[pfx] Re: OT: VPS w/FDE suggestions?

2024-02-20 Thread Ansgar Wiechers via Postfix-users
On 2024-02-21 MRob via Postfix-users wrote: [ off-topic ] It never ceases to amaze me how people *know* that what they're posting is off-topic, yet decide it's okay for them to post it anyway if they just label it as off-topic. Hint: it's not. Regards Ansgar Wiechers -- "Abstractions sa

[pfx] Re: check sender trouble

2023-11-17 Thread Ansgar Wiechers via Postfix-users
d by `postconf mynetworks`. If a localpart-only sender address still is accepted: show the output of `postconf -n` and `postconf -M` as well as the transcript of the `telnet` dialog. Regards Ansgar Wiechers -- "Abstractions save us time working, but t

[pfx] Re: check sender trouble

2023-11-17 Thread Ansgar Wiechers via Postfix-users
mynetworks and you should see a response like 504 5.5.2 : Sender address rejected: need fully-qualified address Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky ___ Postfix-u

[pfx] Re: check sender trouble

2023-11-16 Thread Ansgar Wiechers via Postfix-users
, which is allowed. As a side note: Please avoid making up arbitrary domain names for examples. There are official domains reserved specifically for this purpose. See RFC 2606[1] for details. [1]: <https://www.rfc-editor.org/rfc/rfc2606.html> Regards Ansgar Wiechers -- "Abstractio

Re: bagels

2022-08-22 Thread Ansgar Wiechers
On 2022-08-22 Ruben Safir wrote: > On Mon, Aug 22, 2022 at 08:50:51AM +0200, Ansgar Wiechers wrote: >> You could use a check_sender_access restriction with a regular >> expression like this: >> >> /bagel/ REJECT > > Do I use the map created by the postfix/acces

Re: bagels

2022-08-22 Thread Ansgar Wiechers
chored (since all the localparts seem to begin with the word "bagel"): /^bagel.*=(nylxs|mrbrklyn)\.com@/ REJECT Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: matching envelope sender and a certain header

2022-05-23 Thread Ansgar Wiechers
lid with 'v11' and 'v546' > > etc, etc > > Is this possible with postfix? This should be doable with restriction classes [1], but it's probably easier (and more straightforward) to implement it with a policy service like postfwd [2]. [1] http://www.postfix.org/RESTRICTION_CLASS_README.htm

Re: password security

2022-04-27 Thread Ansgar Wiechers
on who successfully brainwashed half the internet into destroying ICMP because "stealth?" *That* Steve Gibson? I *strongly* advise everyone to take *anything* coming from Gibson with two or three handful of salt. At least. The guy is a charlatan at best. Regards Ansgar Wiechers -- "Abst

Re: reject_unknown_helo_hostname

2022-03-29 Thread Ansgar Wiechers
will this test reject the transport when any of those records are > missing, or when the propagated HELO/EHLO domain doesn't have any of > those records? Postfix will reject the connection when neither A nor MX record exists. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: How to use C class IP address?

2021-12-22 Thread Ansgar Wiechers
.239.195/24  but it does not work, if my > address is 88.103.239.2 You need to specify the network address for that network: mynetworks = 88.103.239.0/24 Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: method to discard email with body containing gmail address

2021-11-08 Thread Ansgar Wiechers
However, the abuse of Gmail Reply-To addresses by spammers/scammers is so rampant (at least in my experience) that on my personal mail server I decided to reject everything with a Gmail Reply-To except for whitelisted addresses. Regards Ansgar Wiechers -- "Abstractions save us time working, but

Re: IP ranges in mynetworks

2021-11-04 Thread Ansgar Wiechers
mas and/or whitespace. Continue long lines by starting | the next line with whitespace. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Way to apply a postfix rule to both FROM and TO?

