Making Rspamd's Blocklists Actually Work: A Private Unbound Resolver + Spamhaus DQS

Here’s a failure mode that hides in plain sight: if your spam filter resolves DNS through a public resolver like Google or Cloudflare, most DNS blocklists silently refuse to answer it. Spamhaus, URIBL, SURBL and friends all do this. Your filter keeps running, adds a few headers, and quietly lets listed senders through — because the lookups that should have flagged them never returned a useful answer.

The fix has three parts: run your own recursive resolver, subscribe to Spamhaus’s free Data Query Service (DQS), and set a reject policy that’s aggressive on definitive signals without inviting false positives. This post is the complete, reproducible setup. My stack is Postfix + Dovecot + Rspamd + ClamAV on MicroShift, managed with Flux; domains, keys and IPs are anonymized, but everything else is exact.

[Read More]

Hardening a Self-Hosted Mail Server: fail2ban, Postfix, and Dovecot

Update (2026-06-05): the action = firewallcmd-rich-rules shown below has since been replaced with fail2ban’s native nftables action. With ~2000 banned addresses the firewalld variant needed 90 seconds to stop and was killed with SIGABRT — it removes each ban as an individual rich rule, and any that firewalld had already dropped during a reload wait for a timeout. See the homelab guide for the current configuration. Everything else here still applies.

[Read More]