76 comments

[ 3.7 ms ] story [ 41.9 ms ] thread
I disagree with the author. If you have your own domain for e-mail, then you've already dealt with all risks and vulnerabilities. Of course you have your e-mail stored locally as well by using an e-mail client, which you would anyway.
Using a cloud provider with your own domain means going through a lot of the “hard” parts, yes (setting DNS records for DMARC/DKIM/SPF/MX mostly). But self hosting does provide benefits on top of that.

Hosting your own MX (the receive side) means a lot of private emails go straight to you: purchase receipts, utility bills, travel itineraries. You can have as many users/mailboxes/aliases as you like without having to pay more. You also get confidence that emails sent to you didn’t get silently treated as spam (cloud providers have disappeared enough 2FA code emails that I really care about this).

Sending emails directly also provides some benefits. You can guarantee that the email is sent with TLS, for example. Having logs to prove that my server sent a message and it was received and acknowledged by the receiving server has been useful to me a couple of times too.

I wonder why the comment replying to mine was banned? It was a well written response.
Seems to have been some auto-moderation mistake. I emailed hn@ycombinator.com (from my self-hosted mail server) and they restored my comments.
Sorry the title should have been "You should self-host your mail server" but it seems HN removes the "You should" in the beginning of a title.

I wanted to start this discussion because I think we are prime for more self hosted mail servers in 2026 and in the post I explain how to use a locally hosted LLM to nudge the spam detector rspamd to whether or not an incoming mail is spam.

Also in times where the EU can order your mail providers to scan for unwanted content [1] (currently limited to CSAM, later probably more) it does feel better to have your data at your hand.

[1] https://en.philenews.com/international/privacy-to-end-in-the...

> But there are other solutions out there like: Stalwart; Mailcow ;Or if you're a purist you can set up your whole server yourself

Another good guide that uses Debian and its standard packages:

* https://workaround.org/ispmail-trixie

(Updated with every release, and upgrade/migration instructions.)

I do. It's nowhere as hard as everyone on here makes it out to be. And I don't even use an easy solution like Mailcow. Spam is a solved problem with rspamd, and it's not even an llm
I still handle email for multiple small businesses (for over 20 years) and recently switched from the mailscanner+spamassasin to rspamd and the scanning is so much better/easier now

my backend is still dovecot+postfix, still works beautifully. I am able to run rspamd+dovecot proxy on a small vps and the storage is handled by a backend office server with dovecot. If VPS has an issue can spinup another easily/anywhere and backend is also virtualized (libvirt) so easily restored (with multiple backups in multiple places)

biggest thing to worry about with deliverability is ensuring your SPF and DKIM (opendkim) are correct, which is not too difficult and rspamd is able to handle the dkim signing/verification which is nice

I've tried self-hosting my mail server, but that means all my outgoing mail will go to Spam on all providers that use reputation-based filtering. In all cases I had SPF, DKIM and DMARC working perfectly, PTR records, etc. but it just doesn't matter. Even a Fastmail domain goes right to spam on my personal account, and they are very very established. It's just not worth it.
Waiting for a submission of "You should run your own NNTP server" (lots of 'nostalgia' for web forums to come back, so why not this too?).
What hosting / VPS companies do you recommend? Finding one which allows you to run a mail server is some work.
Ive self-hosted my email server since 1999. It started in a closet at home in San Francisco. As things got more restrictive (residential ips being black holes) I moved to a Colo. but now I'm back to hosting it on my server in my cellar. I have a fixed ip from my provider init7 (Switzerland) that has never been blacklisted. Reverse dns is set up. All the acronyms like spf, dkim, dmarc are set up. I have no problems sending to Microsoft and Google email addresses.

So I'm doing it now but I'm ready to switch back to one of my Colo servers at any time and I won't be surprised if I have to at some point.

I ran my own self-hosted email server from 2008-ish to 2018, and I would highly recommend against doing it! Especially when Fastmail and Proton are so cheap.

