As a shameless plug: Purelymail, the mail service I'm working on, could use some more beta testers. It's (to my knowledge) the cheapest way to get email on a custom domain right now. https://purelymail.com/
As a shameless plug: Purelymail, the mail service I'm working on, could use some more beta testers. It's (to my knowledge) the cheapest way to get email on a custom domain right now. https://purelymail.com/
The mail is encrypted at rest to protect against illegal access, not legal access. Fastmail are transparent on what they will or won't do. Where's the problem?
I'd be more worried about a programmer working on the bowels of OpenSSL or LibreSSL etc and being seconded by ASIO/ASIS/DSD than about companies.
I'm a long time (and very happy) fastmail customer and I have no problem with their position. Not because "I've got nothing to hide", but because if I did, I'd know not to use their service.
I depply despise the telecommunications assistance act. I think it's badly written and comes from an inherently uninformed and impractical idea that you can legislate against people keeping secrets. I hope that the reviews in Parliament right now, and, hopefully, the changes to be made under a new Labor government, will remove a lot of the stupidity.
We've seen at least the US government have some fairly expansive requests in order to track down one single person, and they never delete the data once they obtain it. So a copy of those records will forever be outside of your control, potentially without you ever knowing it.
End of the day, if you have a scenario where a third party is the custodian of your information, that custodian has control of it and will follow whatever legal framework that they are obliged to follow.
We are on a grandfathered plan now and are putting off upgrading to a current plan as long as possible because it's a huge price jump to start paying for my kids to have 25 GB of storage which they are barely using.
As others have said, your pricing is unpredictable and hard to compute. As I’m evaluating you with competitors, I’m not going to invest the time. In my experience, when a company makes it hard to know what you’re actually going to end up paying, you usually end up paying more than you want (see: Verizon).
From a business perspective, it seems to me your value proposition is that you are striving to be the cheapest email provider. I think you should consider the kind of customer this attracts. The sort of person who thinks a few dollars a month per email address is too expensive is going to be high maintenance. If you want this to be sustainable, I think you need a different angle. Consider that all these other email providers basically charge around the same amount. That isn’t an accident. I don’t know the email business, but I assume it needs a certain margin to actually be sustainable and these guys have landed in the right ballpark.
If you’re looking for business customers, then your pricing is basically rounding error compared to the other guys. It’s not materially different enough to matter for a business of any reasonable size to be worth having as a customer. In fact, the lack of predictability is a major deterrent. Businesses need to create budgets and every variable cost adds to the complexity of the forecast.
I have to disagree with this. Any email service that costs several dollars per mailbox per month is way too expensive for most people who tend to have more than a few email addresses, including shared ones. In many cases these may not be conducive to be trimmed down using aliases.
Take a look at Posteo.de, mailbox.org and Runbox.com. All of them are highly privacy focused, been around for several years, and also provide email for a low price. With prices of hardware going down, even those prices sometimes look high when you see the storage quotas, the low number of aliases (except Runbox), etc. (I concede that hardware is just one part of the solution, but see what Migadu.com says on that front).
Setting up a family of users even on Fastmail’s lowest tier (without own domain support) would soon become quite expensive, not to mention the standard plan.
When you ask them about it they will lie and tell you that it's not technically possible.
Most people have no idea what a MX record is and that other providers support own domains, so they fall for it.
Obviously they depend on customer retention by customer lockin.
I hate people who directly lie like that for their monetary benefit. So I would never go anywhere near them.
> We do not offer domain services because we do not save any personal data for any of our services. This is not possible with domains.
> Domains must be registered to a person’s name and address. As a provider, we would be required to store inventory data for all customers that use their own domains with us. As a result, we would have to provide this information to government agencies when requested.
> Additionally, security reasons also play a role in this decision. With customer domains, the owner of the domain is responsible for setting up security features like DNSSEC (and as a result also DANE). Even things such as SPF and other protocols for delivery would lie in the customer’s hand and could not be guaranteed by us.
