Mail-in-a-Box: a mail server in a box
github.com
github.com
- Setup was largely painless. Main problem was making sure dns settings at my domain registrar were correct.
- Almost zero problems with mail delivery on the big providers [1]. Last time my email was dropped was by amd.com.
- Last year had to do a major version upgrade to mailinabox and it was a huge hassle. I think they need to improve on this. Rolling updates are painless.
Here is my advice to people who are on the threshold of wanting to host their own email, but are unsure because of mail delivery issues. Well, there are zero problems with incoming mail. So setup mailinabox and use that email to register for websites [2]. Use it for all your mailing lists etc.
Do it for a few years and see how it feels. Occasionally send out email. If enough people do it, then over time it will become easier for more people to host their own email.
[1] I have a theory that I deployed. I asked a whole bunch of people with gmail/hotmail email addresses to send me emails first on my new email. I then replied to them. I think this ensured that from that start I was put on the good lists.
[2] Use websitename@yourdomain.come to register. Easy to block spam this way.
This doesn't seem to be uncommon.
MS spreads it's toxic protection in every direction.
Send a dozen emails weekly, in the end felt a bit ridiculous begging. It's a generous free service so I can't complain.
It took me a week of back and forth but I was eventually able to get them to allow my IP address in one of OVH’s banned blocks.
Or people using outlook would treat your emails as spam?
If it's the former, it's kind of shocking. Dark days...
Had no idea that Bronies were still a thing, or that hardcore about it.
They have something weird going on. I had to make an account with them to redeem a game key, and they wouldn't deliver the account verification email to my custom domain hosted by Fastmail. I used a gmail address and the email came instantly. Then out of the blue 24h later the emails to my custom domain were delivered (by which time the verification codes had all expired, of course).
I saw a bunch of discussion where other people reported the same thing like https://old.reddit.com/r/AMDHelp/comments/yr9tqq/amd_rewards... - they got emails instantly when they switched to gmail but other domains didn't work.
I've decided to just move on and pay Fastmail. Email isn't private anyway.
A thousand times this! Everyone even remotely technical or interested in tech should run their own mail server.
For anyone too young to have known, this is how it used to be. Email was desktop (workstation) to desktop. Even when working at large corporations in the 90s, email arrived and was sent to the world directly from my personal workstation.
For anyone worried about deliverability, keep in mind you can outsource the delivery part while still running your own email server for incoming email.
I have experimented with using mailjet as an outgoing relay, for low volumes it was (maybe still?) free. I don't use a relay though, I deliver everything directly. But you don't have to if you worry about delivery.
Why would you do this? For one thing, as parent post says, it gets you used to running the server.
But much more importantly, it gives you complete control of incoming email. Never again is there any chance of google/yahoo/microsoft locking you out of receiving important emails (account resets, bank statements, etc) when you own the receiving server.
Over time you can start relaxing the relaying and deliver directly to most places, only keep the relay to those who give you trouble coughmicrosoftcough.
Or keep the outgoing relay forever if you prefer, but still reap all the benefits of owning the receiving side which is arguably more important.
I do have a few things that I've customized. Updates to MIAB will overwrite them if they're involved in the services it provides. Recently NextCloud updates have been better about removing all of your plugins. The only problem I ever had with it during an update was when the SQLite DB got corrupt. That basically made it so you had to reset NextCloud.
I really wish, we were in a place where such software were designed for NixOS.
Ran into this too, multiple times. Just not worth it if it breaks the underlying OS.
I’ve only caught one sold email being used for spam so far (sketchy wristwatch store that wanted an email to unlock some discount I never used) but really happy I’ll know about the next one.
* Every thread that mentions hosting your own email brings out the it's-pointless-do-do-your-own-mail zealots; ignore them. If you're interested in trying it, try it.
* The only deliverability issues I ever had were with ATT networks because they don't use modern TLS; that was fixable. Mail to Google? Goes through, doesn't go into spam. Mail to Microsoft? Ditto. And this is on a Digital Ocean VM, which isn't the most reputable IP pool in the world.
* MIAB will happily be your full-fledged authoritative DNS server. Although I've since migrated to separating DNS from mail hosting, it was very convenient for a long time.
* Setup is dirt simple. And you get MTA-STS as well as DANE/DNSSEC right out of the box.
* The backup function worked without issue the one time I needed it. I'm sufficiently paranoid that I also do regular snapshots of the whole VM.
* There's a fork, Power Mail In A Box, that updates the UI, adds the ability to plug in relayhost settings, and does a few other nice things. It hasn't been updated in about a year, but was similarly solid.
My only quibble with MIAB, and the reason I migrated to Mailcow recently, is that I wanted to easily set up per-domain relay settings from the UI.
