How Neruna works
Neruna connects to the mail server – same name as the IMAP server, port 4190 –, logs in with the same credentials and writes the out-of-office reply as a Sieve rule. Your own filters stay: Neruna only adds a marked section to your active script. If there is none yet, Neruna creates the script “neruna” and activates it.
Each sender gets at most one reply per day. No reply goes to your own addresses, to mailing lists or to automatic messages.
At the top right, Neruna shows which accounts support out-of-office replies. If a server can't be reached right now – say on the road, when port 4190 is only open in the office network –, the account stays listed with its last known state. Neruna checks again every hour.
What the server needs
ManageSieve on port 4190, under the same name as the IMAP server – and reachable from where Neruna runs (firewall, also outside the office).
STARTTLS with a valid certificate for that name. Without encryption, Neruna doesn't send the password.
Login with user name and password (SASL PLAIN) – with the same credentials as IMAP.
The Sieve extension vacation. For “from – to”, also date and relational – without them the reply can only be switched on and off by hand.
And most importantly: delivery must actually run Sieve (with Dovecot, the Sieve plugin in LMTP or LDA). Otherwise the server stores the rule, but no reply ever goes out.
Example: Dovecot
Packages on Debian/Ubuntu: dovecot-sieve and dovecot-managesieved. vacation, date and relational are enabled by default; STARTTLS uses the same SSL settings as IMAP. The examples are for Dovecot 2.3 (Debian 12, Ubuntu 24.04) – from 2.4 the syntax differs, the building blocks are the same. If you deliver with LDA instead of LMTP, add sieve in 15-lda.conf.
# /etc/dovecot/conf.d/20-managesieve.conf
protocols = $protocols sieve
service managesieve-login {
inet_listener sieve {
port = 4190
}
}
# /etc/dovecot/conf.d/20-lmtp.conf
protocol lmtp {
mail_plugins = $mail_plugins sieve
}
# /etc/dovecot/conf.d/90-sieve.conf
plugin {
sieve = file:~/sieve;active=~/.dovecot.sieve
}
Then restart Dovecot and open port 4190/TCP in the firewall. Complete mail server bundles usually include ManageSieve already – often only the open port is missing.
Testing
1. Reachable – and what can the server do? It lists its capabilities before login. What matters: vacation (for “from – to” also date relational) in the SIEVE line and STARTTLS. End with LOGOUT.
nc mail.example.com 4190
"IMPLEMENTATION" "Dovecot Pigeonhole"
"SIEVE" "fileinto reject envelope … vacation … date relational …"
"STARTTLS"
"VERSION" "1.0"
OK "Dovecot ready."
LOGOUT
On Windows (PowerShell), for reachability – expect TcpTestSucceeded : True:
Test-NetConnection mail.example.com -Port 4190
2. Check the certificate:
openssl s_client -connect mail.example.com:4190 -starttls sieve -servername mail.example.com </dev/null | grep "Verify return code"
Verify return code: 0 (ok)
3. Log in and list scripts, e.g. with the tool sieve-connect – it asks for the password:
sieve-connect -s mail.example.com -u anna@example.com --list
4. Real test: switch on out-of-office in Neruna and send a mail from another address – not from yourself. For a second try, use another sender or wait a day.
Messages in Neruna
- “ManageSieve (port 4190) … is not reachable”
- Port closed (firewall, only open in the office network), service not running, or the certificate doesn't match the server name. Tests 1 and 2.
- “Sieve without ‘vacation’”
- The
vacation extension is missing or disabled (with Dovecot sieve_extensions).
- “no encrypted connection (STARTTLS)”
- Set up TLS for ManageSieve – with Dovecot the same SSL settings as for IMAP.
- “no login with user name and password (PLAIN)”
- Allow PLAIN, with Dovecot
auth_mechanisms = plain login. The password travels over the encrypted connection.
- “Login for the out-of-office reply failed”
- The server doesn't accept the IMAP credentials for ManageSieve – e.g. a different user name or ManageSieve disabled for this account. Test 3.
- “… cannot limit … to a period”
date or relational is missing. Switch on without a period, or enable the extensions.
- “The server rejected the out-of-office reply: …”
- The server gives the reason – such as a full script quota or an extension in the existing script it doesn't know.
- Switched on, but no reply
- Delivery without Sieve (point 5 above), test sent from your own address, the same sender already got a reply today, or the mail came via a list.
- Account missing under “Out of office”
- Neruna has never reached the server, or it can't do out-of-office replies. Tests 1 to 3; restart Neruna after fixing.
Microsoft 365 and Outlook.com
Here Neruna sets the mailbox's automatic replies – no Sieve needed, with “from – to”. For that, Neruna needs permission to change mailbox settings. Older accounts ask for it once: Settings → Accounts → Edit → “Sign in to Microsoft again”. In companies, IT may need to approve the permission.
Microsoft 365: approving Neruna →