Knowledge Base
Reference knowledge for admins, one page at a time: what a protocol or product is, how it works and where it shows up in day-to-day operations, with quick facts, every article on the topic and its place in the protocol stack. The collection keeps growing; 47 topics are planned.
Microsoft
Microsoft Exchange Exchange and Microsoft 365: the mail system behind the mailboxes An overview of Exchange Online, Exchange Server, and hybrid deployments: connectors and mail flow, transport rules, Autodiscover, the role of the last on-premises server, and what running the platform involves today. Active Directory / Entra Active Directory and Microsoft Entra: the identity foundation Why running mail means running a directory: Active Directory and Entra ID in combination, synchronization with Entra Connect, Kerberos and LDAP on the local network, Entra Domain Services for cloud-only environments, and app registrations for system access.
Mail gateways
SEPPmail SEPPmail: The Secure Mail Gateway with GINA Delivery How the SEPPmail Secure E-Mail Gateway works: S/MIME and domain encryption at the gateway, GINA for recipients without keys, its position in the mail flow, LDAP integration and the operational topics from firmware to cluster. Totemomail Totemomail: Email Encryption on the Kiteworks Platform The Totemomail encryption gateway in operation: origins and the takeover by Kiteworks, gateway encryption with S/MIME and PGP, WebMail delivery, LDAP integration, the licensing model based on licensed users, and the M365 integration. HIN gateway HIN: secure email in the Swiss healthcare sector The HIN platform from an operator's perspective: HIN identities and protected mail between healthcare professionals, the HIN Mail Gateway inside an organization's own infrastructure, Access Gateway and client, platform upgrades and their deadlines. Cisco ESA / SMA Cisco Secure Email: ESA and SMA in operation The Cisco email security platform from an administrator's perspective: the Email Security Appliance (ESA) as a gateway, the Security Management Appliance (SMA) for administration and quarantine, AsyncOS, working on the CLI, and certificate maintenance.
AI & automation
Claude Claude and Claude Code: AI assistance for technical work An overview of Claude: Anthropic's AI model, access paths from chat to API, Claude Code as an agent for the terminal and the codebase, and the security questions that arise when running it on self-managed infrastructure. Cloudflare Workers Cloudflare Workers: serverless at the network edge An overview of Cloudflare's serverless platform: code at the edge instead of on servers, the V8 isolate model, storage services from KV to D1 and R2, bindings and Wrangler, and the limits of the model.
Open source & selfhosting
Home Assistant Home Assistant: smart home hub with a local focus An overview of the open source smart home platform: local control instead of mandatory cloud, integrations and device connectivity, automations, installation variants, and the role of APIs, tokens, and MQTT. Rclone Rclone: The Universal Tool for Cloud Storage An overview of the command-line tool for cloud storage: remotes and backends, the core commands sync, copy and mount, client-side encryption with crypt, and integrity checking by checksum. Proton Drive Proton Drive: End-to-End Encrypted Cloud Storage An overview of Proton's cloud storage: end-to-end encryption as its basic principle, origin and ecosystem, clients and platforms, and what a zero-knowledge architecture means for third-party tools and automation. Paperless-ngx Paperless-ngx: self-hosted document management An overview of the open source DMS: the consume pipeline from scan to archive, OCR and full-text search, organization through tags, correspondents, and document types, storage architecture, and operation in containers.
