Email Infrastructure
Self-Hosted Mail
Control Without a Black Box
Hosting your own email is more straightforward than most providers imply. I set up the complete path — submission, delivery, authentication, filtering, webmail, and the operational checks that keep each one working.
What I deliver:
- Full mail server setup: Postfix, Dovecot, and a maintained NixOS mail stack
- SPF, DKIM, DMARC, and BIMI where the domain and mailbox provider support them
- Submission on TLS with authentication; no unauthenticated relay path
- Bounce handling, quota policies, aliases, and sender-login maps
- Rspamd filtering plus virus scanning and abuse controls
- Webmail setup or a documented integration with an existing client stack
You get:
- Mailbox data and routing under your control
- Domain-level authentication and a measured deliverability posture
- No per-user mailbox license layered on top of the infrastructure
- A documented path for accounts, quotas, incidents, and recovery
The Mail Path, End to End
Email only works when every hand-off works. I treat the stack as a sequence and test the complete path from a signed message submitted by an authenticated user to its delivery and quarantine decisions.
Submission
- Submission is offered on port 587 with STARTTLS required.
- Users authenticate before the relay will accept a message.
- The open port 25 service relays only where it must and rejects spoofed or unauthenticated senders.
- Message size and connection limits are explicit to reduce abuse and resource exhaustion.
Authentication
- SPF lists the systems permitted to send for the domain.
- DKIM signs message content and headers so receiving systems can verify that they were not changed in transit.
- DMARC declares what receivers should do when SPF or DKIM fails, then collects reports so the policy can be tightened from evidence.
- BIMI, where available, points receivers to the domain’s verified brand mark.
Filtering & Quarantine
Rspamd handles scoring, bayes learning, rate limits, and abuse rules. Messages above the action threshold are rejected or quarantined rather than silently entering every mailbox. Users get a recoverable quarantine path instead of losing legitimate mail.
Deliverability Is a Measurement
SPF, DKIM, and DMARC only establish identity. Placement in a recipient’s inbox also depends on the sending reputation, complaint rate, message content, reverse DNS, and the receiving provider’s decisions.
I establish and monitor the authentication path, then test real outbound mail against major receivers. That means measuring what the receiving systems report, not treating a valid configuration file as proof of inbox delivery.
What the Service Covers
| Layer | Delivery |
|---|---|
| Identity | Domain, hostnames, TLS, SPF, DKIM, DMARC |
| Submission | Authenticated users, STARTTLS, relay policy |
| Mailboxes | Dovecot storage, quota, access controls, full-text search where appropriate |
| Filtering | Rspamd, virus scanning, quarantine, rate and abuse controls |
| Operations | Bounce handling, queue health, authentication reports, backup and restore |
For the network controls around the mail host and the evidence trail, pair this with Security Services and Monitoring & Observability.