[pfx] Re: SASL login username in log

2024-05-28 Thread Wietse Venema via Postfix-users
Northwind via Postfix-users: > Hello, > > Is it possible to set mail.log for recording sasl login usernames? > > May 29 06:52:45 mx postfix/smtps/smtpd[3022855]: warning: > unknown[138.185.193.64]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 > May 29 06:52:57 mx postfix/smtpd[3023133]:

[pfx] Re: Masters.cf

2024-05-28 Thread Wietse Venema via Postfix-users
John Hill via Postfix-users: > > On 5/28/24 11:48 AM, Wietse Venema via Postfix-users wrote: > > postconf -Mf submission/inet". > > > May 28 10:51:07 proteus.noach.com postfix/submission/smtpd[57120]: > warning: malformed map specification: '{ reject_r

[pfx] Re: "delivered to command" config

2024-05-28 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Adam Weremczuk via Postfix-users: > > I've tried your suggestion. > > > > SERVER1 is still trying to deliver test email locally rather than > > forward to SERVER2: According to your postfinger output, you did not confihgure vi

[pfx] Re: Masters.cf

2024-05-28 Thread Wietse Venema via Postfix-users
John Hill via Postfix-users: > Not working had recipient instead of client. Fixed that and then is says > its not a map. We need: - The complete error message, exactly as logged. - Output from "postconf -Mf submission/inet". Wietse > > On 5/28/24 10:36 AM, John Hill via Postfix-users

[pfx] Re: "delivered to command" config

2024-05-28 Thread Wietse Venema via Postfix-users
Adam Weremczuk via Postfix-users: > I've tried your suggestion. > > SERVER1 is still trying to deliver test email locally rather than > forward to SERVER2: > > : host > mx0.myLANdomain.com[/var/run/cyrus/socket/lmtp] said: 550-Mailbox > unknown. Either there is no mailbox associated

[pfx] Re: "delivered to command" config

2024-05-28 Thread Wietse Venema via Postfix-users
command defined in ~bugzilla2/.forward file > > So my first objective, I guess, would be to allow that local user to > receive emails from outside somehow and be treated as local emails. > > I feel like I'm missing something fundamental here... > > Adam > > > On 21/05/

[pfx] Re: Capture Bounced Email Headers & Content

2024-05-28 Thread Wietse Venema via Postfix-users
Greg Sims via Postfix-users: > > On Mon, May 27, 2024 at 3:40?AM Viktor Dukhovni via Postfix-users < > postfix-users@postfix.org> wrote: > > > You really should have posted "collate" output, which would have shown > > the envelope sender address in the "qmgr active" log entry. Perhaps > > the

[pfx] Re: Capture Bounced Email Headers & Content

2024-05-26 Thread Wietse Venema via Postfix-users
Greg Sims via Postfix-users: > We found the following in our email log: > > May 26 00:35:57 mail01.raystedman.org postfix/t124/smtp[39065]: > 0A7D630F1C7C: to== > cecytebc.edu...@devotion.raystedman.org>, > relay=aspmx.l.google.com[142.251.2.26]:25, > delay=0.52, delays=0/0/0.21/0.31,

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-26 Thread Wietse Venema via Postfix-users
This problem was resolved off-list. Greg Sims: > Wietse & Viktor, > > All is not lost. Restarting BIND on Ray08 solved the problem of > c=30!! I am sorry that I did not review/restart this service earlier. > Your comments related to the 5 second intervals and DNS timeouts > caused me to look

[pfx] Re: How to allow only one specific sender to use smtp ?

2024-05-25 Thread Wietse Venema via Postfix-users
Mike via Postfix-users: > Hello, > > My setup like below: > > I have Postfix setup and use dovecot as SASL. Now, all email accounts > can use the smtp server to send emails. I want to allow only one email > account to send out emails and rest of others can only use POP3 or IMAP. > > How can I

[pfx] Re: SASL reject force disconnect

2024-05-25 Thread Wietse Venema via Postfix-users
John Hill via Postfix-users: > > postscreen_dnsbl_sites = zen.spamhaus.org=127.0.0.[2..11] > Is this the same thing? See https://www.spamhaus.org/faqs/dnsbl-usage/#200 for a table with the purpose of different lookup results. To block xbl listed clients with postscreen, one would configure

[pfx] Re: SASL reject force disconnect

2024-05-23 Thread Wietse Venema via Postfix-users
John Hill via Postfix-users: > I learn something every time I read this group, when I can keep up with > the conversation! > > I had auth on ports I did not need. I use auth on submission port 587, > for users access. > > I do get a boat load of failed login attempts on 587. Funny how a China,

