Re: Another "timed out while sending end of data" Error

2010-08-27 Thread Wietse Venema
Lie, Jafaruddin: > Hi Wietse > 1. No "220 *2**0**200*02*0*00" when > telneting into the Exchange server: > > [r...@mailinglist]~# telnet x.x.1.74 25 > Trying x.x.1.74... > Connected to x.x.1.74 (192.168.1.74). > Escape character is '^]'. > 220 xx.xx.edu.au Micro

Re: global output concurrency limit

2010-08-27 Thread Wietse Venema
Mihamina Rakotomandimby: > I am looking for a setup that doesnt limit incoming messages, but > globally (*not* per destination) limits the delivery. Configure the appropriate PROCESS LIMIT in master.cf. See: man 5 master Wietse

Re: Baffled by "User unknown in virtual alias table"

2010-08-27 Thread Wietse Venema
Adam Tauno Williams: > virtual_alias_maps: ldap:/etc/postfix/ldap-delivery.cf(0,lock|fold_fix): > adam.t.willi...@example.com = ot...@example.com As DOCUMENTED, virtual alias domains MUST replace the recipient domain by a DIFFERENT domain

Re: temporary dns errors are a pain

2010-08-27 Thread Wietse Venema
pf at alt-ctrl-del.org: > Noel Jones, August 27, 2010 3:56 PM: > > > >> On: August 27, 2010 2:23 PM, I wrote: > >>> Is there any known policy server or add-on, that will change > >>> the tempfail action after a couple of hours, for things like > >>> reject_unknown_client_hostname and > >>> reject_

Re: temporary dns errors are a pain

2010-08-27 Thread Wietse Venema
pf at alt-ctrl-del.org: > Wietse: > > pf at alt-ctrl-del.org: > >> Noel Jones, August 27, 2010 3:56 PM: > >> > > >> >> On: August 27, 2010 2:23 PM, I wrote: > >> >>> Is there any known policy server or add-on, that will change > >> >>> the tempfail action after a couple of hours, for things like >

Re: Delayed-ACK holdups to a proxy content filter on lo0 for mid-size messages

2010-08-27 Thread Wietse Venema
Mark Martinec: > On Friday August 27 2010 19:06:02 Victor Duchovni wrote: > > Just so everyone else is clear on the context, this is not a post-queue > > content_filter issue (post-queue content filters use the SMTP/LMTP > > delivery agent which already does the right thing). This applies only > >

Re: temporary dns errors are a pain

2010-08-27 Thread Wietse Venema
pf at alt-ctrl-del.org: > >> > Postfix already replies with a 5XX for an NXDOMAIN result. > >> > > >> NOQUEUE: reject: RCPT from > >> outgoing.jeevantechnologies.com[61.12.114.170]: > >> 450 4.7.1 : > >> Helo command rejected: Host not found; > >> proto=ESMTP helo= > > > > postconf | grep 450 Mea

Re: Log the applied TLS policy

2010-08-28 Thread Wietse Venema
martin f krafft: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. > Dear list, > > We are using $smtp_tls_policy_maps, in addition to > $smtp_tls_security_level==may. Hence, the machine opportunistically > uses TLS, while the policy ensures that certain destinations are

Re: Baffled by "User unknown in virtual alias table"

2010-08-28 Thread Wietse Venema
Adam Tauno Williams: > On Fri, 2010-08-27 at 16:51 -0400, Wietse Venema wrote: > > Adam Tauno Williams: > > > virtual_alias_maps: ldap:/etc/postfix/ldap-delivery.cf(0,lock|fold_fix): > > > adam.t.willi...@example.com = ot...@example.com > > > > As DOCUMEN

Re: postmap -q and address extensions

2010-08-28 Thread Wietse Venema
martin f krafft: > Hello list, > > I am finding that > > postmap -q address+withextens...@domain.com > pgsql:/etc/postfix/virtual_mailbox_maps > > does not return a result, while the address without the extension > works fine. Is this expected behaviour? YES. Wietse

Re: postmap -q and address extensions

2010-08-28 Thread Wietse Venema
martin f krafft: > also sprach Wietse Venema [2010.08.28.2330 +0200]: > > > does not return a result, while the address without the extension > > > works fine. Is this expected behaviour? > > > > YES. > > Thank you. You're welcome. By now you will

Re: Migrating from sendmail, a few questions...

2010-08-30 Thread Wietse Venema
Jean-Yves Avenard: > > I thought I could add something like this in the canonical file: > > /^(reg)-(.*)-(.*)$/ ${2} > > > > However, I read in a few place that this would break recipient validation. > > Should add that while with the canonical above I do get the email to > the proper mailbox deli

Re: Migrating from sendmail, a few questions...

