[pfx] Re: long header folding and DKIM fails

2024-05-02 Thread Bill Cole via Postfix-users
. This can be done with a milter like MIMEDefang or MailMunge which let you do arbitrary things to messages at each step in the mail flow. I have used this to debug similar problems with signing and Sendmail's not-so-obvious mods to messages based on mailer flags. -- Bill Cole b...@scconsult.com

[pfx] Re: reliable RBL

2024-04-11 Thread Bill Cole via Postfix-users
cussion in the SA community of deprecating sa-compile, although no concrete action has been taken to do so. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire _

[pfx] Re: reliable RBL

2024-04-11 Thread Bill Cole via Postfix-users
with it. Were I to set up a new mail system today without legacy reliance on SA, I would probably try using rspamd just to learn about it. Regards. On Wed, Apr 10, 2024 at 10:23 PM Bill Cole via Postfix-users < postfix-users@postfix.org> wrote: On 2024-04-10 at 05:46:36 UTC-0400 (Wed, 10 Ap

[pfx] Re: reliable RBL

2024-04-10 Thread Bill Cole via Postfix-users
NSBL choices carefully and with an understanding of your users and their needs. You may want to consider using them in a more complex filtering tool like SpamAssassin where it is possible to weight the impact of different DNSBLs to fit your needs and to make explicit direct exemptions if you like. -- Bill Cole b...@

[pfx] Re: sender_login_maps and dovecot and roundcube

2024-03-29 Thread Bill Cole via Postfix-users
what I'm missing here. ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com ad

[pfx] Re: collect emails in maildir folder without delivering them to user

2024-03-20 Thread Bill Cole via Postfix-users
aildir in my account. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an

[pfx] Re: postfix not working with squarespace domains

2024-03-17 Thread Bill Cole via Postfix-users
to the behemoth mailbox providers and other frustrations. I will not tell you to give up but you should understand that it is far more difficult to do this today than it was a decade or two ago. Most people can be better served by a good experienced mail provider than by their own efforts. -- Bill

[pfx] Re: Ignoring postscreen DNSBL disposition by recipient address

2024-03-17 Thread Bill Cole via Postfix-users
s explicit design intent. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe sen

[pfx] Re: Ignoring postscreen DNSBL disposition by recipient address

2024-03-16 Thread Bill Cole via Postfix-users
need to do it later in the SMTP transaction. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users

[pfx] Re: A functional lightweight reverse alias?

2024-03-04 Thread Bill Cole via Postfix-users
ow MailMate. I reply to a message with an X-Original-To header and the MUA uses that address to compose and send the message. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Avai

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Bill Cole via Postfix-users
0 virtual_alias_domains = hash:/etc/postfix/virtual_domains virtual_alias_maps = hash:/etc/postfix/virtual_users ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org -- Bill Co

[pfx] Re: Postfix gmail relay SASL authentication failed invalid parameter supplied

2024-02-28 Thread Bill Cole via Postfix-users
have created a apps password* > > *In the file /etc/postfix/sasl_passwd* > [smtp.gmail.com]:587 nuno.catar...@.pt: The error indicates that the password and/or username were incorrect. I believe you need to remove any spaces in the GMail app password. -- Bill Col

[pfx] Re: rbl bounces email that has both rbl_override and client_checks whitelisting

2024-02-28 Thread Bill Cole via Postfix-users
. Their usage is determined by the specific restriction directive referencing them. So you could have 'check_sender_access hash:/etc/postfix/any_name_you_like' and Postfix will use that file, as long as you populate it with access entries and 'postmap' it to create the .db file. -- Bill Cole b

[pfx] Re: rbl override doesn't work perhaps due to sender using relay

2024-02-24 Thread Bill Cole via Postfix-users
, but sometime needed) you need to use check_sender_access. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users

[pfx] Re: postfix alternating between mail.example.com and real hostname?

