Email was my last third-party service
Ever since I discovered the power in self hosting, email was always the one thing I relied on third parties for. That changes today.
Quick recap
I started self hosting not long ago. The very first service I self hosted was Home Assistant. But there isn’t really any non-self-hosted way to run Home Assistant so I think we can skip that one. The next one was Jellyfin. The goal was simple: replace Spotify.
Before using Spotify I had used plenty of other things. Namely, Google Music (remember that?)—where I uploaded my entire music library—and before that I didn’t even rely on the ‘cloud’ at all. I used iTunes on Mac OS X and Winamp on Windows. Those were simpler and happier days where we didn’t walk around with computers in our pockets capable of doing much more than what our home computers did back then.
But hosting Jellyfin is easy. And whether it succeeds or not, really depends on how well you organize your media library and not much else.
Up until this moment, every service I self hosted kind of stayed within our own walls. Although I can access some of them from the outside, such as Jellyfin and Home Assistant, their concerns stay within our walls. In the sense that none of them needs to interact with third party servers.
Email, on the other hand, it’s not quite like that.
Email as a self hosted service
One of the reasons I thought I would never dip my toes into email waters is simply the fact that my servers would need to talk to other servers. I just didn’t want that burden.
Another very relevant reason is what it’s called ‘deliverability’. Basically, how likely is it that the IP of the server the email is being sent from is not listed on spam lists so that your emails are delivered to the inbox of recipients instead of spam folders. Once your IP is marked as spammy, it’s a hard and bumpy road back to inbox city, I heard.
The other obvious reason was the fact that, so far, all my services are running on my NAS, at home. If it suffers from a power outage or the internet is down, my servers are unreachable. The idea of missing emails just because power at home was cut and I was away was nerve-wracking to me. More on that later.
I started on Google
Probably just like many of you, my very first, somewhat serious email address was hosted at Google with a @gmail.com address. The only one I remember having before that was a Hotmail one, but I never took it serious enough to spread it.
Google was perfect for someone starting out with email, which is likely the reason why so many people start there in the first place. Although nowadays there are plenty more options than there were back when I started, the fact that it offered several GB of storage and had plenty of other services like Photos, Drive and Docs, made the offer very compelling. Oh, and did I tell you the price yet? It’s ‘free’, they say.
It took me plenty of time, but eventually I realised that there’s no such thing as a free service on the internet.
When the product is free, you are the product.
Basically, Google can afford to offer all their services at no cost for the end user because they will benefit so much more from the data they will be able to harvest from that zero-cost account. Google sells ads, not products. They are a data company, more than anything.
Think about it: what’s the search engine that most people use? Google!
What’s the OS in most people’s phones? Android. Google owns it.
What’s the email service that most of your friends use? In my case it’s Gmail, from Google.
And I could go on… The amount of data they are able to collect from a single person is inconceivable for most of us.
Apple was next
The very first time I got myself an iPhone (the 3G S—arguably the best yet!) I kept using my Google account for everything, but most importantly for email, contacts and calendars. But recently, in 2022, when I got myself another iPhone (the 14 Pro), I wanted to switch away from Google. Entirely de-Googling my life.
You know, Google has a very well known shady track record when it comes to handling users’ data. (ref 1, ref 2).
I wanted out! And at that point I was fully in. Photos, Drive, Docs, Sheets, Maps, Contacts, Calendars, Email… I was using pretty much everything I could. All ‘free’.
So what did I do? I dove headfirst into the Apple ecosystem. I already had an iPad and a Macbook, and by the time I got the iPhone 14 I also got an Apple Watch. It made sense to me to switch to Apple services.
And yes, I’m sure Apple may also have their own track record of misusing user’s data. But I believe Google is in a league of their own. Nonetheless, Apple is still a tech giant, collecting plenty of user data, as anonymous as that may be.
So everything I was relying on Google for until that moment, I switched to Apple: Apple Photos, iCloud, Apple Maps, Contacts, Calendars and even email. As I subscribed to iCloud too, I was able to use my own domain name for email addresses, which was a nice addition! I even used Hide my Email! And then wrote about the trap it really is.
But as Apple pushed the glass visual style thing, I got more and more disturbed and distracted by the interfaces I was interacting with on a daily basis. Both on the desktop, as well as mobile devices.
