Live data from Hacker News

After self-hosting my email for twenty-three years I have thrown in the towel

cfenollosa.com

351–360 of 744 posts

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#351
post #308

Earlier quoted context omitted.

signup confirm emails are like that. similarly, any "hello pls add me to your allow-list" emails could be made auto-disappear to the "will be deleted in 30 days" folder in ~10-15 minutes, so even if you get a 100 spam messages per day you only see the last of those, you can easily pick what you are looking for, and don't worry about the rest, they'll just disappear. (and you still have 30 days to look for messages th…

signup confirm emails are not what i'm describing, because you need to establish and filter the initial offer that they send you via email itself, which is still prone to phishing. What I'm describing is a situation where users themselves have to proactively subscribe to a connection using some sort of out-of-band mechanism. For example, if a website wanted to send you emails, they could produce some sort of "connect…

I know, but anything out of band won't really work, because that can be phished even more, plus as described above, there's no real need for it either (IMHO).

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#352
Of course it all started with spam. But the response was just as destructive. I worked for a small ISP (25K email customers) back in the mid-2000s, and it was so hard to keep email flowing. All it took was one random customer somewhere on our DSL who had a misconfigured open relay, and spamhaus would blacklist us. They wouldn't respond when we'd try to get the block lifted. We tried and tried to work with them to streamline the process, nobody wanted spam to go through our servers, but they weren't really interested in any cooperation. They were perfectly happy to stop all legitimate email if it stopped a single spam.

I don't work there any more, but I'd be surprised if that little ISP hosts their own email servers nowadays. It's so expensive to deal with such issues, it's just not worth it.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#353
post #160

Earlier quoted context omitted.

It definitely does not - you can allow different work loads for different senders. Mailing lists you actually want can be dropped to zero for instance. Most spam comes from new address pairs, not existing ones. Requiring high cost to get past a first-contact filter, then near zero forever after, is completely reasonable and would practically eliminate unsolicited spam.

But now the sender needs to know the receivers policy and if they remember that there has been contact before. Or I guess you change SMTP but we still allow unencrypted connections so good luck with that.

For newsletter style stuff, nah. The "confirm your registration" email can "pay" to get past the wall, and then you're done - approved pair established, future letters can probably be zero cost and everyone receives the same one.

I wholly admit that this is arguing theoretical setups and that's always problematic, but of course patterns would be established pretty quickly. There are loads of simple tactics that would still make spam dramatically harder, and legitimate use nearly unaffected. The current reputation system has clear, massive gaps that really don't need to exist.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#354
post #235
post #222

Earlier quoted context omitted.

You are totally missing the simple fact that the number of blessed email providers to choose from is slowly going down. I've seen ISPs with thousands of clients to give up and move the mailboxes to large players simply because their clients' email was ending up in the spam so often that running the support has gotten too expensive. It's definitely an anticompetitive practice.

Indeed. I host my domains with dreamhost and it turns out that outgoing mail from their servers will get marked as spam by Google. The exact same mail sent through a gmail address (whether under gmail.com or a custom domain) will be delivered no problem (although after the sudden closing of legacy free email, I found that emails that I had been sending via gmail with my own domain that had been getting blocked by spa…

The problem is your outbound mail server does not have a good reputation. You also probably do not have a large enough swath of IP space to prevent bad neighbors from becoming your problem. Lots of tricks to getting your email sent reliably to most mail servers. What got me out of hosting mail was trying to send an email to a potential lead I met at a local meetup. His email was hosted at some very small and relatively unknown university, but my email was flat out rejected. Something about that moment just clicked that it's not worth my time to chase down the admins and resolve the problem. I'll just start shunting my email through O365. I still selfhost everything else I can, but I offload mail management to a provider

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#355
post #282
post #21

The sweet spot for having control over your email while simultaneously minimizing unforseen headaches is to simply own your domain name and point the MX record to whatever hosting provider you want instead of self-hosting a server at home. Same philosophy for exposing a your personal blog of html files or content like mp4 videos. The sweet spot is to focus on buying a domain name you control. Then let Amazon S3, or C…

> The sweet spot for having no forth amendment protection for your email because its stored by a third party.

Most emails are still going through servers owned by Microsoft or Google, so what does self-hosting email accomplish in reality? Some government entity likely has warrant-less access to most of your emails regardless. I like email as a way to communicate, but speaking pragmatically, it’s just not a secure means of communication in 2022.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#356
OP Carlos Fenollosa mentioned this:

> Over time I realized that residential IP blocks were banned on most servers. > You just cannot create another first-class node of this network. > Email is now an oligopoly, a service gatekept by a few big companies which does not follow the principles of net neutrality.

It's unfortunately true. However, the reason that how we end up like this is more nuanced than just the big players trying to power grab (perhaps) but rather because of the rise of spam/scams/phishing/malware. All big players like Google (Gmail), Microsoft(Outlook/Live.com/Hotmail), Yahoo!, Apple (iCloud) are suffering from those threats, wasted bandwidth and compute on spam detection heuristic AI.

There are industry consortiums like Spamhause and commercial entities like Barracuda to maintain blacklist/whitelist to restrict access of major MTA network interconnect to fight off spams/malwares/phishing/malware delivery from botnets and individuals. And it helps, at the mean time, it consolidated the control of who can send outbound emails.

We are seeing this trend repeatedly in other communication channels like phone calls (due to robocalls, VoIP numbers are being blacklisted by all major players' services) or Text messaging (due to spam texts, major U.S. wireless carriers band together established Campaign Registry to control who can mass send outbound text messages. This is also known as 10DLC registration).

I think the vulnerabilities of previous communication protocols (email, VoIP, SMS/MMS) lie in the fact those protocols are designed with security in mind. Modern community protocols like Push Notification has been designed with security in mind, which make it less susceptible to abuse and spamming. That's probably the way go forward.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#358

Just did a test with my own mailserver hosted on a small-ish local vps. Outlook: OK (had to bother with this one when I started out) Google: OK iCloud: OK I have a pristine track record and not a single byte of outgoing spam so I cannot attest how easy is it to get back into the game after an incident. I do agree with the larger point being made here. It is clear some kind of anti racketeering legislation would be th…

My experience is that Outlook will accept email from a new IP ... for awhile. But rather quickly they block it. I think they watch for a commercial amount of traffic, enough to get a reputation from various services. Not enough traffic for a reputation? Very suspicious, adios... How else would legit commercial email senders bring up a new server?

From the MailOp commercial mailers mailing list, it seems Outlook will eventually unblock you, but you have to keep appealing, etc., for multiple rounds.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#360
post #250

I've been hosting my mail for 20+ years now, with minor issues. I guess I've been lucky. Reading the comments here makes me incredibly sad. Every answer that tells me to use a provider misses the point. The Internet was created so that there could be many independent nodes, not so that everybody has to rely on one of several blessed providers. I should be able to run my own E-mail. The real problem is lack of incenti…

The problem is that collectively we love 'free' (at the point of sale) so much that we'll gladly allow gmail to just walk in and own almost the entirety of the email infrastructure. Then later we realize this gives them the ability to unilaterally make the rules, and we complain. But it's too late.
Post reply on HN