Email Self Hosters - what are you using?

66 points by vetch 13 hours ago on lobsters | 67 comments

ccmtaylor | 13 hours ago

there was a similar thread a while ago here: https://lobste.rs/s/bywnqo/what_s_your_email_setup. It may have useful information in the comments

[OP] vetch | 13 hours ago

Thanks!

pegasus | 13 hours ago

Same thing as 27 years ago: postfix + cyrus imapd. Rock solid as far as mail storage is concerned, but world wide web is in the process of enshittification and tweaking postfix to keep up with spam and filtering policies is becoming an increasing pain. Especially when your mail setup sits on a residential dsl IP with very bad reputation ... you cannot do anything for the likes of gmail to accept mail from you.

theperfecthobbit | 8 hours ago

Same here: Postfix + Cyrusimapd. I have configured it for JMAP as well, and where I can, I use it (aerc in terminal; Bulwark for webmail; trialing Plume on the phone).

I do use anti spam and clamav as well, though.

jbauer | 11 hours ago

OpenBSD + OpenSMTPD + Rspamd + Dovecot on an OpenBSD Amsterdam VM. I followed https://poolp.org/posts/2019-09-14/setting-up-a-mail-server-with-opensmtpd-dovecot-and-rspamd/ back in 2020 and have been running it ever since. I wouldn't change anything.

The first time I sent an email to a Microsoft server (my university email at the time) I got a reply back telling me to fill out a quick form to "prove" I was a real human, but since then I've had no delivery issues at all. Worth noting that, before self-hosting email, I had my domain for ~1.5 years and the TLD, .ca, is probably much more reputable than if you were trying to send email from a .xyz or .biz.

FrostKiwi | 12 hours ago

The NixOS Mailserver package on my personal NixOS bare metal server, german private fiber connection. SMTP2GO as an SMTP relay to not land in spam hell due to IP reputation. Multiple Domains and users across two businesses, rspamd and its classifier trained up on everyone's spam. Pretty sweet so-far.

Biggest mistake so-far, having the default Postfix submit timeout. One user was sending 20MB worth of photos via Android Thunderbird in a factory with no wifi and a bad mobile connection. Got to 90%, timeout, repeat. Actual mail was only sent hours later.

waelk10 | 10 hours ago

Based off of this guide: https://poolp.org/posts/2019-09-14/setting-up-a-mail-server-with-opensmtpd-dovecot-and-rspamd/
I have a stack of OpenSMTPd + rspamd + dovecot on my Parabola GNU/Linux homeserver (yes, running off of a residential address), I am also using an SMTP proxy for some outbound destinations that are really annoyed by my server's lack of PTR record, but that isn't the end of the world since the MXs I want to reach I do reach without an issue.

null_radix | 9 hours ago

im using simple nixos mailserver which uses postfix + dovecot + rspamd

xilef | 13 hours ago

freebsd + postfix + dovecot + blocklistd + spamassassin + greyfix

spamassassin is not as good as rspamd, but I sort of enjoy reading and sometimes replying to spam.

xilef | 13 hours ago

and, I have AWS SES set up as an outgoing relay (usually $0.50 a month), mainly so I can stop filling out Microsoft forms to get email accepted to Outlook.

Ambroisie | 8 hours ago

I pay Migadu to host emails on my custom domain.

Very good customer service, does what it says on the tin and nothing more. Good value.

EDIT: reading other people's answer, I see that this might not qualify into self-hosting. I think email is worth outsourcing to someone else for the price of a coffee a month.

reezer | 8 hours ago

Running OpenSMTPD + rspamd + dovecot on multiple domains. All on OpenBSD. Runs great.

Least favorite part is rspamd. Many moving parts and while I get why the configuration is like that I still find it messy. Well, good thing is you only set it up once.

I stopped greylisting and so on, because basically all spam nowadays comes over properly configured emails servers (including the big ones like Gmail).

There were other SMTP servers in the past. Started out with exim, then did postfix for a while OpenSMTPD config just is so clean.

When I moved over to OpenSMTPD I also replaced opendkim, spamassassin, etc. with rspamd. As mentioned a bit of a love-hate there.

Migrated between providers, so IPs, domains, etc. in 20 years. Only problem I ever had was that at some point servers started demanding DMARC. So quickly set it up for Gmail to accept emails again. Wished more services were as boring as email.