> Because of these reasons we have decided not to offer domain services and instead to remain consistent with our focus on data economy.
See, that's just half-truths that amount to lies.
They claim they need to store personal information about you when you're using your personal domain.
That's untrue. Only if you registered the domain with them they would need to know about you.
It's also untrue, because unlike .de, many other TLDs don't require full names and addresses in WHOIS, or there are "privacy shield" services like the one nearlyfreespeech.net is operating.
Security reasons.
Also untrue (although it's a reasonable business decision that they don't want to handle customers calling their support with the customer's own domain set up problems).
I continue to claim that there is exactly one reason they are refusing: A customer with a *@posteo.de address will pretty much never leave.
I wouldn't mind very much if they admitted that, it's certainly a geeky niche to serve, but this security-and-privacy bullshit really makes me mad.
Do you want to trust your privacy with a company that's lying, even if you wanted to argue that it's a white lie?
Side note: Posteo does not allow own domains (you can only choose from the list of Posteo.* domains that the company owns). The reason for that is mentioned in their FAQ (in short, the company doesn’t want to have or store customer identifying information wherever possible).
Interesting - which products has this been an issue for? I'm on the same grandfathered GSuite deal and used to have this problem, but haven't in a while.
Even I'm put off by being charged based on the number of emails I receive - why should I pay extra if I get a lot of spam that should be caught by the spam filter?
You have up to 6 different types of fees you're going to charge and no easy way for me to figure out what my numbers would end up looking like (Your $7.72 amount means nothing to me since I have no easy way to compare your estimates vs my usage).
So we are looking at 14 + 4 +1 = $19 before you even send/receive emails.
I just did a quick look and it looks like I receive around 6000-7000 email a year. Most of it is advertising and notifications (that doesn't count SPAM emails which are countless and I hope you don't charge for). That's an extra 1.4 bucks.
I send around a thousand emails a year. That might seem much but it is actually very low. It is only 3 emails per day and you can do much more if you use email for personal and work. That's an extra 4 bucks.
So total is $24.4 assuming you stop your billing there. That's half of FastMail offering for a beta product which from the looks of it offer not interface.
I might come off as rude but I think you need to remove the pay-as-you-go billing and just bill something reasonable for a whole year. Plus offer something more than "Just Email"; like have a differentiating feature like security or privacy.
You're right that I need to add more value. My planned direction is more along the lines of utility than security/privacy, which I think Protonmail covers pretty well. There's a lot of interesting value-add to be done in email.
The pricing is more that we offer honest pay-as-you-go pricing, with caps to make sure you don't actually get a ruinous charge, in direct contrast to "billing something reasonable for a whole year". If you'd rather do the former, then yeah! You're really well covered in the email space already. But I think people are getting subscription fatigue, where every service imaginable wants its $5/month cut of the pie.
I'll sign up to your service shortly; it would be very economical with my current usage!
Except the users who already are storing 25GB of mail?
I have ten years of mail on FM. Even with multiple years of multiple heavy mailing lists, sending and receiving photos, etc., I'm at about 4.2GB.
- Offer a calculator so that people can estimate their own cost. A small improvement, probably not significant impact.
- Offer a customer to enter their current IMAP creds, give an accurate estimate based on past usage. A big improvement, but which would require significant trust from the prospective client. Hard sell.
- Offer a guarantee of some kind. "If you don't come off cheaper with Purely, we'll make up for the difference". Reassuring, but increases your risk.
- Up the price of storage, and eliminate the price of traffic. Storage is probably an imperfect but adequate proxy for total usage price, given that the pattern nowadays is to archive rather than delete (non-spam) email.
A huge majority of users use free webmail providers, and the biggest players in that space all allow Oauth access to email. Oauth can be scoped down to just the access you need, whereas if you give out IMAP creds those can be used to wipe somebody's email account.
Also, at least in Gmail's setup [0], the IMAP password seems to be your "Gmail password", which is the same thing as your Google account password. Don't ask for this. You don't want to have these passwords enter your company's infrastructure.
