Self-Hosting a Private Email Alias Service: A Complete Guide to Deploying SimpleLogin on a Personal VPS
Introduction: The Growing Imperative for Email Privacy
In the modern digital economy, your primary email address is more than just a communication tool; it is a universal identifier. Every newsletter subscription, e-commerce account, and SaaS trial demands an email address, effectively creating a map of your digital footprint. This centralization poses severe security and privacy risks. If a single service suffers a data breach, your primary email is exposed to malicious actors, leading to targeted phishing campaigns, credential stuffing attacks, and an influx of unsolicited spam.
To mitigate these risks, privacy-conscious professionals and enterprises are turning to Email Alias Services. These services act as an abstraction layer, generating unique, disposable email addresses for every platform you use. Inbound mail is seamlessly forwarded to your real inbox, while outbound replies mask your true identity. While third-party providers offer convenience, true data sovereignty is achieved only by self-hosting. This technical guide provides a comprehensive, step-by-step blueprint for deploying SimpleLogin—the leading open-source email alias solution—on your own Virtual Private Server (VPS).
Why SimpleLogin and Self-Hosting?
SimpleLogin has emerged as the gold standard for email aliasing due to its robust architecture, open-source transparency, and seamless integration across web browsers and mobile devices. By self-hosting SimpleLogin on a personal VPS, you unlock several critical advantages:
- Absolute Data Privacy: Your email routing logs, alias mappings, and configuration data remain strictly on your infrastructure, away from third-party monetization or surveillance.
- Custom Domain Flexibility: You can manage an unlimited number of custom domains and generate infinite aliases without subscription limitations.
- Cost Efficiency: Leveraging an existing VPS minimizes recurring operational expenses while maximizing hardware utilization.
- Control Over Deliverability: Managing your own mail transfer agent (MTA) settings allows you to fine-tune security protocols and monitor IP reputation directly.
Prerequisites and Infrastructure Requirements
Before initiating the deployment, ensure your infrastructure meets the following baseline technical requirements:
- A Dedicated VPS: A virtual private server running a clean installation of a stable Linux distribution, preferably Ubuntu 22.04 LTS or Debian 12. The minimal hardware footprint requires at least 1 vCPU, 2GB of RAM, and 20GB of SSD storage.
- A Clean IP Address: Verify that your VPS provider has not assigned you an IP address listed on major email blacklists (such as Spamhaus or Barracuda). Port 25 (SMTP) must be unblocked by your provider for both inbound and outbound traffic.
- A Dedicated Top-Level Domain (TLD): A domain name managed via a DNS provider that offers rapid propagation and granular control over advanced records (e.g., Cloudflare, Route 53, or Namecheap).
- Software Dependencies: Docker Compose and Git must be installed on the host system to orchestrate the containerized application.
Step 1: Network and DNS Configuration
The foundation of any self-hosted email infrastructure relies on precise DNS engineering. Incorrect records will cause your forwarded emails to be rejected by major providers like Gmail, Microsoft 365, and ProtonMail. Navigate to your DNS management console and establish the following records, replacing yourdomain.com and 192.0.2.1 with your actual domain and VPS public IP address.
1. Address Records (A/AAAA)
Create an A record pointing your main alias subdomain to your VPS:
app.yourdomain.com. IN A 192.0.2.1Create a wildcard A record to handle incoming emails directed at any dynamically generated alias:
*.yourdomain.com. IN A 192.0.2.12. Mail Exchanger (MX) Record
Direct all incoming mail traffic for your alias domain to your VPS infrastructure:
yourdomain.com. IN MX 10 app.yourdomain.com.3. Email Authentication Frameworks (SPF, DKIM, and DMARC)
To establish cryptographic trust and guarantee high deliverability, you must implement the following three security records:
- Sender Policy Framework (SPF): Authorizes your VPS IP to send mail on behalf of your domain.
yourdomain.com. IN TXT "v=spf1 ip4:192.0.2.1 ~all" - DomainKeys Identified Mail (DKIM): Signs outgoing mail cryptographically. SimpleLogin will generate a specific TXT record key during initialization (commonly using the selector
dkim._domainkey). You must input this value precisely into your DNS configuration. - Domain-based Message Authentication, Reporting, and Conformance (DMARC): Dictates how receiving servers should handle mail that fails SPF or DKIM checks.