[pfx] Re: disable authentication on port 25

2024-05-23 Thread Wietse Venema via Postfix-users
Northwind via Postfix-users: > Hello, > > since my smtp instance is postscreen as showing the follow, > > smtp inet n - y - 1 postscreen > > > How can I disable authentication on port 25 then? > > I know if the smtp instance is smtpd, this option should

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-23 Thread Wietse Venema via Postfix-users
Greg Sims via Postfix-users: > We see conn_use about 24% of the time: But none of the sessions shown in your message have that. Do they also have multiple-of-5-second type 'c' delays? Wietse ___ Postfix-users mailing list --

[pfx] Re: Dedicated servers for Address Verification Probes

2024-05-23 Thread Wietse Venema via Postfix-users
Pedro David Marco via Postfix-users: > Hi all, > is it possible to have several Postfix instances to use a centralized > Postfix server for address verification probes when this centralized > server is NOT an MDA but a relay to external MDAs? You can specify address_verify_relayhost and the like,

[pfx] Re: how disable DSN pipe]

2024-05-23 Thread Wietse Venema via Postfix-users
You have been perfectly clear. As outlined in DSN_README, the RFC does not support a way to selectively disable SUCCESS notification. Postfix is not just a bunch of random hacks thrown together. You are free to use a different mail system. Wietse

[pfx] Re: how disable DSN pipe

2024-05-23 Thread Wietse Venema via Postfix-users
Aleksandr Kolesnikov via Postfix-users: > if the user requests a DSN, he receives a delivery message via the ... > how to prohibit the sending of such DSN? Perhaps: https://www.postfix.org/DSN_README.html Wietse ___ Postfix-users mailing

[pfx] Re: Strengthen email system security

2024-05-22 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Northwind via Postfix-users: > > Hello list, > > > > In the last two days, my mail system (small size) met attacks. > > > > mail.log shows a lot of this stuff: > > > > May 23 06:24:29 mx postfix/smtpd[2655149]: warn

[pfx] Re: Strengthen email system security

2024-05-22 Thread Wietse Venema via Postfix-users
Northwind via Postfix-users: > Hello list, > > In the last two days, my mail system (small size) met attacks. > > mail.log shows a lot of this stuff: > > May 23 06:24:29 mx postfix/smtpd[2655149]: warning: > unknown[194.169.175.17]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 This just

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-22 Thread Wietse Venema via Postfix-users
Greg Sims via Postfix-users: > > It is assumed that you're not a victim of systemd-journald log mangling. > > It may be dropping some messages, and recording others out of order, > > breaking "collate". On Linux systems where systemd is doing the > > logging, you'll want to have Postfix writing

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-22 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Greg Sims via Postfix-users: > > May 22 03:13:22 mail01.raystedman.org t123/smtp[46725]: > > 604BE30A4ACA: to=<@gmail.com>, > > relay=gmail-smtp-in.l.google.com[142.251.2.26]:25, conn_use=2, > > delay=1576, delays=0.05/1550/25/

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-22 Thread Wietse Venema via Postfix-users
Greg Sims via Postfix-users: > May 22 03:13:22 mail01.raystedman.org t123/smtp[46725]: > 604BE30A4ACA: to=<@gmail.com>, > relay=gmail-smtp-in.l.google.com[142.251.2.26]:25, conn_use=2, > delay=1576, delays=0.05/1550/25/0.84, dsn=2.0.0, status=sent (250 > 2.0.0 OK 1716372802

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-22 Thread Wietse Venema via Postfix-users
Greg Sims via Postfix-users: > This is a sample of delays= for google.com -- 20 and 25 second delays: > > 0.01/11/20/0.73, > 0.01/9.5/20/0.77, > 0.01/0/25/0.74, > 0.01/7.6/25/0.91, > 0.01/6.9/25/1.1, > 0.01/13/20/4.6, > 0.01/14/25/0.56, > 0.01/14/25/1.1, > 0.01/0/0.22/0.72, >

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-21 Thread Wietse Venema via Postfix-users
Jaroslaw Rafa via Postfix-users: > Dnia 21.05.2024 o godz. 16:38:21 Wietse Venema via Postfix-users pisze: > > > delays=0.01/2639/25/0.41 > > > delays=0.01/2639/25/0.58 > > > delays=0.01/2641/25/0.58 > > > delays=0.01/2644/25/0.69 > > > d

[pfx] Re: Selection of a custom smtp-transport based on recipient addresse's MX with check_recipient_mx_access doesn't work

2024-05-21 Thread Wietse Venema via Postfix-users
Jaroslaw Rafa via Postfix-users: > Dnia 21.05.2024 o godz. 22:27:04 Henri Schom?cker via Postfix-users pisze: > > > > So what we need to do is to limit the sending rate to all MX servers > > under protection-outlook-com. > > Postfix does not support this, Wietse probably could explain why. > You

