* Google doesn't lose my email; I probably will lose my email, because an email server is backed by a database and doing database backups right is hard if that is not your day-job.
* You can get a good email-receiving experience, but email-sending is very difficult these days if you're a nobody, because a lot of first-stage network-level spam filtering has come down to reputation, and your server IP won't have any (or, if it's a cloud provider IP, will have very likely been used at least once to send spam in the past.) And residential ranges get dinged, too, from the heuristic (stereotype) that the most likely reason to get an SMTP connection from a residential IP is that it's a member of a botnet.
As someone who self hosts, this is clearly not true. With gmail I was receiving a lot of spam from various email marketing companies like mailchimp, easymail, etc. There's a lot of these companies and they are mostly country specific, some less, some more shady.
With self hosting it is easy to block their servers en masse and forget about them. Some companies spam the DNS namespace with predictable, but extremely numerous domain names, which are easy to block using a few regular expressions. Try to make filters in gmail for that, if you don't know from which of the 100 domains the next email will come.
Email from hacked servers is also easy to block. It's mostly PHP servers and all you need to look for is mention of eval() in the headers as nobody sane hopefully evals PHP code to send email.
It just took me a month of spending a few minutes every other day analyzing headers of odd email or two which passes through some generic checks like checking if sending IP address has a domain name and figuring out how to block the sender entirely if possible.
Now I don't get any legitimately looking spam at all and what I get is easily filtered with bayes filter in thunderbird.
Anyway, with spam the hard job is checking the spam folder and that's annoying as hell with gmail, because it's always full of crap, and it's not easy to see occasional false positive. Now I only get 1 spam every two to three days and that's easy to check. Legitimate people who get blocked get bounce message immediately and have chance to re-send according to instructions in the bounce, instead of falling into spam folder and feeling ignored.
Much better experience overall.
EDIT: I guess I can just reject the gmail bounce if it contains the "Received-SPF: fail (google.com:". Ah!
I use IMAP email. My email is simultaneously stored on my server and on every client. If the server is nuked, I can set up a new IMAP server elsewhere and sync my email client to it; I'd want to do this from work where I have gigabit internet, or this would take a while, but it can re-upload all the data to the server.
That said, I'm using a managed account. I'm not communicating about anything that I care if the government subpoenas, and I have no plans to.
Unless we end up in a totalitarian state where constructive criticism of the government becomes an offense. But in that case my public posts would be more than enough to convict me without looking at my emails.
I store my email on dovecot with Maildir storage. For a single or just a few accounts is perfectly fine and you can backup the emails with your favorite backup tool.
Google/Microsoft's spam filtering makes it impossible to send e-mail from a self-hosted solution.
http://penguindreams.org/blog/how-google-and-microsoft-made-...
Unless you're sending out thousands of e-mails per day and build your reputation with their magic-goo trust filter algorithm, you cannot run your own e-mail server and run with the big players. They have made self-hosted e-mail totally unreliable.
I think what you meant by "very good" is "piss fucking terrible."
(Because if a tech-savvy user really wants to email me, they know how to make a throwaway email account and sign the correspondence with a verifiable PGP key).
Of course, this all happened after I got bitten during a job search and had most of my applications hit spam folders ಠ_ಠ
I suspect part of it might be that it's on a Linode and might be sharing a subnet with other spammy machines. That's probably why MailChimp owns a class C and refuses to sell any of it.
Do you host an https site on the same domain? Is your mail server responding to ipv6? (I hear this can be a problem)
There are a lot of testing tools you can run mail through as well to see how well you score.
"Nothing to hide, nothing to fear"
Has become
"Autonomy is pointless, resistance is futile"
In about a month.
You need to remember the fact that already Snowden's revelations have proven that the NSA and other government agencies all have specific budgets for astro turfing activities (manipulating the public opinion by massively participating in online discussions).
And a couple of days ago, there was a nice post on Reddit's front page summing up the situation on Reddit. Reddit is basically completely compromised by whoever has lots of money (government, big industries, etc). Any company can buy astro turfing services nowadays.
So no, you can't trust public online discussion anymore. Not on Reddit and not here. Unless for topics you are absolutely certain that no economic interest is part of the equation.
I mean, the governments of those places will probably snoop your emails, but if their contents have nothing to do with them, they won't care. And they have no treaties with the US to force their hand to turn anything over.
Think of your server as Edward Snowden. What country should it hide in, so the US can't legally get to it?
Sure, but that doesn't mean they won't happily exchange that info as part of a deal with the US, assuming your data is valuable enough.
Uhm, how? Gmail supports Transport Layer Security (TLS), and >80% of their emails to and from other providers do as well (https://www.google.com/transparencyreport/saferemail/). Reject non-TSL emails, give the server a public key and tell it to throw away the email plaintext, and the only remaining threat vectors seem like "get rubber hosed into disclosing your private key" and "server gets compromised, causing future emails (but not past ones) to get exfiltrated".
Can't you say the exact same thing about the US government?
Sounds like a tagline for an erotic movie, that does.
I think you meant "lose".
Lose could rhyme with rose or close. But it doesn't. Instead it rhymes with cruise, clues, two's, moos, and choose (almost).
"Self Hosted" is certainly not going to fare much easier in this same situation.
I do not think that the same result would be had if Google was refusing to deliver data on a non-US server for a non-US citizen.
This breaks down when the person they are investigating is also the email provider.
And this basically is the reason multi national companies self host email servers
If you were a VPS or even a dedicated lease, or shared - I think the fed would be able to pull the same thing.
I don't have a convenient link to the xkcd comic right now that talks about the difference between theoretical and practical security. ;)
> It's not perfect, but at least you would know you're being investigated.
If the prosecution asserts you have evidence material to the case that you would be legally required to render and won't render it, and the judge believes you probably do, that's it; they don't have to prove the evidence is in your emails to search for the evidence in your emails. Fail to render up the emails or render them up in an intentionally-obfuscated form, and they can hold you in contempt at pretty much the judge's discretion (your mileage may vary depending on severity of crime and state law, where applicable).
(Personal observation: people of a technical bent seem, for whatever reason, to underestimate the wide swath of power the legal process has in investigating a murder case).