Migadu – No-nonsense multi-domain email at a flat price
migadu.com
migadu.com
Another point, which may matter to some people, is that while Migadu may be a Swiss company, the data centers where the mails are hosted were in France (this was the case at least a year ago). So the situation is somewhat comparable (not entirely though) to Fastmail being an Australian company with data centers in the U.S. being used.
For those who want multi-domain email services for a lower (flat) price, look at mxroute. It's based out of the U.S. though, which may not be an option for people who want certain services outside Five Eyes jurisdictions.
Are you saying it's based in the US? (Brit here.)
I believe the "based off of" and "based out of" were popularized among the hipster brogrammers of early 21st century, but I might be wrong.
I am not a native speaker.
You might be saddened to learn that languages are a living thing :), and only "owned" by the people speaking it. Dictionaries are always behind by definition, because they encode the words that have caught on sufficiently: there was never a new word created that was first put into a dictionary and people picked it up from there.
Basically, don't get stressed too much with language changes, because it does and always will. Or what are we to make of "brogrammers" (even "hipster" is relatively new, not to mention most of the computing jargon).
> For those who want multi-domain email services for a lower (flat) price, look at mxroute. It's based out of the U.S. though, which may not be an option for people who want certain services outside Five Eyes jurisdictions.
Weird speaking that, but I would be more of concerned of (an accidental) breach of privacy by some Migadu employee than some <country-name> burreau. Not saying about some typical script kiddie or some hacker-magician getting in possession of logins with passwords as leak. It is likely new on the market and I am tempted to say it has near-zero reputation for anyone looking for a private mail right now. Location do matter, but execution more.
GP here. Not sure if you meant Migadu in this sentence, but Migadu is not new in the email market. It has been around for several years (don't want to visit the website to look it up). I also don't believe that it has near-zero reputation.
> I also don't believe that it has near-zero reputation.
Well, I guess I was too harsh but it is small company that already had various problems while operating (thankfully only downtime / lack of support) and it is hard to trust that no leak or breach will happen (and this is what makes me more concerned than some bureau). I also said "it has near-zero reputation for anyone looking for a private" - I don't generalize to whole service but only to private/safe message exchange. This service is perfectly fine for people in IT, startups or just personal emails but if I would be a person, who exchanges confidential documents I will stay away from Migadu. Why? They do not encrypt data on their servers [0][1], which is clearly opposite to what ProtonMail does [2].
[0]: https://www.reddit.com/r/privacytoolsIO/comments/ltcjc5/what...
> 4. They don't encrypt anything other than SMTP, IMAP, HTTPS. You can encrypt your emails manually but they don't encrypt anything on their servers. They claim this is impractical and doesn't truly help with privacy or security.
> 5. They don't force you to give them your real name or personal info, but there are no anonymous or cash payments. They only process payments via PayPal or Stripe though they claim to not keep any information about you that way.
[1]: https://www.migadu.com/procon/
[2]: https://protonmail.com/support/knowledge-base/what-is-encryp...
> So the situation is somewhat comparable (not entirely though) to Fastmail being an Australian company with data centers in the U.S. being used
I don't know if it is a good comparison, as European countries (France included) are subject to GDPR, which does not really have an equivalent in the U.S.
Both of these changes happened without any email announcement, only visible on their site. So effectively because I didn't login into Migadu dashboard, I was losing emails.
I had a back and fore with them on HN some months back and they were trying to whitewash their handling of the storage failure / rules deletion.
The savings are not worth the risk.
Otherwise have been quite happy and except for a lack of calendar it all works quite well.
I was very interested and very seriously considering signing up, until I read this: https://mxroute.com/docs/do-you-support-2fa-on-email-account... While I respect Jarland's opinion/stance, I do not agree.
If you do enable SMTP/IMAP: sure, it's correct. But that often doesn't apply, so I don't think it's a "trick" or "sleight of hand".
> While many offer this, no one tracks them, and they can’t be limited to just the app (because, again, the protocols don’t work this way). So if your account gets compromised and you have 50 passwords, what do you do besides delete all 50 passwords and start over? Delete them one at a time and see how long it takes for spam to stop going out from your account? Reduce server security and log which password is being used (because that’s the only way to gain that insight from the universal protocols)?