2024-02-12 Thread Bill Cole via Postfix-users
ostfix.org/DEBUG_README.html#mail in the section titled "Reporting problems to postfix-users@postfix.org" -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___

[pfx] Re: Understanding log entries

2024-02-10 Thread Bill Cole via Postfix-users
> it continues to retry periodically. From the text, it appears that this > should be a permanent failure, not temporary. Is the receiving MTA confused > or am I? It's a quirk of Telekom. They reject with 554 at connect when they dislike your IP. In my experience, the email address in the

[pfx] Re: ARC or DKIM or SRS?

2024-02-08 Thread Bill Cole via Postfix-users
in postscreen(8) which are described in the "AFTER 220 GREETING TESTS" section of its man page, it must send a 4xx reply to passing clients and hope that they come back within the positive cache timeout. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpyboz

[pfx] Re: Is there a way to reject an internal domain on our border MXes

2024-02-03 Thread Bill Cole via Postfix-users
ks.pcre: [...] /^.*@zimbra.example.org$/ privdom [...] privdom-allow: .example.orgDUNNO 192.0.2 DUNNO Where 192.0.2.0/24 is your privileged network and you want to allow anyone on that network or any client with a verified hostname under example.org. -- Bi

[pfx] Re: Problems with round-robin outbound emails

2024-01-31 Thread Bill Cole via Postfix-users
s handled by 20 mx.b.locaweb.com.br. # host 186.202.157.79 Host 79.157.202.186.in-addr.arpa. not found: 3(NXDOMAIN) On 31.01.24 09:43, Bill Cole via Postfix-users wrote: So if your load balancer isn't at 186.202.157.79, the hosts behind it should not be announcing themselves as xpto.co

[pfx] Re: Are multiple white spaces allowed in a date in headers?

2024-01-31 Thread Bill Cole via Postfix-users
endly. E.g. syslog-generated log files do that. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@p

[pfx] Re: Problems with round-robin outbound emails

2024-01-31 Thread Bill Cole via Postfix-users
support on issues directly related to specific IPs being blocklisted is trying to get their spambots working. There's absolutely no excuse for it in 99% of cases and it leads to random pointless speculation. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scc

[pfx] Re: [postfix] 3.4.23: virtual, pipe and ${original_recipient} vs. ${recipient}

2024-01-25 Thread Bill Cole via Postfix-users
It doesn't. The argument to '-u' is a key to identify a user-specific ruleset. The spamc too (and SA generally) has no mechanism to split envelopes or to provide multiple responses to a single submission. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpyboz

[pfx] Re: Enabling TLS1.3 and allow sending over SMTPS/465

2024-01-22 Thread Bill Cole via Postfix-users
RV records for SMTPS, forcing every MTA to replace its whole DNS logic. Also, the info disclosure of MTA-MTA STARTTLS vs implicit TLS is less meaningful than it is for MUA-MTA, where it exposes end user info. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpyboz

[pfx] Re: Enabling TLS1.3 and allow sending over SMTPS/465

2024-01-22 Thread Bill Cole via Postfix-users
recollection that the root cause was a remarkably stupid issue involving the formal certification. Also worth noting: OpenSSL 1.1.1 is obsolete and has no upstream support. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses

[pfx] Re: improper command pipelining

2024-01-15 Thread Bill Cole via Postfix-users
16\221\311\000\212\000\026\0003\000g\300\236\300\242\000\236\0009\000k\300\237\300\243\000\237 ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org -- Bill Cole b...@scconsult.com o

[pfx] Re: Incoming mail server blocks outlook / microsoft servers

2024-01-10 Thread Bill Cole via Postfix-users
utlook.com clients before any DNSBL checks (in the same restriction list.) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users ma

[pfx] Re: SMTP Smuggling, workarounds and fix

2024-01-04 Thread Bill Cole via Postfix-users
(false positive) bystanders get no clue of any trouble. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users

[pfx] Re: How to configure lmtp delivery

2023-12-31 Thread Bill Cole via Postfix-users
ransport defined in master.cf so that you can use it in *_transport directive in main.cf. The Dovecot "lmtp" is the LMTP server side. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com add

