Re: empty MAIL FROM and check_sender_access

2018-09-25 Thread Viktor Dukhovni
> On Sep 25, 2018, at 12:27 PM, Stefan Bauer wrote: > > I notice that only outlook out of all my mail clients, use the null mailer > address. it looks to me after reading the standard - that outlook does it > right. Is that correct? Outlook is perhaps the only one that is actually sending

Re: empty MAIL FROM and check_sender_access

2018-09-25 Thread Stefan Bauer
I notice that only outlook out of all my mail clients, use the null mailer address. it looks to me after reading the standard - that outlook does it right. Is that correct? Am Di., 25. Sep. 2018 um 17:22 Uhr schrieb Viktor Dukhovni < postfix-us...@dukhovni.org>: > > > > On Sep 25, 2018, at 10:13

Re: TLS: Migrate from *encrypt* to *verify* for specific domain

2018-09-25 Thread Viktor Dukhovni
> On Sep 25, 2018, at 11:58 AM, Wietse Venema wrote: > >> As for "soft failure" with "verify" >> (or "secure"), that's not presently supported in Postfix. > > What about using smtp_delivery_status_filter? By "soft failure", I meant the OP's request to deliver anyway and just log a warning.

Re: TLS: Migrate from *encrypt* to *verify* for specific domain

2018-09-25 Thread Wietse Venema
Viktor Dukhovni: > The DANE survey finds 21 domains with DFN-Verein certificates and working > DANE. There are almost certainly some that don't have DANE TLSA records, > but they could if they wanted to. As for "soft failure" with "verify" > (or "secure"), that's not presently supported in

Re: TLS: Migrate from *encrypt* to *verify* for specific domain

2018-09-25 Thread Viktor Dukhovni
> On Sep 25, 2018, at 11:34 AM, Viktor Dukhovni > wrote: > > The DANE survey finds 21 domains with DFN-Verein certificates and working > DANE. There are almost certainly some that don't have DANE TLSA records, > but they could if they wanted to. FWIW, the certificates found among

Re: TLS: Migrate from *encrypt* to *verify* for specific domain

2018-09-25 Thread Viktor Dukhovni
> On Sep 25, 2018, at 9:29 AM, Paul Menzel wrote: > > We want to improve that. Unfortunately, DANE is not an option as the DFN > does not support that, What do you mean by "DFN does not support that"? If by "DFN" you mean "DFN-Verein", their certificates pose no compatibility issues with

Re: empty MAIL FROM and check_sender_access

2018-09-25 Thread Viktor Dukhovni
> On Sep 25, 2018, at 10:13 AM, Stefan Bauer wrote: > > I was more asking if it's even a good idea to add the null entry to the > table? i would like to be a good postmaster but not want to relax policies > for allowed sender addresses. You need to allow mail with null return addresses.

Devendra Fadnavis: Clean drinking municipal water for North West Virar residents

2018-09-25 Thread gwalashish
Hey, I just signed the petition "Devendra Fadnavis: Clean drinking municipal water for North West Virar residents" and wanted to see if you could help by adding your name. Our goal is to reach 224 signatures and we need more support. You can read more and sign the petition here:

empty MAIL FROM and check_sender_access

2018-09-25 Thread Stefan Bauer
I was more asking if it's even a good idea to add the null entry to the table? i would like to be a good postmaster but not want to relax policies for allowed sender addresses. Am Di., 25. Sep. 2018 um 13:26 Uhr schrieb Wietse Venema < wie...@porcupine.org>: > > Stefan Bauer: > > Hi, > > > > I'm

TLS: Migrate from *encrypt* to *verify* for specific domain

2018-09-25 Thread Paul Menzel
Dear Postfix folks, Currently, our `/etc/postfix/tls_policy` looks like below to force encryption when sending messages to other servers in our organization. mpg.deencrypt .mpg.de encrypt We want to improve that. Unfortunately,

Re: empty MAIL FROM and check_sender_access

2018-09-25 Thread Wietse Venema
Stefan Bauer: > Hi, > > I'm using smtpd_sender_restrictions = check_sender_access > hash:/etc/postfix/allowed_sender > > to make sure, my senders only send out with pre-defined and allowed domains. > > Now i noticed, that if my users acknowledge "read confirmations" in > clients, mails in the

empty MAIL FROM and check_sender_access

2018-09-25 Thread Stefan Bauer
Hi, I'm using smtpd_sender_restrictions = check_sender_access hash:/etc/postfix/allowed_sender to make sure, my senders only send out with pre-defined and allowed domains. Now i noticed, that if my users acknowledge "read confirmations" in clients, mails in the following form arrive at postfix: