25 ms·
How to Run Your Own Mail Server (2017)
- herbst 9y agoUsually you are supposed to add a year to older articles :) Curious if you looked into other mail server options? I mean Postfix (not Postgres) easily handles the load of a single user, but it is still rather hard to configure and modify. I recently started to work with Haraka and even thought its ment for high traffic use cases i wont ever look back to Postfix (not Postgres).
- Torgo 9y agoOpenSMTPD is by far the easiest to configure, and has very secure default settings. It works very good for a single user server.
- j_s 9y agos/Postgres/Postfix/ ?? In any case you should ask the author, as they are currently active on another discussion where they linked their article in a comment: https://news.ycombinator.com/item?id=16238501#16238845 https://news.ycombinator.com/item?id=16238501#16238845 >perlgod: I've spent years tweaking my mail server setup (Postfix, Dovecot, RSPAMD, LDAP...) and did a full writeup a few months ago. I've used other guides online but found most of the rest lacking on details
- herbst 9y agoOh ha, i figured it must be you i just saw the comment before. And yes, damn it. Fixed
- jacobush 9y agoWow. I must have really been abused (likely) by other mail servers to consider Postfix easy then.
- bstamour 9y agoMe too. Sendmail and his friends did unspeakable things to me.
- herbst 9y agoGiven my first real Postfix experience was a scaleable forwarding service that is supposed to support a variation of configs without breaking the config file. Postfix is super easy, and well documented for normal use cases.
- peterburkimsher 9y agoI'd like to run a mail server on a jailbroken iPhone. The use case is to transfer arbitrary files over a local hotspot. I tried installing from the Apple TV tutorial, but it put my iPhone in a boot loop. http://ios-webstack.tk/imap http://ios-webstack.tk/imap Just a chance, but are there any iOS jailbreakers here who could advise?
- JepZ 9y agoWhat do you mean with 'mail server'? Postfix? Dovecot? Running a Postfix on anything else than a dedicated server with a static IP is a pretty bad idea (half the internet will reject the emails you send). And to do all that just to transfer some files is probably like using an iPhone as a fly swatter.
- peterburkimsher 9y agoI don't know why there's so many downvotes and patronising "fly swatter" remarks. There is a use case for this. For example, sharing a photo album with many pictures. Or a mixtape. Or some song lyrics. I can't upload those to the cloud for copyright reasons. Or if I want to make the transfer while away from Internet e.g. skiing, hiking, waterfall trip, etc. - there's no access to Internet services, so iCloud/Dropbox/Google Drive just won't do. I can use lighttpd to serve the folder, but then the user has to hold down and "Save to Camera Roll" for each picture separately. If both phones have Airdrop, then that's fine. But many phones are not iPhones. We could both install a special app for Bluetooth transfers, but we don't have Internet access, remember? So no app store. There's a Mail client on every phone, however locked-down it is. If I can serve a collection of files over a local network and send those directly, not one at a time, then that would be very useful to me. I think a mail server is one solution. If you can propose another flyswatter that meets my requirements, go ahead. Otherwise I still want to find a way to code a mail server, and the parent article is helpful for that.
- JepZ 9y agoHave you considered using Nextcloud?
- Torgo 9y agoI started running my own email server around 2014. I am using every mitigation I can find, but I still get an unending torrent of spam that slips through. If tweaking spam filters and deleting spam is your idea of fun, then run your own email server.
- dmm 9y agoFWIW, I've run my own mail server for 10 years and I hardly ever receive spam, maybe 1-2 a week. And I give out my email everywhere. The only spam mitigation I use is greylisting and blacklisting.
- viperscape 9y agoWhat do you use for the mail server? Do you do any sort of backups or failover? Just curious
- dmm 9y agoI run exim on Debian stable. I use greylistd for greylisting and dovecot for imap. I backup emails daily by taking a btrfs snapshot and rsyncing it to my home server, which I have a regular backup cycle for. If you were really worried you could setup exim to forward every email to a backup server. Failover is manual. I would create a new vm, install debian stable and run a script I've prepared a script that installs packages, copies config files and creates users. Downtime with email is not a big deal, servers will retrying sending for a few days. If you have users complaining to you it's obviously a bigger deal.
- twothamendment 9y agoI've been running since 2001. There were some rough years in there with spam and big providers rejecting for no good reason. Now it has been years since I've had any delivery issues. As for spam, I get 2-3 a week that make it through, but I don't make any effort to tweak it. Thanks for bringing up the painful memories of adding new filters each night. So glad those days are over for me.
- marsrover 9y agoI ran my own mail server for a few months in 2013. I came to the conclusion I'd much rather pay Google $5 a month.
- xienze 9y agoFastmail will let you do it for $50 per year if you pay upfront. Just not sure why anyone would run an email server other than extreme paranoia. It’s hardly a set it and forget it affair.
- stewie241 9y agoJust have somebody else run one for you, like Hillary Clinton did.
- 2bluesc 9y agoI ran my own mail server for years because I didn't trust Google with _all_ my data. Started colocated server for a while, then VPS, then cloud. Setting up an maintaining SPAM mechanisms on a low volume mail server is a nightmare. Switched to Fastmail and haven't looked back. Their Android and Web client are great and they've opened their JMAP[0] interface. [0] http://jmap.io/ http://jmap.io/
- ryanlol 9y agoFastmail is great until their support hands your account over to some random person that just happened to ask.
- xienze 9y agohttps://www.fastmail.com/about/privacy.html https://www.fastmail.com/about/privacy.html They have a very strong privacy policy, they’re not just going to hand your email over to a “random” person.
- skrause 9y agoThey already have: https://news.ycombinator.com/item?id=15855081 https://news.ycombinator.com/item?id=15855081
- akulbe 9y agoFirst, I'd start with "Don't run your own email server unless you absolutely have to." Second, if you must... I'd recommend Mail-in-a-Box. MUCH easier to setup / maintain than this one, at least from a cursory read. https://mailinabox.email https://mailinabox.email
- vog 9y agoI appreciate the write-up! I always wanted to do a similar write-up for my own setup, but I never got around to it. (My setup uses slightly with different components: exim+dovecot+spamassassin+openldap.) However, after reading this, the software developer in me feels like "These tutorials should not be necessary." This should be a GitHub repo, trivial to fork and trivial to test out locally for anyone.
