Matthew Selsky:
> smtpd_relay_restrictions =
> permit_mynetworks
> check_client_access ${cidr}tag-cloud-email-providers.cidr
> permit_tls_clientcerts
> reject
>
> tag-cloud-email-providers.cidr contains:
> [...]
> 209.85.128.0/17 PREPEND X-Gmail-Tenant: TRUE
> [...]
The above allows a recipient only it it satisfies permit_mynetworks
or permit_tls_clientcerts.
Perhaps you can try this:
smtpd_relay_restrictions =
permit_mynetworks
check_client_access ${cidr}tag-cloud-email-providers.cidr
permit_tls_clientcerts
reject_unauth_destination
That will permit mail that your system is primary MX for.
Note that there is an implicit 'permit' at the end.
Wietse