[pfx] Re: TLSRPT support

2025-06-02 Thread Benny Pedersen via Postfix-users
Luca vom Bruch via Postfix-users skrev den 2025-06-02 23:13: I wanted to implement TLSRPT and added the Ghettoforge repo to Alma9 to get the latest 3.10.x release of Postfix, but now I found out that TLSRPT support is not compiled in the RPM Will it ever find its way into a regular .rpm? ask

[pfx] Re: Incoming OpenDKIM signature verification failing

2025-05-09 Thread Benny Pedersen via Postfix-users
Matus UHLAR - fantomas via Postfix-users skrev den 2025-05-09 16:18: On 09.05.25 08:14, Ken Biggs via Postfix-users wrote: Looking at the maillog, I notice policyd-spf is running before opendkim. Could that be modifying the email before dkim validation? it should not. I use pyspf-milter whic

[pfx] Re: Localpart length validation

2025-04-19 Thread Benny Pedersen via Postfix-users
Dmitriy Alekseev via Postfix-users skrev den 2025-04-19 15:59: Reverse path is must to be in place to properly process bounces back if due to any reason dst will fail to get email, and that's all. this is working if hosts does not accept and later bounces SRS is not helpfull there __

[pfx] Re: Localpart length validation

2025-04-18 Thread Benny Pedersen via Postfix-users
Dmytro Alieksieiev skrev den 2025-04-18 13:25: Hi Benn, you want propose any better alternatives for a forwarding to not break SPF and have ability properly send emails without DKIM? the forwarding host have there own spf record, so fix this, its teknical not possible to have borh envelope sen

[pfx] Re: Localpart length validation

2025-04-18 Thread Benny Pedersen via Postfix-users
Dmytro Alieksieiev via Postfix-users skrev den 2025-04-18 11:17: smtpd_recipient_restrictions = check_recipient_access regexp:/etc/postfix/recipient_address_length_restrictions ... /etc/postfix/recipient_address_length_restrictions /^.{38,}@/554 5.1.7 Recipient address rejected: Loc

[pfx] Re: postscreen after greeting tests?

2025-04-18 Thread Benny Pedersen via Postfix-users
Greg Klanderman via Postfix-users skrev den 2025-04-18 03:05: Hard evidence of that would be helpful to show exactly what is logged and exactly what configuration postscreen is using. https://www.postfix.org/DEBUG_README.html#mail gives details. OK: % postconf | grep 'postscreen_.*_\(enable\

[pfx] Re: list.sys4.de

2025-04-09 Thread Benny Pedersen via Postfix-users
Jack Raats via Postfix-users skrev den 2025-04-09 11:53: Sorry. I meant ipv4 only, so an ipv6 only server cann't connect with the mailinglists ARC-Authentication-Results i=1; list.sys4.de; dkim=fail; arc=none (Message is not ARC signed); dmarc=fail (Used From Domain Record) header.from=jaraso

[pfx] Re: A question about the configuration of postscreen

2025-04-06 Thread Benny Pedersen via Postfix-users
Andreas Kuhlen via Postfix-users skrev den 2025-04-06 11:20: smtp inet n - y - - smtpd -o smtpd_sasl_auth_enable=no if -o smtpd_sasl_auth_enable=no is not used in master.cf or main.cf its just inhirited from postconf -d defaults settings with are most time a very big help to not change un

[pfx] Re: A question about the configuration of postscreen

2025-04-06 Thread Benny Pedersen via Postfix-users
Viktor Dukhovni via Postfix-users skrev den 2025-04-06 03:25: To activate postscreen in the master.cf file I added the following passage: smtp inet n - y - 1 postscreen smtpd pass - - y - - smtpd Add -o smtpd_sasl_a

[pfx] Re: double dkim signature (sendmail)

2025-03-24 Thread Benny Pedersen via Postfix-users
A. Schulze via Postfix-users skrev den 2025-03-24 09:06: Sean McBride via Postfix-users: It can. It's probably a better idea than using OpenDKIM, because that project seems dead as best as I can tell, it has had no commits for 7 years: https://github.com/trusteddomainproject/OpenDKIM/comm

