I just wanted an email for my domain and that's not worth 50 bucks a year. I'll just set up my own email system at this point, call it a learning experience and never be exposed to the rest of whatever was in Google Apps.
I just wanted an email for my domain and that's not worth 50 bucks a year. I'll just set up my own email system at this point, call it a learning experience and never be exposed to the rest of whatever was in Google Apps.
(And, when I was first doing this, someone trying to hire me for a job couldn't email me, because their hosting provider was once friendly to spammers and my aggressive blacklisting rejected their TCP connections. Oops.)
Running an email server is hard and very few people regret paying an expert to do it for them.
(As many HN readers know, I work for Google. But I'm not telling you that you should or should not use Google's product here, only that running an email server is not trivial.)
Sleep on it I guess, see how it looks in the morning.
I use Google Apps to host 4 email addresses for my personal domain.
Personal email Online shopping email Forums/Programming email Facebook-only email (so people can't search for me)
I use it for me. I wouldn't pay $20/month for such a service, and Google is smart for not taking free away from existing customers.
No exim4, no spamassassin, no clam-av, no figuring out which indexer to use, or any of that. Just a forward on the incoming mail.
I actually miss running my own email domain, the privacy of it, not the actual administration. I stopped when I had gotten so crazy with aliases and disposable addresses that the spam overwhelmed me. Wasn't worth the time to 'do it right,' and I gave up my privacy for the simplicity of GMail.
I would love to leave GMail and take my privacy back, but I haven't found an acceptable alternative yet.
i fail to see how making good use of available resources is "cheating". the idea isn't to win some geek hair-shirt contest; it is to get email delivered to your domain.
There are many email providers you can use with your own domain. For example, rackspace is $2 a user a month. https://www.rackspace.com/apps/email_hosting/rackspace_email... I'm not sure why people are jumping from "Google won't do this for free for me anymore" to "I must do it myself".
It's pretty easy actually but when authorizing GMail to add a new sender address it usually mails a verification code to that address. Which, in this case would come back into the same Gmail inbox.
So if you have a X@Y.Z forwarding to A@gmail.com, then the verification code would be sent by gmail to X@Y.Z, which in turn, due to your forward settings, would redirect all mail to A@gmail.com.
The difference is that when sending mail from your Gmail.com inbox as opposed to the Google apps inbox for X@Y.Z is that when you send a mail via gmail (even if you fake the sender), the signed-by field will contain "gmail.com". On the other hand, Google apps for domains will set the signed-by field value to "Y.Z" (which would be your domain name).
As far as I know, this is the only difference. In Gmail, you can even set the default sender-address as your custom domain address so you don't need to set it everytime you reply to/compose new emails. And, unless you think/feel that signed-by: domain.name is cool, you're not really missing anything.
for now
myemail@gmail.com on behalf of Rob Aley [me@mydomain.co.uk]
It maybe looks a little unprofessional, but as long as your gmail account isn't something like offensivewords@gmail.com or cutesexyman32@gmail.com, its not too bad.
There are no internet authorities that control mail delivery, either, BTW. Many sites use heuristics to control mail acceptance, however, including third-party whitelists and blacklists. It can suck if you get on a blacklist, but experienced mail administrators only use whitelists and blacklists as one of many metrics regarding mail spamminess. Indicators of good mail like "most of the words in this message are non-spam words" often provide an order of magnitude more ham points than blacklists contribute spam points, so important messages will probably not be dropped even if you're on a blacklist. Of course, many sites have less clever schemes because there is a lot of spam and not a lot of sysadmin time to waste tweaking spam filtering rules.
Mail is hard.
In any case, from a decade of listening to the random things he's had to deal with, I certainly have to agree with your final comment.
I think there are probably some MTAs that will STARTTLS for normal SMTP connections, but again, I've never heard of anyone using SSL/TLS as a spam-filtering criterion. (I might look through my old logs to see if anyone other than me ever issued STARTTLS on my mail server. But I'm guessing the number was near zero.)
Last year I moved and my IP address changed (ISP didn't). I expected to lose the "reputation" the previous one had built up. But I did not have any problems whatsoever. I do hear rumors like yours every now and again but I have a hard time believing them.
