7 ms·
I've been running my own MTA for about 15 years now, so it's definitely possible without spending the majority of one's waking hours to do so. Even when I swit
by TheMog 10y ago
I've been running my own MTA for about 15 years now, so it's definitely possible without spending the majority of one's waking hours to do so.
Even when I switched mail server IPs twice over the last few years I didn't run into the issues you ran into. A large part of it depends on where you run it - if you, say, run it on your home Internet connection that's usually an immediate strike against you because of the insane number of spammers using backdoor'd PCs to do exactly that.
The only time I ran an MTA out of my home was when I was on a commercial ISP with a fixed IP address, that seemed to be good enough for most services including gmail and hotmail.
These days I run my MTA on a VPS with a reputable hosting provider and don't seem to have that many issues with outgoing mails marked as spam.
SPF and DKIM are pretty much a must these days, so that's a good starting point, as are the rest of the precautions you already too. I assume you're using your own domain, how "old" is that domain? That might also have an impact giving how many phishers and spammers register odd domains and use them for a short amount of time. I've used the same domain since about 1999 so that could make a difference.
I use postfix instead of qmail, but I've used qmail in the past. Both work well and are easier to configure than sendmail or exim IMHO. On top of that I do run amavisd/spamassassin/clamav for the incoming emails as well.
One more thing I've got set up that I didn't see in your list is that I've got TLS set up with a non-self signed certificate for both incoming and outgoing email. I suspect that this also makes a difference even if the other email server won't request a client certificate (most, if not all, won't). Certainly shows up when I send an email over to gmail.
My biggest issues these days are more with incoming email:
- You'll never get to the level of spam filtering that, say, gmail offers. To me, that's OK
- I use greylisting to weed out a lot of the spam that would normally make it through spamassassin, but unfortunately that's when you find out how many people have misconfigured servers that bounce emails when they encounter temporary failures
- lucb1e 10y ago> if you, say, run it on your home Internet connection that's usually an immediate strike against you While true, some IP addresses were not previously used, either by home connections or by anyone, so you may be in luck there. There seems to be a correlation with my latest IP switch (three years ago or so) and less mail server trouble. Most services are also smart enough to learn to trust IP addresses after a little while. Even when SPF and DKIM is ignored, this usually solves it in a few emails.
- TheMog 10y agoBeing able to use a previously unused IP address is usually a good thing, pity that there are so few of those left. ISPs definitely seem to have an impact as well, but some spamfilters at least used to automatically assign a negative score to anything originating from an IP block used by an ISP for domestic Internet connections.
- lucb1e 10y agoWell, there's plenty of IPv6 around. My ISP gives out /48 blocks to all customers together with a single, static v4 address. The difference in number of public addresses is incredible.
- TheMog 10y agoGood point, although that's a different rant after I found out that my ISP has an IPV6 enabled backbone but won't allegedly roll out IPV6 to their clients until late this year.
- syshum 10y agoSome ISP turn over their Residential IP Blocks to Blacklist providers to add automatically to the blacklists. ISP state in their TOS you are not to run "servers" from your home connection, as such they simply blacklist all Residential IP;s from the start, because if you are running a email server on a Residential Connection it is either a Botnet, or you are violating the TOS of your plan.
- lucb1e 10y ago> ISP state in their TOS you are not to run "servers" from your home connection I don't know what evil ISP that is but running your own server is 1) encouraged by my ISP since forever (XS4ALL, the Netherlands) and 2) these days it's illegal to tell people not to run servers because of net neutrality laws.
- 10y ago
- dsr_ 10y agoI've been running my own mail server off of a residential connection since 1998, so... 18 years. I do pay for a static IP, and I switched ISPs away from Comcast (who had inherited me as a customer) when they abruptly started to filter inbound port 25 and claimed I had a malware infestation. For years it was qmail, but when I wanted to use SMTP/SSL as much as possible, switching to Postfix was easier than maintaining all the qmail patches. I switched over to Let's Encrypt certs several months ago, and those have been working out quite well for me.
- loup-vaillant 10y ago> when they abruptly started to filter inbound port 25 Didn't you mean "outbound"?
- dsr_ 10y agoNo, I didn't.
- loup-vaillant 10y agoI don't understand. Many providers block the outbound 25 port because of their distrust of the infected computers of their end losers. What could possibly be their rationale for blocking the inbound 25 port?
- angry_octet 10y agoA lot of ISPs say you are not allowed to run 'servers' on your home internet, and hence block inbound low ports like SMTP, IMAP, http. It's just extortion.
- zaxomi 10y agoIncompetence. At least that was the reason why my ISP at the time blocked both outbound and inbound port 25. It took a couple of weeks to convince them that they where wrong and open for inbound again.
- 10y ago
- andrewaylett 10y agoYou are me, almost. I run a small amount of mail out of an OVH box with few issues; before that I hosted from my house on a static IP address. I don't actually greylist any more, though -- I've found that postfix's protocol violation detection (postscreen[0]) is just as good, if not better, and I like my mail to come through immediately :). Amavis is set up to do pre-queue filtering, which means that mail is either rejected or delivered (possibly to the spam folder), my server shouldn't be generating its own bounces or dropping messages on the floor. [0]: http://www.postfix.org/POSTSCREEN_README.html http://www.postfix.org/POSTSCREEN_README.html
- Biganon 10y agoOVH boxes aren't blacklisted everywhere?