DustyFuzzy | 13 hours ago

postfix, dovecot, opendkim, opendmarc, all on a VPS from Scaleway.

I don't have any delivery issues with any major provider, but I have to fill in a form once a year to have my IP taken off the Spamhaus PBL. There's no manual verification on their end when the email you use with Spamhaus lives on the IP you're unblocking :)

I've directed all email to my account, regardless of the local-part (before the @). Probably wouldn't recommend it, it makes it near impossible to ever stop self-hosting.

I'm also rawdogging it without any form of spam filter on the server. Thunderbird does it on my desktop, and on my phone I just scroll past the spam. I should probably set up spamassassin to at least reject the most obvious.

Edit: One issue I've run into is that, for some reason, Tumblr wouldn't even attempt to deliver email verification to my server. Had to contact support to have my email verified!

[OP] vetch | 12 hours ago

I'm currently on DO and am very slowly moving to Scaleway - who seem to do a much better job of keeping their IPs clean from backlisting.

k749gtnc9l3w | 12 hours ago

Same software stack, OVH as hoster, a lot of accounts under multiple subdomains. No spamfilter, and not much spam somehow.

DustyFuzzy | 11 hours ago

Wildcarding all email to yourself is a great way to discover someone who had your domain before the year 2000 is on all kinds of spam lists :)

k749gtnc9l3w | 11 hours ago

Well, I wanted a cheap domain so the gTLD involved did not exist in 2000, that helps!

(If ever deliverability penalty of cheap gTLDs gets prohibitive, well, I will see)

fs111 | 3 hours ago

I've directed all email to my account, regardless of the local-part (before the @). Probably wouldn't recommend it, it makes it near impossible to ever stop self-hosting.

Hosted email providers allow that too, at least Fastmail does

snazz | 10 hours ago

I've directed all email to my account, regardless of the local-part (before the @). Probably wouldn't recommend it, it makes it near impossible to ever stop self-hosting.

I've been able to set up a catch-all/wildcard address on both Google and Fastmail now, so unless you're doing something fancier than I understood, you can definitely use other providers at some point if you stop enjoying self-hosting.

Hales | 11 hours ago

Mox, for a secondary email domain for about a month now, on a cheap VPS (binary lane).

Pros:

  • No docker
  • No need to setup an external DB engine.
  • On the first run it prints out lots of text to test things and help you setup
  • It works

Cons:

  • Rough first-time-setup user experience if you do not use exactly the right command-line options the first time. I had to delete the keys and start from scratch to get things to work, by which point I'd already setup my DNS with the old settings from the first run.
  • I want it behind my HTTP proxy, whilst the author recommends you instead use Mox as your system's HTTP proxy. Few sharp edges getting this setup, including pointing it to where my proxy (caddy) stores its certs, but that's not really the fault of Mox and I think I can see where the author is coming from.

I have not received any spam yet, so I have not tested its anti-spam performance.

z3bra | 10 hours ago

Everything is hosted on OpenBSD at hetzner.

  • OpenSMTPD
  • Dkimproxy
  • Spamd
  • Spamassassin
  • Dovecot
  • Roundcube
  • mlmmj (for mail list)

I love the simplicity of opensmtpd, and the fact that it all runs without a database. Emails are stored as files and accounts are created with a dedicated passwd(5) like file in /etc/mail/.

The only thing I could bother changing is spamd, because greylisting can delay emails, which is frustrating when you just wanna receive that MFA code to login. But I have a script on my phone to remotely toggle it, so it's not that bad, and I love the idea of wasting spammer's time :)

david_chisnall | 8 hours ago

What do people use for backup MX? Synchronising spam filter state seems annoying and I don't want the backup MX to be a way past the spam filter. A lot of spammers are now apparently starting with the lower-priority MXs on the assumption that they don't do as much spam filtering.

I self host and had an issue a while ago where the incoming server died and I needed to update my DNS, but my DNS provider required sending me an email to log in. I'd like to have a backup MX to support that without so much suffering (even if I need to cat the mail spool). Ideally, I'd like the backup MX to monitor the health of the primary and not accept mail when it is working but comes online and catches incoming email when it fails.

johnklos | 6 hours ago

I have my backup MX set up with a much longer greylisting period, and doesn't get skipped for aligned SPF / DMARC. They use more aggressive anti-spam blocklists, and DNS blocks are more aggressive.

