But even beyond that, can they be compelled by a court order to install software on the VPS (and securing against someone with unlimited access to the VM host is… about as practical as securing against someone with physical access)? I'd assume so?
The main benefit to me for runnign my own email is owning my own data/domain, and not having to allow third parties (aka google) full access to all my emails.
It is your call how long you save/enable logs and if you save them to tmpfs and encrypt your swap. You can also encourage your users to 7-zip encrypt sensitive contents. You can also add specific MX routes in transport maps to use VPN connections to make connection logging less useful. Tinc (open source VPN) is great for this, as traffic routes in user-space through your mesh and therefor traffic can end up at its destination without a direct connection.
But you're asking the wrong questions. Email itself has retries built in, it doesn't need perfect uptime. What you should be asking is how badly Gmail deciding you might be a spammer and not caring about fixing that for one person is going to torpedo your deliverability rate.
It took about 1 day to set it all up, where most of the time was spent waiting for DNS changes and for Microsoft to de-list my IP from their blacklist (I probably got a bad IP from DigitalOcean).
After that I have logged in to the instance every two weeks to update the machine, haven't had any problems as of yet.
The uptime shouldn't be any problem, as the other mail providers should retry sending their mail, it's even mentioned in the RFC: https://tools.ietf.org/html/rfc5321#section-4.5.4
Hopefully I haven't missed any mail when updating mailcow-dockerized, I'll never know, hehe.
Really easy and a great experience, compared to doing it from scratch.
By default, they both apply strict security practices so you won't have an open relay, worried about domain masking etc.
Either are about a day to set up and its mostly DNS.