot; prefixed to the &amp;quot;all&amp;quot; source is a policy denoting that mail from the source should be considered a &amp;quot;SoftFail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The sources are:&lt;br /&gt;
&lt;br /&gt;
* a - A DNS A record&lt;br /&gt;
* mx - An MX record&lt;br /&gt;
* ptr - A PTR record&lt;br /&gt;
* ip4 - An ipv4 address or subnet&lt;br /&gt;
* ip6 - An ipv6 address or subnet&lt;br /&gt;
* include - The contents of another domain&#039;s SPF record&lt;br /&gt;
* all - Any mail source (generally used at the end to provide a default policy)&lt;br /&gt;
&lt;br /&gt;
The prefix characters are:&lt;br /&gt;
&lt;br /&gt;
* + - Pass (Valid for SPF)&lt;br /&gt;
* - - Fail (Invalid, and reject mail)&lt;br /&gt;
* ~ - SoftFail (Invalid, but still accept)&lt;br /&gt;
* ? - Neutral (...whatever...)&lt;br /&gt;
&lt;br /&gt;
XMission shared hosting clients can [https://wiki.xmission.com/Adding/Managing_DNS_Records learn to manage DNS records here.]&lt;br /&gt;
&lt;br /&gt;
== Valid SPF for XMission ==&lt;br /&gt;
Any SPF record for a domain sending through XMission should contain &amp;quot;include:_spf.xmission.com&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
If you prefer a less identifiable entry then a minimum inclusion would have the following two sources:&lt;br /&gt;
&lt;br /&gt;
* ip4:166.70.13.0/24&lt;br /&gt;
* ip4:198.60.22.0/24&lt;br /&gt;
&lt;br /&gt;
Note that the SPF record policy is a decision of the domain owner&#039;s. If they want to Fail or SoftFail on all, add other sources, etc., is up to them. We don&#039;t have a singular recommendation or requirement for SPF. If the customer &#039;&#039;&#039;only&#039;&#039;&#039; sends via XMission, the following SPF record is relatively safe:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| @ (base domain) || TXT || &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Valid SPF for XMission with additional sending services&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
SPF Record Merging&lt;br /&gt;
&lt;br /&gt;
Some customers have mailing list or other email sending requirement that require a number of  records be strung together in the SPF record. Fortunately the fairly lenient syntax of SPF records makes this easy to do, here is our default record compared to some merged records:&lt;br /&gt;
&lt;br /&gt;
Default XMission: &amp;quot;v=spf1 a mx include:_spf.xmission.com ~all&amp;quot;&lt;br /&gt;
&lt;br /&gt;
XMission plus Mailchimp: &amp;quot;v=spf1 include:_spf.xmission.com include:servers.mcsv.net ~all&amp;quot;&lt;br /&gt;
&lt;br /&gt;
XMission plus Gmail, plus Constant Contact: &amp;quot;v=spf1 include:_spf.xmission.com include:_spf.google.com include:spf.constantcontact.com -all&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Forwarding ==&lt;br /&gt;
&#039;&#039;&#039;Important note&#039;&#039;&#039; about forwarding (ie automatically redirecting mail from one email address to another, not hitting the forward button):&lt;br /&gt;
&lt;br /&gt;
Forwarding (under most circumstances) &amp;lt;em&amp;gt;BREAKS&amp;lt;/em&amp;gt; SPF. If a domain has a &amp;quot;-all&amp;quot; (&amp;quot;reject all other mail&amp;quot; aka &amp;quot;Fail&amp;quot;) policy in their SPF record, mail will be rejected by any servers respecting SPF after the server performing the forward. Users should keep this in mind when choosing a policy. This is why we suggest &amp;quot;~all&amp;quot; (&amp;quot;SoftFail&amp;quot;) when you initially configure SPF.&lt;br /&gt;
&lt;br /&gt;
== Alias Domains ==&lt;br /&gt;
Domain aliases that are used for sending email with &amp;quot;From:&amp;quot; addresses will need SPF &amp;amp; DKIM records configured. &lt;br /&gt;
&lt;br /&gt;
All customers are strongly encouraged to configure SPF &amp;amp; DKIM records for all alias domains and parked domains to prevent possible abuse.&lt;br /&gt;
&lt;br /&gt;
= DKIM = &lt;br /&gt;
&lt;br /&gt;
== How DKIM Works ==&lt;br /&gt;
DKIM is similar to SPF in that it uses a TXT record on the domain to define a sending policy for that domain. Where it differs is that it uses public key cryptography with this sending policy. A public key is added to that TXT record and any message that is signed with the private key (and thus validates with the public key) is then considered valid.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;DKIM will break automatic responders, like &#039;&#039;Out of Office&#039;&#039; or &#039;&#039;Vacation&#039;&#039; replies.&#039;&#039;&#039; This is due to how DKIM verifies the sender, and how automated replies are generated and sent.  This is intentional, and is a consideration that needs to be made when limiting sending from your domain via DKIM.&lt;br /&gt;
&lt;br /&gt;
== Adding DKIM to an XMission Domain ==&lt;br /&gt;
We have a single private key for XMission DKIM signing. We can sign DKIM with this key on any domain sending out through XMission. It works for Zimbra domains, virtmail, and SMTP relay. To enable this feature for a domain, two things need to happen:&lt;br /&gt;
&lt;br /&gt;
* The domain needs proper DNS for our domainkey key (see below)&lt;br /&gt;
* The domain needs to be added to XMission routing config as one with DKIM signing.&lt;br /&gt;
&lt;br /&gt;
== DKIM DNS ==&lt;br /&gt;
Add the following two TXT records to the domain. Once added you must [https://xmission.com/contact contact] [mailto:support@xmission.com support@xmission.com] to add your domain to XMission&#039;s DKIM routing file and complete the process:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Host !! Record Type !! Value&lt;br /&gt;
|-&lt;br /&gt;
| xmission._domainkey || TXT || &amp;quot;v=DKIM1; t=y; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzWmoe0tzQkSUzMqliwcQQ5zY1HKk4z+Wgp+dRCRe7MmSBPftE9r5Lx1QfTfF/J8gl4k9tFsUvUBap0fk1VGMYUG/2LynVuzpkCI4JlUKF5fbx+MDNZrVi0aX73Edjd9trU6NKldVnhNg1RixDLa4aB04XJviy6+3P1h3IHNaZ0QIDAQAB&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| _domainkey || TXT || &amp;quot;t=y; o=~;&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Reminder: XMission DNS systems do not require entry of the quotation marks on the records above. External DNS system may require quotation marks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Multiple Email Hosts with DKIM&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
It is possible to use more than one host with DKIM, though this is only possible if the DNS records used to announce the public key for the security handshake don&#039;t share subdomains with each other.&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11469</id>
		<title>Zimbra Email Client Configurations</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11469"/>
		<updated>2023-02-09T21:36:40Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__ &lt;br /&gt;
&lt;br /&gt;
These easy to follow instructions will help you configure your favorite client for use with your Zimbra email service.&amp;lt;br/&amp;gt;&lt;br /&gt;
For greater convenience, you can always access your mail at https://zimbra.xmission.com/&lt;br /&gt;
&lt;br /&gt;
For more help, reference the video repository of helpful tips on the [https://www.youtube.com/channel/UCcB648SoNlCNvyIh4arcTGg Zimbra YouTube Channel].&lt;br /&gt;
&lt;br /&gt;
== Recommended Email Settings==&lt;br /&gt;
&amp;lt;p&amp;gt;XMission always recommends an IMAP email configuration [https://xmission.com/blog/2009/02/09/why-imap-rules heres why.]&amp;lt;/p&amp;gt;&lt;br /&gt;
{| style=&amp;quot;text-align: left; border: 1px solid #ccc;&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;2&amp;quot; &lt;br /&gt;
! style=&amp;quot;border-bottom:1px solid #ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Incoming Server Information:&lt;br /&gt;
! style=&amp;quot;border-style: solid; border-width: 0 0 1px 1px; border-color:#ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Outgoing Server Information:&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Server Type: || IMAP&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Server Type: || SMTP&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Hostname: || zimbra.xmission.com&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Hostname: || zimbra.xmission.com &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Port: || 993&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Port: || 587&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Enable encryption: || YES&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Enable encryption: || YES&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Authenticate Using: || Password&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Requires Authentication: || YES&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Login User Name: || Full email address &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |Login User Name || Full email address&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Alternate Port: || 143, SSL POP3 995 &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |Alternate Port: || 465 (For older systems, no longer supported)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
||Webmail Interface: |||[https://zimbra.xmission.com/ https://zimbra.xmission.com/]&lt;br /&gt;
|-&lt;br /&gt;
||Admin Interface: |||[https://zimbraadmin.xmission.com https://zimbraadmin.xmission.com]&lt;br /&gt;
|-&lt;br /&gt;
||Folders: ||| Sent Mail = &amp;quot;Sent&amp;quot;, Drafts = &amp;quot;Drafts&amp;quot;, Trash = &amp;quot;Trash&amp;quot;, Spam = &amp;quot;Junk&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
||MX Record: ||| mx.xmission.com&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
- Please note that some free wireless hotspots may block SSL without an extra fee. If you cannot send or receive while on certain wifi networks (especially ones in airports or public spaces) please check their terms and conditions and ensure they are not blocking SSL connections.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Videos==&lt;br /&gt;
*[https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra Email on Mac using IMAP]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Windows 10 / 8.x / 7 / Vista==&lt;br /&gt;
*[[Hosted_Email:Outlook_2013|Outlook 2013/2016/365]]&lt;br /&gt;
*[[Hosted_Email:Outlook_2010|Outlook 2010]] &lt;br /&gt;
*[[Hosted_Email:Outlook_Connector|Outlook Connector for Zimbra Premium]] and Personal Premium Zimbra accounts&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Zimbra_41|Thunderbird 41]]&lt;br /&gt;
&lt;br /&gt;
====Archive Windows====&lt;br /&gt;
The following Microsoft Widows mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
* Windows XP - Mail applications on this OS will still work but are no longer supported&lt;br /&gt;
*[[Hosted_Email:Outlook_2007|Outlook 2007]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Outlook 2003]]  &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Windows_Mail|Windows Live Mail]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Outlook_Express|Outlook Express]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup|Thunderbird 3]] &amp;lt;-- Please upgrade your mail application to a current version.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Mac OS== &lt;br /&gt;
These settings are compatible across the bulk all OS X versions.&lt;br /&gt;
*[[Hosted_Email:Outlook_Exchange_on_Mac|Outlook Exchange on Mac]] - For Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:MacMail_16.x|Mac Mail 16.x]] - IMAP setup &lt;br /&gt;
** Video Tutorial - [https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra on Mac Mail]&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Mac|Thunderbird Mac]]&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]]&lt;br /&gt;
&lt;br /&gt;
====Archive Mac OS====&lt;br /&gt;
The following Mac mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
*[[Hosted_Email:MacMail_10.x|Mac Mail 10.x]] Same settings for Mail 11.X and 12.X.&lt;br /&gt;
*[[Hosted_Email:MacMail_9.x|Mac Mail 9.x]]&lt;br /&gt;
**[[Hosted_Email:Calendar_Sync_OSX|Calendar Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
**[[Hosted_Email:Contacts_Sync_OSX|Contacts Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:MacMail_7.x|Mac Mail 7.x]]&lt;br /&gt;
*[[Hosted_Email:MacMail_3|Mac Mail 3.x]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Linux==&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup_Linux|Thunderbird Linux]]&lt;br /&gt;
*[[Hosted_Email:Evolution|Evolution Mail]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Mobile==&lt;br /&gt;
*[[Hosted Email Base:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Base and Standard Accounts&lt;br /&gt;
*[[Hosted_Email:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Premium Account configuration with Profile&lt;br /&gt;
*[[Apple iOS Devices - iPhone iPad with Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra email, &amp;amp; Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Android|Android]]&lt;br /&gt;
*[[Android Portable Devices with Microsoft Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra, and Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Windows_Mobile|Windows Mobile &amp;amp; Windows Phone 8]]&lt;br /&gt;
*[[Hosted_Email:BlackBerry|BlackBerry IMAP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]] Terminal based. Works on Linux and Mac OS.&lt;br /&gt;
* Zimbra Desktop -  Zimbra deprecating at end of 2019. Use configuration settings provided at top of page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Convert from POP to IMAP ==&lt;br /&gt;
* Thunderbird POP to IMAP process: https://support.mozilla.org/en-US/kb/switch-pop-imap-account&lt;br /&gt;
* [[Windows Outlook 2007 POP to Zimbra IMAP]] Essentially same instructions for 2003.&lt;br /&gt;
* [[Outlook Express POP to Zimbra IMAP]]&lt;br /&gt;
* [[Windows Live Mail POP to Zimbra IMAP]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Client Email Configuration|Zimbra]]&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Archive_and_Discovery&amp;diff=11462</id>
		<title>Zimbra Archive and Discovery</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Archive_and_Discovery&amp;diff=11462"/>
		<updated>2023-01-27T18:46:27Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Zimbra Archiving=&lt;br /&gt;
XMission Zimbra hosting now fully supports Archiving.&lt;br /&gt;
Zimbra Archiving is an optional feature that enables archiving of messages that were delivered to or sent by Zimbra Collaboration. &lt;br /&gt;
&lt;br /&gt;
Archiving is setup on a per/account basis. When this feature is enabled for an account, a copy of all email from or to that account is forked at the MTA and a copy of the message is delivered to their archive mailbox.&lt;br /&gt;
&lt;br /&gt;
Zimbra archiving can be set up to create archiving accounts that are maintained within Zimbra Collaboration or to work with third-party archiving systems using SMTP forwarding to send messages to a third-party archive server. For third-party archiving, Zimbra Collaboration is configured to act as the forwarding agent. &lt;br /&gt;
&lt;br /&gt;
==Pricing==&lt;br /&gt;
The current rate of Archive licensed accounts is $1.50 per/month per/mailbox.&lt;br /&gt;
Additional quota is $0.10 per/gig of anything above 20GB. &lt;br /&gt;
&lt;br /&gt;
==Enabling Archiving For Your Accounts==&lt;br /&gt;
In [https://wiki.xmission.com/Hosted_Email:_Admin_Panel Zimbra&#039;s admin interface],&lt;br /&gt;
# Search for the desired user you&#039;d like to enable A&amp;amp;D for.&lt;br /&gt;
# Right-click their account, select &#039;&#039;&#039;edit&#039;&#039;&#039;&lt;br /&gt;
# In the left-hand column that features all their account options, select &#039;&#039;&#039;archiving&#039;&#039;&#039; and if their status displays &amp;quot;&#039;&#039;&#039;enable archiving: No&#039;&#039;&#039;&amp;quot; You can click on the button that says &amp;quot;&#039;&#039;&#039;Enable archiving&#039;&#039;&#039;&amp;quot; &lt;br /&gt;
&lt;br /&gt;
You will also need to create the new target archive mailbox,&lt;br /&gt;
# Click &amp;quot;&#039;&#039;&#039;create&#039;&#039;&#039;&amp;quot; and it should automatically generate your new archiving account.&lt;br /&gt;
# Highlight that account in the list, and then click &amp;quot;&#039;&#039;&#039;Select&#039;&#039;&#039;&amp;quot;&lt;br /&gt;
# You should see the field &amp;quot;Currently archived to&amp;quot; be filled in with that newly created archive box. &#039;&#039;&#039;Save&#039;&#039;&#039;&lt;br /&gt;
After closing out of the account and when you search the user again, you should be able to see two entries in the search results; their regular account, and a separate archive account. &lt;br /&gt;
&lt;br /&gt;
We recommend you verify archiving is working properly by sending a test message to their account, and then proxy the archive mailbox to ensure your test is dropped in there as well. You can proxy a mailbox by right-clicking on the highlighted account and selecting &amp;quot;View mail&amp;quot;&lt;br /&gt;
&lt;br /&gt;
====Retention for Archived accounts====&lt;br /&gt;
