Verify address before delivery, spam run

2009-10-22 Thread Martijn de Munnik
Hi List, Some of our customers use our mailservers as antispam/antivirus gateway. So our server accepts mail, does some spam and virus checking and delivers the mail to a remote server. Of course I don't want to accept mail for non existing users so our mailserver verifies the recipient. So far

problems with virtual_alias_maps

2009-10-22 Thread Tomas Macek
Hi, I'm confused about how works the map tables in Postfix, I'm using the 2.4.1 version. I have setup the virtual_mailbox_domains to return the domain names, for that we are the final destination and I have also setup the virtual_alias_maps for trivial rewrite of some addresses. My problem:

Re: run external command when new mail arrives

2009-10-22 Thread rihad
Magnus Bäck wrote: On Wednesday, October 21, 2009 at 19:43 CEST, rihad ri...@mail.ru wrote: OK here's how far I've gone: master.cf: smsnotif unix - n n - - pipe flags=DRhu user=vmail argv=/root/smsnotif ${recipient} /root/smsnotif: #!/bin/sh echo $@

Re: run external command when new mail arrives

2009-10-22 Thread rihad
Wietse Venema wrote: You forgot to test the virtual alias expansion. postmap -q u...@example.com mysql:/etc/postfix/mysql-virtual.cf Thus should produce the same result as a hash: table with: u...@example.comu...@example.com, u...@sms.example.com Ditto for the transport map.

Envelope-to header question

2009-10-22 Thread Guy
Hi, Upgraded Ubuntu recently and one of our users is now complaining that mail forwarded to his freeserve account isn't downloading correctly with them. There does seem to have been one change in the the forwarded mail since the update. Before the update the Envelope-to: header contained the users

Re: run external command when new mail arrives

2009-10-22 Thread rihad
rihad wrote: Now that I've fixed table lookup following from Magnus' advice, all is working! # postmap -q ri...@example.com mysql:/etc/postfix/mysql-virtual.cf ri...@example.com,ri...@sms.example.com The query now looks like this: query = select

2.6.5 - problem with mail-id and not appending 'Date:' header

2009-10-22 Thread wild_oscar
I'm having a problem with a service provider's emails. While in my older server (and another postfix server I have, call it S2) I have no problems with receiving emails, on this new postfix server I've set up I have this issue: - Mail is stored without a 'Date:' header, making some MUA not

bug? virtual_alias_maps, virtual_mailbox_maps locan non local sender difference

2009-10-22 Thread alexs
Hi all. postfix-2.6.5. Part users put mail on mailboxes, another part forwarding to different domain. virtual_mailbox_domains = ulgsm.ru virtual_alias_maps = mysql:/usr/local/etc/postfix/aliases.mysql virtual_mailbox_maps = mysql:/usr/local/etc/postfix/mailboxes.mysql work fine. first checks

Multiple check_client_access in smtpd_recipient_restrictions?

2009-10-22 Thread Harakiri
Hi, the documentation wasnt clear about this. Is it possible to use multiple check_client_access in smtpd_recipient_restrictions? i.e (example). smtpd_recipient_restrictions = permit_mynetworks reject_unauth_destination check_client_access pcre:/etc/postfix/rbl_checks

Re: Verify address before delivery, spam run

2009-10-22 Thread Wietse Venema
Martijn de Munnik: Hi List, Some of our customers use our mailservers as antispam/antivirus gateway. So our server accepts mail, does some spam and virus checking and delivers the mail to a remote server. Of course I don't want to accept mail for non existing users so our mailserver

Re: 2.6.5 - problem with mail-id and not appending 'Date:' header

2009-10-22 Thread Wietse Venema
wild_oscar: I'm having a problem with a service provider's emails. While in my older server (and another postfix server I have, call it S2) I have no problems with receiving emails, on this new postfix server I've set up I have this issue: - Mail is stored without a 'Date:' header, making

Re: bug? virtual_alias_maps, virtual_mailbox_maps locan non local sender differenceu

