Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. As someone in infosec, how do you handle your personal email?

As someone in infosec, how do you handle your personal email?

Scheduled Pinned Locked Moved Uncategorized
infosecemailprivacyselfhostedencryption
11 Posts 7 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B This user is from outside of this forum
    B This user is from outside of this forum
    bobbricoleur@infosec.exchange
    wrote last edited by
    #1

    As someone in infosec, how do you handle your personal email?

    I got tired of Gmail reading everything, so I built a self-hosted
    alternative with:
    - X25519 + AES-256-GCM encryption
    - Postfix/Dovecot on a French VPS
    - SPF/DKIM/DMARC + fail2ban
    - An AI cockpit that classifies urgent vs noise

    Curious what setups other infosec people use. ProtonMail?
    Self-hosted? Something else?

    #infosec #email #privacy #selfhosted #encryption

    4fd485@mastodon.social4 B mrfoostang@foostang.xyzM plaimbock@fosstodon.orgP noplasticshower@infosec.exchangeN 7 Replies Last reply
    0
    • B bobbricoleur@infosec.exchange

      As someone in infosec, how do you handle your personal email?

      I got tired of Gmail reading everything, so I built a self-hosted
      alternative with:
      - X25519 + AES-256-GCM encryption
      - Postfix/Dovecot on a French VPS
      - SPF/DKIM/DMARC + fail2ban
      - An AI cockpit that classifies urgent vs noise

      Curious what setups other infosec people use. ProtonMail?
      Self-hosted? Something else?

      #infosec #email #privacy #selfhosted #encryption

      4fd485@mastodon.social4 This user is from outside of this forum
      4fd485@mastodon.social4 This user is from outside of this forum
      4fd485@mastodon.social
      wrote last edited by
      #2

      @bobbricoleur
      I use tuta mail

      1 Reply Last reply
      1
      0
      • B bobbricoleur@infosec.exchange

        As someone in infosec, how do you handle your personal email?

        I got tired of Gmail reading everything, so I built a self-hosted
        alternative with:
        - X25519 + AES-256-GCM encryption
        - Postfix/Dovecot on a French VPS
        - SPF/DKIM/DMARC + fail2ban
        - An AI cockpit that classifies urgent vs noise

        Curious what setups other infosec people use. ProtonMail?
        Self-hosted? Something else?

        #infosec #email #privacy #selfhosted #encryption

        B This user is from outside of this forum
        B This user is from outside of this forum
        bobbricoleur@infosec.exchange
        wrote last edited by
        #3

        I'm using standard email solution right now, and want to see if there is good alternative ?

        1 Reply Last reply
        0
        • B bobbricoleur@infosec.exchange

          As someone in infosec, how do you handle your personal email?

          I got tired of Gmail reading everything, so I built a self-hosted
          alternative with:
          - X25519 + AES-256-GCM encryption
          - Postfix/Dovecot on a French VPS
          - SPF/DKIM/DMARC + fail2ban
          - An AI cockpit that classifies urgent vs noise

          Curious what setups other infosec people use. ProtonMail?
          Self-hosted? Something else?

          #infosec #email #privacy #selfhosted #encryption

          mrfoostang@foostang.xyzM This user is from outside of this forum
          mrfoostang@foostang.xyzM This user is from outside of this forum
          mrfoostang@foostang.xyz
          wrote last edited by
          #4
          @bobbricoleur@infosec.exchange @relay@relay.infosec.exchange I ran a #WildDuck server for a while. I had to use an smtp relay to send because non-ISP source servers tend to score higher on spam filters even with DKIM, SPF and DMARC in place, so it became a game of diminishing returns.

          When I got tired of that I just went to Proton like a normie.
          1 Reply Last reply
          0
          • B bobbricoleur@infosec.exchange

            As someone in infosec, how do you handle your personal email?

            I got tired of Gmail reading everything, so I built a self-hosted
            alternative with:
            - X25519 + AES-256-GCM encryption
            - Postfix/Dovecot on a French VPS
            - SPF/DKIM/DMARC + fail2ban
            - An AI cockpit that classifies urgent vs noise

            Curious what setups other infosec people use. ProtonMail?
            Self-hosted? Something else?

            #infosec #email #privacy #selfhosted #encryption

            plaimbock@fosstodon.orgP This user is from outside of this forum
            plaimbock@fosstodon.orgP This user is from outside of this forum
            plaimbock@fosstodon.org
            wrote last edited by
            #5

            @bobbricoleur I use proton because AFAICT dovecot 2.4.3 still has TLS/LDAP issues. When that is resolved I'll probably return to self-hosting. What do you use for SPF, DMARC and DKIM?

            1 Reply Last reply
            0
            • B bobbricoleur@infosec.exchange

              As someone in infosec, how do you handle your personal email?

              I got tired of Gmail reading everything, so I built a self-hosted
              alternative with:
              - X25519 + AES-256-GCM encryption
              - Postfix/Dovecot on a French VPS
              - SPF/DKIM/DMARC + fail2ban
              - An AI cockpit that classifies urgent vs noise

              Curious what setups other infosec people use. ProtonMail?
              Self-hosted? Something else?

              #infosec #email #privacy #selfhosted #encryption

              noplasticshower@infosec.exchangeN This user is from outside of this forum
              noplasticshower@infosec.exchangeN This user is from outside of this forum
              noplasticshower@infosec.exchange
              wrote last edited by
              #6

              @bobbricoleur proton mail

              B 1 Reply Last reply
              0
              • B bobbricoleur@infosec.exchange

                As someone in infosec, how do you handle your personal email?

                I got tired of Gmail reading everything, so I built a self-hosted
                alternative with:
                - X25519 + AES-256-GCM encryption
                - Postfix/Dovecot on a French VPS
                - SPF/DKIM/DMARC + fail2ban
                - An AI cockpit that classifies urgent vs noise

                Curious what setups other infosec people use. ProtonMail?
                Self-hosted? Something else?

                #infosec #email #privacy #selfhosted #encryption

                prometheus@infosec.exchangeP This user is from outside of this forum
                prometheus@infosec.exchangeP This user is from outside of this forum
                prometheus@infosec.exchange
                wrote last edited by
                #7

                @bobbricoleur proton with my own domain. I love all the services that proton has. It works well from my Graphene OS phone without Google Play. The calendar, Simlelogin,and the email services are my daily goto's. Minus Lumo+, which I signed up for and now have abandoned for multiple reasons.

                B 1 Reply Last reply
                0
                • B bobbricoleur@infosec.exchange

                  As someone in infosec, how do you handle your personal email?

                  I got tired of Gmail reading everything, so I built a self-hosted
                  alternative with:
                  - X25519 + AES-256-GCM encryption
                  - Postfix/Dovecot on a French VPS
                  - SPF/DKIM/DMARC + fail2ban
                  - An AI cockpit that classifies urgent vs noise

                  Curious what setups other infosec people use. ProtonMail?
                  Self-hosted? Something else?

                  #infosec #email #privacy #selfhosted #encryption

                  H This user is from outside of this forum
                  H This user is from outside of this forum
                  hotarubiko@infosec.exchange
                  wrote last edited by
                  #8

                  @bobbricoleur Self-hosting is always preferred. It is a lot of work. Many mail services still pre-emptively block self-hosting for spam despite spammers not doing self-hosting. It is too easy to add self-hosting to blocklists and some people do this automatically and without cause. Once on it is difficult to get off. Most mail services do collect and retain mail messages. Tuta and proton say they do not retain mail. Tuta and Proton encrypt mail at rest but they possess the keys. Proton may only allow entprise accounts to use smtp. Tuta seems to allow only imaps.

                  Ymmv.

                  Bonne chance.

                  B 1 Reply Last reply
                  0
                  • prometheus@infosec.exchangeP prometheus@infosec.exchange

                    @bobbricoleur proton with my own domain. I love all the services that proton has. It works well from my Graphene OS phone without Google Play. The calendar, Simlelogin,and the email services are my daily goto's. Minus Lumo+, which I signed up for and now have abandoned for multiple reasons.

                    B This user is from outside of this forum
                    B This user is from outside of this forum
                    bobbricoleur@infosec.exchange
                    wrote last edited by
                    #9

                    @Prometheus nice to know, any other similar services you know ?

                    1 Reply Last reply
                    0
                    • H hotarubiko@infosec.exchange

                      @bobbricoleur Self-hosting is always preferred. It is a lot of work. Many mail services still pre-emptively block self-hosting for spam despite spammers not doing self-hosting. It is too easy to add self-hosting to blocklists and some people do this automatically and without cause. Once on it is difficult to get off. Most mail services do collect and retain mail messages. Tuta and proton say they do not retain mail. Tuta and Proton encrypt mail at rest but they possess the keys. Proton may only allow entprise accounts to use smtp. Tuta seems to allow only imaps.

                      Ymmv.

                      Bonne chance.

                      B This user is from outside of this forum
                      B This user is from outside of this forum
                      bobbricoleur@infosec.exchange
                      wrote last edited by
                      #10

                      @hotarubiko thanks a lot for this view , very interesting. so basically Proton, provide you the key that they also have in their server ?

                      1 Reply Last reply
                      0
                      • noplasticshower@infosec.exchangeN noplasticshower@infosec.exchange

                        @bobbricoleur proton mail

                        B This user is from outside of this forum
                        B This user is from outside of this forum
                        bobbricoleur@infosec.exchange
                        wrote last edited by
                        #11

                        @noplasticshower I self-host with Dovecot 2.3 + Postfix on a VPS.
                        No issues with TLS so far — using Let's Encrypt with SNI for multiple domains.

                        SPF/DKIM/DMARC all set up with hard fail. Deliverability has been surprisingly good.

                        Honestly the hardest part was getting the PTR record right with the hosting provider. Once that matched, everything was ok.

                        What TLS issues are you seeing on 2.4? Curious before I upgrade.

                        1 Reply Last reply
                        1
                        0
                        • R relay@relay.infosec.exchange shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups