Hi everyone,
I do understand, that by today it's bordering on insanity to spin your own, but please bear with me: if you set up and run your own mailserver - how do you go about securing it in terms of credential stuffing and all that stuff that is going around the internet?
I'd expect some multi factor authentication in the available IMAP and SMTP servers, but so far my research has brought up zero, zip, zilch, nada.
Has email become such an unusual thing to run yourself or am I missing some obvious alternative to secure account access? There are open source options for running OAuth2 (i.e. Keycloak) and they work great. Are we missing an IMAP and SMTP server that properly support modern authentication protocols? Are they so difficult to implement that none have dared to do it yet?
Would love to hear what you think and if you have any recommendations?
thanks!
I do understand, that by today it's bordering on insanity to spin your own, but please bear with me: if you set up and run your own mailserver - how do you go about securing it in terms of credential stuffing and all that stuff that is going around the internet?
I'd expect some multi factor authentication in the available IMAP and SMTP servers, but so far my research has brought up zero, zip, zilch, nada.
Has email become such an unusual thing to run yourself or am I missing some obvious alternative to secure account access? There are open source options for running OAuth2 (i.e. Keycloak) and they work great. Are we missing an IMAP and SMTP server that properly support modern authentication protocols? Are they so difficult to implement that none have dared to do it yet?
Would love to hear what you think and if you have any recommendations?
thanks!