Hub
Email

Dovecot IMAP / POP3 Login

Dovecot 2.3.20 IMAP and POP3 login-process messages from the mail clients of 275 mailboxes, webmail users and internet noise, as native-style syslog lines in event.original inside ECS JSON. About 23,600 logins a day on a UTC hour-of-day curve. Models login outcomes, not IMAP commands or mail reads. Recurring episodes show four IMAP failures of one mailbox from one public address, then an IMAP login and a POP3 login for the same mailbox and address.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/email-dovecot-imap/generator.yml \
  --id dovecot-imap \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
imap-login: LoginSuccessful IMAP login83.4% share over four daysauthentication, start
pop3-login: LoginSuccessful POP3 login10.7% share over four daysauthentication, start
imap-login: Disconnected (auth failed)Connection closed after failed IMAP authentication5.9% share over four daysauthentication, denied

Realism Features

  • 250 personal and 25 shared mailboxes use office workstations, laptops and phones, each client reconnecting on its own schedule every few minutes to about an hour. Laptops connect from the office, the VPN or one of two home public addresses; phones use a few carrier NAT addresses shared with other subscribers and usually return to each within a day. Some phones use POP3, and some workstations and laptops poll an IMAP and a POP3 account together, so an IMAP login is followed by a POP3 login from the same address within seconds to minutes. Which mailbox uses which clients and addresses is fixed per mail_domain; all activity on top of that differs in every run.
  • About 23,600 logins a day (±3% from day to day) at random times, following a UTC hour-of-day curve: a round-the-clock floor plus a working-day curve peaking at 12:00-13:00, from 0.13-0.15 logins/s at night to 0.51-0.52 logins/s at 11:00-14:00 UTC. Internet scanning is flat around the clock. About 30% of POP3 logins and about 40% of all logins come from public addresses. Rates are synthetic workload settings, not measured Dovecot rates.
  • Rejected logins come from mistyped passwords (one to five failures before a success, more often at the first start after a night), transient rejections, IMAP clients failing with backoff after a password change until updated, new clients and webmail users, plus internet noise: single guesses, password sprays over real and non-existent mailboxes, and brute-force runs from recurring hostile hosts, one-off hosts or phone carrier ranges. About a third of failures come from hostile hosts. Retries follow a failure after a median 15 seconds in working hours and 21 seconds at night.
  • Every chain part also occurs in ordinary traffic of both modes: four failures followed by an IMAP success within 15 minutes about 35 times a day, failure, IMAP success and POP3 success from one mailbox and address about 12 a day, three failures then IMAP and POP3 success about 3 a day, and IMAP-then-POP3 pairs within 10 minutes about 900 a day. Each episode adds about one to each of these counts. Only the full order within 15 minutes of the first failure separates the modes, and the login records do not prove mailbox access or data extraction.
  • Field order and comma joining follow the Dovecot 2.3 settings and first-hand 2.3.20 IMAP captures. Failures carry no mpid, and TLS does not distinguish implicit TLS from STARTTLS, so no destination.port is emitted. The 16-character session ID is a selected profile, and failure durations are modeled on the default auth_failure_delay.
  • No complete 2.3.20 raw capture was found for a TLS failure with the modeled durations or for a POP3 success, so their byte-for-byte fidelity is unconfirmed. Failures are IMAP only; timestamps have one-second resolution and several records can share one second; the hour curve repeats daily with no weekly cycle; the UTC syslog envelope is deployment-specific. IMAP commands, POP3 retrievals, mailbox changes, logouts, LMTP delivery and auth-worker diagnostics are not generated.

Sample Output

{
  "@timestamp": "2026-09-01T12:48:04+00:00",
  "destination": {
    "ip": "10.20.0.20"
  },
  "dovecot": {
    "auth_attempts": 1,
    "auth_duration_seconds": 2,
    "disconnect_reason": "Connection closed",
    "login_result": "failure",
    "method": "PLAIN",
    "protocol": "imap",
    "session": "Clr8Vo8JzJzoZUBv",
    "tls": true
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "login-failure",
    "category": [
      "authentication"
    ],
    "kind": "event",
    "original": "Sep  1 12:48:04 mail01.corp.example dovecot: imap-login: Disconnected: Connection closed (auth failed, 1 attempts in 2 secs): user=\u003cmateo.wojcik@corp.example\u003e, method=PLAIN, rip=198.51.100.44, lip=10.20.0.20, TLS, session=\u003cClr8Vo8JzJzoZUBv\u003e",
    "outcome": "failure",
    "type": [
      "denied"
    ]
  },
  "host": {
    "ip": [
      "10.20.0.20"
    ],
    "name": "mail01.corp.example"
  },
  "related": {
    "ip": [
      "198.51.100.44",
      "10.20.0.20"
    ],
    "user": [
      "mateo.wojcik@corp.example"
    ]
  },
  "service": {
    "name": "dovecot",
    "type": "imap"
  },
  "source": {
    "ip": "198.51.100.44"
  },
  "user": {
    "name": "mateo.wojcik@corp.example"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd the recurring anomaly episodes to the background
anomaly_interval_hours24Hours from one episode start to the next due time, 3 to 8,760
host_namemail01.corp.exampleHostname in the syslog envelope
local_ip10.20.0.20Dovecot listener IP (`lip`)
webmail_ip10.20.0.30Client IP of the webmail server
mail_domaincorp.exampleDomain of all mailbox names

Related Generators