Knowledge Base
Conocimiento de referencia para administradores, página a página: qué es un protocolo o un producto, cómo funciona y dónde aparece en la operación diaria, con datos clave, todos los artículos sobre el tema y su lugar en la pila de protocolos. La colección sigue creciendo; hay 55 temas previstos.
Las páginas marcadas con EN o DE se están traduciendo y por ahora se abren en inglés o en alemán.
Microsoft
Microsoft Exchange Microsoft Exchange: familia de productos y modelos operativos Microsoft Exchange como familia de productos: conceptos y protocolos comunes, diferencias entre Exchange Online y Exchange Server, así como las funciones de la operación híbrida y el flujo de correo híbrido. Exchange Online Exchange Online: arquitectura, flujo de correo y operaciones Exchange Online para administradores de mensajería: modelo de tenant y destinatarios, transporte de EOP, conectores, acceso de clientes, PowerShell y Graph, Message Trace, retención, seguridad y recuperación. Exchange On-Premises Exchange On-Premises: arquitectura y operación del servidor Exchange Server en el propio centro de datos: roles de buzón y Edge, canalización de transporte, Active Directory, bases de datos ESE, DAG, acceso de clientes, seguridad, monitorización, copia de seguridad y recuperación. Exchange Hybrid Exchange Hybrid: identidad, coexistencia y operación Exchange Hybrid explicado de forma clara: requisitos, sincronización de directorios, autoridad de destinatarios, Hybrid Configuration Wizard, OAuth, relaciones de organización, Autodiscover, movimientos de buzones y operación. Hybrid mail flowDE Hybrid-Mailfluss: Routing zwischen Exchange Online und On-Premises Hybrid-Mailfluss Schritt für Schritt: direkte und zentrale Zustellung, Connectoren, TLS-Zertifikate, Remote-Domains, gemeinsame SMTP-Domains, Mail-Gateways, Message Trace und Message Tracking. Active Directory / EntraEN Active Directory and Microsoft Entra: the identity foundation Why running mail means running a directory: Active Directory and Entra ID in combination, synchronization with Entra Connect, Kerberos and LDAP on the local network, Entra Domain Services for cloud-only environments, and app registrations for system access.
Pasarelas de correo
SEPPmailEN SEPPmail: The Secure Mail Gateway with GINA Delivery How the SEPPmail Secure E-Mail Gateway works: S/MIME and domain encryption at the gateway, GINA for recipients without keys, its position in the mail flow, LDAP integration and the operational topics from firmware to cluster. Kiteworks / TotemomailEN Totemomail: Email Encryption on the Kiteworks Platform The Totemomail encryption gateway in operation: origins and the takeover by Kiteworks, gateway encryption with S/MIME and PGP, WebMail delivery, LDAP integration, the licensing model based on licensed users, and the M365 integration. Apache James Apache James: servidor de correo modular y plataforma de Mailets Apache James en su contexto técnico: protocolos y funciones de correo, arquitectura basada en componentes, cola y canalización de Mailets, modelo de buzón y almacenamiento, variantes operativas desde PostgreSQL hasta Cassandra y evolución desde el proyecto Java Apache hasta una plataforma de correo para la JVM. Pasarela HINEN HIN: secure email in the Swiss healthcare sector The HIN platform from an operator's perspective: HIN identities and protected mail between healthcare professionals, the HIN Mail Gateway inside an organization's own infrastructure, Access Gateway and client, platform upgrades and their deadlines. Cisco ESA / SMA Cisco Secure Email: Gateway, AsyncOS y SMA Cisco Secure Email para administradores de mensajería: canalización de correo SEG/ESA, listeners, HAT y RAT, cola de trabajo y entrega, políticas de correo, AsyncOS, servicios SMA, límites de clúster, pila tecnológica, monitorización, recuperación y diagnóstico.
IA y automatización
Claude Claude y Claude Code: arquitectura, API y operación segura de agentes Claude y Claude Code para administradores de plataformas, seguridad y automatización: límites de modelos y API, Messages sin estado, bloques de contenido, streaming, Tool Use y MCP, tiempo de ejecución local de agentes, workspaces y claves, límites de tasa, caché, lotes, observabilidad, protección de datos, prompt injection y recuperación. CloudflareEN Cloudflare Workers: serverless at the network edge An overview of Cloudflare's serverless platform: code at the edge instead of on servers, the V8 isolate model, storage services from KV to D1 and R2, bindings and Wrangler, and the limits of the model.
Open source y autoalojamiento
Home AssistantEN Home Assistant: smart home hub with a local focus An overview of the open source smart home platform: local control instead of mandatory cloud, integrations and device connectivity, automations, installation variants, and the role of APIs, tokens, and MQTT. RcloneEN Rclone: The Universal Tool for Cloud Storage An overview of the command-line tool for cloud storage: remotes and backends, the core commands sync, copy and mount, client-side encryption with crypt, and integrity checking by checksum. Proton DriveEN Proton Drive: End-to-End Encrypted Cloud Storage An overview of Proton's cloud storage: end-to-end encryption as its basic principle, origin and ecosystem, clients and platforms, and what a zero-knowledge architecture means for third-party tools and automation. Paperless-ngxEN Paperless-ngx: self-hosted document management An overview of the open source DMS: the consume pipeline from scan to archive, OCR and full-text search, organization through tags, correspondents, and document types, storage architecture, and operation in containers.
