Mail infrastructure
The stack behind synthe.se: DNSSEC, DANE, DKIM, backups that restore, monitored around the clock. The proof behind the hosting offer.
- Role
- Architecture, deployment, operation
- Period
- 2026
- Stack
- Stalwart, Caddy, DNSSEC, DANE, OpenPGP, vykar, Hora

The brief
I offer hosting, and my own mail runs on the infrastructure I sell. In August 2026, I left Proton for a server I operate myself, with four requirements: the same security, good deliverability, encryption at rest and reproducible deployment.
The server now handles synthe.se and a few other domains, and scores 100% on the internet.nl email test.
In use
The server receives, sends and stores the mail of each domain, accessible over IMAP, JMAP and webmail.
Authenticity: strict SPF, DMARC in reject mode, and two DKIM signatures per message, in Ed25519 and in RSA. The keys change every 90 days, with a week of overlap.
Transport: MTA-STS enforces encryption, and DANE publishes the fingerprint of the server’s key in DNS, signed with DNSSEC. A sending server that validates DNSSEC then accepts only this certificate.
Confidentiality: on an account encrypted at rest, each message is encrypted with its owner’s OpenPGP key before being written to disk, right after spam analysis. WKD publishes this key so that mail clients find it automatically.
Architecture
Everything runs on a dedicated server under Debian. Stalwart listens directly on the mail ports, with its own TLS. A Caddy instance serves the rest: admin, client autoconfiguration, MTA-STS policy, WKD keys, webmail, status page and this site.
Caddy renews the certificates while keeping the same private key, and each renewal is copied into Stalwart: the TLSA records stay valid. A second TLSA record designates a standby key kept offline, already known to remote servers in case of an urgent change.
Every night, Stalwart is paused for about one second, the time it takes to copy its storage. vykar encrypts this copy, deduplicates it and sends it offsite.
Numbered Bash scripts deploy and verify the whole setup from a workstation, and can be rerun at will.
Decisions
Native binaries for mail. In rootless mode, Docker masks the real address of incoming connections. SPF, blocklists and rate limits depend on it: Stalwart and Caddy run under systemd.
A single MX. During an outage, sending servers keep the mail in their queue and retry for several days. A backup MX mostly attracts spammers, who target the least protected server.
A single web front end. On 18 August 2026, Caddy replaced nginx and certbot: a single certificate system, a single configuration, and HTTP/3 for the site.
Every guarantee monitored. Two Hora instances, in two networks, monitor the ports, the certificates, the pinned DNS records and the blocklists. They compare the published TLSA record with the real key every 30 minutes and test a full send and receive round trip.
Every incident adds a probe. In September, after a container engine update, a backup cycle was skipped: the latest copy was 33 hours old when monitoring flagged it. A probe now reads the backup log and confirms each cycle.
Today
The server handles my mail, synthe.se’s mail and the site’s contact form. Each update takes a snapshot, verifies the new binary, replaces it and reverts to the previous version on failure.