Load balancing encrypted email traffic (IMAPS on port 993, POP3S on port 995, and SMTPS on port 465) using HAProxy requires two critical mechanisms: SSL offloading at the load balancer and the PROXY protocol to preserve the client's real public IP address in Dovecot and Postfix logs.
Architecture: Encrypted Client → HAProxy (SSL Termination &
send-proxy) → Dovecot / Postfix (Real IP Preserved)
1. HAProxy Configuration (haproxy.cfg)
frontend imaps_in
bind *:993 ssl crt /etc/ssl/certs/mail.pem
mode tcp
default_backend dovecot_imaps
backend dovecot_imaps
mode tcp
server mail1 10.0.0.1:10143 send-proxy check
2. Dovecot PROXY Protocol Support (/etc/dovecot/dovecot.conf)
Configure Dovecot to accept the PROXY protocol header to log the real client IP:
service imap-login {
inet_listener imap_haproxy {
port = 10143
haproxy = yes
}
}
haproxy_trusted_networks = 10.0.0.0/24