Email is like those creaking old Terminators from the ’70s which continue to function without complaining. Designed for a world that doesn’t exist anymore, it has optional encryption, no built-in auth, three⁺ retrofitted security layers bolted on top, an unstandardized filtering layer and many more quirks. Yet billions of emails arrive correctly every single day.
Email is not elegant but nonetheless it is Lindy. In the new age of agentic AI, we can only expect it to metamorphose into another dimension.
↫ Saurabh “Sam” Khawase
The fact that email is as complicated as it is bad enough, but having it be so dominantly controlled by only a few large gatekeepers like Google and Microsoft surely isn’t helping either. I feel like email is no longer really a technology individuals can actively partake in at every level; it feels much more like WhatsApp or iMessage or whatever in that we just get to send messages, and that’s it. Running your own mail sever isn’t only a complex endeavour, it’s also a continuous cat-and-mouse game with companies like Google and Microsoft to ensure you don’t end up on some shitlist and your emails stop arriving.
I settled on Fastmail as my email service, and it works quite well. Still, I would love to be able to just run my own email server, or have some of my far more capable friends run one for a small group of us, but it’s such a daunting and unpleasant effort few people seem to have the stomach and perseverance for it.

I pay $10 a month for a mail server host. I can add up to about 300 aliases. If I ever get spam on one of them, I just destroy it and create a new one.
Still, about the only thing I use email for these days is to receive electronic bills and such.
First of all, I am really happy the email still works. Sure it has limitations and complexity, but when I try to figure out alternatives I just see the landscape horrible.
The last few years a lot of ‘independent’ providers are producing email options that work very good, at least to me. Self-hosting is a real drama, but being far from large gatekeepers is not complicate.
To be honest, I am much more concerned about about Whatsapp everywhere for everything.
I’ve been with Fastmail for probably two decades now and they have been fantastic. I feel like email is one of the few means of communication that works everywhere and is not completely under control of a single corporation. I completely depend on it, and it is my primary means of (important) online communication. I can do without Whatsapp and the likes, but I would feel crippled without email.
I’ve been successfully running my own email server for years. Once you get it up, it works fine. But you just can’t afford any mistake, otherwise you will get a blackmailed IP. You can practice at your-favourite-cloud-provider.
1. Spin up a VM or so. Check the reputation of the IP address.
2. If the IP address is OK, make sure DNS is set correctly. Reverse is mandatory. Set up throttling. I don’t let any domain send more than 10-15 messages per hour.
3. Configure everything step-by-step, patiently. Michael W Lucas’ book is an excellent resource, but I managed to set it on my own before, with mailcow.
Both my home providers in Europe (one is a local provider, the other one is O2) offer fixed IPv4 and a fixed block of IPv6 with reverse DNS for 10 EUR per month, so I get redundancy. Start slowly. Create a mailbox for yourself, mail your previous email. If you did everything correctly and your IP has a good reputation, you will most probably not land in spam. If you do, mark as not spam. Let it settle, move your services one by one to your new email in your new server and start mailing out from it.
Now I host my email, email for a few friends and even rent out capacity for 2 eshops of people I know. Email is robust. If you lose power, the sender server will retry reaching you a few times and notify the sending user if message delivery failed. Anyone sending from your server will not manage to connect and the message will sit quietly in the outbox until your server is back online.
Moving out is also easy. I had to put my home lab off for a couple of days, no problem. Spin up a quick VM in the cLoUd, find an IP of good reputation, stop your server, move everything your new VM, repoint DNS, let it settle and start the service again.
So Thom, if you feel like scratching the itch, take the chance and spread the word. We can fight this fight. Now I got email, nextcloud for myself and my friends – we all put some money in for storage and we have a mirror across the ocean with backups. We share our photos there, stay in touch via email. For quick calls, I use Signal, but most of my written communication with my closest friends doesn’t even leave my server. It’s my email, Signal or nothing. And guess what? All my friends and relatives chose to stay in touch with me and swallow the inconvenience.
The first server I put up I was 15. NT4, PPTP, simple FTP, 256/128 DSL and no-ip for DNS. My mom hated the box at the corner of the living room but here I am, almost 40, still hosting my own file servers and more (Windows-free nowadays).
Everyone with the technical skills and the budget has the moral duty of taking back control of at least one aspect of their digital lives, in my opinion.
I posted another comment in a similar vein as yours, but it’s awaiting moderation.
I’ve always liked the idea of technology evolving more decentralized, with P2P and federation such that everyone can run their own hardware if they choose. We could have user-friendly turnkey devices to run daemons for messaging/voip/email/files/multimedia/backups/etc. And these services could be integrated with desktop/laptops/tablets/etc so that they are easy for users to setup and use.