I think that large email providers, the likes of Gmail/Hotmail, actually look at the email addresses / domains / servers that their clients send email to. Then they assign trust to those tokens. If you're a large provider, you can do many things with the data you get from your own customer's behaviour. How about looking at accounts that have been in use for some time, seen regular web interface action, and send email to other @hotmail/gmail accounts that actually get read and not flagged spam? If those accounts send mail to my mailserver, then my mail server / domain must have something good going for it. Well that's what I would do if I were running a huge setup anyway...
As for incoming spam: I'm using various postfix tricks, greylisting, and dspam. I have no problems. I should write a howto ;-)
Why? I have two VPSs with the main and backup SMTP servers and with continuous replications of emails between them and I pay less than half. Not to mention they double as web servers, IRC bouncers, etc.
And no matter what I did to reduce spam, about 10 messages a day always made it through.
I probably never get the same traffic as you do, but to me the best decision I made was enabling catch-all and using different addresses for each service out there.
In my case, spammers only send to three types of addresses:
- Random (jumble of numbers and letters@mydomain): very easy to block with a couple of programming lines.
- Fake but plausible (support@, bob@): just blacklist them once.
- Leaked (from websites and such): same as above, nuke it. Only happened to me once.
All in all, I never had to set up SpamAssassin or deal with dropped emails because of untrusted sources. Blocking by destination is much cleaner.
This does not include incoming bandwidth, bandwidth used by your IMAP or webmail client, or DNS lookups that you'll do for every message received. (Also, spam filtering is CPU-intensive, so if you get a lot of email, a Micro instance may not be big enough.)
This doesn't include a secondary MX, either. (I like the DynDNS secondary MX service, personally, which is ~$30 a year IIRC.)
Just tell me where to sign up (next year when AWS free tier expires).
And?
Free users threatening to leave are hilarious (even better when they campaign against ad targeting and AdBlock everything). Google's decision pretty clearly signals that users like you aren't worth it to the company any more than Google Apps are worth $50 to you. Don't do business. That's the point of a market.
I wouldn't pay for it either - I'm grateful that my Google Apps are grandfathered, but nobody is entitled to GMail, Facebook, Twitter, etc. It's a voluntary transaction between two entities and, in this case, you and Google Apps aren't a good fit.
I'm not an enterprise. I don't need more support than regular GMail users. I don't have special needs, like managing what services are allowed. I just don't want a @gmail.com address.
I see people here defending this move, but think of how services like Google+ make mandatory an email address that's managed by Google. That email address will now have to be a @gmail.com address for regular users. Now think of how you can register with any email address on Facebook or Twitter, an email address which becomes your online ID.
By using your own domain with your own email address, if the email provider interrupts the service for you, you can always change your MX records and recover all the accounts that rely on that address. That's not something you can do with a @gmail.com or a @yahoo.com or a @hotmail.com address. If Google cuts off your access for some reason (like in case they find out you're under 18 or some bullshit) or if they delete your account by accident (hey, shit happens), then at the very least your online identity is not lost.
Freeloading is not the issue for me. I am already a paying Google customer in other ways (I buy stuff from Google Play, I pay for Google Drive storage, etc...) and I would happily pay them $50 per year anyway. The bigger issue is that using any Google service requires a Google email account, with Google Apps being a mild remedy for that.
How can I encourage people to use Google's services now? Not mentioning that 2 businesses are now paying customers of Google Apps, because of my freeloading and my recommendations for it.
Also, WTF is it with Google and raising prices? Companies are usually cutting prices down, while they are raising them. This also makes it an issue of trust - usually when I subscribe to services, I expect prices to go down, not up, otherwise I cannot trust it. My trust in Google is eroding right now.
What next? Make Chrome and Android proprietary with a yearly subscription for users? Lots of pesky freeloaders out there.
Plain-old GMail is no different (from a UX perspective) from being the sole user on a Google Apps account, so admins haven't really lost anything in terms of being able to evaluate Google Apps. There's nothing particularly interesting in the free version's admin panel.
Then there's spam... don't even get me started on spam filtering. For me personally $50/year is a bargain considering that running, maintaining, patching a mail server is time consuming and has no real upside.
As a learning experience it's fine, but in practice delivering mail (reliably) sucks hard.
The rest is still a bit of a hassle.
You could sign up for Google Apps, point your domain MX to Google and forward all your SPAM free mail to your private server from the Google Apps console.
