today in #runyourownmailserver

bounce message from microsoft;
550 5.7.1 Service unavailable, Client host blocked using Spamhaus

shit! what happened? did my box get shelled?

oh. that last update enabled ip6. thanks apt. ugh.

After running my newly set up email server with aggressive #fail2ban for about eight months the number of blocked IP is leveling out:

* Scanners (hitting Telnet, FTP, ...): ~20000/90 days
* Spam hosts (on two block lists): ~30/30 days
* SSH (Germany only, others end up as Scanners): ~10/7 days

My old server was flooded with login attempts on SSH and IMAP. Going dark on services like shodan with the scan trap was a game changer.

#RunYourOwnMailServer

PUH!

Ich dachte schon mein eigener E-Mail Server sei kaputt. Seit über 10 Tagen _keine einzige SPAM-Nachricht_! Und das bei einer E-Mail-Adresse, die seit 1995 aktiv ist.

Heute kamen endlich wieder welche herein, die die ordentliche Funktionsweise bestätigen.

Thank you, @mwl for your outstanding #RunYourOwnMailServer.

#sarcasmbutonlyhalf #spam

Edit: English translation in my reply.

@cliffwade @beardedtechguy @protonprivacy You're a tech guy. You should be able to #RunYourOwnMailServer. Works for me.

Check out @mwl's book

https://mwl.io/nonfiction/tools#ryoms

Sysadmin Tools – Michael W Lucas

Since I'm currently reading #RunYourOwnMailServer #RYOMS, the part about #DKIM reminded me about something I heard some time ago, and I managed to find it again. Concept somewhat similar to what #OTR does.
https://blog.cryptographyengineering.com/2020/11/16/ok-google-please-publish-your-dkim-secret-keys/
https://rya.nc/dkim-privates.html

With greetings and thanks to @mwl and @ryanc 😅

#email #mail #security #privacy

Ok Google: please publish your DKIM secret keys

The Internet is a dangerous place in the best of times. Sometimes Internet engineers find ways to mitigate the worst of these threats, and sometimes they fail. Every now and then, however, a major …

A Few Thoughts on Cryptographic Engineering

I'm reading #RunYourOwnMailServer #RYOMS by @mwl , and I'm thinking about what I know so far about #stalwart https://stalw.art/, and I can't figure what his opinion of it would be, I can see it going either way 😅
- "oh, nice, don't need to need with all those separate things and making them talk to each other"
- "eh, if it works for you, cool, I already have mine 🤷"
- "this abomination doesn't even follow Unix philosophy, I wonder what else it does wrong - no, I don't want to know"

#email

Stalwart Labs

Open-source mail and collaboration server with JMAP, IMAP4, POP3, SMTP and WebDAV support and a wide range of modern features. Written in Rust and designed to be secure, fast, robust and scalable.

Just ran accross #runyourownmailserver today. I used to run my own postfix server many years ago.

Anyone else running their own email servers?

So I've finally started making my way through #RunYourOwnMailServer by @mwl

Even though I've read tutorials/articles/documentation of various bits and pieces over the years, I've always struggled to actually get any kind of fully functioning mail server. So far this book is doing a great job of demystifying all of the pieces and confusion I've had and bringing everything together. No doubt by the end of this I'll have a properly configured and functioning mail server.

@are0h
The conclusion I have landed on is that I must #selfhost email as well. I don't suppose you've written about you're experiences at all? I'd be curious to hear your thoughts.

I'm ordering a copy of #RunYourOwnMailServer, because it's been about 21 years since I've hosted email.