2009-10-22 Thread Wietse Venema
al...@ulgsm.ru: Oct 22 13:03:34 skuns postfix/cleanup[46220]: warning: table mysql:/usr/local/etc/postfix/aliases.mysql: empty lookup result for: al...@ulgsm.ru -- ignored Fix that. Wietse

Re: excessive recursion (max 50)

2009-10-22 Thread Wietse Venema
Alberto Lepe: [ Charset ISO-8859-1 unsupported, converting... ] On Wed, Oct 21, 2009 at 8:56 PM, Wietse Venema wie...@porcupine.org wrote: Alberto Lepe: host mail.server_old.com[101.101.101.101] said: 554 5.0.0 rewrite: excessive recursion (max 50), ruleset canonify That is not a

Re: Accept null HELO/EHLO

2009-10-22 Thread ram
On Wed, 2009-10-21 at 09:07 -0400, Wietse Venema wrote: ram: A lotus notes server of our clients in hugely misconfigured to send just a empty HELO. And we are supposed to relay mails for this client. I know getting the lotus admin to set his MTA is the right thing , but we for now I

How to accept incoming emails only to the users listed in my application's mysql database

2009-10-22 Thread Arora, Sumit
Hi All, I was wondering if I can accept only those emails addressed to the users listed in a table of my application database. Can anybody suggest smthing. Thanks, Sumit Arora

Re: bug? virtual_alias_maps, virtual_mailbox_maps locan non local sender differenceu

2009-10-22 Thread Ключников А . С .
* Wietse Venema wie...@porcupine.org [2009-10-22 06:40:01 -0400]: al...@ulgsm.ru: Oct 22 13:03:34 skuns postfix/cleanup[46220]: warning: table mysql:/usr/local/etc/postfix/aliases.mysql: empty lookup result for: al...@ulgsm.ru -- ignored Fix that. It is not problem. al...@ulgsm.ru not

Re: excessive recursion (max 50)

2009-10-22 Thread Alberto Lepe
On Thu, Oct 22, 2009 at 7:42 PM, Wietse Venema wie...@porcupine.org wrote: Alberto Lepe: [ Charset ISO-8859-1 unsupported, converting... ] On Wed, Oct 21, 2009 at 8:56 PM, Wietse Venema wie...@porcupine.org wrote: Alberto Lepe: host mail.server_old.com[101.101.101.101] said: 554

Re: bug? virtual_alias_maps, virtual_mailbox_maps locan non local sender differenceu

2009-10-22 Thread Ralf Hildebrandt
* Ключников А.С. al...@ulgsm.ru: * Wietse Venema wie...@porcupine.org [2009-10-22 06:40:01 -0400]: al...@ulgsm.ru: Oct 22 13:03:34 skuns postfix/cleanup[46220]: warning: table mysql:/usr/local/etc/postfix/aliases.mysql: empty lookup result for: al...@ulgsm.ru -- ignored Fix

How do I restrict?

2009-10-22 Thread Anant Athavale
Dear All, Today, I had to open my Postfix mailer to one IP address. Though, right now I am accepting any mail coming from that IP address, but I want to restrict it to some specific email id. Is it possible to restrict to an email id like webmas...@domain from that IP 10.20.30.40 and

Re: Verify address before delivery, spam run

2009-10-22 Thread Martijn de Munnik
On Thu, 2009-10-22 at 13:03 +0200, Martijn de Munnik wrote: On Thu, 2009-10-22 at 06:35 -0400, Wietse Venema wrote: Martijn de Munnik: Hi List, Some of our customers use our mailservers as antispam/antivirus gateway. So our server accepts mail, does some spam and virus checking and

Re: bug? virtual_alias_maps, virtual_mailbox_maps locan non local sender differenceu

2009-10-22 Thread alexs
* Ralf Hildebrandt ralf.hildebra...@charite.de [2009-10-22 13:08:57 +0200]: * Ключников А.С. al...@ulgsm.ru: * Wietse Venema wie...@porcupine.org [2009-10-22 06:40:01 -0400]: al...@ulgsm.ru: Oct 22 13:03:34 skuns postfix/cleanup[46220]: warning: table

Re: How do I restrict?