- amdavidson 9y agoThere are several projects that do just that: - https://mailinabox.email/ https://mailinabox.email/ - https://mailcow.email/ https://mailcow.email/ - https://modoboa.org/en/ https://modoboa.org/en/
- robotmay 9y agoI've been running a mailcow install for the past year and it has worked remarkably well. Not sure if I'll stick with it when I move my server, but I've got no complaints.
- JepZ 9y agoI think when you setup that whole stuff yourself you are better prepared to fix any problems that might arise. I mean those are 'tutorials', sound like teaching ;-)
- twothamendment 9y agoIcing on the cake: Sprinkle a little Let's Encrypt in there to cover SSL. It doesn't take much to have a cron make a new cert and restart dovecot and postfix. My setup is similar, but it uses MySQL instead of LDAP. I love being able to make aliases and even better - deleting them when I'm done with them.
- perlgod 9y agoAuthor here - I plan on switching to Let’s Encrypt once they support ECC certificates.
- zuck9 9y agoWhy do you need ECC certificates?
- perlgod 9y agoI don't need them, I just prefer them. They are arguably more secure and require much lower CPU usage.
- c0l0 9y agoAny reasonably modern x86_64 CPU can do more than 1000 RSA2048 signs (~ TLS handshakes) a second, per core. Performance considerations really aren't a good reason to not use RSA for TLS KEX.
- nirv 9y agoWhile I share your ECC preference, for today I see no reason to refuse free, reasonably secure LE support by default. ECDSA signing with LE's RSA intermediates is supported from Feb 2016, and full ECDSA cert chain will be added on July 2018[1]. [1] https://letsencrypt.org/upcoming-features/ https://letsencrypt.org/upcoming-features/
- wtetzner 9y agoI think they do support ECC certificates: https://cromwell-intl.com/open-source/google-freebsd-tls/tls-certificate.html https://cromwell-intl.com/open-source/google-freebsd-tls/tls...
- rootsudo 9y agoAlso it's alot of work.
- TheOtherHobbes 9y agoIt took about three days to set up postfix and dovecot for multiple domains from a cold start, including certs and spam filtering. Postfix supports a selection of block lists for spam, and I get no spam at all - although unfortunately my gf sends me email from a Yahoo account, and certain Y! servers get blocked, so that mail bounces. She doesn't do it often enough for me to spend more time getting whitelisting to work. (Currently it doesn't - I don't know why.) The hard part is getting a working config file for postfix, but there are tuts and examples online. Like a lot of older FOSS code, postfix is basically an insane collection of every possible switch for every possible feature, dumped with no particular thought or care into a single config file, and written up - ditto - in a single help file. You only need about 10% of it, but you won't know which 10% until you try. The server gets regular hack/relay attacks from all over, but those get killed by Fail2Ban. I'm not exactly a high profile target, but unlike an old WP site I used to run - it was hacked in weeks - the servers seem to have survived for more than five years now.
- sliken 9y agoYahoo servers don't seem very well managed. Obviously they have lost a billion passwords or so. They also serve malware from their home page often (I've gotten chrome, opendns, and firefox warnings). The ads shown are often pretty ghetto (payday loans and the like). In the interest of security I'd help your gf to a different provider.
- notinventedhear 9y agoYeesh, there's so much involved. I've been running my own mail server with https://mailinabox.email https://mailinabox.email for ~2 years and can heartily recommend it. Still, even with that there are gotchas if you want to be able to send messages from your server to Google et al, eg. reverse-DNS-records, DKIM, SPF. Not for the pressed-for-time.
- freen 9y agoSeconding https://mailinabox.email https://mailinabox.email It's fantastic.
- NetOpWibby 9y agoCame here to suggest MiaB or co-sign. I've been curious about running my own mail server from scratch since you can't run MiaB on the latest Ubuntu flavor.
- oblib 9y agoI've been using mail-in-a-box too for about a year now. I'm pretty happy about not being tied into a 3rd party anymore.
- mzaccari 9y agoAbout 2 years ago I had a customer that required their own private mail server. I set up Mail-in-a-Box on a $5 Digital Ocean droplet, and they've been happy with it ever since. The integration with Let's Encrypt and a relatively smooth upgrade process has made it one of the more enjoyable services I manage. I would highly recommend it.
- mattbillenstein 9y ago+1 Mail in a box is great.
- jycallahan 9y agoBig upvotes for mail-in-a-box! Three years and counting on DigitalOcean!
- Pistos2 9y ago
- teekert 9y agoLove this, I spend many nights in the past fiddling with email.. and giving up. But I manged to get it to work one day and I learned a lot! I started with [0], but eventually found the mail-stack-delivery package in the Ubuntu repos, it sets up almost everything correctly out of the box and I ran with that. While Googling that package name I found this: [1], may also be nice. I also learned that having it in your basement means trouble: Someone pulls the plug, your IP changes or ends up on a spam list. For some years I ran my own server on a DO droplet. It is very cost effective when you can make as much mailboxes as you want for family (+ unlimited aliases, addresses that deliver to both you and your wife, being able to email 500 mb to familie, etc). I still don't know down what sinkhole emails to my brother-in-law's outlook.com address went down. The literal response of MS at the time: We don't manage our own spam filter, try adding more text, make it look more real... But man, the pain, the complexity, the reverse DNS, the startTLS, the SPF record, the DKIM records. It took me a long time to understand the difference between mail servers and MTAs and why there are different ports for them. Also, few providers in the Netherlands even allow you to use port 25, luckily mine did. Email is truly an old protocol that has been hacked up-to-date (more or less) and setting up your own mail server will make this very clear to you :) I'd recommend it though, you'll learn a lot! But to be honest, I now pay 3 euros a months to a dutch email provider because email is too important and I didn't want to go through the pain again when 16.04 came out. I might still have a go at it in the future, there is something beautiful about running your own email server :) [0] https://arstechnica.com/information-technology/2014/02/how-to-run-your-own-e-mail-server-with-your-own-domain-part-1/ https://arstechnica.com/information-technology/2014/02/how-t... [1] https://www.iredmail.org/ https://www.iredmail.org/
- godman_8 9y agoHonestly if you're lazy or want the support it might be nice to get the VPS cPanel license. It sets it up for you with full customization allowed. It also has spamassassin with RBL support in the interface. I think it's $17~ a month excluding VPS cost. You'll also get so many other features that can be disabled.
