Most mobile ISPs in the UK use Procera Networks (now Sandvine) products that do basic deep packet inspection to filter traffic.
You can allocate users to pools and provide contectivity based on the pool, ie allowing you to limit speeds of high usage users or have different filtering lists like this under 18s list.
With these devices you are able to block traffic to specific domains even if SSL is used with relative ease.
As it is done at network level, you can't bypass via different DNS provider, only vpns can bypass
Not an expert at all, but my basic understanding of GDPR is if you outsource a service to a 3rd party and they collect data or do any processing that they shouldn't, you are essentially responsible.
The response to GDPR is interesting. If they are handling and selling your data in ways that are not compatible with GDPR, then you should seriously consider using someone else for that information.
I've used Virtualmin and Horde for my personal email service. Virtualmin does a very good job configuring Dovecot, Spamassassin, Postfix, DNS, Apache/Nginx, etc and Horde is a very good web client for email, contacts, calaendar etc.
I would definitely recommend using Virtualmin, its a hosting control panel that can control mail/websites/dns in one via a simple control panel.
All works like Plesk, but without breaking everything.
They've got a script that sets up dovecot, postfix, apache, bind, clamav, spamassassin, Mysql, and loads of other hosting software and then you configure every thing via a web interface.
I use a catchall and give different email addresses to everyone. I've received 3 spam emails in the past month to my dropbox account, but they aren't the only ones with problems, for example the following are the number of spams for various sites:
* 2 emails Foursquare
* 6 emails Groupon
* 6 emails Rackspace
* 25+ emails Ticketmaster
* 50+ Absolute Radio (UK Radio station)
Absolute Radio was hacked, not sure about the others.