/dev/rob0: > A non-whitelisted client which hit both primary MX (.211) and > secondary (.214) in proper sequence is getting deferred by > postscreen, both times. > > Oct 30 20:30:16 harrier postfix/postscreen[551]: CONNECT from > [216.150.190.51]:35507 to [207.223.116.211]:25 > Oct 30 20:30:22 harrier postfix/tlsproxy[570]: CONNECT from > [216.150.190.51]:35507 > Oct 30 20:30:23 harrier postfix/tlsproxy[570]: Anonymous TLS connection > established from [216.150.190.51]:35507: TLSv1 with cipher DHE-RSA-AES256-SHA > (256/256 bits) > Oct 30 20:30:23 harrier postfix/postscreen[551]: NOQUEUE: reject: RCPT from > [216.150.190.51]:35507: 450 4.3.2 Service currently unavailable; > from=<sen...@example.com>, to=<r...@example.net>, proto=ESMTP, > helo=<laxcolpps03.suth.com> > > But we still don't have the 'PASS NEW' logged. Two seconds go by;
How would postscreen know that the client makes no mistakes over the duration of the entire SMTP session? Wietse