<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Proton_mail on Side Of Burritos</title>
  <link rel="alternate" href="https://staging.sideofburritos.com/tags/proton_mail/" />
  <link rel="self" href="https://staging.sideofburritos.com/tags/proton_mail/index.xml" />
  <subtitle>Recent content in Proton_mail on Side Of Burritos</subtitle>
  <id>https://staging.sideofburritos.com/tags/proton_mail/</id>
  <generator uri="http://gohugo.io" version="0.165.0">Hugo</generator>
  <language>en-us</language>
  <updated>2026-08-30T13:45:00Z</updated>
  <author>
    <name>Josh</name>
    
  </author>
  
      <entry>
        <title>Why I left Proton Mail and Tuta for Stalwart</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/why-i-left-proton-mail-and-tuta-for-stalwart/" />
        <id>https://staging.sideofburritos.com/blog/why-i-left-proton-mail-and-tuta-for-stalwart/</id>
        <published>2026-08-30T13:45:00Z</published>
        <updated>2026-08-30T13:45:00Z</updated>
        <summary type="html">I&amp;#39;ve been paying for Proton Mail for nearly a decade. Recently, I switched to Tuta to test that out as well. But I always wanted to get back to self-hosting my own email server. Around 6 months ago, I came across Stalwart, and I knew I wanted to eventually switch to it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode125s0hbhb">🎥 


<a href="https://youtu.be/UGQVQaR6HhA" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://proton.me/" target="_blank" rel="noopener" class="text-break">https://proton.me/</a></li>
<li>


<a href="https://tuta.com/" target="_blank" rel="noopener" class="text-break">https://tuta.com/</a></li>
<li>


<a href="https://stalw.art/" target="_blank" rel="noopener" class="text-break">https://stalw.art/</a></li>
<li>


<a href="https://stalw.art/docs/email/management/masked-email/" target="_blank" rel="noopener" class="text-break">https://stalw.art/docs/email/management/masked-email/</a></li>
<li>


<a href="https://stalw.art/docs/install/upgrade/" target="_blank" rel="noopener" class="text-break">https://stalw.art/docs/install/upgrade/</a></li>
<li>


<a href="https://stalw.art/pricing/" target="_blank" rel="noopener" class="text-break">https://stalw.art/pricing/</a></li>
<li>


<a href="https://www.smtp2go.com/" target="_blank" rel="noopener" class="text-break">https://www.smtp2go.com/</a></li>
<li>


<a href="https://docs.hetzner.com/cloud/servers/faq/" target="_blank" rel="noopener" class="text-break">https://docs.hetzner.com/cloud/servers/faq/</a></li>
<li>


<a href="https://www.tb.pro/" target="_blank" rel="noopener" class="text-break">https://www.tb.pro/</a></li>
<li>


<a href="https://blog.thunderbird.net/2025/07/state-of-the-thunder-answering-community-questions/" target="_blank" rel="noopener" class="text-break">https://blog.thunderbird.net/2025/07/state-of-the-thunder-answering-community-questions/</a></li>
</ul>
<hr>