- lucb1e 9y ago> on FreeBSD using Postfix, Dovecot, Rspamd, and LDAP. That seems like an awful amount of work / overkill. This is not a good introduction for a normal geek, and die-hard open source fans will figure it out without too much trouble anyway. Postfix is not the best choice for novices, FreeBSD is not the most well-supported/documented system just because it's not as popular as some others, and a directory service shouldn't be necessary. We had to setup Exim, Postfix or Sendmail for school. Sendmail was universally hated the most, Postfix came in second, and Exim was... well, not exactly logical or easy, but the best of the three mainstream MTAs. I'm running hMailServer at home. Windows-only, unfortunately, but until I find a proper replacement, I'll just keep running it in a VM. Nothing else even comes close in admin-friendliness. It's just install and run, with either a local admin interface or a web interface (using PHP, so it runs anywhere).
- Mister_Snuggles 9y agoFreeBSD isn't that bad, but it is different than Linux and the community is smaller. There are some things that the Linux world does better (installing updates), but there are also some things that FreeBSD does better (ZFS, I prefer the split between base and 3rd-party software, etc). The documentation for the base system, however, is very good. The man pages are complete and well-written, and the handbook[0] is a great source of documentation as well. [0] https://www.freebsd.org/doc/handbook/ https://www.freebsd.org/doc/handbook/
- lucb1e 9y ago> FreeBSD isn't that bad, but it is different than Linux and the community is smaller. Which was my point. I know it's better integrated and has better documentation (some coworkers were fans, plus what I read online about it), but I still think going with mainstream is the better choice when writing a general post like "how to run your own mail server". Not that guides for "how to run a mail server on FreeBSD" shouldn't exist. Just that then it should be called that, and not be general advice to anyone who might be googling the general title. There's so much bad press for running your own mail server, while really it's not that hard with the right tools and explanations.
- 9y ago
- perlgod 9y agoAuthor here - happy to respond to any questions.
- mozumder 9y agoHow much of this is common to a Mac OS Server mail setup?
- perlgod 9y agoI believe OS X uses many of the same components under the hood. I have toyed with OS X Server.app (mostly just to get the necessary certificates to get IMAP push notifications working with iOS/Dovecot[1]) and it seems like a really solid choice. Not sure how you go about colocating a Mac Mini in a datacenter though. [1] https://www.c0ffee.net/blog/dovecot-push-notifications https://www.c0ffee.net/blog/dovecot-push-notifications
- mozumder 9y agoYou use it with your home ISP on a static-IP address.
- perlgod 9y agoAny outgoing mail will almost certainly be spam-blocked if you send from a residential IP. Also, most ISPs block port 25.
- mozumder 9y agoNope. When you ask your ISP for a static-IP address, your service goes from Residential to a more expensive Business account, and they open up outgoing mail ports. (At least for Verizon FIOS that I'm on, pretty sure Comcast is same as well.) Cloud IP addresses are probably more problematic for spam blocklists.
- 9y ago
- deadbunny 9y ago> Before we dive in, an important caveat: You will become a sysadmin of your own mail server. This for me is the deal breaker. I say this as a sysadmin. It's all well and good running a single server but if that shits the bed then you have to deal with it immediately. So to run something that doesn't require 24/7 support I now have to run a cluster of servers. I'll also need something to manage those servers like salt/ansible/puppet I also need to deal with being my IP blacklisted because of a previous owner, or just entire domains now delivering my email because they don't like the fact i'm not using $email provider Then there is spam filtering and the constant battle that is. Or I could just pay someone a couple of bucks a month to worry about all that shit and not worry about it.
- icebraining 9y agoIt's all well and good running a single server but if that shits the bed then you have to deal with it immediately. Well, that depends on your needs. SMTP will keep retrying, so you won't lose any emails, you just might not be able to access them immediately. For my personal email, this is perfectly OK. Not that it ever happened, in my six years of running Exim + Dovecot, but that may have just been luck.
- uhhhhhhh 9y agosmtp will eventually give up retrying, and if you're not willing to "always" respond within a few hours, you're going to lose emails.
- icebraining 9y agoIs there any server with such a short default? The RFC recommends at least 4-5 days.
- yosamino 9y agoWell, yeah... but if you have any people actually using the server, they will start calling you around day One asking about their mail. At least if the the mail get's bounced after a few hours only, they get some sort of feedback, instead of being left wondering.
- Faaak 9y agoA docker container would really be useful for that !
- Ronsenshi 9y agoHere's the one that I use: https://hub.docker.com/r/analogic/poste.io/ https://hub.docker.com/r/analogic/poste.io/ One of the easiest mailserver setups i've ever had. If you don't like that it's not super free, there's open source alternative: https://mailu.io/ https://mailu.io/
- petre 9y agoIs there any modern webmail client that's secure and easy to set up? I know about Squirrel Mail and there was another one using the Horde framework, but I'd rather use a uwSGI/PSGI app that preferably doesn't need a mySQL database.
- JepZ 9y agoRegarding web mail: I am much happier with RainLoop [1] than I was with roundcube (better usability). If you are running a Nextcloud anyway, their mail app might be enough[2]. [1]: https://www.rainloop.net https://www.rainloop.net [2]: https://apps.nextcloud.com/apps/mail https://apps.nextcloud.com/apps/mail
- linsomniac 9y agoHow to run your own mail server: Don't. How to run your own mail server (for experts): Don't. I say this as someone who has run my own mail server for 20+ years. Now, if you absolutely have to get off Google, and the other available hosted options don't work for you, then this article looks like a good start. I'd add roundcube for web access and letsencrypt for SSL. One thing you'll never really get, in my experience, is good spam handling. The big providers just have so much more data to work with to prevent spam.
