17 ms·
Poste.io – Complete Mail Server
- velcrovan 4y agoFirst thought: oh, huh, a self-hosted CVE generator. In seriousness, installing Roundcube on my own server circa 2006 was the cause of the first and only time I’ve had a server hacked. It’s probably improved since then or it wouldn’t still be around, but it put me off ever hosting my own email. The risks only get worse the further away you get from personal/hobby use.
- capableweb 4y agoThere is also basic forms of protection you should put in front of everything you make public, in order to reduce the attack surface. Firewall that blocks everything by default, strip all headers unless you veto them manually, aggressive rate-limiting you increase the limit only for specific IPs and so on. Putting up any type of software on a unprotected server even in 2006 is begging for trouble.
- velcrovan 4y agoDefine “unprotected”. The particular server had a firewall and fail2ban along with other measures. But Roundcube is a webmail service, so you’re leaving 443 open in any case. No amount of firewalls or rate limiting will help you if the thing you’re running is a web service that turns out to have a SQL injection vulnerability in one of its endpoints. Email servers in particular are going to be under attack all day long just from normal email activity, and that’s before you throw in any kind of web interface. It can be a big help to point your MX records at some other filtering service, but at that point why are you bothering hosting your own?
- oarsinsync 4y agoI use http basic auth in front of every https internet exposed service. The services may have their own auth system on top of that, but htpasswd in front solves the vast majority of problems. Can’t exploit an SQL injection vulnerability if you can’t reach the endpoint in the first place. I’m less concerned about apache2 and nginx http basic auth vulnerabilities. They’ll get fixed much quicker than random webapps. Anything else goes behind a VPN.
- sconi 4y agowhy not vpn for the https services?
- brirec 4y agoNot OP, but for me I reverse proxy things behind public IPs in an effort to trade a little bit of security and digital footprint for a lot of ease.
- nilespotter 4y agoThat's what I do. Mailcow on an isolated machine, 25/587 open on firewall port forwarding to it, the rest of the various services it offers are only accessible via my home network (https, imaps, there's probably more). Then, I am always on my home network. I started out with a different variation of this that was the same, except instead of using my (thankfully static) home IP in my MX record, I got some cheap hetzner/lightsail/whatever, then routed the incoming 25/587 across a 2 node wg network to the real mail server. It worked fine but ultimately I decided I'd rather expose my real IP in the MX record than pay $5/mo not to. Of course, the secret to making this work without tearing my hair out is that my outgoing mail server only delivers mail to the relay I pay to deliver my mail to the 3 or 4 corporate behemoths who have taken over a once great decentralized service. I have no interest in tending to my deliverability or making appeals to Microsoft or whoever. Also at a personal mail volume with 0 transactional mail, it's very inexpensive.
- oarsinsync 4y agoSome https services are vpn only. Some https services are internet exposed with http basic auth as a first line auth requirement. Some services are available to friends, or I want access to from devices I can’t VPN from.
- m348e912 4y ago>>First thought: oh, huh, a self-hosted CVE generator. Haha, same. I've run my own mail servers, got the tshirt, and don't want to have to do it again. Point your domain to one of a bazillian email services instead.
- foobarbecue 4y agoHm. Been running mailinabox since 2012 or so, no issues. I like the idea of consolodating executables a bit and simplifying the system, so I'll have a look at poste.io.
- fullstop 4y agoI've used https://mailu.io https://mailu.io. It works well, but your biggest problem is going to be getting over the spam filter hurdles of the email giants of the world. Even if everything is properly configured (including dkim / spf / whatever else they've added) your messages will get plopped in the spam folder.
- andix 4y agoMy experience is, that the „quality“ of the mail server‘s IP really matters. The worst experience I got was with digital ocean. A lot of providers just don’t accept email from their IP ranges. Some of them just completely block all DO IPs on router level, and refuse unblocking. For my current server I had to switch IPs a few times, until I got one that was not blocked by any of the major providers. Unblocking a once blacklisted IP seems to be practically impossible. And hotmail or outlook.com just mark a lot of email as spam. I see it now as a problem of the recipients. Office365 just accepts the same emails, it seems to be a strategy of the free mail providers, to give their non-paying customers a worse experience.
- fullstop 4y agoWe got a /24 at our data center and the reputation was, unfortunately, poor. I went through all of the public reputation lists and asked to be removed. It took about three months of incremental effort, but the reputation for the entire /24 is clean now. This is with a "real" mail server, and not mailu.io, but the idea is the same.
