Live data from Hacker News

After self-hosting my email for twenty-three years I have thrown in the towel

cfenollosa.com

321–330 of 744 posts

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#321
post #285

In fairness, things like postfix usually ship with very poor (not to say “moronic”) defaults. Like, postfix won’t even try to connect to tls-enabled smtp for outgoing email by default, and you have to explicitly point it at the certificate bundle it’s supposed to consider valid. And you have to tell explicitly to reject incoming plaintext connections from the public internet. And quite a bit more… Like, why doesn’t p…

There are so many mesolithic defaults in email software. So many things have to be constantly reinvented. I really wish it weren't like that.

Things like Maddy (https://maddy.email/) aim to simplify all this. Really great potential, but they're still work in progress.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#322
post #308

Earlier quoted context omitted.

signup confirm emails are like that. similarly, any "hello pls add me to your allow-list" emails could be made auto-disappear to the "will be deleted in 30 days" folder in ~10-15 minutes, so even if you get a 100 spam messages per day you only see the last of those, you can easily pick what you are looking for, and don't worry about the rest, they'll just disappear. (and you still have 30 days to look for messages th…

signup confirm emails are not what i'm describing, because you need to establish and filter the initial offer that they send you via email itself, which is still prone to phishing. What I'm describing is a situation where users themselves have to proactively subscribe to a connection using some sort of out-of-band mechanism. For example, if a website wanted to send you emails, they could produce some sort of "connect…

This makes sense for service emails and is similar to how push notification services like Pushbullet work, but can't work for humans. You need to be able to give your email to someone IRL so they can send you a message. Mutual approval would be possible in the "we just met and want to exchange emails" situation, but that too breaks when you legitimately want to give anyone the chance to message you.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#323

Earlier quoted context omitted.

> It's just not something I want to babysit anymore because I have other things to focus on Dont know about you, but I have setup my mailserver years ago, and outside of regular OS updates, havent had to touch it.

Where is it hosted? Isn’t the primary issue being blocked by the major providers due to spam filters?

server4you.

there is one blocklist im aware of that simply categorically blocks all their IPs, but thankfully none of the "big tech" players use it, so its really of no consequence to me

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#324

Earlier quoted context omitted.

> It's just not something I want to babysit anymore because I have other things to focus on Dont know about you, but I have setup my mailserver years ago, and outside of regular OS updates, havent had to touch it.

How do you make sure your emails don't end up in spam?

i just have spf+dkim, nothing fancy

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#325
post #300

Earlier quoted context omitted.

> It's definitely an anticompetitive practice. Or maybe it's an overly competitive protocol? Like playing Monopoly. Even a neophyte can end sweeping the game despite not understanding any of the underlying mechanics that drive the game's outcome. Those remaining mail providers are also fighting back the insanity. They 'just' won. Don't hate the player, hate the game.

I wonder if we can’t build a far simpler postoffice app on http (self hosted domain space) and have a whitelisted encrypted exchange.

Of course we can, but good luck getting people to use it. They'll keep using what everyone else uses.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#326

I have had the exact opposite experience, I used mail in a box and set it up on digital ocean on a 5$ droplet. Have not had any spam or blacklisting issues and it was super easy to setup.

Part of the problem is silent deliverability issues. You can send to someone @gmail.com that you've never messaged before and it won't get rejected. It will probably end up in their Junk folder. You don't know it, they don't know it, and unless they check, which many people don't, it will be as if you never sent it.

>You can send to someone @gmail.com that you've never messaged before and it won't get rejected. It will probably end up in their Junk folder.

That happens even if you send from @gmail to @gmail. Well, it happened to me not long ago.

But I've mostly been using lesser known email providers and I haven't noticed any problems.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#327
post #291
post #259

Earlier quoted context omitted.

It’s just because of spam. All open systems that do not impose a cost to participate are destroyed by spam.

Spam has been a thing forever. Literally forever. Yet people have been dealing with spam far better than the big boys, and doing so for decades. Want to talk about anti-competitive? Gmail will accept mails, provide a 250 SMTP response, then drop the email internally. That's not right. At all. You can reject the email easily during SMTP exchange, and people have been doing that literally for 20+ years. No valid excuse…

Agreed. It's the increasing difficulty in getting things delivered to the big providers making it harder rather than spam.

At this rate, eventually we'll have a handful of mail senders (Mailchimp, Sendgrid), and a handful of mail receivers (Google, MS).

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#328
Not seeing anyone talking about email lists, now you need to buy a mailchimp type service, but many mailchimp type companies ban political customers if your not on their team.

Setup a private listserv or mailman use to be easy, but now you need to have a smtp provider in front, or you will quickly get blacklisted. Even then, get too big, and you will trigger some email email providers.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#329
Just did a test with my own mailserver hosted on a small-ish local vps.

Outlook: OK (had to bother with this one when I started out) Google: OK iCloud: OK

I have a pristine track record and not a single byte of outgoing spam so I cannot attest how easy is it to get back into the game after an incident. I do agree with the larger point being made here. It is clear some kind of anti racketeering legislation would be the only fix. Sadly, currently there is zero will from both the EU and the US to fix any of these blatant anti competitive issue on the internet.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#330
post #270
post #259

Earlier quoted context omitted.

It’s just because of spam. All open systems that do not impose a cost to participate are destroyed by spam.

True. But they are not calling for a completely open system. I like this proposal from the author. > Change blacklisting protocols so they are not permanent and use an exponential cooldown penalty. After spam is detected from an IP, it should be banned for, say, ten minutes. Then, a day. A week. A month, and so on. This discourages spammers from reusing IPs after the ban is lifted and will allow the IP pool to be cle…

> I don't mind doing some paperwork or paying a fee to prove I'm legit.

Then how about this: The big email companies all declare one day that any newly registered domain (with an MX record) needs to post a bond for good behaviour in escrow somewhere. If any of them find the domain being used to send spam, they can slash the bond (sending it to some charity or something).

This has the advantage that it doesn't affect any existing senders (so there's no one to complain about it), and it makes transparent the cartel-like power that these companies have over email. Perhaps, to democratise the process a bit, the ITU could organise a ballot (one vote per country) to elect 5 companies/non-profits who would have this bond-slashing power.

Unfortunately to implement something like this, they'd also probably have to demand that DKIM signing become mandatory (so there are cryptographic proofs of any evidence of spamming), and this sort of global consensus / money processing scheme would probably end up being built using a blockchain, whether that was a good idea or not.

Post reply on HN