2021-10-18 Thread Ansgar Wiechers
for the sender match and an access map for the recipient match because that worked best for my use cases, but other table combinations should work as well. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Deprecated: white is better than black

2021-02-25 Thread Ansgar Wiechers
e a racist. If not, then I > apologize. But only if you are not. "Taking action" to accomplish ... what exactly? Somebody please explain to me whose life got improved in any way by replacing the words "whitelist" and "blacklist" with "allowlist" and "de

Re: Restrict clients (IP address) to send outbound email

2021-01-06 Thread Ansgar Wiechers
192.168.17.0/24 local_only ... >8 8< # /etc/postfix/local_domains foo.example.org OK bar.example.org OK ... ---->8 Regards Ansgar Wiechers -- "All vulnerabilities deserve a public fear period prior to patches becoming available." --Jason Coombs on Bugtraq

Re: Sender address rejected: Domain not found

2021-01-05 Thread Ansgar Wiechers
ost server.cointalk.com Host server.cointalk.com not found: 3(NXDOMAIN) Postfix rejects the mail because it cannot resolve the sender domain. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: not an open relay, but something happened

2020-12-15 Thread Ansgar Wiechers
On 2020-12-15 Jeff Abrahamson wrote: > On 15/12/2020 12:36, Ansgar Wiechers wrote: >> Spoofing the envelope from address (Return-Path: ) is >> actually valid (per the SMTP protocol) and a common occurrence for >> mail sent by bad actors. > > Is prohibiting spoofing enve

Re: not an open relay, but something happened

2020-12-15 Thread Ansgar Wiechers
nt senders from spoofing the envelope from address: Return-Path: It does not affect the From: header in the mail: From: p27.eu You need a spam filter if you want to address that as well. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Rejecting messages based on recipient MTA''s IP address

2020-10-01 Thread Ansgar Wiechers
ion-5.1> If a domain should never receive mail it's better to define a null MX for that domain (see RFC 7505). <https://tools.ietf.org/html/rfc7505> Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Checking from-addresses on outbound mail

2020-08-09 Thread Ansgar Wiechers
sual filters don't apply to that. What you can do is disable pickup entirely so that even local users are required to submit mail via SMTP (on localhost). Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Using Postfix sendmail without having Postfix daemon running all the time?

2020-08-06 Thread Ansgar Wiechers
URATION_README.html#null_client [1]: https://www.systutorials.com/sending-email-using-mailx-in-linux-through-internal-smtp/ Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: re-directing disto-pkg'd postfix's bins etc to other config dir location?

2020-07-19 Thread Ansgar Wiechers
implements. If for some reason you must use the pre-packaged Potfix but still have /usr/local/etc/postfix just create it as a symlink to /etc/postfix, not the other way 'round. Regards Ansgar Wiechers -- "All vulnerabilities deserve a public fear period prior to patches becoming available." --Jason Coombs on Bugtraq

Re: The historical roots of our computer terms

2020-06-08 Thread Ansgar Wiechers
On 2020-06-08 John Dale wrote: > Why does this agitate people? Because the whole Political Correctness/Social Justice thing has devolved into a religion. Thus all heathens must convert to this faith or burn at the stake. Regards Ansgar Wiechers -- "Abstractions save us time

Re: smtp servers port

2020-05-29 Thread Ansgar Wiechers
r a specific next hop that port will be used. Of course an MTA can also use submission to send to a next-hop MTA if the latter supports that (since the sending MTA is acting as a client there), but you would need to specifically configure that on the sender. Regards Ansgar Wiechers -- "

Re: discard(8) in a virtual mailbox environment

2020-05-28 Thread Ansgar Wiechers
;example.org" with your virtual mailbox domain and "example.com" with the local domain of the mail server. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: delaying postfix until/unless VPN is up/connected

2020-04-17 Thread Ansgar Wiechers
reload > > > fi;; > > > esac > > > done > > > > Sorry to bring this up after a while, but I have been trying this code, > > but seem to hit a syntax error: > > > > line 10: [: : integer expression expected > > > > > > Line10: i

Re: STMP is rejecting and i'm not sure why

2020-04-03 Thread Ansgar Wiechers
ages were stored into disk by encrypted? AFAIK individual queued messages can't be encrypted, but you can certainly encrypt the volume where the queue is located. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Using Postfix to send home server alerts

2020-02-14 Thread Ansgar Wiechers
ge.com/tutorial/configure-postfix-to-use-gmail-as-a-mail-relay/> Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Are there plans for a buld-in support of REDIS-tables?

