The Register Home Page

back to article Self-hosted email is in steep decline, Microsoft and Google are taking over

The number of large users hosting their own email servers has halved in the last decade, according to Artem Berezin, a researcher who works at business e-mail company Live Direct Marketing. On the Internet Society blog, Berezin explained that DNS records reveal a lot about email. “The MX record says where the mailbox lives. The …

  1. Nate Amsden Silver badge

    self hosting my email for 30 years

    My core configuration has changed just a tiny bit over the past two decades. Postfix(with tons of header filters I setup 20+ years ago), with Anomy Sanitizer (strips HTML from email, last updated 20 years ago), Cyrus IMAP, Spamassassin(last trained at least 17 years ago), a few RBLs, I have about 550 email addresses(unique per site/vendor/interaction), and generally hardly any spam. If an email address gets compromised in some way then I just kill the address. All my email is stored on a reiserfs v3 filesystem (efficient with lots of small files, not a memory hog like ZFS), though I know I'll have to migrate at some point.

    As far as who is self hosting email, how many of those office365 and gmail customers ran exchange on prem for themselves 10-15 years ago? I know MS used quite a bit of strong arm tactics during license audits to get people to move to office 365 in order to get less fines. I have always found it interesting/strange that so many former exchange admins how much they hated running Exchange(maybe it was/is that bad I don't know, I'm not much into windows stuff).

    Despite having all my DMARC/SPF/DKIM stuff set perfectly, and even a special google id thing (forgot the term), google still flags my email as spam unless the user puts me in their address book. Can only guess it's because my "reputation" is low since I send a low volume of mail despite my mail server/domains etc having existed for decades. oh well, not a huge deal.

    Not that I go out of my way to suggest others host their own mail, it has it's use cases, for me it pretty much runs itself. A few years ago I noticed that two of the RBLs I was using had been turned off 7-10 years prior, and other than errors in the mail log I never noticed/cared. I did migrate from Squirrelmail web mail to Roundcube 10+ years ago I think. The most annoying thing was going from Cyrus 1.x to 2.x maybe 15 years ago or something.

    1. DS999 Silver badge

      Use a relay service

      I use purelymail.com, they have a setup specifically for relay users and it is only $10/yr. They say that pricing plan will probably be going away and everyone will have to use the usage based model but I'm pretty sure I'd actually pay less with that since it is just my personal email. But I'll give them the $10 because that's still dirt cheap and they're worth it.

      That avoids the reputation issues of running a small server, but you still control your mail and it is still stored on your server. It just has an extra hop incoming and outgoing. Basically I set the MX to point to them and it is immediately relayed to my server. I point SPF at them and use sendmail SMART_HOST facility to deliver to them and they send it on. I still have DKIM set up on my end, so my DNS has records for both mine and theirs.

      I kept my own DMARC because I've always used 'p=none' and have very little spam so I saw no reason to change that. When I first went to them I had issues with too strong DMARC causing problems elsewhere (long story) so I went back to p=none and disabled DMARC enforcement in their settings as well and all is good.

      So I'm not sure about the claim made in the article that looking at where MX records etc. point to tells you who is hosting their own email. A lot of people probably become tired of fighting the reputational battles of seeing their email quarantined or put into spam folders. Some maybe gave up their own server, but some probably just relay through to someone bigger. No way to tell that simply from looking up DNS records, you'd have to check the headers of mail coming from them.

      1. Tom Chiverton 1

        Re: Use a relay service

        Purelymail are US based so a bit risky to use.

        Any similar EU service ?

        1. Anonymous Coward
          Anonymous Coward

          Re: Use a relay service

          Try some $5 dollar VPS in Iceland, Sweden, USA, China, Brazil as MX records. Use round-robin.

          1. doublelayer Silver badge

            Re: Use a relay service

            Those have bad IP reputation scores, and some servers will block mail based on those scores, and there's almost nothing you can do to get your address off those lists, even if you operate it for years. I can't even blame Microsoft/Google for that. They didn't help, but they didn't start, nor are they the most aggressive, blocking mail by wide IP ranges.

          2. MrReynolds2U

            Re: Use a relay service

            Most VPS services (on big and small providers) I've come across have outbound mail ports blocked. So you have to use a third-party service like SendGrid to send outbound email. Some have restrictions on bare metal too.