[pfx] Re: mail forwarding loop (chaining fetchmail | spamc | sendmail)

2025-03-17 Thread Benny Pedersen via Postfix-users
Paul Neuwirth via Postfix-users skrev den 2025-03-17 09:16: thank you for the suggestion. I found this thread in a forum, which seems to be exactly my use-case: https://forums.gentoo.org/viewtopic-t-829416-start-0.html https://dovecot.dovecot.narkive.com/BcwsH9DF/getmail-and-lda-deliver then

[pfx] Re: mail forwarding loop (chaining fetchmail | spamc | sendmail)

2025-03-16 Thread Benny Pedersen via Postfix-users
Paul Neuwirth via Postfix-users skrev den 2025-03-16 12:57: Hello List, I've a problem here and consulting web searches and AI didn't help much. I am trying to set up a cronjob (explanation later): (user vscan) "/usr/bin/fetchmail -f /etc/mail/.fetchmailrc -p IMAP -a -s -n --folder LearnAsHam

[pfx] Re: Replacing a mail server

2025-03-12 Thread Benny Pedersen via Postfix-users
Kenneth Porter via Postfix-users skrev den 2025-03-12 21:46: Could you run them side by side with the new server having a higher MX priority? Any mail arriving on the old server after that would likely be from spammers/scammers/malware (who like to target low-priority MX servers because they're

[pfx] Re: weird Spamhaus behavior

2025-03-09 Thread Benny Pedersen via Postfix-users
Petko Manolov skrev den 2025-03-09 11:23: On 25-03-09 10:29:51, Benny Pedersen via Postfix-users wrote: Petko Manolov via Postfix-users skrev den 2025-03-09 08:39: https://multirbl.valli.org/lookup/192.168.234.2.html damm i missed it rfc1918, ups Are you saying that the lookup failed

[pfx] Re: dmarc, dkim & spf failed but that message was delivered anyway

2025-03-09 Thread Benny Pedersen via Postfix-users
Petko Manolov via Postfix-users skrev den 2025-03-09 08:23: If a message falsely claim it originates from certain domain and then DKIM fail, i very much don't want to receive, let alone read, this message. Right? this is still not a job for dkim to reject, if you want to reject its better d

[pfx] Re: weird Spamhaus behavior

2025-03-09 Thread Benny Pedersen via Postfix-users
Petko Manolov via Postfix-users skrev den 2025-03-09 08:39: I had to remove zrd.dq.spamhaus.net from postscreen_dnsbl_sites so i can continue to spam you guys with my moronic questions. :) now that you did disclose your dqs key is it possible to see postconf -nf i did an "dig pvv7qvcjnfkjeb

[pfx] Re: test relay

2025-02-19 Thread Benny Pedersen via Postfix-users
Adam Weremczuk via Postfix-users skrev den 2025-02-19 15:26: Now, how do I restrict this relay to only be used by one specific LAN address or one specific LAN subnet? All other SMTP traffic should continue using the defaults already in place. make another smtp in master.cf mail.example.org

[pfx] Re: root user on Linux?

2025-01-14 Thread Benny Pedersen via Postfix-users
Scott K via Postfix-users skrev den 2025-01-14 15:30: I was watching mail being delivered to root in my log so I decided to try to create a root account in my email client but I wasn't able to, I was getting username password error show evidense logs

[pfx] Re: Postfix with Dovecot which should be listening on port 587?