2020-01-09 Thread Ansgar Wiechers
would prefer redis over memcache, since it supports > replication/syncronisation over multiple servers. I would recommend using a configuration management system like Puppet, Ansible, Chef, ... for deploying tables across multiple servers instead of replicating the information with something

Re: Broken Resource Links

2019-12-31 Thread Ansgar Wiechers
to a more > permanent location, or at least update the links. https://www.planetcobalt.net/patrick.koetter/saslfinger/ https://www.planetcobalt.net/patrick.koetter/smtpauth/ I adjusted links where it seemed appropriate. If I made a mistake somewhere please let me know. Regards Ansgar Wiechers

Re: postfix filter to encrypt incoming emails with public gpg key

2019-10-27 Thread Ansgar Wiechers
rough an encrypted transport channel and never store it on disk, an attacker who has gained control of the server can still intercept the message. [1]: https://www.planetcobalt.net/sdb/crypter.shtml Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: outbound.protection.outlook.com

2019-10-02 Thread Ansgar Wiechers
On 2019-10-02 ratatouille wrote: > Do I really have to whitelist all the IPs of > outbound.protection.outlook.com in postgrey? No. You could simply stop graylisting and instead use spam protection measures without its side effects (e.g. postscreen). Regards Ansgar Wiechers -- "Abstra

Re: Debug log level configuration

2019-03-28 Thread Ansgar Wiechers
describe the actual problem you're trying to solve instead of what you perceive as the solution. Debug logging in Postfix should not be required for any normal troubleshooting. What do you think you need this for exactly? Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: stress tested postfix

2019-03-06 Thread Ansgar Wiechers
or delivery and then then somehow discards it. What you have presented so far are allegations at best, without any actual proof. Logs are always a good start for digging into issues like this. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Canonical?

2019-01-01 Thread Ansgar Wiechers
sus hosted versus other domains" section of the document: http://www.postfix.org/VIRTUAL_README.html#canonical Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: block sender/receiver pairs

2018-08-27 Thread Ansgar Wiechers
...@example.org rc_foo >8 In foo_sender_access: 8< b...@example.com REJECT Mail not accepted. some...@example.net REJECT Mail not accepted. >8 Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Reject mails coming from mailservers whos reverse DNS resolution match a certain pattern

2018-08-26 Thread Ansgar Wiechers
etworks permit_sasl_authenticated reject_unauth_destination ... check_client_access pcre:/etc/postfix/client_access.pcre ... and define the offending domain in that file: /\.artegic\.net$/ REJECT Not accepting mail from your domain. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: many le ssl certs assigned to postfix

2018-05-28 Thread Ansgar Wiechers
Please do not reply off-list. On 2018-05-28 Poliman - Serwis wrote: > 2018-05-28 13:18 GMT+02:00 Ansgar Wiechers <li...@planetcobalt.net>: >> On 2018-05-28 Poliman - Serwis wrote: >>> Thank you for advices but how setup different SMTP in MX record if >>> MX re

Re: many le ssl certs assigned to postfix

2018-05-28 Thread Ansgar Wiechers
mailservers with different priority. > I would like to underline I could not understand you properly. MX records only ever specify the servers designated for RECEIVING INBOUND mail for a domain. They say nothing about POP or IMAP (or which servers will handle outbound mail for that matter).

