Supersedes the Go + embed-Mox design. The Go tree is removed; its
architecture doc is preserved at docs/archive/ARCHITECTURE-go-embed-mox.md
because its competitive analysis and data model still hold.
Five decisions recorded as ADRs:
0001 Rust, not Go — accepting ~5,500 lines of protocol code that Mox
would have given us free, to get the first permissively licensed
Rust mail server. Costs stated plainly.
0002 Apache-2.0, not MIT or AGPL — patent grant, trademark, CLA-free
contribution. Public on GitHub; Gitea stays as the private fallback.
0003 Stalwart's primitive crates (Apache-2.0/MIT) yes; its AGPL server
crates never. DANE and MTA-STS sit on the AGPL side of that line,
which is why we write our own.
0004 Milestones, reordered: embedded inbound is required at launch.
0005 Oracle Cloud blocks outbound :25, so direct-to-MX is impossible on
the launch host. Split delivery is mandatory, not an on-ramp.
Twelve crates in three tiers. Tier 1 (mail-dane, mail-mta-sts, mail-dsn)
is standalone and publishable — no `dane` or `mta-sts` crate exists on
crates.io at all today.
openmail-relay ships the provider table as data, with SES and Oracle from
the start. Oracle's and Resend's SPF includes are deliberately None: a
guessed include turns the DNS check green against a mechanism the provider
does not honour, and mail still fails SPF silently.
cargo check/test/clippy/fmt all green; unsafe_code is forbidden workspace
wide; cargo-deny enforces the licence policy in CI.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
27 lines
966 B
Rust
27 lines
966 B
Rust
//! Outbound delivery: smarthost relays and direct-to-MX.
|
|
//!
|
|
//! Two paths behind one interface:
|
|
//!
|
|
//! - **relay** — hand the message to SES / OCI Email Delivery / any smarthost
|
|
//! on submission (587). Someone else's IP reputation. Works everywhere,
|
|
//! including hosts that block outbound :25.
|
|
//! - **direct** — resolve MX, apply [`mail_mta_sts`] and [`mail_dane`], deliver
|
|
//! ourselves. Our reputation, our control, and impossible on a host that
|
|
//! blocks outbound :25 (see `docs/adr/0005-oracle-cloud.md`).
|
|
|
|
pub mod providers;
|
|
|
|
pub use providers::{PROVIDERS, RelayProvider, provider, resolve_host, spf_include};
|
|
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum Error {
|
|
#[error("no usable MX for {0}")]
|
|
NoMx(String),
|
|
#[error("relay rejected: {code} {text}")]
|
|
Rejected { code: u16, text: String },
|
|
#[error("TLS policy violation: {0}")]
|
|
TlsPolicy(String),
|
|
#[error("transient failure, retry: {0}")]
|
|
Transient(String),
|
|
}
|