2025-01-14 Thread Benny Pedersen via Postfix-users
Scott K via Postfix-users skrev den 2025-01-14 14:45: So after I disable Dovecot submission (by renaming /etc/dovecot/protocols.d/submissiond.protocol to submission.protocol.renamed) will Postfix then listen on 587 automatically? It was previously said that Dovecot was listening on 587 and Postfi

[pfx] Re: postfix and openarc

2025-01-14 Thread Benny Pedersen via Postfix-users
Patrick Ben Koetter via Postfix-users skrev den 2025-01-14 13:46: * natan via Postfix-users : Hi What is currently happening with the OpenArc project? On GitHub, I see the last modifications were made 7 years ago. Has the project completely failed? I'm asking because I see that Gmail/G-Suite a

[pfx] Re: What happened to rules

2024-12-18 Thread Benny Pedersen via Postfix-users
Bill Cole via Postfix-users skrev den 2024-12-18 18:36: b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire lol no hire ? --=_MailMate_C8150C25-8790-4C1E-98B8-E5F6361AF918_= Content-Type:

[pfx] Re: Problems Receiving Email But Only from Microsoft/Outlook [lost connection after EHLO]

2024-12-03 Thread Benny Pedersen via Postfix-users
Tim Harman via Postfix-users skrev den 2024-12-03 03:02: # Don't offer Auth until STARTTLS has setup smtpd_tls_auth_only = yes try comment this one, should imho only be overrided in master.cf not used/set in main.cf ___ Postfix-users mailing list

[pfx] no ptr, so i greylist

2024-11-10 Thread Benny Pedersen via Postfix-users
Nov 11 00:52:09 localhost postfix/smtpd[3656]: NOQUEUE: reject: RCPT from unknown[45.90.5.195]: 450 4.7.1 : Recipient address rejected: Greylisted for 60 minutes; from= to= proto=ESMTP helo= https://multirbl.valli.org/lookup/45.90.5.195.html 6 blocked lists only my server that see it so ?

[pfx] Re: Cloudmark CSI

2024-10-30 Thread Benny Pedersen via Postfix-users
Adriel via Postfix-users skrev den 2024-10-30 09:48: Some of my messages were rejected by cloudmark CSI though the message content was totally valid. Do you know this BL provider? Is it a reliable one? Thank you. logs ? CSI gives an reject message to follow sorting out, but end users cant, s

[pfx] Re: Cloudmark CSI

2024-10-30 Thread Benny Pedersen via Postfix-users
APach via Postfix-users skrev den 2024-10-30 17:35: https://csi.cloudmark.com/en/reset/ the reject messages is more correct, your help is here bogus, sorry ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to

[pfx] Re: alternative to one.com ?

2024-10-28 Thread Benny Pedersen via Postfix-users
Viktor Dukhovni via Postfix-users skrev den 2024-10-28 08:31: On Sat, Oct 26, 2024 at 08:31:39PM +0200, Benny Pedersen via Postfix-users wrote: i like to stop using one.com for servial ressons, first that do not support rfc 7505, why ? You mean, I guess, as a DNS provider? one.com is

[pfx] Re: Choose transport based on multiple conditions

2024-10-28 Thread Benny Pedersen via Postfix-users
Birta Levente via Postfix-users skrev den 2024-10-28 21:42: So, as I understand this is possible only with multi-instance? i have all my custommers domains pr domain sender ip, no multi-instance need for this yet if you need more help its esential showing logs, opfuscate is ok, just mentio

[pfx] Re: Choose transport based on multiple conditions

2024-10-28 Thread Benny Pedersen via Postfix-users
Birta Levente via Postfix-users skrev den 2024-10-28 20:32: Hello I have the following situation: default_transport=smtp -need to send to domain1 through smtpa, except if the sender is from_special then send through smtpb smtp.smtp     -o smtp_bind_address=ip1 smtpa . smtp     -o smt

[pfx] alternative to one.com ?

2024-10-26 Thread Benny Pedersen via Postfix-users
i like to stop using one.com for servial ressons, first that do not support rfc 7505, why ? and sending bils to dns admins when one.com users is not domain owner, hmm :) webpage is diffrent pr domains ?, hmm so is there better places to support registra payments, and do fully support dns

[pfx] Re: General feedback on my postfix setup?

