Live data from Hacker News

After self-hosting my email for twenty-three years I have thrown in the towel

cfenollosa.com

411–420 of 744 posts

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#411
post #21

The sweet spot for having control over your email while simultaneously minimizing unforseen headaches is to simply own your domain name and point the MX record to whatever hosting provider you want instead of self-hosting a server at home. Same philosophy for exposing a your personal blog of html files or content like mp4 videos. The sweet spot is to focus on buying a domain name you control. Then let Amazon S3, or C…

This is what I do, though I do think helm is also pretty cool: https://thehelm.com/products/helm-personal-server-v2?variant...

I like the idea of having a node I can just plug into my network. I run my Urbit on a Mac mini with tailscale (which works great).

The core of what he writes about is correct though, email failed to be truly peer to peer (as imo all non-urbit-like federated systems will) because of the incentives that lead to centralization (spam, difficulty of running nodes, etc.)

We’re suffering the consequences of the local max we’re trapped in currently because of this. The promise of the 90s internet was a bunch of people using decentralized services they controlled - instead we're primarily thin clients connecting to a small handful of powerful ad companies. We're mostly serfs [0] allowed access if we give up our data for ad targeting, follow EULAs nobody reads, and don't say anything the company earls disagrees with.

[0]: https://zalberico.com/essay/2020/07/14/the-serfs-of-facebook...

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#412
post #344

Earlier quoted context omitted.

Whitelist is easier. If I added an mail of a friend in this system, we can communicate. Everything else goes blackhole. Nothing is easy about email! Having worked for years just to get reliable in and outboxes is definitely not trivial. Also SMTP is a system out of your control if you want anything verified and actually delivered.

Of course whitelist is easier, but how valuable would your email be if you only allowed your friends to email you? Goodbye order confirmations, subscription reminders, recruiter emails, notifications…

Sounds like a dream, really. And you could always have it be user-driven action, like "Copy this line and paste it into your email provider's whitelist", framing it as a positive win for the user since they have total control over who is allowed to communicate with them.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#413

Earlier quoted context omitted.

The problem is your outbound mail server does not have a good reputation. You also probably do not have a large enough swath of IP space to prevent bad neighbors from becoming your problem. Lots of tricks to getting your email sent reliably to most mail servers. What got me out of hosting mail was trying to send an email to a potential lead I met at a local meetup. His email was hosted at some very small and relative…

It's more than that. I'm on a mailing list for a social organization that I've belonged to for 20 years, and has been hosted at the same place for all of that time. I have marked hundreds of the messages not spam, and still Google sends about 80% of them to spam. Google does not care even if you have regular correspondence with an address -- if the server isn't big enough, it's going to spam. The user's wishes or ide…

I'm surprised that you didn't just whitelist the email after the repeated ham events...!

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#414

Earlier quoted context omitted.

Of course whitelist is easier, but how valuable would your email be if you only allowed your friends to email you? Goodbye order confirmations, subscription reminders, recruiter emails, notifications…

Sounds like a dream, really. And you could always have it be user-driven action, like "Copy this line and paste it into your email provider's whitelist", framing it as a positive win for the user since they have total control over who is allowed to communicate with them.

Seems like you could easily do this yourself with a couple of rules in your email client.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#415
post #273

Earlier quoted context omitted.

So VMC isn’t optional?

Is it that difficult to grasp that there's a "depends" option between "optional" and "not optional"? Nobody really forces you to use HTTPS either, it's not a "monopolizing" standard if someone doesn't trust you without. And again, if you have a way of establishing just as much trust without such a labour-intensive/expensive verification process, please do share.

> Nobody really forces you to use HTTPS either

Yet, in practice, that is exactly what both Chrome and Firefox are trying to do.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#416
This is pretty much exactly the reason I stopped running my own mail. I had the mail host on a static IP, part of a block of "pristine" IPs from a local colocation operation (iNOC in Albany, NY). Ran fine for years, but I started having to call more and more customers about "why haven't you answered my email from two weeks ago?" only to find out I ended up in the spam bin. Wasn't worth it when the risk was losing business.