[pfx] Re: Disable Non Delivery Notifications only for some adresses

2024-05-21 Thread Wietse Venema via Postfix-users
Kevin Cousin via Postfix-users: > Hi, > > We are using Postfix as relay for our internal apps. This apps are > sending mails to final users with from nore...@example.net, but > sometimes, adresses are wrong and a Non delivery notification is > generated ans sent back to nore...@example.net. > >

[pfx] Re: TLS for SMTP Outbound -- Only One tlsproxy

2024-05-21 Thread Wietse Venema via Postfix-users
Greg Sims via Postfix-users: > Thank you Viktor. > > Answers: > * smtp_connection_cache_on_demand = yes -- this was configured > > Changes: > * certs back to defaults > * smtp_tls_loglevel = 1 > > Before enabling TLS our send rate was about 4K emails per minute -- we > are now seeing 300

[pfx] Re: "delivered to command" config

2024-05-21 Thread Wietse Venema via Postfix-users
Adam Weremczuk via Postfix-users: > Thank you Victor. > > What's the easiest way to change: > > bugzilla@mailserver:~$ cat ~/.forward > "|/vol/localhome/bugzilla/site/live/email_in.pl -vvv 2>/tmp/bz_emailin.log" > > to something like: > >

[pfx] Re: Dovecot logging to files causes postfix to break

2024-05-19 Thread Wietse Venema via Postfix-users
Northwind via Postfix-users: > Hello > > When postfix delivery messages to local dovecot, how does the > authentication between postfix and dovecot happen? Local delivery does not involve IMAP. BTW This is the Postfix mailing list. Questions about Dovecot are better asked on their forum.

[pfx] Re: Dovecot logging to files causes postfix to break

2024-05-18 Thread Wietse Venema via Postfix-users
Richard Rosner via Postfix-users: > I have a mailing server setup based on Debian Stable that uses > postfix for IMAP and SMTP and dovecot for internel mail handling, You mean, Postfix for SMTP, Dovecot for IMAP. > like filtering, sorting into users inboxes etc. I now wanted to > set dovecot to

[pfx] Re: Postfix not doing round robin for equal weight MX records

2024-05-17 Thread Wietse Venema via Postfix-users
John Doe via Postfix-users: > We have enabled TLS on nlp3 and all traffic is even now :) > Now it's time for a change to be able to reuse connections for TLS. That would be: smtp_tls_connection_reuse = yes Available in Postfix 3.4 and later. As you have found, connection reuse speeds up

[pfx] Re: inet_interfaces and loopback

2024-05-16 Thread Wietse Venema via Postfix-users
Alex via Postfix-users: > postfix[1350]: egrep: warning: egrep is obsolescent; using grep -E > postfix-out/postfix-script[1355]: starting the Postfix mail system > postfix-out/master[1357]: daemon started -- version 3.7.9, > configuration /etc/postfix-out That is the 'postfix-out' instance.

[pfx] Re: Fwd: [S-announce] [ANN]ounce of s-dkim-sign v0.6.1

2024-05-13 Thread Wietse Venema via Postfix-users
This discussion seems of-topic for the postfix-users mailing list. If you feel strongly about how email is authenticated, I suggest that you join the relevant working group discussions while the details are still mutable. Complaining about the final result is too late, and publishing

[pfx] Re: Postfix not doing round robin for equal weight MX records

2024-05-12 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Fri, May 10, 2024 at 01:13:06PM -0400, Wietse Venema via Postfix-users > wrote: > > > > Logs: > > > grep relay=nlp[123456].*status=sent /var/log/maillog | sed > > > 's/.*relay=//' | sed 's/,.*//' | sort | uniq -c

[pfx] Re: Postfix not doing round robin for equal weight MX records

2024-05-10 Thread Wietse Venema via Postfix-users
Wietse Venema: > Please provide evidence in the form of logs that show the > preference. John Doe: > Is this OK / enough ? > Logs: > grep relay=nlp[123456].*status=sent /var/log/maillog | sed > 's/.*relay=//' | sed 's/,.*//' | sort | uniq -c > 5770 [23]nlp1.loc-prd.net[10.56.155.14]:25 > 5694

[pfx] Re: Postfix not doing round robin for equal weight MX records

2024-05-10 Thread Wietse Venema via Postfix-users
John Doe via Postfix-users: > Hi, > > I was hoping for real MX record round-robin but it does not work on one of > my servers. > > Somehow, postfix is prioritising one of the MX more than others. By default, Postfix looks up SMTP servers in DNS, and randomizes the order of equal-preference

[pfx] Re: Difference between alias_maps and alias_database

2024-05-07 Thread Wietse Venema via Postfix-users
On Tue, May 07, 2024 at 05:47:59PM +0200, Matus UHLAR - fantomas via Postfix-users wrote: > On 07.05.24 17:13, Дилян Палаузов via Postfix-users wrote: > >I try to understand the difference between alias_database and alias_maps. > > >Or, does postalias/newaliases use is alias_database as input,

[pfx] Re: When to set virtual_alias_domains, when virtual_mailbox_domains is already set?