2010-08-30 Thread Wietse Venema
Jean-Yves Avenard: > Hi > > On 31 August 2010 01:00, Adam Tauno Williams wrote: > > "A separate parameter controls Postfix SASL mechanism policy during a > > TLS-encrypted SMTP session. The default is to copy the settings from the > > unencrypted session:" > > > > smtpd_sasl_security_options = no

Re: Migrating from sendmail, a few questions...

2010-08-30 Thread Wietse Venema
Jean-Yves Avenard: > smtpd_sasl_auth_enable = yes > smtpd_sasl_authenticated_header = yes > smtpd_sasl_security_options = noanonymous, noplaintext > smtpd_sasl_tls_security_options = noanonymous If this does not announce the SASL mechanisms that you expect, then the missing mechanisms are not inst

Re: Migrating from sendmail, a few questions...

2010-08-30 Thread Wietse Venema
Wietse Venema: > Jean-Yves Avenard: > > smtpd_sasl_auth_enable = yes > > smtpd_sasl_authenticated_header = yes > > smtpd_sasl_security_options = noanonymous, noplaintext > > smtpd_sasl_tls_security_options = noanonymous > > If this does not announce the SASL mecha

Re: check header from, reply-to, message-id domains against spamhaus dbl?

2010-08-30 Thread Wietse Venema
Victor Duchovni: > On Mon, Aug 30, 2010 at 01:06:28PM -0500, Stan Hoeppner wrote: > > > Is there a straightforward (i.e. relatively painless) way to check the > > header from, reply-to, and message-id domains against dbl.spamhaus.org > > and reject on a positive reply as with reject_r*bl_client? >

postscreen update: DNSBL filters and weights

2010-08-30 Thread Wietse Venema
Postscreen is a single Postfix 2.8 daemon that keeps spambots away from Postfix SMTP server processes, so that more Postfix server resources remain available for handling mail. It will hopefully become part of the next stable Postfix release. Below is a quote from the release notes about new filte

Re: check header from, reply-to, message-id domains against spamhaus dbl?

2010-08-30 Thread Wietse Venema
Stan Hoeppner: > Wietse Venema put forth on 8/30/2010 1:29 PM: > > Victor Duchovni: > >> On Mon, Aug 30, 2010 at 01:06:28PM -0500, Stan Hoeppner wrote: > >> > >>> Is there a straightforward (i.e. relatively painless) way to check the > >>> he

Re: canonical_maps pattern causes NDR to be sent as requeued message

2010-08-31 Thread Wietse Venema
D G Teed: > Aug 30 22:30:20 myself postfix/smtpd[25013]: NOQUEUE: reject: RCPT from > mta03.anisp.ca[24.111.111.111]: 550 5.1.1 <12345...@example.com>: Recipient > address rejected: User unknown in local recipient table > > However, if the email address is of the format of 6 numbers followed by a

Re: Invalid IP address (ipv6)

2010-08-31 Thread Wietse Venema
Arthur Titeica: > Hello, > > I have a postfix which works quite OK with both IPv4 and IPv6 but just > today I see some errors comming from one of the authenticated users. > > Out: 220 xxx.yyy.ro ESMTP Postfix > In: EHLO [::z:z:::fe79:ccd9] The correct syntax for IPv6 address l

Re: Using VERP on Postfix server

2010-08-31 Thread Wietse Venema
Reuben (Plexus IT): > Hey All, > > I am trying to use email sub addressing (VERP) on my Postfix server. To do > this I should be able to add tag to an email address > return+tag=bob@give2partners.org and still receive the email to > ret...@give2partners.org. >

Re: Wildcard .domain.tld notation in mydestination

2010-08-31 Thread Wietse Venema
As far as I can tell, the documentation does not promise that mydestination supports .domain matching, therefore such behavior is not supported. If the documentation is in error, you're welcome to report this and the documentation will be fixed. It is not practical for Postfix to document all the

Re: SASL readme smtp/smtpd confusion

2010-08-31 Thread Wietse Venema
Jasper Jongmans: > The SASL readme section "Postfix SMTP/LMTP client policy - SASL > mechanism properties" > , subsection > "Encrypted SMTP session (TLS)", mentions smtpd_sasl_security_options and > smtpd_sasl_tls_security_options, but I t

Re: Postfix forwarding may result in backscatter

2010-08-31 Thread Wietse Venema
Stefan Seidel: > This forwarding to external addresses however, makes my Postfix create > backscatter. Example: > hijac...@yahoo.example.com sends email to u...@mysystem.com -> > virtual_alias_maps says: deliver it to interestedpa...@gmx.example.com > However, the mail server at gmx.example.com may

