[pfx] Re: smtpd rate limiting

2023-10-03 Thread Wietse Venema via Postfix-users
Noel Jones via Postfix-users: > My first wild guess is setting in_flow_delay to a higher value might > help. Note this may be completely inappropriate for your specific > application. > http://www.postfix.org/postconf.5.html#in_flow_delay That, and reducinig the number of smtpd processes if

[pfx] Re: behavior of postscreen_dnsbl_min_ttl

2023-10-02 Thread Wietse Venema via Postfix-users
patpro--- via Postfix-users: > hello, > > September 29, 2023 4:30 PM, "Wietse Venema via Postfix-users" > wrote: > > > postscreen does not duplicate DNS caching. DNS lookup results are > > already cached in a non-Postfix DNS resolver (see /etc/reso

[pfx] Re: Possible (indirect) libspf2 security issues

2023-09-30 Thread Wietse Venema via Postfix-users
Mike via Postfix-users: > > Quoting Viktor Dukhovni via Postfix-users : > > > On Sun, Oct 01, 2023 at 12:00:25AM +0300, mailmary--- via > > Postfix-users wrote: > > > >> In my case, libspf2 is a dependent package of OpenDMARC > > > > Not surprising, since DMARC takes both DKIM and SPF into

[pfx] Re: smtpd rate limiting

2023-09-29 Thread Wietse Venema via Postfix-users
Matthew McGehrin via Postfix-users: > Hi Kevin. > > If the delays are being caused by bounce message processing, you could Then you should configre Postfix to block undeliverable mail. - Don't accept mail for non-existent recipients. - Don't forward SPAM to other systems. Wietse

[pfx] Re: Postfix smtpd process life time

2023-09-29 Thread Wietse Venema via Postfix-users
Jacek Grabowski via Postfix-users: > Is there any option to set up how long the smtpd process will exist ? > I noticed that after the connection ends, the smtpd process still exists > for several dozen seconds. Can this time be shortened to a few seconds? > Thank you. Wietse: > That would bad for

[pfx] Re: Postfix smtpd process life time

2023-09-29 Thread Wietse Venema via Postfix-users
Jacek Grabowski via Postfix-users: > Hello > > Is there any option to set up how long the smtpd process will exist ? > I noticed that after the connection ends, the smtpd process still exists > for several dozen seconds. Can this time be shortened to a few seconds? > Thank you. That would bad

[pfx] Re: smtpd rate limiting

2023-09-29 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Kevin Cousin via Postfix-users: > > Greetings List, > > > > We recently had an issue and the active queue was full and slowed > > down all new mail delivery. Is it possible to rate limit the mail > > flow to protec

[pfx] Re: behavior of postscreen_dnsbl_min_ttl

2023-09-29 Thread Wietse Venema via Postfix-users
patpro--- via Postfix-users: > Hello, > > I'm surprised to see that dnsblog can issue up to 40 absolutely > identical DNS requests per seconds, for postscreen, when my setup > reads: postscreen does not duplicate DNS caching. DNS lookup results are already cached in a non-Postfix DNS resolver

[pfx] Re: smtpd rate limiting

2023-09-29 Thread Wietse Venema via Postfix-users
Kevin Cousin via Postfix-users: > Greetings List, > > We recently had an issue and the active queue was full and slowed > down all new mail delivery. Is it possible to rate limit the mail > flow to protect smtpd from a massive mail input ? By default, the Postfix SMTP server enforces

[pfx] Re: pipelining issue

2023-09-27 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Joey J via Postfix-users: > > In: DATA > > Out: 354 End data with . > > Out: 451 4.3.0 Error: queue file write error > > This SMTP transcript was sent to you by a Postfix smtpd process. > The file write error may ha

[pfx] Re: pipelining issue

2023-09-27 Thread Wietse Venema via Postfix-users
Joey J via Postfix-users: > In: DATA > Out: 354 End data with . > Out: 451 4.3.0 Error: queue file write error This SMTP transcript was sent to you by a Postfix smtpd process. The file write error may have been logged by that process, or by a Postfix cleanup process. You should be able to

[pfx] Re: IP protocol inconsistency

2023-09-26 Thread Wietse Venema via Postfix-users
raf via Postfix-users: > On Tue, Sep 26, 2023 at 02:01:24PM -0400, Wietse Venema via Postfix-users > wrote: > > > Wietse Venema via Postfix-users: > > > Wietse Venema via Postfix-users: > > > > It's a rather long explanation for "why not do X". l

[pfx] Re: IP protocol inconsistency

2023-09-26 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Wietse Venema via Postfix-users: > > It's a rather long explanation for "why not do X". like several > > times longer than the text that explains what protocol preferences > > do. And this is the only place where adding that

