Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In fairness, things like postfix usually ship with very poor (not to say “moronic”) defaults.

Like, postfix won’t even try to connect to tls-enabled smtp for outgoing email by default, and you have to explicitly point it at the certificate bundle it’s supposed to consider valid.

And you have to tell explicitly to reject incoming plaintext connections from the public internet.

And quite a bit more… Like, why doesn’t postfix have its own freaking spf/dkim implementation BUILT IN?



Are you referring to this? http://www.postfix.org/postconf.5.html#smtpd_tls_security_le...

" encrypt

Mandatory TLS encryption: announce STARTTLS support to remote SMTP clients, and require that clients use TLS encryption. According to RFC 2487 this MUST NOT be applied in case of a publicly-referenced SMTP server. Instead, this option should be used only on dedicated servers. "


There are so many mesolithic defaults in email software. So many things have to be constantly reinvented. I really wish it weren't like that.

Things like Maddy (https://maddy.email/) aim to simplify all this. Really great potential, but they're still work in progress.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: