Self-hosted production infrastructure — mail, DNS and web by Tanveer AhmedSelf-hosted production infrastructure — mail, DNS and web by Tanveer Ahmed

Self-hosted production infrastructure — mail, DNS and web

Tanveer Ahmed

Tanveer Ahmed

The problem

Production mail, DNS and web have to be reachable from the internet without anything in the building being directly reachable, trusted by large receivers like Google and Microsoft, and recoverable after the machine they run on is gone.

What I did

An edge server fronting a hypervisor over an encrypted tunnel, with seven separated service containers behind a reverse proxy doing automated TLS. Mail authenticated properly end to end — SPF, DKIM, reverse DNS, MTA-STS, and DMARC set to reject rather than merely observe. Split-horizon DNS, an intrusion-prevention layer filtering forwarded traffic rather than just local traffic, capped logging, and nightly configuration backups.

The result

Mail that large receivers accept, nothing in the building directly exposed, and a documented bare-metal restore that has been exercised rather than assumed. The DMARC policy is publicly verifiable with one dig query — which is the point: every claim on this estate is checkable.
Like this project

Posted Sep 28, 2026

Mail, DNS and web reachable from the internet with nothing in the building exposed — DMARC at reject, automated TLS, and a restore that has been exercised.