[pfx] Re: IP protocol inconsistency

2023-09-26 Thread Wietse Venema via Postfix-users
> Sadly, I need smtp_address_preference = ipv4 because some > reputation systems (spamhaus, I think) don't realise > that an entity might only have a single ipv6 address. Then you should disable IPv6, in the PostfiX SMTP client (master.cf: smtp -o inet_protocols=ipv4) or globally

[pfx] Re: Exporting environment to specific pipe service

2023-09-26 Thread Wietse Venema via Postfix-users
Matt Saladna via Postfix-users: > I'd like to export a single var to a set of pipe processes without > wrapping with env or setting export_environment in main.cf. > > This works in main.cf, > > export_environment=TZ MAIL_CONFIG LANG X=Y > > On the other hand, adding -o export_environment="TZ

[pfx] Re: Value of client certificates, was: Re: Re: [ext] list.sys4.de fails with starttls

2023-09-25 Thread Wietse Venema via Postfix-users
A. Schulze via Postfix-users: > Am 25.09.23 um 22:11 schrieb Viktor Dukhovni via Postfix-users: > > ... > > So, unfortunate as it may seem, they just increase > > opportunities for failure, without adding anything by way of security. > > ... > > Client certificates serve no purpose unless the

[pfx] Re: [ext] list.sys4.de fails with starttls

2023-09-25 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > > > The best solution is [to] configure client certs *sparingly*, only > > > for transports dedicated to destinations that definitely need the > > > client certs, and not otherwise. > > > > Why? I feel a little like I was feeling in the early 2000s when we had

[pfx] Re: IP protocol inconsistency

2023-09-25 Thread Wietse Venema via Postfix-users
Polarian via Postfix-users: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. > Hello, > > This seems to clarify it a lot, I hope that it is added to the current > manpages. It's already on-line. PS it never hurts to choose an accurate subject line. Wietse

[pfx] Re: IP protocol inconsistency

2023-09-24 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > It's a rather long explanation for "why not do X". like several > times longer than the text that explains what protocol preferences > do. And this is the only place where adding that text would help. I updated the text a little: Notes for ma

[pfx] Re: IP protocol inconsistency

2023-09-24 Thread Wietse Venema via Postfix-users
Polarian via Postfix-users: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. > Hello, > > I understood RFC 5321 before hand, apologies for you having to type > this all out, I feel bad now. > > But my point was, the documentation states that setting a preference is >

[pfx] Re: IP protocol inconsistency

2023-09-24 Thread Wietse Venema via Postfix-users
Polarian via Postfix-users: > Hello, > > Firstly thank you for the response. > > > RFC 5321 requires that the Postfix SMTP CLIENT connects to hosts > > with primary MX preference, before connecting to hosts with a > > secondary MX preference. > > > > For example, given the following DNS

[pfx] Re: Example config aliases from mysqldb and /etc/aliases

2023-09-24 Thread Wietse Venema via Postfix-users
Noah via Postfix-users: > Hi there, > > I am provisioning an postfix installation. Is there an example > configuration for finding aliases from a mysqldb and also checking the > /etc/aliases file please? alias_maps = hash:/etc/aliases proxy:mysql:/path/to/file This will search the MySQL

[pfx] Re: IP protocol inconsistency

2023-09-24 Thread Wietse Venema via Postfix-users
Polarian via Postfix-users: > What technology do you use to pick between the protocols? As documented at the link you mentioned, the Postfix SMTP CLIENT can sort IP addresses, with the same MX preference, by their protocol. RFC 5321 requires that the Postfix SMTP CLIENT connects to hosts with

[pfx] Re: milter outgoing not working

2023-09-24 Thread Wietse Venema via Postfix-users
Stanislav via Postfix-users: > Greetings, > > After upgrading from postfix 3.7.3 to postfix 3.8.2, I've noticed my > email is not signed with DKIM anymore. After further investigation, I've > found that Postfix ignores milter on outgoing emails (incoming goes > through milter ok). This has

[pfx] Re: pipelining issue

2023-09-20 Thread Wietse Venema via Postfix-users
Joey J via Postfix-users: > In: DATA > Out: 354 End data with . > Out: 451 4.3.0 Error: queue file write error Look in Postfix logs. https://www.postfix.org/DEBUG_README.html#logging Look for obvious signs of trouble Postfix logs all failed and successful deliveries to a logfile. When

[pfx] Re: Address family for hostname not supported?

2023-09-18 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Mon, Sep 18, 2023 at 10:31:59AM +1000, Phil Biggs via Postfix-users wrote: > > > >From what I could understand, it seems the recommendation was to return > > >the > > same value as Linux. Is that something postfix would need to take into > > account?