2024-05-06 Thread Wietse Venema via Postfix-users
On Mon, May 06, 2024 at 11:37:54AM +0200, Дилян Палаузов via Postfix-users wrote: > Hello, > > postconf(5) contains: > > virtual_alias_domains (default: $virtual_alias_maps) > virtual_alias_maps (default: $virtual_maps) > virtual_maps (default: empty) > > Thus virtual_alias_domains is by

[pfx] Re: rejecting mails to expired accounts including a hint at the new address

2024-05-04 Thread Wietse Venema via Postfix-users
Edgar Fuss via Postfix-users: > Hello, > > I'm looking for prior art on rejecting mails to expired accounts > including a hint at the new address. You could use the relocated_maps feature for this. This will reject at RCPT TO time, with a hard-coded response "5.1.6 User has moved to ". You

[pfx] Re: Relaying Teams Invitations send by Microsoft365 via Postfix to the Internet

2024-05-03 Thread Wietse Venema via Postfix-users
Norbert Schmidt via Postfix-users: > Hello, > > We've got a single user needing Micro$oft Teams. This users mailaccount > u...@contenso.com is configured on our server AND within Microsoft365 as > sending address for the invitations. > All other mail accounts are local and send via postfix. >

[pfx] Re: milter: how about a SMFIP_NOQUIT?

2024-05-02 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Looks like there is sufficient basis to make SMTPD_QUIT_NC rerquests > thts from Postfix. Just need to figure out how to enable/disable > this particular command based on the Postfix and Milter protocol > versions. There is already some 'set' inter

[pfx] Re: long header folding and DKIM fails

2024-04-30 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > But one thing is plain, if lines get folded "artificially" to > satisfy line length limits, then this is a whitespace that DKIM > will see, and if it was not in the original message, the signature > will break. After the DKIM signature is generated, the

[pfx] Re: long header folding and DKIM fails

2024-04-30 Thread Wietse Venema via Postfix-users
Postfix does not store line endings internally, because different environments have different line ending conventions (for example SMTP has while UNIX has ). Postfix strips line endings on input, and adds them on output. Postfix was modeled after routers with different kinds of network

[pfx] Re: HowTo Migrate from text based mapping/routing to Database based routing

2024-04-30 Thread Wietse Venema via Postfix-users
Ml Ml via Postfix-users: > Hello, > > currently we manually use text files for mapping/routing: > > # postconf -n |grep -e transport -e alias > alias_database = hash:/etc/aliases hash:/etc/postfix/aliases > alias_maps = hash:/etc/aliases hash:/etc/postfix/aliases > allow_mail_to_commands =

[pfx] Re: long header folding and DKIM fails

2024-04-29 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > Wietse Venema via Postfix-users wrote in > <4vsq5f6q3nzj...@spike.porcupine.org>: > |Tim Coote via Postfix-users: > .. > |> SMTP headers are often 'folded' as they flow through MTAs. The > |> standard approach to folding an

[pfx] Re: long header folding and DKIM fails

2024-04-29 Thread Wietse Venema via Postfix-users
Tim Coote via Postfix-users: > Hullo > > I've recently stumbled across this issue and wondered if it's a/ > common, b/ how it can be addressed. > > SMTP headers are often 'folded' as they flow through MTAs. The > standard approach to folding and unfolding is covered in rfcs 5322 > and is relied

[pfx] Re: ipv6 connection

2024-04-29 Thread Wietse Venema via Postfix-users
Jack Raats: > Wietse, > > I run the script every five minutes for more than 13 hours to the DNS > server of Cloudflare (2620:fe::fe). > Four times I had some packet drops (about 25%). Was that network path in any way similar to the path to your MX checker? You can check that with mtr (or

[pfx] Re: ipv6 connection

2024-04-28 Thread Wietse Venema via Postfix-users
Jack Raats via Postfix-users: > In the Netherlands but also in other countries you can use internet.nl > to test your e-mail and webserver. > It test your e-mailserver for ipv6 connectivity, SPF, DMARC and DKIM. > > My mailserver scores sometimes 100%, but also sometimes lower because it >

[pfx] Re: milter protocol: chgheader: wondering on indices

2024-04-25 Thread Wietse Venema via Postfix-users
> * For smfi_chgheader, filter order is important. Later >filters will see the header changes made by earlier ones. Yes, that is fundamental to the way that the Milter API works. Each Milter "inspects" the header and body content that exists after Postfix and previous Milters have

[pfx] Re: status=deferred (bounce or trace service failure)

