home tags events about login
one honk maybe more

benjojo posted 10 Jun 2025 11:12 +0000

I would like to congratulate google for creating the most perfect phishing email (clicking the button asks for auth on the most powerful account in the org) while also not using any of the counter measures (BMI etc etc) that they tell other people to use to defend against phishing emails

We found some security gaps for your organization Review the latest issues we found below. Take action now to better protect your organization, with just a few clicks. Review & take action 	In just a week, Workspace orgs like yours detected 149K+ phishing emails with enhanced security

benjojo replied 10 Jun 2025 11:22 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/X47fK25q96qvK3zn3Y

The whole situation is really frustrating because all I really want is a competent email provider that isn't going to get squashed by microsoft and other deliverability issues, but my alternatives are microsoft ( who I genuinely believe is just as bad as google in this circumstance ) or fastmail who i've never really got the vibe of confidence from.

Self hosting email seems really unattractive here as well, because while doing that for my personal email is totally fine, doing it it away that is reliable enough of my business is a real pain in the ass...

benjojo replied 10 Jun 2025 11:46 +0000
in reply to: https://helvede.net/users/m/statuses/114658819502402755

@m This actually looks pretty good, It seems to be hosted in OVH, and I would really hope it isnt sending out of OVH... but I can handle the outbound part at worst.

Could you send me a email migadu-test@b621.net so I can see what their stack looks like?

benjojo replied 10 Jun 2025 11:33 +0000
in reply to: https://mystical.garden/users/fionafokus/statuses/114658825399288519

@fionafokus I think I can get away with dealing with sending email at worst, bgp.tools already sends 1k+ emails a day without any obvious issues (with an exception of hotmail/msn addresses), but it's the "where do I put the inbox" that won't get RCE'd/breached/DDoS'd, and without being on my infra so I can email customers when I am down, and ideally is in Europe (I'm trying to get to "USA zero" with the exception of stripe)

Such a annoying landscape

benjojo replied 10 Jun 2025 11:41 +0000
in reply to: https://hails.org/users/hailey/statuses/114658827966488427

@hailey To be fair the UK isnt any better with regards to iffy legal natsec laws. But fastmail have just always felt..iffy.

Any time I've poked into their state of affairs technically I've come back with a "oh uh, yeah that's not that great"

I'm sure they (probably) wont lose my mbox to someone else, but will they stay up during "bad times", I'm less sure.

Even their DDoS stuff I can instantly spotted a hole in their cloudflare magic transit deployment, they ran for years without even basic defence of their blocks against hijacks. Urgh

I just really worry how much of Fastmail is just good looks vs actual competency.

jYM2WhWLbBrwhTt175.png

eval@glauca.space replied 10 Jun 2025 12:18 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/Mw4J1BFvmwJs4WWmXZ

@benjojo @hailey oh, yikes.
Tbh I‘ve stuck with fastmail for a while as they seem to be the best I’ve seen at making the email Actually Just Work, despite their issues (US mail hosting, etc.), and dealing with Google or MS365 again is a hellish prospect.
But I would love to see someone come and do it better. (Props to Migadu for being a decent tiny option, my non profit org is with them, but not quite feature complete for my personal use.)

benjojo replied 10 Jun 2025 11:25 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/N9575PbmDhwW3bsGyz

Like, I recognize that I am moving in a direction which is probably not the same direction that most of the business world is (generally disliking the clouds and having product shoved down my throat that I don't want to use)

But it's really quite depressing that there is no "productivity suite" offering that is European and inspires confidence in their competency

Wifiwits@infosec.exc.. replied 10 Jun 2025 11:42 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/Yml6cpMqP3lKK22VJ9

@benjojo I’ve a surprisingly good run with self hosting on linode/Akamai but.. it isn’t business and I don’t risk losing income if I have deliverability issues. I’m planning to move to hosting in house and ditching Akamai but expect I’ll need to use a trusted SMTP gateway to maintain deliverability. All that said there was a period of a couple of weeks when MS was blocking SMTP from most Linode subnets. The interesting thing was they didn’t seem to know why it was happening. Some automated system had done it and none of the folk a mere mortal can interact with seemed able to do anything about it. It simultaneously forces you to use one of the big providers whilst swearing never to use one of the big providers.

29821632@noc.social replied 10 Jun 2025 11:36 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/N9575PbmDhwW3bsGyz

@benjojo Self-hosting my e-mail for a quarter of a century(!) trying every combination of software and platform you can think of. Zimbra for a while was probably the best UI experience but needed a chunky VM. Multiple disappointments with Squirrelmail and Round cube etc too.
And despite all that I still ended up part-using Gmail due to Android's integrated calendar+contact sync which landed me in split-brain e-mail hell for a long time... 1/

29821632@noc.social replied 10 Jun 2025 11:44 +0000
in reply to: https://noc.social/users/29821632/statuses/114658860474276877

@benjojo
About 6 years ago I moved to Fastmail and could not recommend them more!
Handles my sub-domain wildcard addressing perfectly too. (Every shop/login/sign-up I have made in 20+ years got a unique e-mail address, leading to some unbelievable observations of customer database exploitation and brokerage!).
Only criticism is that storage is probably quite stingy when compared to say an O365 small biz account at roughly the same price but I don't tend to store/archive much mail so 🤷
2/2

rweir@mastodon.socia.. replied 10 Jun 2025 11:38 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/N9575PbmDhwW3bsGyz

@benjojo fwiw anecdata, I moved from Google Apps to Fastmail twoish ago and am very happy with it - it just works, they put a lot of care into everything from the webmail client to the live updating DNS instructions to the per-account-email-alias integration with 1Password to JMAP, no deliverability issues I’ve noticed and anti-spam is approximately as good as gmail.

Major downside is they have fewer lawyers fighting subpoenas than Google, and being in Australian/US legal jurisdiction.