Due to the Spam Quarantine reports using the ticket method, leaving port 8006 open to the public is hard to avoid, and I am concerned with the security of leaving the admin web interface exposed like this.
I want to enable 2FA and Webauthn (to use a Yubikey).
This is not as easy as it seems...