While I believe this is technologically doable, unfortunately for people like us the tech giants who are in the best position to make end to end services a widespread reality for average users aren’t interested in doing so. They would have us all tethered to centralized services they control with data collection, ads, subscriptions, etc. Solutions that liberate us from their grasp are dead to them. 🙁
Yes, this is the most important part: it’s federated unlike most of the other systems out there.
This is good to read. I self-hosted my email back in the late 90s but jumped off in about 2005 because Spam and blacklisting became more than I could easily handle. Nice to see that it’s still possible.
These are the posts, I am here for! Kudos.
In general, I am also a big fan of doing stuff myself and keep control as much as possible — but I gave up on e-mail for the following reasons:
– in a SME, you need so redundancy and fail-over (which would make it at least 2 servers plus one admin). So in reality you will buy a virtual server somewhere.
– once you buy a virtual server, e-mail comes free
– unfortunately, all of my clients are Microsoft/Azure infested. And we keep “losing” emails, although our hoster IONOS is one of the largest one in Europe. Now imagine this situation with self-hosting. Losing e-mails (silently) is really bad for us, especially when bound to SLAs with hard constraints and penalties.
– e-mail is cheap, ZOOM is more expensive. So in the reality of a SME, e-mail would be the last thing to self host. My focus would be Web Meeting first and anything that costs money.
– Corporates do not allow WhatsApp/Signal/etc. but are forced to record any communication (in the US at least). They even fined banks for communicating via messenger w/o logs.
Personally to me, e-mail is still the preferred way: formatting, archiving, near-time but asynchronous.
Thom Holwerda,
You know we could walk you through it. with some help you could realistically do it…but only consider it if you actually like the idea of being an email admin, haha. I don’t know if your ISP lets SMTP through, but here it’s usually blocked. and you need a VPS somewhere. Some providers including godaddy don’t let you do direct email hosting even on dedicate VPS/server plans; avoid providers like them. You’ll also need a domain or subdomain for emailing.
I don’t have issues often, but sometimes Inbound spam and blacklisted hosts can make self hosting a drag. People have different luck when it comes to the reputation of nearby IPs. I use DNSBL services to block inbound spam, it blocks loads of spam but it isn’t perfect.
MXToolbox has a nice blacklist lookup tool to query IPs in common DNSBL services. You can also retroactively check spam email headers to see which spam blacklists would have blocked a spam message to consider using them.
https://mxtoolbox.com/
There’s a learning curve, most people don’t want to deal with it and prefer to just outsource it…but I’d say it’s an achievable goal if you are interested.
> it’s an achievable goal if you are interested.
Pretty much this.
I remember going from 0 to self-hosted in 2 days (personal). If SMTP isn’t blocked, the hardest part is getting the provider to set up a PTR record, for that you need a cooperative ISP.
I’m lucky, my ISP just said “ok, here’s the Internet”, and just doesn’t block anything. SSH logs are a doozy to follow, I’m very grateful for fail2ban.
I also got off self-hosting because of blacklisting, the final straw was being wrongly blacklisted and taking weeks to resolve. In the modern AI era I can imagine this becoming intolerable, nobody to talk to, no way to argue your case, no hope of a quick resolution. When we see what is happening on platforms like Youtube, I think we can see what dealing with an AI relay will become.
I too have been using Fastmail as one of my primary providers for a couple of decades. It’s a stable reliable product, not too expensive, just nicely priced and as commercial it comes without the bag of rubbish that comes with various free accounts like Gmail. I often ponder that people who claim email is dead are probably long-term Gmail users, it’s a dog’s breakfast and has itself proven that to everyone more than once.
cpcf,
I still do hosting for customers. Problems are rare, but I have had some bad days, especially when end users are waiting for fixes and the holdup is actually an external provider that isn’t being responsive. Unless you’re some VIP sometimes it’s just easier to get a new VM/IP rather than to get another provider to service an issue with their service promptly. :-/
For me, google gets an F for customer support every single time.. Official support is basically MIA. Layoffs probably hit customer support ranks hard. I’ve noticed that VIPs with a large social media following have a cheat code though: publish their problem publicly and a google representative will pop out of the woodwork and suddenly be available to fix it. This is a nice perk for influencers!
Alfman,
that’s riding on the cutting edge: they will easily blame you when things go wrong while at the same time there is no money in it. I was never a big fan of the “buying IBM” approach — but for e-mail, better stay with the swarm. The Risk/Reward ratio is abysmal bad on this one.