_dmarc.yourdomain.com. IN TXT "v=DMARC1; p=quarantine; pct=100;"
Step 2: Preparing the Host Environment
Connect to your VPS via SSH and execute a system update to ensure all core libraries are secure and up to date:
sudo apt update && sudo apt upgrade -yInstall Docker and Docker Compose if they are not already present on the system:
sudo apt install docker.io docker-compose git -y
sudo systemctl enable --now dockerCreate a dedicated directory structure for SimpleLogin to maintain organization and ensure persistence of configuration files:
mkdir -p ~/simplelogin/sl && cd ~/simplelogin---Step 3: Cloning and Configuring SimpleLogin
SimpleLogin provides an official deployment repository containing the necessary Docker configuration. Clone the repository and extract the essential configuration templates:
git clone [https://github.com/simple-login/app.git](https://github.com/simple-login/app.git) sl-repo
cp sl-repo/docker-compose.yml .
cp sl-repo/example.env .envOpen the .env file using a text editor such as nano or vim. You must modify the environment variables to align with your specific architectural setup:
URL=[https://app.yourdomain.com](https://app.yourdomain.com)
EMAIL_DOMAIN=yourdomain.com
[email protected]
SECRET_KEY=generate_a_long_random_string_here
POSTGRES_PASSWORD=generate_a_secure_db_password_here
DISABLE_REGISTRATION=trueSecurity Note: Setting DISABLE_REGISTRATION=true after creating your initial administrator account prevents unauthorized public users from exploiting your server resources to generate aliases.
Step 4: Database Initialization and Container Orchestration
With the environment variables established, initiate the database migrations. This process seeds the PostgreSQL database with the structural schema required by SimpleLogin:
docker-compose run --rm app alembic upgrade headOnce the database migration completes successfully, initialize the system containers in detached mode:
docker-compose up -dVerify that all microservices (the web application, the email processor, the asynchronous Celery workers, and the PostgreSQL database) are running securely:
docker-compose ps---Step 5: Reverse Proxy and SSL Provisioning
To secure administrative access and ensure encrypted HTTPS connections, deploy a reverse proxy such as Nginx or Caddy on the host machine. Below is a standard Nginx block configured to forward traffic securely to the SimpleLogin web container while enforcing TLS via Let's Encrypt:
server {
listen 80;
server_name app.yourdomain.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name app.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/[app.yourdomain.com/fullchain.pem](https://app.yourdomain.com/fullchain.pem);
ssl_certificate_key /etc/letsencrypt/live/[app.yourdomain.com/privkey.pem](https://app.yourdomain.com/privkey.pem);
location / {
proxy_pass http://localhost:7777;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}---Step 6: Creating the Administrator Account
With the web interface running behind an encrypted proxy, create your primary administrative credentials via the terminal command line:
docker-compose run --rm app python init_app.pyFollow the interactive command-line prompts to enter your primary, secure email address (e.g., your personal ProtonMail or personal server address) and a robust master password. Once completed, navigate to [https://app.yourdomain.com](https://app.yourdomain.com), log in with your newly provisioned credentials, and navigate to the developer settings to extract the DKIM public key string. Apply this final string to your DNS dashboard as detailed in Step 1.
Conclusion and Lifecycle Maintenance
Congratulations! You have successfully established an enterprise-grade, self-hosted private email alias ecosystem using SimpleLogin on your personal VPS. You can now download the SimpleLogin browser extensions (Chrome, Firefox, Safari) and mobile applications, pointing the endpoint URL to your custom domain. This architecture effectively shields your primary email from data leaks, stops spam at the perimeter, and restores absolute control over your digital identity.
To maintain long-term reliability and secure operations, remember to execute periodic system upgrades, set up automated daily backups of your PostgreSQL database volume (~/simplelogin/sl/db), and monitor your server’s IP health to guarantee consistently high email deliverability. Taking control of your data requires technical diligence, but the resulting digital peace of mind is unparalleled.
