Mail-in-a-Box – one-click, easy-to-deploy email server
github.com
github.com
* Well configured, secure email server * Ease of adding/removing domains, aliases, catch-alls and user accounts * Ease of using email, either with the ready-to-go Roundcube webmail or any IMAP/POP client * Batteries included: DNS is included, DKIM, SPF, you name it. DNSSec * Want to host a static HTML site? MiaB's got you covered. * Yes, that included Let's Encrypt SSL certs * Awesome status page to check: version updates, misconfiguration, system health, and for each domain: DNSSEC, nameservers, DNS, TLS/SSL, blacklisting, etc. * Open source! Huzzah!
If you're serious about moving away from Google or any other corporate mailprovider is feasible, take a look at Mail in a Box.
Sure, it's technically for Debian, but if you're comfortable with Linux it's easily adaptable to other distributions. In order to get Gmail to accept your email without it going to spam, you need SPF/DKIM and a SSL cert. Let's Encrypt works, and is a cinch to set up.
You make it sound hard, just there, or do I misunderstand?
One thing to know, you need to activate the option to use TLS for outgoing email. A bit of a stupid default in my opinion.
I'm using spf and dkim, ip is not blacklisted, and the domain I'm sending from has a let's encrypt cert, but my emails still go to gmail spam. (Outlook also, but yahoo goes to the inbox)
Now that I'm thinking, the emails are sent using postfix through the fqdn (subdomain.example.com) which is not served by http and hasn't hot a cert.
If this is the case should sending the emails through example.com or add a cert to host.example.com work?
Or is there another mechanism to use let's encrypt certs for email?
smtp_tls_cert_file = /etc/letsencrypt/live/$domain/fullchain.pem
smtp_tls_key_file = /etc/letsencrypt/live/$domain/privkey.pem
smtp_tls_security_level = may # or encrypt, to force TLS
Also, yes, if I understand you correctly your cert should include subdomain.example.com even if the web-facing content there doesn't use HTTPS.
I think it would be a perfect use case for Docker-based solution.
https://github.com/mail-in-a-box/mailinabox/blob/master/Vagr...
I poked a bit and it appears that the setup script is interactive which complicates playing nicely with Docker somewhat. It installs nsd + postfix, rewrites config files in /etc and mucks with ufw. Could probably mimic some of this by mounting locally customized config files into the Docker container.
This is the skin I installed, it's nothing to write home about but it does the job: https://github.com/messagerie-melanie2/Roundcube-Skin-Melani...
Having said that I recently migrated to fastmail as it costs me <$5 a month and just works for all of my domains. I found I was spending more time making my email work than actually building things in my limited spare time.
You add a fodor.json file, add a link to Fodor and it makes it super easy to get it setup for yourself
Having a local mail server would be useful for making local P2P WiFi links, and emailing photos/music/etc directly between phones without Internet access.
I went with MailJet for SMTP forwarding, 600 emails a month for free.
Nobody with purely-technical solution to this problem can be better in practice. (although we're pretty close) This means you're more likely to get actual spam in your custom deployment.
Sure, this works as long as they don't try to poison your filters, but given its a small and rare target, it's unlikely someone would bother.
It helps, but it's not a solution.
The majority of spam I receive is from addresses that have been leaked ( Santander bank is particularly bad for those for some reason ) or bought in an acquisition; perhaps two or three per year. I just blacklist those addresses.
What really annoys me, though, is that eBay passes my unique-to-them email address to vendors from whom I buy items and several of them have added me to their mailing lists over the years, but thankfully de-subscribe has always worked.
My setup consists of Postfix with postscreen and SpamAssassin. Postscreen blocks clients on a certain type of protocol error that spammers are prone to (speaking out of turn) and based on DNSBLs[1], notably zen.spamhaus.org, which blocks most spammers.
SpamAssassin, in addition to the standard rules and bayes filtering, is configured with Pyzor, Razor2, DCC, and iXhash, and I have some custom rules as well.
I actually get far less spam with my self-hosted setup than I did when I used a paid e-mail service (although it was not Google).
Public IP reputation (DNSBLs) and spam fingerprint databases (Pyzor, Razor2, DCC, iXhash) make self-hosted spam filtering very feasible.
Incredulously, asking first-time senders to retry in a bit still filters out the vast majority of spam.
rspamd, in addition to bayes filtering, has it's own fuzzy fingerprinting system. You can use your own fingerprint db and/or a public one. The public one that is configured in rspamd by default didn't seem to catch any of the spam I get though.
I am progressively transitioning to giving a unique email alias for each service.
1. If the address gets leaked or sold I can identify the culprit and stop the spam by deleting the alias
2. It is a useful security measure too, if a website gets hacked, it becomes harder to correlate my account across websites since it is a unique, non predictable address.
I wasn't even sending out mass emails and 30%+ of my email would never be delivered. I had to constantly check to see if my IP addresses were on the various spam lists (and fight to get my IPs off) and I just got tired of it.
Companies like Google have entrenched themselves in many things like email and are slowly becoming the only option out there. A large amount of email addresses are @gmail.com or run through one of their servers and they ultimately control whether the recipient receives/sees your email.
The 'promotions' tab in gmail also made things worse for many small businesses. Google doesn't want you competing for their advertising space and pushes any emails it deems a 'promotion' off to the side, so users don't actually see it. I'm not even talking about actual spam emails here, but emails users knowingly signup for and are expecting.
Many people don't realize just how much a handful of companies controls the Internet and your ability to make a living online.
I also do not want to invest the time to maintain my own email server. Imho there are good alternative solutions provided by companies such as protonmail.com or mailbox.org just to name two I have personally experience with.
As with everything it is mostly about overcoming your personal comfort zone and start to act. Good luck.
It's about the time and effort it takes to constantly fight the blacklists and the downtime for my business.
I've been operating my own mailserver for over a decade and I haven't ever had to remove my IP addresses from any blacklists, and I haven't ever heard such a thing from other people I know who are operating their own mailservers either.
What if they missed emails they never knew about in the first place? What if they tried to contact someone and just assumed they've been ignored? Unless you know you're not on blacklists, you should be worried at least a bit.
I don't get the complaint about the promotion tab though. I had the emails auto-labelled before more or less as private / adverts / notifications / mailing lists. This maps pretty well to Primary / Promotions / Updates / Forums. Anything that ends up in Social I just unsubscribe from. I'm pretty happy with their autoclassifiers. They don't make me not see emails.
That does bring up the point of how to do blacklist monitoring. There are various commercial services out there that will allow you to check for free and monitor 1 host or something (eg. https://mxtoolbox.com/). I'd prefer to run my own though, does anyone know of a good setup for this?
I'm using DO currently and it's been working fine, though it's just for personal email.
Though once when device connected to my wifi got infected and started sending spam, I got angry (not e)mail from ISP, so I drop tcp/25 on my router firewall.
Now imagine the typical user who has no idea what the letter means or how to configure their router and just ignores it...
I'm surprised your whole ISPs dynamic IP pool isn't already on every spam block list.
edit: just realized you aren't the poster I was replying to, so presumably you're not running your own email server
But it's my name!
Though there are a few minor caveats to this. Microsoft (Hotmail, Outlook, Live, etc. addresses) mail servers are ornery, in that they hold grudges against IP addresses for a long time (seemingly forever, as the server we moved to recently had been in our possession for non-email use for a couple of years, and it was still on a Microsoft blacklist from a prior owner's abuse), and they make you jump through a few hoops to get it removed. Even with SPF and DKIM, they rejected 100% of our mail until we got off of their blacklist. Our previous server never had that problem...but we'd been on the same IP for like five or six years.
You need to be on an IP that is dedicated and that you're going to own for a long time, and not part of consumer IP blocks; you can't effectively run a mail server on a cable or DSL line, even business class, without jumping through a lot of hoops. But, if you're in a colo, you'll be fine. This also applies to AWS and other cloud server IP addresses; as I understand it, huge swaths of them have been burned by spammers who spin up and spam until they get shut down, and then move to another.
So, I guess it's relatively tricky to get things working at the beginning and you may have to fight a little with some of the big email vendors, but it's not really an ongoing thing, in my experience. Get it right, and then don't spam or let your users spam, respond appropriately when abuse does happen, and you can run your own mail server relatively painlessly.
you'd think that it would be this simple, but it's not. I have had SPF/DKIM set up from day one, a totally clean IP, doesn't show up on any block lists at all, yet i'm still having some problems delivering to certain ISPs. Verizon is the biggest problem right now. I had problems delivering to Gmail because my server didn't have a good enough reputation. Everything from my IP was going right into the Gmail spam folder and there was nothing that I could do about it except sit back and wait. It took weeks for Gmail to finally decide that my reputation was good enough.
It's scary just how much power Google has over many things email these days.
Now I have to convince Verizon that my IP is not a dynamically assigned one.
It's not just G that differentiates between transactional email (a receipt) and bulk/marketing mail. Trans/bulk are so different that email companies consider these separate products (e.g. mailchimp vs mandrill).
Generalizing based on myself, I can guarantee that people really hate receiving crap. At least I can visually distinguish the G ads from my email and ignore them.
I got that fixed, and have submitted half-a-dozen requests to have us removed from rfc-clueless, and they've all been ignored (and do their best to hide how to submit and what for). Fuck rfc-clueless - it's a blacklist for 'people who don't follow the rules', but they're bad netizens themselves and don't follow their own rules. Just... fuck them.
I can't imagine what it's like to end up on one of these ignored blacklists when you don't have the might of a professional email service behind you.
Don't let Google and Facebook monopolize our communications.
I do the same but the reality is that 99% of my correspondants use gmail, yahoo or hotmail. So these companies get a copy of all of my communications...
So if I can do it, you can too.
BTW I use Gmail as the front end though - it picks up the mail up from my POP3 server and sends it out via my server over TLS/SSL. That last step was a bit complicated to set up since Gmail doesn't accept self-signed certificates for SMTP sending. But I managed to work out how to set up and renew a free cert from StartCom.
https://en.wikipedia.org/wiki/StartCom#Criticism
https://blog.mozilla.org/security/2016/10/24/distrusting-new...
Do you mean "made it harder for small businesses to get eyeballs on their spam"?
Most consider that a good thing. It's only marketers and spammers who regret the bundling of these "valuable messages".
I run several email servers, and this is NOT the problem. You just need to configure things correctly. It's not 1996 anymore, you need to set up things like DKIM, SPF, etc. Also make sure your hosting provider has not sold you an IP that was previously used by a spammer. [0]
That's all there is to your "problem".
Besides that: Your solution to Google's insane domination is to put even more of your life on their servers? When we know thanks to Snowden that Google is part of the NSA's PRISM mass surveillance program? Surrendering is not what winners do.
[0] Simply run a Blacklist Check here: http://mxtoolbox.com/supertool.aspx
The difference between what a business thinks a user has signed up for and is expecting and what an actual user is actually expecting in their actual mind tends to resemble night and day. For most users the "Promotions" tab was a godsend that rescued them from significant amounts of email that was swamping the stuff in their inboxes they expected and wanted to read. It allows users to engage with promotional material at their own choice and in their own time.
Google's smart filters have been a fantastic win for the user experience.