Probably should mention that binary needs to be setuid, if it is to be called by non-root users. If it'll only ever be called by root, and/or by the user who owns the mailboxes where mail is delivered - there's no need for this.