Hey,

here are both exports of postfix configuration.
It's basicly postfix configured by mailcow with some small changes.
Guess I'll sent it over to the mailcow bugtracker then.

On 24.03.2025 16:32, Markus Winkler (m...@irmawi.de) wrote:
Hi Felix,

On 24.03.25 15:06, Felix Oberst (f...@thorsis.com) wrote:
  *  -> userA is not allowed to send mails from <external u...@gmail.com>.

could you please send the output of

- postconf -fn

/usr/sbin/postconf: warning: /opt/postfix/conf/main.cf, line 209: overriding earlier entry: message_size_limit=104857600 /usr/sbin/postconf: warning: /opt/postfix/conf/main.cf, line 211: overriding earlier entry: submission_smtpd_tls_mandatory_protocols=>=TLSv1.2 /usr/sbin/postconf: warning: /opt/postfix/conf/main.cf, line 212: overriding earlier entry: smtps_smtpd_tls_mandatory_protocols=>=TLSv1.2
alias_database = hash:/etc/aliases
alias_maps = hash:/etc/aliases
append_dot_mydomain = no
biff = no
bounce_queue_lifetime = 1d
broken_sasl_auth_clients = yes
compatibility_level = 3.7
config_directory = /opt/postfix/conf
delay_warning_time = 4h
disable_vrfy_command = yes
inet_interfaces = all
inet_protocols = all
lmtp_destination_recipient_limit = 1
lmtp_tls_mandatory_protocols = >=TLSv1.2
lmtp_tls_protocols = >=TLSv1.2
mail_name = Postcow
mailbox_size_limit = 0
maximal_backoff_time = 1800s
maximal_queue_lifetime = 5d
message_size_limit = 34603008
milter_default_action = tempfail
milter_mail_macros = i {mail_addr} {client_addr} {client_name} {auth_authen}
milter_protocol = 6
minimal_backoff_time = 300s
mydestination = localhost.localdomain, localhost
myhostname = mail.thorsis.com
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 [fe80::]/10
    172.22.1.0/24 [fd4d:6169:6c63:6f77::]/64
mynetworks_style = subnet
non_smtpd_milters = inet:rspamd:9900
parent_domain_matches_subdomains =
debug_peer_list,fast_flush_domains,mynetworks,qmqpd_authorized_clients
plaintext_reject_code = 550
postscreen_access_list = permit_mynetworks,
    cidr:/opt/postfix/conf/custom_postscreen_whitelist.cidr,
    cidr:/opt/postfix/conf/postscreen_access.cidr, tcp:127.0.0.1:10027
postscreen_bare_newline_enable = no
postscreen_blacklist_action = drop
postscreen_cache_cleanup_interval = 24h
postscreen_cache_map = proxy:btree:$data_directory/postscreen_cache
postscreen_discard_ehlo_keywords = silent-discard, dsn, chunking
postscreen_dnsbl_action = enforce
postscreen_dnsbl_sites = wl.mailspike.net=127.0.0.[18;19;20]*-2
    hostkarma.junkemailfilter.com=127.0.0.1*-2
    list.dnswl.org=127.0.[0..255].0*-2 list.dnswl.org=127.0.[0..255].1*-4
    list.dnswl.org=127.0.[0..255].2*-6 list.dnswl.org=127.0.[0..255].3*-8
    bl.spamcop.net*2 bl.suomispam.net*2
    hostkarma.junkemailfilter.com=127.0.0.2*3
    hostkarma.junkemailfilter.com=127.0.0.4*2
    hostkarma.junkemailfilter.com=127.0.1.2*1 backscatter.spameatingmonkey.net*2
    bl.ipv6.spameatingmonkey.net*2 bl.spameatingmonkey.net*2
    b.barracudacentral.org=127.0.0.2*7 bl.mailspike.net=127.0.0.2*5
    bl.mailspike.net=127.0.0.[10;11;12]*4 dnsbl.sorbs.net=127.0.0.10*8
    dnsbl.sorbs.net=127.0.0.5*6 dnsbl.sorbs.net=127.0.0.7*3
    dnsbl.sorbs.net=127.0.0.8*2 dnsbl.sorbs.net=127.0.0.6*2
    dnsbl.sorbs.net=127.0.0.9*2 zen.spamhaus.org=127.0.0.[10;11]*8
    zen.spamhaus.org=127.0.0.[4..7]*6 zen.spamhaus.org=127.0.0.3*4
    zen.spamhaus.org=127.0.0.2*3
postscreen_dnsbl_threshold = 6
postscreen_dnsbl_ttl = 5m
postscreen_greet_action = enforce
postscreen_greet_banner = $smtpd_banner
postscreen_greet_ttl = 2d
postscreen_greet_wait = 3s
postscreen_non_smtp_command_enable = no
postscreen_pipelining_enable = no
proxy_read_maps =
proxy:mysql:/opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf,
    proxy:mysql:/opt/postfix/conf/sql/mysql_mbr_access_maps.cf,
proxy:mysql:/opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf,
    $sender_dependent_default_transport_maps, $smtp_tls_policy_maps,
    $local_recipient_maps, $mydestination, $virtual_alias_maps,
    $virtual_alias_domains, $virtual_mailbox_maps, $virtual_mailbox_domains,
    $relay_recipient_maps, $relay_domains, $canonical_maps,
    $sender_canonical_maps, $sender_bcc_maps, $recipient_bcc_maps,
    $recipient_canonical_maps, $relocated_maps, $transport_maps, $mynetworks,
