offering (self)hosted email for ourselves and maybe others down the line #115

Open
opened 2026-10-06 11:48:29 +00:00 by jessebot · 0 comments
Owner

Let's start by just experimenting with hosting it for ourselves on an inconsequential domain. I'll use this issue to write everything I know/learn about FOSS self-hosting email.

I asked about this on fedi, because why not. And oh boy, there were many more options and opinions on a lobste.rs post someone linked. I read all the responses and compiled everything below.

Full Email Suites

  • maddy

    • It replaces Postfix, Dovecot, OpenDKIM, OpenSPF, OpenDMARC and more with one daemon with uniform configuration and minimal maintenance cost.
      Note: IMAP storage is "beta" and jmap is unsupported. If you are looking for stable and feature-packed implementation you may want to use Dovecot instead. maddy still can handle message delivery business.
  • mailcow

    • selling point is docker images to wrap common stuff like postfix and rspamd
    • using AI in their repos
  • mail in a box

    • older and uses spamassisin - see below
  • mailu

    • built for docker (combines dovecot, postfix, rspamd, webmail, and admin panel)
    • doesn't support jmap and won't until dovecot does
  • mox

  • Stalwart - New kid on the block that many are excited about, but not quite production ready yet. Some comments from lobste.rs:

    • reports of LLM in the pro product
    • reports of LLM generated docs that are frustrating and verbose but somehow incomplete
    • JMAP is a major feature
    • reports of upselling all over the place in the community edition
    • groups support is limited?
    • does its best to work out of the but you still need to troubleshoot things (use https://www.learndmarc.com/ to check your config).
    • There are things like reverse DNS that Stalwart can't help you setup.
    • One thing I'd like to improve later is having a jmap based syncing tool. Similar to mujmap.
  • inbuxa

    • AGPL fork of stalwart aimed at being more free and no longer upselling or checking license keys
    • written using AI
  • mok "mail on kubernetes"

    • seems to wrap postfix + dovecot
    • developer commented and said they want to replace it with mox, but might still be useful to reference

Servers

MTA (mail transfer agent)

  • postfix

    • seems to be the most common for sending mail?
    • has a permissive ai policy (that allows major refactors)
  • Sendmail

    • only mentioned once and seems to be predate postfix
  • courier

  • exim

    • largely seems to have been superceded by postfix, but seems to be the original goto with some still using it
    • has an anti-ai policy
  • OpenSMTPD

Further reading: https://mailtrap.io/blog/postfix-sendmail-exim/

um these?

  • dovecot

    • mentioned commonly in relation to both postfix and opensmtpd
    • had an agents.md in their repo
  • james

    • supports jmap
    • no built in spam detection from what I can tell so far
    • AI in the code base, but less than tmail
  • tmail

    • fork/additions to james?
    • uses claude

imap

  • cyrus primarily mentioned with postfix/exim
  • imap-uw
    • seemingly for openbsd?

Might be useful to look more into JMAP which seeks to replace imap, caldav, carddav

Server Security

Look into various DNSRBLs?

Spam filtering

  • spamassassin
    • seems superseded by rspamd (but mentioned in relation to opensmtpd and postfix)
  • rspamd
    • mentioned frequently in relation to both opensmtpd and postfix
    • has a claude.md in the code base
  • postfix-policyd-spf-python - mentioned for postfix - checks spf records

greylisting specifically

  • greyfix - policy daemon for postfix, mentioned in relation to blocklistd, on codeberg
  • milter-greylist - mentioned in relation to sendmail and procmail
    • not dead, it is just mature, and does not release often.
    • milter-greylist is a stand-alone milter written in C that implements the greylist filtering method, as proposed by Evan Harris.
      Grey listing works by assuming that, unlike legitimate MTA, spam engines will not retry sending their junk mail on a temporary error. The filter will always reject mail temporarily on a first attempt, then accept it after some time has elapsed.
  • sqlgrey - policy daemon for postfix, but source code not touched in over a decade

uncommon

  • spamd (only mentioned in relation to opensmtpd so far)
  • blocklistd - mentioned in relation to postfix, greyfix, and openbsd

DKIM and DMARC

  • opendkim - sponsored by nlnet
  • opendmarc
  • dkimproxy (only mentioned in relation to opensmtpd and does not seem to be active)

Mail list

  • mlmmj (for mail list) - mentioned only in relation to opensmtpd so far, seems old and not touched in 5 years

