Chiming in late on this interesting thread. I recently had an adjacent
use case and while my solution is not complete yet, it is in a workable
condition.
On 2026-09-22 12:25, patpro--- via Postfix-users wrote:
On 22/09/2026 10:09, Gary R. Schmidt via Postfix-users wrote:
I use SMTP2Go <https://www.smtp2go.com/>
Looking at their plan, they start with a free plan for 1000 emails per
month, rate-limited to 200/day. Are humans expected to read such
quantities? the industry is crazy! I want an SMTP milter that counts
the words in an email, send the sender a payment request, and responds
with a 5xx to senders that are not on my very restrictive allowlist or
pay $1/10 words. If I could, I would charge a $50 extra for each SMS
(interruptions!).
I’m not willing (yet) to let a company handle my SMTP traffic.
define "your" traffic. at some point, a message is handed over from
sender (or their service provider) to recipient (or their service
provider). I can control what I send, so I am not worried about using a
third-party to handle deliverability, and I am happy with
<https://mxroute.com/>. I cannot control what my (law office) clients
send to me, so I try to control the pipeline as early as possible to
protect from further disclosure and that means operating the MX server
and doing the receiving without third-party. That is the natural
faultline that I see, and it does not make sense to fight against the
windmills.
Until last year, my email infrastructure was similar to Patrick's: a
self-hosted Postfix somewhere on the internet. Subject to the typical
flurry of attempted unauthorized logins. Saved by some simple
credentials hygiene. But we all know that security by obscurity is a
bad idea. The re-architecture earlier this year was driven by the
expected (and indeed started) increase of AI-enabled exploits. Faster,
larger, but are they smarter?
I decided to align faultlines with the most defendable moats I can find
in the landscape. The result is still a work in progress, but so far I
am happy with the current status that is certainly better defendable
than the previous one.
Two Incus containers, Alpine Linux, two Postfix instances. One
external, out in the wild (I adopted Wietse's terminology: bastion), and
one internal, protected.
THE BASTION
- is disposable. a script builds it and deploys it. the script is
still a hack. TODO: clean it up
- accepts mail from the internet (port 25) with basic/simple filtering
including the alphabet soup (no content inspection)
- adds in the header its spam score with details (rspamd) and an ARC
signature before forwarding
- forward/exfiltrate the message asap, transport over wireguard tunnel
to the internal server, to limit interception opportunities
- SSH connection also behind wireguard tunnel
- for now, it has access to distribution (Alpine Linux) packages over
the internet, but I am considering blocking everything except SMTP in,
SMTP out via wireguard, and SSH. that would require the destroy/deploy
cycle to be a viable form of keeping it updated and not just a defense
mechanism against exploits
- no mailboxes (nothing to harvest)
- no sending of emails. currently very crude (port 25 out blocked).
TODO: decide if I want to selectively allow feedback out; but I am
inclined to leave the sender in the dark and avoid all sort of backscatter.
- TODO: tripwired to self-destruct at the first trace of attack.
purpose: neutralize the speed and frequency of AI-augmented attacks and
prevent them from using the node as a jumping board
- TODO: secure the mail domains with DNSSEC. the goal is to be able to
signal to senders when the bastion has been compromised and prevent them
from sending further messages.
THE INTERNAL INSTANCE
- is protected by traditional perimeter protection
- looks much like a traditional (pre-AI-era) deployment, hardened
- relays SMTP out via third-party "deliverability service" (MXroute)
- hosts the mailboxes
- user access is either from within the perimeter, or (mobile) via
wireguard VPN that is also used to access all other intranet services
- performs computational intensive content inspection, including
AI-driven analysis, and quarantine suspected incoming messages
- does DKIM signature for my domains (I explicitly do not want to give
control of my private keys to a third-party service)
There are still a lot of TODOs, including better management/maintenance
of hard filtering at the bastion's firewall, but for now the system is
up and running in production, I am happy with the current state, and
further development is on the backburner as I have other priorities. My
previous system evolved over time and in more than two decades has
withstood the waves and tides of sewage that have progressively taken
over the internet. I do not know how far the current AIcelleration will
go. I expect that I will need to dedicate more attention to this much
earlier than I did on previous iterations.
--
Yuv, Ontario-licensed lawyer
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]