[pfx] Re: omitting the X-Google-Original-From header

2023-12-19 Thread Bill Cole via Postfix-users
On 2023-12-18 at 17:15:16 UTC-0500 (Mon, 18 Dec 2023 23:15:16 +0100) Steffen Nurpmeso via Postfix-users is rumored to have said: Bill Cole via Postfix-users wrote in <6039ed61-2c8f-4a12-b736-994d32632...@billmail.scconsult.com>: |On 2023-12-17 at 09:27:36 UTC-0500 (Sun, 17 Dec 2023 06

[pfx] Re: Postfix authenticated sender and From: header verification

2023-12-18 Thread Bill Cole via Postfix-users
the researcher mentions, we were not able to actually reproduce This is unsuprising. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users

[pfx] Re: omitting the X-Google-Original-From header

2023-12-17 Thread Bill Cole via Postfix-users
hat header. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to pos

[pfx] Re: PATCH: using Milter to change a PREPENDed header

2023-12-13 Thread Bill Cole via Postfix-users
d score appropriately, if you feel that necessary. In my opinion that's not worthwhile because SA will do its own SPF check and if something else has just done the needed DNS queries, they'll still be in cache. Very fast. -- Bill Cole b...@scconsult.com or billc...@apache

[pfx] Re: printer ip SMTP AUTH / mynetworks question

2023-12-13 Thread Bill Cole via Postfix-users
ity of your MTA, but why? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscri

[pfx] Re: Milter own Postfix-prepended Received

2023-12-11 Thread Bill Cole via Postfix-users
On 2023-12-11 at 09:37:39 UTC-0500 (Mon, 11 Dec 2023 15:37:39 +0100) Carlos Velasco via Postfix-users is rumored to have said: Bill Cole via Postfix-users escribió el 11/12/2023 a las 15:31: On 2023-12-10 at 16:37:16 UTC-0500 (Sun, 10 Dec 2023 22:37:16 +0100) Carlos Velasco via Postfix-users

[pfx] Re: Milter own Postfix-prepended Received

2023-12-11 Thread Bill Cole via Postfix-users
ked since it was created and semi-documented by Sendmail Inc. It is de facto controlled by the current developers of Sendmail, but I don't believe anyone is working to make Milter better, at least not in ways that would break compatibility. -- Bill Cole b...@scconsult.com or billc...@apach

[pfx] Re: Milter own Postfix-prepended Received

2023-12-11 Thread Bill Cole via Postfix-users
. When used as a milter, it works with what Postfix provides it (the relevant macros) to construct a Received header for SA. All of this is documented accurately. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses

[pfx] Re: postsrsd

2023-12-06 Thread Bill Cole via Postfix-users
cketmap error should be able to generate from the service side, as opposed to Postfix itself. How is your disk space doing? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currentl

[pfx] Re: Some TLS connections untrusted in postfix but trusted with posttls-finger

2023-11-30 Thread Bill Cole via Postfix-users
. You can probably make it work for this case with suitable special-casing in your configuration, but your configuration is a total mystery to us... Also, I wouldn't consider it a worthwhile effort for most systems, but that's your call for your environment. -- Bill Cole b...@scconsult.com

[pfx] Re: [ext] gmail failing SPF/DKIM

2023-11-28 Thread Bill Cole via Postfix-users
behavior. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email

[pfx] Re: gmail failing SPF/DKIM

2023-11-28 Thread Bill Cole via Postfix-users
= ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses

[pfx] Re: Postfix authenticated sender and From: header verification

2023-11-28 Thread Bill Cole via Postfix-users
to thwart analysis) is a complicated and potentially dangerous task. As a transport agent, Postfix should not be spending the resources or taking the risk of such analysis. It is much safer to delegate that analysis to specialized external software. -- Bill Cole b...@scconsult.com or billc

[pfx] Re: www.postfix.org outage

2023-11-22 Thread Bill Cole via Postfix-users
) makes sense for physical hosts AND they may go a very long time between upgrades & reboots. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For

[pfx] Re: Odd error

2023-11-21 Thread Bill Cole via Postfix-users
sible for anyone here to even guess which one without the debugging info suggested here: http://www.postfix.org/DEBUG_README.html#mail -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Av

[pfx] Re: Spamc no such file or directory

2023-11-20 Thread Bill Cole via Postfix-users
or directory What’s wrong with ? You probably need to change /usr/bin/sendmail to /usr/sbin/sendmail. (Unless Debian has done something crazy with their mail packages...) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently

[pfx] Re: Why does Postfix evaluate relay restrictions despite an early permit in recipient restriction?

