
Email for a Nine-Year-Old
Everything in this series so far has been plumbing. This post is what the plumbing was for: moving my actual family onto the platform. My wife got an account, our nine-year-old got hers, and suddenly the infrastructure had users who did not care about DKIM alignment and would judge it entirely on whether their calendar synced.
Migrating your own family is a different discipline from deploying software. Software tells you when it’s broken. A family member might just quietly conclude the new thing is worse and route around it. So this phase got the same story-by-story treatment as everything else: create the account, verify email, calendar, and contacts sync on their real devices, and only then move to the next person. The retrospective’s phrasing was “migrated and familiarizing”, which is retro-speak for “it works and the reviews are still coming in”.
Onboarding without a helpdesk
Each person gets a checklist, documented like everything else in the repo: log into webmail with the temporary password, change it immediately in lldap’s self-service UI, enroll two-factor authentication in Authelia, then set up mail, calendar, and contacts on their devices. The docs are written for the family, not for me.
Two design choices made this survivable as a one-person helpdesk. Password changes in lldap propagate instantly to everything that authenticates against it, which after last week’s LDAP course correction is every service including mail; there is no “wait for sync” and no second password anywhere. And 2FA enrollment emails come from the platform’s own SMTP notifier, so the confirmation-code loop works without any external service. When someone inevitably loses a password, there’s an admin reset path through lldap, and an emergency recovery procedure for the day I lose mine, written well before it could ever be needed.
Training wheels, implemented in Sieve
The nine-year-old’s account is where infrastructure meets parenting. My position: this age is right for learning email, and wrong for having an unsupervised inbox on the open internet. The house rule is that email comes with training wheels, and the training wheels are visible.
Technically it’s small and I find that satisfying: a Sieve script with redirect :copy sends a copy of her mail to a parent mailbox, covering both what arrives and what she sends. No third-party “family safety” service scanning content, no cloud dashboard profiling my child; a mail filter, on our own server, implementing our house rule and nothing else. When she’s older the training wheels come off by deleting a script, and the account, the address, and the mail history are hers to keep. That last part is the point of the whole project: her digital identity starts on infrastructure her family controls, not inside an advertising funnel.
Trust, but journal
The security stories rounded out the epic. TOTP two-factor on the SSO portal. A password policy and brute-force regulation in Authelia. Ninety days of authentication logs with a small script that summarizes who logged in from where, which has so far mostly confirmed that my family’s login patterns are extremely boring, exactly as hoped.
Two honest limitations, both documented rather than solved. lldap does not log password change events, an upstream gap discovered only when I went looking for the audit trail, a reminder that research stories should probe operational behavior and not just compare feature lists. And the epic’s cleanest process lesson: an earlier retrospective told me to create a test account before touching live ones, I skipped it, and then found myself unable to rehearse password resets without experimenting on my own family’s mailboxes. The action item you skip is reliably the one you needed.
Next week: the webmail those accounts actually live in, and the money I spent making Roundcube not look like 2012.
You May Also Like

SPF, DKIM, DMARC: Getting Mail Delivered
Running a mail server is easy. Convincing Gmail that your mail server exists legitimately is the actual work.

One Binary for All of Email
Deploying Stalwart across two nodes, with every piece of state pushed out into managed backends.

One Login for Everything: lldap and Authelia
Building the identity layer before there was much to identify against, and the OIDC decision I got to make twice.



