1. I'm a control freak and a privacy freak. I don't trust any third party with my email. I want to know how things work under the hood. And if I want to make a change, I don't want to have to depend on any third party to do it.
2. It's not hard to do. apt-get install postfix and dovecot, invest a couple of hours munging config files, and you're done.
3. Much easier to transition your data if you do get "enterprisey." All your data is on your server, so you can just tar it up and ship it anywhere.
4. You can configure the server so that insecure connections are not possible, making it that much less likely that someone will leak a password accidentally.
5. Stealth. It's much less likely that someone will try to break into my server than into Google's servers.
2. It's not hard to do. apt-get install postfix and dovecot, invest a couple of hours munging config files, and you're done
Bullshit. There's troubleshooting when things go wrong, patching, maintenance, etc.edit: don't forget adding additional storage, managing spam and malware filtering, user admin, backups, and other tasks.
5. Stealth. It's much less likely that someone will try to break into my server than into Google's servers.
You wish. Your single server is much easier to target and break into than Google's.In over 10 years of hosting my own email I've never had a problem that needed troubleshooting after getting the initial installation sorted out. And patching on Debian is trivial.
> Your single server is much easier to target and break into than Google's.
"Stealth" does not mean "harder to break into", it means "less likely to attract the attention of someone with the means and motivation to break in." Google may be harder to break into, but it's a much bigger target.
My house is easier to break into than, say, Bagram air force base. That doesn't mean that I'm safer in Bagram.
Patching is never trivial. The process itself may be trivial, but you have to actually do it. That latter part requires ongoing attention, which makes it non-trivial.
less likely to attract the attention of someone with the means and motivation to break in
That depends. Most attackers go for low hanging fruit. And the fruit hardly hangs low at google with their dedicated security team.
The most juicy targets are actually those little homebrew servers that someone once setup and then mostly forgot about. The spammers can often use these servers for months before anyone (usually the ISP, not the owner) takes notice.
If your server is listening on Port 25 then it's not stealth. It's very likely being scanned while I write this comment - perhaps to see if it's an exim vulnerable to the recent remote-shell exploit (http://www.debian.org/security/2010/dsa-2131).
So, to wrap this up. I also run mailservers for various companies. I also run debian. I even also run dovecot and postfix. But I'm doing this for a living, am subscribed to the relevant security mailing lists, harden the hosts before deploying them, and I monitor them.
If you don't have a dedicated or hired admin to do all that then hosted e-mail usually has the better value proposition.
Not sure what you mean by additional storage? Local corporate e-mail might take up ~10GB per person after a few years? Most of my servers have 1+ TB of local storage + SAN. Takes a lot of e-mail to fill that up.
Spam and malware filtering are both pretty easy. yum/apt-get install clam and/or spamassissin/razor/pyzor/whatever. If you're running your own server(s) anyhow then backups, user admin, etc... are a sunk cost you've already spent.
If you're running your own servers anyhow, it's really not a big deal. I have a normal GMail account and a enterprise google apps account and both of them have pretty frequent IMAP outages (usually just for 5-15 minutes, nothing serious) whereas my mail servers haven't been down in years (minus planned server migrations). Also, if something does break, I like being able to go in and fix it, without waiting for other people.
(conspiracy theory: Google gives the public one text box on a webpage to search the Internet. Do you think they don't have a text box on an internal webpage to search all of Gmail? Do you think facebook doesn't have one internal webpage capable of searching all private communications? Facebook used to advertise "spy on your friends!" as an employment perk.)
and who can subpoena your private communications.
Hate to break it to you, but that same subpoena can just as easily allow your house, office, or datacenter to be raided. Your data is just as susceptible to lawful intercept at Google as it is your private premises.Furthermore, you can fight a subpoena. Do you trust Google to fight a subpoena on your behalf? How would they even know whether or not they should; how would they be able to tell if the subpoena is reasonable or not?
That kind of thing would leak out sooner or later.
It might not be as easy as a textbox to search all of Gmail but your gmail data store appears to be wide open to a fairly large number of google employees.
It's more likely that someone will break into your server than Google's, isn't it?
A thing I learnt while running my own server was that all you needed to be a victim of automated attacks was to have an IP address.
True, it is probably easier for someone to break into my Linode than a Google server. However I think it's probably even easier for someone to break into my Google account. The surface area of a Google account is huge nowadays..
Email should be considered public. Unless you're using encryption it's sent in plaintext and could easily be stored on any server it goes through. While it may be harder for the gov to get access to it a clever hacker or employee can still get it.
> 5. Stealth. It's much less likely that someone will try to break into my server than into Google's servers.
Security by obscurity is not security at all.
i do complex server-side filtering with procmail to keep my inbox clean (so all of my devices polling my mailbox will only alert me when something important comes through), automatically archive all email in an "allmail" backup folder, and do things like rewrite e-mail headers for certain conditions.