[0] https://support.google.com/mail/answer/7126229?visit_id=6368...
I actually just checked the storage price, and I notice that at some point I added a $2/10,000 charge to the equation at some point, which is almost all of the charge price. I'm going to remove that tomorrow, since it was probably just paranoia and not actual cost plus margin.
But I still don't think your offer is reasonable. I consume around 600mb of storage, so if you go above 25gb you'll probably get a 20-30usd bill from the send/receive billing.
> But I think people are getting subscription fatigue, where every service imaginable wants its $5/month cut of the pie.
Exactly, so your solution is to complicate the billing process?
Here is a better deal:
- $xx/year fix - $0.xx/year for storage
No other fees. Sending/Receive emails should not add to your overhead that much (unless the user is abusing).
You're right that sending/receiving don't add to overhead much. The receipt is actually way overinflated right now, and should be down to a more reasonable number tomorrow (about $0.03/1000). I might just waive it completely if it complicates things too much.
Sending is much harder, because I need to deter spammers. I priced it significantly above Mailchimp's price for that reason. But the cost will definitely go down as my ability to detect and ban spammers improves, and we'll likely end up pretty much with a scheme like you're proposing.
Firstly, as others have stated, your pricing is way too complicated for anyone to understand and figure out how much they would be charged. It would be better to make some assumptions and go with pricing based on account, aliases, storage, etc. Your current pricing is almost like one of those cloud service pricing calculators. Very nice in theory for paying based on usage, but practically next to impossible to make any sort of cost estimates on.
Secondly, your privacy policy is very short and doesn't give a lot of comfort. Take a look at Posteo.de to see how privacy is handled. It's one of the best that I know of.
On pricing, also compare with mailbox.org.
I did look at mailbox.org. It's about double for their lowest monthly plan, which is reasonable.
Where I hope Purelymail will shine is that it scales a lot more naturally (once you hit mailbox.org's 2 GB cap, you upgrade to a plan that's 2.5x more expensive), it enables use cases that'd get you frowny faces from other providers (because we charge appropriately), and there's no surcharge for things that don't actually cost more.
Want a dozen usernames? Sure, whatever. Need a hundred users? Sure. Store 2 TB of mail for some reason? We've got you covered.
The downside, as you point out, is that the pricing gets a bit scary and I need to work on making it feel safer.
Maybe a good idea would be posting a simple online calculator or a downloadable spreadsheet?
As a further side note, I don't understand (for an end user) the reference to:
>Emails sent: $4.03 (if sent externally) or $0.03 (if sent within the same account) per 1000 plus $0.18 per GB
I mean, while sometimes I talk to myself, I never wrote to myself, set aside internal company e-mails, which e-mails are not "sent externally"?
Or am I misunderstanding something?
However, I have no quarrel with the approach to pricing here. In order for a service like this to succeed with very established incumbents, it needs to differentiate itself enough to carve out its own niche.
I never thought about the idea of having a "family domain", it could be a nice idea, though I guess its naming could be a possible venue for in-family disputes?
My name is "Mark Stosberg" and my email is "mark@stosberg.com".
1) my mom won't have an e-mail address with the surname of her first husband (my dad, passed away)
2) my brother-in-law (brother of my wife) surely won't have it
3) my cousins all have different surnames
4) my wife may accept one, but I talk with her every day and when we don't meet or talk via phone we tend to communicate via post-its on the fridge or similar
Fastmail provides webmail that is faster to sync than gmail (seriously; I use fastmail for personal and gsuite for work all day); a calendar; and a nice little notes utility. Be warned it's fidgety to sync fastmail calendar on android because you'll have to use a 3rd party app. But again, worth it to de-google your personal life.
1. I don't see anything about DMARC (DKIM, SPF) setup for your users. Do you provide DMARC?
2. Do you use shared ip's for all your users? If yes, how do you make sure my emails don't land in spam-filters, because of other users behaving badly?
