September 23, 2026 at 07:17, "Mel P via Postfix-users" <[email protected] mailto:[email protected]?to=%22Mel%20P%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E > wrote: > On 2026-09-21 11:02, Patrick Proniewski via Postfix-users wrote:
> > I think signing (DKIM, ARC) at home, then forwarding to a postfix > > instance on the VPS for public delivery, is not best practice. > > > There's debate about this. I'm on the side of signing on the > originating server. Plus signing on the MX VPS means storing your > signing key on someone else's computer. honestly, if signing at home before relaying through the VPS is not something that can impair my deliverability, I’ll go that way. Much simpler, so much more robust. And like you say, private key stay sake at home. It also mean I can start the warmup of VPS IP addresses right now by relaying few % of my current outbound email traffic through the VPS (from my current server at the datacenter). > > I’m running FreeBSD. I’ve created a Jail with Wireguard client, a VPN > > tunnel between the Jail and the Wireguard server on the VPS, but I could > > not find a way to use that setup properly. > > > FWIW, I do this with the TLS secure channel capabilities of Postfix > combined with certificate-based authentication, and separate inbound and > outbound transports. I’m intriged. Can you elaborate on that? Thanks, patrick _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