2009-10-22 Thread Noel Jones
On 10/22/2009 6:15 AM, Anant Athavale wrote: Dear All, Today, I had to open my Postfix mailer to one IP address. Though, right now I am accepting any mail coming from that IP address, but I want to restrict it to some specific email id. Is it possible to restrict to an email id like

Re: Multiple check_client_access in smtpd_recipient_restrictions?

2009-10-22 Thread Noel Jones
On 10/22/2009 5:33 AM, Harakiri wrote: Hi, the documentation wasnt clear about this. Is it possible to use multiple check_client_access in smtpd_recipient_restrictions? i.e (example). smtpd_recipient_restrictions = permit_mynetworks reject_unauth_destination check_client_access

Re: problems with virtual_alias_maps

2009-10-22 Thread Noel Jones
On 10/22/2009 2:35 AM, Tomas Macek wrote: Hi, I'm confused about how works the map tables in Postfix, I'm using the 2.4.1 version. I have setup the virtual_mailbox_domains to return the domain names When you use a table for virtual_mailbox_domains, it must not return a list of domains.

Adding mail header if postfix DNS based RBL (realtime black hole) check fails

2009-10-22 Thread Sharma, Ashish
Hello, I have setup a receiving Postfix mail server. Here i have custom code written that parses the whole mail received by postfix and use the headers, body and attachments separately for different uses. I have currently added SPF and DKIM checks in postfix that result in appending of their

how Postfix anti spam configuration works with DNS-based Blackhole List providers

2009-10-22 Thread Sharma, Ashish
Hello, I have setup a Postfix mail server for incoming mails that is required to never reply to external enviornment i.e it will accept all incoming mails and never reply anything that can be used as a trace to locate and verify it's existence. I have implemented the Postfix anti-UCE

Re: Adding mail header if postfix DNS based RBL (realtime black hole) check fails

2009-10-22 Thread Sahil Tandon
On Oct 22, 2009, at 8:52 AM, Sharma, Ashish ashish.shar...@hp.com wrote: Hello, I have setup a receiving Postfix mail server. Here i have custom code written that parses the whole mail received by postfix and use the headers, body and attachments separately for different uses. I have

Re: Postfix 2.6.x slow

2009-10-22 Thread Stan Hoeppner
Eric Vaughn put forth on 10/5/2009 8:23 PM: OLD NEW Centos 5.0. Centos 5.3 (yum update all) i386. x64 2.4 ghrz cpu. 2.83 ghrz cpu Hi Eric, Would you please provide the following: 1. Each server make/model# 2. CPU

RE: Adding mail header if postfix DNS based RBL (realtime black hole) check fails

2009-10-22 Thread Sharma, Ashish
Sahil, Thanks for your prompt reply. my requirement is to setup a silent Postfix mail server that just receives mail and never responds any kind of information etc so that the existence of my mail server can be known. Obviously I need to secure my mail server from spam mails , so I need to

Re: bug? virtual_alias_maps, virtual_mailbox_maps locan non local sender differenceu

2009-10-22 Thread Wietse Venema
al...@ulgsm.ru: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. [ Charset UTF-8 unsupported, converting... ] * Ralf Hildebrandt ralf.hildebra...@charite.de [2009-10-22 13:08:57 +0200]: * ? ?.?. al...@ulgsm.ru: * Wietse Venema wie...@porcupine.org

Re: Verify address before delivery, spam run

2009-10-22 Thread Wietse Venema
Martijn de Munnik: [ Charset UTF-8 unsupported, converting... ] On Thu, 2009-10-22 at 13:03 +0200, Martijn de Munnik wrote: On Thu, 2009-10-22 at 06:35 -0400, Wietse Venema wrote: Martijn de Munnik: Hi List, Some of our customers use our mailservers as antispam/antivirus

Re: problems with virtual_alias_maps

2009-10-22 Thread Tomas Macek
Yes, that's what I returning now: not found - the domain was not found in the virtual_mailbox_domains table Tomas On Thu, 22 Oct 2009, Noel Jones wrote: On 10/22/2009 2:35 AM, Tomas Macek wrote: Hi, I'm confused about how works the map tables in Postfix, I'm using the 2.4.1 version. I