Re: Postfix forwarding may result in backscatter

2010-08-31 Thread Wietse Venema
Stefan Seidel: > I was actually in favour of using SRS as I also use SPF and it is often > mentioned that SRS is needed for SPF to work across forwarding, however > everything I found on the internet told me that Postfix didn't support it. Postfix implements DKIM, DomainKeys, SPF, SRS etc. via (Mi

Re: Postfix Message ID process

2010-08-31 Thread Wietse Venema
Morten P.D. Stevens: > Hi all, > > a small question regard to the postfix message id process. > > Every message has a unique ID provided by the postfix messaging process. The queue file name is only unique while the message is stored in the queue. Once the message is delivered the queue file nam

Re: smtp defer messages on smtp-auth error

2010-09-01 Thread Wietse Venema
Ram: > One of our postfix servers relays outbound mails to a relay provider > using smtpauth. > There have been some issues that sporadically the relay providers > database returns auth-failure for valid accounts and the mail bounces. > > I know they have to fix the issue at their database end , b

Re: Using VERP on Postfix server

2010-09-01 Thread Wietse Venema
8 host postfix/pipe[17625]: BE72CEA0255: > to=, relay=plesk_virtual, delay=0.39, > delays=0.32/0/0/0.07, dsn=2.0.0, status=sent (delivered via plesk_virtual > service) > Sep 1 22:06:08 host postfix/qmgr[16285]: BE72CEA0255: removed > > > Thanks > > Reubs > > > -O

Re: qmgr and file descriptor error

2010-09-01 Thread Wietse Venema
Giovanni Mancuso: > Hi, > > I use postfix in solaris 9 operating system. > > This morning in maillog i read: > > Sep 1 03:11:32 first postfix/qmgr[28676]: [ID 947731 local4.crit] fatal: > stream_connect: send file descriptor: Resource temporarily unavailable Your KERNEL reported to Postfix th

Re: Several relay_recipient_maps files ?

2010-09-01 Thread Wietse Venema
Frank Bonnet: > Hello > > is it possible to have several declared files/db in > the relay_recipient_maps statement ? http://www.postfix.org/postconf.5.html#relay_recipient_maps Wietse

Re: Delay deliver to a group of domains

2010-09-01 Thread Wietse Venema
gestion. You can shut up the warnings with "helpful_warnings = no" in main.cf (and "postfix reload"). Wietse > Regards, Pablo > > On Tue, Aug 24, 2010 at 12:46 PM, Pablo Garcia Melga wrote: > > Thanks Wietse, works just fine. > > > > > >

Re: Problem with SMTP Authentication

2010-09-02 Thread Wietse Venema
schnell-im-netz GmbH - Dominik Sennfelder: > Hello, > > I have an Ubuntu 10.04 Server with postfix installed. > several of our web servers deliver outgoing mail to this server > They do this without authentication allowed by the > mynetworks = > option. > > This works. > The server is setup to u

Re: transport according to sender (not recipient)?

2010-09-02 Thread Wietse Venema
Louis-David Mitterrand: > Hi, > > Can I select a specific transport depending on the envelope sender? No, that would break mail delivery with local recipients. You can have sender-dependent relayhost or default_transport, for mail delivery with non-local recipients. http://www.postfix.org/postc

Re: transport according to sender (not recipient)?

2010-09-02 Thread Wietse Venema
Louis-David Mitterrand: > On Thu, Sep 02, 2010 at 08:21:06AM -0400, Wietse Venema wrote: > > Louis-David Mitterrand: > > > Hi, > > > > > > Can I select a specific transport depending on the envelope sender? > > > > No, that would break mail deliv

Re: Problem with SMTP Authentication

2010-09-02 Thread Wietse Venema
schnell-im-netz GmbH - Dominik Sennfelder: > > > > This is part of the SASL authentication RFC. > > > > 5. The AUTH parameter to the MAIL FROM command > > > > AUTH=addr-spec > > > > Arguments: > > An addr-spec containing the identity which submitted > > the message > >

Re: transport according to sender (not recipient)?

2010-09-02 Thread Wietse Venema
Louis-David Mitterrand: > On Thu, Sep 02, 2010 at 09:01:44AM -0400, Wietse Venema wrote: > > Louis-David Mitterrand: > > > On Thu, Sep 02, 2010 at 08:21:06AM -0400, Wietse Venema wrote: > > > > Louis-David Mitterrand: > > > > > Hi, > > > >

Re: Better logging for a unix socket connection failure in a proxy filtering setup

2010-09-02 Thread Wietse Venema
Mark Martinec: > I'd like to report a rather minor/cosmetic problem - namely a lack of > useful logging when an smtpd service tries to connect to a proxy content > filter over a Unix socket which is too heavily protected - but which took > me far longer to understand than necessary (the strong prot

Re: Postfix + over quota change to perm error

2010-09-03 Thread Wietse Venema
Josef Karliak: >hi guys, >is possible to change error codes for over-quota error ? >Here is a thing - there are about 4 recipients in aliases : > /etc/aliases: > abuse: user1,user2,user3,user4 When sending mail to a multi-user alias, configure an an owner-abuse alias with the address o

Re: postscreen bug ?

