Migrating from Google Workspace or Microsoft 365 to self-hosted mail is no longer madness.
Why self-hosted
- Data sovereignty
- Predictable cost
- Complete control
- Zero vendor lock-in
Technical stack
Postfix MTA, Dovecot, Rspamd, ClamAV, Roundcube/SOGo, Postscreen.
Modern email security
DKIM, SPF, DMARC, MTA-STS, TLSA/DANE, Greylisting.
Example: Postfix main.cf
The essential main.cf settings (TLS, DKIM, RBL anti-spam):
# /etc/postfix/main.cf — esential
myhostname = mail.example.com
smtpd_tls_security_level = may
smtpd_milters = inet:localhost:8891 # OpenDKIM
smtpd_recipient_restrictions =
permit_mynetworks,
reject_unauth_destination,
reject_rbl_client zen.spamhaus.org
DKIM with OpenDKIM
You generate the DKIM key and wire it to Postfix:
apt -y install opendkim opendkim-tools
opendkim-genkey -b 2048 -d example.com -s mail -D /etc/opendkim/keys/
cat /etc/opendkim/keys/mail.txt # cheia publica -> DNS TXT mail._domainkey
# /etc/postfix/main.cf
smtpd_milters = inet:localhost:8891
non_smtpd_milters = $smtpd_milters
systemctl restart opendkim postfix
Dovecot + basic anti-spam
You configure secure IMAP and a first anti-bot line:
apt -y install dovecot-imapd rspamd
# /etc/dovecot/conf.d/10-ssl.conf
ssl = required
ssl_cert = </etc/letsencrypt/live/mail.example.com/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.example.com/privkey.pem
# Postfix: postscreen respinge botii inainte de SMTP
postconf -e 'postscreen_greet_action = enforce'
SPF + DMARC + MTA-STS (DNS)
The DNS records that get mail out of Spam and stop spoofing:
example.com. IN TXT "v=spf1 mx -all"
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"
_mta-sts.example.com. IN TXT "v=STSv1; id=2026"
# https://mta-sts.example.com/.well-known/mta-sts.txt:
# version: STSv1 / mode: enforce / mx: mail.example.com / max_age: 604800
Anti-spam: Rspamd + greylisting
You cut spam with scoring and greylisting:
apt -y install rspamd redis-server
rspamadm configwizard # DKIM, greylist, scoring
# greylisting (intarzie prima livrare -> botii renunta)
echo 'enabled = true;' > /etc/rspamd/local.d/greylist.conf
rspamadm control reload; rspamc stat