Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Koko Wijatmoko
On Thu, 03 Dec 2015 22:26:19 -0500 "Bill Cole" wrote: > DO NOT move the '-o smtpd_tls_wrappermode=yes' line to > the section for the submission service. That is ONLY > for the deprecated port 465 (SMTP inside SSL) service. > If you put it on port 587 for submission, submission > will not work. y

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Bill Cole
On 3 Dec 2015, at 8:33, Koko Wijatmoko wrote: [...] submission inet n - n - - smtpd -o smtpd_tls_security_level=encrypt -o syslog_name=postfix/submission -o smtpd_tls_security_level=encrypt -o smtpd_milters=inet:127.0.0.1:8891 smtp unix - - n

Re: smtpd_helo restrictions no permanent error? Can we change it?

2015-12-03 Thread Noel Jones
On 12/3/2015 5:01 PM, Thomas Nagel wrote: > Hi, > > we implemented a smtpd_helo_restrictions check with this configuration: > > smtpd_helo_restrictions = > permit_mynetworks, > permit_sasl_authenticated, > # check_client_access hash:/etc/postfix/ > check_helo_access hash:/etc/postfix/check_

smtpd_helo restrictions no permanent error? Can we change it?

2015-12-03 Thread Thomas Nagel
Hi, we implemented a smtpd_helo_restrictions check with this configuration: smtpd_helo_restrictions = permit_mynetworks, permit_sasl_authenticated, # check_client_access hash:/etc/postfix/ check_helo_access hash:/etc/postfix/check_helo_access reject_invalid_helo_hostname # reject_non_fqd

Re: spamassassin exceptions

2015-12-03 Thread Benny Pedersen
Peter skrev den 2015-12-03 21:39: In the meantime I found another approach that worked for me: http://serverfault.com/questions/33518/postfix-skip-spam-checks-for-authorized-smtp see my comment on this url

Re: spamassassin exceptions

2015-12-03 Thread Peter
Thanks Wietse, In the meantime I found another approach that worked for me: http://serverfault.com/questions/33518/postfix-skip-spam-checks-for-authorized-smtp Peter On Thu, Dec 3, 2015, at 03:43 PM, Wietse Venema wrote: > Peter: > > I would like to exclude certain IP ranges from scanning at a

Re: Has anyone else seen this please? spamd[94095]: spf: lookup failed: etc etc

2015-12-03 Thread Herbert J. Skuhra
On Thu, Dec 03, 2015 at 05:05:37PM +, Robert Chalmers wrote: > I have spam assassin running under postfix - but I’m getting an error > popping up now and then, and I’m darned if I can locate how to fix it. > Has anyone on the list seen this? > > spamd[94095]: spf: lookup failed: Can't locate ob

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Steve Jenkins
On Thu, Dec 3, 2015 at 9:18 AM, Noel Jones wrote: > On 12/3/2015 11:07 AM, Steve Jenkins wrote: > > On Thu, Dec 3, 2015 at 9:01 AM, Robert Chalmers > > mailto:rob...@chalmers.com.au>> wrote: > > > > To enlarge on that, I have in main.cf and > > master.cf

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Robert Chalmers
Thanks Noel, as it is working - I’ll leave well enough alone then. Thanks > On 3 Dec 2015, at 17:18, Noel Jones wrote: > > On 12/3/2015 11:07 AM, Steve Jenkins wrote: >> On Thu, Dec 3, 2015 at 9:01 AM, Robert Chalmers >> mailto:rob...@chalmers.com.au>> wrote: >> >>To enlarge on that, I ha

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Noel Jones
On 12/3/2015 11:07 AM, Steve Jenkins wrote: > On Thu, Dec 3, 2015 at 9:01 AM, Robert Chalmers > mailto:rob...@chalmers.com.au>> wrote: > > To enlarge on that, I have in main.cf and > master.cf the following > > main.cf > ///

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Robert Chalmers
Thanks Steve So is that main.cf or master.cf that you have it in only… … It’s pretty much your earlier setup you posted that I’m using :-) > I have OpenDKIM and OpenDMARC milters listed only in main.cf, and both are > running fine. So if it’s in master.cf it’s submission only, if in main.cf it

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Steve Jenkins
On Thu, Dec 3, 2015 at 9:01 AM, Robert Chalmers wrote: > To enlarge on that, I have in main.cf and master.cf the following > > main.cf > /// > # dkim > smtpd_milters = inet:127.0.0.1:8891 > non_smtpd_milters = inet:127.0.0.1:8891 > milter_defaul

Has anyone else seen this please? spamd[94095]: spf: lookup failed: etc etc

2015-12-03 Thread Robert Chalmers
I have spam assassin running under postfix - but I’m getting an error popping up now and then, and I’m darned if I can locate how to fix it. Has anyone on the list seen this? spamd[94095]: spf: lookup failed: Can't locate object method "handles" via package "IO::Socket::IP" at /opt/local/lib/p

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Robert Chalmers
To enlarge on that, I have in main.cf and master.cf the following main.cf /// # dkim smtpd_milters = inet:127.0.0.1:8891 non_smtpd_milters = inet:127.0.0.1:8891 milter_default_action = accept //

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Chalmers
So I'm still needing to put the openDkim in master.cf ? - From my iPhone. > On 3 Dec 2015, at 4:50 p.m., Steve Jenkins wrote: > >> On Thu, Dec 3, 2015 at 7:51 AM, Noel Jones wrote: >> Settings in main.cf apply to all services. Settings in master.cf >> only apply to the service they are

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Steve Jenkins
On Thu, Dec 3, 2015 at 7:51 AM, Noel Jones wrote: > Settings in main.cf apply to all services. Settings in master.cf > only apply to the service they are listed in. > > You may have a milter that is needed only in the "submission" > service, such as a DKIM signer. Thanks, Noel. I figured as mu

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Noel Jones
On 12/3/2015 9:43 AM, Steve Jenkins wrote: > On Thu, Dec 3, 2015 at 1:54 AM, Robert Chalmers > mailto:rob...@chalmers.com.au>> wrote: > > Could someone check my master.cf file please > for accuracy and validity. Especially spamassassin and how it’s > setup. > >

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Steve Jenkins
On Thu, Dec 3, 2015 at 1:54 AM, Robert Chalmers wrote: > Could someone check my master.cf file please for accuracy and validity. > Especially spamassassin and how it’s setup. > > master.cf related section: > > submission inet n - n - - smtpd > -o smtpd_tls_security

Re: unknown recipient domain being soft bounced despite 550 setting

2015-12-03 Thread Noel Jones
On 12/3/2015 9:02 AM, Marko Cupać wrote: > Hi, > > I have the following in main.cf: > > soft_bounce = no > unknown_address_reject_code = 550 > > Still, postfix server rejects mail from our exchange server with 450 > instead of 550: > > Dec 3 15:41:32 mx2 postfix/smtpd[40509]: NOQUEUE: reject:

unknown recipient domain being soft bounced despite 550 setting

2015-12-03 Thread Marko Cupać
Hi, I have the following in main.cf: soft_bounce = no unknown_address_reject_code = 550 Still, postfix server rejects mail from our exchange server with 450 instead of 550: Dec 3 15:41:32 mx2 postfix/smtpd[40509]: NOQUEUE: reject: RCPT from exchange.senderdomain.org[D.D.D.D]: 450 4.1.2 : Rec

Re: spamassassin exceptions

2015-12-03 Thread Wietse Venema
Peter: > I would like to exclude certain IP ranges from scanning at all. Say I do > not want to scan messages from 1.2.3.4 at all (do not forward them to > the content filter). How can I generally do that? The simplest solution is to use a spamassassin-internal whitelist. Other solutions are poss

spamassassin exceptions

2015-12-03 Thread Peter
Hi folks, I have SA injected into my postfix system the following way: master.cf: 10.0.0.1:smtp inet n - n - - smtpd -o content_filter=spamassassin spamassassinunix - n n - - pipe user=spamassassin argv=/usr/bin/spamc

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Koko Wijatmoko
On Thu, 3 Dec 2015 20:33:10 +0700 Koko Wijatmoko wrote: > you enable submission service twice again.. > sory again, port 465 != 587..

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Koko Wijatmoko
dont email me private, post it to mailing list.. sorry not to clear what i mean but.. you enable submission service twice again.. > submission inet n - n - - smtpd > -o smtpd_tls_security_level=encrypt > -o syslog_name=postfix/submission > -o smtpd_tls_s

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Koko Wijatmoko
forgot to comment about your SMTP-AUTH, move it to submission. opening SMTP-AUTH on standard SMTP port is risky (brute force attack). On Thu, 3 Dec 2015 12:49:47 + Chalmers wrote: > Thanks. How did I not see that? I cant believe it. > > thanks > > > > On 3 Dec 2015, at 10:50 a.m., Koko W

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Chalmers
Thanks. How did I not see that? I cant believe it. thanks - From my iPhone. > On 3 Dec 2015, at 10:50 a.m., Koko Wijatmoko wrote: > > On Thu, 3 Dec 2015 09:54:50 + > Robert Chalmers wrote: > >> submission inet n - n - - smtpd >> -o smtpd_tls_security

Re: Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Koko Wijatmoko
On Thu, 3 Dec 2015 09:54:50 + Robert Chalmers wrote: > submission inet n - n - - smtpd > -o smtpd_tls_security_level=encrypt > -o syslog_name=postfix/submission > -o smtpd_tls_security_level=encrypt > -o smtpd_milters=inet:127.0.0.1:8891 Err.. "smtpd_tls

Could someone check my master.cf file please for accuracy and validity.

2015-12-03 Thread Robert Chalmers
Could someone check my master.cf file please for accuracy and validity. Especially spamassassin and how it’s setup. master.cf related section: # Begin auto-generated section # This section of the master.cf file is auto-generated by the Server Admin #