Our mail retention policy remains the same even for archived accounts. If a archive mailbox is deleted, mailbox data will be purged 45 days after.&lt;br /&gt;
&lt;br /&gt;
==Discovery==&lt;br /&gt;
If you are trying to locate specific messages across accounts or domains, our helpful support staff is available to conduct a cross-mailbox search for you.&lt;br /&gt;
&lt;br /&gt;
You&#039;ll need to submit a support ticket via email to &#039;&#039;support@xmission.com&#039;&#039; for a request of a cross-mailbox search. You can also head to [http://xmission.com/support Support Resource Center] and under the section titled &#039;&#039;&#039;Other Useful Links&#039;&#039;&#039; click on &#039;&#039;&#039;Email Support/ Open Ticket&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The criteria you&#039;ll want to include to our support staff when making this request would be anything that would help us get relevant hits in the search.&lt;br /&gt;
* Sender&lt;br /&gt;
* Recipient&lt;br /&gt;
* Potential dates of delivery&lt;br /&gt;
* If the message had any attachments or not. &lt;br /&gt;
&lt;br /&gt;
Please note that at this time cross-mailbox search requests will not be handled via phone and chat, only through an emailed support ticket. &lt;br /&gt;
&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Archive_and_Discovery&amp;diff=11461</id>
		<title>Zimbra Archive and Discovery</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Archive_and_Discovery&amp;diff=11461"/>
		<updated>2023-01-27T18:45:36Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Zimbra Archiving=&lt;br /&gt;
XMission Zimbra hosting now fully supports Archiving.&lt;br /&gt;
Zimbra Archiving is an optional feature that enables archiving of messages that were delivered to or sent by Zimbra Collaboration. &lt;br /&gt;
&lt;br /&gt;
Archiving is setup on a per/account basis. When this feature is enabled for an account, a copy of all email from or to that account is forked at the MTA and a copy of the message is delivered to their archive mailbox.&lt;br /&gt;
&lt;br /&gt;
Zimbra archiving can be set up to create archiving accounts that are maintained within Zimbra Collaboration or to work with third-party archiving systems using SMTP forwarding to send messages to a third-party archive server. For third-party archiving, Zimbra Collaboration is configured to act as the forwarding agent. &lt;br /&gt;
&lt;br /&gt;
==Pricing==&lt;br /&gt;
The current rate of Archive licensed accounts is $1.50 per/month per/mailbox.&lt;br /&gt;
Additional quota is $0.10 per/gig of anything above 20GB. &lt;br /&gt;
&lt;br /&gt;
==Enabling Archiving For Your Accounts==&lt;br /&gt;
In [https://wiki.xmission.com/Hosted_Email:_Admin_Panel Zimbra&#039;s admin interface],&lt;br /&gt;
# Search for the desired user you&#039;d like to enable A&amp;amp;D for.&lt;br /&gt;
# Right-click their account, select &#039;&#039;&#039;edit&#039;&#039;&#039;&lt;br /&gt;
# In the left-hand column that features all their account options, select &#039;&#039;&#039;archiving&#039;&#039;&#039; and if their status displays &amp;quot;&#039;&#039;&#039;enable archiving: No&#039;&#039;&#039;&amp;quot; You can click on the button that says &amp;quot;&#039;&#039;&#039;Enable archiving&#039;&#039;&#039;&amp;quot; &lt;br /&gt;
&lt;br /&gt;
You will also need to create the new target archive mailbox,&lt;br /&gt;
# Click &amp;quot;&#039;&#039;&#039;create&#039;&#039;&#039;&amp;quot; and it should automatically generate your new archiving account.&lt;br /&gt;
# Highlight that account in the list, and then click &amp;quot;&#039;&#039;&#039;Select&#039;&#039;&amp;quot;&lt;br /&gt;
# You should see the field &amp;quot;Currently archived to&amp;quot; be filled in with that newly created archive box. &#039;&#039;&#039;Save&#039;&#039;&#039;&lt;br /&gt;
After closing out of the account and when you search the user again, you should be able to see two entries in the search results; their regular account, and a separate archive account. &lt;br /&gt;
&lt;br /&gt;
We recommend you verify archiving is working properly by sending a test message to their account, and then proxy the archive mailbox to ensure your test is dropped in there as well. You can proxy a mailbox by right-clicking on the highlighted account and selecting &amp;quot;View mail&amp;quot;&lt;br /&gt;
&lt;br /&gt;
====Retention for Archived accounts====&lt;br /&gt;
Our mail retention policy remains the same even for archived accounts. If a archive mailbox is deleted, mailbox data will be purged 45 days after.&lt;br /&gt;
&lt;br /&gt;
==Discovery==&lt;br /&gt;
If you are trying to locate specific messages across accounts or domains, our helpful support staff is available to conduct a cross-mailbox search for you.&lt;br /&gt;
&lt;br /&gt;
You&#039;ll need to submit a support ticket via email to &#039;&#039;support@xmission.com&#039;&#039; for a request of a cross-mailbox search. You can also head to [http://xmission.com/support Support Resource Center] and under the section titled &#039;&#039;&#039;Other Useful Links&#039;&#039;&#039; click on &#039;&#039;&#039;Email Support/ Open Ticket&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The criteria you&#039;ll want to include to our support staff when making this request would be anything that would help us get relevant hits in the search.&lt;br /&gt;
* Sender&lt;br /&gt;
* Recipient&lt;br /&gt;
* Potential dates of delivery&lt;br /&gt;
* If the message had any attachments or not. &lt;br /&gt;
&lt;br /&gt;
Please note that at this time cross-mailbox search requests will not be handled via phone and chat, only through an emailed support ticket. &lt;br /&gt;
&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Connect&amp;diff=11460</id>
		<title>Zimbra Connect</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Connect&amp;diff=11460"/>
		<updated>2023-01-27T18:32:05Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Zimbra Connect=&lt;br /&gt;
Zimbra Connect integrates a fully fledged corporate instant messaging platform inside the Zimbra WebClient, including Group and Corporate Messaging, File Sharing, Screen Sharing and Video Chat capabilities.&lt;br /&gt;
&lt;br /&gt;
==Features==&lt;br /&gt;
* Message delivery and read awareness&lt;br /&gt;
* 1-to-1 Instant Messaging&lt;br /&gt;
* Group Messaging&lt;br /&gt;
* Corporate Messaging (Spaces and Channels)&lt;br /&gt;
* Group Video Calls&lt;br /&gt;
* Channel Video calls&lt;br /&gt;
* File Sharing&lt;br /&gt;
* Screen Sharing&lt;br /&gt;
* Emojis&lt;br /&gt;
&lt;br /&gt;
==How to Enable Connect for Your Users==&lt;br /&gt;
In the [https://wiki.xmission.com/Hosted_Email:_Admin_Panel Zimbra Admin console],&lt;br /&gt;
# search for the desired user you&#039;d like to enable Connect for.&lt;br /&gt;
# Right-click their account, select &#039;&#039;&#039;edit&#039;&#039;&#039;&lt;br /&gt;
# In their &#039;&#039;&#039;general information&#039;&#039;&#039; settings change their Class of Service from what is currently listed to &#039;&#039;&#039;xmprofessional&#039;&#039;&#039; (which is a premium level mailbox + connect &amp;amp; archiving features)&lt;br /&gt;
# Next, from the left-hand column for mailbox edit options, select the section that says &amp;quot;&#039;&#039;&#039;Connect&#039;&#039;&#039;&amp;quot;&lt;br /&gt;
There you can enable and disable the Connect option for your user&#039;s mailbox. You can also set available Zimbra Connect parameters such as the ability to save all chat history, enabling video chat instead of audio only, etc.&lt;br /&gt;
&lt;br /&gt;
==Troubleshooting==&lt;br /&gt;
A good place to verify settings is found in the actual mailbox by proxying the account, then selecting the Connect tab and then clicking on the gear sprocket icon to view settings.&lt;br /&gt;
&lt;br /&gt;
[[File:Connect_prefs.png|450px]]&lt;br /&gt;
&lt;br /&gt;
Under &#039;&#039;&#039;Meetings&#039;&#039;&#039;, you can enable/disable the microphone and camera. This will likely be a large percentage of problems for accounts to be able to access audio and video for Connect meetings. Simply click on &amp;quot;Enable microphone&amp;quot; and &amp;quot;Enable camera&amp;quot; to select the desired devices for meetings.&lt;br /&gt;
&lt;br /&gt;
[[File:Connect_settings.png|450px]]&lt;br /&gt;
&lt;br /&gt;
If the audio or video is not working, verify the correct device for the microphone and camera are selected, as that will likely be a large percentage of problems for end-users to be able to access audio and video for connect meetings. This is usually determined by the browser. Below are links for where to find those settings for common browsers. &lt;br /&gt;
&lt;br /&gt;
: https://support.google.com/chrome/answer/2693767?hl=en&amp;amp;co=GENIE.Platform%3DDesktop&lt;br /&gt;
: https://support.mozilla.org/en-US/kb/how-manage-your-camera-and-microphone-permissions&lt;br /&gt;
: https://support.apple.com/guide/safari/websites-ibrwe2159f50/mac&lt;br /&gt;
&lt;br /&gt;
If you run into any other issues related to our Connect feature, please don&#039;t hesitate to reach out to our Technical Support department 24/7 for assistance.&lt;br /&gt;
&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Shell_Access&amp;diff=11446</id>
		<title>Shell Access</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Shell_Access&amp;diff=11446"/>
		<updated>2023-01-12T18:45:08Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* What are some basics on setting permissions with &amp;quot;chmod&amp;quot;? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==How do I activate my shell account?==&lt;br /&gt;
To activate your shell account, simply contact accounting or technical support. &lt;br /&gt;
&lt;br /&gt;
==Why isn&#039;t shell access on by default?==&lt;br /&gt;
Having shell access enabled by default on all accounts presents a  security risk. A shell account gives the user a direct window into  our system. By minimizing the number of active shell accounts, we  minimize the risk of compromising our system.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Can I choose my shell type?==&lt;br /&gt;
Yes. You can choose from bash, tcsh, sh, zsh, csh, and ksh. We recommend using either bash or csh, at first, since they&#039;re the most user-friendly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What is SSH and how do I use it?==&lt;br /&gt;
SSH is a secure shell. Using it is differs, depending on the operating  system.  Mac OS X is probably the easiest. Nothing special has to be installed.  Simply open a terminal window and &amp;lt;tt&amp;gt;ssh username@shell.xmission.com&amp;lt;/tt&amp;gt;.  Accept the key and enter your password.  For most Windows operating systems, an SSH client must be used. There  are many SSH clients on the market and a few are &amp;quot;freeware&amp;quot;. PuTTY is a recommended free SSH client for Windows. Some places to look for additional SSH software would be Download.com and Tucows.com.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Why don&#039;t my screen and text work properly?==&lt;br /&gt;
There are two typical problems that occur during a telnet session.  The first and most common problem is incorrect terminal emulation.  The second problem occurs after a screen has been messed up by viewing  a binary file.&lt;br /&gt;
 &lt;br /&gt;
The most commonly used terminal emulation is vt100, though vt220  is supported and recommended. To change the terminal emulation of  your telnet application, view the preferences and choose either vt100  or vt220. However, even after specifying the terminal emulation for  your telnet application, you may still have problems correctly displaying  columns and rows. For this, you&#039;ll need to define the default size  of your window in your run commands (explained below]).  When trying to fix a screen after viewing a binary file, run &amp;lt;tt&amp;gt;fixvt&amp;lt;/tt&amp;gt; at a command prompt.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What are some common commands I&#039;ll need to know when using the UNIX shell?==&lt;br /&gt;
The most common commands you&#039;ll need to know are &amp;lt;tt&amp;gt;cd&amp;lt;/tt&amp;gt; (changes your directory), &amp;lt;tt&amp;gt;pwd&amp;lt;/tt&amp;gt; (shows your current directory path), and &amp;lt;tt&amp;gt;ls&amp;lt;/tt&amp;gt; (lists the contents of the current directory). For a more complete list of common commands, please see our Common Commands page. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Why do I get &amp;quot;command not found&amp;quot; when using a command I&#039;m sure should work? ==&lt;br /&gt;
It&#039;s possible that you don&#039;t have the paths to the command directories defined correctly in your run commands. For instructions on defining the correct paths, see below. &lt;br /&gt;
&lt;br /&gt;
==How do I edit my shell run commands (rc) file?==&lt;br /&gt;
Your shell run commands are found in a file named &#039;&#039;.cshrc&#039;&#039; (for c shell),  &#039;&#039;.bashrc&#039;&#039; (for borne shell), &#039;&#039;.kshrc&#039;&#039; (for korn shell), etc. This file  will be located in your home directory (/home/users/u/username). It  contains commands that are run when you first log on to set your  paths, environment variables, and aliases. Before changing ANY rc file, it&#039;s recommended you make a back-up copy.&lt;br /&gt;
&lt;br /&gt;
To set or edit your paths, edit your run commands file with a text  editor (pico, vi, ed, etc.). Your paths will be defined after the  command &amp;lt;tt&amp;gt;set path =&amp;lt;/tt&amp;gt;. The default paths should be &amp;lt;tt&amp;gt;/bin /usr/local/bin  /usr/bin&amp;lt;/tt&amp;gt;. If you&#039;d like to add a path, simply add it to the end,  separated by a space. (e.g.: /home/users/u/username/morecommands/)  If you&#039;d like to edit what information is displayed in your prompt,  edit the &amp;lt;tt&amp;gt;set prompt=&amp;lt;/tt&amp;gt; variable. A useful way to define your prompt  is to have it display your current directory. To do this, remove the  default &amp;lt;tt&amp;gt;set prompt=&amp;lt;/tt&amp;gt; and enter this in its place:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;alias cd &#039;cd \!* ; set prompt=&amp;quot;&#039;hostname&#039;:&#039;pwd&#039;&amp;gt; &amp;quot;&#039;&amp;lt;/tt&amp;gt;  To edit your environment variables, first type &amp;lt;tt&amp;gt;env&amp;lt;/tt&amp;gt; at a command  prompt to show your current variables. If you&#039;d like to change any  of these, enter the definition after a new &amp;quot;setenv&amp;quot; line. The proper  syntax, as you&#039;ll see in the default settings, is:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;setenv VARIABLE_NAME path/or/command:/2nd/path/or/command/&amp;lt;/tt&amp;gt;  Adding an alias is fairly simple. If you&#039;d like a certain command  to be run when you type something in at the command prompt, you&#039;d  enter that here. The proper syntax is:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;alias aliasedcommand &#039;realcommand -options&#039;&amp;lt;/tt&amp;gt;  This is also where you define your terminal emulation settings.&lt;br /&gt;
&amp;lt;tt&amp;gt;setenv TERM vt100   &amp;lt;/tt&amp;gt;(sets terminal type)&lt;br /&gt;
&amp;lt;tt&amp;gt;/bin/stty rows 24   &amp;lt;/tt&amp;gt;(sets number of rows)&lt;br /&gt;
&amp;lt;tt&amp;gt;/bin/stty cols 80   &amp;lt;/tt&amp;gt;(sets number of columns)&lt;br /&gt;
&amp;lt;tt&amp;gt;/bin/stty erase ^H   &amp;lt;/tt&amp;gt;(sets backspace command)  &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What are all these files in my home directory, and what are they for?==&lt;br /&gt;
If you do a complete list, showing hidden files, of your home directory,  you will notice that there are several files already there. The files  are listed and explained in the table below. Some of these files will  not be there by default, but only appear if the application that uses  them is run. &lt;br /&gt;
&lt;br /&gt;
===Types===&lt;br /&gt;
rc run commands/preferences (usually, but not always)&lt;br /&gt;
&lt;br /&gt;
===Files===&lt;br /&gt;
.cshrc shell run commands(for csh or tcsh) .gopherrc gopher preferences .login shell preferences (read after run commands at login) .newsrc news preferences .nn Network News Reader preferences .pinerc Pine preferences (pine is primarily used for email) .tin Threaded Internetwork News preferences&lt;br /&gt;
&lt;br /&gt;
===Directories===&lt;br /&gt;
bin can contain scripts or binary executables ftp your personal directory for file transfer mail Email is stored here (used by pine and others) news articles are saved here by default public_html your web pages&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I alter the information shown in my prompt?==&lt;br /&gt;
If you use tcsh, changing the prompt is as simple as entering the command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;set prompt=&amp;quot;options&amp;quot;&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
However, with other shells, you will need to edit the &amp;lt;tt&amp;gt;set prompt=&amp;lt;/tt&amp;gt; line in your shell run commands file (shown above). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What program can I use to read email from a shell? ==&lt;br /&gt;