2010-09-04 Thread Wietse Venema
fdo...@network-steps.com: > postfix keeps complaining > > close database /var/lib/postfix/ps_cache.db: No such file or directory That is a Berkeley DB mis-feature. Newer Postfix snapshots ignore that error. Wietse

Re: postscreen bug ?

2010-09-04 Thread Wietse Venema
Ralf Hildebrandt: [ Charset UTF-8 unsupported, converting... ] > * Wietse Venema : > > > That is a Berkeley DB mis-feature. > > Newer Postfix snapshots ignore that error. > > I'm still seeing it with postfix-2.8-20100830: > > Sep 1 05:14:38 mail postfi

Re: recipient bcc at which point does the mail get duplicated

2010-09-05 Thread Wietse Venema
Frank Doege: > The problem is that postfix seems to generate the bcc message before > the spamfilter > and then send it without checks to the exchange. Look in the Postfix FILTER_README for no_address_mappings. Wietse

Re: processing time metrics for rejected connections

2010-09-05 Thread Wietse Venema
Jeroen Geilman: > As for your original question, the combined processing time of all your > smtpd_* checks will still be reflected in the delay-"a" value (pre-queue). > Whatever time postfix itself adds for processing will be either static > or insignificant (unless you have lots of expensive map

Re: Trying to use different header_checks depending on TCP port for incoming mail

2010-09-05 Thread Wietse Venema
Ralph Seichter: > I'm currently trying to figure out if it is possible to use different > header_checks for TCP ports 25 (mail from world) and 587 (mail submitted > by authenticated users). I tried the following without success: > > # cat /etc/postfix/master.cf > smtp inet n - n - - smt

Re: Trying to use different header_checks depending on TCP port for incoming mail

2010-09-05 Thread Wietse Venema
Ralph Seichter: > On 05.09.10 20:55, Wietse Venema wrote: > > > As documented header_checks are not implemented in smtpd(8) but > > in cleanup(8). > > Yup, that's why I asked if I needed a second cleanup service. > > > If you are courageous you can im

Re: Trying to use different header_checks depending on TCP port for incoming mail

2010-09-05 Thread Wietse Venema
Ralph Seichter: > On 06.09.10 00:25, mouss wrote: > > > add "-o syslog_name=postsubmission" to both your submission and > > cleanup_submission and see if it appears in your logs. > > I see postsubmission/smtpd in the mail log, but postsubmission/cleanup > is not logged. So, I guess my cleanup_sub

Re: Trying to use different header_checks depending on TCP port for incoming mail

2010-09-05 Thread Wietse Venema
Ralph Seichter: [ Charset ISO-8859-1 unsupported, converting... ] > On 05.09.10 22:07, Wietse Venema wrote: > > > Are you running header_checks BEFORE or AFTER the external content > > filter, or both? See the receive_override_options discussion in > > the Postfix FIL

Re: Using VERP on Postfix server

2010-09-06 Thread Wietse Venema
Reuben (Plexus IT): > Sep 1 22:06:08 host postfix-local[24106]: cannot chdir to mailname dir > return+test=bob.com: No such file or directory > Sep 1 22:06:08 host postfix-local[24106]: Unknown user: > return+test=bob@give2partners.org Above, the plesk_virtual service can't find the user yet

Re: Maximum number of delivery of emails

2010-09-07 Thread Wietse Venema
Victor Duchovni: > On Tue, Sep 07, 2010 at 09:07:54PM +0200, lst_ho...@kwsoft.de wrote: > > >> Single-core CPU limit. The system had 4 CPUs and the load peaked at ~25%. > >> The queue manager is single-threaded, and must do a fair amount of message > >> envelope processing. So the current design t

Re: sender and recipient dependend routing in a single postfix engine

2010-09-08 Thread Wietse Venema
Ilja Beeskow: > Hello @all > > I wonder if there is a possibility to tell postfix how to route e-mails > sender > and recipient dependent. Our scenario is as follows. You may have to use an SMTPD policy daemon that replies with "FILTER transport:nexthop". Not every mail routing problem can be

Re: Aggregating/rate-limiting emails

2010-09-08 Thread Wietse Venema
Yang Zhang: > Are there any extensions to Postfix that can aggregate multiple > outgoing emails into a single email within some time window? > > We're developing an application that runs on multiple hosts and emails > notifications to us (the developers @gmail.com) whenever something > goes wrong,

Re: Aggregating/rate-limiting emails

2010-09-08 Thread Wietse Venema
Yang Zhang: > Are there any extensions to Postfix that can aggregate multiple > outgoing emails into a single email within some time window? ... > aggregating messages together into a periodic digest that is emitted > at most once per minute. Any other (low-effort) solution ideas would > be apprec

Re: reject_unknown_client_hostname light?

