Re: "SSL_Shutdown:shutdown while in init" while sending and receiving

2020-05-13 Thread Matus UHLAR - fantomas
after RCPT from [] maybe some form of address veriification? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up

Re: mail from external servers connecting but timing out after tls established. t.s.

2020-05-08 Thread Matus UHLAR - fantomas
from unknown[185.50.149.12] On 08.05.20 20:57, Matus UHLAR - fantomas wrote: remote servers don't connect to smtps port. These are remote clients, guessing passwords. and this address block looks familiar to me, ... apparently abusers I set up certificates with letsincrypt. If these crets

Re: mail from external servers connecting but timing out after tls established. t.s.

2020-05-08 Thread Matus UHLAR - fantomas
from unknown[185.50.149.12] remote servers don't connect to smtps port. These are remote clients, guessing passwords. and this address block looks familiar to me, I set up certificates with letsincrypt. If these crets are wrong, would that cause this type of behavior? no. -- Matus UHLAR

Re: hostname in sasl/pam requests

2020-05-07 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: I have set up pam_abl to automatically block hosts and users from logging. Unfortunately, the hostname seems not to be visible in pam logs: May 7 17:49:38 mail pam-abl[18692]: Blocking access from (null) to service smtp, user xxx is it possible to pass connecting

Re: hostname in sasl/pam requests

2020-05-07 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: I have set up pam_abl to automatically block hosts and users from logging. Unfortunately, the hostname seems not to be visible in pam logs: May 7 17:49:38 mail pam-abl[18692]: Blocking access from (null) to service smtp, user xxx is it possible to pass connecting

hostname in sasl/pam requests

2020-05-07 Thread Matus UHLAR - fantomas
somehow? (I would like to block hosts as well as users when possible) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought

Re: Illegal address syntax

2020-05-07 Thread Matus UHLAR - fantomas
8.x.x] May 7 08:22:44 mail postfix/smtps/smtpd[653]: warning: Illegal address syntax from unknown[192.168.x.x] in RCPT command: May 7 08:22:47 mail postfix/smtps/smtpd[653]: disconnect from unknown[192.168.x.x] ehlo=1 auth=1 mail=1 rcpt=0/1 quit=1 commands=4/5 -- Matus UHLAR - fa

null recipient "@example.com"@example.com accepted

2020-05-07 Thread Matus UHLAR - fantomas
t_non_fqdn_recipient, reject_unknown_recipient_domain, permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination, -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: probably bug in postfix3-3.4

2020-05-06 Thread Matus UHLAR - fantomas
[y.y.y.y]:25, delay=0.14, delays=0.07/0/0.06/0.01, dsn=2.0.0, status=sent (250 2.0.0 046CEjeo032470-046CEjeq032470 Message accepted for delivery) May 6 14:14:45 server postfix/qmgr[2545]: 56BD5280282: removed -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ War

Re: filtering locally submitted emails / tidying up the config

2020-05-02 Thread Matus UHLAR - fantomas
tfix, and expect amavis to use $forward_method to send the mail. I guess using "-D server" and disabling $forward_method would discard your mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varov

Re: why DMARC PASS even SPF got failed

2020-04-29 Thread Matus UHLAR - fantomas
) DMARC than SPF fail (or softfail) with failed DMARC -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "The box said 'Requires Windo

Re: why DMARC PASS even SPF got failed

2020-04-28 Thread Matus UHLAR - fantomas
nder using DKIM and forwarder using SRS fill make both SPF and DMARC pass. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #98652:

Re: postfix + forwadgroup + external amavis with haproxy and no_address_mappings

2020-04-28 Thread Matus UHLAR - fantomas
y    - local haproxy go to amavis    - amavis scanned    - amavis return to postfix - postfix local transport 10.0.100.5 and go to lmtp use LMTP for filtering. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address.

