A few weeks ago, I saw two interesting talks on Tübix. One was about self-hosting an e-mail server with Stalwart, and another was about digital sovereignty in Europe – or at least the first half of it, then it turned into a bit of a rant about the state of the usability of FOSS.

The message in both talks matched the sentiment that can be felt in many circles these days: digital sovereignty is becoming more important than ever. Dependence on (usually US American) hyperscalers should be avoided. This resonates with me.

Of course, digital freedom comes at a cost. But so does signing up to Google, Facebook, Twitter, and so on. If you’re not paying with money, you’re paying with something else: not just your freedom, but also your data, your privacy, your independence.

There are so many reports on social media from people who got locked out of their accounts for opaque reasons and are unable to contact a human being even though they earn their livelihood by publishing on some app store, processing payments with PayPal, or have their entire business infrastructure hosted on G Suite or M365. More recently, people have been locked out for political reasons as well.

We are used to everything on the internet to be free of charge. It’s important to keep in mind that you get what you pay for. For me, it’s more than fair to spend a couple of Euros for a good service that is as important as your e-mail. I had a few e-mail providers in the past: GMX, Arcor (now Vodafone), AOL (So what? They offered IMAP and the address was short, what else do I need?), Protonmail (first time I paid), and now Mailbox.org.

I moved on from Protonmail because it felt too patronizing. More specifically:

  • No automatic forwarding: I only realized after signing up that they don’t provide a way to forward e-mails. They claim it’s for security reasons, and while I understand where they are coming from, it also makes switching providers harder.
  • No IMAP: They don’t offer regular IMAP without their custom-built bridge. Again, I understand that they want to protect users and why OAuth2 is more secure, but I feel sufficiently competent to handle the risk myself and don’t want to be patronized.
  • Weak E2EE: The promise of end-to-end-encryption falls flat if they offer to manage your keys for you. Key management cannot be delegated if you value true E2EE.

And no offense to Switzerland, but it’s just one more government I’m handing control of my data over to.

I deleted my Facebook account a long time ago, then my Twitter account after it became an unabashed platform for right-wing ideology, and recently my Instagram account. I haven’t been using these accounts very actively anyway. To stay up-to-date, I now read Hacker News, Bluesky and some good old RSS feeds.

RSS is a great piece of technology that is part of the “old” internet, where everyone owned a small place on it and most services were decentralized and/or federated. I like that internet. I don’t like where the current internet is headed. And I find the often-cited reasons why I should get a blog completely convincing.

So I’m trying to do my part: get a small place on the internet, with my own domain, an e-mail service that respects my freedoms, and use the internet in the way it was intended to be used.

Even though Stalwart looks amazing, I’m not quite ready yet to host my own e-mails, so I went with Mailbox.org, a German provider. In general, I try to get away from non-European services as much as possible without being radical. I like the convenience of my FireTV too much to ditch it, I don’t have the energy to run a de-Googled phone, and unfortunately there are no competitive alternatives to Claude et al. from Europe. But buying a domain and a small VPS from Berlin-based Ionos was quick, easy and convenient. I could even pay via bank transfer – at least for the domain, then there were “technical issues” and I had to pay for the VPS with a Visa card (yuck!). Unfortunately, Wero was not an option yet.

Next, I threw a site together with Hugo, set up Caddy on my brand new Debian VPS, and here we are! Annoyingly, I ran into one issue of the Hugo theme I picked. Happily, Caddy was even more convenient than I knew! I’m already using it to self-host some local apps using my own CA, which works like a charm, and now I wasted 15 minutes trying to find out how to set up certbot with Caddy just to learn that Caddy requests a certificate from Let’s Encrypt automatically. By default!

So here we are: I have a blog now! My own domain, my own web space, my own little place on the internet.

We’ll see what happens!

So please don’t like and subscribe or leave a comment. Though you’re always free to shoot me an e-mail if you like.