- ams6110 9y agoI run OpenSMTPD. It delivers my mail to a maildir. I read it in emacs. It's pretty simple. But not everyone's cup of tea. If I had to worry about IMAP, Webmail, etc. I wouldn't run my own.
- DrPhish 9y agoI have my opensmtpd setup relay incoming mail to a Citadel IMAP/webmail server. It works a treat. I'm paranoid, so I don't allow external IMAP, force SSL on the webmail, GeoIP block it to only 3 countries and have a simple auth prompt on it as well just in case the landing page has an exploit.
- wila 9y agoBut the spam handling you can actually buy. A spamexperts (to name just one alternative) inbound filter account for 1 domain costs about 1.5 dollar per month for an unlimited number of email boxes.
- cat199 9y ago> One thing you'll never really get, in my experience, is good spam handling. Not quite the same calibre, but really, SpamAssassin+RBLs tuned a smidge too high plus a user whitelist is pretty darn good. Scripting something that auto-adds to whitelist based on sent mail would do even better (but is exactly the kind of 'fun' that people don't have to deal with using 3rd party service). I've heard you can do better with dspam.
- catdog 9y ago
- agentultra 9y agoI run my own mail infrastructure. To say the least I wouldn't recommend it even to my worst enemies. It's horrible. Actually it's fine until it's not. Then your email doesn't work and you could be missing out on important communications. And then you're scrambling to figure out how the spammers managed to exploit your setup this time. And you have to learn a tonne of crap in order to manage it... and the text files! Configuration... configuration everywhere. Obscure configuration. Configuration that has real consequences and causes spooky action at a distance. Configuration that will soon be exploited in strange ways. I was so frustrated the last time my mail server went down that I started writing an SMTP protocol handler in Haskell with the intent of writing a MTA with the goal of minimizing configuration and being secure and resistant to attacks by default. So that hopefully more people can run their own infrastructure without prematurely aging. I dunno how useful it will be to others but at least it will keep my gray hairs at bay, I hope, when it's ready for use. Until then though we need more guides like this for us poor souls who do go down this route. There are way too many out-dated guides awash in the sea of information.
- ericcholis 9y agoSame experience here. Previously I maintained a Merak/IceWarp mail server. The "idea" was great, they provided a nice interface for a small organization (15ish people). But, it became an uphill battle very quickly.
- mozumder 9y agoI run my own mail server, for several years now. A Mac Mini on Mac OS Server on a static IP address. It's been great, literally zero maintenance, but it completely hides everything about the underlying architecture.
- lisper 9y agoHeh, I have had the exact opposite experience. My mail setup has been stable and reliable for years. (I'm a little bit afraid to report this because one possible explanation is that I simply have not been on any serious hacker's radar screen.) I'm not doing anything fancy: just postfix+dovecot, gray listing using a custom milter I wrote in Python, and Spam Sieve running client-side on my Mac.
- TYPE_FASTER 9y agoI've hosted my own mail server for a while. I've gone the Postfix/Dovecot route, I've used qmail, etc. My current setup is WebMin/VirtualMin. It works really well, and will run on the cheapest DO droplet. Fighting spam effectively is not trivial.
- sliken 9y agoSeems pretty trivial to me. 1) install spamassassin 2) turn on greylisting During if you want to to from 1-2 spam a day to 1-2 a month you might want to block the garbage domains like click, link, party, top, webcam, xyz, stream etc. Probably worth enabling a DNS based block list. So an apt get or two, 2-3 lines in a config file. Seems trivial to me, most every mail server HOWTO mentions them, should be just a cut/paste. Sure 9-12 months from now it won't work as well, thus updating SA periodically, just like anything else internet facing.
- apple4ever 9y agoThis isn't bad. I ended up creating an Ansible role to do it for me, and it works great. I thought about Fastmail, but its too expensive when you want to do more than one email address or domain. I run mine on a $5 server from DigitalOcean.
- Mister_Snuggles 9y agoEvery time a thread about running your own email server comes up I think "Oh yeah, I was going to set up FastMail for my domain" The current pricing[0] seems to let you have 100 domains plus 600 aliases[1] for $5/mo. I've got this thought that I will create aliases for every different thing I sign up for and use them to track who's selling my email address to who. I think that a domain plus aliases will do the trick and I think that what I want to do will fit in their limits. [0] https://www.fastmail.com/pricing/ https://www.fastmail.com/pricing/ [1] https://www.fastmail.com/help/account/limits.html https://www.fastmail.com/help/account/limits.html
- floren 9y agoSo I can't quite parse it out from the page, maybe one of the Fastmail users can tell me. I can set up 100 domains and 600 aliases, but if I want my wife to have access to hername@mydomain.com, does she need her own $5/mo account?
- xienze 9y agoNope. You can go nuts with domains, they just route to distinct folders. That said, it’s one logical account, so your wife would have access to all folders/domains.
- corobo 9y ago> I can set up 100 domains and 600 aliases, but if I want my wife to have access to hername@mydomain.com, does she need her own $5/mo account? You can add her as a user to your account (so she can use your domain) and it costs an additional $5/mo for the separate user yes
- workthrowaway27 9y agoI've done this before. It's a pain in the ass. You have to run several different programs each with hundreds of configuration options, make sure the different programs can communicate with each other properly, make sure your email doesn't get flagged as spam, and be your own sysadmin. All for marginal benefit. It would be great if someone wrote a program handling all of this that could be deployed as a single binary with secure defaults and limited configurability, but I don't see that happening any time soon. Email providers are good enough for almost everyone and the people who are good enough programmers to make sense of all the different protocols they'll have to deal with and get everything to interoperate nicely probably have other things to work on that people will actually pay for. Edit: That said, this guide does look like a great resource for someone who is interested in doing this. It's interesting to learn how email works and if I had this guide when I started out I'd have saved a ton of time.
