My setup looks like this:
Mail: Postfix/Dovecot/Roundcube
Setting up a Mail server is the hardest part i think. It's essential to implement measures against spam and abuse. In my setup, this includes: - Get a valid certificate for your mail host and enable opportunistic TLS for SMTP and SMTPD. - Implement DKIM and SPF (and DMARC, http://dmarc.org/) - Use Blacklists: policyd-weight, but look out for changes to public RBL services - Reject Spam in the SMTP session using Milters, never bounce SPAM. - Use spamass-milter and clamav-milter to Filter unwanted stuff. - Use http://sanesecurity.com/ ClamAV signatures, in Debian use the clamav-unofficial-sigs package
Instant Messaging:
http://prosody.im/ is a breeze to configure and it just works.
Telephony / Video calls:
Repro is a secure and simple SIP proxy: http://www.resiprocate.org/About_Repro
But: Resist the urge to install a VoIP PBX like Asterisk and connect it to your phone line & the internet. It will most likely be hacked and abused.
Security:
I've set up a self-signed CA using XCA (http://xca.sourceforge.net/). With a client certificate on a smart card which i embedded into a USB token (http://www.gemalto.com/products/usb_shell_token_v2/), i can run around and plug this USB token in random machines and instantly have my client certificate available in Chrome. This is especially nice if you (like me) don't trust PHP software like the Roundcube Webmailer.