Personal Mail Server on OpenBSD (2019)
nicolascarpi.github.io
nicolascarpi.github.io
Being a neighbor to Tor exit nodes makes mail servers complicated.
I don't have a personal opinion about the company; however, email is important enough that it's worth considering edge cases and future scenarios.
Also, to remove the problem of false positive, refuse spam at the SMTP connection level and do not use a spam folder. This way users will get an MTA email in case of false positive.
On my Fastmail account, 99% of spam comes from a gmail address. I imagine there's a lot more that are filtered upstream with a similar DNS check, but my point is I receive most spam from legitimate addresses on the world's largest email service.
This provides natural pressure for gmail to reduce their outgoing spam rate. I'm sure they do try to get outgoing spam down. Spammers are just a resourceful bunch...
Any large free email provider will have these problems. It's a reason to use your own domain for email, with your own reputation, instead of sharing your reputation with the whole world, including spammers.
I am not doubting you, but did you check that the email was actually coming from google servers?
I don't do any kind of content based filtering in part because some of my users do anti-spam, anti-phishing work, so of course they need to be able to talk about spam and phishing, and they need to forward along spam / phishing, without worrying about filters.
Also, every email, accepted or not, has specific reasons for what happens to them, not a vague set of rules that nobody knows like Gmail has.
I also skipped using IMAP or POP3. There's a mail server with global IP addresses, that forwards inbound mail to my local workstation over WireGuard. My email clients read mail directly from /var/mail. Remote email access is via ssh terminal sessions. Not for everyone, but that's what I do.
I always enjoy the self-hosting explanations. Starting with mail is an interesting choice though. It's relatable to most people, but also very complex compared with a tougher DNS setup, DKIM, SPF, all that stuff.
I'm not sure what the right approach is to maintain good security, and then open up the right ports for simple services.
Fastmail had to implement this a few years ago ourselves, after 20 years of allowing whatever, we had to start by auto-whitelisting all the addresses people were sending from for a while, then slowly start introducing a requirement to prove control of the sending address to add new sending addresses over time! Obviously hosting your domain with us gets you auto-approved for any address on that domain, but otherwise you either need to confirm that you can receive email at an address to send from it now.
But SPF by itself is pretty flawed. I'm keen to write more about DKIM2 when it gets chartered at IETF (hopefully) and we can post more public documents, but it should supersede SPF/DKIM for most uses.
The one big problem I've run into is sending emails to mail servers running the Proof Point blocklist. They have my IP blocked, and there seems to be no way whatsoever to get it unblocked.
Maybe you need to have an enterprise account with them for them to even listen to you.
If it doesn’t work without a middleman then it doesn’t make sense to run your own service. Any spammer can rent a server the way you can.
Would love to see a robust tutorial to show us how to really do spam protection right.
What if said AI gains sentience, but trained on that data?!
The real work is making sure that outbound mail gets delivered, but even that is just making sure you have a clean IP and setting up reverse DNS + DMARC/SPF/DKIM...
https://notes.sagredo.eu/en/qmail-notes-185/razor2-pyzor-spa...
I investigated further and these don't really seem to be incredibly active projects, you sure this is the best solution?
No, but I've been using it without issues for close to 25 years.
If you don't want to run a completely custom setup, there's projects like mailcow out there that can do the heavy lifting for you.
I really don't see a quantitative or qualitative difference between the gmail experience and mine, with the caveat that my setup doesn't label ham from other private mail servers as spam (arguably a good thing)
I self hosted for several years and gave up because even with a clean ASN, I simply wasn't sending enough emails to keep my reputation score high enough, and so deliverability into the big players (Microsoft in particular) was very spotty.
Email isn't that hard it's just laborious to administrate.
I’ve used a smaller hosting company for over 25 years run by a competent admin and it’s now dying a slow death I believe exactly because of this reputation problem from infrequent outbound emails from my domain.
I don’t know what to do tbh because putting my fate in big tech seems super dangerous.
Anyway, everyone is worried about spam but the real problem is sending and having people at outlook.com and gmail.com actually receive your emails!
Now that the era of free money appears to be over I'd not be surprised if I was reading a blog post about an "incredible journey" at Gmail within the decade.
While I think that everyone hosting their own email is the ideal, it's not really feasible on today's Internet. I content myself with fastmail. They're big enough I'm not worried about them dying any time soon.
Get a clean IP and start long form email threads between this new domain and personal Gmail / outlook accounts: checking ‘this is not spam’, and coherent responses.
They also mention getting DKIm and SPF working.
The need for separate caldav , and all the major cloud providers blocking port 25 bummed me out.
I, for one, welcome our new AOL overlords.
Best I can guess is that my host's netblock just happens to be sparkling clean, but it sounds like even that may not be enough anymore
One of the good ones would be Fastmail but there’s many more.
(and thanks for the Fastmail plug)
While I'm every bit qualified to run my own email service, I don't. I pay protonmail to do that for me these days and save myself a lot of time, effort and stress.
Replace "email" in what you wrote with "web". Is it just too easy for something to go wrong? Sure, for certain kinds of people. Everyone should just stop hosting servers altogether, if we're worried about things possibly going wrong.
People here, generally, aren't technically illiterate. We don't need you to tell us that because you're not comfortable doing something, we shouldn't.
It's obvious when your website goes down. It's not obvious that emails aren't being delivered and you've missed something important that you'll never see.
Also, I don't agree that it's not obvious when something goes down. You don't know how I or my users check my email. If anything, I hear from people much more quickly when there's an issue with email than web!
To reply to something you said in your first comment, as someone with over a decade of experience it is my place to share my thoughts about this subject. If you want to ignore my thoughts go ahead, I could care less.. but I don't appreciate how you're acting like I'm doing something wrong.
Maybe spamd is sufficient, but I ended up switching to gmail which was initially great but has dropped off in efficacy over the years.
I also understand sending email can be difficult with strict SPF rules in place causing many email providers to reject legitimate emails from smaller email servers.
https://blog.qualys.com/vulnerabilities-threat-research/2020...
My simpler (?) setup based on the same logical flow as Nico's:
1. Check assigned IP from provider (Hetzner in my case) for issues on black lists (MxToolbox worked great for me).
2. Set up reverse DNS with your provider.
3. Install OpenBSD: confirm default, confirm default, ..., enter hostname, enter username, enter password, confirm default, confirm default, ..., select mirror, confirm default, confirm default, ...
4. Use ssh-copy-id(1) to authorise key logins for the user you set up during the installation.
5. Set up DNS records for both the hostname and SPF (confirm propagation/settings with say MxToolbox, it will be helpful at pretty much every step, so I will stop repeating it now)
6. Enable httpd(8) with `rcctl enable httpd && rcctl start httpd` and set up acme-client(1) with the examples from: https://man.openbsd.org/acme-client
7. Enable and configure spamd(8) (note that I disable greylisting) and uncomment a few lines in `/etc/pf.conf` and reload your PF rules:
> echo spamd_flags=-b >> /etc/rc.conf.local
> rcctl start spamd
> vi /etc/pf.conf
> pfctl -f /etc/pf.conf
8. Configure and enable (`rcctl enable smtpd`) OpenSMTPD, which is about as easy as it gets (I am being more explicit about the hostname than I need to, but it is necessary as the box has multiple hostnames and the MX one is not the primary): pki $HOSTNAME cert "/etc/ssl/$HOSTNAME.fullchain.pem"
pki $HOSTNAME key "/etc/ssl/private/$HOSTNAME.key"
table aliases file:/etc/mail/aliases
table domains file:/etc/mail/domains
table secrets file:/etc/mail/secrets
table virtuals file:/etc/mail/virtuals
filter "rdns" phase connect match !rdns \
disconnect "550 Reverse DNS lookup failed"
filter "fcrdns" phase connect match !fcrdns \
disconnect "550 Forward-confirmed reverse DNS failed"
listen on all tls hostname $HOSTNAME pki $HOSTNAME \
filter { "rdns" "fcrdns" }
listen on all smtps port smtps hostname $HOSTNAME \
pki $HOSTNAME auth <secrets> mask-src
action "local" mbox alias <aliases>
action "relay" relay tls helo $HOSTNAME
action "virtual" mbox virtual <virtuals>
9. Fill in `/etc/mail/domains` and `/etc/mail/virtuals` with the domains and virtual inboxes you want to handle.10. `rcctl start smtpd`
That is it. DKIM is annoying, as it requires a package from ports and all we just did above was with the OpenBSD base system, but it turns out delivery works just fine without it for a small family server (even for Google and M$). I think there is an argument for DKIM (although it adds next to nothing over SPF) to be in base OpenSMTPD as I believe all the complicated code is already in base, but I am not intimately familiar with the OpenSMTPD code base and trust that it will happen if the e-mail climate becomes even more oppressive.
I am cheating somewhat here as I am not doing local delivery/retrieval but relaying to an external SMTP server as I have yet to find a more minimal solution for POP3 than Dovecot that I feel comfortable hosting (pop3d gets close (https://github.com/snimmagadda/pop3d/), but I would need a code audit and I have lacked the time).
This is all from memory (apart from the nearly default `/etc/mail/smtpd.conf`) and I of course take no responsibility for anyone copying and pasting blindly without thinking (this is OpenBSD after all: Use your head).
A final word, if you ever have trouble, use MxToolbox or similar and they will lead you in the right direction if you have misunderstood the documentation or in other ways messed up the configuration.
Admittedly, my "random IP" (and box) with Hetzner comes with a cost of seven or so times per month compared to what you write. But I find it tiresome that we pretty much end up with two camps in every single e-mail thread. One that claims that self-hosting e-mail is dead and impossible in year $X and one that claims that it is not. Stating either of these absolutes is unhelpful as e-mail in year $X requires a lot of nuance.
I should end my comment by stating that I am not attempting to call you out as the worst offender and I appreciate you mentioning delivery services. Until Google started enforcing SPF or DKIM I had a nice working setup where I used a well-established, non-profit SMTP as my outgoing relay as I was scared to bits after reading so many comments about e-mail horrors on HN.
Pre-2005 running FreeBSD was a nice little "secret" that allowed you to run a rock-solid OS without drama or headaches. However, professionally nowadays I've accepted the fact that linux "won" and I don't want to deal with the headaches of finding people that can admin something niche, on top of so much tech tooling being designed on and around linux. Most of my work is done supporting docker containers in some way, so why fight even if it's possible to run docker on FreeBSD...
That being said the filesystem certainly is the weakest part of the OpenBSD and given the uptake in filesystem designs with ZFS, Btrfs and Bcachefs it is interesting to see that OpenBSD is left behind.
For a personal mail server, or even small business, it's not really an issue, you're likely not going to have terabytes of email.