        2. Recluse

          Re: Use a relay service

          Try https://simplelogin.io/

          I believe they are now owned by Proton (of Proton Mail) so it's not going to come much better than that.

          I've given up hosting my own email and now point my domain to Proton Mail via Simple Login)

          As a bonus lf you are a Proton subscriber Simple Login is included within the whole package i.e no further fees to pay.

        3. DS999 Silver badge

          Re: Use a relay service

          I found purelymail by asking ChatGPT, I had never heard of it and might never have found it otherwise. It or one of its "siblings" probably could come up with something for you that's based in the EU beyond the reach of Trump's tiny bruised hand.

      2. Mark 124

        Re: Use a relay service

        I use mailgun for outbound relay. They have EU as well as US hosting, although CLOUD Act makes that basically irrelevant.

        You have to give them a credit card number, but at my volume they've never charged me a cent.

    2. A Non e-mouse Silver badge

      Re: self hosting my email for 30 years

      I have always found it interesting/strange that so many former exchange admins how much they hated running Exchange

      Exchange was a pig to run which is why Exchange admins were happy to give Microsoft the pain of running it. There aren't many features missing from Office 365 Exchange compared to the old on-premise Exchange so it's a no-brainer to move to Office 365. The migration from on-premise to cloud isn't too painful either - providing you've been feeding and watering your on-premise Exchange appropriately. The people who have the most pain are often the ones you never managed their Exchange but just left it running in the corner.

      1. Charlie Clark Silver badge

        Re: self hosting my email for 30 years

        And what about data and pricing sovereignty? Moving to Exchange online is simply asking for trouble.

    3. Lon24 Silver badge
      Flame

      Re: self hosting my email for 30 years

      We've only self hosted for about 15 years. Our mailservers are blacklist free (tested every week) and mostly still work fine EXCEPT for Hotmail + Outlook. Properly setup and spam free - Microsoft's servers are currently rejecting email from half of our mailservers. No rhyme or reason as to which half. I suspect Microsoft are using AI hallucinatory mail filters.

      We used to offer our email servers to clients. We've stop doing that because we can't promise delivery if it includes the large slice of the market owned by one entity to whom it is impossible commmunicate intelligently to identify issues. It really amounts to market abuse in the effective Google/Microsoft duopoly. It's if they were trying to drive us and others out of the market. Who'd have thought it?

      1. DS999 Silver badge

        In the past I would have said

        That any idea that Microsoft or Google were trying to push people off self hosting and into using their cloud email was ridiculous - email service is not a way to make lots of money.

        But in today's world where everyone who has ambitions of owning the AI world (like Microsoft and Google) will want everything human written they can find for training data. There is probably some opt out hidden deep within menus marked "beware of the leopard" to avoid that, or they'll claim it is OK because "anonymize" it first by removing all the headers and anything that looks like a name or address and think that gives them the right to use it.

        1. Charlie Clark Silver badge

          Re: In the past I would have said

          Lots of ISPs / service providers that used to run their own mail infrastructure starting switching to MS Exchange a couple of years ago. This isn't about the ARPU but upselling and lock-in.

        2. collinsl Silver badge

          Re: In the past I would have said

          Email hosting for customers was never about making money.

          Initially it was to lock your customer in to your services - "If you terminate your dialup line or broadband line with us then you'll lose your email address, and it'll be a pain to change it on all those websites and think of how many mails you'll miss from your relatives who don't understand it's changed!" etc.

          Google started offering it for data mining and advertising purposes, and now also include in that bracket AI training and selling datasets to other companies. That's where the real money is now. Remember, if something is free then you are the product.

      2. CrazyOldCatMan Silver badge

        Re: self hosting my email for 30 years

        mostly still work fine EXCEPT for Hotmail + Outlook

        This is another reason why I gave up self-hosting. Yahoo Mail (now Outlook?) also would randomly bounce stuff.

        No problems with our current hosting service.

    4. munnoch Silver badge

      Re: self hosting my email for 30 years

      Registered the family domain in 1995 and been self-hosting since. My hand-crafted sendmail config file has hardly changed over that time and I think I still understand it, just. I have a couple of cloud servers to act as slave DNS and lower priority MX but the main server lives in the garage and is neither a variant of x86 architecture nor running a variant of linux to make sure things aren't too easy! It really should also move to the cloud because the electricity usage is eye-watering, but then I would no longer have the single copy of everything on-prem (its rsynced to a couple of other places too). I see it as a bit of a badge of honour as someone who has been involved with software for virtually their whole life.

