Re: Spam relay problems - need some config assistance

2021-01-24 Thread Viktor Dukhovni
On Mon, Jan 25, 2021 at 03:53:54AM +0100, Benny Pedersen wrote: > /etc/postfix/main.cf: > proxy_interfaces = 1.2.3.4 (the proxy/NAT external network address) This does not solve the issue at hand. It just prevents mail forwarding loops in the smtp(8) delivery agent. -- Viktor.

Re: Spam relay problems - need some config assistance

2021-01-24 Thread Benny Pedersen
On 2021-01-25 01:22, P. Ik. wrote: Dec 29 06:48:27 mail postfix/qmgr[108]: 6A158635: from=, size=, nrcpt=20 (queue active) Dec 29 06:48:27 mail postfix/smtpd[4467]: B033063B: client=unknown[172.17.0.1] Dec 29 06:48:27 mail postfix/smtpd[4470]: C3D6F63C: client=unknown[172.17.0.1] Dec 29 06:4

Re: Spam relay problems - need some config assistance

2021-01-24 Thread Viktor Dukhovni
On Sun, Jan 24, 2021 at 06:30:43PM -0600, P. Ik. wrote: > 172.17.0.* are the container ip's > .1 is the postfix host You have *source NAT* between the Internet and your MTA, so that all external connections appear to originate from the same source. With such a configuration, you MUST NOT trust a

Re: Spam relay problems - need some config assistance

2021-01-24 Thread P. Ik.
172.17.0.* are the container ip's .1 is the postfix host On Sun, Jan 24, 2021 at 6:05 PM Richard wrote: > > > Date: Sunday, January 24, 2021 15:57:18 -0600 > > From: "P. Ik." > > > >> On Sun, Jan 24, 2021 at 9:05 AM Matus UHLAR - fantomas > >> wrote: > >> > >> > >> example could explain much.

Re: Spam relay problems - need some config assistance

2021-01-24 Thread P. Ik.
Thanks for the info Benny, I will make those adjustments. I have mynetworks_style = subnet #mynetworks commented out Local apps that send mail are from other containerized apps on this host and from another host on the 192.168.* address range, but that will eventually go away. I added some log i

Re: Spam relay problems - need some config assistance

2021-01-24 Thread Richard
> Date: Sunday, January 24, 2021 15:57:18 -0600 > From: "P. Ik." > >> On Sun, Jan 24, 2021 at 9:05 AM Matus UHLAR - fantomas >> wrote: >> >> >> example could explain much. >> >> > postconf -n returns: >> >> > mynetworks_style = subnet >> >> > smtpd_relay_restrictions = permit_mynetworks, >

Re: Spam relay problems - need some config assistance

2021-01-24 Thread Benny Pedersen
On 2021-01-24 01:26, P. Ik. wrote: -take mail in from internet for delivery only to local email addresses on this server (I have 3 total local addresses) -local addresses on this server can send mail to any address -local delivery is forwarded to a gmail account Forwarding and reception to gmai

Re: Spam relay problems - need some config assistance

2021-01-24 Thread P. Ik.
Thanks for the reply Matus, another user also asked for similar. As I told them as well, I wasn't sure if based on what I was trying to accomplish someone would see a clear error in my config. I have the mail server shut down until I fix this, I dug out some examples here, I appreciate your assist

Re: New postfix server, authentication confusion

2021-01-24 Thread Viktor Dukhovni
On Sun, Jan 24, 2021 at 12:42:49PM +0100, Jeff Abrahamson wrote: > 1.  Users need to provide user + password to send (smtps) and receive > (imaps).  I see where I've configured this for dovecot, which is > /etc/dovecot/passwd.db.  That file contains lines like this: > > j...@mobilitains.fr:{B

Re: Alternate vs canonical domain name

2021-01-24 Thread Jeff Abrahamson
On 24/01/2021 16:44, Wietse Venema wrote: > Jeff Abrahamson: >> On 24/01/2021 16:08, Wietse Venema wrote: >>> Jeff Abrahamson: I've a domain (mobilitains.fr) with mail mostly configured.? I've also registered mobilitain.fr (without the "s") to catch misspellings.? This is easy for ht

Re: Alternate vs canonical domain name

2021-01-24 Thread Wietse Venema
Jeff Abrahamson: > On 24/01/2021 16:08, Wietse Venema wrote: > > Jeff Abrahamson: > >> I've a domain (mobilitains.fr) with mail mostly configured.? I've also > >> registered mobilitain.fr (without the "s") to catch misspellings.? This > >> is easy for https, but I don't see how to get it working wi

Re: Alternate vs canonical domain name

2021-01-24 Thread Jeff Abrahamson
On 24/01/2021 16:08, Wietse Venema wrote: > Jeff Abrahamson: >> I've a domain (mobilitains.fr) with mail mostly configured.? I've also >> registered mobilitain.fr (without the "s") to catch misspellings.? This >> is easy for https, but I don't see how to get it working with postfix >> (aside from m

Re: Alternate vs canonical domain name

2021-01-24 Thread Wietse Venema
Jeff Abrahamson: > I've a domain (mobilitains.fr) with mail mostly configured.? I've also > registered mobilitain.fr (without the "s") to catch misspellings.? This > is easy for https, but I don't see how to get it working with postfix > (aside from manually mapping each user in /etc/postfix/virtua

Re: Spam relay problems - need some config assistance

2021-01-24 Thread Matus UHLAR - fantomas
On 23.01.21 18:26, P. Ik. wrote: I've been using Postfix for quite some time and recently have installed it in a container but am getting a small amount of relay spam through and a lot of mail errors to unknown addresses (which signaled me to the config issue). example could explain much. pos

Re: missing "connect from" for new connection

2021-01-24 Thread Wietse Venema
Fourhundred Thecat: > Hello, > > I am processing mail logs, where each new connection usually looks like > this: > >connect from >... >disconnect from > > But occasionally I notice there is no matching "connect from ..", and I > only have: > > postfix/smtpd: lost connection after CO

Re: New postfix server, authentication confusion

2021-01-24 Thread Jeff Abrahamson
Thanks, and I do use those tools.  They require me to think to run them.  I'd like to find commandline versions I can stick in cron and configure to notify me if there's a problem.  Most days, there is no problem, and I'm happy not to think about this. For continuing readers, this is the status of

Re: New postfix server, authentication confusion

2021-01-24 Thread Curtis Maurand
for the blackhole lists, etc. take a look ar mxtoolbox.com postfix should be passing sasl requests to dovecot’s imap process. I use a tool called ispconfig which sets all of this up along with other tools such as clamav, rspamd or amavisd along with per user policies. my $0.02. I like its se

Alternate vs canonical domain name

2021-01-24 Thread Jeff Abrahamson
I've a domain (mobilitains.fr) with mail mostly configured.  I've also registered mobilitain.fr (without the "s") to catch misspellings.  This is easy for https, but I don't see how to get it working with postfix (aside from manually mapping each user in /etc/postfix/virtual). Probably I'm just no

New postfix server, authentication confusion

2021-01-24 Thread Jeff Abrahamson
I've set up a new postfix instance which more or less duplicates an older one.  The main change (besides being newer) is that the old one used real users with real accounts while this one uses virtual users.  Some bits work, some don't.  I'm a bit confused on how to test it, really, short of connec