Clients

CLI/TUI

  • mutt - classic, defer to it since neomutt has AI in it
  • aerc
    • anti-ai policy
    • supports jmap
  • meli - anti-ai policy

local syncing and indexing

  • mbsync - synchronize imap4 and maildir inboxes
    • msmtp - smtp client (combo also mentioned in relation to notmuch)
    • mu (and mu4e) as agent, and msmtp to send.

bonus reading: https://ploum.net/2026-01-31-offline-git-send-email.html

Indexing

  • nomuch
    • has an anti-ai policy
    • While reading the mumap code and dependencies I was surprised to learn that notmuch is not thread safe
  • procmail

desktop

Webmail

Android

Let's start by just experimenting with hosting it for ourselves on an inconsequential domain. I'll use this issue to write everything I know/learn about FOSS self-hosting email. [I asked about this on fedi](https://social.open.engineering/@jessebot/statuses/01M46G3HBEZBKBBSHYHWEHYETR), because why not. And oh boy, there were many more options and opinions on a [lobste.rs](https://lobste.rs/s/rwloew/email_self_hosters_what_are_you_using) post someone linked. I read all the responses and compiled everything below. # Full Email Suites - <strike>[maddy](https://maddy.email/)</strike> - It replaces Postfix, Dovecot, OpenDKIM, OpenSPF, OpenDMARC and more with one daemon with uniform configuration and minimal maintenance cost. Note: IMAP storage is "beta" and jmap is unsupported. If you are looking for stable and feature-packed implementation you may want to use Dovecot instead. maddy still can handle message delivery business. - [mailcow](https://mailcow.email/) - selling point is docker images to wrap common stuff like postfix and rspamd - using AI in their repos - <strike>[mail in a box](https://github.com/mail-in-a-box/mailinabox)</strike> - older and uses spamassisin - see below - [mailu](https://github.com/mailu/mailu) - built for docker (combines dovecot, postfix, rspamd, webmail, and admin panel) - doesn't support jmap and won't until dovecot does - [mox](https://www.xmox.nl/) - (no milter / rspamd support, since spam hasn't really been a problem with mox https://github.com/mjl-/mox/issues/47) - sponsored by nlnet - jmap is on the roadmap - AI in the codebase - [Stalwart](https://stalw.art/) - New kid on the block that many are excited about, but not quite production ready yet. Some comments from lobste.rs: - reports of LLM in the pro product - reports of LLM generated docs that are frustrating and verbose but somehow incomplete - [JMAP](https://jmap.io/) is a major feature - reports of upselling all over the place in the community edition - groups support is limited? - does its best to work out of the but you still need to troubleshoot things (use https://www.learndmarc.com/ to check your config). - There are things like reverse DNS that Stalwart can't help you setup. - One thing I'd like to improve later is having a jmap based syncing tool. Similar to [mujmap](https://github.com/elizagamedev/mujmap). - [inbuxa](https://git.coffeylabs.org/inbuxa/inbuxa-server) - AGPL fork of stalwart aimed at being more free and no longer upselling or checking license keys - written using [AI](https://coffeylabs.org/ai/) - <strike>[mok](https://artifacthub.io/packages/helm/si-gitops/mok)</strike> "mail on kubernetes" - seems to wrap postfix + dovecot - developer commented and said they want to replace it with mox, but might still be useful to reference # Servers ## MTA (mail transfer agent) - [postfix](https://en.wikipedia.org/wiki/Postfix_(software)) - seems to be the most common for sending mail? - has a permissive ai policy (that allows major refactors) - [Sendmail](https://en.wikipedia.org/wiki/Sendmail) - only mentioned once and seems to be predate postfix - [courier](https://www.courier-mta.org/) - [exim](https://en.wikipedia.org/wiki/Exim) - largely seems to have been superceded by postfix, but seems to be the original goto with some still using it - has an anti-ai policy - [OpenSMTPD](https://en.wikipedia.org/wiki/OpenSMTPD) - seems to be mostly for BSDs (edit: but can also be run on linux) - author note: I love the simplicity of opensmtpd, and the fact that it all runs without a database. Emails are stored as files and accounts are created with a dedicated passwd(5) like file in /etc/mail/. - author note2: I followed