2024-04-22 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Mon, Apr 22, 2024 at 12:21:01AM -0400, 785 243 via Postfix-users wrote: > > > Recently i'm seeing a few messages deferred with status=deferred > > (bounce or trace service failure) > > > > instead of status=deferred (host .. said: 450 ...) > > > > from

[pfx] Re: active queue is too high

2024-04-19 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Gino Ferguson via Postfix-users: > > We have a relay server which has been working fine (postfix > > 3.3.0-1ubuntu0.4) > > Now there are ~20K mails in the active queue for a certain recipient > > and they are just sitting there. >

[pfx] Re: active queue is too high

2024-04-19 Thread Wietse Venema via Postfix-users
Gino Ferguson via Postfix-users: > We have a relay server which has been working fine (postfix 3.3.0-1ubuntu0.4) > Now there are ~20K mails in the active queue for a certain recipient > and they are just sitting there. Wietse Venema: > What does the output look like from: > grep status=

[pfx] Re: active queue is too high

2024-04-19 Thread Wietse Venema via Postfix-users
Gino Ferguson via Postfix-users: > Hi, > > > We have a relay server which has been working fine (postfix 3.3.0-1ubuntu0.4) > > Now there are ~20K mails in the active queue for a certain recipient and they > are just sitting there. > What does the output look like from: grep status=

[pfx] Re: submission port 465 question

2024-04-17 Thread Wietse Venema via Postfix-users
Mr. Peng via Postfix-users: > Hello, > > I saw this configuration in our master.cf as follows. > > What's the difference between the option "smtpd_relay_restrictions" and > "smtpd_recipient_restrictions"? In my opinion they both mean the sender > must pass the smtp auth. Thanks. > > smtps

[pfx] Re: hmm spf is missing :)

2024-04-15 Thread Wietse Venema via Postfix-users
Benny Pedersen via Postfix-users: > Authentication-Resultslist.sys4.de; dkim=pass header.d=porcupine.org; > arc=none (Message is not ARC signed); dmarc=pass (Used From Domain > Record) header.from=porcupine.org policy.dmarc=none > > intended ? Are you asking why list.sys4.de ignores

[pfx] Re: duplicate deliveries

2024-04-14 Thread Wietse Venema via Postfix-users
Marek Podmaka via Postfix-users: > On Sun, 14 Apr 2024 at 01:15, Wietse Venema via Postfix-users < > postfix-users@postfix.org> wrote: > > > If there is a difference in deduplication, then you have introduced > > a difference up-stream of the delivery agents. You need

[pfx] Re: duplicate deliveries

2024-04-13 Thread Wietse Venema via Postfix-users
Marek Podmaka via Postfix-users: > Hi, > > When/how does postfix prevent duplicate deliveries when delivering to an > alias and explicitly also to the alias result? For example all@domain + Cc > to one of the members of that alias. I have found parameters > "duplicate_filter_limit" and

[pfx] Re: Submission Forward

2024-04-13 Thread Wietse Venema via Postfix-users
svoop_pvde84wdgt--- via Postfix-users: > Hiya! > > I'm running my own Postfix as part of a dockered MailU which works > really smoothly for my own domains. However, I also have a few > email addresses for client projects at work and for the sake of > MUA simplicity, I forward all incoming mail to

[pfx] Re: Forward mail

2024-04-13 Thread Wietse Venema via Postfix-users
Paul van der Vlis via Postfix-users: > Hallo, > > Unfortunately, I have quite a few customers who want to receive email > from their own domain at a different email address, such as a Gmail or > Hotmail address. I forward this in /etc/postfix/virtual. > > But I actually don't understand why

[pfx] Re: disable search by at_domain in virtual

2024-04-09 Thread Wietse Venema via Postfix-users
v k via Postfix-users: > When delivering mail, Postfix generates LDAP queries with query_filter > mail=@domain, which are unnecessary in my environment. This becomes > critical when sending to a mailing list group with many participants, > as each member address generates an additional query,

[pfx] Re: Thunderbird 91, Postfix 3.7.x, Debian 12, Virtual Mailbox Users, TLS with Letsencrypt, error improper command pipelining after helo

2024-04-02 Thread Wietse Venema via Postfix-users
David Mehler via Postfix-users: > Hello, > > Here is the complete log of the connections, IPS x-d out, but I tried > twice, once on 587, once with smtps enabled. Any help appreciated. We DID NOT ask for verbose logs. All we asked for is this: > postfix/submission/smtpd[1529]: improper command

[pfx] Re: Is there a way to just quickly deliver "everything" to a file somewhere

2024-04-02 Thread Wietse Venema via Postfix-users
Dan Mahoney via Postfix-users: > Hey there all, > > I'm setting up a staging version of dayjob?s ticket system, and > we?d basically like postfix to still function, but instead of > touching the internet at all, just deliver everything to a single > file (or a maildir, I suppose), regardless of

[pfx] Re: Thunderbird 91, Postfix 3.7.x, Debian 12, Virtual Mailbox Users, TLS with Letsencrypt, error improper command pipelining after helo

2024-04-01 Thread Wietse Venema via Postfix-users
David Mehler via Postfix-users: > to utilize Thunderbird v91.x. I've tried configuring with both the > automatic configuration and the manual configuration, in both cases I am > getting an error in my maillog from submission/smtpd service stating > error improper command pipelining after helo.