2024-10-25 Thread Benny Pedersen via Postfix-users
Mark via Postfix-users skrev den 2024-10-24 14:00: https://www.pastebin.cz/en/p/fqcoW8Q Anything unneeded, excessive, exaggerated, abusive or wrong there, please? smtpd_sasl_auth_enable = yes remove this in main.cf add it to port 465 587 in master.cf i will refrain for commenting on CHROO

[pfx] Re: From/Reply-To munging (was Postfix in containers/kubernetes)

2024-10-23 Thread Benny Pedersen via Postfix-users
Danjel Jungersen via Postfix-users skrev den 2024-10-23 23:55: I managed to set up a working dkim from this help: this have an invalid dmarc: "v=DMARC1; p=reject; adkim=s; ruf=postmas...@example.org" mailto: is missing s

[pfx] Re: reverse DMARC protection by restoring the "From:" header?

2024-10-23 Thread Benny Pedersen via Postfix-users
Vincent Lefevre via Postfix-users skrev den 2024-10-23 10:37: Probably not a user interface issue. If mail client starts showing the "Author:" address instead of "From:", DMARC/SPF would probably evolve to also ban a different domain in "Author:" to protect the recipient against domain spoofing.

[pfx] Re: From/Reply-To munging (was Postfix in containers/kubernetes)

2024-10-18 Thread Benny Pedersen via Postfix-users
Wietse Venema via Postfix-users skrev den 2024-10-18 18:32: https://docs.mailman3.org/projects/mailman/en/latest/src/mailman/handlers/docs/dmarc-mitigations.html why do maillist at first need to have Reply-To: at all ? too late to get Majordomo back ? :=) https://en.wikipedia.org/wiki/Majord

[pfx] Re: bounced message = spam ?

2024-10-17 Thread Benny Pedersen via Postfix-users
Testeur Starinux via Postfix-users skrev den 2024-10-17 22:39: Is there a solution to unallow this on my postfix server ? with so much debug info in the above its not possible to find the root in the trees :) so postconf -nf, and postconf -Mf, or follow this link here https://amavis-users.

[pfx] Re: Process and deliver email but return error to the client?

2024-09-20 Thread Benny Pedersen via Postfix-users
hawky--- via Postfix-users skrev den 2024-09-20 17:35: Hi Wietse, we are struggling with t-online.de: As you may know as SMTP client you have to fulfill a bunch of requirements to be able to send mails to t-online.de. From time to time we receive mails from t-online.de, but can't answer. So

[pfx] Re: Rejecting by top level domain?

2024-09-05 Thread Benny Pedersen via Postfix-users
Bill Cole via Postfix-users skrev den 2024-09-05 22:35: [Puts on ASF SpamAssassin Contributor hat] not yet for sale :) There is a complex mechanism for this in SpamAssassin which (using the default rules & scores) is NOT an outright ban on any TLD in any particular role in a message but whic

[pfx] Re: Update mynetworks file without postfix restart

2024-09-04 Thread Benny Pedersen via Postfix-users
Burn Zero via Postfix-users skrev den 2024-09-04 07:42: Is there any way to update the mynetworks file without doing a postfix restart? I use mynetworks cidr file. imho no, why is it needed in the first place ? PS: restart vs reload, cidr does only need reload, not restart more help need mor

[pfx] Re: ת: Sending mail through vpn on postfix

2024-08-25 Thread Benny Pedersen via Postfix-users
Jyan Ren via Postfix-users skrev den 2024-08-25 20:09: I'm deploying postfix on my vps, but my ISP has blocked outbound traffic on port 25. install roundcube on vps, enjoy your isp blocking port 25 dont use soks5 ever vpn is fine for roundcube more help ?, show logs from postfix server if a

[pfx] Re: Fwd: limits to auth of submission

2024-08-22 Thread Benny Pedersen via Postfix-users
horizon--- via Postfix-users skrev den 2024-08-22 14:44: u...@mail.com:{CRYPT}$::userdb_quota_rule=*:bytes=1G How can I limit some people can auth with postfix submission (port 587), and some others can't? set password to some random only domain owner knows ? or https://www.postfix.