- andix 4y agoI just went to my cloud provider of my choosing and started to add floating IPs. After a few tries I got a good one. I went through the unblocking process once, and I decided not to do it again. Especially Microsoft gave me a hard time, they started to request documents and then let me wait a few weeks until they replied: we don’t unblock, and we don’t tell you why.
- 4y ago
- andix 4y agoI’m hosting mail servers for over a decade now. They are all very low frequency, so probably not a lot of attackers find them. I try to enable as many automatic updates as possible, because I don’t operate them professionally. Just every few months I check if all updates are installed, and if there is something wrong. So far I only had two hacked accounts (probably the users got phished or used compromised public PCs while logging in to webmail - the country of the attacker was the same where they were on holiday). So far no break-ins that I noticed. But it is for sure possible that somebody broke in without me noticing (and did nothing worth noticing).
- deltarholamda 4y agoRoundcube is a lot better. 2006 was a long time ago. It is a very good option for a webmail service if you're self-hosting.
- Fnoord 4y agoFunnily enough Roundcube isn't even one of the mail protocols. Its software connecting to the mail servers via a GUI over HTTP(S). You don't have to give the entire world access to your web server. You could even use something like AuthPF to allow yourself to access it. Or a VPN like Wireguard. I do the latter now, but I used to do the former. Although back then I just used Mutt over SSH usually. Way faster than the web software I ran back then (probably Apache with Horde). What remains is all the stuff required for sending and receiving email. SMTP, IMAP, and the stuff to deal with spam (some kind of tarpitting as well as SPF/DKIM). In fact even the IMAP server could run behind Wireguard. So its only SMTPd and SPF/DKIM. There are some very secure SMTPd written, with great track records. Back in the days I ran Qmail with Courier-IMAP but I don't think SPF and DKIM existed back then.
- sam_lowry_ 4y agoDovecot, Roundcube, ClamAV, Rspamd are all battle-tested and reasonable choices, but the choice of Haraka, a Node.js-based SMTP server, feels dubious. Why not exim or something similarly solid and well-understood?
- cvalka 4y agoPostfix
- dubcanada 4y agoWhat is wrong with Haraka it's like 10 years old?
- sam_lowry_ 4y agoNode.js
- dsr_ 4y agoI generally recommend replacing Roundcube with SnappyMail (https://snappymail.eu https://snappymail.eu) -- not having to deal with a database by not maintaining much state is a win. I was expecting to see Postfix instead of Haraka. I wouldn't have been very surprised at exim.
- rnk 4y agoThey do have a nice list of features: SMTP + IMAP + POP3 + Antispam + Antivirus Web administration + Web email, ...on your server in ~5 minutes I was running helm (a hardware device plus mail with many of those features) but they couldn't get anywhere in the marketplace.
- koen_hendriks 4y agoLooks very interesting, I'm currently looking for a replacement of Mailcow
- that_courtney 4y agoI feel like this solution is optimizing the wrong problem. The bulk of work with managing a mail server (these days) isn't software setup and admin. On the receiving side, it's all the work dealing with abuse and attacks. On the sending side -- and this is the tough one -- it's getting sites to accept your email. When I finally gave up managing my own mail server (about two years ago), I found that about every six months I was involved in some panic where some large mail provider (Microsoft and Google most frequently) decided they didn't want to accept email from my server. Solving these issues is neither easy nor quick. These days I'm very happy to pay somebody else to run email services using my provided domains.
- andix 4y agoNo, that kind of software optimizes a very important problem. It’s quite cumbersome to set up all components of a mail server by yourself. At some point you start hosting a domain for a friend. Then then friend wants to create some mailboxes, forwardings and so on by themselves. So you just give them SSH and tell them to edit the postfix config? Having a web interface that does it all and doesn’t break things is very important.
- richwater 4y agoWho does this...?
- andix 4y agoGiving out free email addresses to friends and family? Me. Hey, we are starting this charity and need email for 15 people, what should we do? - order domain, create admin-account in the web interface, pass it on, done.
- stonogo 4y agoThis problem is solvable without a web interface: https://manpages.ubuntu.com/manpages/bionic/man5/dot-qmail.5.html https://manpages.ubuntu.com/manpages/bionic/man5/dot-qmail.5...
- arthurcolle 4y agoIf I was running a service that required parsing emails from external sources, could I easily write a script that could parse inbound emails and then do $SOMETHING with them easily? If so, where would that sit in Poste?
- pharos92 4y agoI really have zero complaints or reason to move off Mailcow https://mailcow.email/ https://mailcow.email/
- Mazzen 4y agoEqually happy! Would recommend!