Would you recommend hosting for that use case?
I know some folks have concerns with the privacy of that(1), and really want to run their own SMTP. If that's the case, Mail In A Box can do the job, or you can go with a pure SMTP solution like https://github.com/ix-ai/smtp (not endorsing it -- it's just been on my radar) or a roll-your-own Postfix/Exim solution. The latter requires almost zero resources after it's set up; slap it on a $20/year VM and you're done.
1. Chasing privacy with email is a chimera. If you really want private communications, email is not the tool.
I prefer something like Brevo, which has smaller jumps per tier or even something like MXRoute for $49 per year (limit of 300 emails/hour)
Edit: Completely forgot about ZeptoMail by Zoho - incredibly good value service.
What got me interested is their integration with traefik. It just worked. Not without 9 hours of finding out the right proxy settings, but know I'm attached to it like to IKEA furniture.
On a more serious note, they showed an example of properly proxying a imap/smtp SSL connection. If you asked me before integrating it, I'd have thought it might be impossible, since SMTP has some STARTTLS negotation baked into protocol.
I only knew how to proxy SSL in HTTP and never knew that bare TCP can be used to PROXY and terminate tls as well.
There are altogether too many people who think it's their place to tell others they *shouldn't* self host email, and I think that's a horrible take. It's not too different from saying, "I couldn't learn Finnish, so you shouldn't even try".
Actual, technical objections are fine, but most of the time objections brought up by gatekeepery people just show a lack of understanding and experience. For instance, the most common is "you'll never be able to deliver to...", which is ridiculous. Even if you're on a network that has a bad reputation, you can always smarthost through other providers, and you'll still have all the advantages of having logs and your own filters for incoming email, plus the security of possessing your own data.
The Internet is a better place when less centralized, so it's nice to know that we still have people who haven't thrown their hands in the air and given up to Google / Microsoft / Amazon :)
* https://workaround.org/ispmail-bookworm/
Ansible playbook(s) available:
It doesn't have as many features as mail-in-a-box though for a example no webmail or Cal/CardDAV, so I have to run those separately. It would be great to extend the project
Another similar project is stalw.art mail server. I haven't used that yet but it looks promising, and it supports JMAP (a possible IMAP successor)
One thing about Mail-in-a-Box is you have to dedicate your entire machine to being MAIB, whereas Maddy is just a regular program you can run along with everything else.
https://poolp.org/posts/2019-08-30/you-should-not-run-your-m...
The hodgepodge of software used by MIB is just not good any more.
A few questions:
- I see that it seems to require Ubuntu, assuming this would work on Debian as well without too many needed tweaks? And are there plans to support CentOS? Ubuntu is my daily driver as a desktop OS, but I rarely use it for server apps due to all the "extra stuff" installed and the network stack is slower out-of-the-box than CentOS and I am usually too lazy to do anything about that other than put my server stuff on CentOS.
- Is more documentation available (especially a hardening guide)? For example, I see that Munin's installed (huge fan of Munin, but I'd want to firewall it off for sure), Roundcube used as the front-end management, there are variables you'd want to configure (like support email), I'd probably want to not have sieve open to the world, etc. Basically, I'd love to see a concise list of services and open ports at minimum, so I could figure out what to omit from installation and what to firewall off.
I could have tried this so easily on the new server before moving from the old one.
I am using a traditional provider as "frontend SMTP". Decided against doing my own because I need to send and receive emails for job hunting atm.
When hosting email, receiving is easy part. But storing and fetching it is hard. Sending out, on other side, is hard to configure but easy to store(there is not much to store except DKIM config).
But the hardest part is actually getting providrs to accept your email. I always had issue with ProofPoint and Outlook(Microsoft 365).
I also have issue with 800 emails per hours on fastmail.
Lot of thing like that come up when hosting your own emails.
However, it's worthed it, it open a lot of amazing thing once you own your own email.
With that being said, I recomend Maddy https://maddy.email/ it's a very simple deployment that handle pretty much everything. No need to glue multiple system together.
For spam filering, just use RSPAMD.
---
Are there different hosts I could try? Or am I better off paying for something like fastmail and using them as a smarthost?
I have two email servers running on Digital Ocean just fine - one set up in 2016 and one set up in 2021. It's a matter of doing the initial work to deal with the rejections - following the process the various hosts have set up. There will be a few block lists that you need to submit tickets to to have your IP unblocked. You'll want to create bulk sender accounts (even if you're not) with Yahoo, Microsoft, and Google. It's mostly superstition - "may this web form bring blessings upon my IP". Don't bother actually trying to check any of the reports in the UIs - only Yahoo sends emails to abuse@ for spam reports for small senders.