[pfx] Re: multiple certs for postfix

2024-08-17 Thread Benny Pedersen via Postfix-users
Wesley via Postfix-users skrev den 2024-08-17 08:11: Yes. The current hosting I am using is with a simple case: mail.riseup.net smtp.riseup.net Both works via SSL. If the hosts are: mail.foo.com smtp.bar.com That is a more complicated case. Where SNI is maybe required. cartbot --apache -d

[pfx] Re: dovecot_destination_recipient_limit not mentioned in postconf.5

2024-08-11 Thread Benny Pedersen via Postfix-users
Laura Smith via Postfix-users skrev den 2024-08-11 10:29: Why doesn't dovecot_destination_recipient_limit get a mention in the postconf docs (https://www.postfix.org/postconf.5.html) I discovered I needed it today because of an obscure error in my logs affecting only certain mails. Those mai

[pfx] Re: too many errors after AUTH

2024-08-09 Thread Benny Pedersen via Postfix-users
Corey H via Postfix-users skrev den 2024-08-09 13:53: Hello list, I saw many logs like this in our server log, Aug 9 19:48:27 mx postfix/submission/smtpd[3731732]: warning: unknown[5.31.8.57]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 Aug 9 19:48:27 mx postfix/submission/smtpd[3731732]:

[pfx] Re: vacation segfaults

2024-08-08 Thread Benny Pedersen via Postfix-users
Alex via Postfix-users skrev den 2024-08-08 19:24: # ls -l .vacation* .forward -rw-r--r--. 1 61104 users40 Apr 15 2022 .forward -rw--- 1 61104 users 16384 Aug 8 12:48 .vacation.db -rw---. 1 61104 users 223 Jul 30 2020 .vacation.msg -rw---. 1 61104 users90 Jul 30 2020 .

[pfx] Re: postfix cleanup_service question

2024-08-08 Thread Benny Pedersen via Postfix-users
Laura Smith via Postfix-users skrev den 2024-08-08 10:43: in such case, it should also not be added into "smtp" service, unless Laura (OP) uses different instance for incoming mail (or has more services in master.cf) Basically a derived version of https://www.postfix.org/MULTI_INSTANCE_READ

[pfx] Re: Do you reject DMARC failures?

2024-08-05 Thread Benny Pedersen via Postfix-users
Matus UHLAR - fantomas via Postfix-users skrev den 2024-08-05 11:57: So, even setting DMARC policy to "quarantine" or "reject" would not cause problems. i want to belive when ... if all dmarc policy is allowed what should happens on the time when subscribers got this with a dmarc fail ? mai

[pfx] Re: [OT] Null MX or not?

2024-08-01 Thread Benny Pedersen via Postfix-users
Bill Cole via Postfix-users skrev den 2024-08-01 16:33: OMG, I am apparently non-human... Mail systems and their rates of abuse and/or technical trouble vary greatly. Yes, score=5.773 tagged_above=-999 required=5 tests=[AUTHRES_ARC_NONE=0.5, AUTHRES_DKIM_FAIL=0.5, AUTHRES_DMARC_NONE=1.5, DK

[pfx] Re: Trouble blocking spammer domain

2024-07-30 Thread Benny Pedersen via Postfix-users
Wietse Venema via Postfix-users skrev den 2024-07-30 21:36: Those tables have no effect on the content of message headers. For that, the tables are called header_checks. However, you may be better off with rspamd. or simple milter-regex rspamd is most of the time ok with default config, but

[pfx] Re: Postfix to secured postfix

2024-07-19 Thread Benny Pedersen via Postfix-users
Gerd Hoerst via Postfix-users skrev den 2024-07-19 14:36: smtpd_sender_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_non_fqdn_sender, reject_unknown_sender_domain maybe you miss more smtpd

[pfx] Re: DANE and STS

2024-06-25 Thread Benny Pedersen via Postfix-users
Jeff Pang via Postfix-users skrev den 2024-06-25 08:44: how to deploy the following email security features? google it :) RFC 7672 SMTP-DANE smtp_dns_support_level = dnssec smtp_tls_security_level = dane thats all if you already have tls setup in smtp_ test with posttls-finger your-

[pfx] Re: No email forwarding?

