Mine is pretty secure. I've been running UNIX type mail servers since the .uucp bang path days.It takes only an hour or two to set up a decent Postfix/Dovecot server. It takes about a week to make it bulletproof. I monitor the logs and write custom filters to weed out the attacks de jour.
Did you know that SSL certs are free, now, through Certbot (courtesy of the EFF)? And there's a certbot app in the Ubuntu distribution that makes provisioning them a cinch. The down-side is you are limited to 50 unique certificates per IP -- per week...
