4 ms·
> Don't run your own mail server. Agreed on almost everything, but disagree on this; there's no reason why any reasonably competent and security-focused sysadm
by jamiesonbecker 9y ago
> Don't run your own mail server.
Agreed on almost everything, but disagree on this; there's no reason why any reasonably competent and security-focused sysadmin can't run a secure Postfix or qmail server (although it's hard to run a secure version of qmail these days). In some ways, it's easier than back in the day (hello, letsencrypt!) and in some ways it's harder (DKIM, SPF, etc), but it's still doable and there are some excellent reasons for doing so.
(The rest of your advice is excellent.)
> Don't run Exim.
Absolutely agreed. I'm not sure why Debian opted to make it the default MTA over Postfix (but they also opted for systemd over runit, so..)
- tyingq 9y agoPostfix is nice, but the cognitive load of having to also understand and implement SPF, DKIM, Dmarc reports, antispam, webmail client, etc, is pretty high. The $5/user/month for Gsuite has been worth it for me, even though I could DIY if needed. Their UI makes all those things much smoother. Plus I get bonuses like their labs add-ons, etc.
- nine_k 9y agoOne of the reasons to run your own mail server might be exactly the lack of desire to show your mail contents to a third party.
- Tomte 9y agoDo the people you send mail to and receive mail from also maintain their very own mail server?
- nine_k 9y agoIt's a valid question. They can as well use the same server, e.g. because they work for the same company / organization. A different data retention policy and lack of third-party access may be very important in certain circumstances.