As to running your own email server? Don't bother. Unless you plan to stay on top of exploits, DKIM keys and SPF records you'll wind up with serious mail delivery problems.
As to running your own email server? Don't bother. Unless you plan to stay on top of exploits, DKIM keys and SPF records you'll wind up with serious mail delivery problems.
DKIM & SPF are marginally useful (at best) for ensuring delivery. You're much better off registering your server with http://www.dnswl.org/
Edit: not sure about SenderID, to be honest.
It's no longer current technology and fails to comply with RFC changes that have happened since it was released, including but not limited to 6522, which standardizes bounce messages.
It still does very well at the job it was originally designed to do, but it's no longer a modern, usable tool. It doesn't belong in the modern email toolbox any longer.
Recent Exim exploit: http://www.exploit-db.com/exploits/25970/
Dovecot exploit: https://www.rapid7.com/db/modules/exploit/linux/smtp/exim4_d...
I found a few Sendmail exploits as well but nothing from this year. Sure this stuff is easy to install but there is a reason managed email exists.
https://www.redteam-pentesting.de/de/advisories/rt-sa-2013-0...
By that metric all software on your servers are insecure (consider the number of "just do: 'wget http://trollol.com/pwn.sh|sudo bash -'"-type advice you find looking at install-instruction for random github projects).
I really don't know what the deal is with email, but since the mid 90s there's been this weird thing where everyone wants to follow some kind of step by step guide. But it is just simple software like anything else. If you can setup a webserver or a database server or anything else you can setup a mail server.