&lt;br /&gt;
Probably the most popular options are &#039;&#039;mutt&#039;&#039; (recommended) and &#039;&#039;pine&#039;&#039;, but &#039;&#039;elm&#039;&#039;, &#039;&#039;mail/rmail&#039;&#039;, and &#039;&#039;emacs&#039;&#039; are also available. At a command prompt, run the command &amp;lt;tt&amp;gt;mutt&amp;lt;/tt&amp;gt;, &amp;lt;tt&amp;gt;pine&amp;lt;/tt&amp;gt;, or &amp;lt;tt&amp;gt;elm&amp;lt;/tt&amp;gt; and the mail client will open, also creating either a /mail (pine and elm) or /Mail (mutt) directory. Using mail/rmail &lt;br /&gt;
or emacs isn&#039;t quite as intuitive. It&#039;s recommended that you read the manual before using. (Type &amp;lt;tt&amp;gt;man mail&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;man emacs&amp;lt;/tt&amp;gt; at a command prompt.) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What program can I use to read news (Usenet) from a shell?==&lt;br /&gt;
The newsreaders available on shell are slrn, tin, nn, pine, nmh, trn, and emacs. The most popular ones would be slrn, tin, nn, and pine. We recommend slrn, since it&#039;s the only one that still has development. For more information on how to use any of these programs, type &amp;quot;man&amp;quot; followed by the program name at the command prompt (e.g.: &amp;lt;tt&amp;gt;man tin&amp;lt;/tt&amp;gt;). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How do I kill a process? ==&lt;br /&gt;
Before you kill a processes, you have to have its processes ID. You get this by typing &amp;quot;ps&amp;quot; at the command prompt. Once you&#039;ve determined which one of your processes is the one you want to kill, type &amp;lt;tt&amp;gt;kill -9 PID&amp;lt;/tt&amp;gt; (where PID is the actual processes ID) at the command prompt. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Is there a way to transfer files to and from my XMission account other than FTP?==&lt;br /&gt;
Although FTP is the recommended way to transfer files to and from your XMission account, it&#039;s not the only way. SFTP (ssh ftp) works directly to shell.xmission.com.&lt;br /&gt;
&lt;br /&gt;
==How do I compress and decompress files? ==&lt;br /&gt;
The method you&#039;ll use to decompress a file is determined by looking at the file extension. The instructions below show how to decompress the file in the current directory. For further information, see the &lt;br /&gt;
manual for each program (tar, bzip, unzip, gzip, uncompress).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.tar    &amp;lt;/tt&amp;gt;&amp;lt;tt&amp;gt;tar xvf file.tar&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.Z   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;uncompress file.Z&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.gz   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;gzip -d file.gz&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.zip   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;unzip file.zip&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;file.bz2   &amp;lt;/tt&amp;gt; &amp;lt;tt&amp;gt;bzip2 -d file.bz2&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If there is a combination of formats, such as file.tar.gz, you can &lt;br /&gt;
either pipe one command to the other (e.g. &amp;lt;tt&amp;gt;gzip -d file.tar.gz | tar &lt;br /&gt;
xvf&amp;lt;/tt&amp;gt;), or see if the option is supported by tar (&amp;lt;tt&amp;gt;man tar&amp;lt;/tt&amp;gt;&amp;gt;. Using the command &lt;br /&gt;
&amp;lt;tt&amp;gt;tar xvfz file.tar.gz&amp;lt;/tt&amp;gt; will handle both the gzip compression and the &lt;br /&gt;
tar compression. When piping a .Z file, however, be sure to use &amp;lt;tt&amp;gt;zcat &lt;br /&gt;
file.Z&amp;lt;/tt&amp;gt; (the equivalent of &amp;lt;tt&amp;gt;uncompress -c file.Z&amp;lt;/tt&amp;gt;, which writes to standard &lt;br /&gt;
output the files that were compressed). A similar rule applies to &lt;br /&gt;
bzip2, where you should use &amp;lt;tt&amp;gt;bzcat file.bz2&amp;lt;/tt&amp;gt; (equal to &amp;lt;tt&amp;gt;bzip2 -dc file.bz2&amp;lt;/tt&amp;gt;) &lt;br /&gt;
when piping the output to another command. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==What are some basics on setting permissions with &amp;quot;chmod&amp;quot;?==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First, an understanding of file/directory ownership is needed. Each &lt;br /&gt;
file or directory has a user (also the owner) and a group. The owner &lt;br /&gt;
of your files should always be your XMission username. The groups &lt;br /&gt;
you&#039;ll need to know are www (which gives the web server access to &lt;br /&gt;
the files) and users (which gives any of XMission&#039;s users, from shell, &lt;br /&gt;
access to the files). There&#039;s also the category, others, that includes &lt;br /&gt;
any user or group.&lt;br /&gt;
&lt;br /&gt;
Permissions are based on those three categories: owner, group, and &lt;br /&gt;
others. When you do a long listing of the file (&amp;lt;tt&amp;gt;ls -l filename&amp;lt;/tt&amp;gt;), the &lt;br /&gt;
permissions will be displayed to the left. The format is shown as &lt;br /&gt;
such: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;-rw-r--r-- 1 acctname group 1949 Sep &lt;br /&gt;
19 2000 file.html&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first space defines weather the file is a simple file (shown with a hyphen) or a directory (shown with a d). The next three spaces represent the permissions (highlighted in red) &lt;br /&gt;
for the owner, the next three are for the group, and the last three &lt;br /&gt;
are for others. The letters represent what kind of permissions are &lt;br /&gt;
allowed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;r &#039;&#039;&#039; = Read (view and make copies)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;w &#039;&#039;&#039; = Write (make changes to or delete)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;x &#039;&#039;&#039; = Execute (run program/script) &lt;br /&gt;
When using &amp;quot;chmod&amp;quot; to change permissions, you will need to specify &lt;br /&gt;
the category by using one or a combination of the following letters:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;u &#039;&#039;&#039; = User (Owner)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;g &#039;&#039;&#039; = Group&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;o &#039;&#039;&#039; = Others&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;a &#039;&#039;&#039; = All (same as using &amp;quot;ugo&amp;quot;) &lt;br /&gt;
To change the permissions, execute &amp;quot;chmod&amp;quot; with the following parameters:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod who+/-/=permission file&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The plus (+) adds the following permission, the minus (-) removes &lt;br /&gt;
it, and the (=) adds it, discarding any previous permissions. Some &lt;br /&gt;
examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod g+r file.html&amp;lt;/tt&amp;gt; (adds read access for group)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod go-r file.html&amp;lt;/tt&amp;gt; (removes read access from group and &lt;br /&gt;
others)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod a=x file.html&amp;lt;/tt&amp;gt; (replaces existing permissions with read &lt;br /&gt;
access for all)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tt&amp;gt;chmod g+rx file.html&amp;lt;/tt&amp;gt; (adds read and execute access for group) &lt;br /&gt;
There is another way to change permissions without having to write &lt;br /&gt;
out &amp;lt;tt&amp;gt;chmod who+/-/=permission file&amp;lt;/tt&amp;gt; every time. This method uses a 3-digit octal &lt;br /&gt;
number. Determining the octal number is fairly easy after some practice. &lt;br /&gt;
To start, refer to the chart below. &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
===Symbol Octal===&lt;br /&gt;
&lt;br /&gt;
 ---0 --x1 -w-2 -wx3 r--4 r-x5 rw-6 rwx7&lt;br /&gt;
&lt;br /&gt;
For example, if you&#039;d like to set the permissions on file.html &lt;br /&gt;
to be &amp;lt;tt&amp;gt;-rw-r--r--&amp;lt;/tt&amp;gt; you would determine the octal number &lt;br /&gt;
like this (skip the first space in the set): &lt;br /&gt;
&amp;lt;tt&amp;gt;rw-&amp;lt;/tt&amp;gt; = 6, &amp;lt;tt&amp;gt;r--&amp;lt;/tt&amp;gt; = 4, &amp;lt;tt&amp;gt;r--&amp;lt;/tt&amp;gt; = 4. The octal &lt;br /&gt;
number is 644. &lt;br /&gt;
&lt;br /&gt;
To execute the command, type:&lt;br /&gt;
&lt;br /&gt;
 chmod 644 file.html&lt;br /&gt;
&#039;&#039;&#039;Note&#039;&#039;&#039;: This would be the same as using:&lt;br /&gt;
&lt;br /&gt;
 chmod a+r file.html&lt;br /&gt;
&lt;br /&gt;
 chmod u+x file.html&lt;br /&gt;
&lt;br /&gt;
(if no permissions were previously set).&lt;br /&gt;
 &lt;br /&gt;
Changing ownership and the group of a file would normally be done with &amp;quot;chown&amp;quot; and &amp;quot;chgrp&amp;quot;. However, because these commands are restricted to the user and group being specified, you&#039;re unable to use them on XMission (because you&#039;re only one user and you&#039;re only a member of one group). However, if you&#039;d like a file to belong to the group www, you can either create it in or upload it to your public_html directory. This will set the group, by default, to www. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:FAQ|Shell Access]]&lt;br /&gt;
[[Category:Troubleshooting]]&lt;br /&gt;
[[Category:Getting Started]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Juniper&amp;diff=11319</id>
		<title>Juniper</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Juniper&amp;diff=11319"/>
		<updated>2022-11-30T21:02:43Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{archived}}&lt;br /&gt;
&lt;br /&gt;
===Juniper PPPoE Proceedure===&lt;br /&gt;
&lt;br /&gt;
Juniper users a hierarchical configuration and the PPPoE settings fall under the interfaces section. In this example we will be using the fast ethernet port 0/0/1 for the WAN interface and the final configuration will look like:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interfaces {&lt;br /&gt;
    fe-0/0/1 {&lt;br /&gt;
        unit 0 {&lt;br /&gt;
            encapsulation ppp-over-ether;&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
    pp0 {&lt;br /&gt;
        unit 0 {&lt;br /&gt;
            ppp-options {&lt;br /&gt;
                pap {&lt;br /&gt;
                    local-password &amp;quot;dkwoxslxqpz&amp;quot;;##SECRET-DATA&lt;br /&gt;
                    local-name &amp;quot;username&amp;quot;;&lt;br /&gt;
                    passive;&lt;br /&gt;
                }&lt;br /&gt;
            }&lt;br /&gt;
            pppoe-options {&lt;br /&gt;
                underlying-interface fe-0/0/1.0;&lt;br /&gt;
                auto-reconnect 10;&lt;br /&gt;
                client;&lt;br /&gt;
                idle-timeout 0;&lt;br /&gt;
            }&lt;br /&gt;
            family inet {&lt;br /&gt;
                negotiate-address;&lt;br /&gt;
                mtu 1492;&lt;br /&gt;
            }&lt;br /&gt;
            family inet6 {&lt;br /&gt;
                mtu 1492;&lt;br /&gt;
                dhcpv6-client {&lt;br /&gt;
                    client-type statefull;&lt;br /&gt;
                    client-ia-type ia-pd;&lt;br /&gt;
                    client-ia-type ia-na;&lt;br /&gt;
                    update-router-advertisement {&lt;br /&gt;
                        interface pp0.0;&lt;br /&gt;
                    }&lt;br /&gt;
                    client-identifier duid-type duid-ll;&lt;br /&gt;
                    req-option domain;&lt;br /&gt;
            }&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
}&lt;br /&gt;
security {&lt;br /&gt;
    flow {&lt;br /&gt;
        tcp-mss {&lt;br /&gt;
            all-tcp {&lt;br /&gt;
                mss 1452;&lt;br /&gt;
            }&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Below is a walk through on what commands to enter:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
You will want to ssh / telnet to the router and be at the CLI (command line interface):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
--- JUNOS 11.4xxxx built 2011-05-15 22:21:00 UTC&lt;br /&gt;
{master}&lt;br /&gt;
user@router&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will need to be in the edit mode at this point:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
user@router&amp;gt;edit&lt;br /&gt;
&lt;br /&gt;
Entering configuration mode&lt;br /&gt;
Users currently editing the configuration:&lt;br /&gt;
{master}[edit]&lt;br /&gt;
user@router#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now we will want to set the interface FastEthernet 0/0/1 to use PPPoE encapsulation:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
user@router#edit interfaces fe-0/0/1 unit 0&lt;br /&gt;
&lt;br /&gt;
{master}[edit interfaces fe-0/0/1 unit 0]&lt;br /&gt;
user@router#set encapsulation ppp-over-ether;&lt;br /&gt;
user@router#exit&lt;br /&gt;
&lt;br /&gt;
{master}[edit]&lt;br /&gt;
user@router#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next we will want to edit the ppp pap options pp0 interface:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
user@router#edit interfaces pp0 unit 0 ppp-options pap&lt;br /&gt;
&lt;br /&gt;
{master}[edit interfaces pp0 unit 0 ppp-options pap]&lt;br /&gt;
user@router#set access-profile ppp-profile&lt;br /&gt;
user@router#set local-password &amp;quot;xmission password&amp;quot;&lt;br /&gt;
user@router#set local-name &amp;quot;xmission username&amp;quot;&lt;br /&gt;
user@router#set passive&lt;br /&gt;
user@router#exit&lt;br /&gt;
&lt;br /&gt;
{master}&lt;br /&gt;
user@router#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now we will want to configure the pppoe options:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
user@router#edit interfaces pp0 unit 0 pppoe-options&lt;br /&gt;
&lt;br /&gt;
{master}[edit interfaces pp0 unit 0 pppoe-options]&lt;br /&gt;
user@router#set underlying-interface fe-0/0/1.0&lt;br /&gt;
user@router#set auto-reconnect 10&lt;br /&gt;
user@router#set client&lt;br /&gt;
user@router#set idle-timeout 0&lt;br /&gt;
user@router#exit&lt;br /&gt;
&lt;br /&gt;
{master}&lt;br /&gt;
user@router#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Last we will want to set the ip address, in this example we will use auto negotiate:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
user@router#edit interfaces pp0 unit 0 family-inet&lt;br /&gt;
&lt;br /&gt;
{master}[edit interfaces pp0 unit 0 family-inet]&lt;br /&gt;
user@router#set negotiate-address&lt;br /&gt;
user@router#set mtu 1492&lt;br /&gt;
user@router#exit&lt;br /&gt;
&lt;br /&gt;
{master}&lt;br /&gt;
user@router#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you have ipv6 use the following&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
user@router#edit interfaces pp0 unit 0 family inet6&lt;br /&gt;
&lt;br /&gt;
{master}[edit interfaces pp0 unit 0 family inet6]&lt;br /&gt;
user@router#set mtu 1492&lt;br /&gt;
user@router#set dhcpv6-client client-type statefull&lt;br /&gt;
user@router#set dhcpv6-client client-ia-type ia-pd&lt;br /&gt;
user@router#set dhcpv6-client client-ia-type ia-nd&lt;br /&gt;
user@router#set dhcpv6-client update-router-advertisement interface pp0.0&lt;br /&gt;
user@router#set dhcpv6-client client-identifier duid-type duid-ll&lt;br /&gt;
user@router#set dhcpv6-client req-option domain&lt;br /&gt;
user@router#exit&lt;br /&gt;
&lt;br /&gt;
{master}&lt;br /&gt;
user@router#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Commit these changes and exit edit mode.&lt;br /&gt;
&lt;br /&gt;
[[Category:UTOPIA Troubleshooting|Juniper]]&lt;br /&gt;
[[Category:UTOPIA]]&lt;br /&gt;
[[Category:PPPoE]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Email_attachments&amp;diff=11316</id>
		<title>Email attachments</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Email_attachments&amp;diff=11316"/>
		<updated>2022-11-24T17:46:04Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* Maximum Recipient Limit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Email security and attachments==&lt;br /&gt;
XMission rejects email attachments with commonly malicious file formats as a security measure to prevent potential viruses from impacting customers. Rejecting emails with executable files, for example file.exe, will protect you from possibly receiving malicious software containing a virus or malware. &lt;br /&gt;
&lt;br /&gt;
This blocking is applied to all &#039;&#039;inbound and outbound&#039;&#039; email with attachments. A reject notice will automatically be sent to any sender attempting to send to, or from, the XMission mail system.&lt;br /&gt;
&lt;br /&gt;
Business customers with hosted Zimbra email do not have attachments blocked between accounts on their domain.&lt;br /&gt;
&lt;br /&gt;
==Blocked file types== &lt;br /&gt;
Rejected files end in: &#039;&#039;&#039;scr, vbs, dll, exe, shs, bat, lnk, pif, chm, hta, com, cmd, reg, js, cpl, jsp, vbe, sys, btm, pfr, vb&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Maximum Attachment Sizes==&lt;br /&gt;
XMission allows email attachments with the following sizes:&lt;br /&gt;
