6 ms·
>The main thing I'm hoping to recover is the webmail (I think) service most of my family used. That went down in September, and we've lost access to a number of
by jasode 3y ago
>The main thing I'm hoping to recover is the webmail (I think) service most of my family used. That went down in September, and we've lost access to a number of other accounts because of that.
At first, I self-hosted email on home server. Paid extra for a dedicated IPv4 address in the cable broadband bill at a residence.
I then started dealing with critical business emails, and a single server at the house is not reliable for that so I migrated to semi-self-hosted by paying for business-class email package. I still use my custom domain and point the DNS MX records the the hosting company's server. That was 15 years ago and had a few family & friends also use that for email.
But I'm now in the process of getting everyone off my email server except for me and migrating them to GMail and Microsoft 365 Outlook. They need simple reliable email and my 1-man-army of IT staff (me & myself & I) cannot support them if I'm in the hospital for a month.
My custom email setup has "too many moving parts". There's a login in at the registrar to constantly renew the domain. And there's another login at the hosting company and pay that yearly bill with a credit card. There are multiple points of failure. I'm the proverbial "if he gets hit by a bus" problem: https://en.wikipedia.org/wiki/Bus_factor https://en.wikipedia.org/wiki/Bus_factor
No, I can't write up some documentation with screenshots so they know how to navigate the process at the registrar and hosting company. E.g. if they try to login from their "unrecognized" computer to takeover email administrator tasks, a 2FA email confirmation with random 6-digit code would be sent to guess where? To _my_ email, not theirs. The interconnected dependencies are complicated and invisible because the recovery procedures are not stress-tested. Besides, the web UI changes constantly at those companies so the "oh shit what do I do" documentation would quickly get out of date anyway.
The redditor's story just reinforces my decision to not let people depend on my email server anymore.
If you're hosting email for family & friends, carefully think through all possible failure modes so they're not in trouble if you're not around.
- ryandrake 3y agoThere doesn't seem to be a good solution. Self-Hosting E-mail requires a high degree of technical wizardry, but relying on a cloud E-mail host means you are one inadvertent TOS violation away from losing access to your entire identity (all password reset features ultimately rely on access to E-mail).
- ok_dad 3y agoHow often do people break a TOS? I’m not sure that’s a problem normal people should worry about. There’s always a TOS, whether it’s at the email service or the ISP or the data center.
- gjsman-1000 3y agoI don’t know why this is getting downvoted. If you self-host your email, you are still beholden to your ISP’s TOS. Maybe it’s an improvement because it’s less likely you’ll be found infringing, but it’s still quite real. Let’s not forget your domain registrar either…
- ryandrake 3y agoIt seems every couple of weeks we have a new "I was banned by $COMPANY_X and lost access to everything! They won't tell me why." HN article. It's probably rare, but happens often enough and the consequences are severe enough that it's a risk worth considering. It's likely a lot more rare to get banned from your VPS or ISP than it is to get banned from something like Google, since who knows what the rules are there? Your kid could upload an inappropriate video to YouTube or something, and they'll associate IPs with your account and suddenly you lose access to Gmail.
- amatecha 3y agoYeah, it just happened to me a while ago. Banned from an online game inexplicably, for something I am absolutely innocent of. Their support team refused to do anything, assured me "the ban is correct". Only got lifted because of knowing someone who knew someone and was able to have it actually looked into, rather than the usual non-investigation you'd typically get. I know numerous people who have lost their entire Microsoft or Google account (or other services), with zero explanation, zero recourse, just everything permanently nuked. This can happen to anyone at any time, as erroneous false positives happen seemingly arbitrarily.
- layer8 3y ago
- nytesky 3y ago1Password allows you to share login credentials and stores/generates TOTP which can be used across multiple users/machines. A Yubikey as 2FA is another good option but that is not widely supported yet. Add another phone line for a phone that stays home and is the 2FA phone (or a Google Voice to a shared email account, with all family members phones as the Gmail 2FA, since it supports multiple phones) #1 rule, pay for domains out the full 10 years, every year, everything else is gravy. As long as your estate owns the domain, things can be fixed even if some mail is lost. They have a decade to sort it out ;)
- didip 3y agoI am with you. The last few years I tore down all of my self hosted solutions (except Homebridge) and move all family members to SaaS and I just pay for everything. * All mails are on Gmail or iCloud. * All backups are on Dropbox and iCloud. * All photos are on iCloud shared folders. * All passwords and secret notes are on 1password. And I made sure that I am not the only admin. Life is simpler this way. I wrote detailed instructions on how to recover all these in my will in 1password.
- tmountain 3y agoWe did estate planning. The first page of our family trust is the 1Password recovery page and information about critical accounts. Train your immediate family on what to do if the unexpected renders you useless.
- zrm 3y ago> a 2FA email confirmation with random 6-digit code would be sent where? To _my_ email, not theirs. So you set up an email account specifically for those, and put the credentials for it in the documentation. You probably want that to be hosted somewhere else though, because needing the code to access your email system so you can get the code is not a fun kind of circular dependency. That's not limited to self-hosting though. You lose your device and therefore the saved password for Provider A, to reset it they want to send a code to Provider B, to sign into that they want to send a code to Provider A. 2FA circular dependencies are actually kind of a scourge.
- jasode 3y ago>So you set up an email account specifically for those, Sorry I wasn't clear. I wasn't looking for a "solution". I was trying to explain how one can be blind to future failure scenarios (e.g. 2FA behavior is just one example) and thus, the "admin procedures documentation" can be inadvertently flawed. It's because the owner never had a 2FA verification email for years and so completely forgets that their friend will get an unexpected 2FA random code request in the event of a disaster recovery. I edited my comment to hopefully make that more clear. >The interconnected dependencies are complicated and invisible because the recovery procedures are not stress-tested.*
- zrm 3y agoWhat I'm asking is, how is this unique to self-hosting? You set them up on Cloud Email and it asks for a phone number to create an account, then they find out some debtor used to have their phone number and they're getting calls from debt collectors, or they move and want a number in their new area code, so their phone number changes. No one thinks to update it with the email provider until they insist on sending a code to the phone number you used to sign up ten years ago. Or you set it up for them and it prompts for a backup email, which they don't have because the one being created is their only one, so you use yours thinking something is better than nothing, and now they still need the code sent to yours. How does the hosting method affect any of this?
- crooked-v 3y ago> E.g. if they try to login from their "unrecognized" computer to takeover email administrator tasks, a 2FA email confirmation with random 6-digit code would be sent where? To _my_ email, not theirs. It's infuriating how everyone in the world is doing this forced 2FA stuff now.
- sokoloff 3y agoI spent 15 minutes this morning trying to get a family member access to a code/URL to verify their email address that wasn't being forwarded by the family mail server I run. This happens to me a few times per year and is enough of a hassle to get me to want to get off of this forwarding service.
- calamari4065 3y agoTen or fifteen years ago I set up an email server on a cheap VPS for myself and my then-boyfriend. It took some doing, but I got it reliable enough that we both used it as our primary email. Today I'm married to a different person and still administering email for my ex. Out of everything that came of that relationship, I regret the email server the most.
- herewulf 3y agoUh, did the court order you to administer e-mail in perpetuity? Sounds like it's high time to put your foot down.