[pfx] Re: milter_mail_macros in master.cf for using rspamd

2024-03-30 Thread Wietse Venema via Postfix-users
Martin Stenzel: > Awesome, incredibly fast, you are awesome > But, when I put this definition into master.cf (as you explained > wisely (postfix is overwhelming, in a positive way)) the > X-Spamd-Result header is missing. > > When I put it in main.cf, it works as expected. This is the part of

[pfx] Re: milter_mail_macros in master.cf for using rspamd

2024-03-30 Thread Wietse Venema via Postfix-users
Martin Stenzel via Postfix-users: > Hi group, > > I run rspamd on the same server in which the latest version of postfix > runs on. > > Plus, there is ciphermail for the purpose of GPG signing. > > > For rspamd functionality I have to define milter_mail_macros, but in > master.cf, not in

[pfx] Re: Fallback virtual_transport

2024-03-28 Thread Wietse Venema via Postfix-users
Emmanuel Seyman via Postfix-users: > > Hello, all. > > I handle two SMTP gateways at $WORK which relay mail from the internet > to an internel server and vice-versa. Accordingly, I have > "virtual_transport = smtp:internal-host.example.com" in my main.cf . > > We recently had a network issue

[pfx] Re: Setting up another "smarthost" with Postfix

2024-03-28 Thread Wietse Venema via Postfix-users
Cowbay via Postfix-users: > On 2024/3/28 00:25, Samuel Goodies via Postfix-users wrote: > > Hi guys. I'm inheriting a job that has an email server hosting several > > domains, and I'm wanting to move them behind our firewall and route mail > > from the main mail server to an offsite postfix

[pfx] Re: Documentation update request

2024-03-27 Thread Wietse Venema via Postfix-users
Ricardo F via Postfix-users: > > > Hello, > > I would like to suggest an addition to the documentation under > default_destination_rate_delay and default_destination_concurrency_limit > > As pointed in >

[pfx] Re: Setting up another "smarthost" with Postfix

2024-03-27 Thread Wietse Venema via Postfix-users
My reading is that this will be a sending only host: This postfix server will only take mail from the [main] server and send it out, and return bounce/errors to the main host. It won't accept any incoming mail. We should probably ask how they expect to be receiving mail, then.

[pfx] Re: Setting up another "smarthost" with Postfix

2024-03-27 Thread Wietse Venema via Postfix-users
Samuel Goodies via Postfix-users: [ text/html is unsupported, treating like TEXT/PLAIN ] > Hi guys. I'm inheriting a job that has an email server hosting > several domains, and I'm wanting to move them behind our firewall > and route mail from the main mail server to an offsite

[pfx] Re: check_policy_service for customizing routing & load balancing

2024-03-27 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Tue, Mar 26, 2024 at 02:20:55PM -0400, Wietse Venema via Postfix-users > wrote: > > Viktor Dukhovni via Postfix-users: > > > That's fine, the SRV records can be keyed by destination domain. > > > > Locally-manage

[pfx] Re: check_policy_service for customizing routing & load balancing

2024-03-26 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > That's fine, the SRV records can be keyed by destination domain. Locally-managed SRV records, keyed by the final destination domain name, to select a local relay host? Wietse ___ Postfix-users mailing list

[pfx] Re: check_policy_service for customizing routing & load balancing

2024-03-26 Thread Wietse Venema via Postfix-users
Colin McKinnon via Postfix-users: > Hi, > > I want to provision load balancing for my relays. The catch is that > there is already some customized routing in place based on recipient > domain and large block lists. These are currently handled by a > transport map. > > I would prefer not to

[pfx] Re: Sending email via ipv4

2024-03-24 Thread Wietse Venema via Postfix-users
Jack Raats via Postfix-users: > Hi, > > Can any help me. I want to recieve email via ipv4 and ipv6. main.cf: inet_protocols=ipv4,ipv6 as well as appropriate DNS MX and A records. > I want to send email via ipv6 only. master.cf: smtp .. .. .. .. .. .. smtp -o

[pfx] Re: dane.sys4.de

2024-03-23 Thread Wietse Venema via Postfix-users
Benny Pedersen via Postfix-users: > it go into endless loop if mx is missing, so it does not do a/ > failback testing, is this a bug ? What is 'it', what did you ask 'it' to do, and what are the concrete symptoms in the form of logging? Wietse

[pfx] Re: Do I have to reload Postfix after the X.509 certificate (and key) file has been renewed?

