Running your own mail server in Australia without the spam headache
Hosting your own email feels like a relic from another decade, yet a quiet community of Australians still runs Postfix on a Raspberry Pi in Brisbane, a virtual machine in a Sydney data centre, or a rented VPS in Frankfurt. The reasons vary. Some want to keep correspondence outside the reach of the large platforms that mine messages for advertising. Others simply enjoy the technical puzzle. A few run private servers because they handle sensitive client data and would rather know exactly which machine touches each message. Whatever the motivation, the modern landscape of spam filtering is hostile to newcomers, and an unconfigured mail server can have its outbound mail rejected by Gmail within hours.
The Australian context adds its own wrinkles. Local anti-spam rules under the Spam Act 2003 carry real financial penalties, so misconfigured relays are not just an inconvenience. Internet routing often hops through Singapore or Los Angeles, which means your server's IP reputation depends on neighbours you never chose. And Australian privacy expectations, shaped by the Privacy Act and the Australian Privacy Principles, push many readers toward hosting locally rather than trusting free overseas services with their mail archives.
The good news is that running a clean server is achievable with deliberate setup. The process is mostly about doing the boring things correctly: picking an IP with a clean history, publishing the right DNS records, signing every message, and treating your outbound queue like a fragile reputation asset rather than a firehose.
Choosing hosting, IPs, and reverse DNS
The single biggest decision is the IP address that will send your mail. Residential Australian connections, including most NBN plans from Telstra, TPG, or Aussie Broadband, sit on dynamic ranges that are routinely blocked by major providers. The Spamhaus Policy Block List, for example, has historically listed entire Australian residential ranges used by malware. Running a mail server from a home address in Perth or Hobart is almost guaranteed to fail.
A small virtual private server from a provider that offers dedicated addresses is the practical middle ground. Look for hosts that allow you to set the reverse DNS (PTR) record yourself, or that will set it on request. The PTR record should resolve back to a hostname that itself resolves forward to the IP, a configuration known as forward-confirmed reverse DNS. Major receivers like Microsoft and Yahoo quietly penalise mail that fails this check. Many readers first encounter this trade-off while weighing free cloud storage against the privacy cost of convenience, and email sits in the same category: the cheap option comes with strings.
If you can, choose a provider with a presence in Australian data centres, or at least one that publishes clear information about how outbound port 25 is handled. Some hosts route all SMTP traffic through smart relays regardless of your settings, which can interfere with DKIM signing. A Sydney or Melbourne location keeps latency low for local recipients and means troubleshooting happens during business hours rather than at 3 a.m.
DNS itself deserves attention. Pick a registrar that lets you edit TXT records quickly and supports DNSSEC. For .au domains, auDA requires accurate registration data, which becomes useful if you ever need to prove ownership of a hostname like mail.yourname.com.au during a deliverability investigation.
Authenticating every message with SPF, DKIM, and DMARC
Once the infrastructure is in place, the next layer is proving to receiving servers that your mail is genuinely yours. Three DNS records do almost all of the heavy lifting, and each addresses a different problem that spammers exploit.
Sender Policy Framework, or SPF, is a TXT record listing every host authorised to send mail for your domain. A typical entry for a single-server setup looks like "v=spf1 ip4:203.0.113.42 -all", with the hard fail telling receivers to reject anything coming from other sources. Soft fail (~all) is more forgiving and worth using during the first few weeks while you confirm nothing legitimate is being filtered.
DomainKeys Identified Mail (DKIM) signs each outgoing message with a private key, while the matching public key lives in another TXT record at a selector subdomain. Receivers verify the signature against the published key, which proves the message was not altered in transit and that the sender controls the domain in the From header. Without DKIM, Gmail and Outlook are far more aggressive about flagging mail as suspicious, particularly when the sending IP has limited history.
DMARC ties SPF and DKIM together. It tells receivers what to do when a message fails alignment: quarantine it, reject it, or simply report it. Start with p=none and study the aggregate reports sent to the address in the rua tag. After a month of clean data, tighten to p=quarantine, then to p=reject once you are confident nothing legitimate is being lost. This staged rollout is what separates a smooth launch from a flood of bounced messages.
Hardening Postfix and Dovecot against open relay abuse
The software stack itself needs careful configuration. Postfix handles outbound SMTP for most self-hosters, and Dovecot handles IMAP and POP3 retrieval. Both have safe defaults in modern distributions, but a single misplaced setting can turn your server into an open relay that spammers discover within minutes.