<p><details >
  <summary markdown="span">Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>I wanted to make a video on my updated email setup. For years I was using Proton and Tuda, but at this point I have migrated all my domains to a self-hosted instance of Stalwart.</p>
<p>I want to start off by giving some background on this decision and then some of the pros and cons of it. So while I have my complaints about both Proton and Tuda, in general I think they both provide a great service. It&rsquo;s also worth understanding my outlook on email is that it&rsquo;s not private at all. You&rsquo;re using one unique identifier to contact another unique identifier.</p>
<p>Yes, you can use PGP to encrypt the body of the message and sometimes the subject. You can also use things like aliases or simple login, which can improve your privacy a bit, but that also comes with its own complications. Like now you are stuck paying for a service since you don&rsquo;t have control over those aliases, which I got to give props to Proton on purchasing simple login. It makes it much more difficult to leave their service if you use that alias feature. So if you&hellip;</p>
<p>Even with my view on the privacy of email communication, there still is a massive benefit to using an end-to-end encrypted provider like Tuda or Proton. If you use one of the big centralized providers like Gmail or Yahoo, all your emails are stored in the clear on their servers. They can scrape those emails for information and at this point use them to train their AI models. So while that does help protect your emails that are stored in your inbox, it doesn&rsquo;t help for the emails you send to anyone using Gmail or one of those other providers, but that&rsquo;s a whole separate topic.</p>
<p>Typically when you self-host, it&rsquo;s for a privacy benefit, but with something like Stalwart, if I&rsquo;m being honest, I think it&rsquo;s actually less private to self-host my mail server. If you look at my sideofburritos.com domain right now, you&rsquo;ll see the MX record points to mail.sideofburritos.com. And if you look at that, you&rsquo;ll see it&rsquo;s tied to a Hetzner IP address, so you know the IP of the VPS that I&rsquo;m using.</p>
<p>I&rsquo;m the only one using this mail server, so all the activities&hellip; originates to me. If I&rsquo;m using something like Proton or Tuda, my activity can blend into the masses, but that&rsquo;s not happening in this case. But for me, it&rsquo;s more about control and having visibility into my email versus that small, in my opinion, privacy benefit.</p>
<p>One example of this that kind of pushed me over the edge to finally set this up. I was having some issues on Tuda receiving emails. Randomly, I had an email that was getting rejected that was previously working. I checked the rejected tab in the Tuda app, and I didn&rsquo;t see anything listed there.</p>
<p>I asked their support about it, and they said, not all rejections are visible there as it depends on some criteria. It can make a difference, for example, whether the email was rejected due to an issue with the email itself that caused the rejection, or if the sending server is blacklisted. We can always reach out to the service if there is a general issue with email communications with our server.</p>
<p>So the email that was getting dropped was an email from my membership site. I have mailgun configured as the smtp sending relay on there, so I checked the logs on there. Everything looked like it should have been delivered. Malgun showed no issues with the sending of the email, so tuta was just dropping it for some reason.</p>
<p>I never really got an answer on why those were getting silently dropped, but like I mentioned earlier, that for me that was kind of the breaking point for wanting more visibility into my email instead of this sort of black box set up. And I&rsquo;m not specifically blaming them. I can only imagine the amount of phishing and spam emails they need to filter out, especially offering free accounts. Who knows what kind of traffic they&rsquo;re getting?</p>
<p>But what I really wanted was more visibility, so if something was happening I could dig into it and figure out why. So with stalwart I finished migrating all my domains about two months ago, which I think is a decent amount of time to test it out, and in that time I haven&rsquo;t had any issues with it sending or receiving emails. I&rsquo;ve updated it a few times and all the updates have gone successfully. No issues. Let me put this in dark mode quick.</p>
<p>So some of the pros with Stalwart, since you are self-hosting it yourself, you can host as many domains as you want on there. With Proton, I think the plan I had, I was limited to three, so I needed to use aliases for some domains and shared domains for emails. I couldn&rsquo;t give every domain its own email, so that was kind of an inconvenience.</p>
<p>Stalwart also supports server-side encryption using OpenPGP. So the cool thing about this, Proton actually uses PGP for their encryption, some rendition of it. But if you use a client like Thunderbird, which is what I use because it&rsquo;s the only one I found so far that supports using PGP for opening your emails on desktop and mobile, you can actually discover the published Proton PGP keys for the emails. They publish those by default when you sign up.</p>