Re: Accept null HELO/EHLO

2009-10-22 Thread Wietse Venema
ram: On Wed, 2009-10-21 at 09:07 -0400, Wietse Venema wrote: ram: A lotus notes server of our clients in hugely misconfigured to send just a empty HELO. And we are supposed to relay mails for this client. I know getting the lotus admin to set his MTA is the right thing , but we

Re: Accept null HELO/EHLO

2009-10-22 Thread donovan jeffrey j
On Oct 22, 2009, at 6:50 AM, ram wrote: On Wed, 2009-10-21 at 09:07 -0400, Wietse Venema wrote: ram: A lotus notes server of our clients in hugely misconfigured to send just a empty HELO. And we are supposed to relay mails for this client. I know getting the lotus admin to set his MTA is

Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread David Schweikert
Hi, We are experiencing rather frequent mail deferrals because of a milter-related malfunction: Oct 22 08:48:14 mailhost3 postfix/smtpd[723]: 23C7F8FF16: client=xxx.xxx[1.2.3.4] Oct 22 08:48:14 mailhost3 postfix/cleanup[1415]: 23C7F8FF16: message-id= Oct 22 09:18:16 mailhost3

Re: problems with virtual_alias_maps

2009-10-22 Thread Noel Jones
On 10/22/2009 8:34 AM, Tomas Macek wrote: Yes, that's what I returning now: not found - the domain was not found in the virtual_mailbox_domains table Do not top post. If you require more help, please see http://www.postfix.org/DEBUG_README.html#mail

Re: How to accept incoming emails only to the users listed in my application's mysql database

2009-10-22 Thread Victoriano Giralt
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 On 22/10/09 12:49, Arora, Sumit wrote: I was wondering if I can accept only those emails addressed to the users listed in a table of my application database. It depends on your application database :) ;) and if it can be used as a map. - --

Re: Postfix 2.6.x slow

2009-10-22 Thread Victor Duchovni
On Thu, Oct 22, 2009 at 08:15:56AM -0500, Stan Hoeppner wrote: Eric Vaughn put forth on 10/5/2009 8:23 PM: OLD NEW Centos 5.0. Centos 5.3 (yum update all) i386. x64 2.4 ghrz cpu. 2.83 ghrz cpu Hi Eric, Would you

Re: one domain and 2 mail servers

2009-10-22 Thread Stan Hoeppner
K bharathan put forth on 10/21/2009 12:08 PM: hi all i've to keep two postfix mail server; one at head office and another at regional office; both users will be using example.com http://example.com domain; head office mail server has got hostname/ mx/rdns etc..in the public dns; head office

Re: Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread Wietse Venema
David Schweikert: Hi, We are experiencing rather frequent mail deferrals because of a milter-related malfunction: Oct 22 08:48:14 mailhost3 postfix/smtpd[723]: 23C7F8FF16: client=xxx.xxx[1.2.3.4] Oct 22 08:48:14 mailhost3 postfix/cleanup[1415]: 23C7F8FF16: message-id= Oct 22

Re: Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread David Schweikert
On Thu, Oct 22, 2009 at 11:32:16 -0400, Wietse Venema wrote: Postfix does not enforce timeouts - instead, Postfix depends on the kernel to do the job. When Postfix wants to read, it waits for $timeout seconds for the socket to become readable. When the kernel reports the socket is readable but

Re: How to accept incoming emails only to the users listed in my application's mysql database

2009-10-22 Thread Stan Hoeppner
Arora, Sumit put forth on 10/22/2009 5:49 AM: I was wondering if I can accept only those emails addressed to the users listed in a table of my application database. http://www.postfix.org/postconf.5.html#smtpd_recipient_restrictions -- Stan

Re: Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread Victor Duchovni
On Thu, Oct 22, 2009 at 05:48:49PM +0200, David Schweikert wrote: On Thu, Oct 22, 2009 at 11:32:16 -0400, Wietse Venema wrote: Postfix does not enforce timeouts - instead, Postfix depends on the kernel to do the job. When Postfix wants to read, it waits for $timeout seconds for the socket

Re: how Postfix anti spam configuration works with DNS-based Blackhole List providers

2009-10-22 Thread Noel Jones
On 10/22/2009 7:53 AM, Sharma, Ashish wrote: Hello, I have setup a Postfix mail server for incoming mails that is required to never reply to external enviornment i.e it will accept all incoming mails and never reply anything that can be used as a trace to locate and verify it's existence.