I was running Postfix+Dovecot+Seive+SpamAssassin+Fail2ban+certbot+spf+dkim+reverse-ip+<other random crap>

It worked! Receiving email was overall pretty easy. I know I also did things the "hard way" by ad-hoccing all that together, and today there are a lot more out-of-the-box solutions that do all that for you. But still. Being a full-time email administrator is a job I will never do again unless I'm getting paid for it.

You know what really sucked? Deliverability. Frequently, emails I would send would just ... vanish ... no warnings, no errors, no failures. From my end, everything was perfect. Until days later, people would follow up with me and say, "Are you going to send that email?" ...

I had a business IP (Comcast Business). The IP address was clean, not black listed anywhere, not on SORBS or other lists. Still, successfully delivering an email was like 50/50, with no way to confirm the other party actually got it.

I take a middle path. Self-host receiving mail, and use smtp2go.com for outgoing
I think the timeline is critical here and should be highlighted. Self hosting email server was something that worked out just fine in the past (used to host until 2014), however things have changed a lot with the scale of abuse. its not worth it unless you are doing it as a business. Sending a email from your home IP to big email providers with reliability is next to impossible. Even if we discount the spam management,

1. IP reputation is a big deal, its not just about not being on some blocklist, call it a cartel at this point, its about being on the allow list for other mail providers

2. Keeping it reputable is a continuous effort

This seems to depend so much on the IP address space one is in. I have never experienced deliverability issues after the first year–and that's since the 2010s iirc. The first year I had to ask several friends to send me emails first, or dig out my email from spam and reply to it. After that it worked flawlessly for Gmail, which was hit-or-miss before. A single ISP I had to write to manually–the person responding to my mail explained that they blocked emails from my hoster's IP range wholesale but made an exception for my IP explicitly.

Never had any issues since then, though I did have to adjust to new standards such as DKIM, DMARC, SPF etc. over the years.

I have had my own e-mail server since 2017, and there is only one instance where I know I had a delivery problem, and in that case it was funny, because I wrote to two people who had the same e-mail server, and one got the e-mail the other did not. So probably a SPAM issue, but certainly nothing my e-mail server could have done better...

AFAIK, that case in 2019 was the only time an e-mail went missing.

That’s something I have hard time explaining to the business.

Yea we do all the best practices but still no one can guarantee 100% deliveries. Just not possible for e-mail.

Yes we can have 100% over a year but after that it still is a lottery, can’t say anything about future not having suddenly 40% not delivered

Had no problems at all self-hosting for two decades; then a provider went bust and I lost my static IP block, and with it its two decades of reputation.

I still self-host, but now I cheat for deliverability: route the problematic destinations (I'm looking at you, Outlook) through Amazon SES. At a few cents for five-figure numbers of emails, it's as close to free for personal/vanity email quantities as it gets to have someone whose full time job it is to make sure outgoing mail stays deliverable on your side while still keeping everything else under your control.

One thing to note is that Amazon are not very good at keeping amazonses.com up to date, so despite including it you can't set DMARC to hard-fail SPF or you will have mail bounce days.

I'm running 4 email servers, the oldest is from 2011 or so, to this day.

4 different countries, different AS.

I'm always puzzled by all the issues described by others. I had about 4 issues during these 15 years, all 4 were solved by reading the bounce message and doing what was asked in the message (contacting support of the destination).

I had the same experience. Since 2008 or so on Hetzner of all places too. Their IP reputation is supposed to be shit if you believe any HN post about self hosting. I had issues maybe 3 times. The most recent of which was 2 weeks ago. I read the message, sent the postmaster of a German telecom my two IPs and they added them to their whitelist. That was it. Also postfix+dovecot+rspamd is enough. I have rspamd on the gateway that passes on clean mail to my real mail server.

The comments (not parents') are usually very weird like people are mad at us for hosting our own mail server or something. That is really an interesting phenomenon.

A lot has changed, in fairness. Stalwart + LLMs can help with the full-time email administrator part. It's a lot easier than it was.

And on the deliverability side, using SES for sending avoids this entirely. Yes, ok, not fully self-hosted I suppose, but it's close enough (and for most people, the bill will be pennies).