Re: header_checks question

2020-04-27 Thread Matus UHLAR - fantomas
you. Ideally there is a rate limit so that you won't be email bombed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Your mouse

Re: PATCH: Glibc-2.31 DNSSEC and GCC 10

2020-04-19 Thread Matus UHLAR - fantomas
owever, if people want to shoot themselves in the foot, then Postfix won't stop them. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux - It's n

Re: dumbest questions about limit

2020-04-17 Thread Matus UHLAR - fantomas
ing 'no limit' - although >mailbox_size_limit=0 is valid/documented. > >Although your postconf is reporting 2324 (a little over 22MB), you >can (and may) have different settings in master.cf which override this >- for instance for authenticated vs non-authenticated incoming mails.

Re: dumbest questions about limit

2020-04-16 Thread Matus UHLAR - fantomas
r.cf which override this - for instance for authenticated vs non-authenticated incoming mails. note that some SMTP clients don't check SIZE option your SMTP server sends to them and some don't announce the SIZE in MAIL FROM command. You would not see this message otherwise :-) -- Matus UHLAR - fa

Re: Possible header_check solution?

2020-04-15 Thread Matus UHLAR - fantomas
l with original From: This was discussed in spamassassin mailing list recently. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Chernobyl was an Windows 95 beta test site.

Re: modifying outbound email headers

2020-04-06 Thread Matus UHLAR - fantomas
er, will be modified with a >defined string. Matus UHLAR - fantomas wrote: your mail2news gateway should do that. On 06.04.20 12:43, Stefan Claas wrote: I thought that as well, but the problem would be when users send the same message to multiple mail2news gateways, which is often the ca

Re: modifying outbound email headers

2020-04-06 Thread Matus UHLAR - fantomas
. your mail2news gateway should do that. postfix must *not* change message IDs for regular emails. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Postfix problem with Hotmail (501 5.5.4 Invalid domain name)

2020-04-03 Thread Matus UHLAR - fantomas
rac...@zonanet.com.ar> Please: 1. post whole log line 2. don't merge log with message headers. it's very hard to see what exactly was wrong there. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovan

Re: pflogsumm error.

2020-04-03 Thread Matus UHLAR - fantomas
nged*covisp.net>, proto=ESMTP, helo= On 31 Mar 2020, at 07:43, Matus UHLAR - fantomas wrote: where do you have your pflogsumm version from? On 03.04.20 09:48, @lbutlr wrote: FreeBSD ports which FreeBSD, which perl? original pflogsumm does not support postscreen. OK, so postsc

Re: Using Postfix as a Backup MX

2020-04-01 Thread Matus UHLAR - fantomas
I persinally believe that if you really need backup MX, you should do at least some kind of recipient verification. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVA

Re: Using Postfix as a Backup MX

2020-03-31 Thread Matus UHLAR - fantomas
thorough are they? If not, do any of you have any instructions, tips or tricks that you would not mind sharing with me? All advice would be very much appreciated. I hope all of you are safe and healthy. Thanks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: pflogsumm error.

2020-03-31 Thread Matus UHLAR - fantomas
nged*covisp.net>, proto=ESMTP, helo= where do you have your pflogsumm version from? original pflogsumm does not support postscreen. Debian version 1.1.5-3 includes support for it, and should not generate this kind of errors -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.s

Re: modify "User unknown" message

2020-03-30 Thread Matus UHLAR - fantomas
On 3/30/2020 8:18 AM, Matus UHLAR - fantomas wrote: * Matus UHLAR: remote senders don't understand the message too often. On 30.03.20 14:55, Ralph Seichter wrote: Using "show_user_unknown_table_name = no" will hide the table name. That might reduce some of the confusion. I'd pre

Re: modify "User unknown" message

2020-03-30 Thread Matus UHLAR - fantomas
ssage. yes, the table name is not important. maybe append some catch-all reject to local_recipient_maps could help? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolve

modify "User unknown" message

2020-03-30 Thread Matus UHLAR - fantomas
Hello, can anyone advise me, what's the easiest way to modify error message: "User unknown in local recipient table" if we use: - virtual aliases - aliases - password file? remote senders don't understand the message too often. Thanks -- Matus UHLAR - fantomas, uh...@fantomas