This really cut down on the deliver-to-backup-MX problem, without syncing anti-spam measures.

classichasclass | 5 hours ago

When I was still self-hosting I had a handshake agreement with a friend who was another self-hoster. But obviously that assumes they're as into it as you are (he wasn't after a few years).

icefox | 7 hours ago

Not quite what you asked, but I have a gmail address I use for backup authority. Stuff that hits my gmail gets forwarded to my normal acct automatically, but if my mail server goes down I can still use the gmail acct to access my DNS, Hetzner console, etc. Maybe defeats some of the purpose of self-hosting a little, but it gets used rarely and I had to use it to recover my VPS for real recently and it worked fine.

jbcrawford | 4 hours ago

About a year ago I migrated from Postfix + Cyrus + SpamAssassin to Stalwart for a ~10 user mailserver. The much larger mail servers that I have run in previous jobs (5k+ users) were Postfix+Cyrus, but I'm not so much in that business any more. I'm happy with the result of my migration, but I also don't feel that it was necessary, just "nice to have".

Here's what motivated me to make the change:

  • Simplified configuration: my Postfix + Cyrus configuration had been ported from machine to machine, across distros and over a decade, and had gotten to be complex and frustrating to troubleshoot. Fixing this obviously didn't require switching to new software, but there was an aspect of "in for a penny, in for a pound."
  • Integrated DAV: Stalwart's DAV features are somewhat limited, but they're built in, so I ended up with a better integrated and more feature-rich DAV setup for calendar and contact sync than what I had before.
  • JMAP: JMAP does seem to be the future and I wanted to get onto something that was built around it as closer to a first-class interface.
  • Better spam filtering: Stalwart's spam filtering is better integrated for training and easier to configure than SpamAssassin.

None of these are things that would have been impossible with the Postfix + Cyrus setup, but overall migrating to Stalwart was easier.

Here are my complaints about Stalwart:

  • Documentation: Stalwart uses a configuration model that is very flexible and powerful, so many things that are not "supported" by the admin UI can still be done by manually adjusting the logic-based configuration directives. The problem is that the documentation on this is not very good, so you have to make inferences from different examples and test things out. An example of where this comes up is Postfix-style domain aliasing (entire domain aliased to a single user), which is possible (and not even very difficult!) with Stalwart but will require some real head scratching since there aren't clear instructions and it requires making changes in several different sections of the config.
  • Authentication: this isn't necessarily a Stalwart problem as there are fundamental aspects of email that make SSO difficult, but Stalwart was originally designed under the assumption that it would be the user directory and that shows. For the first years external user directories weren't really supported (for most use-cases due to limitations in Stalwart's LDAP impleemntation), that has since improved but there remain many friction points. For example, app passwords don't work with an external user directory. The good news is that Postifx+Cyrus setups tend to have the same problems for the same reasons, it's just that the greater configuration flexibility of those tools gives you more options to work around them. For example, I had a totally custom authentication setup with Cyrus (it passed the user-furnished credentials to a script I wrote), which I do not think is currently possible with Stalwart.
  • Developer culture: it often feels, to me, like the Stalwart developers lack experience running mailservers. They sometimes ship features that are marginally usable or totally unusable in the real world, and then express surprise when people file issues explaining things that seem obvious to me. I'm not sure how much I can complain about this because there aren't that many people with experience running institutional mail servers these days, and one of the points of Stalwart is to be sort of a clean break. But it is annoying.

lormayna | 13 hours ago

Mox in a Linode VPS. Works well with almost zero effort.

[OP] vetch | 13 hours ago

Mox being mentioned in another thread is the first time I have come across it and what prompted this post. One thing I like about Maddy is that it can use rspamd which seems missing on Mox?

ptman | 9 hours ago

Yes, no milter / rspamd support, since spam hasn't really been a problem with mox https://github.com/mjl-/mox/issues/47

At the moment I'm using mailcow - but I have used docker-mailserver before, and also just OS-level postfix+dovecot+... on Debian for years. I trialed stalwart in the past and I have never heard of maddy. I had a 2nd setup with openbsd and opensmtpd as well, which was fine, but the lack of webmail and some other niceties made it a nonstarter for hosting other non-nerds' email. Would probably use that if I needed a decoupled "receive only" MFA email again.

