A SpamAssassin Surprise
lwn.net
lwn.net
As a counterpoint, I have been running my own E-mail server for the last 25 years or so, and haven't found it to be terribly problematic. Yes, there is an occasional issue, but I'd rather control my mail, than hand it off to someone else.
Get yourself some managed hosting package with a TLD at Hetzner or somebody like them and run your own stuff. NextCloud with calendars, mail, maybe a blog will cost you sth. like 3 Euro/month.
That's totally fine and the hardest part is finding a good domain name anyways. :-D
More: Fastmail is a bunch of techies who really enjoy working with email and unlike a lot of the big companies we have a core of people who've been doing this stuff for 20 years, but are also keeping up with (or even writing) the latest standards. It's a good combination.
ok, ok - I haven't been at Fastmail for 20 years yet. That's still a couple of weeks away.
The day they start trying to put AI trash in Fastmail, though, is the day I start looking elsewhere.
Search on HN or elsewhere for what happens when Google's automated systems ban your account and you lose access to email and everything tied to it. You have no recourse and no chance to recover it unless you have inside contacts or manage to stir up a social media shitstorm.
You can also use your own domain (for example, tied to your real identity: firstname@lastname.com) and move it to a different provider if your current one goes to pieces.
Additionally, I use a separate email address for each service (hn@domain.com, paypal@domain.com, amazon@domain.com, etc.) and can simply remove the alias if it starts receiving spam. You know then who leaked your email to spammers. You can add a random "IV" to be sure (i.e. amazon-5VoXwj5@domain.com).
The only thing is the automatic banning which could be a huge problem.
I find the UI much snappier, and I don't have to deal with some of the accessibility frustrations of gmail.
Plus, it's a service I pay for, and isn't an ad tech offering.
Fastmail's UI is a ton more user-centric. It just feels more thoughtful to me.
Fastmail treats keyboard shortcuts as first class citizens, so you can run it almost completely mouse free.
Spam filtering is on par with gmail, if not better.
Aliases and throwaway accounts are easy to use if you have your own domain. I don't know how gmail handles that.
When you click a link from fastmail it doesn't pass through a fastmail server as gmail does, but instead goes directly to the source.
The calendar is decent but it's a hassle to import .ics files. It's readable and searchable though. If you attach external calendars then there's some delay when you change something on the external calendar. That can be annoying.
The Contacts manager is OK. It's definitely not special but that also means it's not over-engineered.
They have some file storage and notes capabilities which I don't use, and honestly I worry that it's the beginning of adding features for features' sake, but if that continues I can always keep fastmail and move back to Thunderbird or whatever, although that would suck a little bit.
The android app seems good, but I came from K9 mail which wasn't the most polished. I don't use gmail on my phone so I can't compare, but to me Fastmail's app proves the adage that the better a tool is, the less you're aware you're even using it. It just does its job and stays out of the way, which is cool.
I guess adding new calendar entries on a phone can be annoying. Like you tab the box to add a contact and the dropdown menu is obscured by the edge of the screen, stuff like that.
One annoyance is that editing notes doesn't auto-save. I've lost some big edits.
Upload files (or save attachments) to folders. Okay that's pedestrian. But then you can share links to the individual files or a folder as a .zip, which is heaps handy. So far google drive can do this already.
You can also convert a folder into a website using fastmail's domain or a custom address using your own domain, to share as a listing of files or photo gallery, optionally password protected. I've used this quite a bit.
Holy cow I didn't know you could do this!
Gmail is hostile when it comes to alias / catch-all.
AI is... yeah. I can see in theory being able to have an AI answer questions like "who sent me a question I haven't replied to yet?" or "who have I emailed something expecting a response to and not heard back from?" could be powerful - but the tech is really immature and it hallucinates the craziest things. I don't think it's something we need to do in-house - it's something that could be added on with an IMAP or JMAP connector for those who want it.