You'll want to join the Mailop list [0]. I'd say it takes about a month or two, mostly spent waiting, before you are in the clear and have perfect deliverability. Yes, it's annoying. Yes, it can feel hopeless. But it clears up pretty quickly. I've only since had problems with smaller providers and it usually gets resolved by contacting them.
[0]: https://www.mailop.org/ - I think people who work at Yahoo, Google, and Microsoft all monitor this list
You'll need an ISP who can permit traffic on port 25 (usually blocked for domestic connections); a "static" IP address really is necessary (a fixed address, not behind a NAT); and your ISP must be able to handle your reverse DNS entries (IPv4 and IPv6). Any ISP who can handle commercial customers will be able to do all that. And a UPS power source is highly recommended.
In some ways, email is a good place to start self hosting. It's based on store-and-forward, so you can be down for a while ... and when you come back up, any stored email will be delivered :)
But be aware of security, and don't let your server become a spam relay!
It's a bit annoying, but they do it to prevent people from using their infrastructure to send spam. And you only ever have to do it once.
The only downside with MiaB is it is unnecessary complicated to update (both the software AND the server OS). This shouldn't be too hard to address in the future...
References:
I use Ispconfig
they are both ordinary stuff, very very old style
(these all should be in docker swarm nowadays)
Ah, a great modern tool in front of ispconfig is proxmox mail gateway
Unfortunately if you host your mail on linode/digital ocean, you will eventually be blocked, and mst of your email will end up in spam folders.
This year after 13 years of running my own mail services, I finally gave up, I was sending emails and then sending followup “did you get my email” messages from gmail
So you know your own problem. Just find anyone else, or smarthost through a good provider.
I recently emailed a new contact for the first time and their reply to my email went into the Junk folder. How does that happen?
This last week I’ve had two other emails from people that I’ve corresponded with for years go into Junk.
Given how poor iCloud Webmail is - to the degree that it looks like Apple simply doesn’t care about it as a product… at all… I’m not surprised if the internals are being neglected too.
I’ll be moving everything off iCloud very soon.
Just make sure your hosting package/provider allows and supports self-hosted mail. PTR dns records specifically as without your mail might work but much ends up in spam boxes. The mail in a box setup guide covers this too.
I own a couple of cute domain names (something like love.com or pretty.com, but obviously not those), so I'm thinking if I can do a hotmail on those domains.
Edit: It matters because if someone has access to the filesystem, or our MongoDB database, then they still can't read/write to your email mailbox because they don't have your IMAP password (which we only show to you _once_ for 30 seconds and render in-memory). We use ChaCha20-Poly1305 encryption on the SQLite mailboxes (which is generally considered quantum-secure[0]). Passwords are generated[1] via Node.js `crypto.pbkdf2`.
[0]: https://crypto.stackexchange.com/a/90311 [1]: https://github.com/forwardemail/forwardemail.net/blob/d537fc...
On "matters" - I was distinguishing all of a customer's mailboxes being encrypted together vs their mailboxes being individually encrypted. I was saying that the former is the most useful point of comparison I'd want to see - is my data encrypted separately to other people's - not the latter. But I may not be representative.
I've been running my own mail servers for the last, well, 25 years or so. It's fine, if you get your own IP, don't get unlucky by inheriting one after a known spammer, and just keep a clean server.
Don't let other scare you into "having to use" Gmail or other huge ad-tech E-mail providers. That's not what the Internet was designed for.
I've been using mailinabox and it goes to a lot of trouble to provide correct DKIM etc, which I'm sure helps avoid deliverability problems. (Thanks Josh.)
[0] https://docs.digitalocean.com/support/why-is-smtp-blocked/
You should try it.
"Outlook Enterprise" is a mess that refuses email for no good reason. Sometimes it's because Microsoft's DNS resolvers are broken (and can't validate SPF/DKIM), sometimes it's because the mail server rewrites message headers and then tries to validate the signature (which fails, obviously).
I haven't really implemented this in production, but it worked for me one time as a proof-of-concept when I had an issue with disappearing mail - my message went through that time. Later it worked without any tricks, so I haven't bothered.
It wasn't anything complicated, though. I've just did the documented steps to set up Outlook with my own domain (not sure if that's a free option, I have MS365 subscription for Office apps), except that I made no changes that would disrupt my existing mail system - I've added to SPF and DKIM instead of setting/replacing them, and I haven't touched any MX records at all. Then I've just grabbed Outlook's SMTP details and sent a test email to my other test Outlook account via SMTP and it got delivered with my email address, which gave me a confirmation that my idea had actually worked. I haven't really updated my MTA to do the routing thing, as I was about to replace it anyway (I did since then, replaced Postfix with Maddy).
Assuming you don’t send spam, the question of whether or not your IP is on blocklists is primarily a function of both how long you’ve had your IP address, and how well-behaved its neighboring IPs are.
For example I just tried checking[^1] the public IPv4 address of a VPS I’ve been managing for about a year. It’s never sent or received any email for at least as long as I’ve been using it, but it’s showing up on two blocklists![^2]
Surprisingly, my home IP address (which is a dynamic IP, in a pool of other residential IPs) is only on two blocklists[^3] as well. I would have expected more, because in my experience IPs known to be residential are almost always blocklisted, just as a matter of fact!
Of course this doesn’t check the main blocklists used by Microsoft and Gmail. I’d expect my home IP to be on those (because I’d expect the entire pool to be), but maybe my VPS might not be!
Anyway, the point I’m trying to make is that whether or not the battle has been “lost,” it’s definitely stacked against anyone who doesn’t start out with essentially a known-good, static IP address that you can control the reverse DNS record for.
You could do absolutely everything else right, but if you can’t get ahold of an IP address from a reputable provider that isn’t known for spammers using their service, you’ll probably have a lot of trouble with delivery of outbound mail. And that’s not a battle that I want to fight right now…
[^1]: https://whatismyipaddress.com/blacklist-check
[^2]: spam.dnsbl.sorbs.net and dnsbl-3.uceprotect.net.
[^3]: dnsbl.sorbs.net and dul.dnsbl.sorbs.net
You still get to control your incoming email, your filtering, you get logs of everything, you control your email at rest, and you'll still get good logs for outgoing, but deliverability simply is no longer an issue.
So, what other objections do you have for email self-hosters?
I’ve had a mail server in colo for over a decade, and I even recently had to change IP addresses on that server, and I’ve had zero deliverability issues. Set up SPF, DKIM, and reverse DNS, and obviously don’t do anything stupid like send spam or leave an open relay, and you should be fine.
This is frequently the case but not always. Sometimes you don't have any server issues, and originating IP is totally fine, but your messages are 250-accepted then somehow just disappear into the void without reaching the recipient mailbox (not even the "spam" folder).
Fortunately, it's rare (in my experience), but super annoying when this happens, because with FAANGs there's absolutely no way to reach out for any technical support (unless you know someone who works there and they can help you).
Nowadays I user docker-mailserver which is a bit more low level than mail in a box but much easier to setup than everything from scratch
Can second that this is some wonderful software, easy to get started with, nicely documented and works without any significant issues: https://docker-mailserver.github.io/docker-mailserver/latest...
I signed up with a small VPS/hosting provider that offered a decent amount of storage space with their VMs. I don't send spam and have maintained the domain name for a lot of years. I checked the IP for blacklists before migrating the domain to it. I may have had to e-mail one blacklist provider about being removed but if I did, I don't remember it.
Since MIAB sets up DKIM and SPF, your deliverability is pretty good out of the box. I don't send spam and so I think the IP's reputation has been getting better and better over the last few years. The truth is that for personal e-mail, the majority of messages are inbound and that's really not a problem.
By running your own server you can deal with spam as you see fit. I get very little so I deal with it using the "delete" function in my MUA.
But I don't want to bother with outbound reputation so I still use relays to send messages.
who in their right mind would say something like this?
It's more secure, generally, than Google, or Microsoft, or Yahoo, if you know what you're doing, for all of not having the possibility of getting locked out of your own email for no discernible reason and with no real recourse, for not allowing intrusion through other mechanisms of their massive infrastructure, or for not allowing access to your email at rest. Also, many large cloud providers still have issues where one customer can masquerade as another. They don't learn.
Since there's no way to ever know with any certainty whether employees at any large provider is looking at your email (we already know they're scanning it), then you can never have any certainty at all about how private it is. If you set up an email server that uses SSL / TLS for SMTP delivery and reception, then you'll have logs showing whether email you sent or received communicated with the sender's / recipient's email server directly, using encryption, without anyone in the middle being able to intercept.
We can't control the fact that if the NSA really wanted, they could likely make a certificate for any domain that appears legitimate to our servers and do a MITM. Therefore, while I'd assert that my servers are much, much more secure than Google's, I'd never be so naive to say it's "NSA-proof" because of limitations of the Internet that don't necessarily apply to the NSA.
Most folks I've seen do this put such a statement (in the postive) under "non-goals".
I know the us gov. is spying on me, but I also know that they dont care because there is nothing interesting
once in a while I send them dick pics
[1] https://medium.com/@cyberpunk_networks/nsa-proof-your-email-...