No kidding, I've seen so many companies that had their mail systems in premises setup a 1 user Google Apps account ($50/year) to do what I just mentioned above. They got rid of most of their SPAM and saved tons $ on wasted bandwidth.
Has anyone found a good solution for this? I could host it myself but that is a lot of hassle, free email accounts have ads and rarely let you use your own domain. The best I've found so far is email through a shared hosting provider, but it has limitations of its own (no IPv6, no 2 factor auth, self signed TLS certificates, etc). The cost is similar to a Google Apps account but without the linear price increase per mailbox.
Sometimes it's about the pennies. But other times, especially early, it won't be these types chunks of money that kill you. I used to go on CL and do user-studies for $50 a pop and resell the gift cards for cash or amazon credit. So it's hard for me to believe that what you are building can't spare an hour of work to fund baseline communication systems that are pretty well supported.
That is why heroku exists right? Otherwise only linode or ec2 could make business. Now if you have free time (you shouldn't) then, it is a whole different story. I agree with you.
To put it in perspective, Netflix costs ~$108 a year. People have no issues spending $4 a day on a latte, but just 13 lattes costs more than a year of Google Apps. A single latte or a big mac meal at mcdonalds costs more than an entire month of google apps for you.
And then there's coffee, which exceeds them all :)
For that matter, so is beer!
In the case of email, it's obviously valuable. While there are other options out there, ultimately you have to determine the cost of researching, testing, setting up, and switching over you and your employees. All this time is spent away from your money making activities.
I always thought of free Google Apps as the company's brilliant play to control the fabric of the business internet. Can you name anything in the digital realm more important to businesses and organizations of all sizes than long-form communication (email) and content and information-driven collaboration?
Sadly for new users and for Google itself, the company's actions reveal a failure to recognize Apps as anything more than a collection of inter-related services ready for more aggressive monetization. Management fails to see the strategic benefit and leverage afforded by controlling the online fabric of every new business that starts operating as a small team. It's the type of short-term and profit-driven thinking that afflicts so many companies as they reach the complacency of scale.
How much do you make per hour? How many hours do you expect to spend per year maintaining your own email system?
How much would you pay to stop one hacker, one time, from reading your private email?
Are you going to bother to set up two-factor authentication, or just wing it?
For a lot of people, $50 a year would make total sense.
Totally understand someone running their own mail server due to privacy concerns, but that's a different argument to "not worth $50 a year".
My impression is that paid Google Apps support is pretty good: http://contact.googleapps.com/
http://www.rackspace.com/apps/email_hosting/rackspace_email/
I was in the middle of setting up a service for a company of one at the moment and having one or two redirected emails isn't worth fifty dollars a year each right now.
A company of one definitely needs the most reliable communications it can get. Even if you're drowning in leads, it makes you much more credible if you don't have to explain to a client why their email bounced back. A delightful, relevant saying I encountered the other day is 'penny wise, pound foolish'.
hhh, you might be right. I'm really just a bit steamed about researching all this then getting home and realizing they had just killed it.
Aren't both options crushed in effectiveness by redirecting to your main account, whatever that is?
Is that clear enough for you? Self-hosting is a poor idea because screwing up once costs you real money, probably more than you'd spend on a year of hosting at a small business.
My point is, fucking up is bad and easily costs you money. Giving yourself infinitely more ways to fuck up to save $50 a year is stupid. I don't know how I can put it more plainly than that. At this point you're pretty much just trolling.
For 8 I prefer $50 per year. Three more guys over 8 is ridiculous.
I'm lucky in that I already have Google Apps and they're not starting to charge me. But if I didn't I'd look at whether there are reasonable free/cheap alternatives out there.
For customers it looks like the end of free Gmail-for-your-domain. But for competitors I imagine it looks like the end of price gouging.
Let me make a few recommendations. I'm not a sysadmin by trade but I know a few things you can do that will improve your lot in life running mail.
- Postfix and Dovecot. They have the right combination of ease of use, power and security. Don't overconfigure; try to get it working with basic settings first and then evolve it towards what you dream of rather than setting out to configure it that way first.
- SPF and DKIM. I have no trouble getting messages to Gmail and I think this is part of why.