Protocolos y estándares
SMTPEN Understanding SMTP: How Email Is Actually Delivered What SMTP is and how mail flow works: envelope and headers, MX delivery, relays and smarthosts, the ports 25, 465 and 587, StartTLS, and the reply codes with which servers justify acceptance and rejection. LDAPEN Understanding LDAP: the directory protocol behind AD, Entra, and mail gateways What LDAP is and how it works: a directory rather than a database, DIT and distinguished names, bind and search, LDAPS vs. StartTLS, and what of that really counts in Active Directory, Entra, and secure mail gateways. DNS DNS: resolución, delegación y operación El sistema de nombres de dominio desde la perspectiva de un administrador: espacio de nombres, zonas y delegación, resolución recursiva, RRsets, caché y TTL, respuestas negativas, UDP y TCP, EDNS, DNSSEC, replicación de zonas y diagnóstico para infraestructuras de mensajería. TCP / redEN TCP and Networking Basics: What Mail Admins Really Need TCP as the foundation of SMTP, LDAP, and HTTPS: connection setup with the three-way handshake, ports and firewalls, typical failure patterns from timeout to connection refused, and the steps for a quick diagnosis. TLS / certificadosEN TLS and Certificates: Trust in Mail and Directory Operations How TLS secures connections and why certificates are the most common cause of outages: handshake, certificate chains and truststores, SAN instead of CN, LDAPS and StartTLS, renewal without downtime. SSHEN SSH: Remote Access, Keys, and Hardening Secure Shell in day-to-day administration: keys instead of passwords, agent and known_hosts, the essential hardening steps for exposed servers, and SFTP as a file transport. KerberosEN Kerberos: tickets, KDC, and authentication in Active Directory How Kerberos works and why Active Directory is built on it: tickets instead of passwords, KDC and TGT, service principal names and keytabs, the time synchronization requirement, and the typical failure patterns.
Seguridad del correo
Cifrado de correoEN Email Encryption: Transport Protection, S/MIME, PGP, and the Gateway Model The layers of email encryption cleanly separated: opportunistic and enforced TLS on the transport, S/MIME and PGP for content, central gateways instead of client-side chaos, and when each level is sufficient. SPF · DKIM · DMARCEN SPF, DKIM, and DMARC: sender authentication in combination The three sender authentication mechanisms and how they work together: what SPF checks, what DKIM signs, how DMARC ties both to the visible sender, and the rollout path from reports to p=reject. Bastionado y accesoEN Hardening and access protection: reducing attack surface in operations The principles behind every hardening checklist: minimize the attack surface, use central instead of local accounts, grant minimal privileges, apply updates consistently, and keep access traceable, from the appliance GUI to the VPS.
Automatización y APIs
PowerShell / GraphEN PowerShell and Microsoft Graph: Automation for Mail Admins The automation layer above Exchange, Entra and Microsoft 365: Exchange Online PowerShell, Microsoft Graph as an API, app registrations with certificate authentication, and where the classic modules are being retired. APIs e integraciones APIs: contratos, identidades y límites de fallo distribuidos APIs para administradores de infraestructura y mensajería: REST, HTTP y JSON, RPC, GraphQL, gRPC y APIs de eventos, OpenAPI y esquemas, OAuth e identidades de carga de trabajo, gateways, tiempos de espera, reintentos, idempotencia, paginación, límites de tasa, webhooks, observabilidad, versionado e historia técnica.
Operación
Versiones y actualizacionesEN Releases and Updates: Patch Operations for Mail Infrastructure How update operations for Exchange, appliances and gateways become plannable: release types from security update to firmware, maintenance windows and rollback paths, reading release notes, and the question of how quickly patching has to happen. Copias de seguridad y recuperación Copia de seguridad y recuperación ante desastres: estados, objetivos y reanudación Copia de seguridad y recuperación ante desastres para administradores de mensajería: diferenciación respecto a instantáneas, replicación y alta disponibilidad; RPO, RTO y MTD; protección coherente de buzones, colas, configuración, claves e índices; recuperación aislada, orden de reanudación, pruebas de restauración y diagnóstico. Migración y plazosEN Migration and deadlines: keeping mail infrastructure life cycles under control Why migrations in the mail environment are almost always driven by deadlines: end-of-support dates, vendor platform renewals, migration patterns from big bang to coexistence, and the checklist for cutover day. Contenedores y Docker Contenedores: imágenes, tiempo de ejecución y operación fiable Contenedores para administradores de infraestructura y mensajería: artefactos OCI, aislamiento del tiempo de ejecución y del kernel, espacios de nombres y cgroups, red y almacenamiento, orquestación, identidad y cadena de suministro, recursos, salud, registro, recuperación, contenedores de Windows e historia técnica. Almacenamiento y sincronizaciónEN Storage and Sync: Cloud Storage in Technical Terms How cloud storage works technically: object storage versus file system, access through sync, copy, and mount, client-side encryption, storage classes from hot to cold, and integrity checking of transferred data. Licencias y límitesEN Licenses and limits: licensing models for infrastructure software How infrastructure software is licensed: named users, devices, and capacity limits, how license counters are fed technically, what happens when a limit is reached, and the role the directory plays in it. Resolución de problemas y diagnósticoEN Troubleshooting and Diagnosis: Systematic Fault Finding in Infrastructure The methodology behind successful fault finding: a layered model from the connection to the application, taking error messages literally, reproducing minimally, correlating changes, and documenting findings. Testing y pruebas de cargaEN Testing and Load Tests: Probing Infrastructure Under Controlled Conditions Methodology for functional and load testing in messaging and infrastructure environments: what to measure, the baseline-burst-soak sequence, load generators and sinks, marking test runs, and evaluating results with percentiles instead of averages.