• I have wasted weeks to months of time on postfix + dovecot, SSL, non-DUL IPs, spam, etc.

          • 14 days

            Oy, letsencrypt with dns challenge and nsupdate have me automated on the SSL side, proxy for spam, all I care about is the first two now. Yeah, not an easy task, but paying for a spam proxy took 90% of maintenance away.

            • Well the really hard thing about SSL is sni maps, at least when working the first time with it and trying to debug it (especially with Thunderbird desktop which still wrongfully reports an invalid certificate 50% of the time. Click on refresh and it suddenly says it’s okie-dokie)

              • 13 days

                Thankfully we only give two possible endpoints on two different addresses for all our domains … this is good to know because I was thinking about using SANs as well. Thanks for the warning!