&lt;br /&gt;
* Up to 10 MB for @xmission.com accounts via [https://webmail.xmission.com Webmail.XMission.com].&lt;br /&gt;
* Up to 50 MB for @xmission.com email sent with mail applications.&lt;br /&gt;
* Up to 50 MB for our hosted Zimbra email.&lt;br /&gt;
* Up to 100 MB for our hosted Zimbra email to another one of our hosted Zimbra email accounts.&lt;br /&gt;
&#039;&#039;&#039;Note: MIME encoding will change the size of the of the attachment significantly.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Maximum Recipient Limit ==&lt;br /&gt;
* Up to 500 on [https://zimbra.xmission.com Zimbra] via web interface.&lt;br /&gt;
* Up to 1000 using a mail application.&lt;br /&gt;
To send in larger increments, please inquire with our sales department about our [[Mailing Lists]] product.&lt;br /&gt;
&lt;br /&gt;
==Learn more==&lt;br /&gt;
Learn how XMission [http://transmission.xmission.com/2013/08/14/how-xmission-spam-and-virus-filtering-works filters for viruses and spam].&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Email_attachments&amp;diff=11315</id>
		<title>Email attachments</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Email_attachments&amp;diff=11315"/>
		<updated>2022-11-24T00:20:49Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Email security and attachments==&lt;br /&gt;
XMission rejects email attachments with commonly malicious file formats as a security measure to prevent potential viruses from impacting customers. Rejecting emails with executable files, for example file.exe, will protect you from possibly receiving malicious software containing a virus or malware. &lt;br /&gt;
&lt;br /&gt;
This blocking is applied to all &#039;&#039;inbound and outbound&#039;&#039; email with attachments. A reject notice will automatically be sent to any sender attempting to send to, or from, the XMission mail system.&lt;br /&gt;
&lt;br /&gt;
Business customers with hosted Zimbra email do not have attachments blocked between accounts on their domain.&lt;br /&gt;
&lt;br /&gt;
==Blocked file types== &lt;br /&gt;
Rejected files end in: &#039;&#039;&#039;scr, vbs, dll, exe, shs, bat, lnk, pif, chm, hta, com, cmd, reg, js, cpl, jsp, vbe, sys, btm, pfr, vb&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Maximum Attachment Sizes==&lt;br /&gt;
XMission allows email attachments with the following sizes:&lt;br /&gt;
&lt;br /&gt;
* Up to 10 MB for @xmission.com accounts via [https://webmail.xmission.com Webmail.XMission.com].&lt;br /&gt;
* Up to 50 MB for @xmission.com email sent with mail applications.&lt;br /&gt;
* Up to 50 MB for our hosted Zimbra email.&lt;br /&gt;
* Up to 100 MB for our hosted Zimbra email to another one of our hosted Zimbra email accounts.&lt;br /&gt;
&#039;&#039;&#039;Note: MIME encoding will change the size of the of the attachment significantly.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Maximum Recipient Limit ==&lt;br /&gt;
* Up to 500 on [https://zimbra.xmission.com Zimbra] via web interface.&lt;br /&gt;
* Up to 1000 using a mail application.&lt;br /&gt;
To send in larger increments, please inquire with our sales department about our Mailing List product.&lt;br /&gt;
&lt;br /&gt;
==Learn more==&lt;br /&gt;
Learn how XMission [http://transmission.xmission.com/2013/08/14/how-xmission-spam-and-virus-filtering-works filters for viruses and spam].&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Email&amp;diff=11314</id>
		<title>Email</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Email&amp;diff=11314"/>
		<updated>2022-11-17T16:57:27Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;h3&amp;gt;Information&amp;lt;/h3&amp;gt;&lt;br /&gt;
*[[Zimbra Domain Email and Collaboration Suite|Zimbra Email and Collaboration Suite]]&lt;br /&gt;
*[https://xmission.com/blog/?s=zimbra Zimbra power tips on our XMission blog]&lt;br /&gt;
*[[Hosted_Email:Zimbra_Self-Service_Account_Recovery|Zimbra Self-Service Account Recovery]]&lt;br /&gt;
*[[Zimbra_Two-Factor_Authentication| Zimbra Two-Factor Authentication]]&lt;br /&gt;
*[[Zimbra Cloud]] Supported by XMission&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h3&amp;gt;Setup Instructions&amp;lt;/h3&amp;gt;&lt;br /&gt;
*[[Client_Configuration_for_%40XMission.com_Email|XMission.com Email Configuration Instructions]]&lt;br /&gt;
*[[Zimbra_Email_Client_Configurations|Zimbra Email Configuration Instructions]]&lt;br /&gt;
*[[General Email Settings]]&lt;br /&gt;
*[[New_Webmail_Interface|XMission webmail help for @xmission.com email accounts]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h3&amp;gt; Miscellaneous&amp;lt;/h3&amp;gt;&lt;br /&gt;
*[[Delist Request | Request delisting from XMission RBL blocklist.]] &lt;br /&gt;
*[[Suffix_support | Suffix support adds unlimited address options to your XMission email]]&lt;br /&gt;
*[[Email attachments | Security: Why certain email attachments are blocked by XMission.]]&lt;br /&gt;
*[[LDAP/Active Directory | Authenticating XMission hosted Zimbra with customer LDAP/Active Directory.]]&lt;br /&gt;
*[[Phishing_and_Email_Scams | Protect yourself from phishing.]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Email]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Hosted_Email:iOS&amp;diff=11313</id>
		<title>Hosted Email:iOS</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Hosted_Email:iOS&amp;diff=11313"/>
		<updated>2022-11-10T23:16:16Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This iOS profile is specific to Premium Edition mailboxes on the XMission Zimbra Collaboration platform. &lt;br /&gt;
&lt;br /&gt;
==== Download the Profile ====&lt;br /&gt;
Download the XMission email profile by loading this webpage on your iOS device and then &lt;br /&gt;
&#039;&#039;&#039;[https://asset.xmission.com/xmission-zimbra-premium-signed.mobileconfig tapping here]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This profile will sync all your Mail, Contacts, personal Calendars, as well as the Notes and Reminders the iOS device provides. &lt;br /&gt;
&lt;br /&gt;
This profile will not sync any calendars shared with you by other mailboxes on your domain.  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Note:&#039;&#039; Clients with any shared calendars should [https://wiki.xmission.com/Hosted_Email:iOS#Profile_for_Multiple_Calendars use this calendar sharing profile linked below].   or disable calendars and reminders in the iOS settings and then manually configure those using CalDAV.&lt;br /&gt;
&lt;br /&gt;
Shortcut: [http://url.xmission.com/iosp http://url.xmission.com/iosp] is an easily shareable link to use when installing.&lt;br /&gt;
&lt;br /&gt;
==== You will see the &amp;quot;Install Profile&amp;quot; for XMission Zimbra Premium launch.  Tap the &#039;&#039;&#039;Install&#039;&#039;&#039; button. ====&lt;br /&gt;
[[Image:Ios-zimbra-premium-1.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Enter your device&#039;s lock code or password: ====&lt;br /&gt;
[[Image:Ios-zimbra-premium-2.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Enter your email address: ====&lt;br /&gt;
&lt;br /&gt;
If you have purchased Hosted Email for another domain other than @xmission.com, enter that email address with that domain.&lt;br /&gt;
&lt;br /&gt;
[[Image:Ios-zimbra-premium-3.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Enter your email address again: ====&lt;br /&gt;
If you have purchased Hosted Email for another domain other than @xmission.com, enter that email address with that domain.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Ios-zimbra-premium-4.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Enter your password: ====&lt;br /&gt;
&lt;br /&gt;
[[Image:Ios-zimbra-premium-5.png]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Client Email Configuration|XMission Email|iPhone / iPad]]&lt;br /&gt;
[[Category:XMission Email|iPhone / iPad]]&lt;br /&gt;
&lt;br /&gt;
=== Deleting the Profile ===&lt;br /&gt;
If you no longer want this configuration on your device, you can remove the profile.&lt;br /&gt;
&lt;br /&gt;
# Go into Settings&lt;br /&gt;
# Click General&lt;br /&gt;
# Click on &amp;quot;VPN &amp;amp; Device Management&amp;quot;&lt;br /&gt;
# Click on the XMission profile&lt;br /&gt;
# Remove the Profile.&lt;br /&gt;
&lt;br /&gt;
=== Profile for Multiple Calendars ===&lt;br /&gt;
&lt;br /&gt;
Hosted Email clients with shared calendars should utilize this profile by &#039;&#039;&#039;[https://asset.xmission.com/xmission-zimbra-premium-caldav-signed.mobileconfig tapping here]&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
Requirements:&lt;br /&gt;
&lt;br /&gt;
You &#039;&#039;&#039;must disable&#039;&#039;&#039; the Calendars and Reminders inside iOS &amp;quot;Mail&amp;quot; and &amp;quot;Calendar&amp;quot; Settings for &amp;quot;XMission Zimbra Mail &amp;amp; Contacts&amp;quot;. The &amp;quot;XMission Zimbra Calendars &amp;amp; Reminders&amp;quot; entry will provide this functionality.&lt;br /&gt;
&lt;br /&gt;
Turn off the &amp;quot;[ ] Enable delegation for Apple iCal CalDAV client&amp;quot; setting inside Zimbra webmail Preferences / Calendar. Be sure to &amp;quot;Save&amp;quot; the setting inside webmail and then refresh your calendars on the iOS device.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Recommended_Routers&amp;diff=11290</id>
		<title>Recommended Routers</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Recommended_Routers&amp;diff=11290"/>
		<updated>2022-08-26T15:39:32Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Recommended Routers == &lt;br /&gt;
&lt;br /&gt;
When it comes to your connection, your router is one of the most important devices you can add to your home network. We know that routers are not cheap, however in order to meet the demand of your daily wifi needs, you may need to invest a little more money in a router that will cover your entire home with little dead spots. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Keep in mind that while any gigabit router is compatible, XMission recommends the following products based on feedback from our staff and customers. The products below are not required for service. You should choose a router that fits your budget.  &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Please remember XMission cannot guarantee advertised speeds over a wireless connection. When available we recommend the use of Ethernet Cables. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:AsusAX5700-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039; [https://amzn.to/3ynwJXm ASUS AX-5700]: &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; ASUS&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; AX-5700&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Dual-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 3 - Removable&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 WAN / 1 Multi-Gig WAN / 4 LAN gigabit / 2 USB 3.0&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $249.99 - Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.asus.com/us/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX86U/techspec/ Product Specifications]&#039;&#039;&#039; &lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.asus.com/us/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX86U/HelpDesk_Manual/ User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* Comercial-grade home network security&lt;br /&gt;
* Lifetime free ASUS AIProtection Pro, powered by Trend Micro&lt;br /&gt;
* WPA3&lt;br /&gt;
* Advanced Parental Controls&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; |[[File:NetgearOrbi-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/39U69f8 Netgear Orbi Wifi 6]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; NETGEAR&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; Orbi WiFi 6&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Tri-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 8 &lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Multi-Gig WAN / 3 LAN on router / 2 LAN on satellite&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $349.99 - Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.netgear.com/home/wifi/mesh/rbk752/ Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[http://www.downloads.netgear.com/files/GDC/RBK752/RBK752_UM_EN.pdf User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* NETGEAR Armor cybersecurity by Bitdefender 30-day free trial&lt;br /&gt;
* NETGEAR Smart Parental Controls 30-day free trial&lt;br /&gt;
* Easy setup in minutes with Orbi App&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; |[[File:TplinkAX6000-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3HXlgkD TP-Link AX6000]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; TP-Link&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; AX-6000&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Dual-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 8 &lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Multi-Gig WAN / 8 LAN gigabit / 1 USB-A 3.0 / 1 USB-C 3.0&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $259.99 - Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.tp-link.com/us/home-networking/wifi-router/archer-ax6000/#specifications Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.tp-link.com/us/support/download/archer-ax6000/ User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* Free lifetime subscriptions  to TP-LINK HomeCare&lt;br /&gt;
* Next-level Antivirus&lt;br /&gt;
* Robust Parental Controls&lt;br /&gt;
* QoS&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:TplinkDecoX20-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3nlbj6Z Mesh Deco X20] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; TP-Link&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; Mesh Deco X20&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Dual-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 4&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Gig WAN / 1 LAN gigabit / 2 LAN gigabit per satelite&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $179.99 - Amazon 2-pack / $199 - Amazon 3-pack&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.tp-link.com/us/deco-mesh-wifi/product-family/deco-x20/#specifications Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.tp-link.com/us/support/download/deco-x20/ User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* Free lifetime subscriptions  to TP-LINK HomeCare&lt;br /&gt;
* Malicious Site Checker&lt;br /&gt;
* Infected Device Isolation&lt;br /&gt;
* SPI Firewall&lt;br /&gt;
* Parental Controls&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:LinksysVelop-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3HTSHVb Linksys Velop Mesh] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; Linksys&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; Velop AX4000 Tri Band Mesh&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Tri-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 8&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Gig WAN / 3 LAN gigabit / USB 3.0 per unit&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $579.99- Amazon 2-pack&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.linksys.com/us/velop-ax4000-tri-band-mesh-wifi-6-system-mx8000/p/p-mx8000/ Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://downloads.linksys.com/support/assets/userguide/MX4000Series_UserGuide_INTL_LNKPG-00755_RevB00.pdf User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* Easy setup with Linksys app&lt;br /&gt;
* Parental Controls&lt;br /&gt;
* Separate guest access&lt;br /&gt;
* Linksys Seal&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:NetgearNighthawk-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3nrpJCt NETGEAR Nighthawk AX5400] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; NETGEAR&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; Nighthawk Pro AX5400&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Dual-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 4 - Removeable&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Gig WAN / 4 LAN gigabit / USB 3.0&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $299.99- Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.netgear.com/home/wifi/routers/rax50/ Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.downloads.netgear.com/files/GDC/RAX50/RAX50_UM_EN.pdf User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* Easy Setup with Nighthawk App&lt;br /&gt;
* NETGEAR Smart Parental Controls&lt;br /&gt;
* NETGEAR Armor&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:AsusRog-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3u5vCcr ASUS ROG Rapture AX11000] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; ASUS&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; ROG Rapture WiFi 6 Gaming Router&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Dual-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 8 - Removeable&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Gig WAN / 2.5 Gig LAN / 4 LAN gigabit / USB 3.0&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $349.99- Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://rog.asus.com/us/networking/rog-rapture-gt-ax11000-model/spec Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://rog.asus.com/us/networking/rog-rapture-gt-ax11000-model/helpdesk_manual User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* AiProtection Pro by Trend Micro&lt;br /&gt;