Re: Zimbra Red Hat repositories

2018-05-06 Thread Ansgar Wiechers
imbra mailing list. Did you try the Zimbra documentation? Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Question regarding use of amavisd-new

2017-12-13 Thread Ansgar Wiechers
g they might be subject to change anytime without prior notice). Hence MailScanner is not supported and not recommended with Postfix, regardless of whether it does or doesn't work right now. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Bypass restrictions for postmaster/abuse

2017-03-09 Thread Ansgar Wiechers
EADME.html#danger This is probably just personal preference, but in addition to whitelisting postmaster recipients I put a client blacklist before the whitelist where I block all clients who deemed sending spam to a postmaster address a good idea. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: similar email address to one account?

2017-02-12 Thread Ansgar Wiechers
shortname: myname save and run `newaliases`. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Open relay

2016-10-23 Thread Ansgar Wiechers
you may want to disable verbose logging for the smtpd on port 25. Remove the "-v" from this line in master.cf: > smtp inet n - - - - smtpd -v Verbose logging is only required in very specific debugging scenarios and wont do you any good for regular operations or troubleshooting. Regards Ansgar Wiechers

Re: Blocking TLDs

2016-02-21 Thread Ansgar Wiechers
ou're located and whose mail you're handling. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: Can Postscreen and Smapassassin be used together

2015-09-10 Thread Ansgar Wiechers
is rather heavyweight whereas Postscreen was designed to be a lightweight zombie deflection tool. You'd lose that low resource impact advantage by mixing the two. Regards Ansgar Wiechers -- "Abstractions save us time working, but they don't save us time learning." --Joel Spolsky

Re: postfix setup best practice question

2015-08-27 Thread Ansgar Wiechers
to restrict PTR records to a single name. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Do smtpd_milters apply before smtpd_client_restrictions?

2015-06-21 Thread Ansgar Wiechers
-archive.com/postfix-users@postfix.org/msg65583.html Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Tracing why there's a NDN

2015-04-17 Thread Ansgar Wiechers
the spamass-milter run before postscreen? If not, can it? Postscreen was created as a lightweight protection against spam bots. It would be utterly pointless to run it after heavyweight spam protection measures like Spamassassin. Regards Ansgar Wiechers -- Abstractions save us time working

Re: Duplicate suppression and address verification

2015-04-16 Thread Ansgar Wiechers
the MTA correctly receives and delivers two separate transmissions (one for group1, the other for group2). Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: detecting encryption for outgoing mail

2015-02-16 Thread Ansgar Wiechers
/crypter.shtml Run it as a daemon and configure it as a relayhost for your Postfix. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Temporarily block all messages from a particular IP

2015-01-20 Thread Ansgar Wiechers
for the source IP * check_sender_access s/_sender_/_client_/ Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Input requested: append_dot_mydomain default change

2014-09-24 Thread Ansgar Wiechers
On 2014-09-23 A. Schulze wrote: wietse: Dammit, I want to hear from people who expect to have problems or not. OK, I don't expect problems for /my/ systems because I already explicit set 'append_dot_mydomain = no'. Same here. Regards Ansgar Wiechers -- Abstractions save us time working

Re: Selected `RCPT TO:' addresses allowed only from SASL authenticated?

2014-08-23 Thread Ansgar Wiechers
for the reject_sender_login_mismatch restriction[1]. See section Envelope sender address authorization in the SASL README[2] for details. [1] http://www.postfix.org/postconf.5.html#reject_sender_login_mismatch [2] http://www.postfix.org/SASL_README.html Regards Ansgar Wiechers -- Abstractions save us time

Re: improving logging

2014-05-26 Thread Ansgar Wiechers
database row also the blacklist check, spam score and antivirus info ? Postfix logs to syslog and syslog (rsyslog at least) can be configured to write to MySQL instead of files. See [1] for details. [1] http://www.rsyslog.com/doc/rsyslog_mysql.html Regards Ansgar Wiechers -- Abstractions save us time

Re: Need a main.cf file for virtual users

2014-04-17 Thread Ansgar Wiechers
, we're not here to read the documentation to you. Please do your homework yourself. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: smtpd_proxy_filter TLS