Protocols & standards
SMTP Understanding SMTP: How Email Is Actually Delivered What SMTP is and how mail flow works: envelope and headers, MX delivery, relays and smarthosts, the ports 25, 465 and 587, StartTLS, and the reply codes with which servers justify acceptance and rejection. LDAP Understanding LDAP: the directory protocol behind AD, Entra, and mail gateways What LDAP is and how it works: a directory rather than a database, DIT and distinguished names, bind and search, LDAPS vs. StartTLS, and what of that really counts in Active Directory, Entra, and secure mail gateways. DNS DNS for mail admins: MX, SPF, DKIM, and DMARC in one place Why email does not work without DNS: MX and PTR records, SPF, DKIM, and DMARC as TXT records, TTL and propagation, and how to verify entries properly before mail flow suffers. TCP / network TCP and Networking Basics: What Mail Admins Really Need TCP as the foundation of SMTP, LDAP, and HTTPS: connection setup with the three-way handshake, ports and firewalls, typical failure patterns from timeout to connection refused, and the steps for a quick diagnosis. TLS / certificates TLS and Certificates: Trust in Mail and Directory Operations How TLS secures connections and why certificates are the most common cause of outages: handshake, certificate chains and truststores, SAN instead of CN, LDAPS and StartTLS, renewal without downtime. SSH SSH: Remote Access, Keys, and Hardening Secure Shell in day-to-day administration: keys instead of passwords, agent and known_hosts, the essential hardening steps for exposed servers, and SFTP as a file transport. Kerberos Kerberos: tickets, KDC, and authentication in Active Directory How Kerberos works and why Active Directory is built on it: tickets instead of passwords, KDC and TGT, service principal names and keytabs, the time synchronization requirement, and the typical failure patterns.
Email security
Email encryption Email Encryption: Transport Protection, S/MIME, PGP, and the Gateway Model The layers of email encryption cleanly separated: opportunistic and enforced TLS on the transport, S/MIME and PGP for content, central gateways instead of client-side chaos, and when each level is sufficient. SPF · DKIM · DMARC SPF, DKIM, and DMARC: sender authentication in combination The three sender authentication mechanisms and how they work together: what SPF checks, what DKIM signs, how DMARC ties both to the visible sender, and the rollout path from reports to p=reject. Hardening & access Hardening and access protection: reducing attack surface in operations The principles behind every hardening checklist: minimize the attack surface, use central instead of local accounts, grant minimal privileges, apply updates consistently, and keep access traceable, from the appliance GUI to the VPS.
Automation & APIs
PowerShell / Graph PowerShell and Microsoft Graph: Automation for Mail Admins The automation layer above Exchange, Entra and Microsoft 365: Exchange Online PowerShell, Microsoft Graph as an API, app registrations with certificate authentication, and where the classic modules are being retired. APIs & integrations APIs and integrations: REST, tokens, and automation What administrators need to know about APIs: the basic REST pattern, authentication with keys, tokens, and OAuth, rate limits and versioning, local device APIs versus cloud APIs, and the first test with curl.
Operations
Releases & updates Releases and Updates: Patch Operations for Mail Infrastructure How update operations for Exchange, appliances and gateways become plannable: release types from security update to firmware, maintenance windows and rollback paths, reading release notes, and the question of how quickly patching has to happen. Backup & recovery Backup and recovery: bringing mail infrastructure back online What really has to be backed up in mail systems: configurations of gateways and appliances, key material, RTO and RPO as planning parameters, and why a backup without a restore test is not a backup. Migration & deadlines Migration and deadlines: keeping mail infrastructure life cycles under control Why migrations in the mail environment are almost always driven by deadlines: end-of-support dates, vendor platform renewals, migration patterns from big bang to coexistence, and the checklist for cutover day. Containers & Docker Containers and Docker: operational knowledge for self-hosting Containers in everyday administration: images and tags, volumes and the persistence pitfalls, Compose as the standard, networks, update strategies, and health checks, with a focus on reliable long-term operation. Storage & sync Storage and Sync: Cloud Storage in Technical Terms How cloud storage works technically: object storage versus file system, access through sync, copy, and mount, client-side encryption, storage classes from hot to cold, and integrity checking of transferred data. Licences & limits Licenses and limits: licensing models for infrastructure software How infrastructure software is licensed: named users, devices, and capacity limits, how license counters are fed technically, what happens when a limit is reached, and the role the directory plays in it. Troubleshooting & diagnostics Troubleshooting and Diagnosis: Systematic Fault Finding in Infrastructure The methodology behind successful fault finding: a layered model from the connection to the application, taking error messages literally, reproducing minimally, correlating changes, and documenting findings. Testing & load tests Testing and Load Tests: Probing Infrastructure Under Controlled Conditions Methodology for functional and load testing in messaging and infrastructure environments: what to measure, the baseline-burst-soak sequence, load generators and sinks, marking test runs, and evaluating results with percentiles instead of averages.