Re: Postfix Sign smtp from with DKIM

2020-03-27 Thread Matus UHLAR - fantomas
On 27.03.20 10:46, SysAdmin EM wrote: Is it possible to sign smtp from with DKIM? I clarify that I am not talking about the header from. no, only headers can be signed. Also, that would make forwarding impossible. Don't try to do that. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: Invalid Sender (DNS)

2020-03-19 Thread Matus UHLAR - fantomas
would help much more. Now I can only guess you have DNS resolution problem or your mail server correctly refuses mail from invalid domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adr

Re: Warning about non-existent MX for destination domain

2020-03-11 Thread Matus UHLAR - fantomas
I'm afraid I don't have enough of time to build it, otherwise I'd propose you to use it already :) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: Disabling TLSv1

2020-03-06 Thread Matus UHLAR - fantomas
you? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. How does cat play with mouse? cat /dev/mouse

Re: What is this?

2020-02-28 Thread Matus UHLAR - fantomas
and unbanned them after realizing that. It's more likely that messagelabs scan the internet for open relays, mailservers features to gather statistics about the internet. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: What is this?

2020-02-26 Thread Matus UHLAR - fantomas
the connection must be made by SYN,SYN+ACK,ACK and then FIN. If you block data/SYN by any firewll, you won't see those messages. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: From header local mail

2020-02-07 Thread Matus UHLAR - fantomas
On 07.02.20 12:01, xegr...@gmail.com wrote: Hi. In a new install of Postfix 3.4.7-0+deb10u1 on Debian buster, I would like Postfix to append $myhostname instead of $myorigin to local mail That is the point of myorigin, why you want it else? -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: message-id empty

2020-02-06 Thread Matus UHLAR - fantomas
8CJyK1Yg7z3y2C: message-id=<> > >In rfc 822 message-id is not required but I dont known why some times i get >message-id and sometimes not and what it depends on On Wed, Feb 5, 2020 at 12:41 PM Matus UHLAR - fantomas wrote: apparently the client did not create Message-Id: he

Re: Multiple after-queue content filters

2020-02-05 Thread Matus UHLAR - fantomas
er = smtp-amavis:127.0.0.1:10024 apparently amavis is only used when receiving mail other way than smtp (on port 25). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVA

Re: message-id empty

2020-02-05 Thread Matus UHLAR - fantomas
e-id=<> In rfc 822 message-id is not required but I dont known why some times i get message-id and sometimes not and what it depends on apparently the client did not create Message-Id: header. it's up to the client to generate it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ W

Re: Forwarding email as attachment instead of relaying it

2020-01-31 Thread Matus UHLAR - fantomas
e can lose legitimate emails if he/she is using mail account at such an incompetent provider. maybe the OP should configure forwarding properly. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na t

Re: Forwarding email as attachment instead of relaying it

2020-01-31 Thread Matus UHLAR - fantomas
re a way to transfer the email as an attachment to avoid that ? Or just a way to rewrite the envelope sender to u...@example.com ? What do you advise for this case ? you need to rewrite envelope from, e.g. by using postsrs. Note that you can't do that from virtual maps, you must use aliases or .forwa

Re: easy way to forward all root mail to devnull?

2020-01-29 Thread Matus UHLAR - fantomas
mail to you about e.g. disk failing. And perhaps refuse mail to root from external sources. much better. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Postscreen response to client - which rbl is named?

2020-01-25 Thread Matus UHLAR - fantomas
m? On Sat, 25 Jan 2020 at 09:08, Matus UHLAR - fantomas wrote: it is the first onw that responds. if it's a whitelist (scoringnegatively), it's reported anyway. that's where postscreen_dnsbl_reply_map is to be used. On 25.01.20 09:18, Dominic Raferd wrote: Thanks for clearing that up. M

Re: Postscreen response to client - which rbl is named?