2023-11-11 Thread Bill Cole via Postfix-users
On 2023-11-11 at 12:58:04 UTC-0500 (Sat, 11 Nov 2023 17:58:04 +) Matthias Nagel via Postfix-users is rumored to have said: Am Samstag, 11. November 2023, 18:51:04 CET schrieb Bill Cole via Postfix-users: Nope. Review the restriction list docs. PERMIT only short-circuits the current

[pfx] Re: Why does Postfix evaluate relay restrictions despite an early permit in recipient restriction?

2023-11-11 Thread Bill Cole via Postfix-users
. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le

[pfx] Re: Virtual mailbox config

2023-11-09 Thread Bill Cole via Postfix-users
On 2023-11-09 at 20:25:44 UTC-0500 (Thu, 9 Nov 2023 20:25:44 -0500) Phil Stracchino via Postfix-users is rumored to have said: Agh. I've been looking at mail.log on the wrong machine ALL ALONG . Isn't that what I said ? kill me now Nah, just a little told-ya-so. -- Bill Cole b

[pfx] Re: Virtual mailbox config

2023-11-09 Thread Bill Cole via Postfix-users
6256522656D01. Something else I've missed? Looking at the wrong log? Filtering out the relevant lines? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

[pfx] Re: Question about postscreen

2023-11-02 Thread Bill Cole via Postfix-users
recursive caching DNS resolver (AS ANY MTA SHOULD) it is essentially free to "re-check" DNSBLs that postscreen has queried earlier, as the answers will be cached. This would effectively front-load the inherent delay of making DNSBL checks. -- Bill Cole b...@scconsult.co

[pfx] Re: No Permissions To TLS Certificates

2023-10-12 Thread Bill Cole via Postfix-users
that claim in a lot of malware spam... -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org

[pfx] Re: Can postfix/spamassassin save blocked messages ?

2023-10-06 Thread Bill Cole via Postfix-users
. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix

[pfx] Re: pipelining issue

2023-09-20 Thread Bill Cole via Postfix-users
SIZE 7680 > Out: 250-ETRN > Out: 250-ENHANCEDSTATUSCODES > Out: 250-8BITMIME > Out: 250-SMTPUTF8 > Out: 250 CHUNKING > In: MAIL FROM: SIZE=9132359 > Out: 250 2.1.0 Ok > In: RCPT TO: > Out: 250 2.1.5 Ok > In: RCPT TO: > Out: 250 2.1.5 Ok > In: B

[pfx] Re: Stupid questions

2023-09-18 Thread Bill Cole via Postfix-users
to the milters after the terminating . at end-of-DATA but BEFORE it has responded to the client. The milters can then tell Postfix whether or not to accept the message and what changes to make to the message, such as adding headers. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA

[pfx] Re: mask "mail from: " for Microsoft

2023-09-14 Thread Bill Cole via Postfix-users
the 'forward' feature of a mail reader program. If you want to do this in some automated manner, perhaps Bill Cole has some tooling suggestions. Do I? Oh, I guess I've earned that by repeatedly suggesting MIMEDefang (or its sibling MailMunge) for doing things in a milter that no MTA should be doing

[pfx] Re: Postfix mails accepted for delivery, but never received

2023-09-11 Thread Bill Cole via Postfix-users
use it did not. Anyone can send a packet claiming to be from 131.130.3.111. That's precisely how the port 25 intercept works: a middlebox sees packets on port 25 and replies to them with packets supposedly from the target IP. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpyboz

[pfx] Re: Postfix mails accepted for delivery, but never received

2023-09-10 Thread Bill Cole via Postfix-users
years, back around the turn of the millennium. That example was followed by many smaller operations who didn't have any of AOLs mitigating attributes. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For

[pfx] Re: PDS_OTHER_BAD_TLD

2023-09-05 Thread Bill Cole via Postfix-users
On 2023-09-05 at 13:31:06 UTC-0400 (Tue, 05 Sep 2023 13:31:06 -0400) Bill Cole via Postfix-users is rumored to have said: > 6. Many years of BAD operation has sent a steady trickle of poor innocents > here and to the SA Bugzilla making false assertions like yours above and > wasting e

[pfx] Re: PDS_OTHER_BAD_TLD

2023-09-05 Thread Bill Cole via Postfix-users
reference to a domain found at arbitrary places within the message's unstructured content. More directly: If that was sent as you've described – using the .eu domain – that domain is the problem, NOT the .space domain in the body. -- Bill Cole b...@scconsult.com or billc..

[pfx] Re: PDS_OTHER_BAD_TLD

2023-09-05 Thread Bill Cole via Postfix-users
hemoth mailbox providers, but I have no specific knowledge of the quality or affordability of any particular firm. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire _

[pfx] Re: Spam mails seen in logfiles question

2023-08-23 Thread Bill Cole via Postfix-users
g messages sent by reckless spammers who use VERP only because that's what their tools do, and their spamming gets their accounts killed or filled before their giant piles of spam have fully delivered. -Original Message----- From: Bill Cole via Postfix-users Sent: Wednesday, August 23, 20

[pfx] Re: Spam mails seen in logfiles question

2023-08-23 Thread Bill Cole via Postfix-users
techniques to work with fewer errors. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org

[pfx] Re: reverse DNS question for HELO hostname

2023-08-22 Thread Bill Cole via Postfix-users
with this statement, likely an error in translation. All SMTP RFCs have specified that the hostname in HELO must not be required to match the result of client IP's hostname lookup, but they all agree that it should match. Or, more tersely, in regexp: s/needs NOT/does NOT need/ -- Bill Cole

[pfx] Re: Troubleshooting mail loop issue

2023-08-15 Thread Bill Cole via Postfix-users
. but it should then send it to another tenant, correct? You are asking a MS365 question on a Postfix mailing list. "Should" they? Of course. They didn't. Whatever is broken in this case is broken inside Microsoft. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpyboz

[pfx] Re: Block based on subject and rcpt to

2023-08-15 Thread Bill Cole via Postfix-users
) and handle disposition of such messages there. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org

[pfx] Re: Troubleshooting mail loop issue

2023-08-15 Thread Bill Cole via Postfix-users
to fix Microsoft's mishandling of email. (giggles insanely...) But seriously, you cannot fix this problem by reconfiguring Postfix or DNS, the changes must be done in MS365 mail routing. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsul

[pfx] Re: identifying sender failing ssl/tls cipher ?

2023-08-12 Thread Bill Cole via Postfix-users
etailed coherent explanation of why your bespoke config is breaking your system. He will be correct about every word. I will just say that you should remove all non-default TLS-related settings for which you cannot give a detailed technical justification, beyond "some random web page tol

[pfx] Re: email being flagged a spam for using localhost [127.0.0.1] as first hop

2023-08-09 Thread Bill Cole via Postfix-users
your own threat model, but the marginal value of the information in a Received header is rarely significant. On the other side, it is usually possible to detect obfuscated Received headers and it is entirely reasonable for receiving sites to see that in a message and deem it suspect on that basis.

[pfx] Re: Maildir filename format

2023-07-31 Thread Bill Cole via Postfix-users
On 2023-07-31 at 09:34:47 UTC-0400 (Mon, 31 Jul 2023 15:34:47 +0200) Fourhundred Thecat via Postfix-users <400the...@gmx.ch> is rumored to have said: On 2023-07-31 15:09, Bill Cole via Postfix-users wrote: On 2023-07-31 at 02:43:28 UTC-0400 (Mon, 31 Jul 2023 08:43:28 +0200)     1690

[pfx] Re: Maildir filename format

2023-07-31 Thread Bill Cole via Postfix-users
tadata in the names. Do the nioe filenames come from Thunderbird, or from the mailserver ? TBird. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire __

[pfx] Re: which main.cf and postconf

2023-07-10 Thread Bill Cole via Postfix-users
ich is correct? They produce different results because they were built with different configurations, such that they have different embedded default parameters, including the default location of config files. Each 'postconf' will provide the configuration truth about the Postfix installation o

[pfx] Re: which main.cf and postconf

2023-07-10 Thread Bill Cole via Postfix-users
to reconstruct that all by yourself with the underlying FOSS tools, but that's the best choice at this point. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

[pfx] Re: How to configure minimal POP3/IMAP server with postfix?

2023-07-10 Thread Bill Cole via Postfix-users
. So, can I just install and configure Dovecot with Postifx delivering mail to /var/mail? Yes. You might find ~/Maildir more convenient in the long run, but you can do the traditional mbox in /var/mail/ thing. ... and is Dovecot the way to go? Yes. -- Bill Cole b...@scconsult.co

[pfx] Re: SPF questions

2023-06-12 Thread Bill Cole via Postfix-users
_ >> Postfix-users mailing list -- postfix-users@postfix.org >> To unsubscribe send an email to postfix-users-le...@postfix.org > ___ > Postfix-users mailing list -- postfix-users@postfix.org > To unsubscribe send an email to postfix-users-le...@

[pfx] Re: No Postfix novice, but need novice-like advice (was Postfix or Dovecot cracked?!)

2023-06-09 Thread Bill Cole via Postfix-users
onfig problem or some compromising bug in Postfix or Dovecot, it would be open to all sorts of miscreants. A user who has spyware owning their machine leaks their credentials to only one criminal spam operation. Repeatedly. But that's very much a guess. -- Bill Cole b...@scconsult.co

[pfx] Re: Detect/extract attachments in broken messages composed by Apple Mail

2023-05-26 Thread Bill Cole via Postfix-users
. Therefore it would be unsuccessful if you were to do this with mail that you want to relay or forward elsewhere. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___

[pfx] Re: Mx has ip6 only

2023-05-24 Thread Bill Cole via Postfix-users
mail system doesn't have an IPv4 address, it cannot receive mail from other machines that only have IPv4 addresses. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

[pfx] Re: delivery loop?

2023-05-22 Thread Bill Cole via Postfix-users
you should have some *architectural* justification for a backup MX. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list

[pfx] Re: delivery loop?

2023-05-22 Thread Bill Cole via Postfix-users
nd playing standard-compliance games with spammers ("no-listing") for smaller systems. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfi

[pfx] Re: A strange DMARC failure

2023-05-16 Thread Bill Cole via Postfix-users
that DMARC exists does not imply that it is entirely usable as deployed. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list

[pfx] Re: logging strangeness

2023-05-16 Thread Bill Cole via Postfix-users
in Dovecot, it will log failures. For failed Postfix authentications, you will see lines logged by auth-worker in the info log with the username, remote IP, and failure type. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses

[pfx] Re: per-domain sender_checks?

2023-05-16 Thread Bill Cole via Postfix-users
reactive approach where I'm always adding > sender_checks.pcre entries? Have you looked into using restriction classes? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Availa

[pfx] Re: DKIM and DMARC

2023-05-16 Thread Bill Cole via Postfix-users
gile, and are broken by MTA behaviors which have been commonplace for the lifetime of the Internet. If you reject messages based on an existing DKIM signature not verifying, you will reject some entirely legitimate mail for no good reason. -- Bill Cole b...@scconsult.com or billc...@apache.