3. Do you have a system in place and already experience to behave differently to different email hosters (e.g. send emails differently to gmail, yahoo or gmx)?
4. Do you provide spam-filters for incoming emails?
5. Do you provide support for email encryption and signatures (might be trivial, because it's part of the client, not sure about this one)?
6. What are your availability and reliability guarantees? What is your average/90%/99% delivery time and how often do you eventually drop an email? Will you inform me, when that happens?
7. How do you store my emails? Is strong encryption in place?
These are questions that I would want to have answered before signing up for such a service and they are the things that distinguish you from simply self-hosting emails for that money. It's also the reasons why I sometimes have to get emails from friends using their own domain from the spam-filter.
Sending emails is way harder than most people think (source: have worked in email infrastructure of a company sending billions of emails per month). Problems come especially, because email response codes are used differently across email hosters and it gets especially tricky when multiple independent users send emails over the same ip.
2. Same way anyone does it, I'd assume. Shared IPs, rate limits on sending, banning users who send spam emails. I'll likely need to hone exact approaches more.
3. Not that I know of? The mailserver I'm using might handle that.
4. Yea, fairly generic Spamassassin setup that I'm tuning.
5. I think signatures work through Roundcube, and maybe clientside encryption too.
6. I don't have SLAs yet (it's a beta!). My architecture allows for continuous deployment with no planned downtime, though. Delivery from gmail -> my servers and back seems to take about a minute as far as I know, but I can't answer the delivery time metrics without more data. You should get a bounce email on final delivery failure, which should take a maximum of about 208 minutes.
7. They're stored encrypted and compressed in S3, with an encryption key based off of a derivative of your password. Specifically: The encryption is AES/GCM with a per-message key encrypted by a libsodium crypto box, whose private key can be retrieved with a derivative of the user's password. The bucket also has AES-256 encryption in place.
Good questions! I'm going to work on documentation tomorrow. And yea, I realize that sending emails is going to suck.
About DKIM: It adds another layer of authentication to the email by adding a signature. It being absent isn't really a bad indicator, because unfortunately email headers might change during delivery. This will invalidate the DKIM signature. But it being there is a strong positive that the email comes from the domain it says it does. From another perspective: An email that might be filtered as spam without DKIM is more likely to go through with a positive DKIM result.
SpamAssassin assigns small positive scores for valid SPF/DKIM/whatnot headers (and larger negative for lacking either), but it's not really an effective spam deterrant. Spammers can set up their own domains that pass all the checks (although I've heard they're having good times just sending from Gmail).
DMARC authorizes recipient servers to outright refuse email from your domain if it does not contain a valid DKIM signature, and/or comes from a non-authorized IP.
In short, SPF+DKIM+DMARC prevent email spoofing from your domain, protecting you from backscatter and reputation degradation.
If that IP is shared, what's stopping someone else from signing up with you and then sending email that purports to come from microsoft.com?
It's not that easy to find, but it's there. As long as you don't care about using third-party clients (free plan has IMAP/SMTP disabled), it's a viable option. I've used it for a year or two before I've switched to FastMail and it worked fine.
> We sell email.
You do what with my mail ?
I think that's entirely fair. This is a pretty new project, and trust is built over time.
> The attempt at monetization strikes me as extremely premature, given the competition.
Free email services leave a bit of a sour taste in my mouth, since you're not the customer. I'd also have to put more work into stuff like adding hard caps to prevent abuse, but my thinking so far is that email really isn't something you should fuss over storage caps on.
It might be ultimately necessary to attract people (although Fastmail doesn't have a free tier), but I'll get there when I get there. I'm content to take it slow for now.
Thank you! I love being able to just pay a (modest) fee and not have to worry (as much) about perverse incentives. It fixes or minimizes so many problems.
FastMail, et al, alternatively aren't primarily engaged in the advertising business so they'd see a very small return from violating that trust and massive losses, so the gain/loss relationship is inverted.
The strongest endorsement I’ve seen for GSuite is that even direct competitors to Google have no issues using it. They trust Google with their data that much.
