Live data from Hacker News

After self-hosting my email for twenty-three years I have thrown in the towel

cfenollosa.com

691–700 of 744 posts

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#691

Earlier quoted context omitted.

Yep SMTP relay is the only sane choice nowadays sadly. Sending your own mail is a losing battle against the email blacklist cartel.

No...it isn't the only sane choice. If it works for you, great. Forunately for Internet freedom, there many of us small timers left who have no issues hosting our own email.

I have no issue hosting, it's just tiresome keeping clear of Spamhaus etc.

Using an SMTP relay was a suitable trade-off, for me, but I respect those who are able to endure the pains of sending non-flagged emails without it.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#692
post #250

I've been hosting my mail for 20+ years now, with minor issues. I guess I've been lucky. Reading the comments here makes me incredibly sad. Every answer that tells me to use a provider misses the point. The Internet was created so that there could be many independent nodes, not so that everybody has to rely on one of several blessed providers. I should be able to run my own E-mail. The real problem is lack of incenti…

Here are some ideas that could solve spam:

1. Require the email receiver to add the sender to their contact list, then put all other emails in "Junk". The UX of this could be quite good nowadays with smartphones and QR codes. The changes to email apps are minimal:

  - 1) When a user opens a "mailto:" URL, the email program shows the normal "send email" screen with a "Just add to Contacts" button at the top.

  - 2) Email program has a function to show a QR code with the user's "mailto:" URL.
2. Add support to the SMTP protocol to let the receiving server demand that the sender make a small "postage" payment. This will require a privacy-preserving micro-transaction system. I worked on one that doesn't use crypto [0].

Here are some ideas for improving the current system, but not actually solving spam:

3. Create a protocol for automatically reporting emails marked as spam back to their admins. Servers will only accept signed emails. Then servers can do lots of things like:

  - Mark sent emails as "Receiver flagged this as spam" and inform the user.

  - When an account begins sending spam, rate limit it, disable it pending password reset, or alert the admin.
4. Add SMTP responses that mean "rejecting because your server sends spam" and "rejecting because that user sends spam". Servers can mark sent emails as "Receiver rejected this email" and inform the user.

5. Build a shared spam reporting system that accepts only signed emails and supports searching by email address. Receivers can use it to identify compromised user accounts and reject their email. Senders use it to identify receivers acting in bad faith (reporting ham as spam). A centralized version would be straightforward. A decentralized version would be a challenging project.

6. Add support to the SMTP protocol for reporting rate limits and cooling-off times to email senders. Admins of large shared email systems can feed these metrics into a monitoring system and receive alerts of problems early.

[0] https://github.com/mleonhard/hipp

EDIT: tone

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#693

Earlier quoted context omitted.

MIAB user here. I pay ~$4 for a small VPS hosted here in Hungary. The company did a pretty good job of keeping it's IP range clean apparently. I only had to request whitelisting from 2 spamlists. One being Outlook's. I filled out their form and my mail was delivering a few days later. I wonder how the ubuntu 22.04 upgrade is progressing though. The EOL of 18.04 is getting pretty close.

my point exactly. was your experience an exercise in futility as the OP wants us to believe?

Not at all. My only problem is that I can never be 100% sure my emails are going through. Shame that some large servers don't send bounce notifications (khm, outlook)

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#694

For those who might choose to run their own email these days, you don't have to postfix + dovecot: https://github.com/foxcpp/maddy https://blitiri.com.ar/p/chasquid/ These options are much easier to set up, will do things like generate DKIM for you, etc. I talk about this a lot[0]. There are positively awesome tools for email out there. [EDIT] - Since I'm repeating myself I've collected all the options into a post[1]…

Thanks for the post!

o/t: Could you add a close button to that ethical ads element? It's obscuring a decent chunk of the screen on mobile and I can't figure out how to dismiss it

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#695
post #350
post #198

The topic often comes up. Can't say I share the experience. My servers have never been put on a blacklist in the 7 years they've been running, and one of them operates from my residential DSL connection. Standard postfix+dovecot stack on an Archlinux VPS, I log in once a year to update the packages and make sure there is enough disk space left.

Essentially all residential IPs are blacklisted for email servers, at least on port 25. Many ISPs blackhole any traffic on port 25 to residential IPs. Do you have port 25 working on your residential connection?

It's blocked by default but my ISP lets me open it. But as noted by NavinF I'm not using it anyway.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#696
post #694

For those who might choose to run their own email these days, you don't have to postfix + dovecot: https://github.com/foxcpp/maddy https://blitiri.com.ar/p/chasquid/ These options are much easier to set up, will do things like generate DKIM for you, etc. I talk about this a lot[0]. There are positively awesome tools for email out there. [EDIT] - Since I'm repeating myself I've collected all the options into a post[1]…

Thanks for the post! o/t: Could you add a close button to that ethical ads element? It's obscuring a decent chunk of the screen on mobile and I can't figure out how to dismiss it

Hey apologies, I just enabled EthicalAds this week, I'll look into this and add something... I'll also forward your concern to them.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#697
post #651

Earlier quoted context omitted.

K-9 Mail is an app available for Android which supports PGP (if clunkily). https://k9mail.app/ > I'm not going to remotely pretend that this would make PGP attractive or viable for the greater public. I do want to address your valid point that the general-purpose computer seems to be a dying breed, but that there are still options for mobile devices. I've used K-9 Mail, though rarely do these days (it went poorly-mai…

Most of my friends and family don't have Android devices.

Perhaps you might care to share with us what types of devices they do have, seeing as my mental telepathy transgizmatron happens to be in the shop presently.

Note that I also listed an iOS option, and mentioned that there are others.

Again: PGP-enabled email apps are available on many platforms, though, again, this addresses only a small part of the larger challenge at encouraging adoption.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#698

Earlier quoted context omitted.

> like saying "You can only have hamburgers two ways, cook them yourself or McDonalds." and your comment seems to be saying it’s OK if we lose the ability to cook hamburgers at home, because there are other (more ethical) restaurants that aren’t McDonalds. am i misunderstanding?

The metaphor is kinda good. It's okay for people to refuse your home-cooked burgers because they don't trust them to be safe. There are actual small food vendors that comply with sanitation rules and you can have them provide catering services, professionally. And that is okay.

we mandate public health measures because it's kind of easy to check for "safe to eat" quality.

also arguably it's too ineffective considering how hard it is to open a restaurant. (because instead of harassing random taco trucks we should focus on other preventative measures, better visibility of food safety, better reporting and tracking)

sure maybe it's time for a "Let's Email" (after letsencrypt) service that handles reputation for email senders.

we already have certificate transparency logs, OCSP, CAA records, and all the fancy stuff, what's needed is something similar.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#699
post #694

Earlier quoted context omitted.

Thanks for the post! o/t: Could you add a close button to that ethical ads element? It's obscuring a decent chunk of the screen on mobile and I can't figure out how to dismiss it

Hey apologies, I just enabled EthicalAds this week, I'll look into this and add something... I'll also forward your concern to them.

Thank you very much!

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#700
G'Day Guys I have gone and had a another look at EFF and the issue for me is they have a 'Donate' in the menu. I'm a OG coder and have been giving away my efforts for decades, I believe that $$$ is the root of all evil, so I don't have any spare cash. What about a BC list of IPV4 that is a referral WL, I'm not gr8 at branding and don't believe in marketing, so the best I can come up with is 'BEN - Blockchain Email Net' ???
Post reply on HN