3 ms·
I ran email servers for my personal domains in the 90s and early 2000s. What eventually caused me to move everything to gmail was the massive pain of dealing wi
by excitom 5y ago
I ran email servers for my personal domains in the 90s and early 2000s. What eventually caused me to move everything to gmail was the massive pain of dealing with spam and trying to keep up with the latest spam filtering, which is essential.
- georgyo 5y agoRspamd has made that trivial for a number of years. It's an amazing tool.
- megous 5y agoYou don't need to keep up with anything if you use bogofilter, or similar statistics based methods, to classify it. You can do server side filtering based on other non-content things like DNS lookups, or IP blacklists, but that's just adding needless failure modes on the receive side. I don't do any non-content filtering, to keep things simple for the senders and latency down. Statistical methods are just that effective on a personal mail server level.
- znpy 5y agoI've been running my own mailserver for the last ten years and I must say that nowadays I'm not even running an antispam filter anymore because I basically don't get spam. What I do instead (instead of running an antispam server) is checking all stuff that a proper mail admin would do, that is: - greylisting (postgrey) - reject hosts not listed in spf records for the sender (spf-policyd) - verifying dkim signatures, if present (opendkim) Also f#@k spamhaus and those people, they will mark you as a spam host on pure prejudice.
- jesterson 5y agoWonder how it works for you... I've been running my own mail infrastructure for 10+ years. hosting tens of domains with hundreds of thousands of messages daily. That's said, most of my spam senders match SPF and have proper DKIM records. Only few absolutely outrageous spammers ignore it. Setting DKIM and SPF is not a rocket science and I'd be extremely surprised if spammers wouldn't do that.
- znpy 5y agoUh ... Your dkim settings are for your recipients to validate your emails. You should ALSO be checking dkim signatures on incoming e-mails (opendkim does that IIRC). Also, I forgot to mention that I REQUIRE tls for incoming smtp connection. That's another thing rising the bar for spammers. If you're using postfix, it's very open by default, in the sense that it doest not come with spf and/or dkim/dmarc tooling and it's not going to, for example, require (or even allow) ssl/tls for incoming smtp connections (and won't use it for outgoing smtp connection). One last thing: a little bit of spam leaks trough... But it's like less than a single spam email per two weeks.
- jesterson 5y ago> I forgot to mention that I REQUIRE tls for incoming smtp connection This would cut quite a number of legitimate emails for me. Surprised it works for you.
- znpy 5y agoI forgot to mention: I also require SSL/TLS for incoming smtp/submission connections.
- jjav 5y agoSpam is basically a non-issue these days. Just run your favorite bayesian filter locally and it's taken care of. On my mail server I don't do any silly blocking, simply pass everything through spamprobe and my spam rate is so close to zero that I don't notice. Maybe like once a month.