Unified PowerMTA + MailWizz Single-Node Infrastructure Engineer (ISP-grade block)
Budget: ₹12,500 – ₹37,500 INR
We are bypassing slow corporate agency partners to hire an independent, professional-grade MTA DevOps / Deliverability Engineer to own the production-ready bare-metal/VDS deployment, enterprise software licensing procurement, core installation, and advanced telemetry integration for our foundational seed node (VDS-Node-01).
This is an all-in-one, unified single-node deployment model. You will build and stabilize the entire execution stack on an isolated VDS instance backed by an Intel Xeon Platinum core array (4 vCores, 8 GB RAM, 80 GB NVMe Storage) running a minimal server image of Ubuntu 22.04 LTS provided via our network partner, Hostarox.
Explicit Scope of Work (SOW) & Key Deliverables:
1. Software Procurement, Licensing & Unified Installation
MailWizz EMA Build: Clean directory installation, database setup, and license activation of MailWizz EMA directly onto VDS-Node-01. This instance will serve as our unified control center, campaign database, and submission hub.
PowerMTA Enterprise Setup: Secure, provision, and activate a legitimate, official enterprise-grade PowerMTA license key bound natively to our host node environment.
2. OS Hardening & Kernel Tuning
Optimize the underlying Linux network stack to protect the transmission loop from latency spikes and packet jitter across ISP backbones.
Configure the host system to run kernel-level BBR Congestion Control, optimizing file descriptors and TCP buffer allocations (/etc/sysctl.conf).
Execute hardware-level Processor Affinity Pinning: Enforce strict scheduling parameters within the Linux kernel to pin local database and web worker processing threads to CPU Cores 0-1, leaving CPU Cores 2-3 entirely dedicated to PowerMTA's high-volume SMTP transmission threads.
3. Network Binding & VirtualMTA Hardening
Configure the network perimeter across 5x separate, dedicated static IPv4 addresses originating from our authorized ISP-grade block (with delegated rDNS panel access via our partner, Hostarox).
Map the master /etc/pmta/config using a strict Hard-Binding Model. Dynamic IP pool rotation or random fallback pools are completely disabled.
Hard-link each VirtualMTA path to its designated static ISP IP, ensuring hostnames and HELO strings match our white-label layout (s1.hostarox.com through s5.hostarox.com).
4. Local Loopback Integration & Custom Telemetry Stamp
Connect MailWizz directly to PowerMTA on localhost (127.0.0.1) over internal port 25/2525, utilizing an explicit IP-whitelist block to bypass SMTP authentication latency.
Configure MailWizz to inject a mandatory custom header string into every outbound MIME payload:
X-Sender-MTA: tenant_[TENANT_ID]_pool
Configure PowerMTA to read this header on the fly via translation macros, mapping the traffic instantly to the corresponding isolated client pool container.
5. Real-Time JSON Telemetry Shipping Pipe
Deploy an active log transport agent (Filebeat/Fluentd configuration with a local memory buffer) to monitor the active PowerMTA accounting log (/var/log/pmta/acct.csv) in real time.
Map the data shipper to parse all successful deliveries, hard bounces, and transient rate limits (250, 421, 451, 550), converting them to lightweight JSON payloads streamed securely back to our live webhook database ingestion hook
6. CNAME-Based Sender Authentication (Compliance Standard)
In alignment with our NIST CSF 2.0 / ISO 27001 compliance standards, we do not hold customer registrar credentials.
Implement a pure CNAME-Based Delegation Architecture. Build standard DNS zone templates so onboarding customer domains seamlessly map back to our centrally managed server zone records for SPF, DKIM, and DMARC alignments via custom CNAME paths.
Contractor Vetting Questions (Mandatory Responses Required):
To filter out automated spam bids, you must answer these three technical questions explicitly in your proposal:
1. Confirm that you have the explicit capability to handle procurement, clean environment installation, and enterprise licensing for BOTH MailWizz EMA and PowerMTA on an isolated Ubuntu 22.04 LTS environment.
2. Explain your exact method for configuring MailWizz to inject custom X-Sender-MTA tracking headers and routing them to distinct PowerMTA VirtualMTA static containers on localhost without causing submission queue blocks.
