Dovecot IMAP / POP3 Login
Dovecot 2.3.20 IMAP and POP3 login-process messages from the mail clients of 275 mailboxes, webmail users and internet noise, as native-style syslog lines in event.original inside ECS JSON. About 23,600 logins a day on a UTC hour-of-day curve. Models login outcomes, not IMAP commands or mail reads. Recurring episodes show four IMAP failures of one mailbox from one public address, then an IMAP login and a POP3 login for the same mailbox and address.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/email-dovecot-imap/generator.yml \
--id dovecot-imap \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| imap-login: Login | Successful IMAP login | 83.4% share over four days | authentication, start |
| pop3-login: Login | Successful POP3 login | 10.7% share over four days | authentication, start |
| imap-login: Disconnected (auth failed) | Connection closed after failed IMAP authentication | 5.9% share over four days | authentication, denied |
Realism Features
- 250 personal and 25 shared mailboxes use office workstations, laptops and phones, each client reconnecting on its own schedule every few minutes to about an hour. Laptops connect from the office, the VPN or one of two home public addresses; phones use a few carrier NAT addresses shared with other subscribers and usually return to each within a day. Some phones use POP3, and some workstations and laptops poll an IMAP and a POP3 account together, so an IMAP login is followed by a POP3 login from the same address within seconds to minutes. Which mailbox uses which clients and addresses is fixed per mail_domain; all activity on top of that differs in every run.
- About 23,600 logins a day (±3% from day to day) at random times, following a UTC hour-of-day curve: a round-the-clock floor plus a working-day curve peaking at 12:00-13:00, from 0.13-0.15 logins/s at night to 0.51-0.52 logins/s at 11:00-14:00 UTC. Internet scanning is flat around the clock. About 30% of POP3 logins and about 40% of all logins come from public addresses. Rates are synthetic workload settings, not measured Dovecot rates.
- Rejected logins come from mistyped passwords (one to five failures before a success, more often at the first start after a night), transient rejections, IMAP clients failing with backoff after a password change until updated, new clients and webmail users, plus internet noise: single guesses, password sprays over real and non-existent mailboxes, and brute-force runs from recurring hostile hosts, one-off hosts or phone carrier ranges. About a third of failures come from hostile hosts. Retries follow a failure after a median 15 seconds in working hours and 21 seconds at night.
- Every chain part also occurs in ordinary traffic of both modes: four failures followed by an IMAP success within 15 minutes about 35 times a day, failure, IMAP success and POP3 success from one mailbox and address about 12 a day, three failures then IMAP and POP3 success about 3 a day, and IMAP-then-POP3 pairs within 10 minutes about 900 a day. Each episode adds about one to each of these counts. Only the full order within 15 minutes of the first failure separates the modes, and the login records do not prove mailbox access or data extraction.
- Field order and comma joining follow the Dovecot 2.3 settings and first-hand 2.3.20 IMAP captures. Failures carry no mpid, and TLS does not distinguish implicit TLS from STARTTLS, so no destination.port is emitted. The 16-character session ID is a selected profile, and failure durations are modeled on the default auth_failure_delay.
- No complete 2.3.20 raw capture was found for a TLS failure with the modeled durations or for a POP3 success, so their byte-for-byte fidelity is unconfirmed. Failures are IMAP only; timestamps have one-second resolution and several records can share one second; the hour curve repeats daily with no weekly cycle; the UTC syslog envelope is deployment-specific. IMAP commands, POP3 retrievals, mailbox changes, logouts, LMTP delivery and auth-worker diagnostics are not generated.
Sample Output
{
"@timestamp": "2026-09-01T12:48:04+00:00",
"destination": {
"ip": "10.20.0.20"
},
"dovecot": {
"auth_attempts": 1,
"auth_duration_seconds": 2,
"disconnect_reason": "Connection closed",
"login_result": "failure",
"method": "PLAIN",
"protocol": "imap",
"session": "Clr8Vo8JzJzoZUBv",
"tls": true
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "login-failure",
"category": [
"authentication"
],
"kind": "event",
"original": "Sep 1 12:48:04 mail01.corp.example dovecot: imap-login: Disconnected: Connection closed (auth failed, 1 attempts in 2 secs): user=\u003cmateo.wojcik@corp.example\u003e, method=PLAIN, rip=198.51.100.44, lip=10.20.0.20, TLS, session=\u003cClr8Vo8JzJzoZUBv\u003e",
"outcome": "failure",
"type": [
"denied"
]
},
"host": {
"ip": [
"10.20.0.20"
],
"name": "mail01.corp.example"
},
"related": {
"ip": [
"198.51.100.44",
"10.20.0.20"
],
"user": [
"mateo.wojcik@corp.example"
]
},
"service": {
"name": "dovecot",
"type": "imap"
},
"source": {
"ip": "198.51.100.44"
},
"user": {
"name": "mateo.wojcik@corp.example"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the recurring anomaly episodes to the background |
| anomaly_interval_hours | 24 | Hours from one episode start to the next due time, 3 to 8,760 |
| host_name | mail01.corp.example | Hostname in the syslog envelope |
| local_ip | 10.20.0.20 | Dovecot listener IP (`lip`) |
| webmail_ip | 10.20.0.30 | Client IP of the webmail server |
| mail_domain | corp.example | Domain of all mailbox names |
Related Generators
Microsoft Exchange Message Tracking
Exchange Server 2019 message tracking — SMTP receive/send, mailbox delivery, transport routing, shadow redundancy, anti-spam filtering, distribution group expansion, and delivery failure DSNs.
Kaspersky Secure Mail Gateway
Kaspersky Secure Mail Gateway (KSMG) ScanLogic events — anti-virus, anti-spam, anti-phishing, content filtering, mail authentication (SPF/DKIM/DMARC), KATA integration, message backup, and scan failure events in ECS-compatible JSON.
Fortinet FortiMail
FortiMail email security gateway — mail statistics, SMTP protocol events, antispam verdict (clean/spam/phishing), antivirus scanning with quarantine actions, and system administration logs.