Live data from Hacker News

After self-hosting my email for twenty-three years I have thrown in the towel

cfenollosa.com

461–470 of 744 posts

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#461

I am not a Google employee, but I do work with email anti-spam at scale. There's a lot to critique here but it boils down to three points: 1. Spam filter behavior has changed because spam has increased in volume and sophistication, not because ISPs want to save money, or to eliminate competition. Some techniques that worked well 5 years ago aren't as effective anymore. One of the consequences of this has been a reduc…

> The filtering behavior reported here is either misunderstood or misrepresented. First, no, no major ISP (Gmail, Yahoo, Microsoft/Outlook, icloud) is going to permanently block an IP range; filters are designed to be dynamic. In severe, ongoing, high-volume spam scenarios, you could see a 2-week block, maybe occasionally 30 days. But never "one strike". You say you're knowledgable, but I also ran my own email server…

The overwhelming majority of legitimate mail will never see anything remotely near a 14-day block. Again, it's reserved for severe, ongoing, high-volume spam scenarios; ISPs use other methods like short-term deferrals for more common/less severe problems.

If you find yourself in an IP range involved in a severe, ongoing, high-volume spam scenario that's affecting your delivery, then it means your provider is not managing IP range reputation, or not doing it very well, and you should vote with your dollars and move somewhere else.

As a rule of thumb, email-specific service providers tend to do a better job of managing IP range reputation than more general purpose providers like VPSes.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#462
post #406

Earlier quoted context omitted.

ok, this is the text book definition of "out of touch"

Yep. On any other site I’d assume that comment was satire. Nothing’s changed in the last decade: https://moxie.org/2015/02/24/gpg-and-me.html https://blog.cryptographyengineering.com/2014/08/13/whats-ma...

My canned response to the second article/rant:

* https://articles.59.ca/doku.php?id=pgpfan:wtmwp

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#463
post #21

The sweet spot for having control over your email while simultaneously minimizing unforseen headaches is to simply own your domain name and point the MX record to whatever hosting provider you want instead of self-hosting a server at home. Same philosophy for exposing a your personal blog of html files or content like mp4 videos. The sweet spot is to focus on buying a domain name you control. Then let Amazon S3, or C…

Controlling your domain/mx is the most valuable thing.

Email reception has not been a problem for me so I enjoy having my mx pointing to my own mail server. It gives me more control and it requires very little maintenance.

If I was going to outsource anything the first choice would be outbound. My email system does everything right for reputation protection. All senders are authenticated on secure connections and the senders are people I trust. Nothing bad gets sent and my static IP is on a reputable server host and is not on any public black lists. I maintain SPF, DKIM etc. If someone decides to block my IP for no reason by accident or on purpose there is very little I can do or care to do anymore.

I have an alternate path for emails setup via a server I host elsewhere ready to go. If I run into a widespread delivery issue due to massive indiscriminate ip blacklisting of my provider I can enable it. That has happened once in 20 years. If delivery gets too hard I will change that policy to send all outgoing emails through a commercial smtp delivery service and let them deal with the problems.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#464

I gave up self-hosting ages ago. For a while I even used the old Google for Families grandfathred in setup. That also went the way of the dodo a few years ago for me. I signed up for ImprovMX, setup my domains there, and just route my emails to whatever service I want. I use a random gmail account that I use for my login and Google services, but the email itself is never exposed anywhere, I only give out the custom d…

Another very happy (paying) customer of ImprovMX here. I have a dozen or so domains for family and friends configured this way, using ImprovMX for both inbound MX and outbound SMTP (using Gmail as the 'front end' mailbox, but using the custom domain/addresses everywhere).

I too gave up self hosting this all a few years ago - especially when hosting domains for others (family) who aren't tech savvy, I got sick of having to troubleshoot why their emails weren't being delivered. Outsourcing the delivery component to ImprovMX and the mail storage and even inbound spam filtering to Gmail, made things so much easier, even if it does mean relying on a centralised party like ImprovMX.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#466
We still are fighting the oligopoly with our vaulted c1.fi email service. Please feel free to check us at https://c1.fi/v/hn20220905/?lang=en.

Here's EU's JRC-MECSA report on our service: https://mecsa.jrc.ec.europa.eu/en/finderRequest/b5daceffc76e....

Support for client's own domain is currently under works. Our webmail supports PGP and one can use IMAPS/SMTPS or ActiveSync based native email clients too.

All servers self hosted (we run C1/Gentoo!) in our own computing facility in Finland. =)

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#467

Wrote my smtp server 5 years ago. Still running. BTW, did you know the smtp protocol works without DNS? You just need to puth the ipv4 between brackets @[xxx.xxx.xxx.xxx] and for ipv6 @[ipv6:...]. spam? simplicity and freedom has a price (personnaly, I have have very, very little spam since I am self-hosted), and don't think corpos won't try to force you to use their servers one way or another... Whose coding the vir…

>BTW, did you know the smtp protocol works without DNS? // I did but assume no-one uses that as it's not practical because most IP addresses serve more than one domain? Or does SMTP handle that, like some extra "really-to:" header to encode the user@domain if you use IPvX for delivery?

RFCs.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#468

Earlier quoted context omitted.

was just gonna ask how you would handle DKIM and SPF stuff. Hetzner? Digitalocean?

I use a small datacentre in my country, actually not far from where I live. DKIM/SPF are independent of the provider. The easiest way to understand is to consider how receiving works. If I'm getting an email from hnemail.example, the first thing I do is consider the IP address. Oh, 257.257.257.1? Ok. So I then ask DNS "what is the SPF record for hnemail.example?" and it returns v=spf1 mx -all This tells me only to ac…

DKIM selectors aren't UUIDs. You can of course use a UUID as a selector, but you don't have to. My selectors are named S-YYYYMM (when I rotate the keys), so my current public key is at S-202001._domainkey.example.com.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#469
The address 929@homeaffairs.gov.au, which must be used by Australian permanent residents to update their personal details, refuses to accept email messages unless they are from big tech.

Shame on you, Australian Department of Home Affairs.

And shame on Telstra, which provides the service.

---

Remote-MTA: dns; dibp-ibmail2.msng.telstra.com.au

Diagnostic-Code: smtp; 554-mx.msng.telstra.com.au 554 Your access to this mail system has been rejected due to the sending MTA's poor reputation. If you believe that this failure is in error, please contact the intended recipient via alternate means.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#470

Earlier quoted context omitted.

I completly agree with you. While Hetzner is my actual neighbor as their headquarters is right in the neighboring town, I still use a server at very small scale provider. I have no problem with my email server. I receive some spam here and there, mostly from Russia. But I immediatly block the according IP addresses for some time. For years I avoided to use any external service to decide whether its Spam or not. But a…

If you are using external blocklists, you are perpetuating the problem here. Small mail operators end up on blocklists through no fault of their own, and it sounds like your server would reject them just like the big servers do.

You don’t have to use blocklists to block messages.

I use blocklists in my self-hosted setup but only for the purpose of adding header fields that my Bayesian anti-spam filter can use to classify messages. I don’t reject anything out-right, aside from attempted spoofs of the domains my server is authoritative for. Everything is received— it just may end up in an “Unsure” folder if it seems too shady for the filter to put in my inbox.

Post reply on HN