3 ms·
I've read that advice, about not hosting your own email server, every week for a few years now, but at least for anyone with a few years of self-hosting experie
by tupolef 3y ago
I've read that advice, about not hosting your own email server, every week for a few years now, but at least for anyone with a few years of self-hosting experience I would disagree.
There is just a little more checkpoints than 15 years ago. Before, you needed to check your reputation on spamfilters, be careful of viruses and sending rates and dome basic DNS entries.
Nowadays, check that your IPs are clean, subscribe to some monitoring for ip/domain reputation, host your own dns server and correctly use IPv6, DNSSec, Rspamd, Dkim, Dmarc, Spf, autoconfig/autodiscover.
But when it's in place there is nothing special to update or debug.
I would suggest to check ISPconfig as a semi-DIY solution.
- 8fingerlouie 3y agoI'm not saying it's hard if you know what you're doing, but "correctly use IPv6, DNSSec, Rspamd, Dkim, Dmarc, Spf, autoconfig/autodiscover" is a lot of technology for simply sending and receiving email. Considering that emails are insecure by design, and any email will have at least 2 participants, and you have no control over where the remote participant sends/receives emails, self hosting for privacy concerns is also pretty much pointless, except of course if you encrypt emails, but then the server doesn't matter anymore, and you might as well just use a public provider. My argument is that by using a custom domain with a public provider, you will get almost all the benefits of self hosting emails, but none of the disadvantages. You're still in control of your domain, and even if your provider shuts down, you're just a couple of MX records away from your new provider.
- tupolef 3y agoYou're right about the difficulty and the privacy, but I hope that people will still host their own little part of internet. The fundamental parts that you can host universally today are still a website and a mail server. Everyhing else like fileservers, webapps, federated services, streaming, vpns, game servers... have multiple implementations and evolve rapidly every year. If people no longer host the most fundamental services, it's leaving the play field to the industry. And one day we won't even be able to do it anymore.
- 8fingerlouie 3y ago>If people no longer host the most fundamental services, it's leaving the play field to the industry. While i tend to agree, i also fear that this exact phrase is what is keeping email in the dark. Email in it's current form is old, very old, and everything "modern" about is DKIM, SPF, etc, has been added in the form of X- headers, but besides that, nothing much has changed, and because it needs to be compatible with potentially decades old software, nothing much will change. At the same time, email has been crucial to business/industry needs, and while alternatives exist, they kinda feel like the "instant messenger" days of the early 2000s, where there were a dozen or more different instant messaging networks, and you needed an account everywhere to be able to talk to people. Just look back at 2020 and COVID. How many different "Collaboration" platforms did you sign up for just to be able to work ? Teams ? Zoom ? Slack ? Discord ? How many of them are open standards ? How many different mail providers did you sign up with ? (making spam catching accounts for collaboration platforms doesn't count). Email is in dire need of a complete rework, but with so many different implementations of both servers and clients, that is not likely to happen fast. By "reducing" the number of participants, it allows changes to the standard to be more radical, and allows for faster propagation of those changes. As it is now, those changes can only be small, and must be iteratively rolled out. Many of the proposed addons like DKIM has almost a decade behind it (if not more), and it is still not mandatory. Email needs an "email 2.0" which breaks compatibility with older versions. Is this not an issue for the web then ? Well, despite having a relatively small amount of browser implementations, as well as a relatively small amount of web server implementations, at least compared to email, if you look at HTTP 2.0, that also took a long time to roll out, but i assume because HTTP has had a couple of decades less than email, the problem is not as widespread yet.
- tptacek 3y agoMost deliverable domain names aren't DNSSEC-signed. Does anyone here have good information about the impact of signing on deliverability? It wouldn't surprise me if it was used as a signal somewhere, since DNSSEC adoption is so small and signing selects for the fussiest networks.