2024-06-23 Thread Benny Pedersen via Postfix-users
Jaroslaw Rafa via Postfix-users skrev den 2024-06-23 23:15: But nobody wants to implement this, they rather want to advise against forwarding. forwarding is not brokken, what is brokken is that srs is needed to solve another domains spf records ? no just stop fokus on dkim, and dmarc aligm

[pfx] Re: No email forwarding?

2024-06-22 Thread Benny Pedersen via Postfix-users
Jeff Pang via Postfix-users skrev den 2024-06-23 00:54: I know how to setup postfix + opensrs for email forwarding. But google "why email forwarding is a bad idea" will get a lot of results. Should we not enable forwarding in now days? Thanks postfix can easely be setup as sasl client so it by

[pfx] Re: DQS key in error responses

2024-06-22 Thread Benny Pedersen via Postfix-users
Cody Millard via Postfix-users skrev den 2024-06-22 12:55: You can see my dqs key in the error send to the client. Is this a problem? If so, how could I remove the DQS key from the response? your postfix conf reveal it postscreen_dnsbl_reply_map = texthash:/etc/postfix/postscreen_dnsbl_reply

[pfx] Re: SPF hostname and domainname

2024-06-21 Thread Benny Pedersen via Postfix-users
Peter via Postfix-users skrev den 2024-06-21 08:45: On 21/06/24 07:13, Wietse Venema via Postfix-users wrote: SPF/DKIM/DMARC Checklist for (IMO) the best chance of getting your mail to be accepted: 1. HELO banner should pass SPF. 2. Envelope Sender should pass SPF. 3. Envelope Sender do

[pfx] Re: discard message

2024-06-20 Thread Benny Pedersen via Postfix-users
Paul Schmehl via Postfix-users skrev den 2024-06-20 21:28: If it’s header_checks, I would probably use something like /^X-Spam-Status: Yes, score=[5-100[/ to catch everything above five. header checks in postfix is done before content filters, so you would love to reject spam on base of remot

[pfx] Re: Troubleshooting roundcube connections to postfix

2024-06-18 Thread Benny Pedersen via Postfix-users
Viktor Dukhovni via Postfix-users skrev den 2024-06-18 15:27: On Tue, Jun 18, 2024 at 03:20:46PM +0200, Benny Pedersen via Postfix-users wrote: xpoint@tux ~ $ posttls-finger -w -lsecure -C "www.stovebolt.com:465" "www.stovebolt.com" posttls-finger: Connected

[pfx] Re: Troubleshooting roundcube connections to postfix

2024-06-18 Thread Benny Pedersen via Postfix-users
Paul Schmehl via Postfix-users skrev den 2024-06-18 08:04: posttls-finger: server certificate verification failed for mail.stovebolt.com[108.174.193.29]:465: num=62:Hostname mismatch This looks like it’s working correctly now, right? hostname mismatch means still need to reissue new cert m

[pfx] Re: Troubleshooting roundcube connections to postfix

2024-06-18 Thread Benny Pedersen via Postfix-users
Paul Schmehl via Postfix-users skrev den 2024-06-18 06:39: On Jun 17, 2024, at 10:14 PM, Cowbay via Postfix-users wrote: On 2024/6/18 10:43, Paul Schmehl via Postfix-users wrote: The problem is neither tls nor ssl worked. No matter what config I used, roundcube would always through an error.

[pfx] Re: Help with reject_sender_login_mismatch

2024-06-18 Thread Benny Pedersen via Postfix-users
Jeff Peng via Postfix-users skrev den 2024-06-18 09:30: smtps inet n - y - - smtpd -o smtpd_sender_restrictions=permit_sasl_authenticated,reject_sender_login_mismatch,reject order matters, first wins -o smtpd_sender_restrictions=reject_sender_login_misma

[pfx] Re: Troubleshooting roundcube connections to postfix

2024-06-18 Thread Benny Pedersen via Postfix-users
Peter via Postfix-users skrev den 2024-06-18 04:08: On 18/06/24 13:00, Jeff Peng via Postfix-users wrote: On 2024-06-18 07:30, Peter via Postfix-users wrote: On 17/06/2024 17:28, Paul Schmehl wrote: though it's a big offtopic, may I ask that, for roundcube, how to stop users adding their own

[pfx] Re: Troubleshooting roundcube connections to postfix

2024-06-17 Thread Benny Pedersen via Postfix-users
Jeff Peng via Postfix-users skrev den 2024-06-17 14:18: $config['imap_host'] = 'ssl://localhost:993'; then RC will connect to server failed due to mis-configured certs. $config['imap_conn_options'] = array ( 'ssl' => array ( 'verify_peer' => false, 'verify_peer_name' => false, ), ); but fa

[pfx] Re: Troubleshooting roundcube connections to postfix

2024-06-16 Thread Benny Pedersen via Postfix-users
Paul Schmehl via Postfix-users skrev den 2024-06-17 06:49: I’m hoping I have solved the problem. I have roundcube sending mail on port 25 with no auth (all daemons are running on the same server), and it is sending mail. Gmail rejects it, but I’ve altered my spf record to include localhost. I

[pfx] Re: Fastest way to reject unwanted sender

2024-06-16 Thread Benny Pedersen via Postfix-users
John R. Levine via Postfix-users skrev den 2024-06-16 15:18: I'm looking at the postscreen man page and I don't see anything about mail addresses. Am I missing something? postscreen is not smtpd I do see smtpd_command_filter. How about if I map MAIL FROM: to QUIT? so this needs smtpd mi

[pfx] Re: TLSv1 from major mailprovider?

2024-06-07 Thread Benny Pedersen via Postfix-users
Daniel Hiepler via Postfix-users skrev den 2024-06-07 10:20: My cipher config is: smtpd_tls_mandatory_ciphers = medium smtpd_tls_mandatory_exclude_ciphers = aNULL, eNULL, LOW, 3DES, MD5, EXP, PSK, SRP, DSS, DES, RC4, PSK smtpd_tls_mandatory_protocols = !SSLv2,!SSLv3,!TLSv1,!TLSv1.1 tls_medium

[pfx] Re: Capture Bounced Email Headers & Content

2024-06-04 Thread Benny Pedersen via Postfix-users
Wietse Venema via Postfix-users skrev den 2024-06-04 17:02: - Create a wild-card SPF policy for *.raystedman.org that permits all your SMTP client IP addresses. just not make it random as a * helo should be non shared aswell, but should at same time be on same domain i remember policyd v1

[pfx] Re: Masters.cf

2024-05-29 Thread Benny Pedersen via Postfix-users
Viktor Dukhovni via Postfix-users skrev den 2024-05-29 14:07: Perhaps a bit of luck? For me, the XBL only catches around 10% of the SASL probes. May your luck hold up. https://www.abuseipdb.com/user/139902 enless tryes :) all zen.spamhaus.org should be used as authbl, but not pbl 127.0.0.10

[pfx] Re: Masters.cf

2024-05-28 Thread Benny Pedersen via Postfix-users
John Hill via Postfix-users skrev den 2024-05-28 22:12: On 5/28/24 3:38 PM, Benny Pedersen via Postfix-users wrote: John Hill via Postfix-users skrev den 2024-05-28 21:14: I had dumped the configs but here is what I had. submission inet n   -   y   -   - smtpd   -o

[pfx] Re: Masters.cf

2024-05-28 Thread Benny Pedersen via Postfix-users
John Hill via Postfix-users skrev den 2024-05-28 21:14: I had dumped the configs but here is what I had. submission inet n - y - - smtpd -o smtpd_tls_security_level=encrypt -o smtpd_sasl_auth_enable=yes -o smtpd_delay_reject=no -o { smtpd_client_

[pfx] Re: How to allow only one specific sender to use smtp ?

