This could be an option but a little cumbersome to keep updated perhaps?
Debian on auto update with minimal packages lasts for years
Another option that I’m using is this:
- I do a encrypted backup with Borg on a separate drive on my server
- On my work desktop PC, Windows, at boot it connects via ssh and syncs that Borg backups on a new HDD that I purchased and installed, one way sync, silently and without prompts (We are a small business and I am allowed to do that, if you’re not allowed to do that it could be your parents PC)
- Success syncs are pinged to healthchecks.io which emails me if after too many days (configurable) the sync hasn’t been completed
- Errors are also sent to healthchecks.io
- Company group policy settings then keeps my backup server automatically updated
I set the mail server to bounce everything that doesn’t match dkim.
I almost don’t receive spam anymore.
The problem is that sometimes some legitimate services didn’t configure their email server correctly