José Luis Tallón schrieb: > > What we do (without policyd-weight, however): > > Redirect these "problematic domains" to a special restriction class (we > call it from_freemail) > Then, we match the sending server with *any* valid sending server for > that domain. > > Something along the lines: > ACCESS (check_sender_access somewhere) > terra.es from_telefonica > > from_telefonica = check_client_access > hash:$config_directory/access_from_telefonica > > /etc/postfix/access_from_telefonica > terra.es reject_unauth_destination > telefonica.net reject_unauth_destination >
Is it possible that you meant permit_auth_destination instead of reject_unauth_destination? Also this requires that you (manually) determine the valid sending hosts of terra.es which can not be compared to the things policyd-weight does.