2010-09-08 Thread Wietse Venema
pf at alt-ctrl-del.org: > Am I missing something obvious? Yes. http://www.postfix.org/postconf.5.html#reject_unknown_reverse_client_hostname Wietse

Re: integrate dspam into postfix

2010-09-08 Thread Wietse Venema
Martijn de Munnik: > So I'm using a mailbox_transport to call dspam. Unfortantly the mail > doesn't show up in the logs after the lmtp part (I have lmtp -v in > master.cf) and the mail isn't delivered. When I remove the The mailbox_transport delivers the mail to dspam, therefore the mail no

Re: sqlite driver and centos

2010-09-09 Thread Wietse Venema
subscri...@viliar.net.ru: > > If you want Postfix to support the obsolete API then you > > cannot remove support for the preferred API. > > Sorry for delay with answer. I'll send this diff as workaround. Because > I'm not a programmer/coder. Probably correct decision is using some another > ifdefs

Re: Trouble with multiple outgoing IPs and FILTER rules

2010-09-09 Thread Wietse Venema
l...@ds.gauner.org: > Hi, > > when using multiple outbound IPs in master.cf and FILTER we encountered an > unfortunate problem. > > Postfix seems not to update the nexthop when a filter matches in a > multi-recipient mail. As documented, the FILTER action affects ALL RECIPIENTS of the same messa

Re: Rewriting Received: header

2010-09-09 Thread Wietse Venema
Steve Huston: > *) When is the Received: line actually written to the message? If it's > after cleanup runs, then this is moot and I will have to figure a > different way of doing things (I have an idea already [1]) pickup(8) and smtpd(8) produce Received: headers. They write the message to clean

Re: Trouble with multiple outgoing IPs and FILTER rules

2010-09-09 Thread Wietse Venema
Dominik Schulz: > Am Donnerstag, 9. September 2010, 17:31:14 schrieb Wietse Venema: > > l...@ds.gauner.org: > > > Postfix seems not to update the nexthop when a filter matches in a > > > multi-recipient mail. > > As documented, the FILTER action affects ALL R

Re: Virtual users pop3d suggestions

2010-09-10 Thread Wietse Venema
Nick Edwards: > Another quick question before I depart for work, I understand also (from > that other lists thread) that postfix does not support maildir++ , with that > curiosity, I googled and found mention of it not being introduced due to > possible race conditions, but the latest mentions were

Re: sqlite driver and centos

2010-09-10 Thread Wietse Venema
subscri...@viliar.net.ru: > On Thu, 9 Sep 2010 11:06:07 -0400 (EDT), Wietse Venema > wrote: > > Will this work? Unfortunately I can't test Postfix myself on every > > version of everything. > > > > Wietse > > > > *** ./dict_sqlite.c-F

Re: Tiny documentation errors

2010-09-10 Thread Wietse Venema
Jasper Jongmans: > http://www.postfix.org/QSHAPE_README.html#active_congestion > Google Groups link produces "documented not available" error. I guess they changed the location. Someone who remembers the thread subject may be able to dig up its current location. > http://www.postfix.org/XFORWARD_

Re: Tiny documentation errors

2010-09-10 Thread Wietse Venema
Bryan Irvine: > On Fri, Sep 10, 2010 at 1:25 PM, Bryan Irvine wrote: > > On Fri, Sep 10, 2010 at 1:08 PM, Wietse Venema wrote: > >> Jasper Jongmans: > >>> http://www.postfix.org/QSHAPE_README.html#active_congestion > >>> Google Groups link produces &qu

Re: warning: bogus file name: maildrop/.turd_postfix

2010-09-10 Thread Wietse Venema
donovan jeffrey j: > greetings > > i just upgraded postfix to 2.7.1 on a OSX 10.6.4 machine. From what I have > read in the archives it may be an incorrect user or permission but it's not > harmful. How do i clear the warning ? > > I used macports > > Sep 10 22:00:22 mx1 postfix/master[191]:

