Table of Contents
- Background
- Gentlemen, Start Your Migrations
- Some Configs Are More Idiosyncratic than Others
- You (Probably) Can’t Get There From Here
- One Final Hurdle
Background
I’ve run a Debian VSP on Hostwinds.com1 for years now. I use it to host a number of (infrequently updated) blogs and, recently, a few Blazor server apps2. It also serves as a learning platform when I feel like spending time with Linux. While it handles very little traffic, it also provides email services for a number of my blogs.
A couple of years ago, while doing a Debian upgrade/update I totally hosed it. How? Well, by doing something immensely stupid: interrupting the update, which had stalled on trying to install a particular package3

I would never, ever have even thought of doing something so dumb on Windows, where I spend most of my time. But I’d been so impressed over the years about just how solid Debian is that I just assumed the update engine was just another interruptible app. Wrong!
Gentlemen, Start Your Migrations!
Fixing the resulting mess involved some very high-level tech support from Hostwinds. Fortunately, I always do what they call snapshots (backups) before doing any major system update, so they had something to work with.
What I didn’t know at that time was that the fix permanently tied my VSP to that particular snapshot, which couldn’t be deleted. I learned that when I tried to clean up some old snapshots, found I couldn’t get rid of that one, and contacted tech support. The only solution was to migrate everything to a new VSP.
Migrations are something Hostwinds will do for you, with one important caveat: they’ll install the apps that were on your old machine, but won’t configure what I call the idiosyncratic ones, like sshd. And like postfix and dovecot, which formed the basis of my email servers.
Getting most of my idiosyncratic apps reconfigured was pretty straightforward and went quickly, aided in no small way by Google Gemini Pro4. So much so that I figured I’d get everything wrapped up in another day or so of part-time work.
Little did I know.

Some Configs Are More Idiosyncratic than Others
I ended up spending about a week getting postfix and dovecot squared away. Why’d they take so long? Well, for two reasons.
First, between the last time I’d updated dovecot on my old VSP and now, dovecot had undergone some major breaking changes in how its configuration was defined. That change confused Gemini Pro (and later ChatGPT, when I decided to try throwing another AI at the mess) a lot. My prompts always included the OS I was running (Debian Trixie) and the dovecot version (2.4)…but Gemini Pro routinely forgot the dovecot version, and created directions using the obsolete configuration syntax. ChatGPT forgot, too, but not quite as often.
Which wouldn’t have been that big of an issue if the AI’s didn’t always issue their instructions in a tone-of-voice which implied they were absolutely certain of what they were talking about. It was not uncommon for my AI dialog to go something like this:
- AI: Those log entries clearly identify the problem. Do this to fix it.
- Me: Okay, will do. Wait, that didn’t work. Here’s some more logs.
- AI: Hmmm, run this test.
- Me: Okay, here are the results.
- AI: Ah! That change you just made was incorrect.
- Me: WTF?!? You told me to make that change!
- AI: Apologies. I forgot you’re using dovecot 2.4.
Observation #1 about current AIs: they are cocksure, far and away beyond their actual level of expertise.
Overall, I would say ChatGPT is better at system configuration tasks than Gemini Pro. It not only seems more knowledgeable, but the UI is better suited to viewing and reacting to code snippets.

You (Probably) Can’t Get There From Here
But the bigger culprit was simply that I was trying to do something with postfix and dovecot which, while clearly possible — my old VSP had run the way I wanted for years — was just a little past what the people who write and maintain postfix and dovecot expected you to want to do.
You see, I wanted my email server to support four different domains (and maybe more in the future) using IMAP. The IMAP requirement is what drove me to dovecot…but the multiple domains means I had to set things up for postfix and dovecot to handle virtual domains (and users).
What’s a virtual domain? Any domain that isn’t the “main” domain for the server. That’s considered the system domain, and its users are plain old system users.
When I set up postfix and dovecot years ago, for some reason I decided to make one of the four email domains the system domain. I didn’t have to do that — they could all have been virtual domains so far as postfix and dovecot were concerned. I think the reason I made the choice was because I had started hosting podcasts with a buddy of mine, and I wanted to give him a user account on the system, so I thought the email server should naturally support both system and virtual users5.
That seemingly minor choice had profound consequences. To put it simply, while it is (supposed to be) possible for postfix/dovecot to handle both system and virtual users6, that’s not a scenario that it was intended to address.
It took about four days of AI chats and tweaking to come to that conclusion.
Actually, it was ChatGPT which came to that conclusion. I just decided to accept its advice. Once I did, things came together very quickly.

One Final Hurdle
There was one last configuration struggle which had nothing to do with postfix or dovecot.
On my old server I ran into problems with emails coming from it being treated as spam by various recipients. One of the things I did to address this was to install and run OpenDKIM on the server. This requires adding the public key of a public/private key pair to each email domain’s DNS table. This should simply involve adding a specially formatted TXT record.
Unfortunately, the size of the base64 encoded public key exceeds the maximum allowed size of a TXT record’s value (which is 255 characters).
To support very long TXT values, there’s some behind the scenes magic that DNS table editors do. I’m not exactly sure what’s involved7, but, however it’s done, it’s extremely persnickety about the format of the string you paste into the text box in the DNS table editor. In fact, there are numerous websites which offer customized formatting capabilities to ensure your raw public key complies with the requirements for pasting it.
Unfortunately, this is one of the very few areas where the Hostwinds website falls flat on its face. I tried quite a few ways to format and paste the public key into the TXT entry. Every attempt failed…and, worse yet, failed after apparently succeeding (i.e., the UI appeared to accept the value, but returning to the DNS table editor later showed that it had been rejected).
The solution was to send the public keys to Hostwinds tech support and have them insert them. Which they promptly did, solving the problem.
I can’t tell you how gratifying it was to send and receive emails without any errors cropping up!
great company, IMHO; generally responsive and almost always willing to spend time educating me in addition to solving problems ↩
I find it really cool to run Microsoft stuff on Debian…and it’s fast, even on my little setup ↩
I really like Debian, but I will say its package management can be a little flaky. Several times a package update will pause because it is looking for user input…which is, of course, impossible to provide in an apt/aptitude-based update cycle. BTW, the correct solution is not to interrupt the update, but to interrupt the particular program that is paused waiting for input. In all the times I’ve encountered this annoying glitch that solves the problem. But it does require digging into the running processes to figure out who’s the culprit. ↩
I got access to Gemini Pro as a “freebie” when I upgraded my Google Drive account — I use it mostly to archive media files — to 5 terabytes, simply so I’d stop getting messages every time I logged into Windows that You’re Running Out of Space And Horrible Things Will Happen To You If You Do. ↩
The funny thing is my co-host is very bright but has little or no interest in using computers in a bare metal kind of way, so I didn’t need to give him a system user account. ↩
I know it’s possible, I’d somehow been doing it for years! ↩
I think it involves storing the long record as multiple quoted shorter records. ↩