* Easy Port forwarding&lt;br /&gt;
* Simultaneous Gaming and VPN&lt;br /&gt;
* ASUS AiMesh Compatible&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Routers on a budget ==&lt;br /&gt;
We know that you may not be able to afford the best router out there. So we chose a few that will work when you are in a pinch. &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:Netgearax6700-w.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/39Wybqp NETGEAR AX1800] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; NETGEAR&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; AX1800 4-Stream Wifi 6 Router&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039; WiFi 6/Dual-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 3&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Gig WAN / 4 LAN gigabit&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $119.99- Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.netgear.com/home/wifi/routers/rax10/ Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.downloads.netgear.com/files/GDC/RAX10/RAX10_UM_EN.pdf User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* Easy setup with Nighthawk App&lt;br /&gt;
* Additional add ons:&lt;br /&gt;
** NETGEWAR Armor $99 / year&lt;br /&gt;
** NETGEAR Smart Parental Controls $34.99/ year&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:LinksysEA7500.jpg|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3y1IPUC Linksys EA7300] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; Linksys&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; EA7300&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039;  Dual-band&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 3&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 Gig WAN / 4 LAN gigabit / USB 3.0 &lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $129.99 - Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://www.linksys.com/us/p/P-EA7500/ Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[http://downloads.linksys.com/downloads/userguide/EA7500-MUG_International_20160610.pdf User Guide]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Includes:&#039;&#039;&#039;&lt;br /&gt;
* Easy Setup&lt;br /&gt;
* Simultaneous dual band ( 2.4 + 5 GHZ ) &lt;br /&gt;
* MU-MIMO simultaneously streaming and gamin on multiple devices&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
* Model numbers may vary depending on the most recent revision from the manufacturer and may have different firmware versions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Enterprise == &lt;br /&gt;
For intermediate users, or those who would like to take advantage of the full capabilities of the XMission Network, we recommend Ubiquiti&#039;s UniFi wireless line: a proprietary mesh-like network environment, commonly used in enterprise-level deployments. XMission&#039;s office and some staffers use Ubiquiti for wireless access points.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:Er-x-01_grande.png|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3dxPDml EdgeRouter X] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; Ubiquiti Networks&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; ER-X&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039;  None&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 0&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 5 Gb ports / 1 data/PoE input port, 3 data ports, 1 data/PoE passthrough port.&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $129.99 - Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://store.ui.com/collections/operator-edgemax-routers/products/edgerouter-x Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://dl.ubnt.com/guides/edgemax/EdgeRouter_ER-X_QSG.pdf User Guide]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
{|&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:center;vertical-align:top;&amp;quot; | [[File:ER-10X.png|200px]]&lt;br /&gt;
| style=&amp;quot;width: 375px;padding:5px;text-align:left;vertical-align:top;&amp;quot; | &#039;&#039;&#039;[https://amzn.to/3pm4ROk EdgeRouter 10X] &#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;Specifications:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Brand:&#039;&#039;&#039; Ubiquiti Networks&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Model:&#039;&#039;&#039; ER-10X&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;WiFi:&#039;&#039;&#039;  None&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Antennas:&#039;&#039;&#039; 0&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Ports:&#039;&#039;&#039; 1 RJ45 Serial Port / 10 Ethernet Ports / Port 0 Supports PoE in / Port 9 Supports PoE out&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;Price:&#039;&#039;&#039; $129.99 - Amazon&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://store.ui.com/collections/routing-switching/products/edgerouter-10x Product Specifications]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;br&amp;gt;&#039;&#039;&#039;[https://dl.ubnt.com/qsg/ER-10X/ER-10X_EN.html User Guide]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Placement of your router == &lt;br /&gt;
The placement of your router is very important. Your wireless signal will need to travel from your router to where you are in your home. Putting your router in a utility closet is probably not the best choice, if your utility closet is in your basement and you spend all day upstairs. You may want to reconsider a more central location for your router. Materials such as concrete, metal, brick and sheetrock - you know the stuff your walls are made from - can and will impact the strength of your wireless signal.&lt;br /&gt;
&lt;br /&gt;
== Router Issues == &lt;br /&gt;
If you continue to have issues with your current router, it may be time to upgrade. If after talking with our support department and we have walked you through factory resetting your router and updating the firmware with no change to performance, then it may be time to get a new router. You can visit our [[Router and Wireless Troubleshooting]] guide to help you further.&lt;br /&gt;
&lt;br /&gt;
[[Category: Troubleshooting]]&lt;br /&gt;
[[Category: UTOPIA]]&lt;br /&gt;
[[Category: UTOPIA Troubleshooting‏‎]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11195</id>
		<title>Zimbra Email Client Configurations</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Email_Client_Configurations&amp;diff=11195"/>
		<updated>2022-07-14T19:07:01Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__ &lt;br /&gt;
&lt;br /&gt;
These easy to follow instructions will help you configure your favorite client for use with your Zimbra email service.&amp;lt;br/&amp;gt;&lt;br /&gt;
For greater convenience, you can always access your mail at https://zimbra.xmission.com/&lt;br /&gt;
&lt;br /&gt;
For more help, reference the video repository of helpful tips on the [https://www.youtube.com/channel/UCcB648SoNlCNvyIh4arcTGg Zimbra YouTube Channel].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2 style=&amp;quot;padding-top:1.5em&amp;quot;&amp;gt;Recommended Email Settings&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;XMission always recommends an IMAP email configuration [https://xmission.com/blog/2009/02/09/why-imap-rules heres why.]&amp;lt;/p&amp;gt;&lt;br /&gt;
{| style=&amp;quot;text-align: left; border: 1px solid #ccc;&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;2&amp;quot; &lt;br /&gt;
! style=&amp;quot;border-bottom:1px solid #ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Incoming Server Information:&lt;br /&gt;
! style=&amp;quot;border-style: solid; border-width: 0 0 1px 1px; border-color:#ccc; background-color: #eef; padding:2px 8px&amp;quot; colspan=2 | Outgoing Server Information:&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Server Type: || IMAP&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Server Type: || SMTP&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Hostname: || zimbra.xmission.com&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Hostname: || zimbra.xmission.com &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Port: || 993&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Port: || 587&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Enable encryption: || Yes.&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Enable encryption: || Yes. (TLS/SSL)&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Authenticate Using: || Password&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; | Requires Authentication: || Yes&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Login User Name: || Your full email address &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |Login User Name || Your full email address&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;padding:2px 8px&amp;quot; |Alternate Port: || 143 &amp;amp;nbsp;&lt;br /&gt;
|style=&amp;quot;border-left:1px solid #ccc; padding:2px 8px&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
||Webmail Interface: |||[https://zimbra.xmission.com/ https://zimbra.xmission.com/]&lt;br /&gt;
|-&lt;br /&gt;
||Admin Interface: |||[https://zimbraadmin.xmission.com https://zimbraadmin.xmission.com]&lt;br /&gt;
|-&lt;br /&gt;
||Folders: ||| Sent Mail = &amp;quot;Sent&amp;quot;, Drafts = &amp;quot;Drafts&amp;quot;, Trash = &amp;quot;Trash&amp;quot;, Spam = &amp;quot;Junk&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
||MX Record: ||| mx.xmission.com&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
- Please note that some free wireless hotspots may block SSL without an extra fee. If you cannot send or receive while on certain wifi networks (especially ones in airports or public spaces) please check their terms and conditions and ensure they are not blocking SSL connections.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Videos&amp;lt;/h2&amp;gt; &lt;br /&gt;
*[https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra Email on Mac using IMAP]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Windows 10 / 8.x / 7 / Vista&amp;lt;/h2&amp;gt;&lt;br /&gt;
*[[Hosted_Email:Outlook_2013|Outlook 2013/2016/365]]&lt;br /&gt;
*[[Hosted_Email:Outlook_2010|Outlook 2010]] &lt;br /&gt;
*[[Hosted_Email:Outlook_Connector|Outlook Connector for Zimbra Premium]] and Personal Premium Zimbra accounts&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Zimbra_41|Thunderbird 41]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Archive Windows&#039;&#039;&#039; &lt;br /&gt;
The following Microsoft Widows mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
* Windows XP - Mail applications on this OS will still work but are no longer supported&lt;br /&gt;
*[[Hosted_Email:Outlook_2007|Outlook 2007]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Outlook 2003]]  &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Windows_Mail|Windows Live Mail]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Outlook_Express|Outlook Express]] &amp;lt;- Please upgrade your mail application to a current version.&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup|Thunderbird 3]] &amp;lt;-- Please upgrade your mail application to a current version.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Mac OS&amp;lt;/h2&amp;gt; These settings are compatible across the bulk all OS X versions.&lt;br /&gt;
*[[Hosted_Email:Outlook_Exchange_on_Mac|Outlook Exchange on Mac]] - For Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:MacMail_10.x|Mac Mail 10.x]] Same settings for Mail 11.X and 12.X.&lt;br /&gt;
** Video Tutorial - [https://www.youtube.com/watch?v=vIshNacUSLU Setting up Zimbra on Mac Mail]&lt;br /&gt;
*[[Hosted_Email:MacMail_9.x|Mac Mail 9.x]]&lt;br /&gt;
**[[Hosted_Email:Calendar_Sync_OSX|Calendar Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
**[[Hosted_Email:Contacts_Sync_OSX|Contacts Sync]] - for Personal Premium and Zimbra Business accounts&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Mac|Thunderbird Mac]]&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Archive Mac OS&#039;&#039;&#039; &lt;br /&gt;
The following Mac mail applications are out of date and no longer supported beyond the settings provided below.&lt;br /&gt;
Zimbra platform does not guarantee compatibility on all legacy mail applications as many are outside RFE compliance and lack proper security.&lt;br /&gt;
*[[Hosted_Email:MacMail_7.x|Mac Mail 7.x]]&lt;br /&gt;
*[[Hosted_Email:MacMail_3|Mac Mail 3.x]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Linux&amp;lt;/h2&amp;gt;&lt;br /&gt;
*[[Hosted_Email:Thunderbird_Setup_Linux|Thunderbird Linux]]&lt;br /&gt;
*[[Hosted_Email:Evolution|Evolution Mail]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Mobile&amp;lt;/h2&amp;gt;&lt;br /&gt;
*[[Hosted Email Base:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Base and Standard Accounts&lt;br /&gt;
*[[Hosted_Email:iOS|Apple iOS Devices - iPhone/iPad]] - Zimbra Premium Account configuration with Profile&lt;br /&gt;
*[[Apple iOS Devices - iPhone iPad with Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra email, &amp;amp; Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Android|Android]]&lt;br /&gt;
*[[Android Portable Devices with Microsoft Exchange]] - Zimbra Business Premium, XMission.com Personal Zimbra, and Consumer Edition w/ ActiveSync, Exchange setting&lt;br /&gt;
*[[Hosted_Email:Windows_Mobile|Windows Mobile &amp;amp; Windows Phone 8]]&lt;br /&gt;
*[[Hosted_Email:BlackBerry|BlackBerry IMAP]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt; Other &amp;lt;/h2&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[[Hosted_Email:Mutt|Mutt]] Terminal based. Works on Linux and Mac OS.&lt;br /&gt;
* Zimbra Desktop -  Zimbra deprecating at end of 2019. Use configuration settings provided at top of page.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt; Convert from POP to IMAP &amp;lt;/h2&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Thunderbird POP to IMAP process: https://support.mozilla.org/en-US/kb/switch-pop-imap-account&lt;br /&gt;
* [[Windows Outlook 2007 POP to Zimbra IMAP]] Essentially same instructions for 2003.&lt;br /&gt;
* [[Outlook Express POP to Zimbra IMAP]]&lt;br /&gt;
* [[Windows Live Mail POP to Zimbra IMAP]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Client Email Configuration|Zimbra]]&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Two-Factor_Authentication&amp;diff=11061</id>
		<title>Zimbra Two-Factor Authentication</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Two-Factor_Authentication&amp;diff=11061"/>
		<updated>2022-06-02T02:31:07Z</updated>

		<summary type="html">&lt;p&gt;Benjii: /* How to revoke trusted computer/device */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=&#039;&#039;&#039;Two Factor Authentication or 2FA&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
All XMission Zimbra email accounts support a beneficial security practice known as &#039;&#039;&#039;two-factor authentication&#039;&#039;&#039; (aka, 2FA). This includes both &#039;&#039;&#039;base and premium accounts&#039;&#039;&#039;. Two-factor authentication provides mailbox protection by combining something you know (your password) and something have (your smartphone or USB-key, etc.) Once configured you will utilize the 2FA authentication with all devices and programs you use for accessing email. All major platforms support and encourage the use of 2FA.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa-diagram-zimbra87.png | 700px | Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
XMission email customers can opt-out of password yearly password changes by implementing two-factor authentication (2FA). &lt;br /&gt;
&lt;br /&gt;
Once set, your password will never expire unless you disable the advanced authentication. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NOTE&#039;&#039;&#039;: Should you disable 2FA, your password will automatically be set to expire within 30 days and you will have to update your password.&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;How it works&#039;&#039;&#039;=&lt;br /&gt;
By using both a password and a PIN code from a trusted device, like a smartphone, 2FA adds layers of login security to the account. This helps with preventing brute-forcing passwords, or if your password gets leaked/exposed/found from another site, if you use the same password on multiple systems. &lt;br /&gt;
&lt;br /&gt;
In simple terms, two-factor authentication prevents unauthorized users from accessing the system because they are very unlikely to have both variables to access the account. The password and PIN are needed to login. The PIN is sent to the mailbox owner&#039;s smartphone, through something like the Google Authenticator app. If either variable is missing, access is denied.&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;2FA Video Tutorial&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