Re: Another tiny documentation error in http://www.postfix.org/SASL_README.html

2010-09-11 Thread Wietse Venema
Patrick Ben Koetter: > * Richard Chapman : > > I'm not suer whether this is the correct place to report this - but > > if not please advise: > > > > In the document: > > http://www.postfix.org/SASL_README.html > > > > In the section entitled: > > > > > > Postfix SMTP/LMTP client policy -

Re: warning: bogus file name: maildrop/.turd_postfix

2010-09-11 Thread Wietse Venema
donovan jeffrey j: > > On Sep 10, 2010, at 10:30 PM, Wietse Venema wrote: > > > donovan jeffrey j: > >> greetings > >> > >> i just upgraded postfix to 2.7.1 on a OSX 10.6.4 machine. From what I have > >> read in the archives it may be an inco

Re: warning: bogus file name: maildrop/.turd_postfix

2010-09-11 Thread Wietse Venema
donovan jeffrey j: > > On Sep 10, 2010, at 10:49 PM, donovan jeffrey j wrote: > > > > > On Sep 10, 2010, at 10:30 PM, Wietse Venema wrote: > > > >> donovan jeffrey j: > >>> greetings > >>> > >>> i just upgraded postf

Postscreen update

2010-09-13 Thread Wietse Venema
Postscreen is a single Postfix 2.8 daemon that keeps spambots away from Postfix SMTP server processes, so that more Postfix server resources remain available for handling mail. It will hopefully become part of the next stable Postfix release. After adding DNSBL weights and filters two weeks ago, I

Re: Postscreen update

2010-09-13 Thread Wietse Venema
Matt Hayes: > Thanks for the update. I'm working on implementing this now, however, > I'm a bit confused with the postscreen_dnsbl_reply_map option. > > I know this is useful when you enabled the DEEP checks, which I plan on > doing, but want to make sure I have the full concept behind the abov

Re: Postscreen update

2010-09-14 Thread Wietse Venema
Frank Doege: > On 09/13/2010 10:55 PM, Wietse Venema wrote: > > Postscreen is a single Postfix 2.8 daemon that keeps spambots away > > from Postfix SMTP server processes, so that more Postfix server > > resources remain available for handling mail. It will hopefully > &

postscreen 20100914 problem

2010-09-15 Thread Wietse Venema
The postscreen in snapshot 20100914 has a problem where it terminates after logging a warning: Sep 15 00:58:38 spike postfix/postscreen[60527]: warning: ps_dnsbl_receive: unex pected event: 1 Sep 15 00:58:38 spike postfix/master[13545]: warning: process /usr/libexec/postf There is no loss of mail

FIXED (postscreen 20100914 problem

2010-09-15 Thread Wietse Venema
Wietse Venema: > The postscreen in snapshot 20100914 has a problem where it terminates ... > There is no loss of mail (or even delay of mail) but I'll try to fix it > today. Meanwhile, snapshot 20100913 is problem free. Postfix snapshot 20100915 fixes this trivial problem, and has

postscreen 20100916 update

2010-09-15 Thread Wietse Venema
Postfix snapshot 20100916 fixes one tiny buglet in postscreen, and improves the logging for pregreeting spambots. If nothing else comes up, this will be the last update in a while. Wietse Bugfix (introduced 20100914): the "postscreen_greet_wait" delay speedup worked only for DNSB

Re: Funny headers_checks matching

2010-09-16 Thread Wietse Venema
Jure Simsic: > Hi > I'm trying to replace To: header with header_checks regexp rule. The funny > thing is, as I've figured out, the rule works perfectly if the Received: > header is after the To: header (or missing), but does nothing if it is > before the To: header. I've tried running in debug mod

Re: Funny headers_checks matching

2010-09-16 Thread Wietse Venema
Wietse Venema: > Jure Simsic: > > Hi > > I'm trying to replace To: header with header_checks regexp rule. The funny > > thing is, as I've figured out, the rule works perfectly if the Received: > > header is after the To: header (or missing), but does nothi

Re: Forwarding only bounce messages to a different SMTP server

2010-09-16 Thread Wietse Venema
Tauren Mills: > 2. Configure postfix to forward bounce type emails to port 8025. I > don't know how to configure Postfix to do this. Any suggestions or > assistance would be appreciated. Untested example follows: /etc/postfix/main.cf: transport_maps = pcre:/etc/postfix/transport.pcre /etc/po

Re: postscreen

2010-09-16 Thread Wietse Venema
Vernon A. Fort: > using versions 2.8-20100913 and 2.8-20100915 - when i shutdown postfix, > i sometimes (more often that not) see the postscreen daemon hanging out > around 10 seconds after the master process terminates. Same results on > two different machines (intel/amd). postscreen cannot be t