    $smtpd_sender_login_maps, $smtp_sasl_password_maps
queue_run_delay = 300s
recipient_canonical_classes = envelope_recipient
recipient_canonical_maps =
proxy:mysql:/opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
recipient_delimiter = +
relay_domains =
proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
relay_recipient_maps =
proxy:mysql:/opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
relayhost =
sender_dependent_default_transport_maps =
proxy:mysql:/opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
smtp_address_preference = any
smtp_dns_support_level = dnssec
smtp_header_checks = pcre:/opt/postfix/conf/anonymize_headers.pcre
smtp_sasl_auth_enable = yes
smtp_sasl_auth_soft_bounce = no
smtp_sasl_mechanism_filter = plain, login
smtp_sasl_password_maps =
proxy:mysql:/opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
smtp_sasl_security_options =
smtp_sender_dependent_authentication = yes
smtp_tls_CAfile = /etc/ssl/certs/ca-certificates.crt
smtp_tls_cert_file = /etc/ssl/mail/cert.pem
smtp_tls_key_file = /etc/ssl/mail/key.pem
smtp_tls_loglevel = 1
smtp_tls_mandatory_protocols = >=TLSv1.2
smtp_tls_policy_maps =
proxy:mysql:/opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
smtp_tls_protocols = >=TLSv1.2
smtp_tls_security_level = dane
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
smtpd_data_restrictions = reject_unauth_pipelining, permit
smtpd_delay_reject = yes
smtpd_discard_ehlo_keyword_address_maps =
    cidr:/opt/postfix/conf/esmtp_access.cidr
smtpd_discard_ehlo_keywords = chunking, silent-discard
smtpd_error_sleep_time = 10s
smtpd_forbid_bare_newline = yes
smtpd_hard_error_limit = ${stress?1}${stress:5}
smtpd_helo_required = yes
smtpd_milters = inet:rspamd:9900
smtpd_proxy_timeout = 600s
smtpd_recipient_restrictions = check_recipient_mx_access
    proxy:mysql:/opt/postfix/conf/sql/mysql_mbr_access_maps.cf,
    permit_sasl_authenticated, permit_mynetworks, check_recipient_access
proxy:mysql:/opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf,
    reject_invalid_helo_hostname, reject_unauth_destination
smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated,
    defer_unauth_destination
smtpd_sasl_auth_enable = yes
smtpd_sasl_authenticated_header = yes
smtpd_sasl_path = inet:dovecot:10001
smtpd_sasl_type = dovecot
smtpd_sender_login_maps =
    proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
smtpd_sender_restrictions = reject_authenticated_sender_login_mismatch,
    permit_mynetworks, permit_sasl_authenticated, reject_unlisted_sender,
    reject_unknown_sender_domain
smtpd_soft_error_limit = 3
smtpd_tls_auth_only = yes
smtpd_tls_cert_file = /etc/ssl/mail/cert.pem
smtpd_tls_dh1024_param_file = /etc/ssl/mail/dhparams.pem
smtpd_tls_eecdh_grade = auto
smtpd_tls_exclude_ciphers = ECDHE-RSA-RC4-SHA, RC4, aNULL, DES-CBC3-SHA,
    ECDHE-RSA-DES-CBC3-SHA, EDH-RSA-DES-CBC3-SHA
smtpd_tls_key_file = /etc/ssl/mail/key.pem
smtpd_tls_loglevel = 1
smtpd_tls_mandatory_ciphers = high
smtpd_tls_mandatory_protocols = >=TLSv1.2
smtpd_tls_protocols = >=TLSv1.2
smtpd_tls_received_header = yes
smtpd_tls_security_level = may
smtps_smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3
smtputf8_enable = no
submission_smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3
tls_preempt_cipherlist = yes
tls_server_sni_maps = hash:/opt/postfix/conf/sni.map
tls_ssl_options = NO_COMPRESSION, NO_RENEGOTIATION
transport_maps = pcre:/opt/postfix/conf/custom_transport.pcre,
    pcre:/opt/postfix/conf/local_transport,
    proxy:mysql:/opt/postfix/conf/sql/mysql_relay_ne.cf,
    proxy:mysql:/opt/postfix/conf/sql/mysql_transport_maps.cf
virtual_alias_maps =
    proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_alias_maps.cf,
proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_resource_maps.cf,
proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf,
proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
virtual_gid_maps = static:5000
virtual_mailbox_base = /var/vmail/
virtual_mailbox_domains =
proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
virtual_mailbox_maps =
proxy:mysql:/opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
virtual_minimum_uid = 104
virtual_transport = lmtp:inet:dovecot:24
virtual_uid_maps = static:5000