1. Give the passwords names that identify the client app 2. Track that name / login / actions - it's not less secure to track browser type on the web, the equivalent is what's happening here (that's iPhone1, thunderbird on my mac, ...) 3. Present this information to the account user. I should have access to the logs of who's accessing my data. 4. If your account has 50 passwords, it has 50 clients that you have to delete and start over on. Same as if you'd used a single password on all 50 clients.
Then again I'm not a software developer, I'm an admin and hope to be hiring a dev this year. MXroute works mostly on open source or licensed software, with a heavy focus on custom in-house configuration being around the outbound relays, as the initial focus of MXroute was based on getting emails to their recipients, no matter the cost. These days, that's increasingly difficult and time consuming for a lot of people (IP reputation, etc).
SELECT username, ... FROM applications WHERE username = ? AND password = MD5(?)
to SELECT username + ' ' + applicationName FROM ... (as above)
Then log the user name for each session, or return an extra field that is the app name when doing a password check (assumes your MX can do this). This is the general idea, and it's more pointing out why the advice is wrong, than talking about how to fix it and make it possible.Obviously, hosting in the US isn't a cure-all. And there are other good reasons to work with companies in Europe; for instance, their data privacy rules can often be better than ours, which can give you some commercial protections.
But these discussions about where people's email is hosted always talk about jurisdictional issues, and the only jurisdictional issue that matters here is this: if NSA is going to swipe mail from Google Mail, there's a whole fuckload of paperwork they have to do. If they want to get mail from your random email provider in Switzerland, they can just push a button.
within the US, it requires some type of judicial process. You can argue about corrupt judges, power tripping FBI agents, etc. etc. but the fact is, its harder to obtain this data inside the USA.
Further, if you are just committing regular old crimes, the FBI will need to run some type of parallel reconstruction IF they obtained your data using less than pristine methods.
What DoJ attorney would risk their career cause some dumb-ass FBI agent went rogue and pistol whipped the sys-admin for the data?!?!?!?!
https://www.washingtonpost.com/graphics/2020/world/national-...
It's definitely a false sense of security to assume that being on one side of a particular border increases your security. There may be degrees of truth to it but there's no "if your data is here, no agency will ever come for it." When protecting the contents of your data is important, the largest workload should be on sender and recipient. The protocols they decide to use, the encryption they choose for their content, etc.
Migadu has taught me bargain basement email is too expensive in the long run.
And that's at best, assuming you got no emails at all the previous day.
So eventually the maximum you'll get is sum 0 to inf [ 0.9^n ] ... Which is 10x
If allowance is fungible like you say, then sure, you're right. My experience of accountants and lawyers is that they don't treat these things as fungible, and are more likely to do something like:
Day 1:
allowance 200 emails
carried over 0
consumed 0
Day 2:
allowance 200
carried over 180
consumed 0
Day 3:
allowance 200
carried over 180 // 90% of 200 not 380
consumed 50 // consumption taken from allowance first
Day 4:
allowance 200
carried over 135 // 90% of 150 not 200 or 330
consumed 0
and so on.Maybe it's treated as fungible, but IMO the above is how lawyers and accountants would treat it.
So far the best email service I've found is Tutanota, who provide a custom domain for €12 / mo if you pay yearly [1], which is the cheapest I've found so far. I also like how my mail is encrypted at rest. The only downside is I have to use their web client which has limited features.
I chose them for their pricing model: they charge not per mailbox or domain, but rather per total number of emails in/out and storage. While this probably makes them less money, it always seemed like an honest and fair approach to billing.
For my personal domain email, I use Fastmail, but that comes in at $50 yearly. Not something I can justify when just playing around with an idea.
In my opinion, multiple accounts are really only necessary if you have employees or collaborators and want to make sure that not everyone can access your stuff.
But that's just my point of view, I understand that what works for me may not be suitable for your projects.
For small projects, I don’t necessarily want to reply with my main address, hence why I want to have it seperated.
Not true. You can set up Sending Identities to use another address for sending.
One point about your post: Migadu has (or at least had) all the data stored in data centers in France. It also doesn't encrypt data at rest. So I'm not sure how the privacy angle exactly works.
Using a service from a Hindu nationalism supporter goes against my personal world view.