How good are you guys at preventing account takeovers? We live in a world where your digital property is backstopped by "send me an email with a link I can click to regain access to a broken account". Everything I've collected digitally over the course of 20 years "belongs" to my email address through that power dynamic. Tens of thousands of dollars of value that I can only maintain access to if I can guarantee that me and me alone have access to my email account, and I will always have access to that account.
I would love to get my email away from Google, I do not trust them at all. But they have demonstrated to me multiple times that they are adept at preventing unauthorized access to my account.
Do you have behavioral account takeover prevention? Do you have a risk and fraud department whose job it is to ensure that me and me alone have access to that email? Do you have people who I can call and demonstrate my identity to in order to regain access to that email account if it does get hacked?
2FA is not an answer.
On the other hand, I am puzzled by your assertion that 2FA is not the answer. Fastmail has passkeys and TOTP... you are a seriously high profile target if that's not enough for you.
> Do you have people who I can call and demonstrate my identity to in order to regain access to that email account if it does get hacked?
Google doesn't have this, right? And actively doesn't want it. Once your account is locked down and you're not falling for the phishing attacks, this is the route in.
> Tens of thousands of dollars
So your security only has to stand up to say $50k of assult? No problem. That's not 0-day money. Just stick with your TOTP 2FA.
If I lose the key to my house, I can change the lock, it's my property. If I lose the key to my Post Office box, the Post Office will charge me money to set up a new key. I have RIGHTS to my physical property and physical business relationships.
What happens when I lose my Fastmail key? Currently the status quo is "get fucked". Which is utterly insane to me. My options in that reality are to either, set up 2fa and ensure that I lose my digital life at some point, or not have 2fa and get my shit taken instead.
Google doesn't do much in that regard, other than making me confident that they won't let anyone else pollute my ad profile, but I was an actual child when I set that up, and it doesn't cost $5 a month.
Obviously, the more information we have about you, the easier it is for you to prove your identity! Often the people who lose all their credentials and can't get the account back at all are the ones who used anonymous payment methods, clear all their cookies, use a fake name. Hard to identify those!
But generally, we help people regain access with a combination of payment method, backup communication methods they have registered with us like another email address or a phone number, and at the most extreme - Government ID. Provide enough of those and survive the lockout period in which we've informed the person with access to the account and given them a chance to object, we can get you back in.
Seriously the "24 hour lockout while we make sure nobody is accessing the account" is a pretty key part of slowing down attacks - generally if someone's identity is stolen then the attacker's main advantage is speed rushing through all their other accounts, so the slow-down is hugely advantageous.
...spamming every online discussion about selfhosting email, [just go with Fastmail, it's greeaaaat!] or like that.
FTFY
True fact, many of us do love reading HN and chiming in. We don't mind self hosters at all. Eventually they get sick of it and move their email to Fastmail, or in extreme cases come work for us!
(it took me a good year of being a Fastmail staff member to finally decide to shut down my own self-hosting and just make it a Fastmail Family account... figured if I was going to get paged by my family for the email being broken I might as well be on the clock)
You must be naive to say that. They don't have your "best interest in heart" - they have to increase revenue. And they will become thew "ad company" sooner or later.
Fastmail is not any different. It's just not there yet.
* https://workaround.org/ispmail-bookworm/
(They include instructions for upgrading from their previous iterations, e.g., buster->bullseye->bookworm.)
Running your own mail can be harder from the start than from our position of having done it for years though. All the things that we know and learned one at a time as they came up, a new mail admin needs to learn at the start. Also, I have old domains with no bad rep, and my mail is sent from static IPs that have been reputationally clean for all the time I've had them (well over a decade). If you run your mail server on a VPS provider you might have more trouble from their IP range than I have from mine (though you do always have the option of paying a little for a relay service like mxroute which will deal with deliverability problems for you).
For me it's quite the opposite, I'd rather let someone who does nothing else all day than providing email services to people for money handle the occasional issue.
Regarding the SpamAssassin issue, TFA doesn’t clarify whether it’s Validity or SpamAssassin that is using the DNSWL interface wrong.