Watch this official Zimbra.com video on configuring 2FA inside webmail: https://youtu.be/_eEwnnaEvMU&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;How to enable for the Modern interface&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
Two-factor authentication is included by default for all XMission Zimbra accounts. This means all &#039;&#039;&#039;base and premium&#039;&#039;&#039; accounts can use it. Two-factor has to be enabled from the online Zimbra webmail interface for all accounts. &lt;br /&gt;
&lt;br /&gt;
* To enable 2FA go to: &#039;&#039;&#039;Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account &amp;gt; Set up two-factor  authentication&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-01-Setup.png]]&lt;br /&gt;
&lt;br /&gt;
* The first step shows a brief description about two-step authentication. Simply click the &#039;&#039;&#039;&amp;quot;Setup two-step authentication ...&amp;quot;&#039;&#039;&#039; link to begin the configuration process.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-02-Setup-PassConfirmation.png]]&lt;br /&gt;
&lt;br /&gt;
* The next step will ask for your current password. Enter and click on &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
* Next it will establish the second component the user must have, (the &amp;quot;what you have&amp;quot; such as a smartphone application or usb key). The Two Factor authentication wizard will show a Wiki link with the OTP Apps Zimbra recommends. In this example we will be authenticating with your smartphone. ([https://xmission.com/blog/2017/02/08/6-steps-to-zimbra-two-factor-authentication-with-yubikey Reference this blog post on 2FA with a USB key].)&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-03-Setup-InstallAuthApp.png]]&lt;br /&gt;
&lt;br /&gt;
* Once you have installed the smartphone app, the Zimbra 2FA wizard will show a unique key that the you must enter in the Smartphone OTP App unless you use the QR code instead to connect the app.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-04-ConnectQR.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to Install and Configure an OTP smartphone app&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
In this example, we use Google authenticator, but please visit the Zimbra Wiki where you can find other options. &lt;br /&gt;
&lt;br /&gt;
=== Google Authenticator ===&lt;br /&gt;
In the App Store or Play Store, search by Google authenticator, then click Install.&lt;br /&gt;
: [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;amp;hl=en_US&amp;amp;gl=US Google Play Store - Google Authenticator]&lt;br /&gt;
: [https://apps.apple.com/us/app/google-authenticator/id388497605 App Store - Google Authenticator]&lt;br /&gt;
&lt;br /&gt;
* Once the app is installed, open it, and click &#039;&#039;&#039;Get Started&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-01.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* The app will ask if you want to scan a QR code or enter the setup key.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-02.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* All done! Now the app is configured and will show a 6-digit code that changes after 15 seconds.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Finishing the configuration in the Web Client&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
* Once the user has the App configured and showing the 6 digit code, the user can enter the Code in the wizard window and click &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-05-Setup-EnterAuthCode.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The two-step authentication feature is now enabled, and the user will be prompted for a code in each new Browser, smartphone, computer, or app where he or she tries to access the account.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-06-Setup-Successful.png]]&lt;br /&gt;
&lt;br /&gt;
* In the users’ Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account (if the Admin has enabled these options under the COS), the user will see more options like the one-time codes, Trusted devices, and Applications.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Testing Zimbra Two-factor authentication&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
We recommend testing from a new web browser session on another computer.&lt;br /&gt;
&lt;br /&gt;
Time to test from another web browser, computer, smartphone, or the Zimbra Desktop application, you should successfully pass the two-factor authentication process. &lt;br /&gt;
&lt;br /&gt;
For example on the Web Client: One-time Codes&lt;br /&gt;
&lt;br /&gt;
[[file:OneTimeCodes.png]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: #ff0000;&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;NOTE:&amp;lt;/strong&amp;gt;&amp;lt;/span&amp;gt; With the two-factor authentication enabled, there may be a situation where you don&#039;t have the secondary device (phone/usb key). This is where Zimbra allows the use of one-time codes. This feature allows you to generate multiple codes to use in case of emergency. The total number of one-time codes can be configured by XMission. If you need these refreshed let us know.&lt;br /&gt;
&lt;br /&gt;
From the Settings section of the Primary account for Two-Factor authentication you will find the &amp;quot;One-time Codes&amp;quot; option, click &#039;&#039;&#039;View&#039;&#039;&#039; to see your available codes. You must keep the codes secure (written somewhere, in another device, etc.).  Just be certain it is an absolutely secure area where others won&#039;t find it.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Trusted Devices&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Zimbra Web Client and Zimbra Touch Client can be configured as trusted devices during the second challenge stage of two-factor authentication. Once the computer/device is established as trusted you will only need to provide standard credentials, bypassing the two-factor code.&lt;br /&gt;
&lt;br /&gt;
[[file:TrustedDevices.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to trust a computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Once the user enters two-factor code in the login screen the user will have to select the check box &#039;&#039;&#039;Trust this computer&#039;&#039;&#039; and click &#039;&#039;&#039;Verify&#039;&#039;&#039; to trust the current computer/device. User can trust more than one computer/device.&lt;br /&gt;
&lt;br /&gt;
[[file:HowToTrust.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to revoke trusted computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
You can easily revoke a trusted computer/device in Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account &amp;gt; Trusted Devices found in your Zimbra webmail. Revoke trust for any selected device by clicking &amp;quot;revoke this device&amp;quot; link or get rid of them all by clicking on &amp;quot;revoke all other devices&amp;quot; link.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-06-Setup-Successful.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Application Passcode&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Clients such as IMAP or ActiveSync do not support the UI flow needed for TOTP authentication. This means that you will need to use the Application Code section to create codes for IMAP and ActiveSync use. For these users need to generate application passcode.&lt;br /&gt;
&lt;br /&gt;
===Application passcodes:===&lt;br /&gt;
&lt;br /&gt;
Randomly generated.&lt;br /&gt;
Can be created by giving a label and revoked by their label.&lt;br /&gt;
Changing account password will revoke all application passcodes.&lt;br /&gt;
&lt;br /&gt;
===How to create an application passcode===&lt;br /&gt;
&lt;br /&gt;
* Users can create an application passcode by navigating to &#039;&#039;&#039;Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account&#039;&#039;&#039; and selecting &#039;&#039;&#039;&amp;quot;Add a passcode&amp;quot;&#039;&#039;&#039; button.&lt;br /&gt;
&lt;br /&gt;
[[file:AppPasscode-01-AddingPasscode.png]]&lt;br /&gt;
&lt;br /&gt;
* Next enter the application name you desire in the &#039;&#039;&#039;&amp;quot;Add a passcode&amp;quot;&#039;&#039;&#039; dialog and click &#039;&#039;&#039;Next&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
[[file:AppPasscode-02-AddPasscode.png]]&lt;br /&gt;
&lt;br /&gt;
* Application passcode will get generated, then it can be used to sign in to your account from that device.&lt;br /&gt;
&lt;br /&gt;
[[file:AppPasscode-03-PasscodeForApp.png]]&lt;br /&gt;
&lt;br /&gt;
==Revoking Application Codes==&lt;br /&gt;
&lt;br /&gt;
Once the user generates application passcode user can revoke it by navigating to &#039;&#039;&#039;Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account&#039;&#039;&#039; in Zimbra Web Client. Users can revoke this application passcode after selecting the required name in the list.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;How to enable for the Classic interface&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
Two-factor authentication is included by default for all XMission Zimbra accounts. This means all &#039;&#039;&#039;base and premium&#039;&#039;&#039; accounts can use it. Two-factor has to be enabled from the online Zimbra webmail interface for all accounts. &lt;br /&gt;
&lt;br /&gt;
* To enable 2FA go to: &#039;&#039;&#039;Preferences &amp;gt; Accounts &amp;gt; Account Security, Setup two-step authentication&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[file:2fa_XM_Zimbra_AccountSecurity.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
* Simply click the &amp;quot;Setup two-step authentication ...&amp;quot; link to begin the configuration process.&lt;br /&gt;
&lt;br /&gt;
* The first step shows a brief description about two-step authentication. Next click on &#039;&#039;&#039;Begin Setup&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa_XM_Zimbra_Begin_Setup.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
* The next step will ask for your current password. Enter and click on &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
* Next it will establish the second component the user must have, (the &amp;quot;what you have&amp;quot; such as a smartphone application or usb key). The Two Factor authentication wizard will show a Wiki link with the OTP Apps Zimbra recommends. In this example we will be authenticating with your smartphone. ([https://xmission.com/blog/2017/02/08/6-steps-to-zimbra-two-factor-authentication-with-yubikey Reference this blog post on 2FA with a USB key].)&lt;br /&gt;
&lt;br /&gt;
* Once you have installed the smartphone app, the Zimbra 2FA wizard will show a unique key that the you must enter in the Smartphone OTP App.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa_XM_Zimbra_code_example.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to Install and Configure an OTP smartphone app&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
In this example, we use Google authenticator, but please visit the Zimbra Wiki where you can find other options. &lt;br /&gt;
&lt;br /&gt;
=== Google Authenticator ===&lt;br /&gt;
In the App Store or Play Store, search by Google authenticator, then click Install.&lt;br /&gt;
: [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;amp;hl=en_US&amp;amp;gl=US Google Play Store - Google Authenticator]&lt;br /&gt;
: [https://apps.apple.com/us/app/google-authenticator/id388497605 App Store - Google Authenticator]&lt;br /&gt;
&lt;br /&gt;
* Once the app is installed, open it, and click &#039;&#039;&#039;Get Started&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-01.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* The app will ask if you want to scan a QR code or enter the setup key.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-02.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* All done! Now the app is configured and will show a 6-digit code that changes after 15 seconds.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Finishing the configuration in the Web Client&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
* Once the user has the App configured and showing the 6 digit code, the user can enter the Code in the wizard window and click Next.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa6.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The two-step authentication feature is now enabled, and the user will be prompted for a code in each new Browser, smartphone, computer, or app where he or she tries to access the account.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa7.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
* In the users’ Preferences &amp;gt; Accounts &amp;gt; Account Security (if the Admin has enabled these options under the COS), the user will see more options like the one-time codes, Trusted devices, and Applications.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa8.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Testing Zimbra Two-factor authentication&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
We recommend testing from a new web browser session on another computer.&lt;br /&gt;
&lt;br /&gt;
Time to test from another web browser, computer, smartphone, or the Zimbra Desktop application, you should successfully pass the two-factor authentication process. &lt;br /&gt;
&lt;br /&gt;
For example on the Web Client: One-time Codes&lt;br /&gt;
&lt;br /&gt;
[[File:2fa10.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: #ff0000;&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;NOTE:&amp;lt;/strong&amp;gt;&amp;lt;/span&amp;gt; With the two-factor authentication enabled, there may be a situation where you don&#039;t have the secondary device (phone/usb key). This is where Zimbra allows the use of one-time codes. This feature allows you to generate multiple codes to use in case of emergency. The total number of one-time codes can be configured by XMission. If you need these refreshed let us know.&lt;br /&gt;
&lt;br /&gt;
From the Preferences settings for 2FA  you will find &amp;quot;One-time Codes&amp;quot; option, click &#039;&#039;&#039;View&#039;&#039;&#039; to see your available codes. You must keep the codes secure (written somewhere, in another device, etc.).  Just be certain it is an absolutely secure area where others won&#039;t find it.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Trusted Devices&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Zimbra Web Client and Zimbra Touch Client can be configured as trusted devices during the second challenge stage of two-factor authentication. Once the computer/device is established as trusted you will only need to provide standard credentials, bypassing the two-factor code.&lt;br /&gt;
&lt;br /&gt;
[[File:Trusteddevices2.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to trust a computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Once the user enters two-factor code in the login screen the user will have to select the check box &#039;&#039;&#039;Trust this computer&#039;&#039;&#039; and click &#039;&#039;&#039;Verify&#039;&#039;&#039; to trust the current computer/device. User can trust more than one computer/device.&lt;br /&gt;
&lt;br /&gt;
[[File:Trusteddevices1.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to revoke trusted computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
You can easily revoke a trusted computer/device in Preferences &amp;gt; Accounts &amp;gt; Trusted Devices found in your Zimbra webmail. Revoke trust for any selected device by clicking &amp;quot;revoke this device&amp;quot; link or get rid of them all by clicking on &amp;quot;revoke all other devices&amp;quot; link.&lt;br /&gt;
&lt;br /&gt;
[[File:Trusteddevices3.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Application Passcode&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Clients such as IMAP or ActiveSync do not support the UI flow needed for TOTP authentication. This means that you will need to use the Application Code section to create codes for IMAP and ActiveSync use. For these users need to generate application passcode.&lt;br /&gt;
&lt;br /&gt;
===Application passcodes:===&lt;br /&gt;
&lt;br /&gt;
Randomly generated.&lt;br /&gt;
Can be created by giving a label and revoked by their label.&lt;br /&gt;
Changing account password will revoke all application passcodes.&lt;br /&gt;
&lt;br /&gt;
===How to create an application passcode===&lt;br /&gt;
&lt;br /&gt;
* Users can create an application passcode by navigating to &#039;&#039;&#039;Preferences &amp;gt; Accounts &amp;gt; Applications&#039;&#039;&#039; and selecting Add Application Code button.&lt;br /&gt;
&lt;br /&gt;
[[File:Appcode1.png]]&lt;br /&gt;
&lt;br /&gt;
* Next enter the application name you desire in the &#039;&#039;&#039;&amp;quot;Add Application Code&amp;quot;&#039;&#039;&#039; dialog and click Next. &lt;br /&gt;
&lt;br /&gt;
[[File:Appcode2.png]]&lt;br /&gt;
&lt;br /&gt;
* Application passcode will get generated, then it can be used to sign in to your account from that device.&lt;br /&gt;