At some point in late 2025, I was looking for alternatives to macOS and found Omarchy—a Linux operating system by DHH. Shortly after, I placed my order of a Framework Desktop. I’m switching to Linux!
As you can imagine, all those Apple services I was using would be troublesome to rely on with a Linux computer. Although email, calendars and contacts still worked just fine with Betterbird, things like Apple Photos, Apple Maps and iCloud were now things in a browser, not native apps.
Especially iCloud was a pain to deal with. Because on macOS it’s so well integrated into the system that’s just seen as another folder. Nobody even thinks about it. But accessing my files on iCloud on Linux meant I had to browse through the folders in a browser, download files and then use them as I intended. There are ways to ‘integrate’ iCloud within Linux but I was unwilling to provide my Apple credentials to a third-party application.
As I relied more and more on Linux and got so used to it—I’m still using it today and never looked back—I noticed I would eventually have to switch everything once again. And the hardest part would be email… Not the client. The service!
A better alternative
At this point in my life I knew I wouldn’t want to go back to Google, that’s for sure. So besides Google and Apple, what else could I use? No, not Microsoft! I wanted to move away from tech giants entirely. I thought if I had to give some metadata or even place my entire digital life in the hands of a tech company, let it be a small one, not a giant.
And so I started looking around and found out about Migadu—not linking on purpose.
The content on their website felt too close to home, with several copy bits here and there that genuinely made me smile. That’s not common nowadays. I remember it saying it was the closest thing to self hosting email servers without all the hassle of actually doing it. I mean… For someone already self hosting a bunch of services at this point, that idea alone was a very strong point.
Besides, their whole pricing model was not based on domain or mailbox count, as plenty of email services do. It was based on storage and traffic. And both of them, according to the website, were soft limits. I liked the content on the website so much that I signed up and migrated some domains to it to test it out. Shortly after I even sent them an email offering my design/development services.
And to my surprise, they actually liked the idea! They wrote an agreement, we signed it, and in February 2026 I started collaborating with them.
At this point I had migrated a couple of my domains to their service. Actually, I started using a completely new approach to email where my personal email—still at Apple at this point, gladly—is only used for a few personal things, and the majority of websites, shops and services we usually need email for were now using email addresses on a new domain just for that purpose, hosted on Migadu.
So I’m both a user and a collaborator at the same time… I saw a mile away how this could be a bad idea once I got myself into it. But I didn’t quite know what to do at the time. I mean, switching email services right after being ‘hired’ would be odd, to say the least.
A few months later, they terminated the agreement—and to put it mildly, we didn’t part on good terms. I was pissed! I saw this coming and still couldn’t avoid it. And I’m not talking about the termination, let’s be clear.
I’m going to write a whole blog post about that work experience alone. Believe me, there’s plenty to cover on that front.
So here I am once again, looking for a new email service. This time I’m more aware of what I want. Or perhaps, what I don’t want. Besides, I need to move fast. As I don’t want to keep my email domains on their servers for much longer.
Found something similar
MXroute—also not linking—had a very similar offering to what Migadu had, so I got naturally interested.
The first thing I did was signing up. And for that, I used an email address from my ‘secondary’ domain. This is a .top domain, which is commonly linked to spam. But the thing is, I will rarely send emails from that domain. It’s for receiving >95% of the time. And so far, every time I signed up with an email from this domain, I got zero issues.
This time though, their ‘anti-fraud’ system stopped me and asked me for government-issued ID. Note that their terms of service didn’t mention identification card a single time. For all I knew, there was no requirement—and really shouldn’t be!—for a service like this to ask for my government-issued ID card. But apparently this was a thing triggered by Stripe, their payment processor, not them.
So I reached out to the support team at MXroute, which is also not as easy to do as it should be for someone in this limbo of being signed up but not yet a client.
Remember that at this point I’ve signed up but I couldn’t even pay them, I got stopped when picking a product.
Support took days to get back to me. Naturally, as I’m not a paying user, I’m going to be the last of their priorities. I went back and forth with the support agent, because they wanted me to create a new account, but that one was already using the email address I wanted to use in the first place, until the CEO himself replied. And what he said is worth quoting:
I am not willing to provide information that allows people to bypass our fraud prevention systems. I understand if you don’t like how it works. I’m willing to accept the loss of business from that.