Re: how Postfix anti spam configuration works with DNS-based Blackhole List providers

2009-10-22 Thread Stan Hoeppner
Sharma, Ashish put forth on 10/22/2009 7:53 AM: Hello, I have setup a Postfix mail server for incoming mails that is required to never reply to external enviornment i.e it will accept all incoming mails and never reply anything that can be used as a trace to locate and verify it's

Re: Postfix 2.6.x slow

2009-10-22 Thread Stan Hoeppner
Victor Duchovni put forth on 10/22/2009 10:20 AM: On Thu, Oct 22, 2009 at 08:15:56AM -0500, Stan Hoeppner wrote: Eric Vaughn put forth on 10/5/2009 8:23 PM: OLD NEW Centos 5.0. Centos 5.3 (yum update all) i386. x64 2.4 ghrz cpu.

Re: Using different CA for smtpd on port 25 on and port 587

2009-10-22 Thread Victor Duchovni
On Wed, Oct 21, 2009 at 11:45:31PM +0200, Roland Dirlewanger wrote: Why do you expect clients on port 25 to have client certificates? In my opinion, as soon as a non anonymous TLS connection is set up between a client and a server, it is legitimate for both sides to verify whom

Re: Postfix 2.6.x slow

2009-10-22 Thread Victor Duchovni
On Thu, Oct 22, 2009 at 11:18:12AM -0500, Stan Hoeppner wrote: There is really no need to pursue this at this time. No evidence has yet been found to support the new system being slower than the old. I think you've demonstrated it's not slower. I'm wondering why it's not faster, In a

Re: Postfix 2.6.x slow

2009-10-22 Thread Wietse Venema
Stan Hoeppner: I think you've demonstrated it's not slower. I'm wondering why it's not faster, vs what you described as about equal, in performance. Granted, More than 25 years ago people discovered that it is incredibly hard to spread one program over multiple CPUs such that it keeps every

Re: Accept null HELO/EHLO

2009-10-22 Thread Victor Duchovni
On Thu, Oct 22, 2009 at 06:56:49PM +0200, Geert Hendrickx wrote: On Thu, Oct 22, 2009 at 09:36:06AM -0400, Wietse Venema wrote: I'll implement the regexp to edit command code anyway. It's cheaper than sending someone to a customer next time. Would this eg. also allow to substitute

Postfix 2.6.x slow

2009-10-22 Thread Stan Hoeppner
Victor Duchovni put forth on 10/22/2009 11:41 AM: On Thu, Oct 22, 2009 at 11:18:12AM -0500, Stan Hoeppner wrote: There is really no need to pursue this at this time. No evidence has yet been found to support the new system being slower than the old. I think you've demonstrated it's not

Re: Accept null HELO/EHLO

2009-10-22 Thread Wietse Venema
Geert Hendrickx: On Thu, Oct 22, 2009 at 09:36:06AM -0400, Wietse Venema wrote: I'll implement the regexp to edit command code anyway. It's cheaper than sending someone to a customer next time. Would this eg. also allow to substitute domains (s/@olddomain$/@newdomain$/) in RCPT TO,

Re: Accept null HELO/EHLO

2009-10-22 Thread Victor Duchovni
On Thu, Oct 22, 2009 at 01:34:59PM -0400, Wietse Venema wrote: Also, the RCPT TO command shows the address in raw form, so the same address may appear in different but equivalent forms: RCPT TO:u...@example.com RCPT TO:user@example.com The second is not RFC compliant, quoted-strings are

