3 ms·
Should probably have a [2019] tag, as things do change through time. I always enjoy the self-hosting explanations. Starting with mail is an interesting choice
by hnbear 2y ago
Should probably have a [2019] tag, as things do change through time.
I always enjoy the self-hosting explanations. Starting with mail is an interesting choice though. It's relatable to most people, but also very complex compared with a tougher DNS setup, DKIM, SPF, all that stuff.
I'm not sure what the right approach is to maintain good security, and then open up the right ports for simple services.
- easterncalculus 2y agoI do wish this article had talked about SPF.
- brongondwana 2y agoSPF has challenges with shared infrastructure - if you are sending from a large service and using SPF then anyone else on that service and spoof you unless the service has outbound controls to restrict which addresses you can send from. Fastmail had to implement this a few years ago ourselves, after 20 years of allowing whatever, we had to start by auto-whitelisting all the addresses people were sending from for a while, then slowly start introducing a requirement to prove control of the sending address to add new sending addresses over time! Obviously hosting your domain with us gets you auto-approved for any address on that domain, but otherwise you either need to confirm that you can receive email at an address to send from it now. But SPF by itself is pretty flawed. I'm keen to write more about DKIM2 when it gets chartered at IETF (hopefully) and we can post more public documents, but it should supersede SPF/DKIM for most uses.
- stackghost 2y agoThe ISPMail tutorial from workaround.org is the gold standard for "host your own email" and has been for years.