I'm pretty happy with mailcow.

I don't generally fiddle with my email setup. I take whatever latest Debian or Ubuntu LTS as a host, then run that machine until the base OS is EOL, which is often 4-5 years, then I see if my setup on top still makes sense or if I need to switch. Last time there was some problem with docker-mailserver on the VPS I had after an OS upgrade iirc, that is why I switched, it had worked before.

sjamaan | 10 hours ago

You say you tried stalwart before but you're not using it currently. Any particular reason(s)?

theperfecthobbit | 8 hours ago

Not the OP, but I trialed Stalwart as well. I have high expectations of it, and am following development on Github. However, I am not yet using it "in production" for my mail server.

The project has very frequent updates and bug fixes, which is great, but not mature enough yet for me to use it. I'll trial it again once it reaches v1.0.

It's been a long time, might have even been when it was very fresh, and wasn't ready - or some development lull. I faintly remember that I recent-ish rediscovered it and was happy to see it was still around...

fourfourthree | 10 hours ago

postfix + dovecot + rspamd on a colocated linux box - has been my go to for 20 years. Email goes through it faster than any other setup I've used.

My main email client is mac mail and iOS mail.

I'd quite like an easier way to add aliases than editing a config file and running postmap... but it works, and an easier way to rotate DKIM keys.

johnklos | 6 hours ago

I'm still running good old Sendmail (with procmail, milter-greylist, opendkim, imap-uw). I wrote some nice rulesets that I never replicated elsewhere, so short of some big change that would require moving, I'm sticking with it.

Once it's set up, it's surprisingly easy to maintain.

schmonz | 4 hours ago

notqmail (as you might guess from the hat), Dovecot for IMAP, rspamd, DKIM, SPF, SRS, yadda. If I could change one thing, it'd be to have way more time to improve notqmail. If I could change two things, I’d wish into existence a checkpassword-shaped IMAP server that’s as production-ready as Dovecot. bincimap unfortunately isn’t it.

reidrac | 3 hours ago

I've self-hosted my email for over 25 years.

Currently Debian stable with postfix + sqlgrey + postfix-policyd-spf-python + OpenDKIM and a couple of DNSRBLs, with dovecot imap.

I receive very little spam, and sometimes the big providers may filter my email as spam, and there is not much I can do about it unfortunately. I generate little traffic so it doesn't matter I that have been in the same IP for the last 12 years or so, I can't gain the reputation they want.

I started with OpenBSD and sendmail, but the Internet was a very different place back then.

ruuda | 13 hours ago

I'm trialing Stalwart, but I haven't used it enough to yet to give a good evaluation. The way the settings work is quite nice. The LLM-written documentation is annoying to read, but at least it exists. I was hoping Stalwart could be a good alternative for Google Workspace's calendar features for my company, but so far the groups support is limited compared to Google Groups.

ishan | 13 hours ago

Stalwart. I use it in my homelab to receive bank statement emails that are picked up by windmill. I will soon start using it to send emails to homelab services users.

I use it from Thunderbird and looking forward to Thunderbird release on ipados/ios.

MailInABox (which runs on Ubuntu Server) on a home server. It's been great. I'm fortunate to have a good ISP who didn't blink at fixed-address/open-ports and who's IP addresses haven't been problematic.

Very happy with MIAB. It manages DKIM etc very cleanly and provides all the usual features. Can send to MS/Google fine (after following MS instructions). Only hassle is delayed sign-up emails as it uses greylisting. MIAB is aimed at virtual servers, but with a little network knowledge it runs fine on a local server.

Only things I'd change .... I'd run it on FreeBSD, and add some way to temporarily disable greylisting.

mxuribe | 8 hours ago

Hi @drp, curious why you might run it on FreeBSD instead? Care to share the reason(s) why?

Same for a while now:

  • postfix
  • dovecot
  • rspamd (+dkim signing)

But this is new:

  • Zitadel for auth (switched from LDAP)
  • custom Go panel for app passwords

draxil | 12 hours ago

mailu it provides a pretty complete solution in docker containers.

My only concern is being better at security in the age where I'm sure spammers are using agents.

louwers | 10 hours ago

zimpenfish | 10 hours ago

Currently exim + dovecot + rspamd + nginx (imap proxy) + fail2ban (not technically part of the mail stack but it does a lot of work keeping it running by blocking the arseholes.)

I'd love to switch to a more modern setup but this has ~25 years of accumulated fudges and quirks on top - working out how to port those to, e.g., Postfix, is beyond me at the moment.

OpenSMTPD, rspamd and Dovecot on a linux VPS. I'm moving it to a local FreeBSD box with some very carefully exposed internet facing endpoints (via a VPS still) to allow email delivery. Access will require being connected via a wireguard VPN (this breaks IMAP IDLE on android unless you want to waste all your battery life but you can fix it with dovecot and some lua).

Main thing I would change in that transition is to use virtual users rather than OS users... That's about it.

raphting | 9 hours ago

I use p25.dev (EU sovereign, privacy focused email gateway) in front of a few different setups (Stalwart, Postfix, Postern).

Full disclosure: I created p25.dev and Postern.

kenichi | 7 hours ago

stalwart in a sparse zone on omnios for the last 2 years

PuercoPop | 7 hours ago

I'm using Stalwart. For clients I'm using sterna on mobile and aerc on the desktop. I'm using JMAP instead of IMAP. One thing I really like about Stalwart is that is using JMAP to update its configuration. It is currently a little rough, but I do think it will much better in the end. It allows one to have a declarative configuration of resources like Folders, tags, aliases, sieve scripts, etc.

The installation recommends you to use curl | sh - (no, thanks), but the script is well written so it can be used to learn how to setup Stalwart. Given how much care went into the installation script, I really do wonder why they don't also write down a document. Their docs as another comment mentions are verbose and not very useful. I've yet to figure out how to tell its spam filter about a false positive.

Stalwart does its best to work out of the but you still need to troubleshoot things (e.j. use https://www.learndmarc.com/ to check your configuration). There are things like reverse DNS that Stalwart can't help you setup.

Updating Stalwart so far has been a breeze. Just download the new executable, unzip and restart the service. There was a big change from 0.15 to 0.16 but so far no manual upgrade process has been needed.

Besides their docs, their support portal is mostly an LLM answering questions, which as one might guess is not very useful.

Some small QoL changes I'd like to see:

  • A toggle to remove all the upsell entries in the menu
  • Their stallwart-cli to integrate with the system's keychain (SecretService in Linux)
  • A preview of how would a sieve script would have classifiy the existing emails in the inbox.

So far my experience with Stalwart has positive. Its a good way to start self-hosting email, but I do worry about how much they are pushing LLMs into their main product. I may end up moving to another server later.

One thing I'd like to improve later is having a jmap based syncing tool. Similar to https://github.com/elizagamedev/mujmap. (While reading the mumap code and dependencies I was surprised to learn that notmuch is not thread safe).

Siosm | 5 hours ago

I was running postfix + spamassassin + dovecot for a long time but I'm now using Stalwart (https://stalw.art/) and I'm not going back. The management interface is great. JMAP support suffers from a lack of good email clients with support.

kevincox | 4 hours ago

I use postifx and dovecot with rspamd for spam filtering (and DKIM signing). I can't say I love any of the stack but it seems to work well.

I also heavily leaned on https://gitlab.com/simple-nixos-mailserver/nixos-mailserver/ for guidance.

oceanhaiyang | 4 hours ago

Was using Proton then Tuta but find them both to be walled gardens using privacy as a means to lock you I .

Now I use Mailbox.org.

maurycy | 3 hours ago

Postfix + mutt over ssh. OpenDKIM for signing outgoing messages. SPF checking + a blacklist of five problematic addresses has been enough to keep spam manageable. (~ 4/week with a published contact email on my website)

Works well enough that I haven't bothered to setup IMAP or anything. Of course that only works because I don't really use my phone much (ssh from android is possible but would be a horrible experience). Probably not a viable setup for your use case.

jonatan | 3 hours ago

Mailcow!

Running on my home network. Outgoing relayed thru my ISPs SMTP relay.

Only compliant is that the default soft-reject behavior of the rspamd config. It leverages that many spam bots alledgedly don't retry email sending, while legitimate MTAs do. While all legitimate email arrives within ~5m it is still annoying, so I disabled the soft reject. Haven't seen any of these spam bots yet.

Debian + Postfix + Dovecot, with account management and rather unconventional wildcard matching done in postgresql. I have spamassassin in the loop but I never got it to work properly; it assigns basically the same score to the most legitimate and the most obvious spam mails.

The crazy wildcards (for ad-hoc addresses) are super nice. The nonfunctional spam filtering is the main pain point, especially for my younger brother who used the main mail address I host for him in some Minecraft forum when he was about 13.

donio | 3 hours ago

I'd be curious about people's take on RBLs, both from sender and receiver perspective. Do you use them? Which ones? Do they give you trouble?
I find them highly effective. When combined with using unique email addresses for each signup I get very little spam. Most of what I do get comes forwarded from my vanity gmail address.

Debian server running postfix and dovecot. Have been running this setup for about two decades now. Don't really want to change anything on my end.

lukecyca | 2 hours ago

I've been using docker-mailserver for at least a decade.

zelest | an hour ago

OpenBSD + OpenSMTPD + Dovecot on a Raspberry Pi 5 with a NVMe HAT at home, with a openbsd.amsterdam VM as my outgoing relay.

Then the usual SPF, DKIM, DMARC setup...

tuxes | 13 hours ago

There are some minor issues with it - some are me, some are who knows.

It could be worth trying to fix the minor issues.

I've had some great success with having LLMs diagnose issues for me. For email servers, I would tell the LLM the issues I have, and ask it to diagnose and reproduce the bug(s) with a reproducible test suite using the nixpkgs VM test harness.

If you do choose to find an alternative mail server, the test suite remains useful for checking they actually resolve the minor issues.

I am aware some people don't want to use LLMs, which is fair enough too.

quicksilver03 | 38 minutes ago

Until a few months ago I was using Exim + Dovecot + Rspamd, then I moved over to Stalwart. I like how Stalwart integrates IMAP, SMTP and spam filtering, even though there are some rough edges and the installation documentation leads you to the wrong path more often than not.

The primary MX running Stalwart are dedicated servers at OneProvider in Paris (Scaleway) and HostDZire in Canada (Leaseweb). Until now I have been lucky enough to get relatively clean IP addresses, I also use HetrixTools to monitor various DNSBL.

For secondaries, I have a job that exports the mailbox and alias names from Stalwart to Exim running on 2 different VPS.

[OP] vetch | 13 hours ago

The me issues are 1) moving server and 2) correctly configuring the DANE/TLSA to update with each new certificate renewal. Not really an issue as I don't do too much outbound email.

Sadly LLMs don't magically give me an extra 20 hours in the day.

theperfecthobbit | 8 hours ago

correctly configuring the DANE/TLSA to update with each new certificate renewal

Just in case you're not familiar with it, there is a tool called danebot that is quite useful for automating this. It's a wrapper around certbot.

And, it would be wild not to use something to continually check your tlsa / dane status. There's danecheck and also dane-smtp-verify that could be perused for this task.

None of this adds time to your day, though... :-)

icefox | 7 hours ago

Postfix, dovecot, and that's about it. I'm sure it could be fancier if I wanted, but last time I made it fancier I forgot how it worked by the time I needed to change something again, so it's very vanilla. I should check out rspamd someday, it seems.

It's all hosted on a Hetzner VPS that somehow isn't on too many spam lists. Sometimes I can't send email to Microsoft addresses, but... that doesn't tend to come up anyway, so it's fine!

Out of curiosity, does anyone run one for small/medium size organizations?

The only holdouts I can think of are universities that have mailservers they have kept rolling forward, with decades old IPv4 blocks.

Yes, not university. It mostly works fine, we also own our own IP's(class C) which helps with reputation.

We have the never ending hiccups from Microsoft and other large email players, but generally you just follow their ever changing mess and it usually gets fixed. It's not a full-time job, but it def. takes some time. It usually comes in waves, so you have to keep on top of your mail logs to avoid users sending help request in about email being mean.

So it's just annoyance. There is a reason people outsource this all the time. MS, Google and all the other large players make being a 3rd party mail server annoying. The annoyance is ever changing and they document their crap about half the time, so you have to just plow through.

Our system is just Postfix and friends, nothing special.

Cloudron. Not much. It's really easy to set up and gives you access to many self hosted apps, including email.