2020-01-25 Thread Matus UHLAR - fantomas
? it is the first onw that responds. if it's a whitelist (scoringnegatively), it's reported anyway. that's where postscreen_dnsbl_reply_map is to be used. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: Graphing

2020-01-24 Thread Matus UHLAR - fantomas
many wayt to put data to RRD. Looks like the munin plugins only counts how many mails there are in different queues https://github.com/cmur2/munin-postfix/blob/master/postfix_mailqueue That data you can use with nagios, cacti and other monitoring systems. -- Matus UHLAR - fantomas, uh...@f

Re: What does check_sender_access checks?

2020-01-21 Thread Matus UHLAR - fantomas
SMTP authentication or source IP address. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "To Boot or not to Boot, that's the question." [WD1270 Caviar]

Re: Bounce mails manually

2020-01-17 Thread Matus UHLAR - fantomas
will still be tried, which leads to our problem (this thread). I was recently forced to add a ridiculous MX record to my domain, pointing back to the same name (eg. "rafa.eu.org MX 10 rafa.eu.org") I've seen recommendation to do this (just for sure) long ago. -- Matus UHLAR - fantomas,

Re: Bounce mails manually

2020-01-16 Thread Matus UHLAR - fantomas
ny means. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "They say when you play that M$ CD backward you can hear satanic messages.

Re: Bounce mails manually

2020-01-16 Thread Matus UHLAR - fantomas
04336.html if such mail stayed in queue for some time, further mail to (and from) the domain could be refused, which would lower amount of such mail in queue. That should help not only against spammers, but against ignorrant bulk mail senders. -- Matus UHLAR - fantomas, uh...@fantomas

Re: Bounce mails manually

2020-01-16 Thread Matus UHLAR - fantomas
n requests. Wietse advised policy script: http://postfix.1071664.n5.nabble.com/handling-long-term-unreachable-addresses-domains-td104336.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na t

Re: Postfix HELO checks

2020-01-16 Thread Matus UHLAR - fantomas
ves. the downside is we still don't know what is (or was) wrong. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "They say when you pl

Re: phising attacks

2020-01-15 Thread Matus UHLAR - fantomas
there's only one Jo Blogs in the world, there's possibility a real Jo Blogs is sending the mail, just not the one you may think. Blocking the mail might be bad. This is why I recommend to verify strange/suspicious requests. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: phising attacks

2020-01-15 Thread Matus UHLAR - fantomas
measures? Hardly any. Is possible, teach you users to verify strange requests. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost

Re: handling long-term unreachable addresses/domains

2020-01-15 Thread Matus UHLAR - fantomas
On 09.01.20 17:09, Matus UHLAR - fantomas wrote: on a few mail servers/gateways, we receive mail from domains that are unreachable for mail delivery on a long-term basis. besides spammers, there are companies that send mail from domains which don't have MX records, and A records point

Re: Port 25 closed on bulk sending servers

2020-01-15 Thread Matus UHLAR - fantomas
, mail? I have asked about very similar issue a week ago. Will bump. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 2B|!2B, that's a question!

Re: Postfix HELO checks

2020-01-15 Thread Matus UHLAR - fantomas
rough amavis in either direction, so that's a problem... are you sure amavis sends mail through port 10025? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Christian Science Programming: "Let God Debug It!".

Re: Postfix HELO checks

2020-01-14 Thread Matus UHLAR - fantomas
from localhost [127.0.0.1]: 550 5.7.1. : Helo command rejected: Your server is misconfigured as you are not a member of this domain; from= to= proto=ESMTP helo= On 10.01.20 15:52, Matus UHLAR - fantomas wrote: ok, this looks like recipient rejection

Re: Postfix HELO checks

2020-01-10 Thread Matus UHLAR - fantomas
meone help me figure out why? > >I can probably remove/comment the offending line and rely on other >rejection parameters, but it still rejects a significant of spam >attempts, so I'd prefer to keep it. On Fri, 10 Jan 2020 at 13:39, Matus UHLAR - fantomas wrote: logs? On 10.01.20 14:

Re: Postfix HELO checks

2020-01-10 Thread Matus UHLAR - fantomas
parameters, but it still rejects a significant of spam attempts, so I'd prefer to keep it. logs? don't you have check_helo_access at different place in any chance? I'm not sure what smtpd_relay_restrictions debian adds to main.cf by default. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

handling long-term unreachable addresses/domains

2020-01-09 Thread Matus UHLAR - fantomas
like to detect this kind of domains and block them. Ideally, not immediately, but when e.g. domain is inaccessible for a given time, e.g. when mail starts being returned. Is something similar possible now? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: SEMDMAIL Error message

2020-01-08 Thread Matus UHLAR - fantomas
="YES" openvpn_configfile="/usr/local/etc/openvpn/server/server.conf" On Jan 8, 2020, at 11:25 AM, Pintér Tibor wrote: permission On 1/8/20 4:19 PM, Jason Hirsh wrote: I am getting the following error message even though I am using postfix and no longer start SEN

Re: Aliases/.forward/virtual_users confusion

2019-12-20 Thread Matus UHLAR - fantomas
. Am I correct? And what is preferred? An /etc/aliases file that is in use (next to the one I am using) or a ~root/.forward file? alias_maps are processed before .forward, virtual_alias_maps before alias_maps. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Advice: NFS, hardware, SATA vs SAS etc

2019-12-18 Thread Matus UHLAR - fantomas
with postfix. However, this is off-topic in this queue. hopefully proposed solutions will be enough for you, good luck. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOS

Re: Postfix: Sender address rejected: Domain not found

2019-12-17 Thread Matus UHLAR - fantomas
already pointed out, postfix uses DNS/MX lookups and and since you can't put MX to /etc/hosts, you must use DNS or explicit transport map. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: Whitelisting refuses to work

2019-12-17 Thread Matus UHLAR - fantomas
, but that doesn't work either. What did i miss? how does the rejection look like in logs? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 42.7 percent

Re: Postfix: Sender address rejected: Domain not found

2019-12-16 Thread Matus UHLAR - fantomas
/hosts. Dec 16 15:41:10 smarthost01-ded postfix/smtp[30826]: B0C15488B4: to=, relay=none, delay=0.05, delays=0.01/0/0.04/0, dsn=5.4.4, status=bounced (Host or domain name not found. Name service error for name=ferozo-admin.com.ar type=: Host not found) -- Matus UHLAR - fantomas, uh

Re: configuration postscreen

2019-12-14 Thread Matus UHLAR - fantomas
>I would avoid unduly short postscreen cache times, that can lead to >legitimate clients not getting through at all. On Fri, Dec 13, 2019 at 05:40:33PM +0100, Matus UHLAR - fantomas wrote: I'm not sure if that would help. Apparently, both postscreen and smtpd will use the same name

Re: configuration postscreen

2019-12-13 Thread Matus UHLAR - fantomas
that would help. Apparently, both postscreen and smtpd will use the same nameserver for dnsbl lookup, and if it's cached from previous postscreen lookup, it will probably give the same result. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: rejections after limiting access to smtp auth

2019-12-11 Thread Matus UHLAR - fantomas
and milters on port 25, so spam is refused at SMTP level. Clients don't like that because sending mail takes time. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Relay and Sender Restrictions

2019-12-07 Thread Matus UHLAR - fantomas
the relay does not. This means that the destination rejects emails from the relay. the destination? If you are talking about recipient, you must put reject_non_fqdn_recipient and reject_unknown_recipient_domain into smtpd_recipient_restrictions -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: how to configure backup MX to relay messages to primary MX

2019-12-06 Thread Matus UHLAR - fantomas
to contain public IP address(ed) that map to it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is like a steel trap - rusty and illegal

Re: Recipient address rejected for recipient address in virtual

2019-12-02 Thread Matus UHLAR - fantomas
ess be verified? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam is for losers who can't get business any other way.

Re: Bounce spam configuration.