I included the religous connections because some other people might also have similar thoughts.
The money also goes to silent partners, investors etc. so where do you stop?
We should judge people on their integrity and business model imho, religion is a straw man.
That is not the same thing as being religious.
I feel like they really care about how they offer their service and given how laser focused it is that translates into me being extremely satisfied with their offering.
Unfortunately I’m still using another provider for my primary domain because I can’t get real time push notifications on Apple Mail with Migadu—they’re limited to 15 minute fetches for best case scenario
There isn’t anyone else that does this that I know of, and so the value provided in this one area is incredible.
There are other limits, like sending 20 emails per day on the cheapest plan, but I don’t think I’ve ever sent that many emails before.
- service@example.com
- anotherservice@example.com
And they all land on the same inbox and you don’t have to worry about those services that still don’t allow +I think it makes good sense for a free email provider. You don't want to distinguish bobsmith@... from Bob.Smith@.... It will just cause misdelivered emails.
What are people using these providers for, and do you feel like they secure your mailbox enough?
Remember that email communication, irrespective of provider, is not secret unless GPG or similar is used. If a MFA enabled account can be accessed with only a password reset email, it is fundamentally insecure.
Regardless, their security is respectable and their fair simpler infrastructure makes me much more confident that it isn't full of holes.
Office 365 is brutal for sending from devices. In fact it’s impossible with security defaults (more like overrides) enforcing 2FA and one of their supported options is literally (I’m not joking here) to use another mail server that’s not Office 365.
https://docs.microsoft.com/en-us/exchange/mail-flow-best-pra...
I'm looking forward to them deploying 'Alps' their new UI I've been using it on my self-hosted mail and its pretty sweet.
Looking at our usage, the biggest account is 3.7GB, and in the last 180 days the most emails sent was 12 in one day, and the most received was 158 - so micro looks like a fit.
The pricing looks pretty spot on for what we need, and the features seem good, so I've set up a 14day trial with just my email to see how it goes.
I guess the only thing is calendar and contact sync, (I tried to get the calendar to work, but keeps saying it does not exist /shrug)
Any recommendations for a calendar/contact provider?
[0] https://www.billdietrich.me/SecureCommunication.html?expanda...
What happens if I go over the limit, people that send me email get a message that their email bounced because my plan doesn’t allow more?
> If no upgrade is made, incoming messages will be deferred until the following day, and sending messages will be refused If you try blasting mails in or out, your limit will be quickly gone and you will not be able to receive and/or send more. This will also trigged a bunch of alerts on our end.
> In most normal situations, you will be warned if you are reaching your limits so you have time to analyze the traffic and possibly upgrade your plan. This allows you to pay only what you really use.
> If no upgrade is made, incoming messages will be deferred until the following day, and sending messages will be refused
My current setup is very simple. We have a GoDaddy Gen 4 server (don't knock it, rock solid, no issues at all) were we host email for multiple domains as we please. It's super simple. No email hosting nightmares. Just point the MX record to that server and host the site anywhere else or on the same server. One fixed annual cost (~$600/yr) and you can do whatever you want. This is hard to beat.
I've been thinking of migrating to a Zimbra setup to self-host email on something like a Linode server. I absolutely detest per-mailbox/per-user plans. Frankly, it has been very hard to beat our current GoDaddy setup.
If you are dealing with multiple domains, each with multiple mailboxes, costs can add-up very quickly. It then becomes a cash bleed. Every service (not just email) wants $5 to $20 per month from you. It is very easy to end-up spending thousands of dollars per month through these "bleed" costs.
Anyhow, other than time to make the transition, what has stopped me from taking this path is that Zimbra seems "fat" in the sense that it requires a "fat" server to run.
[0] https://www.zimbra.com/ [1] https://pk.godaddy.com/hosting/vps-hosting
Probably.
> Wouldn't you just use GSuite and set up other domains as aliases?
Not if you think this Migadu or some other service suits your needs better or provides better value.
I have been trying to move away from Zoho. I tried protonmail for the last month but it's not for me. E2E is great but the loss in functionality is a bit much.
I switched to fastmail today but I have ran into some issues there as well[1] and so far I have seen a lot of recent reddit posts criticizing the extremely slow response time(2+ days) in support tickets. So, now I am not sure if fastmail is a good option.
Migadu has been recommended to me in the past, maybe I should try that out
[1] https://reddit.com/r/fastmail/comments/m4rj0g/_/h3tq036/?con...
I might just move everything to iCloud+ when they start supporting custom domains this fall since $1/mo for 50GB seems pretty reasonable.
2. Terrible, Inconsistent UI.
3. Push notifications are broken and Their apps are broken. I dont get notifications in clients configured with IMAP and their apps also dont send notifications. I have to manually refresh in both cases.
4. Relatively minor issue but I am against Zoho's founder's political alignment, and that is putting this issue mildly.
I had great delivery with zoho for year even use their free plan. They used to offer SMTP/IMAP on their free tier few years ago and continue to granfathering those my account.
If you like consistent UI then no one can beat gmail. Even fastmail/protonmail/outlook cannot beat gmail in UI/UX to me.
Stay away from iCloud is my advice. Their proofpoint spam filtering is the worst to deal with. Lots of people are going to have trouble reach iCloud inbox.
Anything but not iCloud. That isn't their primary business and consider level of Apple support and randomly ban/block people out of iCloud(you will find some here), I would advice against using them.
Give zoho I tried. They are very reliable, their spam filtering isn't as good as gmail so sometime legitimate emails go to Spam but that's a problem with any mail provider. Time to time you have to train spam system. Especially if you got a lot of email from people with a new domains email you first time. New domains that are created within 7 days and send out email are more likely to be flagged.
It's also not clear what the jurisdictions of the company (I presume Latvia) and its data centers are.
This looks like a good option for semi-important communications if the need is just for a few mailboxes.
migadu's mail number limit does not make sense to me: This risks losing emails.
I was surprised that there wasn't an open source script, a bit like you would run with apt-get, that would simply ask you some questions and do all the bits for you.
Postfix is obviously really powerful but for a noob to it, I found it overwhelming without consulting lots of docs.
I did find https://www.iredmail.org/ but that has a feature limit for the free version. The bits you actually really want costs up to $500/year. Not much if it is for your main business, but a lot when you only want it for a part of your larger system.
Try out this [0] , it’s pretty easy to self host , comes with decent defaults and makes it quite easy to setup a bunch of tools from spam checking to anti virus , dkim , dmarc , etc and gives you some handy parameters you can change in its default config file after that you can further customise the tools it uses directly (although I’ve only had to do that once or twice while setting up some custom settings) Takes 5 mins to setup a decent instance
It's a bad idea to use a small email provider to send emails.
It is a bad idea to support monopolization.
My major problem is the lack of cross platform email clients with snooze capabilities.
This translated in me using gmail UI, which is what I wanted to avoid in the first place.
You can get to paid email clients, but they all include email hosting, defeating the purpose.
https://techcrunch.com/2020/12/08/german-secure-email-provid...
However no, most privacy relevant emails I get are either directly sent from a Webservice, company own SMTPS or other privacy aware email providers.
Sure some friends hit me up with their Gmails, but I usually do not consider these mails privacy relevant.
Mini with 100 outgoing emails for only 90USD a year is comparably bad
The price is right, concerns over privacy and support are not.
I think it's quite refreshing to not have parallax scrolling, and the same tired looking icons and vector graphics.
Everything I need to know is pretty much there on the front page.
in summary it makes it very hard to quickly identify the problem it solves and illustrate how migadu fixes it.
take a look at this article: https://blog.roastmylandingpage.com/landing-page-roasts/
Linked article is just an opinion of some person, and I have to say I quite disagree with it:
- If I'm looking for a email hosting, I definitely know what the pain is, and I assume they will fix it by providing hosting for my emails.
- Testimonials & awards are bullshit. They don't help me determine if I want to use the service or not.
"in summary it makes it very hard to quickly identify the problem it solves and illustrate how migadu fixes it."
I want to host my email, they host email .... there isn't much more to it :)
They don't really advertise, and it is word of mouth it seems - if you have got there, then there is a pretty good chance you know what you want, and can spend a few mins to read through and see if it fits.
I really dislike this "distil everything down because people can't spend a few minutes reading" trend, everyone seem far more interested in marketing fluff and speak, and not just taking the time to understand what they want
What next? UUCP providers? Flat price BBS?