2014-04-08 Thread Ansgar Wiechers
in smtpd_proxy_filter setup? Are Postfix and amavis running on different hosts? Otherwise don't bother. Encrypting connections on localhost is just a waste of system resources. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: New server, still older software, minimal configuration (connect / disconnect from unknown)

2014-03-25 Thread Ansgar Wiechers
should not? I have no idea, what i should fix :-( Some host connects to your mail server, then disconnects from your mail server. Apparently without doing anything else. What problem do you perceive here that would require fixing? Regards Ansgar Wiechers -- Abstractions save us time working

Re: New server, still older software, minimal configuration (connect / disconnect from unknown)

2014-03-25 Thread Ansgar Wiechers
On 2014-03-25 postfix-users@postfix.org wrote: Ansgar Wiechers wrote: On 2014-03-25 postfix-users@postfix.org wrote: I was suspecting this already: Mar 25 12:16:56 HOSTNAME postfix/smtpd[6243]: connect from unknown[180.93.167.227] Mar 25 12:16:58 HOSTNAME postfix/smtpd[6243]: disconnect

Re: confused about virtual_mailbox_domains parameter

2014-03-18 Thread Ansgar Wiechers
about the actual problem in tons of unrelated information. See here for more information on reporting problems to this list: http://www.postfix.org/DEBUG_README.html#mail Regards Ansgar Wiechers -- All vulnerabilities deserve a public fear period prior to patches becoming available. --Jason

Re: Finding source of illegal address from localhost

2014-02-24 Thread Ansgar Wiechers
: -timeshare.escape.artist-user=example@atcturbo.com The leading hyphen is what makes the address illegal. To allow addresses starting with a hyphen set allow_min_user = yes in main.cf. http://www.postfix.org/postconf.5.html#allow_min_user Regards Ansgar Wiechers -- Abstractions save us time

Re: Fwd: Header_checks

2014-01-10 Thread Ansgar Wiechers
, so you can't conditionally check To: and From: header in the same rule. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: tls_eecdh_*_curve

2014-01-05 Thread Ansgar Wiechers
://crypto.stackexchange.com/questions/10263/should-we-trust-the-nist-recommended-ecc-parameters german Fefe blogged about this back in September. https://blog.fefe.de/?ts=acceb732 /german Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel

Re: Design details of high performance dovecot cluster

2013-12-06 Thread Ansgar Wiechers
scenario. (If needed we can buy additional hardware like load balancer). This is a dovecot-related question, which is off-topic for the Postfix mailing list. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: can not telnet,can not send mail

2013-11-25 Thread Ansgar Wiechers
]:25: Connection timed out) command just like telnet mail.example.com 25 Trying IP... Looks to me like your provider is blocking outbound connections to port 25/tcp. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Catch-all virtual alias

2013-11-11 Thread Ansgar Wiechers
you're doing. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Catch-all virtual alias

2013-11-10 Thread Ansgar Wiechers
found in it: f...@example.com f...@example.net b...@example.com b...@example.net ... This can be done with a Makefile or some other script. [1] http://www.postfix.org/VIRTUAL_README.html Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel

Re: Convert all envelope ids to lowercase

2013-11-07 Thread Ansgar Wiechers
tolower() function calls in all reporting modules Localparts are not case-insensitive. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: What is causing this mail forwarding loop bounce?

2013-10-15 Thread Ansgar Wiechers
/XUYR4ZDe Please do not enable verbose logging unless specifically asked to. Normal Postfix logging usually suffices for troubleshooting delivery problems. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: smtpd_data_restrictions - catching aliases with regexp?

2013-10-01 Thread Ansgar Wiechers
to the alias - mai...@example.com - and includes orig_to (see below) the mail is not being DISCARDed. Can anyone tell me the correct way to do this? Remove the aliases pointing to devn...@example.com. Problem solved. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us

Re: Restrict

2013-09-18 Thread Ansgar Wiechers
that only internally, i.e. on our domain. Can anyone send me a link to the official documentation, or an example on how to do this. I think reject_sender_login_mismatch is what you're looking for. http://www.postfix.org/postconf.5.html#reject_sender_login_mismatch Regards Ansgar Wiechers

Re: Anyone use this email server configuration ?