2019-11-27 Thread Matus UHLAR - fantomas
added as eml attachment ? this looks like job for spam filter like spamassassin or amavis, not postfix. On 27.11.19 09:35, Julian Kippels wrote: maybe you should look into rejecting Spam pre-queue with smtpd_proxy_filter I recommend milter over using smtpd proxy. -- Matus UHLAR - fantomas, uh

Re: Forwarding mail without breaking SPF?

2019-11-27 Thread Matus UHLAR - fantomas
elope from:, not any headers. Checking header From: was stupid microsoft attempt for spf/2 that failed. Once again, SPF does not apply to mail headers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: how to setup a privacy oriented mailserver

2019-11-26 Thread Matus UHLAR - fantomas
on 2019/11/26 19:27, Matus UHLAR - fantomas wrote: ...and there's no "starttls" on 465, that's what I meant "implicit". while port 465 was assigned for SMTPS in January 2018, it's been used this way on many sites/services for years (even decades) On 26.11.19 20:50, Wes

Re: how to setup a privacy oriented mailserver

2019-11-26 Thread Matus UHLAR - fantomas
on 2019/11/26 17:02, Matus UHLAR - fantomas wrote: I would set up port 465 also. Note that TLS on 465 is implicit, while on 587 is explicit, so it's easier to allow unencrypted connections by a mistake on 587. On Tue, 26 Nov 2019, Wesley Peng wrote: 587 is also used for StartTLS, am I right

Re: how to setup a privacy oriented mailserver

2019-11-26 Thread Matus UHLAR - fantomas
than port 25 all countries from which you will not be using the server. you apparently mean, from countries client won't be able to receive mail from. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie

Re: Question about DMARC

2019-11-22 Thread Matus UHLAR - fantomas
, not headers. Any forwarder that keeps envelope address (which is common for .forward files or MTA-level mail aliases) thus breaks spf unless measures are made. And this it the main problem with SPF enforcement. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Question about DMARC

2019-11-22 Thread Matus UHLAR - fantomas
problem. ...and even adding this information to list mail doesn't prevent some subscribed users from complaining about getting the mail. Unfortunately, MUA support of maling lists is not very common. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT

Re: transport clash with mydestination

2019-11-21 Thread Matus UHLAR - fantomas
On 21.11.19 12:16, Matus UHLAR - fantomas wrote: I run "proxy.example.com" server with ".example.com" in transport_maps, to direct all example.com subdomains to internal server my $mydestination contains proxy.example.com and some other names, however all domain to proxy.exa

transport clash with mydestination

2019-11-21 Thread Matus UHLAR - fantomas
vers. What should I to to exempt $mydestination from being looked up in transport_maps? Thank you -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: relay based on sender and destination

2019-11-19 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 99 percent of lawyers give the rest a bad name.

Re: Client host rejected

2019-11-19 Thread Matus UHLAR - fantomas
On Mon, 18 Nov 2019 17:23:43 +0100 Matus UHLAR - fantomas wrote: seems something is wrong with your (or maybe their) reverse DNS resolution... On Mon, 18 Nov 2019, siefke_lis...@web.de wrote: This is what I had: [siefke@sisi-dell ~]$ nslookup 195.128.103.214 214.103.128.195.in-addr.arpa

Re: IP addresses in helo

2019-11-18 Thread Matus UHLAR - fantomas
ossible spam and send them to spam folder, it's completely up to you. Just note that people with too many spams in spam folder may start ignoring it and complain... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addre

Re: Client host rejected

2019-11-18 Thread Matus UHLAR - fantomas
. office.denic.de.3480IN A 81.91.160.182 seems something is wrong with your (or maybe their) reverse DNS resolution... however that's temporary error (4xx) and the client should try again. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: IP addresses in helo

2019-11-18 Thread Matus UHLAR - fantomas
RFC point of view. If you use it for this, you'll end up rejecting legitimate emails. this can happen anytime anyone rejects any e-mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: Hiding Spamhaus key from replies