https://poolp.org/posts/2019-09-14/setting-up-a-mail-server-with-opensmtpd-dovecot-and-rspamd/ back in 2020 and have been running it ever since. I wouldn't change anything. Further reading: https://mailtrap.io/blog/postfix-sendmail-exim/ ## um these? - [dovecot](https://doc.dovecot.org/2.4.5/) - mentioned commonly in relation to both postfix and opensmtpd - had an agents.md in their repo - [james](https://james.apache.org/) - supports jmap - no built in spam detection from what I can tell so far - AI in the code base, but less than tmail - [tmail](https://github.com/linagora/tmail-backend) - fork/additions to james? - uses claude ## imap - [cyrus](https://github.com/cyrusimap/cyrus-imapd) primarily mentioned with postfix/exim - its imapd but also supports [jmap partially](https://www.cyrusimap.org/imap/download/installation/http/jmap.html#jmap-implementation-status)? - has AI in the code base - [imap-uw](https://github.com/uw-imap/imap/blob/master/README.md) - seemingly for openbsd? Might be useful to look more into [JMAP](https://jmap.io/) which seeks to replace imap, caldav, carddav ## Server Security Look into various [DNSRBLs](https://en.wikipedia.org/wiki/Domain_Name_System_blocklist)? ### Spam filtering - <strike>[spamassassin](https://spamassassin.apache.org/)</strike> - seems superseded by rspamd (but mentioned in relation to opensmtpd and postfix) - [rspamd](https://github.com/rspamd/rspamd) - mentioned frequently in relation to both opensmtpd and postfix - has a claude.md in the code base - [postfix-policyd-spf-python](https://pypi.org/project/pypolicyd-spf/1.3.2/) - mentioned for postfix - checks spf records #### greylisting specifically - [greyfix](https://codeberg.org/KMK/greyfix) - policy daemon for postfix, mentioned in relation to blocklistd, on codeberg - [milter-greylist](http://hcpnet.free.fr/milter-greylist/) - mentioned in relation to sendmail and procmail - not dead, it is just mature, and does not release often. - milter-greylist is a stand-alone milter written in C that implements the greylist filtering method, as proposed by Evan Harris. Grey listing works by assuming that, unlike legitimate MTA, spam engines will not retry sending their junk mail on a temporary error. The filter will always reject mail temporarily on a first attempt, then accept it after some time has elapsed. - <strike>sqlgrey</strike> - policy daemon for postfix, but source code not touched in over a decade #### uncommon - <strike>spamd</strike> (only mentioned in relation to opensmtpd so far) - [blocklistd](https://man.netbsd.org/blocklistd.8) - mentioned in relation to postfix, greyfix, and openbsd ### DKIM and DMARC - [opendkim](http://www.opendkim.org/) - sponsored by nlnet - [opendmarc](https://github.com/trusteddomainproject/OpenDMARC) - <strike>dkimproxy</strike> (only mentioned in relation to opensmtpd and does not seem to be active) ## Mail list - [mlmmj](https://github.com/v12mike/mlmmj) (for mail list) - mentioned only in relation to opensmtpd so far, seems old and not touched in 5 years # Clients ## CLI/TUI - [mutt](https://en.wikipedia.org/wiki/Mutt_(email_client)) - classic, defer to it since neomutt has AI in it - [aerc](https://sr.ht/~rjarry/aerc/) - anti-ai policy - supports jmap - [meli](https://meli-email.org/) - anti-ai policy ### local syncing and indexing - [mbsync](https://isync.sourceforge.io/mbsync.html) - synchronize imap4 and maildir inboxes - [msmtp](https://marlam.de/msmtp/) - smtp client (combo also mentioned in relation to notmuch) - mu (and mu4e) as agent, and msmtp to send. bonus reading: https://ploum.net/2026-01-31-offline-git-send-email.html ### Indexing - [nomuch](https://github.com/aclements/notmuch) - has an anti-ai policy - While reading the mumap code and dependencies I was surprised to learn that notmuch is not thread safe - [procmail](https://en.wikipedia.org/wiki/Procmail) ## desktop - [claws](https://www.claws-mail.org/) ## Webmail - [sogo](https://www.sogo.nu/) - [Roundcube](https://roundcube.net/) ## Android - k9mail - [sterna](https://codeberg.org/emon/sterna-mail)
jessebot changed title from offering hosted email to offering (self)hosted email for ourselves and maybe others down the line 2026-10-07 08:13:01 +00:00
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
oeng/argocd-apps#115
No description provided.