Yes I figure if I’m going to pay someone to resolve a domain to an IP address I might as well pay the same person to operate my mailbox. Having clients that sync the mailbox offline is “local” enough for me.
Same story. Ran a set of about 20 postfix mail servers for my company. Prided myself on being proactive, setting everything up correctly. Using things like DANE even before they were mandatory but the trouble was always random blocking which was outlook.com 90% of the time and occasionally yahoo and Deutsch telekom. At least the latter provided contact details and were helpful getting things unblocked but Microsoft had horrific support. You are blocked, we won't or can't tell you why, nothing in the mail management system shows you any problems so we can't tell you what to fix, please see this 15 year old guide as to how to setup email properly and we will tweak the setting a bit to let your mail through until the next time we decide to block it.

So frustrating because they have no legal obligation to accept our emails but our product relies on them being delivered.

I gave up and moved everyone over to SES instead.

Fastmail is not cheap...
Proton doesn't really host a standard email server like imap for you to access on the client side. You have to bridge/proxy/translate it. And Proton doesn't offer any of the convienences like distribution lists that you expect for the past 30+ years.
If you hate it, don't do it, sure.

But I encourage everyone who likes tech and freedom to host their own email. So many reasons.

Some are pragmatic, for example that way you won't ever get locked out suddenly of your entire digital existence when google/microsoft decide to lock you out for no reason and you will never reach support capable of helping.

Some are more about taking a stand for freedom, but that's also worthwhile. The internet was not meant to be owned by just a few behemots who get to control all content. The internet is about distributed peer to peer protocols. Nothing embodies that better than everyone running their own mail server, if you can.

As many say below, if you're worried about the deliverability you can still run your own email server and have nearly all the benefits even if you use a third party relay for delivery.

That said I also deliver from my email server and it is totally fine, the fears are overhyped. Delivery to microsoft is the worst, but even that one just takes filling a form on occasions (been over a year since had to do it last time).

I run self-hosted email for more than 80 domains across three VPSs, almost all of which are one-offs or joke domains and then a handful of old and new personal and business domains.

No deliverability problems. The issues with self-hosting email are drastically overblown.

That's not been my experience. I've been selfhosting email on a small provider VPS for years, never had any deliverability issues that I know of. I've set up DKMS, SPF..etc records properly and I send maybe a dozen emails a day at most.
Good luck having your emails hitting any inbox instead of ending up in spam.
Man these days it's nearly impossible. Even my web host has trouble hosting email, even though I use it and they do a decent job. Only medium-sized specialist companies and large ones like Gmail do it well. It's just those spammers - we could have nice things like self-hosted email if everyone were nice, but we can't.
I've been self hosting since 2012 or so and it is a mixed bag. Deliverability is fine provided you're on a clean IP range, which generally only reputable hosts have.

There was a moment when my son was born and he was in NICU that my mail broke. I just went without for a while. Not ideal.

Since then I've thought: self hosting is nice but hosting cooperatively is probably the best way forward. Democratic control might beat technical control. I'll do it soon, I think: I'd be fascinated to know what people think.

Before self-hosting your own, first get a domain and just point it at a mail provider that allows custom domains. It will cost, but so will a VPS. I suspect a lot of DIY homelab types would have most of their needs met with just that setup:

- you get the vanity email address

- you can switch email providers (including self-hosting later on)

- you can have ~unlimited aliases (depends on the provider)

Most of the setup consists of steps you will have to take anyway when self-hosting (getting a domain, changing DNS records), except for a major amount of headaches that will be taken care of for you.

Agreed. Also being able to use as many aliases as you like (or a catch-all) is very nice.
Some providers use the reputation of the mail servers (smtp.domain.com) and not the actually domain (your-domain.com).
I self-host with telekom business, 2 fixed ip lines fiber and vdsl at home everything from auth ns to mail and web. Its around 85€ for me.

it's still doable and you get the best feeling there is: Living in the internet.

Can recommend 100%.

