> >1. all mail from inside goes to this (edge - 1 ) postfix box. > > > >2. if from trusted/don't-scan-it listsen...@domain.tld, then don't go to > >edge/out-MX relayhost, resolve/send directly to Internet.
Use an access map with a nexthop-less FILTER action: FILTER smtp: This requires Postfix 2.7. See note 3 in the access(5) manpage. > >3. if not from listsen...@domain.tld, then send to relayhost. relayhost = [mail.isp.com] Wietse