Re: postscreen rhsbl

2010-09-16 Thread Wietse Venema
Vernon A. Fort: > Also, since postscreen cache's the dnsbl hits - Only for a split second. However, the lookups will be cached in the local DNS server, which you should have if your mail server handles a non-trivial amount of email. Wietse

postscreen 20100917 update

2010-09-16 Thread Wietse Venema
It looks like the postscreen changes are tapering off. Below are a number of code cleanups but no functionality changes. This is uploaded as postfix-2.8-20100917. I won't have time to make further changes in the coming weeks except when it is really necessary. Wietse Cleanup: postscr

Re: Funny headers_checks matching

2010-09-17 Thread Wietse Venema
Jure Simsic: > As the list refuses me to post such long debugs, I'm splitting my mail in > two: No-one here asked for DEBUG logging, so you just wasted a lot of electrons sending information that no-one will look at. Wietse

Re: postscreen rhsbl

2010-09-17 Thread Wietse Venema
Wietse Venema: > Vernon A. Fort: > > Also, since postscreen cache's the dnsbl hits - > > Only for a split second. However, the lookups will be cached in > the local DNS server, which you should have if your mail server > handles a non-trivial amount of email. The pos

Re: Funny headers_checks matching

2010-09-17 Thread Wietse Venema
Jure Simsic: > On Fri, Sep 17, 2010 at 1:16 PM, Wietse Venema wrote: > > > Jure Simsic: > > > As the list refuses me to post such long debugs, I'm splitting my mail in > > > two: > > > > No-one here asked for DEBUG logging, so you just wasted a l

Re: DB error connection

2010-09-17 Thread Wietse Venema
Oscar Mauricio Cruz Lazo: > However when I try and log into HORDE/IMP I get this error: > [...] when i check my APACHE log everything looks fine This is not the right mailing list for questions about Horde/Imp or Apache logging. Wietse

Re: conditional "recipient address verification" - how to do?

2010-09-18 Thread Wietse Venema
Eugene V. Boontseff: > I would be thankful for the idea, how to implement the following: > 1) if the main destination server is unavailable, my postfix accepts all > its mail. For this you need a list of valid recipients, otherwise you become a source of receive-then-bounce backscatter spam.

Re: dnsblog query fails, dig succeeds

2010-09-18 Thread Wietse Venema
Len Conrad: > postconf mail_version > mail_version = 2.7-20091209 > > we run a copy of zen locally: > > process dnblog -v logs: > > dns_query: 226.224.46.92.zen.rbldnsd.domain.net (A): Host not found > > but > > dig @zen.rbldnsd.domain.net 226.224.46.92.zen.rbldnsd.domain.net +short > 127.0.0

Re: dnsblog query fails, dig succeeds

2010-09-18 Thread Wietse Venema
Wietse Venema: > Len Conrad: > > postconf mail_version > > mail_version = 2.7-20091209 > > > > we run a copy of zen locally: > > > > process dnblog -v logs: > > > > dns_query: 226.224.46.92.zen.rbldnsd.domain.net (A): Host not found

Re: dnsblog query fails, dig succeeds

2010-09-19 Thread Wietse Venema
Len Conrad: > >>> Did you use the same resolv.conf on the same host. > >> > >>Did you do the lookups as an UNPRIVILEGED user. > >> > >>You are giving zero details, so I have to start at the bottom. > > > >I'm logged into the postscreen machine and su to root to work on postfix and > >run dig. We

Re: dnsblog query fails, dig succeeds

2010-09-19 Thread Wietse Venema
Len Conrad: > >> dns_query: 226.224.46.92.zen.rbldnsd.domain.net (A): Host not found > >> > >> but > >> > >> dig @zen.rbldnsd.domain.net 226.224.46.92.zen.rbldnsd.domain.net +short > >> 127.0.0.11 > > > >Did you use the same resolv.conf on the same host. Obviously you didn't because dig @zen.rb

Re: Can postfix guarantee durability (fsync)?

2010-09-20 Thread Wietse Venema
Yang Zhang: > Can postfix be configured to guarantee durable email receipt? This is required by internet mail RFC and therefore not configurable. Wietse > E.g., can it be sure to fsync the mbox/Maildir file and/or directory > before it acknowledges successful receipt of an email?

Re: Can postfix guarantee durability (fsync)?

2010-09-20 Thread Wietse Venema
Yang Zhang: > Just to be clear, if I have this Maildir in my mailbox postmap: > > j...@mydomain.com joe/ > > and most other settings are the Ubuntu 10.04 postfix defaults, then > postfix will have done an fsync by the time the "250 OK: queued as > 12345" comes back, such that if I then immediat

Re: Can postfix guarantee durability (fsync)?

