6 ms·
Selfhosted Email by Maddy on Oracle Cloud
- mndgs 3y agoGood God, the length of the text ..
- tomgs 3y agoLove the intro to self-hosting your email, but aren't you going to be flagged as spam by the main providers anyhow?
- Banditoz 3y agoYou can partially mitigate it by making sure DMARC, DKIM, and SPF are configured right. There are tools online you can use to verify they're setup right, don't remember which sites though.
- goku12 3y agoI have used mxtoolbox.com in the past. However, I don't know how reputed they are. Note that the 'big mail providers' won't accept your mails even after you apply every known trick in the book. This is especially true for the two biggest ones that provide free services and hosted services on customers domains.
- teddyh 3y agoJust off the top of my head, I would suggest using the “Test your email” tool at <https://internet.nl/ https://internet.nl/> for testing incoming e-mail, and <https://www.learndmarc.com/ https://www.learndmarc.com/> and <https://www.mail-tester.com/ https://www.mail-tester.com/> for testing sending e-mail.
- mjl- 3y agoI would also suggest https://www.email-security-scans.org/ https://www.email-security-scans.org/ for testing outgoing emails.
- teddyh 3y agoOthers for testing outgoing e-mail which I have saved, but don’t regularly use: • <https://www.checktls.com/TestReceiver https://www.checktls.com/TestReceiver> • <https://www.helloinbox.email/ https://www.helloinbox.email/> • <http://isnotspam.com/ http://isnotspam.com/>
- teddyh 3y agoIf, by “self-host” you mean “hosted by the cheapest VPS I could find, using an IP address range from the wrong side of the metaphorical rail road tracks”, then yes. If by “self-host” you mean “hosted by myself in a server rack in my house, possibly using a VPN to a respected IP connectivity provider”, then no.
- fiddlerwoaroof 3y agoI’ve had pretty good luck running my own on digital ocean for several years now.
- unclet 3y agoActually, I have tested sending mail to Gmail or other Mail Service Provider, and have not found any one flagged my email as spam.
- teddyh 3y ago> And the finally ~all means if the sender connect fullfill the rule of SPF, the email delivered should be move to trash. No it doesn’t. “-all” would mean that. What “~all” means is that it merely suggests that the mail might be invalid. Or, to quote RFC 7208: A "softfail" result ought to be treated as somewhere between "fail" and "neutral"/"none". The ADMD believes the host is not authorized but is not willing to make a strong policy statement. Receiving software SHOULD NOT reject the message based solely on this result, but MAY subject the message to closer scrutiny than normal. The ADMD wants to discourage the use of this host and thus desires limited feedback when a "softfail" result occurs. For example, the recipient's MUA could highlight the "softfail" status, or the receiving MTA could give the sender a message using greylisting [RFC6647], with a note the first time the message is received, but accept it on a later attempt based on receiver policy.
- teddyh 3y agoQuite a lot of typos. “platintext”? > The p= means the police. Whoop whoop.
- unclet 3y agoFixed. Sorry, I am not a native english speaker.
- teddyh 3y agoMore typos: ”Staic”, “domian”, “PRT record”, “fullfill”, “ploice”, and “intrested”.
- unclet 3y agoFixed, again ;-) thank you very much :)
- benrapscallion 3y agoLots of singular/plural errors as well. Might run the text through Grammarly or ChatGPT to rectify those.
- teddyh 3y agoMentions, but does not cover, DANE and TLSA. It does cover the stupider alternative, MTA-STS, which is basically DANE for people who are politically against DNSSEC.
- xyzzy_plugh 3y agoI don't know, I find that most people are against DNSSEC for non-political reasons. Did Chrome drop support for political reasons? No. Covering MTA-STS is practical. The fact they do so wins them points towards having built something that works in the real world.
- teddyh 3y agoChrome has no business “supporting” DNSSEC in the first place; it should all be handled by the operating system and the resolver. So I don’t think this is a point against DNSSEC. My guess is that people are against DNSSEC because it’s difficult. You know how people are saying “It’s always DNS”? People hate dealing with DNS, because they don’t understand it. And DNSSEC is then another dimension of difficulty on top of that. But DANE is clearly the technically better solution. I mean, MTA-STS requires a file to be served from an HTTP server to even work. So now you need an HTTP server in addition to your SMTP server! In any case, you should not, probably, deal with DNSSEC yourself! Note how the article does not cover running your own DNS server, but instead vaguely talks about editing DNS records. And if you have your DNS hosted by somebody else, DNSSEC is their problem. And once you have DNSSEC provided for you, you can use DANE and TLSA records without issue, without having to host an HTTP server for MTA-STS.
- mjl- 3y agoTo protect my email with DANE, I ended up running DNS myself. I used to be at AWS Route53. It supports DNSSEC (but quite user-unfriendly). But it does not support TLSA records (!). I'm still curious why, though Route53 is giving off a vibe of being frozen in time (a long time ago). Anyway, modern bind or knot take care of the keying part pretty much automatically (this made DNSSEC harder in the past). Just add records to the zone file, reload zone. DNSSEC signing is automatic and changes propagated to secondaries. I agree with you that DANE is a better solution. MTA-STS adding a webserver and HTTP libraries to email as requirement is a bit much. Also, where DANE is per MX host, MTA-STS is per recipient domain, requiring a TLS certificate for each (operationally not great when you're hosting many domains). MTA-STS also relies on mail servers keeping track of historically retrieved policies, which must be refreshed in the background. And if a first connection attempt is intercepted (falsely getting told no _mta-sts DNS record exists), there is no protection. This isn't possible with DANE.
- teddyh 3y ago> If you need a web interface, you may be intrested in Roundcube or Squirrelmail. I thought RainLoop was the new hot thing. (<https://www.rainloop.net/ https://www.rainloop.net/>)
- rascul 3y agoI understand Squirrelmail to be basically dead for over a decade.
- teddyh 3y agoIt was removed from Debian in 2016. But there seems to be some recent activity: <https://squirrelmail.org/ https://squirrelmail.org/>, <https://sourceforge.net/projects/squirrelmail/ https://sourceforge.net/projects/squirrelmail/>
- tmikaeld 3y agoThis seems risky, Oracle Cloud shuts down VPS they deem to be "inactive", in other words, not under any load or traffic. This would fit that category.
- sodality2 3y agoThey also shut down the VPSs they deem to be “too active” as in using too much resources, if you’re on the always free tier
- SXX 3y agoThough there are no other cloud hosting providers that give you VPS with public IP and 24GB RAM for free. Oracle did shutdown my VM like 2 times in 3 years, but considering I paid them $0 it's borderline awesome service.
- sodality2 3y agoSounds like you got further than me, they simply permabanned my payment information (also cannot complain too much since i didn’t pay a dime either, but seriously?!)
- SXX 3y agoIDK, their support is pretty responsive and the only requirement they have is that you must sign up using actual credit card and not some prepaid / debit one.
- unclet 3y agoHave you upgrade from the always free plain to the Pay as You Go subscription?
- SXX 3y agoNo I did not, but I dont host my mail on their servers either. I still used it quite extensively and it's far more reliable than 99% of cheap cloud providers. I mostly use them as my personal build server and VPN.
- wiradikusuma 3y agoAsking again here (different thread) but still about email: Is making email hosting with cute name still a thing? I own a couple of cute domain names (something like love.com or pretty.com, but obviously not those), so I'm thinking if I can do a hotmail on those domains.
- deleted 3y ago[deleted]
- teddyh 3y ago> apt-get install gcc libc6-dev make Note: There’s an easier, more canonical way to do that: apt install build-essential
- averageRoyalty 3y agoQuite a lot of critical responses here. Personally I think this is a great write-up. Most people in tech these days appear to look down their nose and say 'oh no, you can't host your own mail server anymore'. This write-up goes to show that it's not as complex as people seem to think. I'd be curious to see a follow up from the author to address the other claim of this crowd - that the big mail providers mark you as spam due to no existing reputation on the IP, despite all the processes and policy being correct.