<p>So if I&rsquo;m emailing someone at Proton.me, I click discover in Thunderbird, it finds their published public PGP key, and now those emails are intent-encrypted. So I don&rsquo;t actually need a Proton account to email someone using Proton encrypted. So that&rsquo;s pretty great.</p>
<p>And on the topic of security, Stalwart reminds me of Graphene OS in the sense that out of the box, the default setup is pretty secure. You don&rsquo;t have to worry about being an open relay just because you set it up.</p>
<p>In the past, when I used to self-host my own email server, this was about a decade ago at this point, most of those services available at the time were configured to be open by default. So you had to make sure you locked them down, didn&rsquo;t miss anything. Otherwise, you could be an open relay and now you&rsquo;re sending spam mail because someone found your server when they were scanning the internet.</p>
<p>With Stalwart, it handles MTA-STS, TLS provisioning, DKIM key generation, rotation, and DNS publication. All of that is handled automatically if you use their DNS integration. I&rsquo;m currently using it with Cloudflare and Bunny.net. Both have been working flawlessly.</p>
<p>It also has&hellip; automatic IP banning, rate limiting, ACLs. So if someone&rsquo;s scanning your server and they trigger that rate limit, that IP is automatically blocked.</p>
<p>So this next part is going to get a bit into the weeds on how email works. But if you&rsquo;re at all curious about this, it&rsquo;s going to be worth watching. Otherwise, you can just skip ahead to the cons section of this video.</p>
<p>So I currently host my stalwart server on Hetzner. And by default, they block ports 25 and 465. This is common on VPS providers. Spammers will sign up quick and start spamming from their IP addresses using a VPS, which can cause a bunch of IPs to get block listed. So by default, they block that.</p>
<p>If you&rsquo;ve been paying for a month or a few months with a VPS using Hetzner, you can request those ports to be unblocked. I did it and it was unblocked within seconds. I think it was automated.</p>
<p>But as far as sending goes, I actually use a SMTP relay. In this case, SMTP to go. The reason for that is is while I do plan to have that Hetzner VPS long term, I don&rsquo;t want to be responsible for the IP reputation of that. If an IP gets marked as spam or block listed, now people will stop receiving your emails because of the IP reputation. It&rsquo;s not something I want to worry about.</p>
<p>If I had my own AS and my own IP range assigned to me, which would be way more long term that setup than I would send from my IP range. But in this case, I don&rsquo;t. But that would be a fun future project.</p>
<p>SMTP2Go, their free plan offers 1000 emails per month. That doesn&rsquo;t count against receiving emails. That&rsquo;s just sending. I can&rsquo;t imagine more people, at least an individual, send more than 1000 emails per month. So the free plan should work for you. That&rsquo;s what I use. So far, it&rsquo;s been great. I haven&rsquo;t encountered any sending reliability issues.</p>
<p>There&rsquo;s also a bunch of other free relays out there you can use. I think Postmark has 100 emails per month. Mail gun has a thousand they allow, so there&rsquo;s definitely options, but that&rsquo;s what I use for sending. Again, I don&rsquo;t want to worry about the IP reputation of my vps, so I use a third party for the sending.</p>
<p>But getting back to some of the other things that stalwart offers, they do have a masked email option. You&rsquo;ll notice this is marked as an enterprise feature, which I&rsquo;ll talk about in a few minutes. So I believe this is similar to something like simple login. Each mask is bound to one account and can be disabled or destroyed independently, so end users can hand out different addresses to every external service and cut them off without affecting the others.</p>
<p>I really do like simple login as a service. It&rsquo;s easy to use, provides a nice privacy benefit, but it&rsquo;s kind of like the mafia. It&rsquo;s really easy to get into it, but good luck migrating away from it. So I&rsquo;m hoping to move to something like this using a separate domain specifically for aliases, but we&rsquo;ll see how that goes.</p>
<p>One other pro regarding stalwart is mozilla who offers thunderbird. They&rsquo;re going to be offering thunder mail in the future, which is a paid hosted version for email. You can join their waitlist if you want, but they have a blog post where they mention that the only project we&rsquo;re using to help build thunderbird pro is stalwart, but we absolutely want to make sure the project gets its financial support from us to support its sustainability and well-being.</p>
<p>To me, that&rsquo;s a huge benefit to using stalwart. There&rsquo;s going to be a large company behind it supporting it financially, and I think that speaks a lot to the longevity of the project.</p>
<p>Now getting to some of the cons of stalwart. As we saw on the masked email wiki page, it&rsquo;s marked as an enterprise feature. So if we go to stalwart pricing, the minimum you can pay for is 25 mailboxes, which comes out to 60 usd per year. I actually think that&rsquo;s cheaper than my proton plan currently that I have. I pay for it. To me, that&rsquo;s more than worth it to support the open source project and get some of the other features that are behind that payment.</p>