- lisper 9y agoI started working on this a while back and got as far as writing a collection of scripts that spins up a mail server from scratch and does all the configuration. It's not complete (doesn't include spam filtering or search) and it uses Common Lisp to drive the process, which is the main reason I haven't published it. I didn't think there would be much interest in something that obscure. But if there is interest I'd be happy to clean up the code and put it on github.
- daanavitch 9y agoI have been running a Zimbra mail server for years and it's been great. Everything is included, configuration is quick and easy and there's lots of documentation online. The only negatives are that upgrading is a pain (I have to spin up a whole new server and migrate everything with Zextras Migration Suite) and the whole thing takes up quite some resources.
- RandomCSGeek 9y agoThere seem to be at least a couple of projects on GitHub on this topic. Eg. https://github.com/aimxhaisse/docker-mailz https://github.com/aimxhaisse/docker-mailz Now how many of them actually work is a different question altogether.
- Jaruzel 9y agoSlightly tangential, but is there something for RSpamd, where it can be run as just a blind mail relay? I.E. like this: Internet Email (SMTP) -> [MTA + Rspamd] -> [Real MTA + Inboxes] I ask because I've got a mail server system I'm happy with, but just want to bolt a better anti-spam filtering system on in front of it. Thanks.
- perlgod 9y agoI believe it would work fine, configure rspamd as a milter on the first hop and relayhost everything to "Real MTA".
- Jaruzel 9y agoSo Rspamd+PostFix ?
- dmoo 9y agoHave you looked at assp, lots of parameters but does the job.
- Jaruzel 9y agoI did, a very long time ago, it seemed, um, overkill for my needs. Maybe I should revisit!
- j45 9y agoThis is an insightful guide on how email works. Instead of running each component individually, I would recommend looking at something like Zimbra or another OSS mail package that handles a lot of this. I hosted my own email for over 10 years and maintaining the bits are as painful if you don't have a plan in place. A decent comparable for do-it-yourself hosting is the kind of luck a product like MDaemon provides - it decent job on windows of rolling all the features into a reasonably manageable server, as well as being quite affordable. I don't work for MDaemon, but tools like this make hosting email relatively trivial. http://www.altn.com/Products/MDaemon-Email-Server-Windows/ http://www.altn.com/Products/MDaemon-Email-Server-Windows/
- throwawayeo5 9y agoEmail is always a nightmare. My ex runs a BSD mail server that seems to work alright (and he has a cloud service that will handle mail in the event of a server failure). Me? I pay Fastmail like $50/year to do that for me, and they’re wonderful. I tried to sign up for a trial with my own domain, and when I got a strange error that didn’t let me log in, I put in a ticket (as a non-customer) and the issue was rectified quickly. I swear, I don’t work for Fastmail, but I’d much rather use them (or any email provider that is halfway decent) than fiddle with my own mail server.
- andris9 9y agoExisting mail server solutions seemed so complicated and just plain wrong that I went and wrote my own mail server software from scratch https://wildduck.email/ https://wildduck.email/
- nicolaslem 9y agoI've been feeling the same for a while. Congratulation for doing it, it looks great!
- Yetanfou 9y agoI've run my own mail server ever since I got something resembling broadband internet in 1996. Back then spam was non-existent, Sendmail was the emperor without clothes about to be dethroned and I hacked sendmail.cf without needing to look at the the bible [1]. I've never regretted running my own server, nor have I ever contemplated moving to a hosted solution. Spam is not a problem either, Spamassassin in combination with a greylist make for a nearly spam-free experience. The whole setup has been migrated from the original Pentium-66 via an aBit-BP6 (SMP for the masses [2], retired in 2009) to the current Intel SS-4200 (upgraded to a dual-core Pentium but still limited to 2GB). In practice a Raspberry Pi would be enough to run a viable mail server so even this rather anaemic setup does its job without breaking a sweat. The whole setup consists of Debian (Sid) running Exim through a smarthost, feeding through Spamassassin + greylistd into Dovecot. Apart from some auto-manual intervention to cope with Microsoft/Google/... not coping with the greylisting and thus needing whitelisting it more or less just works. In other words, just go ahead and run your own server. [1] http://shop.oreilly.com/product/9780596510299.do http://shop.oreilly.com/product/9780596510299.do [2] https://en.wikipedia.org/wiki/ABIT_BP6 https://en.wikipedia.org/wiki/ABIT_BP6 [3] http://ss4200.pbworks.com/w/page/5122751/FrontPage http://ss4200.pbworks.com/w/page/5122751/FrontPage
- brandon272 9y agoWhat do you estimate has been your total investment of time in running your own mail server?
- pwg 9y agoNot the OP, but I've been running my own email server since about the same time-frame (and it started life on a dual CPU Pentium 100Mhz box). Total time investment since circa 1998: estimated maybe 100-200 hours total (note, over an approximately 20 year span), and most of that was spent during the inevitable of reinstall new OS on current or newer box, then move config over portions of the process. I've also always been on Postfix, which has always been way more secure than sendmail ever was at the time. And Postfix is also much easier to configure for the basic case of "send/receive email for a personal domain".
- 9y ago
- philrw 9y agoLooking at that postfix main.cf gave me flashbacks and not in a good way. Google can have it. Or ProtonMail. Running my own mail server didn't pay enough ($0) for the complaints I got from its users (family). I'll focus on VoIP PBX and home automation until someone gobbles that up too.
- codingdave 9y agoI've run my own mail for about 15 years. Just recently stopped.There was nothing wrong with the process, it worked. But I thought about how much time I've spent on running my own domain and email over the last couple decades, and added up what it got me over those years... and the value just wasn't there. I know the article is concerned with owning your own data, and I appreciate the point. But finding a mail provider that meets your needs is, IMO, a better way to spend your time than just saying "Gmail isn't good for me, so I'll do my own."
- icelancer 9y agoI use iRedMail and set up my own mail server for my small business. I am beginning to wish I hadn't, even though I've had literally 0 problems outside of a single reboot to fix an issue. https://www.linuxbabe.com/mail-server/ubuntu-16-04-iredmail-server-installation https://www.linuxbabe.com/mail-server/ubuntu-16-04-iredmail-... I dunno. I feel like I'm sitting on a timebomb. It's hosted on DigitalOcean and while it works great with RoundCube and gmail... eh. I dunno why I even did it in the first place.
- le-mark 9y agoOther than the feeling of 'sitting on a timebomb' are there any other specifics you can cite? Have you looked into contracting someone for a few hours a month to check/update things? I have considered doing what you have done, and your feedback has piqured my curiosity.
- icelancer 9y agoNot really. Just everyone smart I talk to says the same thing as everyone else in this thread: Don't do it. I'm not a sysadmin, I'm a developer who runs a company and doesn't even work in IT in my own company anymore. Bleh. So far so good, though....
- ddoolin 9y agoI use iRedMail and have been for 3 years now and I love it. It's really just a collection of scripts and updates are just updates to the underlying packages. Everything is transparent if you want to know what's going on. It takes awhile to get used to all the moving pieces (if you care to even know them as it isn't necessary) but I've found their setup to work very smoothly and be very stable. I'm also a developer, btw. This mail server is only for me so it's not a big deal but if I had to I'd probably be comfortable setting it up for a small business. I wouldn't recommend it for that still, though, since you are the support in that case.
- bedros 9y agoWhat webmail client people tried with their own setup that they like?
- phelmig 9y agoThanks for posting this. I'm currently running a similar setup and to me it's a horrible technical debt. Any ideas how to migrate multiple mailboxes for multiple domains to a managed solution?
- jstewartmobile 9y agoThis is a very good guide. One nice thing about the programs he chose is that their config options are fairly stable (can't vouch for Solr). That many moving pieces would be absolutely unmanageable if the options changed frequently. Been using a similar setup for years without difficulties. Adding something like fail2ban into the mix wouldn't hurt. If you're going to do this, first check that your VPS / ISP allow inbound traffic to port 25/tcp. AWS allows it upon special request. GCE doesn't. Don't know about the others. In the US, most residential ISPs block 25/tcp inbound.
- Tepix 9y agoIf you run your own mail server you can save a ton of work and time and get great defaults and features by using Sovereign from https://github.com/sovereign/sovereign https://github.com/sovereign/sovereign
- grinsekatze 9y agoThis is an interesting write-up, but doing it like this files like way too much work. I have been using mailcow[0] for years now and it does all of this for me and works great. The UI is beautiful and intuitive. And setting up mailcow literally takes a few of minutes, since the project was ported to docker. Highly recommend it. [0] https://github.com/mailcow/mailcow-dockerized https://github.com/mailcow/mailcow-dockerized
- goerz 9y agoI've been pretty happy paying Fastmail to run my email server for me.
- nicolaslem 9y agoI've recently moved to Fastmail and I'm blown away by the service. Everything feel well thought, well integrated, their web interface is fast, their mobile app is great, they respect standards... I could continue all day. From reading their blog[0] you can tell that they are passionate about email. It is a bit pricey for a personal email with a few accounts, but I'm happy to give them their well-earned money. [0] https://blog.fastmail.com https://blog.fastmail.com
- brlewis 9y agoI have an old server that I need to migrate. It uses exim4 and pipes email to programs for certain addresses, and needs to send out automated email for forgotten passwords, etc. Is it worth moving to Postfix or something better? This is the part of the migration I look forward to the least.
- alasdair_ 9y agoI've done this, more than once, both for ISPs and personally. I even put together a self-contained single-DVD installer that would install and set everything up securely and solidly. (I don't think I have a copy any longer and if I did it's very out of date) I still don't recommend doing it. Even for the security-concious. It's just not worth it.
- SwellJoe 9y agoI'm surprised by how many people think mail is an impossibly hard problem. There some things about mail that are stupid; the core protocols are old and it shows. But, once things are working, you can leave it alone for years (aside from regular software updates) without trouble. I have. I've never not run my own mail servers (and often for several other people/companies/projects, as well) in the past 20 years. I used to consider myself an expert on the topic, but it's required so little of my time/thought in the past several years that I've forgotten most of that expertise. I think what I'm trying to say is that it's not harder than it used to be (though some problems, like spam and security requirements for safety, have gotten worse in absolute terms). With modern tools and packaging on modern Linux distributions, you can be up and running pretty quickly. My company ships a turn-key solution as part of Virtualmin, but you can build something similar without that in an afternoon or two if you're reasonably Linux-savvy and have some notion of how all the pieces fit together (maybe a couple extra afternoons if you don't know the basics; DKIM and SPF can be tricky, since you also have to know or learn you some DNS). It's harder than a web server or DNS server, but not something you should flee in terror from. Admittedly, it's gotten cheaper in recent years to outsource it...and with microservice-based architectures, maybe it makes more sense to have some other API than SMTP (though SMTP is very easy to use from every language I've ever worked in). But, there are problems and complexities with outsourcing, as well.
- erikb 9y agoI seriously always failed getting over that first hurdle every time I tried. I didn't try this one yet, but most guides deviate from whatever my setup will be by a little, and that then increases to a lot of investigation work with pretty unclear config values and not a lot of debugging tools. Have I invested enough energy? Apparently not. But I'm over the weekend-sized amount by a multipler bigger than three.
- interfixus 9y agoYeah, it's learnable, it's doable, it really doesn't need to be all that hard. And then ... after you've done every damned thing exactly by the book, and DKIM'ed the dickens out of your headers, killed the spam, policed yourself off the blacklists, etc. etc. - turns out you might as well not have bothered. The googles and the microsofts (the microsofts especially!) will one day drop your outgoing mail without the slightest notification, because the ip range, or because the full Moon, or just because they can. I ran that show for nearly fifteen years, but threw in the towel last year, and handed over to Fastmail. With regret, although their service is first rate. Email is not a succesful federated protocol these days. The monoliths effectively killed it off.
- jacksnipe 9y agoIt always makes me happy when a blog serves me less than 40kB to read an article!
- storsjt 9y agoWould a better and easier alternative be to run your mail service through AWS?[1] Sure it's _hosted_ in a centralised place but since you're paying for it Amazon shouldn't have an incentive to harvest your data. [1]: https://aws.amazon.com/ses/ https://aws.amazon.com/ses/
- Tepix 9y agoUse a cheap dedicated server. A Raspberry Pi 3 can do it. You can use a cheap VPS to tunnel a "proper" IP address to your home network. Or rent a cheap dedicated server like Kimsufi or online.net for a couple of bucks per month.
- storsjt 9y ago> Before we dive in, an important caveat: You will become a sysadmin of your own mail server. I don't want to become a sysadmin of my own mail server, however I'd appreciate not having my personal data harvested by webmail providers (e.g. gmail, outlook.com). Using a Pi or dedicated server would make me a sysadmin. Using AWS email seems like a decent middle ground which isn't too expensive ($0.10 per 1000 sent and $0.10 per 1000 emails received).
- spac 9y agoThen why not pay for Fastmail for example?
- CodeWriter23 9y agoRunning your own personal, non-commercial server may be just fine. But if you’re business is pumping out volumes of email, no amount of DMARC, DKIM, SPF, CFL participation and fighting to stay off IP blacklists will prevent you from eventually succumbing to the user that clicks the Junk button to delete their emails. This will tank your domain’s reputation and get your emails routed to Junk (or silently discarded) for all recipients at the big ESPs like Gmail, etc. SPAM scoring is outsourced to companies like Symantec, CloudMark and others. They are the mail-zapping, score-keeping monoculture of the email ecosphere. You basically need a large company who will take your word for it that you’re not SPAMming and interface with the filtering industry on your behalf to de-nerf your domain once the Junkie McJunkbuttons of the Internet screw your reputation over.
- sedachv 9y agoWhat is CFL participation?
- CodeWriter23 9y agoCustomer Feedback Loop. When Junkie taps the Junk button you get notified by the ESP to delete them any mailing lists and never email that address again. They typically track this as a metric against your domain. And some ESPs, like Comcast won’t even sign you up to participate unless you’re big.
- danieltillett 9y agoYep. Basically the big email companies have outsourced their anti-spam filtering problem to the email service companies. I used to run my own email server for around 15 years with minimal issues, but I gave up when my mail started disappearing into the hotmail/gmail/yahoo blackhole.
- libpcap 9y agoIf Hillary can do it, so can you.
- thro1237 9y agoIsn't it possible to make all these changes in a server and make it available as a docker container or VM (with minimal customization required for end users?)
- m104 9y agoFor sure! After years of running a personal mail server with a setup similar to what's described in the article, I moved to using a pre-built docker setup and haven't looked back: https://github.com/tomav/docker-mailserver https://github.com/tomav/docker-mailserver The easiest way to get this type of VM setup going is to start up the container on your mail host with all of the fun features (filters mostly) turned off, verify that the new mail container works as expected, then slowly start turning on features one by one so that if you happen to break something with a bad configuration you know how to roll back to a configuration that is functional.
- mderazon 9y ago> Luckily, running your own mail server is not as daunting as many would have you believe Looks pretty daunting to me
- deleted 9y ago[deleted]
- tzs 9y agoOne thing I'd like to see covered is sender dependent outgoing mail routing. For example, suppose I have things set up so all outgoing mail from my home goes through my SMTP server. If I send an email with a from address of tzs@mydomain, then the setup in the article is perfect. Suppose, though, I send an email from home with my from address set to tzs@employer, where "employer" is my employer's domain? Assume this email is not to an @employer address [1]. With the setup in the article (and in almost every other similar setup I've seen covered in similar articles) this might run into spam filter issues unless I've convinced my employer to add my SMTP server to their SPF record. The way I want this to be handled is for my SMTP server to see that the mail is from an @employer address, and instead of trying to deliver it directly, relay it through employer's SMTP server. This is similar to the common "smart host" configuration often used when you run an SMTP server at home, but want it to send all outgoing mail through your ISP's SMTP server instead of trying direct delivery. Essentially what I want is a conditional smart host based on the from address. Postfix supports this. In fact, it seems to support it in a couple different ways. I played with it a bit but could not quite get it working. What I'm doing for now, until I find out how to do it right, is only send work email outside of work from my desktop Mac. I took tzs@employer off the list of mail aliases for my mydomain mail account, and created a second account in Apple Mail for @employer. I set the incoming mail server to POP3 on 127.0.0.1 so that it would fail, and set the outgoing server to smtp.employer. It complained for a while that it could not contact the POP3 server, but eventually stopped complaining, and the address in the configuration dialog changed to 0.0.0.0. With that setup Apple Mail sends mail from @employer directly to my employer's SMTP. Sometime recently, after an OS update, that stopped working. It would no longer let me enable an account unless it could successfully talk to the incoming mail server for that account. I did find an ugly workaround for that. I gave it the correct address for employer's POP3 server, and the correct password. Once it was happy, I went to Keychain Access, found the saved password for the POP3 server, and changed it in Keychain Access to something incorrect. Mail then complains that it cannot login to the POP3 server, but that does not cause it to disable the account. Net effect: a send only account in Apple Mail. (It is important to do the password change in Keychain Access, not in Mail, because Mail won't save the change until it sees the new password work). (If that had not worked, I probably would have written a dummy POP3 server that always reports no mail and used that). [1] This happens reasonably often for me, because I have my mail server set up to use fetchmail to fetch my incoming work email and deliver it via procmail. Same for any other SMTP accounts I have. That way I only have to configure mail clients to work with mail server and I get access to all my mail from all of my non-web email accounts.
- osrec 9y agoThe configuration of mail servers is so unbelievably grueling, it can almost reduce one to tears! I love having my email and data on my own server, but it is horrendously time consuming to get it up and running, and if something goes wrong, you could be looking at a weekend of work (often involving trial and error with poorly documented config formats). Sometimes I wish email could be replaced with something simpler but just as ubiquitous. Sigh
- Libturd 9y ago100% not worth it. anyone who says otherwise just likes to make things difficult for themselves and the people around them.