- Make sure your hosting provider is not huge and very high quality. I chose RootBSD because they're small but highly technical. If you have a lot of spare cash, iNetU are quite good and sometimes help with FreeBSD. The larger or crappier the host is, the more likely you'll wind up in blacklisted IP space. (BSD hosting companies tend to be smaller and more technical, and BSD is great software, so I'd recommend that if you're interested.) Getting off a blacklist isn't a lot of fun and it's not hard to wind up on one, but I find being on a discriminating host is a good preventative measure.
- Rely on IMAP. If you want webmail, try and find one that is really just an IMAP frontend. I tried and liked Roundcube a while back; these days I have IMAP clients everywhere so I don't know what the new hot stuff is, but IMAP is fantastic.
- I strongly recommend you get an account with DNSReport.com. Their software can detect most of the DNS problems you can get yourself into that wreak havoc with mail. Odds are good you'll be doing a lot more DNS than before, it's a great tool to have in the toolbox.
- Stay on top of your security updates. I recommend running sshguard and whatever other security software/IDS/firewall type stuff you can stand. Make sure you're not giving out a bunch of shell accounts with root on this server. Seems obvious, but people forget or get lazy. FreeBSD will email you a security message every day; if something like that isn't coming your way, consider trying to set it up. It tells me, among other things, who tried to log into the server, how many times they failed, what their IP was, and lots of other stuff.
There are a number of nice upsides to running your own mail server.
- Email can be hooked up to the database various ways.
- Automatic emailing for free (keep an eye on it).
- Scripted email handling for free (Procmail etc).
- Get system-generated messages emailed (Nagios/monit etc., login/sudo failures, etc.)
- Advanced forwarding/wildcard accounts.
Anyway, I hope you do give it a shot despite the nay-saying. Cost-effective? No, but it's a blast, and many of the upsides would be hard to replicate with Gmail. Of course the web mail UI will be worse. Tradeoffs.
(I ask because I'm still trying to get an idea of just how vulnerable your garden-variety server is, user stupidity aside)
If you've got a "garden variety" server with a strong password, I wouldn't worry.
I've got a laptop slung on the end of my ADSL line that has had literally millions of attempts.
If you are worried, you can install fail2ban which will block repeated attacks at the firewall level.
And if you use SSH keys you should be totally safe.
Remember to apply security fixes though since the automatic attacks also probe for ancient versions of SSH servers.
One easy way to manage it is make a folder for each hostname, and add things like mysql root password, ssh port, public IP, pivate IP as different entries relating to the all aspects of managing the host.
I've run my own mail server for 15 years, since I got my first permanent connection. I host on the end of it as I have a large distrust of "the cloud".
It is cost effective for me as it has increased my merchantable skill portfolio. I've ended up designing some mail systems (50k+ users) for some large ISPs in the past thanks to my accumulated knowledge.
Debian is probably the easiest to get off the ground - it's pretty much "sudo aptitude install postfix dovecot" and follow the instructions. I was a FreeBSD user but primarily due to apathy, I tend to use Debian.
This is about to change however, when FreeBSD supports the raspberry pi as it's a much lower memory and power footprint device so some of FreeBSD's simplifications and optimisations will assist there.
For me, a Raspberry Pi with a 32 gig SD card plugged into my 12Mbit connection will suffice for the 18 users and 5 domains via IMAP that are currently being hosted on a much larger machine. Cost to me: $40-50. No brainer.
Regardless, one's privacy is already compromised the moment they sign up for Internet service; that information can be made available to the right people after one subpoena.
http://searchengineland.com/google-fired-two-employees-for-b...
http://www.wired.com/threatlevel/2010/01/operation-aurora/
http://readwrite.com/2010/09/27/googles_second_transparency_...
Google read your email and use it to throw targeted ads at you.
There is a fine line between profiling, tracking and analysing communications and utilising that data for something nefarious. The only deciding factor on how far it goes is cash.
People use e-mail constantly. It's important. $50 per person per year isn't a blip on the radar. Do you know how much money you'll lose if your 18 users can't access their mail for an hour? Now consider how much time they'll spend setting up their own mail clients instead of using Gmail. Think of the increased time and frustration waiting for searches to finish. Think of the extra time they'll spend deleting spam. You're paying a lot more than $40-50 for that mail server, but the real cost is obscured from you.
It's a no-brainer: skimping on email hosting is simply not worthwhile.
