Dovecot Fails to Start With an Error in 95-iworx-sni-hosts.conf

How the Issue Manifests

Dovecot is stopped and cannot be restarted.

Checking the status of the Dovecot service shows an error referencing /etc/dovecot/conf.d/95-iworx-sni-hosts.conf, like the following:

[root@server ~]# systemctl status dovecot
× dovecot.service - Dovecot IMAP/POP3 email server
Loaded: loaded (/usr/lib/systemd/system/dovecot.service; enabled; preset: disabled)
Active: failed (Result: exit-code) since Thu 2026-07-02 15:16:49 UTC; 12min ago
Docs: man:dovecot(1)
https://doc.dovecot.org/
Main PID: 160453 (code=exited, status=89)
CPU: 73ms

Jul 02 15:16:49 server systemd[1]: Starting Dovecot IMAP/POP3 email server...
Jul 02 15:16:49 server dovecot[160453]: doveconf: Fatal: Error in configuration file /etc/dovecot/conf.d/95-iworx-sni-hosts.conf line 23: ssl_cert: Can't >
Jul 02 15:16:49 server systemd[1]: dovecot.service: Main process exited, code=exited, status=89/n/a
Jul 02 15:16:49 server systemd[1]: dovecot.service: Failed with result 'exit-code'.
Jul 02 15:16:49 server systemd[1]: Failed to start Dovecot IMAP/POP3 email server.

Common Cause of the Issue

/etc/dovecot/conf.d/95-iworx-sni-hosts.conf is missing SSL information for some domains on the server.

Troubleshooting

Check the SNI Hosts File for Incomplete Entries

  1. Log in to the server at the CLI as root, either via SSH or from the terminal

  2. With a text editor, open /etc/dovecot/conf.d/95-iworx-sni-hosts.conf. The following example uses the Vim text editor:

    vim /etc/dovecot/conf.d/95-iworx-sni-hosts.conf
    
  3. Enable line numbers in the text editor. The following example is sets line numbers in Vim:

    :set nu
    
  4. Find the line number stated in the status error. In the following example, the domain block starting on line 17 is correct. The domain blocks starting on lines 22 and 27 are incorrect, and missing private key information:

    17 local_name ftp.domain.com {
    18 ssl_cert = </home/domainco/var/domain.com/ssl/domain.com.chain.pem
    19 ssl_key = </home/domainco/var/domain.com/ssl/domain.com.priv.key
    20 }
    21
    22 local_name example.com {
    23 ssl_cert = </home/examplec/var/example.com/ssl/example.com.chain.pem
    24 ssl_key = <
    25 }
    26
    27 local_name sub.example.com {
    28 ssl_cert = </home/examplec/var/example.com/ssl/example.com.chain.pem
    29 ssl_key = <
    30 }
    
  5. Note the domains with incomplete entries, and exit the text editor

How to Resolve

  1. Log in to the server at the CLI as root, either via SSH or from the terminal

  2. Run the following. This will check the SSL status for the domains on the server, and rewrite the corresponding information in /etc/dovecot/conf.d/95-iworx-sni-hosts.conf:

    nodeworx -u -n -c MailDovecot -a syncDovecotSniHosts
    
  3. Start Dovecot:

    systemctl start dovecot
    
  4. Confirm that the service is running:

    systemctl status dovecot
    

Other Considerations

  • If the sync completes but Dovecot still shows same error upon attempted restart, the most common cause is that the SSL certificate for the affected domain is corrupt or partially missing on disk. Reinstalling the certificate for that domain, and then re-running the sync command generally resolves the issue. Information on how to manage domain-level SSL certificates can be found here.