<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[As someone in infosec, how do you handle your personal email?]]></title><description><![CDATA[<p>As someone in infosec, how do you handle your personal email?      <br />                                                               <br />  I got tired of Gmail reading everything, so I built a self-hosted  <br />  alternative with:                                                  <br />  - X25519 + AES-256-GCM encryption                                  <br />  - Postfix/Dovecot on a French VPS                                  <br />  - SPF/DKIM/DMARC + fail2ban                                        <br />  - An AI cockpit that classifies urgent vs noise                    <br />                                                                     <br />  Curious what setups other infosec people use. ProtonMail?          <br />  Self-hosted? Something else?                                       <br />                                                                     <br />  <a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/email" rel="tag">#<span>email</span></a> <a href="https://infosec.exchange/tags/privacy" rel="tag">#<span>privacy</span></a> <a href="https://infosec.exchange/tags/selfhosted" rel="tag">#<span>selfhosted</span></a> <a href="https://infosec.exchange/tags/encryption" rel="tag">#<span>encryption</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/51a3c25b-9d23-4a32-b9d2-39f0ab2021d9/as-someone-in-infosec-how-do-you-handle-your-personal-email</link><generator>RSS for Node</generator><lastBuildDate>Mon, 06 Apr 2026 05:02:38 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/51a3c25b-9d23-4a32-b9d2-39f0ab2021d9.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 04 Apr 2026 16:09:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 17:18:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/noplasticshower%40infosec.exchange">@<span>noplasticshower</span></a></span>  I self-host with Dovecot 2.3 + Postfix on a VPS.<br />No  issues with TLS so far — using Let's Encrypt with SNI for multiple domains.                                                  <br />                                                                     <br />SPF/DKIM/DMARC all set up with hard fail. Deliverability has been surprisingly good.<br />               <br />Honestly the hardest part was getting the PTR record right with the hosting provider. Once that matched, everything was ok.<br />                                                                     <br /> What TLS issues are you seeing on 2.4? Curious before I upgrade.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347576955901446</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347576955901446</guid><dc:creator><![CDATA[bobbricoleur@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 17:18:54 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 17:13:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/hotarubiko%40infosec.exchange">@<span>hotarubiko</span></a></span> thanks a lot for this view , very interesting. so basically Proton, provide you the key that they also have in their server ?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347555464908751</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347555464908751</guid><dc:creator><![CDATA[bobbricoleur@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 17:13:26 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 17:09:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/prometheus%40infosec.exchange">@<span>Prometheus</span></a></span> nice to know, any other similar services you know ?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347540885209684</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347540885209684</guid><dc:creator><![CDATA[bobbricoleur@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 17:09:44 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 17:08:11 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@bobbricoleur">@<span>bobbricoleur</span></a></span> Self-hosting is always preferred. It is a lot of work. Many mail services still pre-emptively block self-hosting for spam despite spammers not doing self-hosting. It is too easy to add self-hosting to blocklists and some people do this automatically and without cause. Once on it is difficult to get off. Most mail services do collect and retain mail messages. Tuta and proton say they do not retain mail. Tuta and Proton encrypt mail at rest but they possess the keys. Proton may only allow entprise accounts to use smtp. Tuta seems to allow only imaps. </p><p>Ymmv. </p><p>Bonne chance.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/hotarubiko/statuses/116347534805238508</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/hotarubiko/statuses/116347534805238508</guid><dc:creator><![CDATA[hotarubiko@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 17:08:11 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 16:44:08 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@bobbricoleur">@<span>bobbricoleur</span></a></span> proton with my own domain. I love all the services that proton has. It works well from my Graphene OS phone without Google Play. The calendar, Simlelogin,and the email services are my daily goto's. Minus  Lumo+, which I signed up for and now have abandoned for multiple reasons.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Prometheus/statuses/116347440212235575</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Prometheus/statuses/116347440212235575</guid><dc:creator><![CDATA[prometheus@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 16:44:08 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 16:26:28 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@bobbricoleur">@<span>bobbricoleur</span></a></span> proton mail</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/noplasticshower/statuses/116347370738465293</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/noplasticshower/statuses/116347370738465293</guid><dc:creator><![CDATA[noplasticshower@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 16:26:28 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 16:18:12 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@bobbricoleur">@<span>bobbricoleur</span></a></span> I use proton because AFAICT dovecot 2.4.3 still has TLS/LDAP issues. When that is resolved I'll probably return to self-hosting. What do you use for SPF, DMARC and DKIM?</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/plaimbock/statuses/116347338261329575</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/plaimbock/statuses/116347338261329575</guid><dc:creator><![CDATA[plaimbock@fosstodon.org]]></dc:creator><pubDate>Sat, 04 Apr 2026 16:18:12 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 16:15:44 GMT]]></title><description><![CDATA[<span><a href="https://infosec.exchange/ap/users/116347132620429381">@bobbricoleur@infosec.exchange</a></span> <span><a href="/user/relay%40relay.infosec.exchange">@relay@relay.infosec.exchange</a></span> I ran a <a href="https://foostang.xyz?t=wildduck" rel="tag">#WildDuck</a> server for a while. I had to use an smtp relay to send because non-ISP source servers tend to score higher on spam filters even with DKIM, SPF and DMARC in place, so it became a game of diminishing returns.<br /><br />When I got tired of that I just went to Proton like a normie.<br />]]></description><link>https://board.circlewithadot.net/post/https://foostang.xyz/mrfoostang/p/1775319344.023253</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://foostang.xyz/mrfoostang/p/1775319344.023253</guid><dc:creator><![CDATA[mrfoostang@foostang.xyz]]></dc:creator><pubDate>Sat, 04 Apr 2026 16:15:44 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 16:12:08 GMT]]></title><description><![CDATA[<p>I'm using standard email solution right now, and want to see if there is good alternative ?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347314410873222</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116347132620429381/statuses/116347314410873222</guid><dc:creator><![CDATA[bobbricoleur@infosec.exchange]]></dc:creator><pubDate>Sat, 04 Apr 2026 16:12:08 GMT</pubDate></item><item><title><![CDATA[Reply to As someone in infosec, how do you handle your personal email? on Sat, 04 Apr 2026 16:11:30 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@bobbricoleur">@<span>bobbricoleur</span></a></span> <br />I use tuta mail</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/4fd485/statuses/116347311926995568</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/4fd485/statuses/116347311926995568</guid><dc:creator><![CDATA[4fd485@mastodon.social]]></dc:creator><pubDate>Sat, 04 Apr 2026 16:11:30 GMT</pubDate></item></channel></rss>