I beg to differ on:

> but if your home internet checks these boxes, you can 100% host your own mailserver at home:

    Static IPv4 address (make sure it's not blacklisted)
    Not behind a CGNAT
    Ability to change the PTR record of your IP (usually though the support of your ISP)
    Ability to open common mailserver Ports (25,143,465,587,993)

Because above is only needed if you want to communicate with people using Gmail, Yahoo, Outlook, Fastmail, Proton etc (The monopoly).

For normal folks, they are better off using an alternate less privileged email service like email.riamu.io.

The biggest problem with self-hosting a mail server is reliably being able to send email and have it be delivered to the recipient. Something I have been thinking about setting up is self-hosting a dovecot server so that all of my emails that I receive are on my system, but using another provider for sending email. I don't send that many emails, so there is not much privacy loss in regards to a third-party being able to see my sent emails, but I still get the benefit of noone but me having access to my received emails.
> but I still get the benefit of noone but me having access to my received emails.

Other than every smtp relay hop and any network tap along the way that could keep a copy. Hope you're encrypting and not worried about the envelope. Email is fundamentally not private. Self-hosting doesn't help all that much (though it may keep it out of certain companies' hands, aside from the emails copied to or sent from that provider)

I've been self-hosting for 20 years now - a few years ago I switched to using Mail-in-a-Box (https://mailinabox.email/) which makes management a lot easier than configuring each service manually.

It definitely requires some effort but once you've got it up and running it's pretty hands off. The only issues I've ever had are expiring certs but I've fixed that by configuring auto-renewals and it's all good now.

Ensuring your source IP isn't blacklisted is probably the single most important factor. I had to request a new IP from Linode where my server runs as the one it was originally assigned had a bad reputation.

I'd love to self-host a mailing list, or that protonmail or fastmail offered listserv like functionality. It feels fairly intimidating to hoist my own mail server and listserv on top of that. It feels like there's too much domain-specific knowledge one needs to have to reliably debug and maintain it: DKIM, spam management, certbot, fail2ban, blah blah blah.
Every single person I know who has run their own email server has, at one point or another, either outright lost mails or had important mails delayed for days.

It's not worth it.

I've hosted and actively used my own email server for > 10 years and there are two things that are true at the same time:

It is absolutely possible to host, use, and achieve decent deliverability with your own server. It takes work and is a different beast than running a webserver, but that frontier is not dead (yet).

At the same time: it is an ABSOLUTELY TERRIBLE IDEA to suggest that folks operate an email server out of residential IP through your ISP. The spam prevention ecosystem is so draconian now that email traffic flowing out of address ranges belonging to residential owners is yeeted into the sun. If you've operated email infrastructure at decently large scales, you know that SPF/DKIM/DMARC are just one part of how spam is identified, and mixing in the source of email traffic into the detection heuristics is a significant part of that identification process. Achieving decent delivery can often involve "warming up" an IP over time to establish its reputation, and consumer address ranges are a hodge-podge of activity that incur very little trust about what they're doing.

I agree with some commenters that exhort the exercise of self-hosting email to prevent the venerable protocol becoming a homogeneous GMail and Outlook-only world, but there are reliable ways to do this: using a VPS, relying on a company for the sending/SMTP part, or something similar. But footguns abound, and disgorging SMTP packets from your LAN edge is one of them.

The problem isn’t spam, the problem is you becoming the spam.

I did test email selfhosting before and there’s a substantial amount of times my emails were never seen by the recipient, sometimes it did cost me good jobs/deals.

So now I use paid email while I control the domain and everything else, so I have the portability feature if I wanted to switch providers without any efforts, but I know now my emails will be delivered whenever I hit sent.

That being said, I self host everything else in my digital life, and I believe everyone should.

I started self-hosting my email server earlier this year. I use maddy[0] as my email server and route outgoing mail through MailPace[1] to avoid being memory-holed (despite having SPF and DKIM set up correctly).

My reason for self-hosting is control, not privacy: the fact that the cleartext of my outbound emails is visible in the MailPace UI is not a concern; the problem I'm solving is that email providers can delete your account.

[0] https://maddy.email/

[1] https://mailpace.com/