E-mail is not, in practice, a federated protocol which anyone can participate in. E-mail is, in practice, a protocol where Microsoft, Apple and Google can send mail between each others' systems.
Stop using e-mail.
Right after everyone and your grandma stop using e-mail as a UUID. No, phone number doesn't cut.
Recently, I finally gave up running my own outbound email, because I realized that no matter what I do, I'm still being blocked based on my IP address.
I now pay FastMail 5 USD a month basically for their IP address, using them for outbound email only.
Email is anyway inherently and fundamentally inadequate for security.
I'd rather not use it at all now, and stop having an email address.
Apart from rDNS and FCrDNS (which the connecting host has to have) I don't have a Spam filter (and never had). I create a new mail address for everything. (name-number@...) I have gotten like ~2 Spam mails.
(I still have my 25 year old GMX address. (I even have premium.) I use it for my providers in order not to create a chicken and egg problem. Only my MX is public. Everything else is behind a VPN.)
It has become a lot easier than it used to be thanks to things like Mailinabox.
Not quite 25 yet but approaching and same view. Keeping on top of DKIM and SPF and all that have reduced the "I can't send mail to XYZ" issues. Pretty much the only thing I get now is family being temporarily locked out of SMTP by fail2ban when the automatic family-unbanner has missed that entry.
There were occasional issues, mostly a few years ago, with the big providers dropping silently messages or delaying them by a day or so, but eventually it has always worked well. This year has been a hassle with the new rules forced by Google, but during most years the time spent with managing the E-mail server has been completely negligible.
Ideally we should get to a point where self hosted email ecossystem is self sustaining and makes them not irrelevant, but also not so dominant. As developers, we should aim to create out of the box solutions, with batteries included (I've seen more and more such solutions, like maddy, wildduck, etc), that anyone can setup as easily as wordpress.
It should have default sane and secure configs, with a simple UI with a setup wizard with options like "Single vs Multi Tenant", integration with DKIM, SPF, DMARC APIs on most DNS providers, etc.
The goal is to kill the "misconfigured email server" argument from the giants.
I have very rarely had issues reading email.
I think the best bet is making email better and easier to self host,
https://devblogs.microsoft.com/oldnewthing/20060523-10/?p=31...
> maybe invent something
Good luck with that. So many have tried, none have prevailed.
https://www.demandsage.com/how-many-emails-are-sent-per-day/....
In the current email system who represents the interests of the common user? Not gmail. Not mailchimp. I'm not saying they are bad, just that their interests are not my interests.
So perhaps the right thing is to add a layer to email that provides common users control. Email servers that provide consensual service can talk to each other. Not a white list, a trust list. Otherwise just use gmail.
How to do this? If you send a non-consensual mail, you pay a fine. A way for mail providers to make money by improving the basic function of common users.
I'm just making this up, I'm sure you can come up with a better system. Or perhaps you can help me understand whether the purpose is valid or not?
Spam is already illegal, but spammers don't pay a fine because good luck actually finding them.
This also describes all other communications and socialness on the web; from bbs and forums to modern "social media". Is there anything small and niche (apart from, literally, HN) that hasn't been completely utterly destroyed by the nasty people online?
User upvote/downvote systems can be helpful, provided there are checks and balances against being gamed.
Local and specialist fora are doing quite well. Some have been around for decades because they offer what social media promises but doesn't deliver. Examples:
https://thestampforum.boards.net
https://thehaif.com
https://forums.atariage.com
Most offer RSS, so you can roll your own "feed" like a social media site, but without being followed, tabulated, and monetized to death.Their secret is friction and moderation. You have to jump through a hoop or two get registered, unlike social media where the barriers to entry are so low that bots step over them without a care. That's because these web sites care about the content, not tallying up monthly user statistics for shareholders.
It's like radio. If you're in Los Angeles, you can listen to KROQ, which serves its corporate owners and shareholders far away, or you can listen to KCSN, which serves its listeners locally.
That is, I'm using greylisting, and yes, this still blocks quite a number of incoming messages, as spammers do not retry to send their spam, if it doesn't work at the first attempt.
