2-08 / Series
2-08 № 08 · 2026

Put the mailbox
on your own side.

Outside Exchange and Outlook — the inbox on your side, sending yourself when the conditions hold

Mail is the record of the business itself. Correspondence, contracts, history — all of it piles up there. By now the foundation, the gate, the code, and the documents are on your own side. This chapter takes back the inbox those records flow into every day. Receiving is easy; sending has conditions. Write the conditions down first, then stand it up.

Take control of the inbox back to your own side

Stand up Stalwart on one machine

The mail server is Stalwart. A Rust single server carries SMTP, IMAP, JMAP, spam defense, and DKIM signing. It is a replacement for Exchange. Storage can be pointed at the PostgreSQL from 2-03. The machine it stands up on is the one handed to the AI in 2-02.

The official install script sets up the binary (/usr/local/bin/stalwart), the configuration (/etc/stalwart), the data (/var/lib/stalwart), a dedicated stalwart user, and the systemd unit. As 2-02 decided, no Docker.

curl --proto '=https' --tlsv1.2 -sSf https://get.stalw.art/install.sh -o install.sh
sudo sh install.sh                 # the official installer; runs as a systemd service

In the admin UI, create the domain and the mailboxes. No code is written.

Get the DNS right — MX, SPF, DKIM, DMARC

With mail, the DNS is the real body of the work, more than the server. Set these four correctly.

example.com.      MX    10 mail.example.com.
example.com.      TXT   "v=spf1 mx -all"
default._domainkey.example.com.  TXT  "v=DKIM1; k=rsa; p=...(generated by Stalwart)"
_dmarc.example.com.  TXT  "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

The reverse record (PTR) is what the receiving server uses to check the sender's IP. On a fixed-IP line the provider has already set it, so there is nothing for you to do (2-02).

Send it yourself when the conditions hold — the relay is the fallback

When you send from your own server, the receiving server asks whether the sender can be trusted. It looks at four things, and when all four hold, you can send yourself.

When they hold, sending stays on your side too. Even then, a recipient's server may decide not to accept. This is not about OSS being inferior; it is the reality of how mail works. When a recipient cannot be reached, borrow an authenticated SMTP relay (a send-only service) for outbound sending only. What you borrow is deliverability; the inbox stays on your side.

The inbox on your side. Sending yourself, when the conditions hold. When a recipient cannot be reached, borrow the sending alone — stand it up with the line drawn.

Read and write with Thunderbird

Reading and writing work with any client that speaks IMAP. Thunderbird is free and runs the same on Windows, Mac, and Linux. Phones connect with the stock mail app over IMAP. The JMAP that Stalwart speaks is for the tools you write yourself (2-12).

Leave the current server as it is

No migration procedure is needed. New mail is received by Stalwart. Past mail stays inside the current server and is handled there. Thunderbird opens several accounts side by side, so when you look back, you see both there. Microsoft 365 and Gmail both open in Thunderbird (both sign in with OAuth2; Microsoft Learn and Mozilla's support pages, checked 2026-10-05).

Point the MX at Stalwart once receiving has been confirmed (2-12). When the old server is cancelled, drag only the folders worth keeping across to the new side in Thunderbird.

Retention and safety are a few lines of rules

Mail retention needs no dedicated archive product. All the mail already sits in the 2-03 PostgreSQL, and it is already inside the 2-01 rule "protect the data and the spec." How many years to keep is one line in the business-rules Markdown. That is the entire retention spec.

The safety side is one line too. Never open executable attachments. Spam is handled by Stalwart's built-in filter. For a suspicious mail, have the AI read the body before any attachment is opened, as input to your judgment.

How to check you are done

This chapter is done when these five hold.

  1. A mail sent from an outside address, such as Gmail, to your own domain can be read in Thunderbird
  2. A mail sent from Thunderbird to an outside address lands in that person's inbox (not in spam)
  3. Through ssh, you can log in to the admin UI and see the domain and mailboxes you created
  4. Queried from outside, all five records answer: MX, SPF, DKIM, DMARC, PTR
  5. In Thunderbird, both the old server's account and Stalwart's sit side by side
systemctl status stalwart                      # running under systemd
dig +short MX example.com                      # the MX answers
dig +short TXT default._domainkey.example.com  # the DKIM key answers
dig +short -x <the server's IP>                # the reverse record (PTR) answers

What the human holds

Values the human supplies

Actions the AI states before performing

Versions checked, and when

Summary

The inbox, on your own side.

The next chapter stands up meetings and calendars (Jitsi, Radicale), bringing Teams and calendar sharing to our own side.


Related articles