Postfix 2.6.x slow

2009-10-22 Thread Stan Hoeppner
Wietse Venema put forth on 10/22/2009 12:04 PM: Stan Hoeppner: I think you've demonstrated it's not slower. I'm wondering why it's not faster, vs what you described as about equal, in performance. Granted, More than 25 years ago people discovered that it is incredibly hard to spread one

Re: Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread David Schweikert
On Thu, Oct 22, 2009 at 11:52:36 -0400, Victor Duchovni wrote: Which version? All recommended patch sets applied? We have Solaris 10 (kernel patch 13-03, dated January 2009). I did now a tcpdump during another such case and I found out that this is happening during the DATA phase: the

Re: Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread Victor Duchovni
On Thu, Oct 22, 2009 at 09:46:55PM +0200, David Schweikert wrote: On Thu, Oct 22, 2009 at 11:52:36 -0400, Victor Duchovni wrote: Which version? All recommended patch sets applied? We have Solaris 10 (kernel patch 13-03, dated January 2009). I did now a tcpdump during another such

Re: Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread Wietse Venema
David Schweikert: On Thu, Oct 22, 2009 at 11:52:36 -0400, Victor Duchovni wrote: Which version? All recommended patch sets applied? We have Solaris 10 (kernel patch 13-03, dated January 2009). I did now a tcpdump during another such case and I found out that this is happening during

Re: Postfix 2.6.x slow

2009-10-22 Thread Wietse Venema
Stan Hoeppner: running at 1/4 speed (I'm only getting 3MB/sec whereas with the [...] kernel they are getting 14-18MB/sec) I hope you have those numbers mixed up, and that you meant to write 45MB/s with a good driver and 15MB/s with a bad one. With single-disk sequential file access of uncached

RE: Postfix 2.6.x slow

2009-10-22 Thread Eric Vaughn
For our problem, Postfix was not the issue. -Original Message- From: owner-postfix-us...@postfix.org [mailto:owner-postfix-us...@postfix.org] On Behalf Of Wietse Venema Sent: Thursday, October 22, 2009 2:25 PM To: Postfix users Subject: Re: Postfix 2.6.x slow Stan Hoeppner: running

Re: Envelope-to header question

2009-10-22 Thread mouss
Guy a écrit : Hi, Upgraded Ubuntu recently and one of our users is now complaining that mail forwarded to his freeserve account isn't downloading correctly with them. There does seem to have been one change in the the forwarded mail since the update. Before the update the Envelope-to:

Re: Adding mail header if postfix DNS based RBL (realtime black hole) check fails

2009-10-22 Thread mouss
Sharma, Ashish a écrit : Sahil, Thanks for your prompt reply. my requirement is to setup a silent Postfix mail server that just receives mail and never responds any kind of information etc so that the existence of my mail server can be known. Obviously I need to secure my mail server

Re: Milter-induced temporary reject (can't read SMFIC_HEADER reply packet header)

2009-10-22 Thread David Schweikert
On Thu, Oct 22, 2009 at 17:04:50 -0400, Wietse Venema wrote: smtpd_timeout is no MESSAGE TRANSFER time limit. smtpd_timeout is an INACTIVITY time limit. OK, I get it :-) Thanks for the explanation. I did solve my problem by increasing the timeout in the milter. Cheers David

Re: Postfix 2.6.x slow

2009-10-22 Thread Stan Hoeppner
Wietse Venema put forth on 10/22/2009 4:25 PM: Stan Hoeppner: running at 1/4 speed (I'm only getting 3MB/sec whereas with the [...] kernel they are getting 14-18MB/sec) I hope you have those numbers mixed up, and that you meant to write 45MB/s with a good driver and 15MB/s with a bad one.

Re: excessive recursion (max 50) [SOLVED]

2009-10-22 Thread Alberto Lepe
On Thu, Oct 22, 2009 at 8:06 PM, Alberto Lepe d...@alepe.com wrote: On Thu, Oct 22, 2009 at 7:42 PM, Wietse Venema wie...@porcupine.orgwrote: Alberto Lepe: [ Charset ISO-8859-1 unsupported, converting... ] On Wed, Oct 21, 2009 at 8:56 PM, Wietse Venema wie...@porcupine.org wrote: