ok.  Nu stiam cum e cu unbound. Am mai invatat ceva , multumesc!

dar am pus la containerul postfix dns: 1.1.1.1 si 8.8.8.8 in resolv.conf a ramas 127.0.0.11 dar acum rezolva hidroelectrica.ro in container . Presupun  ca face redirectarea care o facea catre unbound catre 1.1.1.1


root@mail:/home/paul/mailcow/mailcow-dockerized# docker exec -it mailcowdockerized-postfix-mailcow-1 nslookup mail.hidroelectrica.ro
Server:        127.0.0.11
Address:    127.0.0.11#53

Non-authoritative answer:
Name:    mail.hidroelectrica.ro
Address: 91.216.144.232
Name:    mail.hidroelectrica.ro
Address: 91.216.144.231

acum cred insa ca e ceva buba si cu DNS hidroelectrica de nu il rezolva multi  inclusiv unbound

de ex :

root@mail:/home/paul/mailcow/mailcow-dockerized# dig mx hidroelectrica.ro

; <<>> DiG 9.18.12-0ubuntu0.22.04.2-Ubuntu <<>> mx hidroelectrica.ro
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 33846
;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;hidroelectrica.ro.        IN    MX

;; ANSWER SECTION:
hidroelectrica.ro.    3600    IN    MX    40 mail.hidroelectrica.ro.
hidroelectrica.ro.    3600    IN    MX    50 mail.hidroelectrica.ro.
hidroelectrica.ro.    3600    IN    MX    10 mail0.hidroelectrica.ro.
hidroelectrica.ro.    3600    IN    MX    10 mail1.hidroelectrica.ro.
hidroelectrica.ro.    3600    IN    MX    0 hidroelectrica-ro.mail.protection.outlook.com.

;; Query time: 68 msec
;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)
;; WHEN: Wed Aug 30 15:36:58 EEST 2023
;; MSG SIZE  rcvd: 188

uite cum sunt puse prioritatile de la MX-uri !

Multumesc, acum mi-a dat la hidroelectrica doar greylisted  sper ca mai apoi sa primeasca mailuri


Paul


On 30.08.2023 15:11, Catalin Muresan wrote:
La docker (docker-compose0 poti sa speicific ce DNS servere vrei tu:

https://github.com/compose-spec/compose-spec/blob/master/spec.md#dns

m-am uitat rapid la docker-compose.yml de la mailcow si din ce vad foloseste unbound pentru DNS cu toate celelalte containere folosind serviciul respectiv (am decupat ce nu era relevant):


    unbound-mailcow:
      image: mailcow/unbound:1.17
      networks:
        mailcow-network:
          ipv4_address: ${IPV4_NETWORK:-172.22.1}.254
          aliases:
            - unbound


    postfix-mailcow:
      image: mailcow/postfix:1.71
      dns:
        - ${IPV4_NETWORK:-172.22.1}.254
      networks:
        mailcow-network:
          ipv4_address: ${IPV4_NETWORK:-172.22.1}.253
          aliases:
            - postfix

daca la tine resolv.conf apare cu 127.0.0.11 inseamna ca ai ceva mailcow mai vechi ? dar solutia e aceeasi, pune

dns:
  - 1.1.1.1
  - 8.8.8.8

la postfix (sau la toate) si ai rezolvat

On Wed, 30 Aug 2023 at 08:31, Paul Lacatus via RLUG <rlug@lists.lug.ro> wrote:

    stiu ce contine :

    root@mail:~# docker exec -it mailcowdockerized-postfix-mailcow-1 cat
    /etc/resolv.conf
    nameserver 127.0.0.11
    options ndots:0

    indica ca nameserver 127.0.0.11 deci serverul de dns al lui
    dockerd care
    din pacate nu stiu de unde isi ia forwarders


    On 29.08.2023 22:10, a via RLUG wrote:
    > eventual poti sa vezi daca exista un /etc/resolv.conf in acel
    mailcow
    > container si ce contine
    >
    >
    > On Tue, Aug 29, 2023 at 7:54 PM Paul Lacatus via RLUG
    <rlug@lists.lug.ro>
    > wrote:
    >
    >> LE . Am dezinstalat docker din snap instalat din apt. Nici o
    >> imbunatarire !  Mailcow inainte sa lansez docker compose face
    un script
    >> de setup. In ultima instanta ma gandesc sa nu ia ceva acolo din
    resolv.conf
    >>
    >>
    >> Paul
    >>
    >>
    >> On 29.08.2023 19:09, Paul Lacatus via RLUG wrote:
    >>> On 29.08.2023 18:53, a via RLUG wrote:
    >>>> incearca si un restart la docker.service dupa modificarea
    resolv.conf
    >>>> (eventual si containerd.service)
    >>>>
    >>>> poate are vreun cache cu versiunea veche
    >>>>
    >>> Docker e instalat pe vps din snap. Am incercat snap restart
    docker, ok
    >>> dar masinaria tot nu merge.  Am si rebootat sistemul dupa
    update de
    >>> kernel
    >>>
    >>>
    >>> root@mail:~# docker exec -it mailcowdockerized-postfix-mailcow-1
    >>> nslookup mail.hidroelectrica.ro <http://mail.hidroelectrica.ro>
    >>> ;; connection timed out; no servers could be reached
    >>>
    >>>
    >>> root@mail:~# docker exec -it mailcowdockerized-postfix-mailcow-1
    >>> nslookup mail.paul-lacatus.ro <http://mail.paul-lacatus.ro>
    >>> Server:        127.0.0.11
    >>> Address:    127.0.0.11#53
    >>>
    >>> Non-authoritative answer:
    >>> Name: mail.paul-lacatus.ro <http://mail.paul-lacatus.ro>
    >>> Address: 46.214.204.147
    >>>
    >>> si din host
    >>>
    >>> root@mail:~# dig mx hidroelectrica.ro <http://hidroelectrica.ro>
    >>>
    >>> ; <<>> DiG 9.18.12-0ubuntu0.22.04.2-Ubuntu <<>> mx
    hidroelectrica.ro <http://hidroelectrica.ro>
    >>> ;; global options: +cmd
    >>> ;; Got answer:
    >>> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 45473
    >>> ;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0,
    ADDITIONAL: 1
    >>>
    >>> ;; OPT PSEUDOSECTION:
    >>> ; EDNS: version: 0, flags:; udp: 1232
    >>> ;; QUESTION SECTION:
    >>> ;hidroelectrica.ro <http://hidroelectrica.ro>.       IN    MX
    >>>
    >>> ;; ANSWER SECTION:
    >>> hidroelectrica.ro <http://hidroelectrica.ro>.   3600    IN   
    MX    10 mail0.hidroelectrica.ro <http://mail0.hidroelectrica.ro>.
    >>> hidroelectrica.ro <http://hidroelectrica.ro>.   3600    IN   
    MX    10 mail1.hidroelectrica.ro <http://mail1.hidroelectrica.ro>.
    >>> hidroelectrica.ro <http://hidroelectrica.ro>.   3600    IN   
    MX    0
    >>> hidroelectrica-ro.mail.protection.outlook.com
    <http://hidroelectrica-ro.mail.protection.outlook.com>.
    >>> hidroelectrica.ro <http://hidroelectrica.ro>.   3600    IN   
    MX    50 mail.hidroelectrica.ro <http://mail.hidroelectrica.ro>.
    >>> hidroelectrica.ro <http://hidroelectrica.ro>.   3600    IN   
    MX    40 mail.hidroelectrica.ro <http://mail.hidroelectrica.ro>.
    >>>
    >>> ;; Query time: 64 msec
    >>> ;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)
    >>> ;; WHEN: Tue Aug 29 19:06:45 EEST 2023
    >>> ;; MSG SIZE  rcvd: 188
    >>>
    >>>
    >>>
    >>>
    >>>> On Tue, Aug 29, 2023 at 6:31 PM Paul Lacatus via RLUG
    >>>> <rlug@lists.lug.ro>
    >>>> wrote:
    >>>>
    >>>>> Am un vps pe care rulez un mailcow.  De cand l-am facut nu
    mai primesc
    >>>>> mail de la Hidroelectrica ! Altele merg inclusiv google sau
    microsoft
    >>>>> fiind cu toate DKIM, DMARC, SPF in regula.
    >>>>>
    >>>>> postfix spune :
    >>>>>
    >>>>> NOQUEUE: reject: RCPT from unknown[91.216.144.231]: 450 4.1.8
    >>>>> <nore...@hidroelectrica.ro>: Sender address rejected: Domain not
    >> found;
    >>>>> from=<nore...@hidroelectrica.ro> to=<p...@lacatus.eu>
    proto=ESMTP
    >>>>> helo=<mail.hidroelectrica.ro <http://mail.hidroelectrica.ro>>
    >>>>>
    >>>>> Incerc un dig mx in vps si intr-adevar nu intoarce nimic  dig mx
    >>>>> @1.1.1.1 <http://1.1.1.1> intoarce corect
    >>>>>
    >>>>> DNS din /etc/resolv.conf puse de hosting nu gasesc intr-adevar
    >>>>> hidroelectrica ! Pun in /etc/resolv.conf 1.1.1.1 si 8.8.8.8
    totul merge
    >>>>> ok in host dar in containerul cu postfix nu rezolva .
    Containerul cu
    >>>>> postfix are in resolv.conf 127.0.0.11, DNS intern docker
    compose.
    >>>>> Acesta
    >>>>> insa ar fi trebuit sa se actualizezeautomat  dupa
    resolv.conf din host.
    >>>>> Asa zic toate manualele. Dau docker compose down si up -d,
    la fel. Dupa
    >>>>> down ii mai dau si un pull si up -d . Tot ioc.  De unde sa o
    iau . Unde
    >>>>> are forwarders-urile DNS intern docker?
    >>>>>
    >>>>>
    >>>>> Paul
    >>>>>
    >>>>>
    >>>>> _______________________________________________
    >>>>> RLUG mailing list
    >>>>> RLUG@lists.lug.ro
    >>>>> http://lists.lug.ro/mailman/listinfo/rlug_lists.lug.ro
    >>>>>
    >>>> _______________________________________________
    >>>> RLUG mailing list
    >>>> RLUG@lists.lug.ro
    >>>> http://lists.lug.ro/mailman/listinfo/rlug_lists.lug.ro
    >>> _______________________________________________
    >>> RLUG mailing list
    >>> RLUG@lists.lug.ro
    >>> http://lists.lug.ro/mailman/listinfo/rlug_lists.lug.ro
    >> _______________________________________________
    >> RLUG mailing list
    >> RLUG@lists.lug.ro
    >> http://lists.lug.ro/mailman/listinfo/rlug_lists.lug.ro
    >>
    > _______________________________________________
    > RLUG mailing list
    > RLUG@lists.lug.ro
    > http://lists.lug.ro/mailman/listinfo/rlug_lists.lug.ro

    _______________________________________________
    RLUG mailing list
    RLUG@lists.lug.ro
    http://lists.lug.ro/mailman/listinfo/rlug_lists.lug.ro

_______________________________________________
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug_lists.lug.ro

Raspunde prin e-mail lui