[pfx] Re: DKIM and DMARC

2023-05-16 Thread Bill Cole via Postfix-users
s. NOTE WELL: DKIM signatures are notoriously fragile, and are broken by MTA behaviors which have been commonplace for the lifetime of the Internet. If you reject messages based on an existing DKIM signature not verifying, you will reject some entirely legitimate mail for no good reason. -- Bill Col

[pfx] Re: domain based vhosts

2023-05-04 Thread Bill Cole via Postfix-users
are differentiated by IP address and TCP port number. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org

[pfx] Re: Future Date:

2023-05-02 Thread Bill Cole via Postfix-users
milters that can call SA. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe

[pfx] Re: tls_high_cipherlist parameter

2023-05-01 Thread Bill Cole via Postfix-users
is, and there is also an in-depth README in the Postfix documentation for TLS configuration. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix

[pfx] Re: postscreen question

2023-04-29 Thread Bill Cole via Postfix-users
tfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org -- https://kenpeng.pages.dev/ ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org -- B

[pfx] Re: Deny any sender address with subdomain

2023-04-28 Thread Bill Cole via Postfix-users
ve several anti spam feature enabled but i get still some messages which are coming from subdomains or sub sub domains Yes, indeed you do... Or you would, if I CC'd a copy of this to you directly. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scc

[pfx] Re: postscreen question

2023-04-26 Thread Bill Cole via Postfix-users
on the "deep tests" as well, but it seems to be really scary to me :) Don't. They are not worth it. What is the best practice here ? I am curious for your opinions. Only use Postscreen's before-greeting tests. The "deep" tests add very little marginal value. -- Bill Col

[pfx] Re: Subject modification based on recipient

2023-04-26 Thread Bill Cole via Postfix-users
for this. For example, MIMEDefang (or its descendant MailMunge) could do this in a filter_end() subroutine. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix

[pfx] Re: Sender address rejected, but domain is found?

2023-04-25 Thread Bill Cole via Postfix-users
nameservers for eurobank-direktna.rs (the domain part of the sender address) times out for me at the moment, which may be related to what you're seeing. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Availa

[pfx] Re: Use of PTR record

2023-04-25 Thread Bill Cole via Postfix-users
'myserver.mydomain.com 1.2.3.4' in my hosts file, but I am not quite convinced that is the only solution. Actual DNS is also an option, and a better one usually. As you've chosen to pose this as a hypothetical with bogus details, there may be complications we can't see. -- Bill Cole b

[pfx] Re: postfix does not add Return-Path if mail is missing it

2023-04-23 Thread Bill Cole via Postfix-users
, I guess...) for details. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe

[pfx] Re: Reject mail by language

2023-04-18 Thread Bill Cole via Postfix-users
, you need to use an external tool such as ASF SpamAssassin or rspamd, usually integrated with Postfix via a milter interface. Note that detection of specific languages in email is intrinsically imperfect. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many

[pfx] Re: SPF: HELO does not publish an SPF Record

2023-04-12 Thread Bill Cole via Postfix-users
lving. Believing that every SpamAssassin hit is a "problem" that can or should be "solved" is simply not true. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___

[pfx] Re: Different set of milters for one domain?

2023-03-28 Thread Bill Cole via Postfix-users
ideas for how to do what people want... Fortunately, many milters provide the tools to be selective about how to handle different target domains. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

[pfx] Re: Allow TLSv1 only for internal senders

2023-03-18 Thread Bill Cole via Postfix-users
My understanding is that the marginal risks of TLSv1.0 are not relevant to SMTP. It is also inherently counter-productive to prohibit TLSv1.0 if you allow unencrypted SMTP as a fallback. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addres

[pfx] Re: postscreen logs MIA

2023-03-17 Thread Bill Cole via Postfix-users
, that should be replaced with: smtp inet n - n - 1 postscreen smtpd pass - - n - - smtpd You can get a clean look at your master.cf settings with 'postconf -Mf' -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA

[pfx] Re: use object storage as message store

2023-03-11 Thread Bill Cole via Postfix-users
. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le

[pfx] Re: milter-reject: END-OF-MESSAGE

2023-03-10 Thread Bill Cole via Postfix-users
spamd documentation or whatever support channels exist for rspamd. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire ___ Postfix-users mailing l

  1   2   3   4   5   6   7   8   9   10   >