- postconf -fM

/usr/sbin/postconf: warning: /opt/postfix/conf/main.cf, line 209: overriding earlier entry: message_size_limit=104857600 /usr/sbin/postconf: warning: /opt/postfix/conf/main.cf, line 211: overriding earlier entry: submission_smtpd_tls_mandatory_protocols=>=TLSv1.2 /usr/sbin/postconf: warning: /opt/postfix/conf/main.cf, line 212: overriding earlier entry: smtps_smtpd_tls_mandatory_protocols=>=TLSv1.2
smtp       inet  n       -       n       -       1 postscreen
10025      inet  n       -       n       -       1 postscreen
    -o postscreen_upstream_proxy_protocol=haproxy
    -o syslog_name=haproxy
smtpd      pass  -       -       n       -       -       smtpd
    -o smtpd_sasl_auth_enable=no
    -o smtpd_sender_restrictions=permit_mynetworks,reject_unlisted_sender,reject_unknown_sender_domain
smtps      inet  n       -       n       -       -       smtpd
    -o smtpd_tls_wrappermode=yes
    -o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
    -o smtpd_tls_mandatory_protocols=$smtps_smtpd_tls_mandatory_protocols
    -o tls_preempt_cipherlist=yes
    -o cleanup_service_name=smtp_sender_cleanup
    -o syslog_name=postfix/smtps
10465      inet  n       -       n       -       -       smtpd
    -o smtpd_upstream_proxy_protocol=haproxy
    -o smtpd_tls_wrappermode=yes
    -o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
    -o smtpd_tls_mandatory_protocols=$smtps_smtpd_tls_mandatory_protocols
    -o tls_preempt_cipherlist=yes
    -o cleanup_service_name=smtp_sender_cleanup
    -o syslog_name=postfix/smtps-haproxy
submission inet  n       -       n       -       -       smtpd
    -o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
    -o smtpd_enforce_tls=yes
    -o smtpd_tls_security_level=encrypt
    -o smtpd_tls_mandatory_protocols=$submission_smtpd_tls_mandatory_protocols
    -o tls_preempt_cipherlist=yes
    -o cleanup_service_name=smtp_sender_cleanup
    -o syslog_name=postfix/submission
10587      inet  n       -       n       -       -       smtpd
    -o smtpd_upstream_proxy_protocol=haproxy
    -o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
    -o smtpd_enforce_tls=yes
    -o smtpd_tls_security_level=encrypt
    -o smtpd_tls_mandatory_protocols=$submission_smtpd_tls_mandatory_protocols
    -o tls_preempt_cipherlist=yes
    -o cleanup_service_name=smtp_sender_cleanup
    -o syslog_name=postfix/submission-haproxy
588        inet  n       -       n       -       -       smtpd
    -o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
    -o smtpd_tls_auth_only=no
    -o smtpd_sender_restrictions=check_sasl_access,regexp:/opt/postfix/conf/allow_mailcow_local.regexp,reject_authenticated_sender_login_mismatch,permit_mynetworks,permit_sasl_authenticated,reject_unlisted_sender,reject_unknown_sender_domain
    -o cleanup_service_name=smtp_sender_cleanup
    -o syslog_name=postfix/sogo
590        inet  n       -       n       -       -       smtpd
    -o smtpd_helo_restrictions=
    -o smtpd_client_restrictions=permit_mynetworks,reject
    -o smtpd_tls_auth_only=no
    -o smtpd_milters=
    -o non_smtpd_milters=
    -o syslog_name=postfix/quarantine
591        inet  n       -       n       -       -       smtpd
    -o smtpd_helo_restrictions=
    -o smtpd_client_restrictions=permit_mynetworks,reject
    -o smtpd_tls_auth_only=no
    -o smtpd_milters=
    -o non_smtpd_milters=
    -o syslog_name=postfix/bcc
smtp_enforced_tls unix - -       n       -       -       smtp
    -o smtp_tls_security_level=encrypt
    -o syslog_name=enforced-tls-smtp
    -o smtp_delivery_status_filter=pcre:/opt/postfix/conf/smtp_dsn_filter
smtp_via_transport_maps unix - - n       -       -       smtp
    -o smtp_sasl_password_maps=proxy:mysql:/opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
tlsproxy   unix  -       -       n       -       0       tlsproxy
dnsblog    unix  -       -       n       -       0       dnsblog
pickup     fifo  n       -       n       60      1       pickup
cleanup    unix  n       -       n       -       0       cleanup
qmgr       fifo  n       -       n       300     1       qmgr
tlsmgr     unix  -       -       n       1000?   1       tlsmgr
rewrite    unix  -       -       n       -       - trivial-rewrite
bounce     unix  -       -       n       -       0       bounce
defer      unix  -       -       n       -       0       bounce
trace      unix  -       -       n       -       0       bounce
verify     unix  -       -       n       -       1       verify
flush      unix  n       -       n       1000?   0       flush
proxymap   unix  -       -       n       -       -       proxymap
proxywrite unix  -       -       n       -       1       proxymap
smtp       unix  -       -       n       -       -       smtp
relay      unix  -       -       n       -       -       smtp
showq      unix  n       -       n       -       -       showq
error      unix  -       -       n       -       -       error
retry      unix  -       -       n       -       -       error
discard    unix  -       -       n       -       -       discard
local      unix  -       n       n       -       -       local
virtual    unix  -       n       n       -       -       virtual
lmtp       unix  -       -       n       -       -       lmtp flags=O
anvil      unix  -       -       n       -       1       anvil
scache     unix  -       -       n       -       1       scache
maildrop   unix  -       n       n       -       -       pipe flags=DRhu
    user=vmail argv=/usr/bin/maildrop -d ${recipient}
smtp_sender_cleanup unix n -     y       -       0       cleanup
    -o header_checks=$smtp_header_checks
127.0.0.1:10027 inet n   n       n       -       0       spawn user=nobody
    argv=/usr/local/bin/whitelist_forwardinghosts.sh
589        inet  n       -       n       -       -       smtpd
    -o smtpd_client_restrictions=permit_mynetworks,reject
    -o syslog_name=watchdog
    -o syslog_facility=local7
    -o smtpd_milters=
    -o cleanup_service_name=watchdog_cleanup
    -o non_smtpd_milters=
watchdog_cleanup unix n  -       n       -       0       cleanup
    -o syslog_name=watchdog
    -o syslog_facility=local7
    -o queue_service_name=watchdog_qmgr
watchdog_qmgr fifo n     -       n       300     1       qmgr
    -o syslog_facility=local7
    -o syslog_name=watchdog
    -o rewrite_service_name=watchdog_rewrite
watchdog_rewrite unix -  -       n       -       - trivial-rewrite
    -o syslog_facility=local7
    -o syslog_name=watchdog
    -o local_transport=watchdog_discard
watchdog_discard unix -  -       n       -       -       discard
    -o syslog_facility=local7
    -o syslog_name=watchdog



Thanks and regards,
Markus
--

Sehr geehrte Damen und Herren,

Best Regards,
Mit freundlichen Grüßen

Felix Oberst
IT
+49 391 544 563 2080

Thorsis Technologies GmbH
Oststr. 18
39114 Magdeburg
T+49 391 544 563 1000
https://www.thorsis.com

Sitz der Gesellschaft: Magdeburg
Amtsgericht Stendal HRB 30646
Geschäftsführer: Dipl.-Inf. Michael Huschke

Reply via email to