      Biggest issue for me recently has been getting iOS to accept the certificate that cyrus presents. It can't be self-signed any more (you have to install your own root certificate on all devices and sign with that), but you also need some funky alternate subject thing to make it happy. Took me a long time to get openssl set up to produce that. Issuing new certificates is scripted although I think the cron isn't working so I had to go in a few months back and do it manually. Given long enough I'll get around to fixing that.

    5. CrazyOldCatMan Silver badge

      Re: self hosting my email for 30 years

      I used to (hosted my family domain and a couple of others - include two for one of my brother's businesses).

      Gave it up a couple of years ago when it became too much hassle (oh look, the postfix service has stopped (again) and not restarted - so much for systemd!) and I got tired of my brother asking what was happening to his email..

      If it was just the family domain I might have stayed hosting it myself

      I still own the domains but they are now handled by one of the EU-based providers.

  2. Jou (Mxyzptlk) Silver badge

    Outsourced mail.

    I still don't like the dependency. It is where the world is going, but I still don't like it.

    All centralized at one vendor equals single point of failure, not in your hand. And mail ist just the "least important" part.

    1. TReko

      And a single point of vulnerability

      All Microsoft Exchange emails and mailboxes in the world could have been spied on and copied by (probably) Chinese hackers for years.

      1. sabroni Silver badge
        Mushroom

        Re: All Microsoft Exchange emails and mailboxes in the world could have been spied on

        I knew it!

        Fucking Microsoft's fault that email is shit!

        Those mother fuckers!!!!

        1. CrazyOldCatMan Silver badge

          Re: All Microsoft Exchange emails and mailboxes in the world could have been spied on

          I blame the move away from 7-bit ASCII to the HTML/JS-riddled abominations of today.

          1. Jou (Mxyzptlk) Silver badge

            Re: All Microsoft Exchange emails and mailboxes in the world could have been spied on

            What? You can blame HTML mail on Netscape 2.0 Mail from 1995, which made HTML mails more common. Microsoft just "followed the trend" with their own interpretation of "Rich Mail". (Who remembers WINMAIL.DAT ?)

    2. DS999 Silver badge

      Re: Outsourced mail.

      Unfortunately the internet, despite its original design by ARPA to be spread out with no single point of failure, keeps consolidating into bigger and bigger pieces that are a single point of failure. Most people depend on one of a few big tech companies for their email. All those mom and pop internet providers from the 90s got bought out and now even big players like Centurylink and Spectrum get bought out and consolidated. A small fiber provider in my town (not the one I use luckily) was acquired by T-Mobile recently. Instead of routing all over the place it is increasingly concentrated in major peering centers.

      All the web sites that aren't on AWS or Google/MS equivalents are signing up with Cloudflare, making them probably the biggest single point of failure there is. We've seen major outages at Cloudflare, at Microsoft, at AWS, and at Google over the past year or so. Those were accidents that didn't have a real cause other than some engineer "oopsing". What happens if they get hacked by a major nation state (perhaps with AI help) so there is an adversary deliberately working against them as they try to bring things up? They could be down for days...and a third of the internet with them.

      1. Anonymous Coward
        Anonymous Coward

        Re: Outsourced mail.

        You're conflating the Internet with certain services that run over the Internet. For sure, some services are consolidating and that's not good, but the Internet itself is not.

        1. collinsl Silver badge

          Re: Outsourced mail.

          I agree that you are technically correct, but to the average end user there is no functional difference. If they can't get to half their websites because Amazon broke their DNS, or they can't get their email from Outlook online because Azure won't let them log in they're not going to say "ah well, at least the transport network links are still working", they're going to say "I can't get to anything I want to, this is an awful experience".

          1. Anonymous Coward
            Anonymous Coward

            Re: Outsourced mail.

            Yes I know that. But it wasn't an "average end user" I was replying to.

            I was replying to DS999 who like everyone else here is not an "average end user".

        2. doublelayer Silver badge

          Re: Outsourced mail.

          I'm not sure they are. A lot of their comment considered routing infrastructure. In the area covered by that infrastructure, that is the internet. If everything routes through one exchange and it breaks, the entirety of the internet is cut off for that area. We could debate how much of the physical infrastructure is consolidating, as I have some anecdotes of it going the other way, but I think they did consider more than services.