[pfx] Re: [ext] list.sys4.de fails with starttls

2023-09-17 Thread Wietse Venema via Postfix-users
In my case, all STARTTLS commands fail. Delivery succeeds after re-connecting with plaintext. Apparently, not all connections are retried in plaintext. To work around one could say: smtpd_discard_ehlo_keyword_address_maps = cidr:{ {188.68.34.52 starttls}

[pfx] Re: [PATCH 3.9-20230912] postconf(5)'s inet_protocols says "see 'postconf -d output'"

2023-09-16 Thread Wietse Venema via Postfix-users
??? via Postfix-users: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. > $ man 5 postconf | grep ^inet_protocols > inet_protocols (default: see 'postconf -d output') > $ man 5 postconf | grep -F "see 'postconf" > inet_protocols (default: see 'postconf -d output') >

[pfx] Re: how to log forwarded email subject

2023-09-14 Thread Wietse Venema via Postfix-users
Eero Volotinen via Postfix-users: > Hi list, > > I need to log all subjects that are forwarded via my mailproxy. how to do > this? > > looks like this is not working for me? > > https://www.linuxtechi.com/log-email-subject-maillog/ Then you made a mistake. Try "tail -f" instead of "tailf".

[pfx] Re: mask "mail from: " for Microsoft

2023-09-14 Thread Wietse Venema via Postfix-users
Marc Lucke via Postfix-users: > On 15/09/2023 12:08 am, Wietse Venema via Postfix-users wrote: > > > Marc Lucke via Postfix-users: > >> re: > >> https://techcommunity.microsoft.com/t5/exchange-team-blog/updated-requirements-for-smtp-relay-through-exchange-onl

[pfx] Re: mask "mail from: " for Microsoft

2023-09-14 Thread Wietse Venema via Postfix-users
Marc Lucke via Postfix-users: > re: > https://techcommunity.microsoft.com/t5/exchange-team-blog/updated-requirements-for-smtp-relay-through-exchange-online/ba-p/3851357 > That text is about relaying email: you originate a message, and use Postfix to ask a Microsoft email service to deliver

[pfx] Re: Number of active amavis processes

2023-09-13 Thread Wietse Venema via Postfix-users
Jesper Dybdal via Postfix-users: > On 2023-09-13 09:00, Matus UHLAR - fantomas via Postfix-users wrote (in > another thread): > > > you may need to limit number of concurrent amavis instances if you > > don't have enough of CPU or RAM, e.g. in main.cf: > > > >

[pfx] Re: postscreen_dnsbl_min_ttl only for success results?

2023-09-13 Thread Wietse Venema via Postfix-users
lutz.niederer--- via Postfix-users: > Hi! > > "The minimum amount of time that postscreen(8) will use the result from a > successful DNS-based reputation test before a client IP address is required > to pass that test again." > > By "successful" ... > > 1 - Do you mean that postscreen was

[pfx] Re: relay to a different server base on the ip

2023-09-10 Thread Wietse Venema via Postfix-users
Zorg via Postfix-users: > Hi > > let me explain, I m searching to relay mail according to the IP of > origin of the mail. > > But can't find a way to achieve this > > > for example > > Email coming from 10.1.1.1 will be send to 192.168.1.1 > > Email coming from 10.2.2.2??? will be send to

[pfx] Re: something like "enforce_mime_output_conversion"

2023-09-04 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Mon, Sep 04, 2023 at 12:18:38PM -0400, Viktor Dukhovni via Postfix-users > wrote: > > > It is best to enable this for outbound mail only, i.e. messages that > > arrive on the submission ports or through local submission via > >

[pfx] Re: something like "enforce_mime_output_conversion"

2023-09-04 Thread Wietse Venema via Postfix-users
Tinne11: > Is there some parameter which could have been named > enforce_mime_output_conversion in analogy to disable_mime_output_conversion > or some other way to configure this? Wietse Venema: > Presently, MIME downgrade is an after-queue feature (i.e. after > mail is queued), i

[pfx] Re: local_recipient_maps does not apply to local mail submission

2023-08-31 Thread Wietse Venema via Postfix-users
I have added text that ``Other Postfix interfaces may still accept an "unknown" recipient.'' in LOCAL_RECIPIENT_README.html and postconf.proto. Wietse ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to

[pfx] Re: how to rewrite domain on the fly before relaying

2023-08-30 Thread Wietse Venema via Postfix-users
Danil Smirnov via Postfix-users: > Hi Wietse, > > Thank you for your response! > > On Wed, Aug 30, 2023 at 8:07?PM Wietse Venema via Postfix-users < > postfix-users@postfix.org> wrote: > > > This is one of the purposes of virtual_alias_maps. > > > &

[pfx] Re: how to rewrite domain on the fly before relaying

2023-08-30 Thread Wietse Venema via Postfix-users
Danil Smirnov via Postfix-users: > Hi, > > I have a Postfix server that serves domain1.tld > using transport_maps, local_recipient_maps, and relay_domains parameters in > order to relay all incoming emails to the local LMPT listener. > > Now I want to receive emails @domain2.tld in the same

[pfx] Re: smtpd_command_filter: Bounce-never regex sample wrong?

2023-08-27 Thread Wietse Venema via Postfix-users
lutz.niederer--- via Postfix-users: > Hi! > > In postconf > smtpd_command_filter section there is an example for never > bouncing mails (no DSN): > > # Bounce-never mail sink. Use notify_classes=bounce,resource,software > # to send bounced mail to the postmaster (with message body

[pfx] Re: Comcast still 421 throttling (RL000001) multiple recipients.

2023-08-27 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Bill Sommerfeld via Postfix-users: > > About three years ago there was a thread on postfix-users ("Comcast 421 > > throttling multiple recipients") discussing a low-traffic site having > > difficulties sending to multiple recipie

[pfx] Re: Comcast still 421 throttling (RL000001) multiple recipients.

2023-08-27 Thread Wietse Venema via Postfix-users
Bill Sommerfeld via Postfix-users: > About three years ago there was a thread on postfix-users ("Comcast 421 > throttling multiple recipients") discussing a low-traffic site having > difficulties sending to multiple recipients at comcast in a single smtp > session. The thread starts here: > >

[pfx] Re: Spam mails seen in logfiles question

2023-08-25 Thread Wietse Venema via Postfix-users
Bill Cole via Postfix-users: > On 2023-08-23 at 14:38:18 UTC-0400 (Wed, 23 Aug 2023 12:38:18 -0600) > IUL Support via Postfix-users > is rumored to have said: > > > I must be missing something in what you're saying. > > > > If the server receives a message for myu...@mydomain.com and myuser's >

[pfx] Re: How can I set up a very simple postfix server

2023-08-23 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > |Alls you need is to 'mount' the maildtop directory into a container > |with read/write permission, and install the Postfix sendmail and > |postdrop programs insalled in the container. As long as there is a > |Postfix pickup daemon running somewhere, it

[pfx] Re: How can I set up a very simple postfix server

2023-08-22 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > "But" postfix's sendmail reads the postfix configuration, it will > not work otherwise, at least once i tried last. > Going over SMTP (submission that is) can share a single postfix > instance in between many containers that do not have access to > the actual

[pfx] Re: Rate limiting gmail

2023-08-22 Thread Wietse Venema via Postfix-users
Jaroslaw Rafa via Postfix-users: > Dnia 22.08.2023 o godz. 15:41:43 Alex via Postfix-users pisze: > > This mail server unfortunately has quite a few users who use ~/.forward to > > forward mail through to their personal gmail account from their corporate > > account. > > > > Aug 22 15:33:08

[pfx] Re: reverse DNS question for HELO hostname

2023-08-22 Thread Wietse Venema via Postfix-users
Peter H via Postfix-users: > Hello, > > When my mailserver talks to other MTA, it certainly will issue a HELO > command. > > Saying the hostname after HELO is: mail.host.com, which points to an IP. > > But this IP's PTR doesn't point back to the hostname above. A Postfix SMTP server will set

[pfx] Re: How can I set up a very simple postfix server

2023-08-22 Thread Wietse Venema via Postfix-users
Bruce Dubbs via Postfix-users: > I have built postfix-3.8.1 from source and want to use it only on the local > system. > That is, I really only want it to receive messages from applications like > sudo, cron, > or some simple scripts using mailx and post it to the local user's mailbox. > > My

[pfx] Re: SASL authentication with colon „:“ in username not possible

2023-08-20 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > If we change the syntax of smtp_sasl_password_maps entries, then > that will require a new configuration parameter to indicate how the > lookup result should be parsed. > > My preference would be: > > smtp_sasl_password_map_result_deli

[pfx] Re: PATCH: Postfix does not fallback to plaintext

2023-08-20 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > The patch below should apply to Postfix 3.0 and later. It disables > the 'time before active queue' threshold for probe messages. Serg (the OP in this thread) confirmed immediately that this patch solved his problem. This code is now available in the post

[pfx] Re: smtp auth on port 25

2023-08-16 Thread Wietse Venema via Postfix-users
Jon Smart via Postfix-users: > > Jon Smart via Postfix-users skrev den 2023-08-16 04:01: > > > >> How can I disable auth on port 25? I really don't want users to use > >> port > >> 25 for auth sender. i am using postfix version 3.6.4 on ubuntu 22.04. > > > > its default disabled, no ? > > > >

[pfx] Re: local_recipient_maps does not apply to local mail submission

2023-08-16 Thread Wietse Venema via Postfix-users
Etienne Miret via Postfix-users: > > If there is a DISCREPANCY between local_recipient_maps and your > > local delivery agent, then you MUST UPDATE your local_recipient_maps > > accordingly. > > I wasn't complaining about that discrepancy. I was complaining that the > local_recipient_maps is

[pfx] Re: local_recipient_maps does not apply to local mail submission

2023-08-16 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > ?tienne Miret via Postfix-users: > > I found this discrepancy surprising and am suggesting it is removed. In > > case others argue it is useful or that removing it will break some > > configurations, I am asking it is documen

[pfx] Re: local_recipient_maps does not apply to local mail submission

2023-08-16 Thread Wietse Venema via Postfix-users
?tienne Miret via Postfix-users: > I found this discrepancy surprising and am suggesting it is removed. In > case others argue it is useful or that removing it will break some > configurations, I am asking it is documented. The default local_recipient_maps setting uses the UNIX password

[pfx] Re: local_recipient_maps does not apply to local mail submission

2023-08-15 Thread Wietse Venema via Postfix-users
?tienne Miret via Postfix-users: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. > Hello, > > After troubleshooting an issue on my Postfix server, I found out that > the local_recipient_maps parameter is ignored for locally submitted > emails. That is, a recipient

[pfx] PATCH: Postfix does not fallback to plaintext

2023-08-15 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Tue, Aug 15, 2023 at 11:33:08AM -0400, Wietse Venema via Postfix-users > wrote: > > > With that, the condition evaluates to: > > > > 1: session->tls_context == 0 true > > 2: state->tls->

[pfx] Re: Postfix does not fallback to plaintext

2023-08-15 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Tue, Aug 15, 2023 at 11:33:08AM -0400, Wietse Venema via Postfix-users > wrote: > > > With that, the condition evaluates to: > > > > 1: session->tls_context == 0 true > > 2: state->tls->

[pfx] Re: Postfix does not fallback to plaintext

2023-08-15 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > > > Aug 15 12:22:18 flopster postfix/cleanup[9839]: 5058916E081A: > > > message-id=<20230815092218.5058916e0...@flopster.at.encryp.ch> > > > Aug 15 12:22:18 flopster postfix/qmgr[11478]: 5058916E081A: > > > from=, size=316, nrcpt=1 (queue active) > > > Aug 15

[pfx] Re: Troubleshooting mail loop issue

2023-08-15 Thread Wietse Venema via Postfix-users
Your loop, based on Received: headers, newer at the top, older at the bottom: Received: from xavier.example.com (209.216.111.114) by CO1PEPF44F7.mail.protection.outlook.com (10.167.241.197) with Microsoft S Received: from localhost by xavier.example.com (Postfix) with ESMTP id

[pfx] Re: Disappointments at https://www.postfix.org/docs.html

2023-08-14 Thread Wietse Venema via Postfix-users
DL Neil via Postfix-users: > The "Postfix Howtos and FAQs" is out-dated and requires > correction/editing. To assist the web-master:- Checking links takes timm, so thanks for doing that. I think it is best to drop the page with 'howto' links. The page was created almost a decade before sites

[pfx] Re: SASL authentication with colon „:“ in username not possible

2023-08-14 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > There is a tool that given a JSONschema will generate a parser in > C that populates a C structure, at github.com/badicsalex/json_schema_to_c > (~300 LOC). This depends on github.com/zserge/jsmn (~500 LOC). The > generated parser is much bigger,

[pfx] Re: SASL authentication with colon „:“ in username not possible

2023-08-13 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Sun, Aug 13, 2023 at 01:47:05PM -0400, Wietse Venema via Postfix-users > wrote: > > > > Any votes for JSON? :-) > > > > > > { "account": "user:foo", "base64password": "

[pfx] Re: SASL authentication with colon „:“ in username not possible

2023-08-13 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Sat, Aug 12, 2023 at 08:05:52PM -0400, Wietse Venema via Postfix-users > wrote: > > > My preference would be: > > > > smtp_sasl_password_map_result_delimiter > > printable character or C escape (like \t for TAB) &

[pfx] Re: SASL authentication with colon „:“ in username not possible

2023-08-12 Thread Wietse Venema via Postfix-users
zonie via Postfix-users: > > > > Wietse Venema via Postfix-users : > > > > ?zonie via Postfix-users: > >> Hello, > >> > >> currently it's not possible to specify a username containing a colon ?:? > >> inside a ?smt

[pfx] Re: email being flagged a spam for using localhost [127.0.0.1] as first hop

2023-08-09 Thread Wietse Venema via Postfix-users
Michel Verdier via Postfix-users: > On 2023-08-09, Steffen Nurpmeso via Postfix-users wrote: > > > 192.0.2.1:submission inet n - n - - smtpd > > -o syslog_name=vpnsub > > -o smtpd_sasl_auth_enable=no > > -o > >

[pfx] Re: email being flagged a spam for using localhost [127.0.0.1] as first hop

2023-08-09 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Wed, Aug 09, 2023 at 02:53:02PM -0400, Wietse Venema wrote: > > > > > vpnsub_cleanup unix n - n - 0 cleanup > > > > -o {header_checks=regexp:{{/^Received:/ IGNORE}}} > > &

[pfx] Re: email being flagged a spam for using localhost [127.0.0.1] as first hop

2023-08-09 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Viktor Dukhovni via Postfix-users: > > On Wed, Aug 09, 2023 at 06:48:11PM +0200, Steffen Nurpmeso via > > Postfix-users wrote: > > > > > Yeah the wonderful suggestion of this super helpful list (thanks > > > again!) for

[pfx] Re: email being flagged a spam for using localhost [127.0.0.1] as first hop

2023-08-09 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Wed, Aug 09, 2023 at 06:48:11PM +0200, Steffen Nurpmeso via Postfix-users > wrote: > > > Yeah the wonderful suggestion of this super helpful list (thanks > > again!) for my setup (laptop postfix on "forbidden address" relays > > to in-VPN postfix which

[pfx] Re: email being flagged a spam for using localhost [127.0.0.1] as first hop

2023-08-09 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > Michel Verdier via Postfix-users wrote in > <87fs4s49y5@free.fr>: > |On 2023-08-09, Fourhundred Thecat via Postfix-users wrote: > | > |> do you think this would be OK, or does the hostname and IP (be it > |> localhost.local) have to be there ? > | >

[pfx] Re: bounce management

2023-08-08 Thread Wietse Venema via Postfix-users
Matus UHLAR - fantomas via Postfix-users: > >> > We're only doing basic spam protection for them, > >> > >> What is the nature of the "basic spam protection"? Can it be done > >> pre-queue? > > On 07.08.23 15:19, Alex via Postfix-users wrote: > >Yes, most likely, I would think. It's a basic

[pfx] Re: bounce management

2023-08-07 Thread Wietse Venema via Postfix-users
Alex via Postfix-users: > Hi, > > > > > We're only doing basic spam protection for them, > > > > What is the nature of the "basic spam protection"? Can it be done > > pre-queue? > > > > Yes, most likely, I would think. It's a basic spamassassin setup with a few > rules looking for specific

[pfx] Re: sender_dependend_relay_host_maps and local recipients

2023-07-24 Thread Wietse Venema via Postfix-users
Robert Senger via Postfix-users: > Hi Viktor, > > thank you. So, it's not possible to route email different when sent > from an authenticated user through port 587, than imcoming email sent > through port 25? This would avoid a loop, as far as I understand > things... Postfix routing does not

[pfx] Re: server does not pick up new certificates

2023-07-24 Thread Wietse Venema via Postfix-users
Bernardo Reino via Postfix-users: > >> I cannot imagine why/when the cerbot client would fail to run the > >> post-hooks (in a sane environment). > > > > Systems crash. What are the reliability guarantees from the certbot > > client: will it run once, or will it somehow maintain state and > >

[pfx] Re: server does not pick up new certificates

2023-07-24 Thread Wietse Venema via Postfix-users
Bernardo Reino via Postfix-users: > On Sun, 23 Jul 2023, Viktor Dukhovni via Postfix-users wrote: > > > On 23 Jul 2023, at 4:21 pm, Charles Sprickman via Postfix-users > > wrote: > > > >> In the case of the dehydrated ACME client > >> (https://github.com/dehydrated-io/dehydrated) there's an

[pfx] Re: server does not pick up new certificates

2023-07-23 Thread Wietse Venema via Postfix-users
lejeczek via Postfix-users: > > > On 23/07/2023 16:00, Wietse Venema wrote: > > lejeczek via Postfix-users: > >> -> $ postfix reload # did not work, new certs/files where > >> only picked up with "full" restart, with "systemd" in this cas

[pfx] Re: server does not pick up new certificates

2023-07-23 Thread Wietse Venema via Postfix-users
lejeczek via Postfix-users: > -> $ postfix reload # did not work, new certs/files where > only picked up with "full" restart, with "systemd" in this case. > > and when done, then server-postifx supplied new certs > immediately - clients where happy. > > I was thinking "glitch" for perhaps

[pfx] Re: postfix database, aliases, permissions, configuration issue, help requested, perplexed

2023-07-22 Thread Wietse Venema via Postfix-users
David Mehler via Postfix-users: > Hello, > > Thanks everyone for the feedback. > > I've commented out proxy_read_maps which seems to have done it, > postfix/local isn't trying to get in to things and aliases are > working, though I'm not sure if the perms there are right, 755 > root:root on

[pfx] Re: SASL authentication with colon „:“ in username not possible

2023-07-19 Thread Wietse Venema via Postfix-users
zonie via Postfix-users: > Hello, > > currently it's not possible to specify a username containing a colon ?:? > inside a ?smtp_sasl_password_map?, as the colon is used to split username and > password from each other. > > Is this limitation intentionally or was it just overlooked? Just like

[pfx] Re: something like "enforce_mime_output_conversion"

2023-07-18 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Tinne11 via Postfix-users: > > Is there some parameter which could have been named > > enforce_mime_output_conversion in analogy to disable_mime_output_conversion > > or some other way to configure this? > > It would avoid the need

[pfx] Re: something like "enforce_mime_output_conversion"

2023-07-18 Thread Wietse Venema via Postfix-users
Tinne11 via Postfix-users: > Is there some parameter which could have been named > enforce_mime_output_conversion in analogy to disable_mime_output_conversion > or some other way to configure this? It would avoid the need for (null) content filters that I discuss in my other response. However

[pfx] Re: something like "enforce_mime_output_conversion"

2023-07-18 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Tue, Jul 18, 2023 at 01:43:46PM +0200, Tinne11 via Postfix-users wrote: > > > In order to follow this recommendation, a Postfix MSA (being part of a > > system DKIM-signing outbound messages) needs to be configured to convert all > > submitted 8-bit

[pfx] Re: Mail archival like with always_bcc, but different BCC destinations by virtual mailbox domains

2023-07-16 Thread Wietse Venema via Postfix-users
r.barclay--- via Postfix-users: > Hello, > > I have a Postfix installation for virtual mailboxes. It is the > mail server (inbound MX and outbound) for a few domains. The server > allows submission with SMTP AUTH (Dovecot SASL). > > At the moment I use always_bcc to "copy" / mirror any inbound

[pfx] Re: local sending

2023-07-11 Thread Wietse Venema via Postfix-users
Ken Gillett via Postfix-users: > I disagree about Apple. In this respect they most definitely ARE > idiots. Email addresses do NOT require anything after the @. That > simply means the user of that name on the current host. If they Postfix by design makes this impossible; it was written as a

[pfx] Re: warn_if_reject and MILTER

2023-07-11 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Patrick Ben Koetter via Postfix-users: > > Greetings, > > > > I was wondering if there's something similar to warn_if_reject when it comes > > to dry-run / test-run MILTER applications in Postfix. The documentation on > > warn_i

[pfx] Re: warn_if_reject and MILTER

2023-07-11 Thread Wietse Venema via Postfix-users
Patrick Ben Koetter via Postfix-users: > Greetings, > > I was wondering if there's something similar to warn_if_reject when it comes > to dry-run / test-run MILTER applications in Postfix. The documentation on > warn_if_reject does not mention MILTERs, which usually means the feature isn't >

[pfx] Re: where setup permit_mx_backup

2023-07-11 Thread Wietse Venema via Postfix-users
Tom Reed via Postfix-users: > Greeting list, > > besides relay_domains, I can use permit_mx_backup to setup a secondary MX > server. permit_mx_backup should be used ONLY after reject_unverified_recipient, otherwise Postfix will accept mail for non-existent recipients, the Postfix mail queue will

[pfx] Re: Send every mail to external antispam gateway

2023-07-10 Thread Wietse Venema via Postfix-users
Alexander Rehbein via Postfix-users: > Hello, > > I'm looking for a solution to send every mail, also from one internal > mailbox to another internal mailbox, to an external server which check > the mails. The external server will send every mail back to postfix. > Also every external mail will

[pfx] Re: which main.cf and postconf

2023-07-10 Thread Wietse Venema via Postfix-users
Ken Gillett via Postfix-users: > What does 'postconf -d' show? "postconf -d config_directory" shows where the postconf command looks for main.cf (and master.cf). The settings in mainl.cf then determine the location of other Postfix program and data files. It would be worthwhile to find out if

[pfx] Re: pattern matching in local tables

2023-07-07 Thread Wietse Venema via Postfix-users
joe a via Postfix-users: > On 7/7/2023 3:46 PM, joe a via Postfix-users wrote: > > One hesitates to post this. > > > > Found some oddness when changing a destination in transport_maps > > (transport_maps = lmdb:/etc/postfix/transport). > > > > Seems related to pattern matching. > > > > The

[pfx] Re: Getting Recipient when Message size limit is exceeded

2023-07-07 Thread Wietse Venema via Postfix-users
If no-one else posts one, I can post a solution that: - relies on smtpd_delay_reject=yes to postpone check_policy lookup until RCPT TO. - disables the SIZE announcement in EHLO - diusables the SIZE check in MAIL FROM - calls check_policy to let postfwd (etc.) reject mail, but that only works

[pfx] Re: Maildir changes in 3.7.4?