2024-03-23 Thread Wietse Venema via Postfix-users
TLS using processes will eventually pick up new certifictate info. A Postfix SMTP client and server process has a limited life time, bounded by max_idle (100s) and max_use (100 times). A tlsproxy process (used by postscreen, and by a Postfix SMTP client when reusing an SMTP-over-TLS connection)

[pfx] Re: Why has smtpd_tls_cipherlist been deprecated?

2024-03-23 Thread Wietse Venema via Postfix-users
Matthias Nagel via Postfix-users: > Hello everybody, > > what is the rationale behind the deprecation of the setting > `smtpd_tls_cipherlist`? Are there any plans to remove it entirely > in some future versions? smtpd_tls_cipherlist was removed in Postfix 2.3 (18 years ago). Postfix 2.9 (12

[pfx] Re: Postfix thinks smtp.gmail.com uses self-signed certificate

2024-03-23 Thread Wietse Venema via Postfix-users
Cowbay via Postfix-users: > So, I will collect necessary information next time I encounter this > issue as what Viktor suggested. Please note that Postfix does not automatically use the "system" root CA store that openssl s_client and curl may use. That could result in verification differences

[pfx] Re: Postfix thinks smtp.gmail.com uses self-signed certificate

2024-03-22 Thread Wietse Venema via Postfix-users
Unleess you can hand over the certificate that Postfix complained about, you have not proven that Postfix was in error. Specifically, yout tests with curl and openssl s_client may have used a different IP address than Postfix, because the smtp.gmail.com IP address changes frequently. The

[pfx] Re: postfix and from

2024-03-21 Thread Wietse Venema via Postfix-users
natan via Postfix-users: > 1. > FROM is encoded as "FRIENDLY_NAME " == encoding ==> "base64" That form is NOT VALID. For proper encoding, please see https://datatracker.ietf.org/doc/html/rfc2047#section-5 > 2. > FROM is encoded as "FRIENDLY_NAME " == encoding ==> > "base64 " That form is

[pfx] Re: Don't BCC a particular domain

2024-03-21 Thread Wietse Venema via Postfix-users
/or email addresses that need to be excluded. Wietse > Excuse. my ignorance, > > Richard > > On 3/21/24 8:54 AM, Wietse Venema via Postfix-users wrote: > > Richard Raether via Postfix-users: > >> We have an auditor account where all incoming and outgoin

[pfx] Re: Feature request

2024-03-21 Thread Wietse Venema via Postfix-users
Ralf Hildebrandt via Postfix-users: > Hi! > > I wonder if this is possible: > > If a PCRE/regexp style map is triggering, it can be quite hard to > find out WHICH pattern actually caused the action. > > So maybe postmap (when invoked with "-b", "-h" or "-q key") could emit > which regular

[pfx] Re: Don't BCC a particular domain

2024-03-21 Thread Wietse Venema via Postfix-users
Richard Raether via Postfix-users: > We have an auditor account where all incoming and outgoing mail is BCC'd > to, to retain for compliance reasons. However, since mailman retains its > own archives, and we have a mailman on a separate server with a separate > domain, is there a way to tell

[pfx] Re: Trouble with qmqp

2024-03-21 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Brad Koehn via Postfix-users: > > I'm trying to deliver email with Postfix 3.7.10 using `qmqpd`. > > Unfortunately when I do this, the email is often unreadable by a > > variety of email clients. > > I suppose you mean "receiv

[pfx] Re: Trouble with qmqp

2024-03-21 Thread Wietse Venema via Postfix-users
Brad Koehn via Postfix-users: > I'm trying to deliver email with Postfix 3.7.10 using `qmqpd`. > Unfortunately when I do this, the email is often unreadable by a > variety of email clients. I suppose you mean "receive" mail with Postfix using qmqpd. > Curiously, if I deliver the same email

[pfx] Re: smtpd filter orig_client

2024-03-19 Thread Wietse Venema via Postfix-users
Reg Inaldo via Postfix-users: > > Hi > > I am seeing an issue with relaying and am looking for a way to filter on > a specific smtp line but can't find a way to make it work: > > In the transaction (eg):? mta-k postfix/smtpd[23771]: 97F808837: > client=localhost[127.0.0.1],

[pfx] Re: [PATCH] Drop removed -style option from html2text

2024-03-11 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Christian Goettsche via Postfix-users: > > On Mon, 11 Mar 2024 at 17:50, Wietse Venema wrote: > > > > > > Christian Goettsche via Postfix-users: > > > > html2text dropped the command line option -style in version 2[1]. &g

