> Viktor Dukhovni via Postfix-users <[email protected]>:
> On Wed, Sep 23, 2026 at 01:56:00PM +0200, Gerald Galster via Postfix-users 
> wrote:
> 
>>> Yes, the tunnel involves additional moving parts, with a Postfix secure
>>> channel you just need to ensure that each side knows the other's public
>>> key:
>> 
>> I disagree on the moving parts:
>> 
>> - it's static routing (once set up, you're good)
> 
> The TLS secure channel is equally static.
> 
>> - once the tunnel is up, it fails only when the underlying network fails,
>>  which would break TLS delivery too
> 
> Same, for TLS, but without the addtional requirement to configure
> WireGuard, and make sure that only Postfix SMTP traffic is forwarded
> via the tunnel.

We're talking about different setups:

Option 1)
Internet -> VPS data center (DNAT) -> wg tunnel -> local server -> jail 
(Postfix)

Option 2)
Internet -> VPS data center (Postfix) -> TLS/SMTP -> local server -> jail 
(Postfix)

I'm talking about Option 1 where the VPS merely routes traffic to a single 
Postfix
instance (a FreeBSD jail) on a local server behind a firewall.

You seem to refer to Option 2 which requires two Postfix instances — one on
the VPS and one on the local server — which is inherently more work to configure
and maintain than Option 1.

In this case Option 1 is the better solution because it needs just one Postfix
instance on a single server: everything - user management, antispam/antivirus,
blacklists, user access (submission/POP/IMAP) - lives on that one server.
There is no split setup where you have to configure antispam, blocklists, and
hostname checks on the VPS while user management, DKIM signing, spam filtering
for user submissions and data storage (IMAP/POP) live on the local server.
And since there's no IMAP/POP on the VPS anyway, the local server has to be
reachable regardless so users can access their mail.

Best regards,
Gerald
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to