There are lots of reasons to not use Gmail. Maybe $50/year is a lot for you. Maybe your needs are modest. Maybe you want the knowledge and experience of running mail. Maybe you want or need to interface your other components with mail. Maybe you don't like the rest of Google Apps. Maybe you hate the Gmail interface. Ultimately, most people will choose Gmail despite whichever of those reasons might apply. There's no need to turn a technical decision into a dogmatic one.
Backups: tar and gzip daily, then scp to a friend's server in another country. Also take manual backups to encrypted USB stick weekly which I carry around on me at all times.
Searching: you only have to search it if you have lots of it. I have 9 messages in my maildir. I receive perhaps 20-30 messages a day. No problems - they all fit on the screen. If it's worth keeping, it goes as a ticket/wiki entry or in the hg repo as a document.
Spam: get one or two a week per user. Just delete by hand at the moment. People who use imap use their mail client's spam filtering stuff. If it gets problematic I'll probably install a filter.
Calendars/contacts: both in mercurial in agenda format (plain text, one line per event or contact). Very easy to manage and share. Have you tried keeping a central address book/calendar accurate using any other method?
I know how much we'll lose without email which is why it is where it is :) About 2m from me most of the time.
Cost? I've spent 20 minutes on admin this year. Everything is automated..
I'm not skimping, I'm making sure we do it right so we don't need all the tooling and features. To be honest, google is too cheap to be good if you ask me and their reputation shows regulalrly with outages and problems.
I ran a linksys NSLU2 as my mail server for a few years, with a USB stick as its storage. With Debian linux with Dovecot, Postfix, spamassassin, and the Spamhaus DNSBLs set up I managed to keep the signal to noise ratio pretty damn high too.
It was fun, and remarkably not hard.
http://www.codinghorror.com/blog/2010/04/so-youd-like-to-sen...
- I kept a mostly "if it works don't break it" approach, but about once a year there'd be some alert about security issues with some specific software and I'd run a "aptitude update". Invariably it'd update the packages out of order, libc would get screwed up, and I'd have to reinstall the whole server.
- I could never get the spam filtering up to snuff. I had daily auto-training spam+ham folders etc set up, the works, but I'd always get a a few spam messages in my inbox, and a handful of false positives. Used SPF but it had to be softfail since someone I visit friends/relatives who's ISPs have blocked SMTP ports aside from their own relay.
- My fault, but I ran a forwarding address for a friend, and I got blocked by my ISP since it forwarded some spam messages that got flagged.
- I don't feel properly equipped to deal with backups. (sure you can set up an rsync to somewhere else [that you have to pay for], but you also want to keep monitoring that they're good, test restores, etc)
Easily worth $50/year for me to not have to think about it.
edit: forgot the biggest reason I switched: I got an iPhone, and iOS doesn't do push email over IMAP. Gmail supports Exchange, and there's no way I'm going to be hosting that myself...
What distribution are you using? I've never had this happen, though for important servers I tend to use Debian stable. I would be shocked if it happened on stable.
I earn more than $25 per day, therefore $50 per year for mail hosting is worth it!
Show your work, please.
[1] http://www.google.com/intl/en/enterprise/apps/business/custo...
For example, Live (Microsoft service)[1] or Yandex (Russian google vis-a-vis). [2][3]
[3] Major caveat: the interface is in Russian only now, but after initial setup it shouldn't be a big deal;
At $50 / year for Google it's cheaper to buy a domain from GoDaddy and pay for email services (webmail + IMAP) that are automatically tied to your domain.
That is BS and Google knows it
Why? Because Google can suspend your account at a whim and not even tell you why.
Google did that to a friend of mine, yes, paid account, yes called support line, they basically said "tough, it may return in 48h"
We also run an email system at work, though it's a lot more work than other services - mostly due to spam / deliveriabilty - so even if you do pay $50/yr still seems a bargain. IMHO you need 100+ users to even think about justifying the time cost for running a mail server yourself.
Also, I get access to all the new Google stuff without having to wait for Google to make it 'business-ready'.
Email is a solved problem that is totally worth it to outsource or pay someone else to manage in-house. If you feel comfortable setting up your own mail server, managing spam, updating it, etc., and WANT to do it, then you're probably not Google's target audience, anyway.
Free is only really free if you don't value your time.