September 23, 2026 at 07:17, "Mel P via Postfix-users" 
<[email protected] 
mailto:[email protected]?to=%22Mel%20P%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E
 > wrote:
 
> On 2026-09-21 11:02, Patrick Proniewski via Postfix-users wrote:

> > I think signing (DKIM, ARC) at home, then forwarding to a postfix
> >  instance on the VPS for public delivery, is not best practice.
> > 
> There's debate about this. I'm on the side of signing on the 
> originating server. Plus signing on the MX VPS means storing your 
> signing key on someone else's computer.

honestly, if signing at home before relaying through the VPS is not something 
that can impair my deliverability, I’ll go that way. Much simpler, so much more 
robust. And like you say, private key stay sake at home. 

It also mean I can start the warmup of VPS IP addresses right now by relaying 
few % of my current outbound email traffic through the VPS (from my current 
server at the datacenter).

 
> > I’m running FreeBSD. I’ve created a Jail with Wireguard client, a VPN
> >  tunnel between the Jail and the Wireguard server on the VPS, but I could
> >  not find a way to use that setup properly.
> > 
> FWIW, I do this with the TLS secure channel capabilities of Postfix 
> combined with certificate-based authentication, and separate inbound and 
> outbound transports.

I’m intriged. Can you elaborate on that?

Thanks,
patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to