Live data from Hacker News

Reasons to not use your own domain for email

bautista.dev

191–200 of 227 posts

Re: Reasons to not use your own domain for email

#191
post #96

> Reasons to not use your own domain for email Aside from the fact that the author of the blog doesn't really provide any "reasons" in their blog ... There are ZERO reasons not to use your own domain name for email. The biggest reason TO use your own domain name is that you are not subject to the corporate whims of your ISP, cloud-email provider or whatever. You get to choose, and you get to choose when to switch. Th…

What about blacklists? I read that it is a huge problem with custom domains.

You can still send through commercial services. My own email is received through Cloudflare (which does forwarding with SRS) and sent via Amazon SES (a paid service, but pennies per month for manual, personal email).

Deliverability and blacklists are their problem.

Re: Reasons to not use your own domain for email

#192

Earlier quoted context omitted.

Which communication methods leak no metadata? If two people are communicating, the message always needs to know where it's going and in most cases where it's coming from. Not encrypting the email subject is an implementation detail really.

> Which communication methods leak no metadata? All leak something, but there are differences in what and how much. > If two people are communicating, the message always needs to know where it's going and in most cases where it's coming from. Yes, but in this case it'd be actually better to use something like Signal. You want something that's plausibly used often, is always encrypted, and is used for random chit-chat…

Sure, but sometimes we don't care about knowing who is communicating. For example:

I don't care if someone knows my bank sent me a message, but I want the content of the message to be secure (not just in transit, but also at rest)

I don't care if someone knows my primary care physician sent me a message, but I want my lab results to be secure.

I don't care if someone knows I communicated with my CPA, but I want my tax and receipts to be secure.

Re: Reasons to not use your own domain for email

#193
post #186

Earlier quoted context omitted.

A great idea in theory, but a large number of Americans wouldn’t trust the government with this (never mind they can do this with paper mail—this is a different scale). I don’t know why we trust corporations any more than that. Convenient UX, I guess.

That is why I suggested the post office. It is highly regulated but separate enough from "the government" (at least in the US). I expect that many people would still use 3rd party providers for personal email and less important things. But it is certainly nice to be able to have bank statements, tax documents, or any business with government services conducted through a verified email.

Also, the post office would have lots of incentive to implement encryption (s/mime or pgp) as they aren't interested in analyzing messages. They would want to make sure that government services can send secure communication to you.

Re: Reasons to not use your own domain for email

#194

Earlier quoted context omitted.

I've read that advice, about not hosting your own email server, every week for a few years now, but at least for anyone with a few years of self-hosting experience I would disagree. There is just a little more checkpoints than 15 years ago. Before, you needed to check your reputation on spamfilters, be careful of viruses and sending rates and dome basic DNS entries. Nowadays, check that your IPs are clean, subscribe…

I'm not saying it's hard if you know what you're doing, but "correctly use IPv6, DNSSec, Rspamd, Dkim, Dmarc, Spf, autoconfig/autodiscover" is a lot of technology for simply sending and receiving email. Considering that emails are insecure by design, and any email will have at least 2 participants, and you have no control over where the remote participant sends/receives emails, self hosting for privacy concerns is al…

You're right about the difficulty and the privacy, but I hope that people will still host their own little part of internet. The fundamental parts that you can host universally today are still a website and a mail server. Everyhing else like fileservers, webapps, federated services, streaming, vpns, game servers... have multiple implementations and evolve rapidly every year. If people no longer host the most fundamental services, it's leaving the play field to the industry. And one day we won't even be able to do it anymore.

Re: Reasons to not use your own domain for email

#195
post #192

Earlier quoted context omitted.

> Which communication methods leak no metadata? All leak something, but there are differences in what and how much. > If two people are communicating, the message always needs to know where it's going and in most cases where it's coming from. Yes, but in this case it'd be actually better to use something like Signal. You want something that's plausibly used often, is always encrypted, and is used for random chit-chat…

Sure, but sometimes we don't care about knowing who is communicating. For example: I don't care if someone knows my bank sent me a message, but I want the content of the message to be secure (not just in transit, but also at rest) I don't care if someone knows my primary care physician sent me a message, but I want my lab results to be secure. I don't care if someone knows I communicated with my CPA, but I want my ta…

True, but that's incredibly user unfriendly. The average person isn't good at doing that level of risk evaluation. What's important and what not isn't intuitive.

And we have a much friendlier than GPG system for that: putting that on a website protected by HTTPS.

Re: Reasons to not use your own domain for email

#196
post #193
post #186

Earlier quoted context omitted.

That is why I suggested the post office. It is highly regulated but separate enough from "the government" (at least in the US). I expect that many people would still use 3rd party providers for personal email and less important things. But it is certainly nice to be able to have bank statements, tax documents, or any business with government services conducted through a verified email.

Also, the post office would have lots of incentive to implement encryption (s/mime or pgp) as they aren't interested in analyzing messages. They would want to make sure that government services can send secure communication to you.

I disagree with this particular point. The US Postal Service has searched, read, and censored mail during wartime, and it's naive to assume that any provisioning of email service wouldn't have the ability embedded in it at behest of whatever legislation authorizes to the USPS to do so.

Also, given the current political climate, I would be very concerned that the Comstock Laws are coming back. Can you imagine your email provider blocking or maybe even criminally prosecuting people who send you information about contraception, safe sex, abortion, or legal sex work?

Re: Reasons to not use your own domain for email

#197
post #192

Earlier quoted context omitted.

Sure, but sometimes we don't care about knowing who is communicating. For example: I don't care if someone knows my bank sent me a message, but I want the content of the message to be secure (not just in transit, but also at rest) I don't care if someone knows my primary care physician sent me a message, but I want my lab results to be secure. I don't care if someone knows I communicated with my CPA, but I want my ta…

True, but that's incredibly user unfriendly. The average person isn't good at doing that level of risk evaluation. What's important and what not isn't intuitive. And we have a much friendlier than GPG system for that: putting that on a website protected by HTTPS.

But that puts all the data on a 3rd party site where I _might_ be able to make a copy of it for myself. It is annoying to get an email from my bank about an "important message", and instead of just sending me the message, I now have to go to the bank's app to read it. Oh, and it disappears after 30 days, so I have no way to archive it or look back on important messages from a year ago.

A government system could easily implement s/mime transparently for all emails sent within that system (meaning any other government agency or registered providers).

Re: Reasons to not use your own domain for email

#198

The best reason against it is the fact many website, because of stupid policies or incompetent engineers, will reject the address as invalid. Happens to me regularly and makes my life difficult. I still like better than the alternative though. I got locked out of google accounts twice in my life and had one other email provider close entirely.

I’ve had a .me tld for 5 years and am yet to come across a single site that rejects it.

Same, going on 10 years now. I used to get weird looks from people when I told them my email but now I don't even get those anymore.

Re: Reasons to not use your own domain for email

#199
post #193

Earlier quoted context omitted.

Also, the post office would have lots of incentive to implement encryption (s/mime or pgp) as they aren't interested in analyzing messages. They would want to make sure that government services can send secure communication to you.

I disagree with this particular point. The US Postal Service has searched, read, and censored mail during wartime, and it's naive to assume that any provisioning of email service wouldn't have the ability embedded in it at behest of whatever legislation authorizes to the USPS to do so. Also, given the current political climate, I would be very concerned that the Comstock Laws are coming back. Can you imagine your ema…

I'm not suggesting that anybody would be required to use their government provided email for everything. I am just suggesting that it should be available to every citizen as a right, since a reliable email address is so important to every day life now.

I wouldn't be sending anything through my government email that I would sent through the post mail. I would be cautious about sending anything through email, as it probably ends up in gmail unencrypted as it is, and is transmitted in the open through multiple relays.

But, we also know that Google, Yahoo, and other _do_ scan all your email. I'm not sure why you feel any safer with a huge corporation that has no oversight.

Re: Reasons to not use your own domain for email

#200
post #199

Earlier quoted context omitted.

I disagree with this particular point. The US Postal Service has searched, read, and censored mail during wartime, and it's naive to assume that any provisioning of email service wouldn't have the ability embedded in it at behest of whatever legislation authorizes to the USPS to do so. Also, given the current political climate, I would be very concerned that the Comstock Laws are coming back. Can you imagine your ema…

I'm not suggesting that anybody would be required to use their government provided email for everything. I am just suggesting that it should be available to every citizen as a right, since a reliable email address is so important to every day life now. I wouldn't be sending anything through my government email that I would sent through the post mail. I would be cautious about sending anything through email, as it pro…

[deleted]
Post reply on HN