HI All,
Every day i m seeing hundreds of mails in mailq, all they are having
unknown domain name.
I had changes in my Postfix server but I don't how to restrict this
unwanted mails and due that my mail server showing blacklist in public
black lists..
Please find below my postfix configuration:
Note: Server's host name changed intentionally, to hide identity of mail
server
# See /usr/share/postfix/main.cf.dist for a commented, more complete version
# Debian specific: Specifying a file name will cause the first
# line of that file to be used as the name. The Debian default
# is /etc/mailname.
#myorigin = /etc/mailname
smtpd_banner = $myhostname ESMTP $mail_name (Ubuntu)
biff = no
# appending .domain is the MUA's job.
append_dot_mydomain = no
# Uncomment the next line to generate "delayed mail" warnings
#delay_warning_time = 4h
readme_directory = no
#disable_dns_lookups = yes
#relayhost = 192.168.1.1
# TLS parameters
smtpd_tls_cert_file = /etc/ssl/certs/smtpd.crt
smtpd_tls_key_file = /etc/ssl/private/smtpd.key
smtpd_use_tls=yes
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
# See /usr/share/doc/postfix/TLS_README.gz in the postfix-doc package for
# information on enabling SSL in the smtp client.
myhostname = *abc.test.com*
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
myorigin = /etc/mailname
mydestination = *abc.test.com*, localhost
mynetworks = 127.0.0.0/8 192.168.0.0/16
mailbox_size_limit = 0
recipient_delimiter = +
inet_interfaces = all
inet_protocols = ipv4
home_mailbox = Maildir/
# Deepak: the last part of following line is important
mailbox_command = procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/
smtpd_sasl_local_domain =
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
broken_sasl_auth_clients = yes
smtpd_helo_restrictions =
permit_mynetworks,reject_invalid_hostname,reject_non_fqdn_hostname,permit
smtpd_sender_restrictions =
reject_unknown_sender_domain,hash:/etc/postfix/access
smtpd_recipient_restrictions =
permit_sasl_authenticated,permit_mynetworks,reject_unauth_destination,reject_unknown_recipient_domain,reject_non_fqdn_recipient,reject_non_fqdn_sender,reject_unknown_sender_domain,reject_rbl_client
sbl.spamhaus.org
smtp_tls_security_level = may
smtpd_tls_security_level = may
smtpd_tls_auth_only = no
smtp_tls_note_starttls_offer = yes
smtpd_tls_CAfile = /etc/ssl/certs/cacert.pem
smtpd_tls_loglevel = 1
smtpd_tls_received_header = yes
smtpd_tls_session_cache_timeout = 3600s
tls_random_source = dev:/dev/urandom
--
From
Kamlesh Verma
System Administrator | Srishti Software Application Pvt Ltd
L-174,6th Sector HSR Layout,Bangalore-560102
Cell:- +91-9686450284