Disable unauthenticated relay from foreign networks. Postfix's smtpd_relay_restrictions should require authentication for any destination outside mynetworks, which by default includes only localhost and your private subnet. Authentication itself should run on a submission port such as 587 with STARTTLS, never on port 25, which is reserved for server-to-server traffic. Dovecot can authenticate the same users through its auth-sql backend, so passwords never sit in plain text files.
TLS is non-negotiable for both submission and the server-to-server channel. Let's Encrypt certificates are widely accepted by receivers and renew automatically. Force TLS version 1.2 as a minimum and prefer modern cipher suites. Some legacy Australian corporate networks still pass through old mail gateways that only support TLS 1.0, and you will need to weigh compatibility against the security cost; for personal mail, dropping legacy support is usually the right call.
Rate limiting deserves a mention. Postfix's anvil and smtpd_client_message_rate_limit can throttle outbound volume from a single client, which protects you if a script on your own machine starts looping. The same tools prevent a compromised account from being used to blast tens of thousands of messages overnight, which would burn your IP reputation and possibly attract attention under the Spam Act.
Warming up the IP and protecting reputation
A new IP address has no reputation, which receivers treat as suspicious rather than neutral. Warming up means sending small volumes of legitimate mail at first, then gradually increasing. A practical schedule begins with around fifty messages per day to your own accounts at Gmail, Outlook, and Fastmail, mixed with a few trusted correspondents. After two weeks, double the volume. After a month, you can handle typical personal traffic of a few hundred messages per day without triggering filters.
List hygiene matters more than most newcomers realise. Every address you send to should be one that has explicitly opted in, even if you collected it years ago at a conference in Sydney. Hard bounces within the first hour should result in the address being suppressed. Spam complaints are even more damaging: a complaint rate above 0.3 percent will get a fresh IP listed by major feedback providers.
Some self-hosters rely on third-party SMTP relays like Mailgun or Amazon SES for the first few months while the IP warms up, then switch to direct delivery. This hybrid approach is useful if you send transactional mail from applications, since those systems tend to have unpredictable volumes that can spook filters. Anyone running payment-linked services such as PayPal-based casino games will recognise the flood of account-related messages that follows a real signup, which is exactly the burst pattern that lands fresh IPs on a blocklist.
Consider monitoring services such as Mail-Tester, MXToolbox, and the Postmaster Tools offered by Google and Microsoft. A score below 9 out of 10 on Mail-Tester usually indicates a configuration problem you can fix in minutes. Postmaster Tools takes longer to provide useful data, but it shows the actual spam rate that large providers see from your IP, which is the closest thing to ground truth available to an individual operator.
Maintaining habits that keep mail flowing
Even with perfect setup, blocks will happen. The question is how quickly you can diagnose them. When a recipient on Telstra's Bigpond webmail service reports that your messages vanish, check the SMTP logs first. Postfix writes a line for every message it accepts, queues, and delivers, including any deferred status with explanation. A response of "554 5.7.1 Service unavailable; Client host blocked" usually means your IP is on a blocklist, which you can look up directly.
If a blocklist adds you, most operators provide a removal form. Some require a small fee, others are free. Be cautious about delisting services that email you out of the blue claiming you are listed; many are scams targeting self-hosters who panic. The trusted lists, including Spamhaus and Spamcop, have transparent policies and clear removal procedures.
Complaint handling under Australian law deserves its own paragraph. The Spam Act requires that every commercial electronic message include an unsubscribe mechanism, and ignoring unsubscribe requests can result in penalties exceeding one million dollars for individuals. Even non-commercial mail sent in bulk, such as a newsletter for a local football club in Adelaide, falls under the law. Build the unsubscribe path into your mailing workflow from day one.
Schedule a monthly maintenance window. Renew TLS certificates, check DKIM and DMARC alignment against a fresh Mail-Tester report, review Postfix logs for unusual source addresses, and confirm that backup snapshots still run. The discipline of successful self-hosters tends to look unglamorous, but it is what separates a server that delivers mail reliably for years from one that quietly breaks during a long weekend.
A practical first step is to spin up a small VPS with a dedicated IP this weekend, install Postfix and Dovecot with the configurations above, and send your first ten signed messages to a Gmail address you control so you can see the full authentication chain in the original message view before adding any real recipients.