The thing I regret the most? Wasting days waiting for their replies.
What I believe happened: a combination of using a .top email address, an IP of a VPN provider and perhaps something else, was enough for the ‘anti-fraud’ system to be suspicious. That’s all fine. What’s not understandable is that even when an actual person attempts to solve it by reaching out to them to go past it without actually providing private information, such as photo and government-issued card number, they outright refuse to accept that such a system could make a mistake in the first place.
And of course they are in their own right to refuse providing service to whoever they decide. I just wished they had either written in the terms that one might get asked for an ID card or outright ban users that are flagged by this system.
This ambiguity only allows for both parties to waste their time on something that will never end well.
Actual self hosting email
I’m not the best at reading between the lines, but when the signs are this obvious, I can read them. At this point, it felt like the universe wanted me to take care of my own email servers. It was either the universe or myself. Not quite sure.
But this time was different. As I mentioned before, hosting email servers is not the same thing as hosting something like your Immich server. And the first road block is very close to home. It’s your ISP, actually. Apparently, even if you wanted, most ISPs nowadays block port 25, which is the one used for the SMTP protocol. The one used to send out emails.
So it makes it hard to host your email servers at home, when your internet service provider doesn’t even allow traffic on the port you would need to send out emails.
Some ISPs also block inbound ports. Which outright denies any possibility of hosting your email servers on something like a closet laptop.
If you want to self host email, but your ISP only allows for inbound traffic, you may rely on a third-party service, if you’re willing to, such as SMTP2GO to send out emails—their free tier is very generous.
You still host your actual emails, but rely on a third-party service to send.
Besides, most ISPs also don’t allow you to have a static IP address, or the ones that do may charge plenty for it.
If I can’t host my email servers at home, where can I host them?
Third party servers
At this point I started looking for companies that offered VPS services—Virtual Private Server—that I could use to host my email servers. And there are mainly 2 things worth mentioning from my findings.
1: Some VPS providers also block ports
Some providers, like Hetzner, block those ports by default, but you can request an unblock—after a month or so as a paying customer—and they’ll open them up for you.
Others outright say they are blocked and there’s nothing you can do about it. Which invalidates the use I needed for this VPS.
And others, like Netcup—the provider I’m using—have those ports blocked by default, but are user managed. Meaning, you go into your VPS settings and unblock them. Done. How it should be.
2: KYC is everywhere nowadays
Then there’s KYC… If you don’t know what KYC is, that’s exactly where I was just a few weeks ago. It means Know Your Customer. It’s some bullshit enforced on users, usually from banks, that mandate you as a user to provide them with government-issued identification.
A VPS can be as cheap as 7 EUR nowadays. You are basically renting a computer for a specific amount of time. That requires identification.
But you can go into a store and buy a computer forever without providing an ID. And you can also buy a pocket knife without providing an ID. But apparently renting a VPS is considered dangerous to the point of companies having to collect their users’ private data. And we all know how well they handle it.
I wouldn’t be surprised if at some point this KYC thing is spread throughout every single internet service. But so far, Netcup didn’t ask me for anything they didn’t need to provide me service.
The current setup
So I got myself a VPS at Netcup with Debian installed out of the box. They emailed me the credentials to connect to it via SSH. The first thing I did was to change the credentials. Then I created a new user for me and deactivated the default one. That’s your first layer of security.
Then I disabled SSH over the internet, installed cloudflared, and configured Cloudflare Access to only allow my email address to receive OTP codes. Only the subdomains/ports/services needed are exposed.
The flow is something like this:
sshinto my vps;- Browser window opens with Cloudflare Access;
- I input my email address (only this one is able to receive OTP codes);
- I go to that email address and find the OTP code;
- Input it in the browser window and authenticate;
- Terminal window accepts the auth and lands me in the VPS;
Basically, the only way in is through that Cloudflare Tunnel. And the only person who has access to it is me. This happens both for ssh as well as for the admin panel.
Speaking of admin panel, instead of installing and configuring multiple services like dovecot, rspamd, etc, as one usually does when self hosting their email servers, I decided to install Stalwart instead. I had first heard about Stalwart in a video by Side of Burritos on YouTube, not long ago.
This is a relatively recent project, as far as I can tell, but it already got the attention (and I think money too) from Mozilla.
If it’s good enough for Mozilla, it’s probably good enough for me.
At this point the sharper among you may be wondering: if you’re going to self host your email servers, and depend on an email arriving in your inbox to get access into your VPS, isn’t it like a dog chasing its own tail?
It is! And that’s exactly the only reason why I have also signed up for Tuta. Another email service.
They don’t ask for any personal information, which makes it extremely compelling to sign up to. They also don’t provide standard IMAP/SMTP server endpoints for you to use on your favorite email app, so there’s that. Just like Proton, for the most part.
For me, I use it solely to get OTP codes from Cloudflare. I don’t need to have it in my email app. Nor do I need to send emails from it. It’s just a safety net that I know I can count on.
And if for some odd reason I need to access my VPS and Tuta is failing, I can always log into Cloudflare’s dashboard and include another email address (like the old Gmail one) to allow temporary access through it too.
And, if all hell breaks loose, Netcup has this thing they call “SCP rescue system” that allows me to boot into a rescue image where I can ssh into my mail server VPS without the tunnel.
I think I’m covered on that front.
So far, I’ve been using Stalwart for a few weeks only. I already migrated all my domains to it. All my mailboxes. Everything email is running on that VPS. If that VPS burns, I have no email service. That’s how committed I am to it. The experience has been excellent.
And since I also wanted to spin up a Radicale server to self host my calendars and contacts, I’m also using Stalwart’s capabilities to do it. Worked like a charm!
Just as I was writing this blog post, I had a greylisting incident. Yesterday my wife had forwarded an email to me, and today Google (yes, she uses Gmail) sent her a notification saying they couldn’t deliver that email to me.
452 4.2.2 greylisted, please try again in a few moments.
This was on me. I had configured greylisting’s duration to just 5 minutes. And apparently services like Gmail retry on an exponential backoff—roughly 15 minutes, then 30, then 60—and keep trying over the next couple of days. I just had to extend this duration and ask her to retry. I got the email after another delivery. And a few hours later I also got the first one that Google couldn’t deliver.
Misconfigurations can lead to undelivered email. When you self host, you are the user, the support team and engineer too. If you can’t afford this, I suggest you find an email service you can trust instead.
Own your email address
I wrote about this topic before. I have said it once and I’ll say it again:
If you don’t own the domain name of your email address, you don’t own your email address.
If it ends in @gmail.com or @icloud.com or @outlook.com or @some-other-service.com you don’t own it!
This means you can be denied service at any time, or the product can be killed and you will lose access to your emails. Are you prepared for it? Would you be able to do your life normally if you didn’t have access to your Google/Apple/Microsoft account?
The solution is simple! Find yourself a domain name, which can be as cheap as a few euros per year for a .com domain. Then find an email service you can trust—definitely not Migadu or MXroute for me, but your mileage may vary—that allows you to use your own domain name.
Create your very first [email protected]. And that’s it! That’s your email address. You can switch email providers in the future. But that address remains the same. Nobody can take that away from you. Providing you keep paying for the domain, that is.
Keep an offline archive
I had this as a plan for a few years but haven’t gotten to implement it—and it’s fairly easy to do so—until recently when I completely migrated away from Apple.
Because of the fact that most people don’t own their email addresses, they stay within the same email provider for years and years. As you can imagine, this generates a huge amount of email exchange over time. Thousands and thousands of emails can be exchanged over the course of just a few years. And most people might not even be aware of how many emails they are hosting on these third-party providers.
Of course we all get newsletters and emails we never asked for and are not directed to us. But we also get a lot of emails with personal information, shopping habits, hotel reservations, flights, OTP codes, bills, etc, etc. That’s a lot of personal information to trust on a single entity. Even if that was anonymous—which it isn’t—it would be fairly easy to create a persona out of it. That’s valuable information nowadays.
Ever wondered why TVs are getting cheaper? Data! While every other electronic device gets more and more expensive, TV prices have been plummeting over the years. When TV manufacturers can harvest your data by looking at what you watch on your TV through a technology called ACR—Automatic Content Recognition—they can feed you targeted ads, sell your data to whoever wants it as many times as they can. Why would they care about the TV itself? The TV is not the product anymore. You are!
What I do is I keep most of my emails as an offline archive. I have a self hosted dovecot instance that I connect to from my home LAN only, where I keep the emails from all my accounts from previous years. This way I can connect to it from an email client, which enables me to search over the archive while deliberately denying access from the outside world so they are safe and sound.
