Nisdos Mail
Articles
Notes on email custody, storage and privacy — what we learned building Nisdos Mail, and what it means for your own mailboxes.
Developers
SPF, DKIM and DMARC: what each record does and how to set it up SPF, DKIM and DMARC are three TXT records that prove mail from your domain is really yours. What each checks, what breaks it, and the order to add them. Unlimited email addresses on your own domain: one address per purpose Unlimited email addresses on your own domain let you run one address per purpose. Why providers cap aliases, what changes when addresses are free, and recipes. Email hosting for developers: mailboxes you control, not an email API Email hosting for developers as hosted mailboxes you control: unlimited addresses on your domain, mail written into your own S3, R2, WebDAV or Git storage.
Comparisons
Google Workspace alternative: when custody beats the suite A Google Workspace alternative makes sense only if custody and jurisdiction outrank Docs, Calendar and Meet. What you gain, and who should stay. MXroute, Migadu and Fastmail alternatives: what all three share MXroute, Migadu and Fastmail are all good hosts that store your mail on their servers. Here is what changes when you hold the bytes yourself. Proton Mail alternative: custody, not just encryption You want a Proton Mail alternative when your concern is custody: Proton cannot read your stored mail, but it still holds the ciphertext on its own servers.
Pricing
Bring-your-own-storage
Email hosting on your own S3 bucket: how the storage works What lands in your S3 bucket when email is stored there: how a routing service verifies, encrypts and writes each message into a bucket you own. Email in your own cloud storage: how bring-your-own-storage works Bring-your-own-storage email routes and encrypts your mail, then writes it into cloud storage you own: your S3, R2, WebDAV or a Git repository.
Privacy
Who holds your email keys? The four custody combinations Email custody is two questions: who holds the keys that decrypt your mail, and who holds the stored bytes. The four combinations fail in very different ways. Zero-access email: what it means and what it does not cover Zero-access email means the provider encrypts arriving mail with your public key and cannot read what it stores. What it does not cover: metadata, custody.
Data sovereignty
GDPR and email hosting: what the regulation actually requires GDPR makes you the controller of your mailboxes and your host a processor. What that means in practice: Article 28 terms, transfers, breach duties. Email data residency: region, jurisdiction, and the difference Data residency is where the bytes of your mail physically rest. Jurisdiction follows whoever controls them. They are separate choices, and both are choosable. Self-hosted email alternative: control without the server Self-hosting email buys custody and costs you deliverability work forever. The middle path keeps the custody and hands off the SMTP stack. The CLOUD Act and your email: what US law actually reaches The US CLOUD Act obliges providers under US jurisdiction to produce data they control, wherever the disks sit. What that means for email, and what changes it.