<p>And then regarding the privacy and pgp keys, so proton and tuta, well actually I don&rsquo;t know what tuta uses exactly, but with proton they automate that entire pgp key setup. With stalwart you&rsquo;ll have to generate those keys yourself, configure them. It&rsquo;s not difficult, but it does take some time to set up.</p>
<p>And like I mentioned earlier, the only clients I found so far that support that encrypted mailbox are thunderbird. I couldn&rsquo;t find any web clients that supported it, which is unfortunate. I think I saw something that stalwart might offer a first party webmail client and hopefully it&rsquo;s supported in there. I would like to have webmail accessible. So you are limited on the clients you can use. You&rsquo;ll have to use the app thunderbird desktop and mobile if you want that.</p>
<p>Stalwart does have built-in spam spam filtering, but it&rsquo;s overly aggressive. You&hellip; there is a feature where you can submit the mail and say this is not spam to kind of teach the filter. I don&rsquo;t know if I just don&rsquo;t receive enough mail or I haven&rsquo;t done that enough, but it hasn&rsquo;t really seemed to help.</p>
<p>But I do guess it&rsquo;s better that it&rsquo;s overly aggressive versus not being good enough, so I just make it a habit to check the spam folder every so often. I have also configured a few sieve rules to allow list domains and senders to make sure those don&rsquo;t get marked as spam. So again, kind of goes back to that self-hosting setup. There might be some things you need to tune yourself.</p>
<p>It&rsquo;s also worth mentioning that stalwart is currently pre-version one. They expect the version one released in the first half of 2026. It&rsquo;s currently the second half, so I&rsquo;m assuming it&rsquo;ll be next year in 2027 because at this point there&rsquo;s not, there is no stable or finalized database schema and configuration system. So when you are doing upgrades, there might be some breaking changes you&rsquo;ll have to handle yourself since you are self-hosting.</p>
<p>If that doesn&rsquo;t sound like something you want to do, then you might want to put this off till version one. Like I said, though, I started doing this about three months ago or two months ago. All the upgrades so far, there&rsquo;s a new version every week, have been straightforward and simple. Docker pull and Docker up, and the new version was deployed.</p>
<p>So those are the cons that I found so far regarding stalwart directly. These next cons are more self-hosting in general related.</p>
<p>If something happens with your email setup, there&rsquo;s no status page to check. There&rsquo;s no email support to contact. It&rsquo;s on you to resolve. If you&rsquo;re not receiving emails, you&rsquo;re wondering what&rsquo;s going on. Again, that&rsquo;s on you. You need to check the logs, see what&rsquo;s going on. Did you hit your limit in your SMTP relay? Did your ports somehow get blocked? Did Docker stop running? Did the process crash?</p>
<p>In my experience self-hosting, these things aren&rsquo;t common, but when they do happen, they can take some time to figure out. I really do think that self-hosting is easy, especially with docker. A couple commands, you can have a service running setup and you can start using it.</p>
<p>The part that&rsquo;s not easy, which I think a lot of people don&rsquo;t think about when they&rsquo;re paying for a cloud service, is consistent reliable backups. It&rsquo;s easy to set a service up, but if that hard drive dies, you know, even if you&rsquo;re using a shared hosting provider, they do have hardware issues. If that server dies and they just give you a new one with a fresh installation of your operating system, can you restore your backups? Do your backups run reliably every day? Do you monitor those backups? Do you check them for freshness? Do you document your restore procedure?</p>
<p>Different things like that that people don&rsquo;t talk about enough because they&rsquo;re not that interesting to share because you only need them in a worst case scenario. But if you are self-hosting, you really need to think about those and take that into consideration before you decide to dive in head first.</p>
<p>So is the juice worth the squeeze? I don&rsquo;t know. That&rsquo;s up to you. To me it is. I also just enjoy doing this kind of stuff.</p>
<p>If you&rsquo;re going to be annoyed when you get an alert on the weekend in the middle of the day when you&rsquo;re hanging out with some friends and you&rsquo;re now no longer receiving email, then doing something like this probably isn&rsquo;t for you. Stick to a managed provider.</p>
<p>But if you&rsquo;re at all interested in self-hosting email, I definitely recommend checking out stalwart. I&rsquo;m also thinking about doing a full setup video with another domain that I have that I don&rsquo;t currently have set up to receive email. If you think that&rsquo;d be useful, let me know down in the comments or in the comments on my blog, and if there&rsquo;s enough of those I&rsquo;ll try to make that video happen.</p>
<p>But that&rsquo;s all I got for this video. I hope you have a great rest of your day and I&rsquo;ll see you next time.</p>

</details></p>

]]></content>
      </entry>

</feed>