So with excellent software like Wietse Venemas Postfix and a rather restrictive setup, an email server is a low maintenance server to use IMHO.
Edit: running your own email server gives you enough email address for you and your family to make it much easier to detect phishing emails: one address per shop and you'll notice if an email to the address of a shop tries to pose as your bank or some other sender. And it's easy to block certain senders after their job is done.
I highly recommend the experience for those interested. I also recommend regularly reevaluating whether you’re still having fun doing it.
Another reason why it's not great to use allow/block-lists: You're passing the IP's of everyone you're communicating with to those 3rd parties.
In mox (a mail server, I'm the author), junk filtering is first done based on known good/bad reputation of the (verified) domain of the address of the sender, based on classifications made by the user (and mox helps with those classifications). That means everyone you've seen good/bad mail from before, can quickly be classified without the need to contact any allow/blocklist. For first-time senders, a bayesian content-based classification is used. That is almost always is good enough. But you can also configure blocklists. They will only be consulted as long as there isn't enough reputation for the sender. Once you've corresponded with someone a few times, the blocklist isn't used for their messages anymore.
I feel articles like this overstate the burden. I can agree that running a self-hosted server at scale (multi tenant/multi user) could be very painful and would be a full time job.
But if it’s a single user (you), it’s almost set it and forget it. Many resources out there to test your mail server is configured correctly (ie, mailtester).
The only painful issues I have had:
- if using a “dynamic” IP from a VPS host. You might find that many RBLs block them by default. It’s somewhat easy to get it reset though, and have only had to do it twice (cloudmark and outlook).
- occasionally have to deal with obvious brute force attempts to find vulnerable accounts. But this is resolved with fail2ban and setting up alerts on postfix and dovecot logs
Also, compared to the old days. There are many projects that make it stupid simple to setup a mail server with sane defaults.
Current projects I am watching:
- stalw.art
- docker mail server
I have been considering stalwart. Especially since there are plans to add in CalDAV (Calendar), and CardDAV (Contacts) support. I was previously looking at Cyrus IMAP for this functionality but will ultimately wait/support stalwart for the AIO solution.
> configuration was introduced as part of a hurried email server replacement driven by the demise of CentOS 7
They knew for YEARS, and even after the Red Hat controversy of shitting down CentOS, they still sat on their butt and did nothing until the very last minute, and then f*ked it up. That's some serious negligence.
Also, any competent self-hoster knows you need to run a recursive DNS resolver on-host to avoid these kinds of issues. Many other DNS-based RBL services already had such limits and those issues were extremely well-known. This is another sign of negligence.
This guy is an idiot and should not be running a mail server. And, he/they have no business telling anyone else what to do.
But I'm stuck -- I exclusively use 'tagged' email addresses when giving anyone my email address, so every incoming message is addressed to "myusername-sometag@domain"... and gmail, of course, uses a + instead of a - for doing that kind of tagging. So if I tried to migrate hosts, literally none of my incoming email would arrive anymore.
Sucks that a decision I made before gmail even existed now restrains me so much. :/
https://www.fastmail.help/hc/en-us/articles/1500000277942-Ca...
https://help.zoho.com/portal/en/community/topic/receive-only...
I have a similar mail address pattern (ebay-534389@foo etc.) When I started 7 years ago. I opened my password safe and changed one account after another. If the old account received something I overlooked and I was still interested in it, I changed this address too. A year later and the old address receives nothing anymore.
Nothings stops me or you from changing it back.
Update: And yes, there are a million providers that provide a catch-all mechanism. Even some domain registrars provide catch-all forwarding.
And never use "+" as a separator. There are zillions of shitty regex email address "validators" that won't take it even though gmail uses it.
Self-Host or Email as a Service both have their intermittent issues.
The number one sources of the very worst spam that lands in my inboxes are Google, Microsoft, and Apple, and by worst I mean the most legitimate-appearing messages that contain the most hideous of links and attachments.