&lt;br /&gt;
[[File:Appcode3.png]]&lt;br /&gt;
&lt;br /&gt;
==Revoking Application Codes==&lt;br /&gt;
&lt;br /&gt;
Once the user generates application passcode user can revoke it by navigating to &#039;&#039;&#039;Preferences &amp;gt; Accounts &amp;gt; Applications&#039;&#039;&#039; in Zimbra Web Client. Users can revoke this application passcode after selecting the required name in the list.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Known Issues=&lt;br /&gt;
&lt;br /&gt;
===Zimbra bugs===&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=103824 Bug 103824] {AUTH} Provide 2FA configuration capability in ZCO&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=104144 Bug 104144] 2fa:ReferenceError: AjxDebug is not defined when zimbraFeatureTwoFactorAuthRequired in multinode rolling upgrade environment&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=104648 Bug 104648] allow clearing 2FA data from admin console&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=105678 Bug 105678] Application specific password entry should be purged when 2FA disabled from Admin Console&lt;br /&gt;
&lt;br /&gt;
===Notes===&lt;br /&gt;
&lt;br /&gt;
Disabling two-factor authentication using Admin console does not clear user&#039;s two-factor data. Admin can disable user&#039;s two-factor authentication in case user is facing issues with authentication using TOTP/scratch codes. Re-enabling user&#039;s two-factor authentication using Admin console after user&#039;s problem has got resolved will allow user to use two-factor authentication. In future, Bug 104648 will allow Admin to clear user&#039;s two-factor data.&lt;br /&gt;
&lt;br /&gt;
===Third party issues===&lt;br /&gt;
&lt;br /&gt;
Issue - Mail client issues with application passcode&lt;br /&gt;
&lt;br /&gt;
Scenario: User&#039;s zimbra account is configured on EWS Apple Mail and Thunderbird (IMAP/POP3). User enables 2FA using Web client, adds application passcodes for Apple Mail and Thunderbird applications.&lt;br /&gt;
&lt;br /&gt;
Expected behavior: Both clients (Apple Mail) and Thunderbird should prompt for new password, user if enters application passcode, authentication should succeed.&lt;br /&gt;
&lt;br /&gt;
Current behavior:&lt;br /&gt;
&lt;br /&gt;
EWS Apple Mail app complains about connection failure and provides option to enter new password, wherein entering correct application passcode does not work. Only option is to Edit Account and provide new password, which works correctly.&lt;br /&gt;
&lt;br /&gt;
Thunderbird (IMAP/POP3) prompts for new password after some time (after few minutes or sometimes after restarting client)&lt;br /&gt;
&lt;br /&gt;
===Failed Login Attempts===&lt;br /&gt;
&lt;br /&gt;
Please note, use of Two-Factor Authentication (2FA) does not prevent account suspension due to exceeding [https://wiki.xmission.com/Hosted_Email:_Admin_Panel#Password_Expiration_and_Failed_Login_Attempts failed login attempts] limits.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Email]]&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=Zimbra_Two-Factor_Authentication&amp;diff=11018</id>
		<title>Zimbra Two-Factor Authentication</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=Zimbra_Two-Factor_Authentication&amp;diff=11018"/>
		<updated>2022-05-06T22:42:22Z</updated>

		<summary type="html">&lt;p&gt;Benjii: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=&#039;&#039;&#039;Two Factor Authentication or 2FA&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
All XMission Zimbra email accounts support a beneficial security practice known as &#039;&#039;&#039;two-factor authentication&#039;&#039;&#039; (aka, 2FA). This includes both &#039;&#039;&#039;base and premium accounts&#039;&#039;&#039;. Two-factor authentication provides mailbox protection by combining something you know (your password) and something have (your smartphone or USB-key, etc.) Once configured you will utilize the 2FA authentication with all devices and programs you use for accessing email. All major platforms support and encourage the use of 2FA.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa-diagram-zimbra87.png | 700px | Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
XMission email customers can opt-out of password yearly password changes by implementing two-factor authentication (2FA). &lt;br /&gt;
&lt;br /&gt;
Once set, your password will never expire unless you disable the advanced authentication. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NOTE&#039;&#039;&#039;: Should you disable 2FA, your password will automatically be set to expire within 30 days and you will have to update your password.&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;How it works&#039;&#039;&#039;=&lt;br /&gt;
By using both a password and a PIN code from a trusted device, like a smartphone, 2FA adds layers of login security to the account. This helps with preventing brute-forcing passwords, or if your password gets leaked/exposed/found from another site, if you use the same password on multiple systems. &lt;br /&gt;
&lt;br /&gt;
In simple terms, two-factor authentication prevents unauthorized users from accessing the system because they are very unlikely to have both variables to access the account. The password and PIN are needed to login. The PIN is sent to the mailbox owner&#039;s smartphone, through something like the Google Authenticator app. If either variable is missing, access is denied.&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;2FA Video Tutorial&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
Watch this official Zimbra.com video on configuring 2FA inside webmail: https://youtu.be/_eEwnnaEvMU&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;How to enable for the Modern interface&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
Two-factor authentication is included by default for all XMission Zimbra accounts. This means all &#039;&#039;&#039;base and premium&#039;&#039;&#039; accounts can use it. Two-factor has to be enabled from the online Zimbra webmail interface for all accounts. &lt;br /&gt;
&lt;br /&gt;
* To enable 2FA go to: &#039;&#039;&#039;Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account &amp;gt; Set up two-factor  authentication&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-01-Setup.png]]&lt;br /&gt;
&lt;br /&gt;
* The first step shows a brief description about two-step authentication. Simply click the &#039;&#039;&#039;&amp;quot;Setup two-step authentication ...&amp;quot;&#039;&#039;&#039; link to begin the configuration process.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-02-Setup-PassConfirmation.png]]&lt;br /&gt;
&lt;br /&gt;
* The next step will ask for your current password. Enter and click on &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
* Next it will establish the second component the user must have, (the &amp;quot;what you have&amp;quot; such as a smartphone application or usb key). The Two Factor authentication wizard will show a Wiki link with the OTP Apps Zimbra recommends. In this example we will be authenticating with your smartphone. ([https://xmission.com/blog/2017/02/08/6-steps-to-zimbra-two-factor-authentication-with-yubikey Reference this blog post on 2FA with a USB key].)&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-03-Setup-InstallAuthApp.png]]&lt;br /&gt;
&lt;br /&gt;
* Once you have installed the smartphone app, the Zimbra 2FA wizard will show a unique key that the you must enter in the Smartphone OTP App unless you use the QR code instead to connect the app.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-04-ConnectQR.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to Install and Configure an OTP smartphone app&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
In this example, we use Google authenticator, but please visit the Zimbra Wiki where you can find other options. &lt;br /&gt;
&lt;br /&gt;
=== Google Authenticator ===&lt;br /&gt;
In the App Store or Play Store, search by Google authenticator, then click Install.&lt;br /&gt;
: [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;amp;hl=en_US&amp;amp;gl=US Google Play Store - Google Authenticator]&lt;br /&gt;
: [https://apps.apple.com/us/app/google-authenticator/id388497605 App Store - Google Authenticator]&lt;br /&gt;
&lt;br /&gt;
* Once the app is installed, open it, and click &#039;&#039;&#039;Get Started&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-01.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* The app will ask if you want to scan a QR code or enter the setup key.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-02.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* All done! Now the app is configured and will show a 6-digit code that changes after 15 seconds.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Finishing the configuration in the Web Client&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
* Once the user has the App configured and showing the 6 digit code, the user can enter the Code in the wizard window and click &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-05-Setup-EnterAuthCode.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The two-step authentication feature is now enabled, and the user will be prompted for a code in each new Browser, smartphone, computer, or app where he or she tries to access the account.&lt;br /&gt;
&lt;br /&gt;
[[file:2FA-06-Setup-Successful.png]]&lt;br /&gt;
&lt;br /&gt;
* In the users’ Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account (if the Admin has enabled these options under the COS), the user will see more options like the one-time codes, Trusted devices, and Applications.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Testing Zimbra Two-factor authentication&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
We recommend testing from a new web browser session on another computer.&lt;br /&gt;
&lt;br /&gt;
Time to test from another web browser, computer, smartphone, or the Zimbra Desktop application, you should successfully pass the two-factor authentication process. &lt;br /&gt;
&lt;br /&gt;
For example on the Web Client: One-time Codes&lt;br /&gt;
&lt;br /&gt;
[[file:OneTimeCodes.png]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: #ff0000;&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;NOTE:&amp;lt;/strong&amp;gt;&amp;lt;/span&amp;gt; With the two-factor authentication enabled, there may be a situation where you don&#039;t have the secondary device (phone/usb key). This is where Zimbra allows the use of one-time codes. This feature allows you to generate multiple codes to use in case of emergency. The total number of one-time codes can be configured by XMission. If you need these refreshed let us know.&lt;br /&gt;
&lt;br /&gt;
From the Settings section of the Primary account for Two-Factor authentication you will find the &amp;quot;One-time Codes&amp;quot; option, click &#039;&#039;&#039;View&#039;&#039;&#039; to see your available codes. You must keep the codes secure (written somewhere, in another device, etc.).  Just be certain it is an absolutely secure area where others won&#039;t find it.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Trusted Devices&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Zimbra Web Client and Zimbra Touch Client can be configured as trusted devices during the second challenge stage of two-factor authentication. Once the computer/device is established as trusted you will only need to provide standard credentials, bypassing the two-factor code.&lt;br /&gt;
&lt;br /&gt;
[[file:TrustedDevices.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to trust a computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Once the user enters two-factor code in the login screen the user will have to select the check box &#039;&#039;&#039;Trust this computer&#039;&#039;&#039; and click &#039;&#039;&#039;Verify&#039;&#039;&#039; to trust the current computer/device. User can trust more than one computer/device.&lt;br /&gt;
&lt;br /&gt;
[[file:HowToTrust.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to revoke trusted computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
You can easily revoke a trusted computer/device in Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account &amp;gt; Trusted Devices found in your Zimbra webmail. Revoke trust for any selected device by clicking &amp;quot;revoke this device&amp;quot; link or get rid of them all by clicking on &amp;quot;revoke all other devices&amp;quot; link.&lt;br /&gt;
&lt;br /&gt;
[[file:RevokeTrust.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Application Passcode&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Clients such as IMAP or ActiveSync do not support the UI flow needed for TOTP authentication. This means that you will need to use the Application Code section to create codes for IMAP and ActiveSync use. For these users need to generate application passcode.&lt;br /&gt;
&lt;br /&gt;
===Application passcodes:===&lt;br /&gt;
&lt;br /&gt;
Randomly generated.&lt;br /&gt;
Can be created by giving a label and revoked by their label.&lt;br /&gt;
Changing account password will revoke all application passcodes.&lt;br /&gt;
&lt;br /&gt;
===How to create an application passcode===&lt;br /&gt;
&lt;br /&gt;
* Users can create an application passcode by navigating to &#039;&#039;&#039;Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account&#039;&#039;&#039; and selecting &#039;&#039;&#039;&amp;quot;Add a passcode&amp;quot;&#039;&#039;&#039; button.&lt;br /&gt;
&lt;br /&gt;
[[file:AppPasscode-01-AddingPasscode.png]]&lt;br /&gt;
&lt;br /&gt;
* Next enter the application name you desire in the &#039;&#039;&#039;&amp;quot;Add a passcode&amp;quot;&#039;&#039;&#039; dialog and click &#039;&#039;&#039;Next&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
[[file:AppPasscode-02-AddPasscode.png]]&lt;br /&gt;
&lt;br /&gt;
* Application passcode will get generated, then it can be used to sign in to your account from that device.&lt;br /&gt;
&lt;br /&gt;
[[file:AppPasscode-03-PasscodeForApp.png]]&lt;br /&gt;
&lt;br /&gt;
==Revoking Application Codes==&lt;br /&gt;
&lt;br /&gt;
Once the user generates application passcode user can revoke it by navigating to &#039;&#039;&#039;Settings &amp;gt; Accounts &amp;gt; Select &amp;quot;Primary&amp;quot; Account&#039;&#039;&#039; in Zimbra Web Client. Users can revoke this application passcode after selecting the required name in the list.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=&#039;&#039;&#039;How to enable for the Classic interface&#039;&#039;&#039;=&lt;br /&gt;
&lt;br /&gt;
Two-factor authentication is included by default for all XMission Zimbra accounts. This means all &#039;&#039;&#039;base and premium&#039;&#039;&#039; accounts can use it. Two-factor has to be enabled from the online Zimbra webmail interface for all accounts. &lt;br /&gt;
&lt;br /&gt;
* To enable 2FA go to: &#039;&#039;&#039;Preferences &amp;gt; Accounts &amp;gt; Account Security, Setup two-step authentication&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[file:2fa_XM_Zimbra_AccountSecurity.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
* Simply click the &amp;quot;Setup two-step authentication ...&amp;quot; link to begin the configuration process.&lt;br /&gt;
&lt;br /&gt;
* The first step shows a brief description about two-step authentication. Next click on &#039;&#039;&#039;Begin Setup&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa_XM_Zimbra_Begin_Setup.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
* The next step will ask for your current password. Enter and click on &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
* Next it will establish the second component the user must have, (the &amp;quot;what you have&amp;quot; such as a smartphone application or usb key). The Two Factor authentication wizard will show a Wiki link with the OTP Apps Zimbra recommends. In this example we will be authenticating with your smartphone. ([https://xmission.com/blog/2017/02/08/6-steps-to-zimbra-two-factor-authentication-with-yubikey Reference this blog post on 2FA with a USB key].)&lt;br /&gt;
&lt;br /&gt;
* Once you have installed the smartphone app, the Zimbra 2FA wizard will show a unique key that the you must enter in the Smartphone OTP App.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa_XM_Zimbra_code_example.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to Install and Configure an OTP smartphone app&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
In this example, we use Google authenticator, but please visit the Zimbra Wiki where you can find other options. &lt;br /&gt;
&lt;br /&gt;
=== Google Authenticator ===&lt;br /&gt;
In the App Store or Play Store, search by Google authenticator, then click Install.&lt;br /&gt;
: [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;amp;hl=en_US&amp;amp;gl=US Google Play Store - Google Authenticator]&lt;br /&gt;
: [https://apps.apple.com/us/app/google-authenticator/id388497605 App Store - Google Authenticator]&lt;br /&gt;
&lt;br /&gt;
* Once the app is installed, open it, and click &#039;&#039;&#039;Get Started&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-01.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* The app will ask if you want to scan a QR code or enter the setup key.&lt;br /&gt;
&lt;br /&gt;
[[file:GoogleAuth-02.jpg|300px]]&lt;br /&gt;
&lt;br /&gt;
* All done! Now the app is configured and will show a 6-digit code that changes after 15 seconds.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Finishing the configuration in the Web Client&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
* Once the user has the App configured and showing the 6 digit code, the user can enter the Code in the wizard window and click Next.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa6.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The two-step authentication feature is now enabled, and the user will be prompted for a code in each new Browser, smartphone, computer, or app where he or she tries to access the account.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa7.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
* In the users’ Preferences &amp;gt; Accounts &amp;gt; Account Security (if the Admin has enabled these options under the COS), the user will see more options like the one-time codes, Trusted devices, and Applications.&lt;br /&gt;
&lt;br /&gt;
[[File:2fa8.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Testing Zimbra Two-factor authentication&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
We recommend testing from a new web browser session on another computer.&lt;br /&gt;
&lt;br /&gt;
Time to test from another web browser, computer, smartphone, or the Zimbra Desktop application, you should successfully pass the two-factor authentication process. &lt;br /&gt;
&lt;br /&gt;
For example on the Web Client: One-time Codes&lt;br /&gt;
&lt;br /&gt;
[[File:2fa10.png| Image (c) Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: #ff0000;&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;NOTE:&amp;lt;/strong&amp;gt;&amp;lt;/span&amp;gt; With the two-factor authentication enabled, there may be a situation where you don&#039;t have the secondary device (phone/usb key). This is where Zimbra allows the use of one-time codes. This feature allows you to generate multiple codes to use in case of emergency. The total number of one-time codes can be configured by XMission. If you need these refreshed let us know.&lt;br /&gt;
&lt;br /&gt;
From the Preferences settings for 2FA  you will find &amp;quot;One-time Codes&amp;quot; option, click &#039;&#039;&#039;View&#039;&#039;&#039; to see your available codes. You must keep the codes secure (written somewhere, in another device, etc.).  Just be certain it is an absolutely secure area where others won&#039;t find it.&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Trusted Devices&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Zimbra Web Client and Zimbra Touch Client can be configured as trusted devices during the second challenge stage of two-factor authentication. Once the computer/device is established as trusted you will only need to provide standard credentials, bypassing the two-factor code.&lt;br /&gt;
&lt;br /&gt;
[[File:Trusteddevices2.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to trust a computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Once the user enters two-factor code in the login screen the user will have to select the check box &#039;&#039;&#039;Trust this computer&#039;&#039;&#039; and click &#039;&#039;&#039;Verify&#039;&#039;&#039; to trust the current computer/device. User can trust more than one computer/device.&lt;br /&gt;
&lt;br /&gt;
[[File:Trusteddevices1.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;How to revoke trusted computer/device&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
You can easily revoke a trusted computer/device in Preferences &amp;gt; Accounts &amp;gt; Trusted Devices found in your Zimbra webmail. Revoke trust for any selected device by clicking &amp;quot;revoke this device&amp;quot; link or get rid of them all by clicking on &amp;quot;revoke all other devices&amp;quot; link.&lt;br /&gt;
&lt;br /&gt;
[[File:Trusteddevices3.png]]&lt;br /&gt;
&lt;br /&gt;
==&#039;&#039;&#039;Application Passcode&#039;&#039;&#039;==&lt;br /&gt;
&lt;br /&gt;
Clients such as IMAP or ActiveSync do not support the UI flow needed for TOTP authentication. This means that you will need to use the Application Code section to create codes for IMAP and ActiveSync use. For these users need to generate application passcode.&lt;br /&gt;
&lt;br /&gt;
===Application passcodes:===&lt;br /&gt;
&lt;br /&gt;
Randomly generated.&lt;br /&gt;
Can be created by giving a label and revoked by their label.&lt;br /&gt;
Changing account password will revoke all application passcodes.&lt;br /&gt;
&lt;br /&gt;
===How to create an application passcode===&lt;br /&gt;
&lt;br /&gt;
* Users can create an application passcode by navigating to &#039;&#039;&#039;Preferences &amp;gt; Accounts &amp;gt; Applications&#039;&#039;&#039; and selecting Add Application Code button.&lt;br /&gt;
&lt;br /&gt;
[[File:Appcode1.png]]&lt;br /&gt;
&lt;br /&gt;
* Next enter the application name you desire in the &#039;&#039;&#039;&amp;quot;Add Application Code&amp;quot;&#039;&#039;&#039; dialog and click Next. &lt;br /&gt;
&lt;br /&gt;
[[File:Appcode2.png]]&lt;br /&gt;
&lt;br /&gt;
* Application passcode will get generated, then it can be used to sign in to your account from that device.&lt;br /&gt;
&lt;br /&gt;
[[File:Appcode3.png]]&lt;br /&gt;
&lt;br /&gt;
==Revoking Application Codes==&lt;br /&gt;
&lt;br /&gt;
Once the user generates application passcode user can revoke it by navigating to &#039;&#039;&#039;Preferences &amp;gt; Accounts &amp;gt; Applications&#039;&#039;&#039; in Zimbra Web Client. Users can revoke this application passcode after selecting the required name in the list.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Known Issues=&lt;br /&gt;
&lt;br /&gt;
===Zimbra bugs===&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=103824 Bug 103824] {AUTH} Provide 2FA configuration capability in ZCO&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=104144 Bug 104144] 2fa:ReferenceError: AjxDebug is not defined when zimbraFeatureTwoFactorAuthRequired in multinode rolling upgrade environment&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=104648 Bug 104648] allow clearing 2FA data from admin console&lt;br /&gt;
&lt;br /&gt;
[https://bugzilla.zimbra.com/show_bug.cgi?id=105678 Bug 105678] Application specific password entry should be purged when 2FA disabled from Admin Console&lt;br /&gt;
&lt;br /&gt;
===Notes===&lt;br /&gt;
&lt;br /&gt;
Disabling two-factor authentication using Admin console does not clear user&#039;s two-factor data. Admin can disable user&#039;s two-factor authentication in case user is facing issues with authentication using TOTP/scratch codes. Re-enabling user&#039;s two-factor authentication using Admin console after user&#039;s problem has got resolved will allow user to use two-factor authentication. In future, Bug 104648 will allow Admin to clear user&#039;s two-factor data.&lt;br /&gt;
&lt;br /&gt;
===Third party issues===&lt;br /&gt;
&lt;br /&gt;
Issue - Mail client issues with application passcode&lt;br /&gt;
&lt;br /&gt;
Scenario: User&#039;s zimbra account is configured on EWS Apple Mail and Thunderbird (IMAP/POP3). User enables 2FA using Web client, adds application passcodes for Apple Mail and Thunderbird applications.&lt;br /&gt;
&lt;br /&gt;
Expected behavior: Both clients (Apple Mail) and Thunderbird should prompt for new password, user if enters application passcode, authentication should succeed.&lt;br /&gt;
&lt;br /&gt;
Current behavior:&lt;br /&gt;
&lt;br /&gt;
EWS Apple Mail app complains about connection failure and provides option to enter new password, wherein entering correct application passcode does not work. Only option is to Edit Account and provide new password, which works correctly.&lt;br /&gt;
&lt;br /&gt;
Thunderbird (IMAP/POP3) prompts for new password after some time (after few minutes or sometimes after restarting client)&lt;br /&gt;
&lt;br /&gt;
===Failed Login Attempts===&lt;br /&gt;
&lt;br /&gt;
Please note, use of Two-Factor Authentication (2FA) does not prevent account suspension due to exceeding [https://wiki.xmission.com/Hosted_Email:_Admin_Panel#Password_Expiration_and_Failed_Login_Attempts failed login attempts] limits.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Email]]&lt;br /&gt;
[[Category:Zimbra]]&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:TrustedDevices.png&amp;diff=11017</id>
		<title>File:TrustedDevices.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:TrustedDevices.png&amp;diff=11017"/>
		<updated>2022-05-05T23:51:25Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Trust devices can be reviewed and have their trust revoked in this section of the Zimbra Modern interface&amp;#039;s settings.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Trust devices can be reviewed and have their trust revoked in this section of the Zimbra Modern interface&#039;s settings.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:OneTimePasscode.png&amp;diff=11016</id>
		<title>File:OneTimePasscode.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:OneTimePasscode.png&amp;diff=11016"/>
		<updated>2022-05-05T23:50:52Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Locating the one time codes in the Zimbra Modern interface.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Locating the one time codes in the Zimbra Modern interface.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:OneTimeCodes.png&amp;diff=11015</id>
		<title>File:OneTimeCodes.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:OneTimeCodes.png&amp;diff=11015"/>
		<updated>2022-05-05T23:50:05Z</updated>

		<summary type="html">&lt;p&gt;Benjii: The 2FA settings on the Modern interface will allow the user of one time passcodes that are presented in this format.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The 2FA settings on the Modern interface will allow the user of one time passcodes that are presented in this format.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:HowToTrust.png&amp;diff=11014</id>
		<title>File:HowToTrust.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:HowToTrust.png&amp;diff=11014"/>
		<updated>2022-05-05T23:49:13Z</updated>

		<summary type="html">&lt;p&gt;Benjii: When logging in to the website, it will ask for a code from the authentication app.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;When logging in to the website, it will ask for a code from the authentication app.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:GoogleAuth-02.jpg&amp;diff=11013</id>
		<title>File:GoogleAuth-02.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:GoogleAuth-02.jpg&amp;diff=11013"/>
		<updated>2022-05-05T23:48:17Z</updated>

		<summary type="html">&lt;p&gt;Benjii: The Google Authenticator app will prompt to either put in the key or to scan the QR code.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Google Authenticator app will prompt to either put in the key or to scan the QR code.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:GoogleAuth-01.jpg&amp;diff=11012</id>
		<title>File:GoogleAuth-01.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:GoogleAuth-01.jpg&amp;diff=11012"/>
		<updated>2022-05-05T23:45:52Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Brand new google authentication app page to begin the setup process.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Brand new google authentication app page to begin the setup process.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:AppPasscode-03-PasscodeForApp.png&amp;diff=11011</id>
		<title>File:AppPasscode-03-PasscodeForApp.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:AppPasscode-03-PasscodeForApp.png&amp;diff=11011"/>
		<updated>2022-05-05T23:43:03Z</updated>

		<summary type="html">&lt;p&gt;Benjii: The screen will provide a passcode to use in place of the normal mailbox&amp;#039;s password when connecting it to the protected mailbox.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The screen will provide a passcode to use in place of the normal mailbox&#039;s password when connecting it to the protected mailbox.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:AppPasscode-02-AddPasscode.png&amp;diff=11010</id>
		<title>File:AppPasscode-02-AddPasscode.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:AppPasscode-02-AddPasscode.png&amp;diff=11010"/>
		<updated>2022-05-05T23:41:25Z</updated>

		<summary type="html">&lt;p&gt;Benjii: When generating the passcode for a particular application, you will want to provide it a descriptive name for easy review.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;When generating the passcode for a particular application, you will want to provide it a descriptive name for easy review.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:AppPasscode-01-AddingPasscode.png&amp;diff=11009</id>
		<title>File:AppPasscode-01-AddingPasscode.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:AppPasscode-01-AddingPasscode.png&amp;diff=11009"/>
		<updated>2022-05-05T23:40:03Z</updated>

		<summary type="html">&lt;p&gt;Benjii: To generate an application specfic passcode, the settings page will provide an option here.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;To generate an application specfic passcode, the settings page will provide an option here.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:2FA-06-Setup-Successful.png&amp;diff=11008</id>
		<title>File:2FA-06-Setup-Successful.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:2FA-06-Setup-Successful.png&amp;diff=11008"/>
		<updated>2022-05-05T23:37:22Z</updated>

		<summary type="html">&lt;p&gt;Benjii: After successfully verifying you will be presented with a completion screen looking like this.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;After successfully verifying you will be presented with a completion screen looking like this.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:2FA-05-Setup-EnterAuthCode.png&amp;diff=11007</id>
		<title>File:2FA-05-Setup-EnterAuthCode.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:2FA-05-Setup-EnterAuthCode.png&amp;diff=11007"/>
		<updated>2022-05-05T23:36:48Z</updated>

		<summary type="html">&lt;p&gt;Benjii: To confirm the authentication app is successfully connected, enter the code generated by the app.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;To confirm the authentication app is successfully connected, enter the code generated by the app.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:2FA-04-ConnectQR.png&amp;diff=11006</id>
		<title>File:2FA-04-ConnectQR.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:2FA-04-ConnectQR.png&amp;diff=11006"/>
		<updated>2022-05-05T23:35:16Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Authentication app can be connected to the 2FA service by entering a key or easily scanning a QR code.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Authentication app can be connected to the 2FA service by entering a key or easily scanning a QR code.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:2FA-03-Setup-InstallAuthApp.png&amp;diff=11005</id>
		<title>File:2FA-03-Setup-InstallAuthApp.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:2FA-03-Setup-InstallAuthApp.png&amp;diff=11005"/>
		<updated>2022-05-05T21:56:36Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Prompt to install an authentication app to use in conjunction with Zimbra&amp;#039;s 2FA service.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Prompt to install an authentication app to use in conjunction with Zimbra&#039;s 2FA service.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:2FA-02-Setup-PassConfirmation.png&amp;diff=11004</id>
		<title>File:2FA-02-Setup-PassConfirmation.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:2FA-02-Setup-PassConfirmation.png&amp;diff=11004"/>
		<updated>2022-05-05T21:55:25Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Password prompt that occurs after initiating the 2FA setup.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Password prompt that occurs after initiating the 2FA setup.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
	<entry>
		<id>https://wiki.xmission.com/index.php?title=File:2FA-01-Setup.png&amp;diff=11003</id>
		<title>File:2FA-01-Setup.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.xmission.com/index.php?title=File:2FA-01-Setup.png&amp;diff=11003"/>
		<updated>2022-05-05T21:54:30Z</updated>

		<summary type="html">&lt;p&gt;Benjii: Using the Zimbra Modern interface the window to setup Two-Factor authentication looks like this.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Using the Zimbra Modern interface the window to setup Two-Factor authentication looks like this.&lt;/div&gt;</summary>
		<author><name>Benjii</name></author>
	</entry>
</feed>