          In the case of some services, it is fair to consider them substantial subsets of the internet. DNS, for example, is fundamental to so much that, even if routing works everywhere, if DNS failed, so much of what we use the internet for would also fail that it might be worth including. Again, we can still debate how much DNS has consolidated. They mentioned individual services and things that represent or affect the entire internet in their comment, so I don't think they conflated.

      2. Charlie Clark Silver badge

        Re: Outsourced mail.

        The consolidation is being driven by people putting convenience before independence.

  3. news.bot.5543

    > Google and Microsoft operate filters to detect messages they believe come from untrustworthy sources

    I gave my aunt a mail on my domain, and she ran into this issue, so I ended up setting her up with an Outlook mail as a backup.

    I don't send many emails, and half of them I don't generally see responses, so no idea if they ever got to the other side.

    It all really infuriates me.

    And, I always remember, back in the early days of Google mail... I often wondered why anybody would use GMail for a business account, when clearly they would be slurping up all your business data.

    1. Anonymous Coward
      Anonymous Coward

      Google and Microsoft operate filters to detect messages they believe come from untrustworthy sources.

      I have had issues with email sent (from a paid provider) to Google email addresses for the longest while, must be over seven years now.

      If I am lucky, it gets labelled as SPAM and the recipient can retrieve it.

      Otherwise it goes straight into the great big Google Black Hole never to be seen or heard of again.

      In both cases I am never notified that my email did not get through.

      Soon it will be Gmail or Gmail affiliates only.

      .

    2. LionelB Silver badge
      Flame

      This – absolutely infuriating.

      I've maintained several email addresses under my personal domain for over two decades now. I don't self-host email – ironically, I tend to use Gmail these days, redirect and alias my email addresses there, using their SMTP servers to send email. Over the past couple of years this is rapidly becoming unusable, since many messages I send are randomly (and usually silently) rejected; the worst offender being… Gmail. Even though my messages are sent via their own SMTP servers. For a steadily increasing number of recipients I end up having to use my actual Gmail address to be sure my mail gets through. This completely defeats one of the primary motivations for having email addresses under my domain, which is to maintain independence of the email host.

    3. Charlie Clark Silver badge

      Whenever I send e-mails to new contacts who have G-Mail accounts, they're always classified as Spam. :-(

      MS Exchange has default settings for new accounts that give priority to SPF over DKIM.

      People and companies choose "free" and "convenient" over "reliable".

  4. Pete 2 Silver badge

    Going down?

    > The number of self-hosted mail servers is falling fast

    Possibly reflecting the diminishing popularity and / or use of email in general. Except of course, for spamming, phishing and other undesirable activities

    1. Bebu sa Ware Silver badge
      Windows

      Re: Going down?

      > Possibly reflecting the diminishing popularity and / or use of email in general.

      And the lack of skill or knowledge of young system admins etc to set up a contemporary mail service. It's a fair amount of effort to put together and configure. Not as though you can buy a Linux cdrom with a "mail-in-a-box" turn-key installation.

      I noticed a fall off in organisational email use over my last 15 years or more — younger users were increasingly preferring verbal communication which, on the basis of the emails they were compelled to send, I attributed to their near illiteracy.

      Old buggers, happy in retirement prefer not to be communicated with so Google, Microsoft etc are welcome to feast on the e-shite you don't want to see anyway.

      Think the phrase is (consulting the cranky old geezer standard operating manual) "get off my lawn."

      1. Anonymous Coward
        Anonymous Coward

        Re: Going down?

        My children rarely use email: They mainly use WhatsApp & Snapchat.

        Me? 7-bit ASCII email all the way.

      2. CrazyOldCatMan Silver badge

        Re: Going down?

        Not as though you can buy a Linux cdrom with a "mail-in-a-box" turn-key installation

        There are several linux mailserver-inna-box packages available..

        All seem to come with the basic MTA (usually postfix), some sort of webmail and a control panel of some sort.

        Sadly, a lot of them are docker-infested abominations but not all.

    2. find users who cut cat tail

      Re: Going down?

      E-mail may be going down in popularity, but what is replacing it? E-mail

      a) is an open standard not owned by any specific entity – although barely, as the article points out.

      b) is text, possibly longer text, with structured thoughts and structured responses to different points.

      c) lasts ‘forever’ and can easily be searched. I commonly look up something in e-mail threads from 2009 about an obscure file format or other odd technical point.

      d) does not require instant attention (unless you make the mistake of enabling notifications for incoming messages). You get to that e-mail when you get to it.

      e) can be easily stored locally, even for off-line access.

      If you messages do not matter, you may not need these features. But if your messages do not matter, just do not bother sending them to me.

      1. Pete 2 Silver badge

        Re: Going down?

        > b) is text

        There is a certain type of individual who prefers the convenience (to themselves) of sending "stream of consciousness" voice messages. Some lasting many minutes. Some containing no useful / required / actionable content at all. Many of these messages will occupy all their recipients for some time, just to save the sender the effort of collecting their thoughts and writing them down.

        > c) lasts ‘forever’ and can easily be searched

        Many outfits engaged in litigation would view this as a definite vulnerability

        > d) does not require instant attention

        Given the short attention span / impatience of many workers (esp. those in "team" management) who expect and demand instant responses I can see why email falls from favour

        1. Charlie Clark Silver badge
          Thumb Down

          Re: Going down?

          Anecdotal bias – just because a few people are doing something, doesn't mean everyone is.

          Business communication must be archived for at least 5 years in many jurisdictions. One of the reasons why MS Teams chats are **not** deleted when you remove the account.

          And I've seen a resurgence in e-mail newsletters over the last few years as an attempt to retain attention.

          In addition, not everyone uses the same networks – I have about 5 but refuse to use WhatsApp. RCS is helping to fill the gap here.

      2. Tron Silver badge

        Re: Going down?

        I run a business via e-mail. What else would I use? Facebook messaging?

        Businesses use webmail services as they are pretty good at blocking scammers/dodgy attachments. Organisations have plenty of halfwits that will click on an attachment and let malware in. Webmail generally reduces this risk.

        E-mail has never been secure by default. If that is an issue for you (slurping/mil employee), you would be using additional encryption.

        E-mail works really well, and most of GAFA's attempts to bugger with it have failed.

        Best to have accounts on at least two webmail services in case one falls over. And use a client like Thunderbird to create a backup of your e-mail on your hard drive and on back up drives.

        Monopolistic ownership is always a potential issue, but e-mail is useful and generally works. It will outlast the AI bubble.

      3. A Non e-mouse Silver badge

        Re: Going down?

        c) lasts ‘forever’ and can easily be searched

        You've never run email in a corporate environment. The corporate rule of thumb is: If it doesn't exist you can't be asked for it and it can't be used against you.

    3. DS999 Silver badge

      I see very little spam

      I have never got a lot of it on my main internet account probably because I've kept a spam account on hotmail since its inception that I'd give when something seemed kinda shady - that gets tons of spam but I only have reason to check it a few times a year when I need to click on a verification email sent to it or whatever.

      But I see less these days than I ever have, or post dotcom at least. About the only thing I see now are a few times a week I get some invoice spam where they are trying to get me to pay to renew the subscription I don't have to Macafee or similar.

      It took a long time to get everyone on board but DKIM, SPF and DMARC really have made it a lot harder to send spam. Not impossible, to be sure, but the bar is higher which reduces the profit and increases their friction, so most of the spammers have moved on to different scams.

      1. tiggity Silver badge

        Re: I see very little spam

        "It took a long time to get everyone on board but DKIM, SPF and DMARC really have made it a lot harder to send spam."

        I stopped self hosting (personal email, not business stuff) a while ago, as even with (after much blood, sweat & tears as my day job is coding not mail setup) everything configured correctly I found (as others have mentioned on this thread) that the "big boys" such as Google & MS were treating my email as spam (best case) or not even delivering it (worst case). It does seem a deliberate policy to "extinguish" the small email providers. So I gave up & now use a third party for my personal email.

  5. Hubert Cumberdale Silver badge

    Use Tuta

    That is all.

    1. Anonymous Coward
      Anonymous Coward

      Re: Use Tuta

      Tuta?

      If the service is free, you are the product.

      .

      1. Hubert Cumberdale Silver badge

        Re: Use Tuta

        The service is not free. I pay for it.

        And there is very little way in which Tuta can make anyone a product when they have such strict privacy protections. Even on their free tier. It's freemium – simps like me are actually subsidising the people on the free tier, and Tuta benefits from the free tier due to exposure and word of mouth and the hope that people will upgrade. While I understand the instinct to scepticism that has been fed by the likes of Google and Microsoft, this is a normal business model, sans enshittification.

