For years I ran vanilla qmail with two patches (AUTH support for sending authentication, and a patch to allow for a database of valid supported emails so you get rid of the backscatter issue).
It was absolutely fantastic, it ran without issues for years. It was very fast and I never had issues with losing mail or behaviours that baffled me or left me scratching my head.
I currently have a postfix setup, and while it works well I am very wary of upgrading it for fear of breaking something and causing mail to bounce or not be delivered. With qmail it would just queue mail if you accidentally misconfigure something (such as the delivery program is unavailable), with Postfix I've had it simply drop mail on the floor. Sure they are issues that could be solved with better testing, and verification of systems, but qmail is a lot more forgiving without bouncing.
I also quite prefer qmail to postfix in terms of its flexibility and resilience, but it really does highlight one of the biggest problems with long term use of djb software: It always seems to reach a point where djb feels it's done (or he's done with it) and it sits there for years with no updates, while still appearing to be the authoritative version of that product.
Vanilla qmail is genuinely unusable on the internet today (because of the backscatter issue in particular), but netqmail, which is still maintained, still looks like a secondary fork to someone who doesn't know the history. It doesn't help that djb for a long time used licensing that was incompatible with reasonable distribution of these forks as well.
So these days I actually tend to go for the forks and clones of djb software where possible. I use netqmail on my mail server, runit instead of daemontools, etc.
Unmaintained software is a problem and vanilla NaCl also left unfixed issues.
For example, the signature system was a prototype that shouldn't be used any more. The portable AES128 implementation produces incorrect output on some other platforms, one of the Curve25519 implementations performs out of bounds memory accesses, and one of the poly1305 implementations will produce incorrect output if your application changes the FP rounding mode. CurveCP was also a fantastic idea, but the NaCl implementation was just a proof of concept that cannot really be used in actual projects.
But would you rather have djb spend time addressing qmail compilation issues on Ubuntu 14.10, or keep making significant advances in applied cryptography (and security in general) instead?
In addition to organizing competitions, the amount of game-changing publications he made or contributed to is very impressive. And it might not have been the case if he didn't move on from software he wrote years ago.
Have you tried OpenSMTPD? It's really great. My config file is about 30 lines (and most of them are comments) – unlike with Postfix. And it's from OpenBSD, which means it has better security than others :-)
I really want to try OpenSMTPD, but I need it to hook into my Dovecot backend for SMTP auth (SASL would be awesome), and it needs to work with in-line email filtering (i.e. when a message is rejected as spam by amavisd I need that error to propagate back to the sending server). I haven't found good information on how to do any of that yet.
Right now my pipeline is pretty simple:
Postfix accepts -> milter (amavisd) -> dovecot for delivery
I would want to replicate something similar. Do you have any good resources or information?
It was absolutely fantastic, it ran without issues for years. It was very fast and I never had issues with losing mail or behaviours that baffled me or left me scratching my head.
I currently have a postfix setup, and while it works well I am very wary of upgrading it for fear of breaking something and causing mail to bounce or not be delivered. With qmail it would just queue mail if you accidentally misconfigure something (such as the delivery program is unavailable), with Postfix I've had it simply drop mail on the floor. Sure they are issues that could be solved with better testing, and verification of systems, but qmail is a lot more forgiving without bouncing.