2013-09-02 Thread Ansgar Wiechers
server, but it can not be encrypted when you send it out to another server, which pretty much breaks any concept of NSA-proof email. Read again. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: reject_unknown_client_hostname and 450s

2013-06-30 Thread Ansgar Wiechers
is insignificant? I'd say fail2ban is the way to go about this. If you want to be on the safe side, make the threshold somewhat higher and extend the lockout period. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Virtual Hosting (Ubuntu 12.04)

2013-06-25 Thread Ansgar Wiechers
bugged all the time as it is. You're mistaken. example.com, example.net and example.org as well as the TLDs .test, .example, .invalid and .localhost were reserved for this exact purpose. See RFC 2606 [1]. [1] http://www.ietf.org/rfc/rfc2606.txt Regards Ansgar Wiechers -- Abstractions save us

Re: Is this an attack?

2013-06-19 Thread Ansgar Wiechers
Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Using TLS for certain domains

2013-06-12 Thread Ansgar Wiechers
or remove any linebreaks. They just modify how the text is displayed. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: postfix.org != www.postfix.org ?

2013-06-05 Thread Ansgar Wiechers
@iridium:~ $ host -t a postfix.org postfix.org has no A record Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: postfix.org != www.postfix.org ?

2013-06-05 Thread Ansgar Wiechers
On 2013-06-05 Steve Jenkins wrote: On Wed, Jun 5, 2013 at 2:11 AM, Ansgar Wiechers li...@planetcobalt.netwrote: mod_rewrite wouldn't help with this, because there is no domain A record for postfix.org. cobalt@iridium:~ $ host -t a postfix.org postfix.org has no A record It's not like

Re: virtual user (unknown user)

2013-05-18 Thread Ansgar Wiechers
an unix user :=) Quoting from the original mail: After read many howto I try to use virtual user. He seems to want fred to be a virtual (mailbox) user. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: virtual user (unknown user)

2013-05-18 Thread Ansgar Wiechers
On 2013-05-18 Benny Pedersen wrote: Ansgar Wiechers skrev den 2013-05-18 17:27: He seems to want fred to be a virtual (mailbox) user. in that case he should not list fuckaround dot org in mydestination, but in virtual_mailbox_domains No, he shouldn't. Please carefully re-read his mail. He

Re: virtual hosting problem

2013-05-18 Thread Ansgar Wiechers
server is the final destination. $relay_domains is for relaying mail for domains that your server is NOT the final destination of. Do NOT mix the two. Remove $mydestination from $relay_domains. Restart Postfix after you applied these changes. Regards Ansgar Wiechers -- All vulnerabilities deserve

Re: virtual user (unknown user)

2013-05-16 Thread Ansgar Wiechers
a proper entry for the address in /etc/postfix/vmailbox. All of this is explained rather well in the documentation[1]. [1] http://www.postfix.org/VIRTUAL_README.html Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: virtual user (unknown user)

2013-05-16 Thread Ansgar Wiechers
removed the line from /etc/postfix/virtual? What is the output of the following commands: postmap -q f...@nuvolabianca.org hash:/etc/postfix/virtual postmap -q f...@nuvolabianca.org hash:/etc/postfix/vmailbox Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us

Re: Reject emails except some inside a list

2013-05-04 Thread Ansgar Wiechers
: userA: userA userB: userB ... Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Too much traffic

2013-04-02 Thread Ansgar Wiechers
that route. For further help post the output of postconf -n (as requested per the list welcome message) and the abovementioned log excerpt. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: smtpd_sender_restrictions some help needed

2013-03-17 Thread Ansgar Wiechers
to use a policy service. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: a few questions:new to postfix