    2. Tom Chiverton 1

      Re: Use Tuta

      Doesn't appear to provide SMTP for outgoing? Or IMAP? So webmail only.

      Also costs a fair whack, 3 euro per user per month per domain?

      1. Hubert Cumberdale Silver badge

        Re: Use Tuta

        Yes. That's what email actually costs. That's why I am not the product. And no, you can't use those things with EEE email. That's just a fact.

  6. Sproggit Silver badge

    A Rare FOSS Foot-Gun Moment

    We're in the process of getting FTTP connected where I live, so in anticipation of being able to get a decent net connection, I decided to set up my own (currently experimental) mail server, with a domain that's not publicly registered but simply hosted in my own local DNS, in order to allow my local hardware to communicate via email...

    My setup consists of an 8Gb Raspberry Pi4B running the following software stack:-

    Raspberry PiOS v13, "Trixie"

    MariaDB v11.8.5

    Postfix v3.10.5

    Dovecot v2.4.1-4

    With the exception of Dovecot, I found setting up all of the above to be extraordinarily straightforward - I'd heard "tales of woe" and been warned off the attempt by several "hardcore tekkie" friends, but found all of this to be pretty good.

    Getting Dovecot to work, on the other hand, was quite a bit more complicated. In the end I resorted to using Anthropic Claude and the process still took more than two days to get right.

    A big part of the issue for me was that most of the online documentation I could find referenced Dovecot v2.3, which is *very* different from 2.4.

    But another part of the issue was the anecdotal evidence - claims in discussion threads, for instance - that Dovecot themselves had done this on purpose, in order to force commercial users of their product to take up paid subscriptions in order to maintain support (on the basis that 2.4 was *so* impenetrably complex, that commercial users would give up and pay for help).

    I don't know if this has been responsible for prompting existing self-hosted mail users to be provoked to jump ship and move to an externally-hosted service from one of the big players, but I would not be in the least bit surprised if that was the case. Certainly the timing seems to line up suspiciously well.

    What I can say - with certainty - is that there are simply no excuses for Dovecot when it comes to producing an understandable, supportable product. It's 2026 - and if you're capable of writing an MDA with the power and sophistication of Dovecot, then you're capable of writing it to be configurable by humans. I'm not a huge fan of Microsoft server-side products in general, but I set up Exchange Server 5.5 for the employer I worked for maybe *thirty* years ago - and it was orders of magnitude easier than getting Dovecot to work today. That's a major issue, right there.

    It's a rare exception in the FOSS software firmament - an extremely capable piece of technology made inaccessible by it's byzantine complexity and lack of useful configuration tools.

    Foot, meet gun.

    1. Goodwin Sands Bronze badge

      Re: A Rare FOSS Foot-Gun Moment

      I've a similar setup: Pi3B + fedora + sendmail + dovecot 2.3.9.2.

      Planned move to 2.4 now cancelled! Thank you for the forewarning.

      In return I'd encourage you to start sending & receiving external mail. It's very doable and allows for all sorts of customisations such as an alias file for outgoing mail.

    2. Justin Pasher

      Re: A Rare FOSS Foot-Gun Moment

      I run a similar software setup for publicly accessible email. I recently upgraded to Trixie, which involves upgrading Dovecot to 2.4.

      Yes, going from Dovecot 2.3 to 2.4 was a bit of a pain. It's wasn't difficult conceptually; the difficulty lied in getting every custom configuration mapped over properly to the new formats. Debian starts you out with a good template, but it still required little tweaks. The hardest part is knowing whether everything still properly worked after those changes were ported. I had to test in my own staging environment, and finally got everything working. Once I deployed, one thing still didn't work properly (and it affected accepting emails, so quite important).

      Which brings me to my main point. After all is said and done, the configuration of a self-hosted email system isn't terribly difficult (as long as you have a decent Linux skill set). Once that self-hosted system becomes public and is responsible for sending and receiving email to the world, THAT is where it takes a long time to master. Making sure every little thing is configured exactly how it should (SPF, DKIM, DMARC, FCrDNS, spam filtering, proper bounce handling, feedback loop participation, blacklist avoidance, etc) doesn't just come straight from a guide. It is a constantly evolving landscape to get and keep things working properly. No wonder more people don't want to deal with it.

  7. Furious Reg reader John

    Do these numbers add up to the headline?