The reason is simple: I rarely need access to emails from previous years. Sometimes I do. And that’s what the archive access is for. But not all the time. And especially not in the hands of a tech giant.
Emails are just text files
Did you know that an email is really just a text file? Headers, content and attachments, all in a text file. This makes it extremely easy to store and transport emails.
But there’s a quite obvious downside, especially in the age of AI.
Text is really easy to inspect and parse. Unless… they are encrypted!
And this is exactly what I did on my new email setup. For all this time I wasn’t even aware that emails could be encrypted. And let me be clear here, because there are two kinds of possible encryption for email: at rest and in transit.
Encryption in transit is quite common. It basically means that server A encrypts before sending to server B. That’s what SSL is for. While your emails are being transported—say by a mail man—they are protected from prying eyes. But then when the emails land on server B they are decrypted and stored in plain text.
This would be the equivalent of a mail man carrying letters from storage facility A to storage facility B in envelopes that obfuscate the contents, but then when depositing them in facility B, unwrapping them and completely exposing their contents to whoever comes along. Would that make any sense to you? Because that’s exactly what happens with email. For most people anyway.
To avoid this, you need to enable encryption at rest. It keeps the envelope around the content while resting. As it should.
This works by generating a pair of private and public keys. The server encrypts the messages with the public key and your email client decrypts them with the private key. This effectively makes your emails impossible to read for anyone else who doesn’t have access to your private key. And you should take good care of it, as if it’s the key to your home. You lose it, you’re in trouble.
So even if you can’t or don’t want to self host your email servers, do yourself a favor and enable encryption at rest. And then make sure your email client supports decrypting it. For instance, I use an OpenPGP key. Betterbird (the email client I use on Linux) does support it. Mail on iOS/iPad OS doesn’t. Which means that even if I wanted, I wouldn’t be able to read my emails on the phone or tablet. That’s fine by me. But your mileage may vary.
Avoid proprietary protocols
Protocols such as SMTP and IMAP have been around for years. The whole email infrastructure around the world has been based on them. These are protocols you use when you connect to your email provider using an email client, such as Mail on iOS. They allow you to receive and send emails.
But there are services, such as Tuta or Proton that don’t expose SMTP/IMAP servers. Apparently Proton does have a bridge app so that your email client connects to a local server that only acts as a bridge to the actual Proton servers. But this bridge only exists for desktops. Your phones and tablets are out. See what I mean? You are locked in.
You should not build your email infrastructure around proprietary protocols. Those will make it hard for you to migrate away from in the future, in case you want to.
Open and standard protocols are the way to go. Something most email clients can work with makes it extremely easy to migrate between providers. That’s your freedom. You should be able to use any email client you want. You should be free to use any email provider you want. The emails are yours. The addresses are yours. The domain is yours. They provide the infrastructure. That’s it.
Keep a backup at hand
Privacy and freedom are one thing. But something else you should not overlook is redundancy. That email archive I mentioned above is not a backup. That’s an archive! And I do want to backup my archive. Otherwise I risk having a failing NAS overnight and wake up to no emails at all in the archive.
I talked about my backup strategy in great length in another post.
To put it shortly, I have an on-site 10 TB drive I keep at hand and to which I backup all important data in my NAS. Then I have an off-site array of 4 TB drives to which I connect via Cloudflare Tunnel and send only the most important data. That’s the data I would never want to live without. That data is fully encrypted. Both in transit and at rest. To the point where if someone got physical access to this disk, they would get absolutely nothing but a paperweight.
Summing up
After spending years hosting my emails at Google and then at Apple, I migrated to a small tech company that ended up being far from ideal. I tried one last small company that denied me service. Got fed up and decided to rent a VPS, install Stalwart and run my own email servers.
If you want something done right, you gotta do it yourself.
Now my emails are fully encrypted at rest and in transit. I also keep an archive of my emails from previous years which is only accessible at home, via a dovecot instance running on my NAS. Besides, I also keep an onsite copy of that archive, as well as an off-site one. Fully encrypted.
I take good care of my encryption and SSH keys nowadays. As I depend on them more and more for multiple digital services in my life. Encrypted data is data tech companies can’t use. Let’s keep it that way.