2019-11-18 Thread Matus UHLAR - fantomas
art of my smtpd_recipient_restrictions. I want to change that to use my secret key, but I can't seem to find a way to map the server name to something else (to hide the key). On Mon, 18 Nov 2019, Matus UHLAR - fantomas wrote: What's the point of using spamhaus in smtpd_recipient_restrictions whe

Re: Hiding Spamhaus key from replies

2019-11-18 Thread Matus UHLAR - fantomas
can't seem to be able to make sense of it :-? How can I configure postfix to do like postscreen_dnsbl_reply_map but for smtpd? What's the point of using spamhaus in smtpd_recipient_restrictions when you have already done so in postscreen? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.f

Re: What am I missing? DNSBL on submission port?

2019-11-18 Thread Matus UHLAR - fantomas
tmaster so they could receive mail from blacklisted sites -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Enter any 12-digit prime number to continue.

Re: reject mail if dns and rdns differ

2019-11-13 Thread Matus UHLAR - fantomas
only requires ehlo.example to resolve. It's even weaker requirement and has FPs too, but I consider this one just enough -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOST

Re: postscreen with IP-ranges?

2019-11-12 Thread Matus UHLAR - fantomas
the mail. what reason are they refesed with? You can whitelist their IP ranges locally or use DNS whitelists that contain their IPs -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: reject mail if dns and rdns differ

2019-11-12 Thread Matus UHLAR - fantomas
You call it from e.g. procmail, or in other words it expects a mail message on STDIN and writes it back out with changes on STDOUT. It makes a bunch of DNS queries. It adds a bunch of headers; it's up to you to do with them as you wish. why not spamassassin instead? -- Matus UHLAR - fa

Re: reject mail if dns and rdns differ

2019-11-11 Thread Matus UHLAR - fantomas
fails) or reject_unknown_reverse_client_hostname (IP has no reverse DNS, no matter if it points back). mail.namase.de is the HELO (EHLO) name. You must not reject mail when helo name differs from DNS name (RFC violation). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: redirect HOLD queue to alternate MTA??

2019-11-06 Thread Matus UHLAR - fantomas
suspicious mail in this manner rather than released by postmaster. this looks like a job for spam filter, not opendmarc. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Dictionary attacks

2019-11-04 Thread Matus UHLAR - fantomas
be very carefull here. Still, it certainly can’t hurt. I'm afraid it won't even help much - seems that dictionary attacks work much slower. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: Warning on Connection time

2019-11-02 Thread Matus UHLAR - fantomas
=1 rcpt=0/1 quit=1 commands=5/6 Nov  2 15:08:07 stl-mx postfix/smtpd[3017]: disconnect from keeper-us-east-1b.mxtoolbox.com[52.55.244.91] ehlo=1 mail=1 rcpt=0/1 quit=1 commands=3/4 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: postfix filter to encrypt incoming emails with public gpg key

2019-10-27 Thread Matus UHLAR - fantomas
? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I feel like I'm diagonally parked in a parallel universe.

Re: reject_unknown_sender_domain seems not to work

2019-10-25 Thread Matus UHLAR - fantomas
ns that the dns server failed to find out whether the domain exists. it's a DNS problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "

Re: Mailq timestamps in localtime rather than UTC

2019-10-24 Thread Matus UHLAR - fantomas
set wrong. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Two words: Windows survives." - Craig Mundie, Microsoft senior

Re: outbound.protection.outlook.com

2019-10-02 Thread Matus UHLAR - fantomas
s (e.g. postscreen). On 02.10.19 14:12, ratatouille wrote: I use both, postscreen and postgrey. with postscreen, postgrey is in fact obsolete. I got rid of it, since of too many false positives related to outlook, gmail etc. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ W

Re: Specifying certificates in master.cf

2019-10-01 Thread Matus UHLAR - fantomas
to override globals. Also, smtp_tls* is unneeded in smtpd config, since it's related to smtp client. And, you probably don't authenticate to others using your certificate, so it's apparently useless too. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

<    4   5   6   7   8   9   10   11   12   13   >