3) Just run email on it. If you do run a webserver on the same server, DON'T RUN PHP! In my experience [1] the single most abused attack vector on webservers is PHP and about 60% of the time it's abused to install spam sending software on the server and that leads to the IP address getting marked as a spammer.