- stofzuiger 4y agoDoes not run on anything other than x64. Otherwise it's perfect.
- flangola7 4y agoWho is running a mail server on their phone?
- mcmcmc 4y agoProbably no one, but plenty of people run services on SBCs
- andix 4y agoIf you want to host email on your raspberry at home, your main issue is usually that your IP will be in a known „dial-up“ IP range, that is blocked by all major email providers. And most home internet providers block port 25 too. And you need a fixed IP, it’s a nightmare if your mail server‘s ip ever changes.
- jeroenhd 4y agoThis is also a problem for ARM servers. Oracle's free tier is quite generous, especially if you use their free ARM offering (4 * 1 core with 6GB of RAM, no time limit on the free offering), but you can't run Mailcow on it. This has been flagged on Github and the dev's response was "well, don't run anything important on a free server" and that was basically the end of that. I was pretty disappointed with that, but on the other hand there's nothing that prevents you from building the images yourself on ARM.
- andix 4y agoI evaluated it once, and ended up using https://mailcow.email https://mailcow.email I think the fact that it includes SoGO with Cal/CardDAV and active sync was the main reason, poste.io doesn’t seem to provide a solution for contacts and calendars. I’m still very happy with mailcow. And they include all features in the free version.
- stevenjgarner 4y ago>> User database is stored in SQLite database - in file How much of the configuration can be data-driven from SQL sources? Just the users? What about multiple domains? Aliases? etc. Something like the MySQL interface with PostFix [1] [1] https://www.postfix-tutorial.com/ https://www.postfix-tutorial.com/
- nik736 4y agoAny solution for CalDAV?
- jeroenhd 4y agoMailCow has CalDAV/CardDAV/ActiveSync support. They leverage Nextcloud for DAV support; you could theoretically set up a minimal Nextcloud setup to get *DAV support into this but you'll have to do it manually (and for some platforms you may need to add and configure an extra reverse proxy).
- sourcecodeplz 4y agoIf I want to send unlimited emails from my domain (not 500 max or 2000 per day) and I don't want to worry about hacks AND don't want to pay for overages, simple shared hosting is the (cheapest) way!?
- elorant 4y agoIt might be cheap but depending on the reputation of the hoster your e-mails will be hit or miss.
- gwbrooks 4y agoI know of no shared-hosting provider that doesn't throttle emails. The minute you're talking more than about 200 an hour, you're going to either host your own mail server or route through any of the dozens of commercial SMTP providers.
- JadoJodo 4y agoI _love_ playing around with (and sometimes actually) self-hosting stuff. But email is something that I will HAPPILY pay someone like FastMail or ProtonMail ~$5/mo to handle and avoid myself the hassle. It just works. I can add whatever subdomains/addresses/sending profiles/etc., and I don't ever have to think about data backups, blacklists, spam reputation, or any of the dozen other issues I've heard about since I became aware of how email hosting works in ~2006. Kudos to those of you in this thread who live the dream, though (really).
- zacharyvoase 4y ago> All passwords are by default stored as salted SHA512 hash (5000 rounds). Attackers will have hard time to crack your passwords. SHA512 isn't a good choice for this, because it's optimized for fast low-memory computation. Why not use bcrypt or argon2, which are industry-accepted best practices for password hashing?
- x3n0ph3n3 4y agoThis is why I configured fail2ban with my own poste deployment.
- themoonisachees 4y agoHow is f2b relevant to hash cracking mitigations?
- x3n0ph3n3 4y agoAt least it prevents remote brute-forcing.
- daneel_w 4y agoTheir rationale is probably because those two don't scale very well when you want to make their efforts count, whether bcrypt's hunger for CPU or Argon2's hunger for CPU and/or RAM. Bcrypt is very capable at bogging things down when you have lots of users authenticating very frequently, which is often the case with a POP3 server. A mere 100 e-mail clients authenticating every 2 minutes on average to check for new mail incurs a significant load even with a mild bcrypt work factor. On the opposite end PBKDF2 with 5000 rounds is much leaner, and if you enforce long passwords - which is immensely important no matter what password-hashing you use - then even fewer rounds are needed.
- zacharyvoase 4y agoWell if you want passwords to be difficult to crack if an attacker gets access to the hashes, you kind of just have to deal with it.
