5 ms·
Buy a domain on a service that allows API-based DNS updates. Put up a RPI at home. postfix + dovecot + roundcube should do the trick. Add FW forwardings for 8
by treffer 13y ago
Buy a domain on a service that allows API-based DNS updates.
Put up a RPI at home. postfix + dovecot + roundcube should do the trick.
Add FW forwardings for 80/443/25 (or allow IPv6 to pass through)
Update DNS records every N minutes. (cron, nsupdate, dyndns clients, amazon command line tools....). You will need SPF/DKIM.
The RFC for SMTP says Mail Servers have to retry for 7 days before giving up on mail delivery. This should be plenty for your home server. There are also commercial Mail relay and backup MX services (sometimes even as a free offer for buying domains on website X).
You can backup the SD-Card whenever you want. Your Mail stays at locations you control.
I currently have a root server, but I'm heavily considering "in-housing" those services because of the NSA activities.
EDIT: it's 7 days
PS: Some old firewalls block dynamic IPs for mail delivery. I'm not sure how common this is today, especially as SPAM and botnets have evolved a lot.
- ubercore 13y agoI think a lot of IP blocks show up in blacklists just by virtue of belonging to cable companies.
- josho 13y agoI've been running my mail server from my home for months. There is one block list that my IP range is on due to the nature of it running from my home. But, I tested with the big free providers and haven't found a single email provider that blocks me as a result.
- FiloSottile 13y ago> PS: Some old firewalls block dynamic IPs for mail delivery. I'm not sure how common this is today, especially as SPAM and botnets have evolved a lot. The problem is not that firewalls block dynamic IPs, but that a lot of mail servers, to deal with spam servers, started accepting mail only from some trusted smarthosts. So there might be some server that will reject your mails. (I don't honestly know how much SPF makes things better.) However, your ISP SMTP server will accept mail from its IP range (as they know how to find you if you abuse the service) and will relay mail for you. So probably your best bet is setup outgoing mail to go through it (Internet site with Smarthost, or something like that). Ah, and don't forget to setup your server for SSL!
- mindslight 13y agoMost ISPs block outbound tcp port 25, which is why you'll likely need to setup your ISP's smtp server as a smarthost for a consumer connection. FWIW running a personal mail server on Linode for 8 years, I've never had a remote mail server refuse acceptance due to my IP address not being on some protocartel whitelist. I have had a few annoying false positives from Mailavenger, but clearly that's not my config that's broken :>
- josho 13y agos/most/some/ If an ISP blocks port 25 then it means they'll have a bunch of support calls from people who's email client doesn't send email because SMTP is blocked. So, in my experience not many ISPs do that anymore. Besides it isn't actually an effective way to stop spam.
- mindslight 13y agoWell I currently see both Sonic.net and Verizon blocking outbound tcp/25, which is the extent of my limited sample. According to RFC4409, mail submission is supposed to be done on tcp/587 these days. And no matter how effective at actually stopping spam in general, I suspect tcp/25 is blocked out of a desire to not end up on IP blacklists due to botnetted customers.
- Taeram 13y agoIf you're okay having your outgoing mail go through another hop, something like mailgun.com has a free plan if you send less than 10k emails per month.
- deleted 13y ago[deleted]
- eps 13y agoDo NOT host at home. For one, this violates every second provider's ToS, if not every single one. For two, lots of providers block incoming SMTP connections on TCP/25. More importantly, they may start blocking it without notice and you'll have no clue that they did. For three, you will most likely end up on a RBL (blacklist) in no time solely because you come from a "consumer" IP range. I mean, hosting at home is technically simple, but in the end it created more problems that it solves. Get a hosted server and use it instead.
- treffer 13y ago1. My ISP send me a router that has a feature to host a internet accessible fileserver. Out-of-the-box. ISPs in germany do not promote home-hosting but they give you devices that do it. 2. Incoming / Outgoing TCP/25 blocking: Not a problem with ISPs in Germany. 3. Blacklisting: At most a problem if you send mails. Plus GMAIL requires SPF/DKIM for just about evey IP, so yes, you are on a blacklist unless you do some DNS magic. BUT once you do the magic it will override IP block - unless the other side has a shitty setup....
- eps 13y agoRe #3 - it is safe to assume that a shitty setup is a norm rather than an exception. Gmail is the exception. Everyone else just run postfix + rbl_filter and would have none of these modern SPF nonsense.
- kwhitefoot 13y agoNot everyone is in the US.