The build stage runs on the build platform and cross-compiles for the
target, so arm64 needs no emulation. The configuration check runs a
native build, since the target binary may not run on the builder.
Accepts mail for an allowlist of domains from allowlisted client networks
and discards it on receipt. No outbound code, no logging, scratch image;
all settings are Dockerfile build arguments compiled into the binary.