    22.4% running their own server

    21.8% using Google Workspace

    16.8% using Microsoft 360

    The leaves 39% using some other mail as a service.

    That's nearly double Google's figures and well outstrips Microsoft. So on these numbers it's not just concentrated in the two "big ones" at all. It's interesting to see that more people are realising what a shit product 360 is compared to Workspace.

    UNLESS, that 39% are actually pointing to the additional security services (Mimecast, Proofpoint, etc) that you have to buy to bolster 360 or your own server (which are included in Workspace in some form)? That would actually make 360 have nearer half the market!

    And why on earth are one in five companies (maybe 1 in 4, if part of that 39% is actually ending up in a companies own server) wasting their time running an email system instead of just buying it as a service? I wonder if they are also wasting their time running DNS and CDN, both of which are again best bought as a service.

    1. gryphon

      Re: Do these numbers add up to the headline?

      Similar to my thoughts.

      I presume that a lot of self-hosted systems are 'hiding' behind external hygiene services like Mimecast, Symantec.Cloud and so on.

      Certainly my clients all run things that way.

      Really, anyone that has a mail server straight on the internet these days is just asking for trouble in one form or another.

      As to percentages using Exchange on-premises I expect that will continue to fall as MS force the switchover to Exchange SE.

      There are use cases for it, usually security related, but not very many and the user licensing isn't particularly cheap unless leveraging M365 licenses for the on-prem mailbox.

      Would still need to pay for the server licenses though.

      1. I could be a dog really Silver badge

        Re: Do these numbers add up to the headline?

        Really, anyone that has a mail server straight on the internet these days is just asking for trouble in one form or another.

        But if you don't run your own mailserver, direct to the internet for sending and receiving, then you are missing the primary reason for running your own mailserver - control and visibility. I set my inbound policies, I see the logs, I can see from the logs if something has been delivered*.

        * OK, "200 OK" doesn't mean it actually goes into a recipient's mailbox, but that's their problem for picking a s**t by design mail service like Google or Microsoft or ...

        1. Chloe Cresswell Silver badge

          Re: Do these numbers add up to the headline?

          Had this today for a client.

          Pay slip to one person isn't arriving.

          outlook.com address.

          Our logs show it all the way till outlook.com accepts it.

          1. I could be a dog really Silver badge
            Mushroom

            Re: Do these numbers add up to the headline?

            And when you point out that it was delivered to MS who didn't drop it in their mailbox - somehow it'll be your fault for not sending it right

    2. Clausewitz4.1 Bronze badge
      Devil

      Re: Do these numbers add up to the headline?

      If not using your own email servers, you are subject to censorship/sabotage from governments/competitors.

      The more competitive an industry is, bigger the chances of running a local email server.

      Using cloud providers, I saw a lot of emails to disappear or not arrive at all.

    3. doublelayer Silver badge

      Re: Do these numbers add up to the headline?

      "And why on earth are one in five companies (maybe 1 in 4, if part of that 39% is actually ending up in a companies own server) wasting their time running an email system instead of just buying it as a service?"

      Perhaps because the options to buy it as a service are often not great. A lot of the ones I've seen charge a lot per user per month, whereas a self-run system scales better. Not a big deal for a small number of users, not a big deal if you need some of the stuff that 365 or Workspace bring with it, but for email alone, the pricing can often be uncompetitive. By comparison, the cost of running versus renting a mail server is far different from a CDN or DNS. A CDN is much more expensive to build by yourself since you need geographic and network diversity. DNS is quite easy to build unless you're going for lots of redundancy, but it's very cheap to outsource and they already have lots of redundancy.

  8. Chloe Cresswell Silver badge

    Email SPF/DKIM/DMARC

    One thing that winds me up is how Google/etall say they require correct email service records to cut down on spam entering their servers and users mailboxes.

    But do sweet FA about the amount of spam flowing out of _their_ services.

    SPF/DKIM/DMARC does nothing when the spam is coming, DKIM signed, out of gmail.

    SPF? Match

    DKIM? Valid.

    DMARC: pass.

  9. original_rwg

    Come in to my parlour....

    Lets not forget how non-trivial Micros~1 made applying service packs to Exchange. Firstly, like all software products, it's got it's own vulnerabilities so service packs are important. If you're an organisation then e-mail is probably a very important service so applying the service packs had to become an out of hours task.