- wankle 4y agoI looked it over. If I were starting out today I might try it. I disagree with the usual horde of "ohh there be dragons in there" since I generally do not have blocking issues with deliverability. Gmail from my gmail to my personal email account the past couple of months can take anywhere from a minute to over an hour, that's been odd. Gmail from my gmail to one of my other gmail's or from Hotmail to my personal or from Yahoo to my personal are all fine. Delivering from my personal to my gmail has been fast and consistent. It's odd that from my own gmail to my own personal can sometimes be slow the past couple of months. Other than that though, I've found running my own server to be liberating to have the option. Probably doesn't mean anything any more but I feel good to be able to do it.
- _joel 4y agoDone mail admin for 20+ years at unis/ISPs etc.. still use fastmail for my personal stuff now.
- rkagerer 4y agoWas interested to learn more but the poor English in the first couple paragraphs of their page turned me away.
- jacooper 4y agoI think a focus on transactional email would be more rewarding, as landing in spam doesn't really matter(just tell the user to check their spam folder). Currently the best I have found is Postal.io, but its not really light.
- Avamander 4y ago> Currently the best I have found is Postal.io, but its not really light. Have you tried Emailengine?
- jacooper 4y agoDoesn't seem to allow direct SMTP connections/ isn't actually opensource.
- Avamander 4y agohttps://github.com/postalsys/emailengine https://github.com/postalsys/emailengine Seems open-source to me.
- jacooper 4y agoOpen source ≠ source available https://opensource.com/resources/what-open-source https://opensource.com/resources/what-open-source
- Avamander 4y agoYou should've said that you want libre software instead. A custom license doesn't really make an open-source project just source-available, you're granted plenty of rights as an user to use that source. Source-available would be much more restrictive than this.
- jacooper 4y agoAnything not adhering to the OSI definition of open source isn't open source, that's an official US court ruling. https://lwn.net/Articles/888291/ https://lwn.net/Articles/888291/
- ggm 4y agoUgh. Docker only. So again, people are basically rejecting any engagement with the [Net|Open|Free|Dragonfly]BSD world. iRedMail has exactly the same components, and from what I can see almost exactly the same flow logic, except its available on BSD platforms as well as linux.
- zhb 4y agoiRedMail author here (Zhang Huangbin). It's quite reasonable that vendors don't support BSD due to the input-output ratio. Maybe there're many BSD servers, but not many BSD EMAIL servers compared to Linux. Take some real numbers of some iRedMail release, when it's been deployed on 22832 linux servers[1], only 300 BSD servers[2] deployed. [1] Including Ubuntu 20.04 + 22.04, Debian 10 + 11, RHEL/CentOS/Rocky/Alma 8 + 9. [2] Including FreeBSD + OpenBSD.
- airhack 4y agoAgreed the real problem is getting other servers to accept your mails. While I can understand the paranoia, bottom line is that the number of domains that can successfully send mails is now seriously limited to a few big players who now have a virtual monopoly on emails. Which is not really good in my opinion...
- AceJohnny2 4y agoOfftopic, but have people had any success maintaining a personal email domain as forwarding to the major email providers? I have a vanity domain, and used to be able to use GMail to send email as that domain [1], and forward received mail from that domain back to GMail. But with SPF, DKIM, and DMARC (or something), this has broken and such received email gets marked as spam and/or phishing. I don't know how to fix the forwarding/receiving flow [2], because GMail will see the message coming from an arbitrary source, but being forwarded by an intermediate (my hosting provider's forwarding email server) which will fail its integrity checks. I have not been able to understand how to solve this. Clearly, forwarding servers aren't a well-regarded use-case in this new era of verified email flow. Also, I'm not just talking about GMail. I used to do forwarding for my family who used a variety of providers, so I can't just switch to GMail (via Google Domains) for my entire domain. [1] GMail still offers that feature, under Settings->Accounts and Import->"Send mail as" [2] the sending flow is easy: just add gmail's SPF to my own domain's
- georgyo 4y agoARC is what you need, it a similar signing as DKIM, but resigns a message. https://en.m.wikipedia.org/wiki/Authenticated_Received_Chain https://en.m.wikipedia.org/wiki/Authenticated_Received_Chain
- AceJohnny2 4y agoInteresting. I see a gotcha though: > Validating an ARC chain only makes sense if the receiver trusts the ARC signers. In fact, an ARC chain can be counterfeited,[3] so ARC processing applies when receivers trust the good faith of ARC signers, but not so much their filtering practices. Is there any documentation on how GMail and Hotmail onboard a ARC-using domain? Their documentation is very... sparse.
- Avamander 4y agoThe same way they're gathering intel on domain/IP trustworthyness.
