10 ms·
That's really interesting. I've been considering moving back to my own mail server from gmail for a long time but have been worried about the security issues.
by wonko1 10y ago
That's really interesting. I've been considering moving back to my own mail server from gmail for a long time but have been worried about the security issues.
This is one more thing pushing me in that direction.
- hippich 10y agoyou might be interested in https://github.com/sovereign/sovereign https://github.com/sovereign/sovereign
- reitanqild 10y agoThat seems to be a great repo, both as a starting point for self hosting and as a starting point for learning ansible!
- tlrobinson 10y agoInstalling 10 other services doesn't seem like a good way to run a secure mail server.
- floatboth 10y agoWell, that setup offers a personal "cloud", not just mail. And the focus is more on "independent" than "secure". I wouldn't worry too much about running many services. They all run as their own unprivileged users. (Of course chroots or even jails/containers would be better.)
- chrismartin 10y agoI've been hosting my personal email on a $5/month DigitalOcean server, running Postfix + Dovecot, for almost two years. I think it's reasonably secure. I run updates regularly and trust the distro maintainers to release timely fixes for new vulns. Aside from that, I mostly ignore it because it works. I should probably look at the logs, but eh. After the typical host hardening stuff (which isn't much work with modern OS defaults), I have configured SPF, DKIM, DMARC policy, opportunistic TLS for server-to-server, and mandatory TLS for IMAP client connections. From a data privacy perspective, I know that nobody is mining the contents of my mailbox (except the messages I send to Gmail, etc. users!), and my server is not a high-value target for compromise. (Yes, DigitalOcean could snoop on my non-GPG-encrypted messages if they wanted. I guess I could migrate the server back to my own hardware.) I also encourage friends to use GPG, though this is orthogonal to one's choice of email host. For clients I use Thunderbird on desktop and K-9 Mail on Android. Mobile push via IMAP IDLE works out of the box. (I also run a CalDAV/CardDAV server to sync contacts/calendar/todo across devices, but that is technically separate.) Overall I'm really happy with the arrangement. The only annoyance was having my messages to Gmail users consistently marked as spam, but after doing everything suggested by mail-tester.com, I think I'm making it through most of the time.
- Karlozkiller 10y agoThank you for that post. I've been trying some time ago, mostly for fun, to set up an email server. I did get one up and running with a setup similar to what you describe but was spam-filtered by Gmail as you describe. And because of this I kind of gave up. But now I might try it again some time.
- pja 10y agoYou can expect a fresh IP from one of the cloud hosting services to be spam filtered out of the box by Google et al these days. If you’re lucky, the IP in question hasn’t previously been used to spam & by very slowly ramping up your email rate Google will eventually decide that you’re probably OK. Getting this right appears to be something of a black art however :(
- j_s 10y agoA discussion from long ago about Gmail deliverability: https://news.ycombinator.com/item?id=9855030 https://news.ycombinator.com/item?id=9855030
- JupiterMoon 10y agoWhat CalDAV/CardDAV server do you run?
- mike-cardwell 10y agoNot the parent, but I use Nextcloud for this (previously ownCloud). There are carddav and caldav sync applications for Android. I assume other operating systems have them too. https://nextcloud.com https://nextcloud.com
- foepys 10y agoI can recommend radicale [1]. It's very simple and doesn't need a lot of resources. It also supports authentication via an IMAP server so you don't have to keep a separate user database. 1: http://radicale.org/ http://radicale.org/
- a3n 10y agoI run dovecot on my laptop, for a few years now, for local email storage. I usually move my messages down from fastmail once or twice a year. I just recently set it up to use TLS on port 993. It was easy to do.
- hannob 10y agoI run my own mail server, I can tell you this: Buffer overflows and format string vulns in your imap implementation will be the least of your worries. It is certainly still valuable work to audit the software used for the mailserver. But the challenges lie elsewhere. The biggest chunks are configuration issues and - if you have users that aren't very security savvy - stolen passwords and subsequent abuse of mail accounts for spam.
- noinsight 10y ago> configuration issues This is where having a mail server with a sane configuration file comes handy. OpenSMTPd is simply awesome in that regard. Plus, it too was recently audited and vulnerabilities fixed so it should be secure. OpenSMTPd + Dovecot makes for an awesome combination for a mail server.