Andreas Reichel,
I see your point, but it’s not just email, so much in IT has been an abysmal race to the bottom. I sell the whole package including email because customers expect it Email/web/dns/database/offsite backups/monitoring/reporting/administration/etc are all bricks that go together to build something greater. If you deliver everything except email then your package has holes and you lessen the value for customers and encourage them to go elsewhere for everything.
Alright, now it becomes clearer though my concern stands: RDBMS/DNS is in your hands and you actually can do something about. E-Mail (filtering on the receiver’s end) has become a matter of luck and so I would look for an option to relay it.
Anyway, you certainly know your business best and its always good talking to you.
Best and cheers!
In my little userland bubble I am happy to have Gmail – I can’t think of a better place to for all the adverting, spam and scams I receive to end up. I almost never get important or worthy email anymore.
I love email, despite all its flaws, I kinda feel it’s the last remnant of the “better days” of the Internet. Sure, it’s become a bit of a mess to set up, but it’s still an amazingly simple and functional bit of technology.
I have stopped trying to host my own email, though. Email and texting are the 2 means of communication I can hardly live without to this day, and the pressure of self-hosting my (family’s) email was a bit too much: any disruption meant I’d have to set everything else aside until it was solved, be it because an update has borked something or because your Internet neighbor being trojaned got your whole subnet on some spamming blacklist…
In the end, I’ve settled for some middle-ground: a local open-source services company hosts my MX, I copy all mail to a local dovecot installation and delete everything older than 6 month from their servers. This gives me piece of mind on all accounts and switching shop is pretty easy if I ever feel something’s off with them. I don’t have to worry about losing access to my emails 2 days after the beginning of my overseas family vacation, and that’s actually priceless to me.
worsehappens,
It was simple at the beginning, but these days it’s a mess. There’s so much duck tape holding things together.
At least in theory I welcome a modern replacement that cleans up the mess and brings modern features and end to end security with consistent implementations. However I have huge reservations because deep down I know today’s companies want to apply enshitification to just about everything. Things like federation and independent hosting are so important to our rights, but they are dying with new platforms because the companies designing them want to trap the world in their grasp with anti-features like subscriptions and taking away our rights for their benefit.
So while I don’t like all the hacks and antiquated features that are entangled in legacy email, if the alternative is a platform designed by tech giants to take away our independence, then I have to prioritize freedom over modernization.
Hmmm … Fastmail seems to be operating out of the US.
Does that raise concerns for any non-Americans?
Just asking for a friend.
ponk,
That’s an interesting question. How much do people actually care if their data is in US jurisdictions? …I’m not sure? Are there many foreigners boycotting US companies like microsoft/google/apple/etc? They’re all subject to US jurisdiction.
Obviously most people aren’t persons of interest, but still there are cases like this that highlight how everyone’s data is at risk of being used by law enforcement
https://moneywise.com/news/news/supreme-court-geofence-warrants-fourth-amendment-privacy
They make all kinds of arguments for why they’re entitled to scan data belonging to non-specific persons. The supreme court may finally weigh in on whether these police dragnets will be the law of the land or not. Foreigners in other countries should know that they have fewer rights in the eyes of the NSA and other government agencies.
For me, my main concern is not about what happens to my data if it’s in the U.S., it’s what happens if my access to it becomes hostage to whatever political shenanigans go on between America and the EU/UK, or between Google/Microsoft and the EU/UK.
I pay for an email service in the EU and I’m in the process of changing my government and utility contact addresses from Gmail and Hotmail over to it. Years ago I used to run my own server but these days I don’t have the time and energy to do so.
From your wording (using “operating out of”), I assume you already know that Fastmail is an Australian company. But yes, their servers are in the US.
I don’t love that they operate out of the US, tbh, but they are open about what to expect privacy-wise (https://www.fastmail.help/hc/en-us/articles/6049922252943-Fastmail-privacy), are generally very open about lots of things on their blog (https://www.fastmail.com/blog/), and provide a good service. So I have stuck with them as a customer.
At the very least, if things get really really bad in the US and overstep what Fastmail is prepared to put up with, they could theoretically shift the servers overseas since they are Australian.
Unfortunately, waiting until things get _really_ bad sounds a bit to0 much “horse/barn door” for comfort.
(especially since things are already kinda bad right now and trend-line is not very encouraging).
I (at work) host emails and also manage the a mail service for another client that has tons of schools as clients themselves.
It’s a pain, but not because of the protocols involved themselves, but the users:
“X sent me a mail but I haven’t received it yet (that was 5 minutes ago) – (checks the logs) no incoming for you nor spam, i have no control of the senders queue – never mind it arrived in the meanwhile” : People forget it’s async
“I sent an e-mail to Y but Y says it didn’t arrive – grep through logs, hum 200 within a few seconds on O360 servers, check with them 😀 – Y receives other emails than mine, why didn’t Y get mine – told you (log snip) they got the mail” I have no power on the dark side of the force (and their postmaster tools are mostly no help tbh)
“can you lower the dkim/spf shananigans and be less trigger happy on spamassassin rules, some random newsletters aren’t getting through – you sure ? – yes – ok …… Errrr, accounts are submerged in cr*p – yeah well, you send legit stuff that look like cr*p and wanted to receive more in the meanwhile” (they’re bringing a bad rep to our AS, and lot’s of their clients clients clients accounts got hacked over the years too, doesn’t help)
“Hey, client Z had a problem with something doing this or that – Can you give me some timestamp so I can grep through the logs, recent activity shows nothing special – err, Z said it was 2 months ago, let me ask Z again – 2 months ? that’s archeology, please ask Z – ….. (no more reply)”
“Bref” … e-mails are lot’s of headaches, hard to bill hours, and tons of unanswered tickets (even clients give up on helping us help them) the most painful and least profitable service you can offer as long as you leave any door open to interaction, same goes for small website hosting… you need to industrialize it as much as possible, fill in wikis of self-servicing tips, and not implement anything that is not needed by most people (others will adapt) … that’s a lot of work ahead == you still need people (that you usually don’t fire in the end) == not a two people company, but way bigger
We’d rather be deploying proxmox clusters on 100G networks, it is way more satisfying once it purs 🙂
> It’s a pain, but not because of the protocols involved themselves, but the users:
to add to that:
1) once I had a user who asked wether it’s possible that some agency shuts down their mailservice outside of business hours. he tried to send them mails in the evening and they always fail. he sent an email during business hours before and it worked. it was something very important and the user insisted that he used the correct address etc.
well. of course there was a typo in the e-mail-address
2) users that use “mark as spam” to make e-mails disappear. I see many of them in the feedback loops for email, mostly from hotmail/outlook users. why would anyone mark a purchase receipt as spam? WHY? just delete it if you do not need it anymore.. sheesh
crazy-weasel,
I had a user who would mass forward emails from the hosting account to his personal gmail account. Then he used the spam button in gmail, marking emails forwarded from himself as spam. The result was that the hosting IP got blacklisted. And when that happens google stops delivering all emails from all users on that IP, not just his. I instructed the user to setup gmail to pull the emails via IMAP instead of forwarding them. I also had to switch IPs.Since unrelated users can and do share IPs like this, blacklisting based on IPs is a really dumb solution, but it’s become a necessary evil. IP blacklisting hurts innocent parties and that’s just the way it is.
I think AI classifiers might be the most effective solution for spam today, but it’s hard to generalize because even as a human I can look at an email and not know whether or not it’s spam. In other words it’s not always clear whether the sending party had permission to send the email or if it was purely unsolicited.
If we could design a new email system from the ground up, we could make adding users to an email list require the permission of that user. SPAM laws say senders are already supposed to have user permission, but the technology doesn’t actually enforce it at all and spam remains rampant. Cryptographic identifies and other technology could offer novel solutions for these kinds of problems, but email systems are too antiquated and deploying robust cryptographic and permission based solutions across the entire email network is a pipe dream.
New protocols that solves these problems has long been something I’ve wanted to build. But it’s one of those things that can’t be viable on an isolated island. The giant corporate fish could get the ball rolling, it would require the buy in from all the major tech companies and email clients. But a small grass roots movement would face catch-22 adoption obstacles.
oh no! 😀
but yes – it’s true, a single user can ruin your ip-reputation easily. never had that problem with gmail though.
> because even as a human I can look at an email and not know whether or not it’s spam.
I had a customer who asked me about an e-mail, wether it’s spam or not – they were not sure and did not want to click on it. Mysterious link in it, no direct connection to the sender in any way – but yes, was from the municipality and they used a weird provider for sending out some stuff.
> we could make adding users to an email list require the permission of that user.
but what about transactional mails? you don’t have to be on a list in order to receive those, and currently you’d need to receive them to get on a list. 😀
or just regular mail between people.
also weird: currently I see spam mails that seems to be confirmation-mails from legit support systems – spam message is in the subject, or as the name, and the body is just “thank you for your message, our support team will look at it” (or similar)