How do I find out why a mail server isn't delivering email?
FrontierStack's Mail Server Policy section (on each linked server) audits the SMTP configuration read-only — open-relay protection, authentication, submission-port (587) login, inbound TLS, sender-spoofing, DNS blocklists and the MX/SPF/DKIM/DMARC of every domain the server claims. It reads the config the running Postfix actually uses, so it doesn't give the wrong answer on macOS Server (where the live config is /Library/Server/Mail/Config/postfix, not /etc/postfix). Alongside it, a Delivery probe sends one tagged test message end-to-end through the relay and reports the exact SMTP verdict — accepted & queued (with the queue id), deferred, rejected, or a TLS-certificate failure — which is how you tell “accepted then silently dropped” from real delivery. On an old Apple Server.app box FrontierStack also finds Postfix's real log even when the config leaves logging to syslog/ASL, and reads the mail queue and the Server.app /Library/Logs/Mail/ files. See the security reference.
Run it all from one Mac app.
FrontierStack installs, monitors and secures the whole stack — locally and across your fleet — from a single native macOS app.
Download FrontierStack