3. Detail your specific architectural experience in setting up Filebeat or Fluentd log patterns to capture and stream real-time PowerMTA CSV status events to an external HTTPS REST API webhook.
This is an all-in-one, unified single-node deployment model. You will build and stabilize the entire execution stack on an isolated VDS instance backed by an Intel Xeon Platinum core array (4 vCores, 8 GB RAM, 80 GB NVMe Storage) running a minimal server image of Ubuntu 22.04 LTS provided via our network partner, Hostarox.
Explicit Scope of Work (SOW) & Key Deliverables:
1. Software Procurement, Licensing & Unified Installation
MailWizz EMA Build: Clean directory installation, database setup, and license activation of MailWizz EMA directly onto VDS-Node-01. This instance will serve as our unified control center, campaign database, and submission hub.
PowerMTA Enterprise Setup: Secure, provision, and activate a legitimate, official enterprise-grade PowerMTA license key bound natively to our host node environment.
2. OS Hardening & Kernel Tuning
Optimize the underlying Linux network stack to protect the transmission loop from latency spikes and packet jitter across ISP backbones.
Configure the host system to run kernel-level BBR Congestion Control, optimizing file descriptors and TCP buffer allocations (/etc/sysctl.conf).
Execute hardware-level Processor Affinity Pinning: Enforce strict scheduling parameters within the Linux kernel to pin local database and web worker processing threads to CPU Cores 0-1, leaving CPU Cores 2-3 entirely dedicated to PowerMTA's high-volume SMTP transmission threads.
3. Network Binding & VirtualMTA Hardening
Configure the network perimeter across 5x separate, dedicated static IPv4 addresses originating from our authorized ISP-grade block (with delegated rDNS panel access via our partner, Hostarox).
Map the master /etc/pmta/config using a strict Hard-Binding Model. Dynamic IP pool rotation or random fallback pools are completely disabled.
Hard-link each VirtualMTA path to its designated static ISP IP, ensuring hostnames and HELO strings match our white-label layout (s1.hostarox.com through s5.hostarox.com).
4. Local Loopback Integration & Custom Telemetry Stamp
Connect MailWizz directly to PowerMTA on localhost (127.0.0.1) over internal port 25/2525, utilizing an explicit IP-whitelist block to bypass SMTP authentication latency.
Configure MailWizz to inject a mandatory custom header string into every outbound MIME payload:
X-Sender-MTA: tenant_[TENANT_ID]_pool
Configure PowerMTA to read this header on the fly via translation macros, mapping the traffic instantly to the corresponding isolated client pool container.
5. Real-Time JSON Telemetry Shipping Pipe
Deploy an active log transport agent (Filebeat/Fluentd configuration with a local memory buffer) to monitor the active PowerMTA accounting log (/var/log/pmta/acct.csv) in real time.
Map the data shipper to parse all successful deliveries, hard bounces, and transient rate limits (250, 421, 451, 550), converting them to lightweight JSON payloads streamed securely back to our live webhook database ingestion hook
6. CNAME-Based Sender Authentication (Compliance Standard)
In alignment with our NIST CSF 2.0 / ISO 27001 compliance standards, we do not hold customer registrar credentials.
Implement a pure CNAME-Based Delegation Architecture. Build standard DNS zone templates so onboarding customer domains seamlessly map back to our centrally managed server zone records for SPF, DKIM, and DMARC alignments via custom CNAME paths.
Contractor Vetting Questions (Mandatory Responses Required):
To filter out automated spam bids, you must answer these three technical questions explicitly in your proposal:
1. Confirm that you have the explicit capability to handle procurement, clean environment installation, and enterprise licensing for BOTH MailWizz EMA and PowerMTA on an isolated Ubuntu 22.04 LTS environment.
2. Explain your exact method for configuring MailWizz to inject custom X-Sender-MTA tracking headers and routing them to distinct PowerMTA VirtualMTA static containers on localhost without causing submission queue blocks.
3. Detail your specific architectural experience in setting up Filebeat or Fluentd log patterns to capture and stream real-time PowerMTA CSV status events to an external HTTPS REST API webhook.
Related categories:
System Admin
Linux
Web Security
Ubuntu
Email Handling
Mailwizz
Documentation
DevOps
Network Security
Performance Tuning