    If you were running Skype for Business, then you had to remove the language packs before applying the service pack. The service pack was invariably a complete re-install of Exchange server and typically took a long time - hence the OOH. Now you have to re-install the language packs for SfB and hope that when your Exchange box restarts that all the connectors you have set up are still there (I know of at least one occasion when one vanished).

    Now repeat the process on your other Exchange server(s) if you have them.

    Then there's the licencing costs but that's a whole other debate.

    So would Micros~1 keep moving the goal posts and 'incentivise' their customers into shifting their Exchange infrastructure to their cloud?

    1. JT_3K

      Re: Come in to my parlour....

      Everything Exchange was a hellscape. Whilst I was happy doing just about every task as a generalist IT lead, Exchange (bigger jobs) was the one thing I always brought in specialists to do it. Whether it was the time a new instance of 2007 refused to start until a combo of three disconnected Event Log items were found to link to a buried Technet demanding a specific negative 9 digit number (I remember it starting with -213) in a registry key; or the time a glowing-brain-type used ADSIEdit to tidy my AD from six previous Exchange installs or attempts before finally rolling out 2016 as part of a no-excuses technical-debt pay-down.

      My sole main memory of Exchange was that if you were doing something structural, there was no "undo", no "uninstall", no restoring a backup because it'd failed on a setting in AD and you couldn't roll your estate back. If an update failed, if a Service Pack didn't take, if the function turning something major on or off somehow missed a Registry or AD operation, you were screwed. Fat chance that the logs or Events would show the actual problem in an actionable way. Sure, if you lived and breathed nothing but, you ultimately got used to it and knew which rocks to turn over when this happened.

      I remember a fabulous Microsoft event called "Exchange Unplugged", towards the back end of the period in which Microsoft cared about supporting the pros. They brought out the real techhies, not the marketing goons. They stumbled a bit and were a little uncomfortable, but when they realised it was a supportive and engaged technical audience, they came to life. One of them explained in great length that the reason SQL 2012 clustering had gone through a generational leap in such a short period, is that they'd taken the clustering codebase to use for Exchange, fixed it through heavy rewrite, then returned working code to the SQL team.

      It was never accessible to the generalist though

  10. Anonymous Coward
    Anonymous Coward

    It has been all down hill into the cesspit since we abandoned Zimbra for Microsoft 364.85 years ago

  11. Anonymous Coward
    Anonymous Coward

    Simples

    Simple - stop writing to people with GMail.

    There. Problem solved.

  12. The Original Steve

    Stats are misleading

    I'd wager good money that considerably more mail / domains flow via through Office 365 AND Exchange on-prem configured in a hybrid.

    Migrating mailboxes off Exchange to Exchange Online requires a hybrid setup first normally. I suspect many have left an on-prem Exchange box for management, relaying and as a DR but punted their users to the cloud years ago. MX will still point to on-prem before firing up the cloud.

    Plus few Exchange on-prem customers are foolish enough to have an MX pointing directly to Exchange without a filter first!

  13. H_M

    Fastmail

    Personally, I used to self-host, but in the end it's really much easier to use a hosting provider given all of the SPF/DMARC and host-based blacklisting of residential/cloud IP ranges.

    I personally use fastmail.com as an independent provider - based in Australia but they offer the choice of hosting email in the USA or EU based on residency.

    1) I originally ran a mail/DNS server at home but this fails if your home server dies while you're on a two week holiday, plus persistent listing of home IP addresses in Spamhaus and similar IP blacklists

    2) Running a cloud server (e.g. Slicehost/Rackpace back in the day) solves one problem (outage when not home) but still suffers from cloud providers repeatedly on IP blacklists. Plus things like Squirrelmail can be slow

    3) So paying a few dollars per month to host a domain with a real provider is a lot less work in the end. IMHO at least

  14. Jou (Mxyzptlk) Silver badge

    fetchmail...

    I love the email hosts on prem, but the rest of it does not have to be. I still have a customer with is small number of mailboxes, which are polled via fetchmail from the provider. This very very VERY simple way to set up that exchange (still exchange 2013 BTW since customer ist stubborn, and I deny service since beginning this year). All this time the customer was effectively protected from so many possible issues and security holes...

    Lately I feel like this "very big step backward" should be done for much bigger installations as well. Just poll the mail, instead of getting it directly. Whether you use Fetchmail-Win (can be extracted from cygwin without needing full cygwin install), or one of those others is up to you :D.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon