3 ms·
This is exactly what I do. Debian + Postfix + rspamd. It basically runs itself, I login to the rspamd web gui every now and then and add a few hosts to the "tru
by muppetman 3y ago
This is exactly what I do. Debian + Postfix + rspamd.
It basically runs itself, I login to the rspamd web gui every now and then and add a few hosts to the "trusted DMARC" whitelist so they get a better score through rspamd, but I don't really need to do that.
I've been running it for ~5 years this way and it hardly ever lets a spam through (Very rarely the spams that are just images get through) and I've rejected 2 mails that I'm fairly sure were legit (just bulk marketing ones though)
People always say "Use Mailcow!" and I say "But why?". Adding the additional complexity of docker with the random firewall rules it adds, individual containers that need to be fed and watered. It's a mailserver, all the processes are doing the same mail related function.
Don't get me wrong, there's a very real place for Mailcow etc, but for a small end-user mailserver I think it adds overhead that makes running a mailserver more complex, not less.
Anyway, great in depth article.
- rbut 3y agoI've done both vanilla postfix, dovecot, rspamd, etc and mailcow. For me the reason I use mailcow is it's a few commands and I have a fully functional mail, calendar, and contacts server with a web UI. It can then be updated with a single update.sh. Using mailcow I don't need to mess around with virtual domains, connecting it to mysql, DKIM, etc which is far more than a few commands. I also get a nice admin UI, web mail and CalDAV and CardDAV which you don't get with the above. Also I'd consider the separate containers a good thing so that if rspamd, or clamav, for example, has a CVE they can't pivot to other parts of your mailserver.
- muppetman 3y agoYou make a good point, especially around isolation. While I use docker and I know the basics of it, I'd hate to try and debug it if something went wrong (i.e. postfix container wouldn't start). For that reason I've stayed clear of using it for "critical" life things, like our email. For a number of years there my wife's business email I was also sending through my mailserver, so it needed to be super reliable. I'm not saying docker/mailcow isn't reliable, only that if it did break in funky ways, I don't have the knowledge domain to fix it. But I'm familiar with all the individual programs and running them on a "flat" linux system, so that's what I did. But yes, you certainly make some good points that are worth considering if someone else is reading these comments and thinking about doing it themselves!
- nextgens 3y agoAs one of the maintainers of Mailu, I'd say use Mailu! Why? three main reasons: (a) security (as you have identified isolation matters, but that is not the only thing), (b) get the benefits of "battle-tested" setups and (c) features On security: in its default config, Mailu scans emails for malicious macros via oletools (and optionally viruses via clamav). It also uses a hardened-malloc, Snuffleupagus (a security module for PHP), gates all PHP code behind an authentication wall (webmails), ... and does both DANE and MTA-STS validation to ensure your emails are delivered to the right place. The authentication stack handles "smart" rate-limiting: you get to limit the number of authentications with distinct credentials over a time-period (a misconfigured thick client won't trigger it), you have plenty of ways to avoid running into it (application tokens for thick clients, per-device cookies that give you a way out, whitelisting of "used" addresses, ...) and you also get to rate limit the number of sent emails (useful if a spammer gets their hands on the credentials of one of your users) On the importance of "battle-testing" setups: well, there are plenty of non-subtle ways of breaking an email setup. Experience has shown that all the layers in the stack can be problematic... I can give you a bunch of examples of what we ran into recently if you want. On features: your setup might be simpler but your users are missing out. Whether it's enhanced filtering (like with oletools), better indexing (full text search), indexing of attachments (with OCR! via Apache Tika), configuring server-side rules with managesieve or just "having an interface" to configure ooo, change their passwords, configure aliases or delegate permissions. I have started spending time on Mailu because I don't like the bloat that comes with Mailcow. Give Mailu a shot; it is reasonably easy to debug when things go wrong (and not written in PHP :p).
- BLKNSLVR 3y agoI use Mailu and after some slight teething problems in setup it's been solid. In fact, I just added another domain to it.
- JacobSeated 3y agoYou could install a basic setup with a "apt install x x x" one-liner in ubuntu, and it would not take more than a few minutes to configure everything with sensible defaults. The key here probably is, most people don't want to spend time learning enough about Postfix, Dovecot. Etc. To do that.
- xyst 3y agomailcow mailinabox Just postfix + rspamd I’ll have to give self hosting a shot with one of my domains :)