2010-09-20 Thread Wietse Venema
Yang Zhang: > Can you pinpoint the exact RFC & section you're referring to? Thanks. I will give you as home work to study the following documents: RFC 821 RFC 2821 RFC 5321 These have lots of other good stuff about Internet mail. Wietse > On Mon, Sep 20, 2010 at 1

Re: Can postfix guarantee durability (fsync)?

2010-09-20 Thread Wietse Venema
Ralf Hildebrandt: > * Yang Zhang : > > > > No. Postfix replies "250 OK: queued as 12345" when the message is QUEUED. > > > > Doesn't this contradict your original reply that durability is > > guaranteed? If there's no fsync, then the message may not have been > > persisted to non-volatile storage

Re: REJECT mails to a specific domain -> ERROR mail to postmaster

2010-09-21 Thread Wietse Venema
Michael Weissenbacher: > > BUT - now for every mail that is sent to olddomain.com an ERROR Mail is > > sent to the Postmaster that looks like this: > > +++ snip1 +++ > > From: Mail Delivery System [mailto:mailer-dae...@mail.ourserver.com] > > Sent: Tuesday, September 21, 2010 12:45 PM > > To: Postm

Re: REJECT mails to a specific domain -> ERROR mail to postmaster

2010-09-21 Thread Wietse Venema
Michael Weissenbacher: > Hi Wietse! > > Wietse Venema: > > > > Please look at the output from this command: > > > > $ postconf -n notify_classes > > > > This parameter was changed from its default value. Why? > > > >

Re: REJECT mails to a specific domain -> ERROR mail to postmaster

2010-09-21 Thread Wietse Venema
Michael Weissenbacher: > In: MAIL From: SIZE=28675 > Out: 250 2.1.0 Ok > In: RCPT To: > Out: 451 4.3.5 Server configuration error Oops. You are getting postmaster noticifications because of the "Server configuration error". See the maillog file for details. You need to fix that regardless.

Re: REJECT mails to a specific domain -> ERROR mail to postmaster

2010-09-21 Thread Wietse Venema
Michael Weissenbacher: > Sep 21 15:04:58 smtp1 postfix/smtpd[14679]: warning: unknown smtpd > restriction: "med" That is also a configuration error. Wietse

Re: Problem with postfix-dnswl-permit (Was Re: REJECT mails to a specific domain -> ERROR mail to postmaster)

2010-09-21 Thread Wietse Venema
Michael Weissenbacher: > Hi Wietse! > > > Michael Weissenbacher: > >> Sep 21 15:04:58 smtp1 postfix/smtpd[14679]: warning: unknown smtpd > >> restriction: "med" > > > > That is also a configuration error. > > > This error was really HARD to track. Took me the whole day. But now i > finally found

Re: How to log/archive full outgoing mails including BCC info?

2010-09-21 Thread Wietse Venema
Yang Zhang: > How do you get Postfix to keep a log of all outgoing mails, in their > complete form (all headers + payload) as received from clients? The > closest param I've found so far are always_bcc & friends, but these > lose some information (at least the BCC field). Thanks in advance for > an

Re: postfix/local: Too many open files when opening .forward

2010-09-21 Thread Wietse Venema
Alexander 'Leo' Bergolth: > Hi! > > Since yesterday I am experiencing big problems when delivering mail to > an alias-list. (Yes, I have set up an owner-listname alias. :-)) Do you have the RIGHT owner-listname alias. > When delivering mail to a list which is implemented as an > ldap-alias-list

Re: postfix/local: Too many open files when opening .forward

2010-09-21 Thread Wietse Venema
Alexander 'Leo' Bergolth: > On 09/21/2010 10:57 PM, Wietse Venema wrote: > > Alexander 'Leo' Bergolth: > >> Since yesterday I am experiencing big problems when delivering mail to > >> an alias-list. (Yes, I have set up an owner-listname alias. :-)

Re: testing pipelining

2010-09-22 Thread Wietse Venema
Kammen van, Marco, Springer SBM NL: > Hi List, > > Is there a command line trick to test pipelining? No, but you could use Postfix instead. Sometimes the problem is not with the SMTP server itself, but with a %#^#&% firewall that mis-implements the protocol. With pipelining, multiple commands a

Re: postfix/local: Too many open files when opening .forward

2010-09-22 Thread Wietse Venema
Alexander 'Leo' Bergolth: > The file contains: > 8< > x...@gmail.com > \lhock Your loop does not reproduce. With this in my own .forward file: /dev/null \wietse Sending mail to wietse results in one copy to /dev/null and one copy to the mailbox file, an

<    12   13   14   15   16   17   18   19   20   21   >