I self-host my own e-mail servers for ~25 years now.
-
I self-host my own e-mail servers for ~25 years now. Just finished he migration to a new system today.
- OS: FreeBSD 15.0-RELEASE
- MTA: Postfix 3.10
- IMAP: Dovecot 2.3
- Filter: Rspamd 3.14I used Imapsync to migrate the content of my Mailboxes from the old to the new system. Worked absolutely fine.
Having the E-Mail Jail and the mailbox data on an encrypted ZFS dataset (AES256) that's manually unlocked with my passphrase after rebooting the system. Backups are done via ZFS send/recv to by backup server (-w for raw send to ensure, data is encrypted at rest)
- SPF: ✅
- DKIM Signing: ✅
- DMARC Reporting: ✅
- E-Mail delivery to major providers: ✅
- IPv6 working and actually being used: ✅All working perfectly well. In about a week, I'll decomission the old Debian based system, that I used since 2017!
-
I self-host my own e-mail servers for ~25 years now. Just finished he migration to a new system today.
- OS: FreeBSD 15.0-RELEASE
- MTA: Postfix 3.10
- IMAP: Dovecot 2.3
- Filter: Rspamd 3.14I used Imapsync to migrate the content of my Mailboxes from the old to the new system. Worked absolutely fine.
Having the E-Mail Jail and the mailbox data on an encrypted ZFS dataset (AES256) that's manually unlocked with my passphrase after rebooting the system. Backups are done via ZFS send/recv to by backup server (-w for raw send to ensure, data is encrypted at rest)
- SPF: ✅
- DKIM Signing: ✅
- DMARC Reporting: ✅
- E-Mail delivery to major providers: ✅
- IPv6 working and actually being used: ✅All working perfectly well. In about a week, I'll decomission the old Debian based system, that I used since 2017!
Has DKIM really been worth the effort? I'm onboard with DMARC, but DKIM is a pain.
-
Has DKIM really been worth the effort? I'm onboard with DMARC, but DKIM is a pain.
@philleu It's pretty effortless (2 lines of config) with rspamd and it helps with deliverability to Google:
# cat dkim_signing.conf
path = "/var/lib/rspamd/dkim/$domain.key";
selector = "mail"; -
@philleu It's pretty effortless (2 lines of config) with rspamd and it helps with deliverability to Google:
# cat dkim_signing.conf
path = "/var/lib/rspamd/dkim/$domain.key";
selector = "mail";Thanks for the tip. I've been happy with DMARC alone, but I'll take another look.
BTW Of course GOGGLE (and friends) need help.
-
I self-host my own e-mail servers for ~25 years now. Just finished he migration to a new system today.
- OS: FreeBSD 15.0-RELEASE
- MTA: Postfix 3.10
- IMAP: Dovecot 2.3
- Filter: Rspamd 3.14I used Imapsync to migrate the content of my Mailboxes from the old to the new system. Worked absolutely fine.
Having the E-Mail Jail and the mailbox data on an encrypted ZFS dataset (AES256) that's manually unlocked with my passphrase after rebooting the system. Backups are done via ZFS send/recv to by backup server (-w for raw send to ensure, data is encrypted at rest)
- SPF: ✅
- DKIM Signing: ✅
- DMARC Reporting: ✅
- E-Mail delivery to major providers: ✅
- IPv6 working and actually being used: ✅All working perfectly well. In about a week, I'll decomission the old Debian based system, that I used since 2017!
@Larvitz Why imapsync and not rsync since you're root on both systems..?
-
@Larvitz Why imapsync and not rsync since you're root on both systems..?
@Nux Old system used mbox files while the new one is using Maildir .. Imapsync was simple 🙂
-
@Nux Old system used mbox files while the new one is using Maildir .. Imapsync was simple 🙂
@Larvitz Fair enough - I didn't think that was still in use, quit on it as soon as I discovered qmail 20 years ago and never looked back. :))
-
I self-host my own e-mail servers for ~25 years now. Just finished he migration to a new system today.
- OS: FreeBSD 15.0-RELEASE
- MTA: Postfix 3.10
- IMAP: Dovecot 2.3
- Filter: Rspamd 3.14I used Imapsync to migrate the content of my Mailboxes from the old to the new system. Worked absolutely fine.
Having the E-Mail Jail and the mailbox data on an encrypted ZFS dataset (AES256) that's manually unlocked with my passphrase after rebooting the system. Backups are done via ZFS send/recv to by backup server (-w for raw send to ensure, data is encrypted at rest)
- SPF: ✅
- DKIM Signing: ✅
- DMARC Reporting: ✅
- E-Mail delivery to major providers: ✅
- IPv6 working and actually being used: ✅All working perfectly well. In about a week, I'll decomission the old Debian based system, that I used since 2017!
And finally added the last piece to my new Mailserver: Observability via Promtail/Loki. Done for today 🙂
-
undefined stefano@mastodon.bsd.cafe shared this topic