- 4y ago
- hardwaresofton 4y agoHave written a bit about self hosting email[0]. I personally run: - Proton Mail (not self Hosted but for some addresses) - Haraka - Maddy For people new to self hosting email I recommend maddy over the usual postfix + dovecot [0]: https://vadosware.io/post/its-never-been-easier-or-harder-to-self-host-email/ https://vadosware.io/post/its-never-been-easier-or-harder-to...
- dingaling 4y agoA rather large caevat on Maddy: Note: IMAP storage is "beta". If you are looking for stable and feature-packed implementation you may want to use Dovecot instead. So at this point it replaces postfix.
- hardwaresofton 4y agoYeah it's "beta", but I've been using it for years at this point. That warning has been there for a while -- I don't think it's accurate at this point -- You can use SQLite or other DBs to hold your IMAP data: https://maddy.email/reference/storage/imapsql/ https://maddy.email/reference/storage/imapsql/ https://maddy.email/reference/blob/fs/ https://maddy.email/reference/blob/fs/ https://maddy.email/reference/blob/s3/ https://maddy.email/reference/blob/s3/ I've used all three of these actually (over the years -- more recently I've moved a bunch of my imapsql workload to S3-compatible storage on Backblaze) and they work great. If you're sending and receiving gobs and gobs of email maybe think twice, but for someone who is dipping their toes into self-hosting email maddy is one of the best choices out there. As usual YMMV, and back things up, if they are important to you.
- cosmojg 4y agoAh, whoops, based on that logo, I mistook this for a "Version 2" release of the venerable https://posteo.de/en https://posteo.de/en What advantages does this have over just running RoundCube myself? The things listed on the pricing page seem fairly superficial.
- Aloha 4y agoIt sure costs alot of money without solving the fundamental problems of email (getting others to accept your messages).
- throwaway892238 4y ago> All passwords are by default stored as salted SHA512 hash (5000 rounds). Attackers will have hard time to crack your passwords. Tell me you don't know about password security without telling me you don't know about password security > SMTP - port 25, 465 (TLS), 587 Tell me you don't follow RFCs without telling me you don't follow RFCs > https://poste.io/doc/license https://poste.io/doc/license you are allowed to run unlimited count of instances for your own use only you can't sell or distribute container images to third parties, every mailserver operator needs to have its own license Rather take the 3 hours to just set up all that FOSS software myself and give it away to everyone for free but thanks anyway
- anaganisk 4y agoAt least they are hashing and not storing encrypted passwords. But even a baby framework with may be 10s of deployments have switched to bcrypt, etc. Im not sure why they're boasting about SHA512. But I am a little lost on the RFC thing. Could you enlighten me. I thought they were standard ports for legacy,TLS, and SSL ports.
- imp0cat 4y agotldr; 465 is obsolete,you should not use it; 25 is for relaying mail between servers; 587 is the default mail submission port today.
- smorrebrod 4y agoIsn't 465 safer since 587 uses STARTTLS and STARTTLS can be downgraded?
- justsomehnguy 4y ago> since 587 uses STARTTLS and STARTTLS Technically yes, but for the last decade I've seen only one instance where 587 was explicitly STARTTLS (Fastmail), everyone else just running TLS on it.
- mike503 4y agoI used poste years ago and I enjoyed it. It doesn't magically fix DKIM/all that other crap but it was nice having something run perfectly "out of the box" from all the daemon perspectives.
- igtztorrero 4y agoI used PostalServer since 2019 in a VPS No error, No blacklist Perfect Solución !
- wyclif 4y agoI'd like to try it, but the landing page writing doesn't inspire confidence that this is a polished product. If the developers are reading this comment, I might be able to help tighten and smooth that out. I have 99.9999% English fluency and write at the highest calibre.
- withinboredom 4y agoThe only reason I’d host my own email these days is to run a globally distributed queue. Not for humans.
- rackthehacks 4y agoThank you for sharing.
- lormayna 4y agoI really like MOX approach: https://github.com/mjl-/mox https://github.com/mjl-/mox for self hosting email. A single binary, no web interface.
- kuon 4y agoMany people are saying it is hard to run a mail server, but I never had any deliverability issue with mine. The most important (well hard because I needed ISP collaboration) step was to get a reverse DNS for the IP. I am sending emails from a few domains, so not too much. And my volume is low (10 per day). I run openbsd and I mostly followed that guide https://prefetch.eu/blog/2020/email-server/ https://prefetch.eu/blog/2020/email-server/