[pfx] Re: [PATCH] Drop removed -style option from html2text

2024-03-11 Thread Wietse Venema via Postfix-users
Christian Goettsche via Postfix-users: > On Mon, 11 Mar 2024 at 17:50, Wietse Venema wrote: > > > > Christian Goettsche via Postfix-users: > > > html2text dropped the command line option -style in version 2[1]. > > > > I am not using that html2text version on the machine where I prepare > >

[pfx] Re: [PATCH] Drop removed -style option from html2text

2024-03-11 Thread Wietse Venema via Postfix-users
Christian Goettsche via Postfix-users: > html2text dropped the command line option -style in version 2[1]. I am not using that html2text version on the machine where I prepare Postfix releases. I found that removing that flag makes the output massively different. I need that documentation builds

[pfx] Re: Dumb question about logging

2024-03-09 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Sat, Mar 09, 2024 at 12:49:42PM +0100, Matus UHLAR - fantomas via > Postfix-users wrote: > > > In case of domains in relay_domains, the command could be even > > postfix/relay, so one needs to exclude that one as well. > > Actually, no, the "relay"

[pfx] Re: [ext] Re: [OT] postfwd3 as check_policy_service hogging the CPU

2024-03-09 Thread Wietse Venema via Postfix-users
Matus UHLAR - fantomas via Postfix-users: > On 07.03.24 12:14, Wietse Venema via Postfix-users wrote: > >The Postfix SMTP server counts only the recipients that it accepts, > >not the ones that it rejects. > > > >That is, a DATA or BDAT command after all recipients

[pfx] Re: preserving multi line header_checks REPLACE

2024-03-08 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Fri, Mar 08, 2024 at 03:45:42PM -0500, Wietse Venema via Postfix-users > wrote: > > > The postmap command reads input from stdin one line at a time, and > > applies each input line to all the header_checks patterns. It can't >

[pfx] Re: preserving multi line header_checks REPLACE

2024-03-08 Thread Wietse Venema via Postfix-users
Mailinglists35 via Postfix-users: > > Hi > > I run a postfix 3.5.9 smtp relay for a webserver that sends user signup and > forgot password emails. That's the only use case and the server does not > receive any other emails and neither generates any locally. > > I'm trying to prevent

[pfx] Re: Dumb question about logging

2024-03-08 Thread Wietse Venema via Postfix-users
Stephen Satchell via Postfix-users: > Assuming that one's configuration has open relay, what does a log entry > for relayed mail look like? > > I don't think I've any open relay, but I want to look and make sure. > > I've searched for half an hour, and no answer came up. But, I did find >

[pfx] Re: Misunderstanging on masquerade_domains and rewriting in master.conf

2024-03-07 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > What if i would have multiple smtpd listening on different xy and > each needs different settings? Would i need different main.cf's > for each of those? > And you say the local_header_rewrite_clients at least i can > specifiy via -o, if i understand

[pfx] Re: Active queue congestion

2024-03-07 Thread Wietse Venema via Postfix-users
Colin McKinnon via Postfix-users: > Thank you, Viktor. > > I am planning to look at increasing the size of the Active queue however I > would need to resize to a minimum of 50x based on past events. That should be OK as long as your syustem has enough memory. > > You can also configure a

[pfx] Re: [ext] Re: [OT] postfwd3 as check_policy_service hogging the CPU

2024-03-07 Thread Wietse Venema via Postfix-users
Ralf Hildebrandt via Postfix-users: > * Viktor Dukhovni via Postfix-users : > > > Note that if you want the actual recipient addresses, (not just a > > count), > > I just need the count in this case > > > you'll need to also intercept recipient restrictions. > > oh! > > > The Postfix smtpd(8)

[pfx] Postfix stable release 3.9.0

2024-03-07 Thread Wietse Venema via Postfix-users
[An on-line version of this announcement will be available at https://www.postfix.org/announcements/postfix-3.9.0.html] Postfix stable release 3.9.0 is available. Postfix 3.5 - 3.8 were updated earlier this week; after that, Postfix 3.5 will no longer be updated. The main changes are below. See

[pfx] Re: Milter multiline header formatting

2024-03-07 Thread Wietse Venema via Postfix-users
Claus Assmann via Postfix-users: > On Wed, Mar 06, 2024, Wietse Venema via Postfix-users wrote: > > > > Again, Postfix does not store line terminators, not when email comes > > > from UNIX tool with \n, via SMTP with \r\n, or encapsulated as > > > netstrings which

[pfx] Re: improving SRS support

2024-03-07 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Wed, Mar 06, 2024 at 07:30:01PM -0500, Christophe Kalt via Postfix-users > wrote: > > > The two options I've seen for implementing SRS are milter and > > [sender_]canonical_maps but it seems to me that neither are a good fit when > > rewriting the envelope

  1   2   3   4   5   6   7   >