Why should this be a security issue? If you are a whisteblower or political exposed person then maybe yes.
What is the point in using other services like forwardemail.net which can read your incoming mails in clear text? Isnt that a security issue?
Mailcow itself was designed for exposing it to the internet, with own firewall rules (iptables) and fail2ban (netfilter).
I personally think there are only 2 motivations for running a mail server at home.
Privacy - you want to limit access to your mail content to as few systems/parties as possible. a VPS like you have it is a better alternative because you do not need additional relay services.
Learning - find out how a mailserver works.
If you don’t really care about the 2, and/or do not have time and dedication to maintain a complex mail server, you should better use services like protonmail or mailbox.org, or keep running mailcow on a VPS.