Stefano Marinelli<p>Sharing some technical details about how I'm setting up the hosted email service. It will not be a service of BSD Cafe but tied to my own business. It will run entirely on BSD systems and on bare metal, NOT on "cloud" VPS. It will use FreeBSD jails or OpenBSD or NetBSD VMs (but on bhyve, on a leased server - I do not want user data to be stored on disks managed by others). The services (opensmtpd and rspamd, dovecot, redis, mysql, etc.) will run on separate jails/VMs, so compromising one service will NOT put the others at risk. Emails will be stored on encrypted ZFS datasets - so all emails are encrypted at rest - and only dovecot will have access to the mail datasets. I'm also considering the possibility of encrypting individual emails with the user's login password - but I still have to thoroughly test this. The setup will be fully redundant (double mx for SMTP, a domain for external IMAP access that will be managed through smart DNS - which will distribute the connections on the DNS side and, in case of a server down, will stop resolving its IP, sending all the connections to the other. Obviously, everything will be accessible in both ipv4 and ipv6 and in two different European countries, on two different providers. Synchronization will occur through dovecot's native sync (extremely stable and tested). All technical choices will be clearly explained - the goal of this service is to provide maximum transparency to users on how things will be handled.</p><p><a href="https://mastodon.bsd.cafe/tags/BSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BSD</span></a> <a href="https://mastodon.bsd.cafe/tags/FreeBSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FreeBSD</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenBSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenBSD</span></a> <a href="https://mastodon.bsd.cafe/tags/NetBSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetBSD</span></a> <a href="https://mastodon.bsd.cafe/tags/emailHosting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>emailHosting</span></a> <a href="https://mastodon.bsd.cafe/tags/encryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encryption</span></a> <a href="https://mastodon.bsd.cafe/tags/ZFS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ZFS</span></a> <a href="https://mastodon.bsd.cafe/tags/dovecot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dovecot</span></a> <a href="https://mastodon.bsd.cafe/tags/opensmtpd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensmtpd</span></a> <a href="https://mastodon.bsd.cafe/tags/rspamd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rspamd</span></a> <a href="https://mastodon.bsd.cafe/tags/emailSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>emailSecurity</span></a> <a href="https://mastodon.bsd.cafe/tags/techTransparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>techTransparency</span></a> <a href="https://mastodon.bsd.cafe/tags/ipv6" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ipv6</span></a> <a href="https://mastodon.bsd.cafe/tags/Europe" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Europe</span></a></p>