- digitalsin 9y agoThere's no reason to not at least run mail-in-a-box if you consider yourself a technical person but have limited time. It's absurdly easy to set up and the maintainers / contributors do an awesome job. Running your primary email on these big hosting companies is taking your privacy and pissing it right down the drain. It's really not that hard folks. https://mailinabox.email/ https://mailinabox.email/
- deleted 9y ago[deleted]
- golemiprague 9y agoIf Hillary could do it anybody can do it
- kazinator 9y agoBeen running mine for almost 8 years. Exim MTA, Courier IMAPD on Debian. Pretty easy setup; nothing complicated. For remote access I use two things: RoundCube webmail, and K-9 Mail on Android. For sending mail from K-9, I connect home, via authenticated SMTP which is on port 587, rather than 25. I have developed a little web app called Tamarind for generating throw-away mail aliases. http://www.kylheku.com/cgit/tamarind/tree/ http://www.kylheku.com/cgit/tamarind/tree/ I run some mailing lists which use GNU Mailman. For archiving them, I don't use that horrible pipermail, but rather a hacked version of Lurker. I patched Lurker to pass through HTML so that HTML mails end up rendered as HTML in the archive. The HTML has to be scrubbed, so I wrote a little scrubber for that: http://www.kylheku.com/cgit/hc/tree/ http://www.kylheku.com/cgit/hc/tree/ Lurker patches: http://www.kylheku.com/cgit/lurker/ http://www.kylheku.com/cgit/lurker/
- mattbillenstein 9y agoI run my own email server as well and the problem I see with it is that Google has all my email anyway -- probably 90% of the people I communicate with use gmail, so even if I don't, most of my sent mail is already in their system anyway.
- YTGRK 9y agohttps://youtu.be/I2l8xkjTUh4 https://youtu.be/I2l8xkjTUh4
- sfilargi 9y agoI run my own mail server that I coded myself (https://github.com/sfilargi/puremail https://github.com/sfilargi/puremail). It's basically a single binary that has an SMTP server and webmail server. It works absolutely fine for me without much stress. I do hit a couple of bugs here and there, mainly on the mail parsing, but it's not big deal.
- locusm 9y agoIf youre running your own email services and wonder why outlook.com / hotmail.com are blocking you you can signup for this. https://postmaster.live.com/snds https://postmaster.live.com/snds Its useful as quite often youll get blocked just for being in the same IP block as a spammy server. My experience to date is that once you notify them your IP isnt the culprit the block gets removed pretty quick.
- locusm 9y agoI think the Gmail equivalent is Postmaster Tools. https://postmaster.google.com https://postmaster.google.com
- leonroy 9y agoI run my own mail server. Have done since Evolution mail was in BETA circa 2003 ish (time flies). Started with a Linux Mandrake based Postfix, Procmail, Dovecot, Fetchmail setup with SpamAssassin then moved onto a proper Debian setup with Exim, Courier, Procmail, SpamAssassin and then finally after all that faff I found Zimbra. If you like email Zimbra's great - it's a fully baked mail server which you install on your Linux distro of choice and it goes off and installs all of the above for you. Everything is managed via a GUI and you have a great web interface and standards based IMAP, CalDAV support. If you buy the paid version you can even get ActiveSync and Exchange Web Services for it. Despite all that though, I would give anything to have all those countless hours I put into running my own mail server back. It is a colossal time sink. I can't even stress how much work it is, especially if you have anyone relying on the box for their primary mail account. It's no fun at all. You're gonna be debugging Fetchmail for when you or your user's want POP3 accounts downloading mail locally. Procmail for filtering. SpamAssassin (gawd if ever there was something which consumed my life it's that software and its myriad libs and helpers), not to mention familiarize yourself with DNS MX records, SPF, DKIM etc. etc. All of the above works surprisingly well and is fairly solid - until it isn't. When Google added DKIM/SPF protection and blacklisted servers which didn't was a fun weekend that I'd rather have spent with my family. When customer emails started bouncing because their IPs had hit an over zealous RBL list which Zimbra was using was a fun afternoon of debugging. When Zimbra decides to randomly let in 10-20 spam emails a day into my mailbox is another weekend project which I've yet to get round to. Thank god I'm self employed is all I can say because no employer would tolerate an employee putting the care and feeding required to maintain a personal email server! Unless you want to nurture a career as a mail sysadmin seriously, don't host your own mail server. Bottom line I'd recommend to anyone thinking about hosting one to either: 1. Don't 2. Use Microsoft Exchange Server 3. Use Zimbra 4. Seriously, don't - consider Fastmail, Gmail, O365 or Protonmail instead.
- c17r 9y agoDoes any else remember Matt Simerson‘s FreeBSD Mail Toaster script? Seems like he’s still working on it: https://github.com/msimerson/Mail-Toaster https://github.com/msimerson/Mail-Toaster
- ef4 9y ago> Getting off GMail is one of the best ways to take back your data in the face of dragnet surveillance. This just isn't true. You can host your own mail server and GMail will probably still end up hosting a large fraction of the email you read and write, because the people you correspond with are still using GMail. (In the same vein, you can refuse to have a Facebook account but Facebook probably has a dossier on you anyway. Enough people you know have dumped their contacts into Facebook that they already know your place in the social graph.)
- dade_ 9y agoThat is a very defeatist position.
- KeepFlying 9y agoDefeatest of realist? You can and should work to reduce your footprint if that concerns you, but there are still systematic issues that make it hard to stay completely outside of there services. Mainly what OP mentioned with contact uploads.
- ankitank 9y agoWhy not use solutions like iRedmail or Mail in a box? iRedmail - https://www.iredmail.org/ https://www.iredmail.org/ Mail in a box - https://mailinabox.email/ https://mailinabox.email/ They allow you to setup your own mail server and yet make it easier to get started. I have been using iRedmail and it has been working well so far.
- foxhop 9y agoI run my own outbound mail server for my infra. I couldn't justify paying a 3rd party just to make my mail more deliverable. I understand the cat/mouse game of spam but that should not prevent the rest of the world from running thier own email services. I also accept inbound mx for some of my personal domains, but I don't currently manage my own mailboxes, the mail gets aliased to my Gmail account. If at some point I get fed up with this arrangement I can transparently change where the email ends up.