2013-03-15 Thread Ansgar Wiechers
Please keep this on-list. I'm not doing personal support for free. On 2013-03-14 Littlefield, Tyler wrote: On 3/14/2013 2:51 AM, Ansgar Wiechers wrote: On 2013-03-13 Littlefield, Tyler wrote: I'd also like to be able to use procmail on these. Procmail is designed for local delivery. It looks

Re: a few questions:new to postfix

2013-03-14 Thread Ansgar Wiechers
/ADDRESS_CLASS_README.html [2] http://standish.home3.org/virtual-procmail Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Virtual domain and masquerading

2013-03-14 Thread Ansgar Wiechers
configuration on the other servers. That's what configuration management was invented for. You may want to look into puppet et al. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Postfix Config -- Need assisance

2013-03-14 Thread Ansgar Wiechers
that RFC you must enable authentication on that port. Also, do *not* enable verbose logging (-v) unless specifically asked to do so. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: LDA understanding

2013-03-14 Thread Ansgar Wiechers
using a pre queue filter because it results in become a backscatter and you are usually not permitted by law accept a message with 250 OK and drop it silent That would be a post-queue filter. A pre-queue filter rejects, so you don't become a backscatter source. Regards Ansgar Wiechers

Re: Postfix being an ass: Relay access denied when rcpt to: is issued

2013-03-13 Thread Ansgar Wiechers
, otherwise you're prone to becoming an open relay. Also put all restrictions under $smtpd_recipient_restrictions. Unless you set smtpd_delay_reject = no (which you shouldn't) the result will be the same, and it's easier to maintain this way. Regards Ansgar Wiechers -- Abstractions save us time

Re: Postfix being an ass: Relay access denied when rcpt to: is issued

2013-03-13 Thread Ansgar Wiechers
On 2013-03-13 Viktor Dukhovni wrote: On Wed, Mar 13, 2013 at 01:48:57PM +0100, Ansgar Wiechers wrote: Mar 12 17:13:01 mediaserver postfix/smtpd[12785]: NOQUEUE: reject: RCPT from ip68-227-115-116.ok.ok.cox.net[68.227.115.116]: 451 4.3.5 recipi...@domain.com: Recipient address rejected: Server

Re: Postfix being an ass: Relay access denied when rcpt to: is issued

2013-03-13 Thread Ansgar Wiechers
a hash table hash:/etc/postfix/filtered_domains, but neglected to actually create it. You probably just created the text file /etc/postfix/filtered_domains without converting it to an actual hash table. Run postmap /etc/postfix/filtered_domains. Regards Ansgar Wiechers -- Abstractions save us time

Re: Postfix being an ass: Relay access denied when rcpt to: is issued

2013-03-12 Thread Ansgar Wiechers
as well as an excerpt from your mail log demonstrating the problem. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Our postfix works fine, but it is very slow when we send newsletter

2013-02-20 Thread Ansgar Wiechers
is. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Relay access denied

2013-01-18 Thread Ansgar Wiechers
On 2013-01-17 Muzaffer wrote: On 17 January 2013 18:40, Ansgar Wiechers li...@planetcobalt.net wrote: On 2013-01-17 Muzaffer wrote: I've just found out a virtual file in the format u...@example.com example doesn't work with virtual_alias_domains. Guess I need to find another solution

Re: Relay access denied

2013-01-17 Thread Ansgar Wiechers
doesn't work with virtual_alias_domains. Guess I need to find another solution. Please describe in more detail what you're trying to achieve. Given this little information it's highly unlikely anyone could come up with a satisfactory solution/recommendation. Regards Ansgar Wiechers

Re: abusive language by Reindl

2013-01-14 Thread Ansgar Wiechers
. Regards Ansgar Wiechers -- Abstractions save us time working, but they don't save us time learning. --Joel Spolsky

Re: Simplest approach to full-adress aliases?

2012-11-17 Thread Ansgar Wiechers
/VIRTUAL_README.html Regards Ansgar Wiechers -- All vulnerabilities deserve a public fear period prior to patches becoming available. --Jason Coombs on Bugtraq

  1   2   3   4   >