I moved to Proton Mail as I like their simple interface and support their goals. Pretty good service so far, worth paying for, but I do sort of miss running my own services.

If you run your own mail server in 2022, you are the resistance.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#417
post #263

Earlier quoted context omitted.

Can you please provide a few references to that claim?

https://gpgtools.org GPG Mail is a paid for add-on, but it works and it works well.

It's not a paid add-on... GnuPG is open source. They are selling a support plan in case you need help with open source.

Here is the same thing, without the paid support. https://github.com/Free-GPGMail/Free-GPGMail

- GPG Suite was released under an Open Source license in the past. Is that stil the case?

You GPG Suite including GPG Mail is still going to be released under an Open Source license.

- Am I still allowed to compile my own version of GPG Mail / GPG Suite removing any code regarding the trial or activation?

You absolutely are, the GPL makes sure of that. You will find the source code on this website next to the download link for GPG Suite.

We would kindly like to ask you not to use our names or icons if you plan to publish a binary for others to use. Also please do not release any complete installers as that may suggest that they are official releases.

https://gpgtools.org/faq

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#418
post #235
post #222

Earlier quoted context omitted.

You are totally missing the simple fact that the number of blessed email providers to choose from is slowly going down. I've seen ISPs with thousands of clients to give up and move the mailboxes to large players simply because their clients' email was ending up in the spam so often that running the support has gotten too expensive. It's definitely an anticompetitive practice.

Indeed. I host my domains with dreamhost and it turns out that outgoing mail from their servers will get marked as spam by Google. The exact same mail sent through a gmail address (whether under gmail.com or a custom domain) will be delivered no problem (although after the sudden closing of legacy free email, I found that emails that I had been sending via gmail with my own domain that had been getting blocked by spa…

As a counterpoint, I host a couple of domains with Dreamhost and have had no such issues. They've been serving the email for my main domain for 15 years and AFAIK I've never had any of those emails go directly to spam within Gmail or elsewhere. I do periodic smoke testing by sending test emails to different place, plus I have a reasonable number of external users making use of the domains for email as well. FWIW I moved all my DNS records to Cloudflare, but that was only in last couple of years.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#419
I self host my private email server since 2005. Never had big problems. One time my server was wrong configured and then marked on spamhaus. Just fill in a form and all works fine again. Maybee gmail will blacklist me in some weeks, but fuck you gmail, I have nearby no one that uses a gmail account. I had in all this year no problem with any other peer. So, maybee the writer has just a malconfigured mailserver or don't know that he is marked on spamhaus because any reason.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#420

Earlier quoted context omitted.

> responsibility for spam (and other kinds of abuse) can be delegated via simple reputation scoring for netblocks, sender authentication and a proper feedback mechanism along the chain. Are there any real-world examples of this? I know other decentralized networks like Tor and BitTorrent have some sort of reputation and feedback system. What type of "spam" do they deal with and how well do they deal with it? Are ther…

As a practitioner, I can tell you that this proposal would be quite a bit behind state of the art for email spam filter accuracy. For example, there's a surprising amount of legitimate mail that gets sent without authentication, and which you don't want to block because your end users will get mad if it goes missing. I may also point out that "reputation scoring for netblocks" is the exact problem the original blog p…

if netblock reputation were known small non-spam senders would congregate, this would help weed out the spammers.

but google et al. don't provide any feedback. nor any way to build reputation for your IP. (where are all the staking blockfoo chainbar solutions? or at least let people pay a one time fee for some exception)

anyway, since we already have certificate transparency, we could have a similar one to look up MTA/domain repu provider, then sending DKIM signed HTTP calls to the reputation report address, and let people aggregate it.

Post reply on HN