2023-07-06 Thread Wietse Venema via Postfix-users
Dan Mahoney via Postfix-users: > All, > > We have our aliases file pushing things into our RT install, but > also saving things to a maildir, so we can manually feed a single > file back in, thusly: > > In /etc/aliases: > > noc:"|/usr/local/sbin/rtmailgate ops noc

[pfx] Re: virtual_mailbox_map not needed anymore?

2023-07-05 Thread Wietse Venema via Postfix-users
Juerg Reimann via Postfix-users: > Hello group > > I'm a bit puzzled here. I usually create new users first for > Dovecot, then add to the configuration of Postfix the path to the > relative maildir in virtual_mailbox_maps (the domain and other > users for that virtual domain already exist). Now

[pfx] Re: Typo in man postconf ("Postix")

2023-07-03 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Tue, Jul 04, 2023 at 06:19:26AM +1000, Trent W. Buck via Postfix-users > wrote: > > > master:postfix/proto/postconf.proto:6450: This feature is available in > > Postix 2.10 and later. > > master:postfix/proto/stop:1185:Postix > > > > Are these typos? >

[pfx] Re: Postfix "sendmail -bv" command: Trouble with spamassassin and virtual_aliases

2023-06-29 Thread Wietse Venema via Postfix-users
Robert Senger via Postfix-users: > Hi all! > > I am running Postfix 3.4.23 on Debian 10.13 Buster, with SpamAssassin > 4.0.0 and spamass-milter 0.4.0-2 for spam detection. > > Until now, SpamAssassin was configured to use system wide bayes > database for the bayesian classifier, which is trained

[pfx] Re: Upgrading from 2.1.10 to 3.7.4.1

2023-06-27 Thread Wietse Venema via Postfix-users
Patrick Mahan via Postfix-users: > I lost my domain server a few weeks ago just as I was leaving on a > pre-paid vacation with the family. I have replaced the server (running > FreeBSD) and am in the process of getting my domain services (dns, mail, > etc) back up and running. > > I am taking

[pfx] Re: Forward inside other forward fails for non-local accounts

2023-06-26 Thread Wietse Venema via Postfix-users
Alberto Lepe via Postfix-users: > I'm sorry, I realized that I made a mistake while trying to translate the > real situation to a simple example in my original message: > > Instead of: > a...@example.com -> ( (y...@example.com -> yuko@localhost) and > yuko.exam...@gmail.com) > Aliases: >

[pfx] Re: Mail delivery to a higher priority MX record for a given domain.

2023-06-23 Thread Wietse Venema via Postfix-users
anant--- via Postfix-users: Content-Description: Plaintext Message > Hello, > > For a domain, we are finding in logs that, for most of the mails, > mails are getting delivered to a server of remote domain having lower > priority MX record.? For some mails, the mail is getting delivered to

[pfx] Re: Postfix: running a script on authentication failure

2023-06-22 Thread Wietse Venema via Postfix-users
Postfix does not implement SASL auth. It proxies the bits betwen the remote SMTP client and (SASL library or Dovecot). If you must see SASL details, use Dovecot "auth_debug=yes" logging, and run a tool that acts on that information. Wietse ___

[pfx] Re: Submission behaviour

2023-06-20 Thread Wietse Venema via Postfix-users
Andr? Rodier via Postfix-users: > However, is there an option, in Postfix, to keep the TCP connection > opened for submission(s) protocols (ports 465 or 587) For RECEIVING mail, specify a long smtpd_timeout value, like 1000s master.cf: submission .. .. .. .. .. .. .. smtpd other

[pfx] Re: Is it possible in postfix spf policy to utilize multiple action=prepend to add multiple headers?

2023-06-19 Thread Wietse Venema via Postfix-users
Jaroslaw Rafa via Postfix-users: > Dnia 19.06.2023 o godz. 16:53:58 Anton Hvornum via Postfix-users pisze: > > > > Thank you, yes that one slipped by me entirely. > > I'll have to re-evaluate how to mark mails as spam with multiple > > headers when SPF is not passing then. > > To add multiple

<    1   2   3   4   5   6   7   8   9   10   >