Seconded. I'd also add make that domain a .com, .net, or .org.
Yes, some of the other TLDs are cheaper, especially since they started making TLDs for almost everything. But spammers have jumped all over those, using them in from and return addresses. I suspect that a fair number of people have black holed email from entire TLDs due to this.
I know I have. I'm currently dropping all email from domains under: accountant, bid, christmas, click, club, cricket, date, download, faith, gdn, gq, help, info, link, loan, men, party, press, pro, racing, review, science, site, space, stream, team, top, trade, uno, webcam, website, win, work, xyz, and zone.
I'm not sure it's a winning proposition to have variable rate email services aimed at individuals or small companies.
People prefer to know up front what something costs, and I imagine they even rather pay double or triple the "real cost" if it means they don't have to think about it any more.
> Up to five users.
> 5GB/User, 25MB attachment limit.
> Web access only. Email hosting for single domain.
That "Web access only" is pretty crippling.
I know that fastmail will be in business in two years, but I'm not so sure about you.
If you offered some sort of auto-backup option, so that even if you went down I could take my mail elsewhere, that would be more compelling.
The infrastructure I'm running on really is pretty cheap. The biggest expense by far are the databases, which run about $250/month for two. If I had to pay out of pocket to support even just a few users for a year, I'd do it.
Anyway I think the best paranoid option (no matter what mailhost you're using) is to set up automatic forwarding to a backup address. Or you can use imapsync [0] from time to time, which is a bit finnicky but gets the job done pretty well. (I actually might try putting up a quick web interface for imapsync sooner or later to cover import/export use cases.)
Misses sent mail though...
> imapsync
If the emails are deleted on the server doesn't the client just delete them too?
Is there any chance FastMail will implement this anytime soon?
I've done this for years, with it forwarding to my gmail account. I never actually send an email of the @gmail.com variety.
If you want, you can limit the hosts that are allowed to send mail coming from your domain using SPF. Google does not control your domain so they can’t force, forbid or give your the option to do anything, but they do have a supported way for you to add their servers to the list.
This is all legacy though, if you set up a new alternative address you have to allow Gmail to send the messages through your own SMTP server.
I was unaware gmail free has a supported way to add the correct SPF records. Though thinking about it, even unsupported might be as simple as regularly scraping them from gmail and hosting them on your domains DNS records.
But they probably don't support DKIM through that (now legacy?) hack, which granted, isn't that important if emails come from a gmail mail server.
It can forward to any email account/mailbox. e.g. Fastmail or ProtonMail or whoever.
I just happen to use to to forward to a gmail account. I think mentioning that was my mistake given the current sentiment as it distracted from the point I was trying to make.
@Sendotsh then pointed out what he thought was a limitation in using Gmail this way, which I responded to, and here we are. :-)
I have a `.la` but I'm unsure if I want to put my email behind it. Thoughts?
.com has legitimacy, it's not going to have hiccups (some country code domain names are pretty iffy, like .io had issues a while back), and contracts with ICANN ensure it's not going to extort a huge price out of you.
Am I missing something? The domain dropdown has no options and all usernames are taken.
It's fixed now, sorry.
>You can add more users (and any domains you own) later if you need them!
>If you later add custom domains, you can reset your account with those too!
Make sure, for starters, that if you use a custom domain for your email, you use a registrar with stellar security practices, as opposed to Namecheap, Godaddy, and many others that have shown deep flaws with vulnerabilities to social engineering. Otherwise, once someone has access to your domain, they have access to your email, which is the keys to the kingdom.
We have this weird dichotomy in services pricing that's either free or pretty expensive. If you're a free customer, you're not a customer. You're a potential customer in need of sales. And everyone is looking for the features they can put behind a pricing gate.
Let me know if you run into any issues!
Please don't change, even if you get much bigger.
I'll definitely try not to become full of bullshit :). I hope it's not as inevitable as it seems. (It probably helps that there's no VC funding involved, and I can stay small.)