2024-05-25 Thread Benny Pedersen via Postfix-users
Mike via Postfix-users skrev den 2024-05-25 23:58: How can I make that? check_sasl_access https://wiki.zimbra.com/wiki/How-to-restrict-ssl-login imho same you want ? just replace reject with permit, and reject all remaining if sasl user is not that user __

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Benny Pedersen via Postfix-users
Stephan Seitz via Postfix-users skrev den 2024-05-24 15:01: Carefull, if you have „smtpd_tls_auth_only = yes” (I think), then you’ll see AUTH after STARTTLS… port 25 must not be tls only if its needed use another port for tls only ___ Postfix-use

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Benny Pedersen via Postfix-users
Northwind via Postfix-users skrev den 2024-05-24 14:37: and restarted postfix. now I think it should be working. telnet localhost 25 ehlo localhost if you see AUTH in ehlo results it not done yet no AUTH results take another beer :) ___ Postfix-us

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Benny Pedersen via Postfix-users
Northwind via Postfix-users skrev den 2024-05-24 14:17: so, in main.cf: smtpd_sasl_auth_enable=no comment this out in main.cf, it already default no then in master.cf: submission inet n - y - - smtpd -o smtpd_sasl_auth_enable=yes Am I right? yes does this

[pfx] rspamd bugs ?

2024-05-24 Thread Benny Pedersen via Postfix-users
Authentication-Results list.sys4.de; dkim=pass header.d=junc.eu; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=junc.eu policy.dmarc=reject where comes REJECT from ? ___ Postfix-users mailing list -- postfix-us

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Benny Pedersen via Postfix-users
Allen Coates via Postfix-users skrev den 2024-05-24 11:51: Many moons ago I was told to put "smtpd_sasl_auth_enable=no"  in main.cf, blocking the function everywhere, and then put "-o smtpd_sasl_auth_enable=yes" in the submission stanza(s) in master.cf, expressly enabling it *just* there. th

[pfx] Re: IPv6 and RBL checks

2024-05-15 Thread Benny Pedersen via Postfix-users
Matus UHLAR - fantomas via Postfix-users skrev den 2024-05-15 11:29: On 15.05.24 11:25, Jos Chrispijn via Postfix-users wrote: Recently I noticed this in my logfile: 0.3.9.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.4.6.8.4.0.b.8.f.7.0.6.2.bl.spamcop.net: Host or domain name not found. Name service erro

[pfx] Re: IPv6 and RBL checks

2024-05-15 Thread Benny Pedersen via Postfix-users
Jos Chrispijn via Postfix-users skrev den 2024-05-15 11:25: Can someone explain why bl.spamcop.net reverses the ipv6 ip, thus not recognizing it like postscreen? https://multirbl.valli.org/lookup/2607%3Af8b0%3A4864%3A20%3A%3A930.html dnsbl must be reversed, not any news there and note valli.

[pfx] Re: private/dovecot-lmtp]: Connection refused)

2024-05-11 Thread Benny Pedersen via Postfix-users
Jason Hirsh via Postfix-users skrev den 2024-05-11 16:51: status=sent (delivered via dovecot service (lda(ja...@theoceanwindow.com): Error: net_connect_unix(/var/run/dovecot/stats-writer) failed: Permis)) grep -r stats /etc/dovecot/ i get an helpfull url from it /etc/dovecot/conf.d/10-metri

[pfx] Re: private/dovecot-lmtp]: Connection refused)

2024-05-11 Thread Benny Pedersen via Postfix-users
Jason Hirsh via Postfix-users skrev den 2024-05-11 02:47: I am running Postfix/Dovecot/MySQL mail server. It was doing ok until I tried to improve it., I maybe just reboot ? :) dsn=4.4.1, status=deferred (connect to triggerfish.theoceanwindow.com [1][private/dovecot-lmtp]: Connection refuse

[pfx] Re: Which DKIM application for postfix 3.9.0

2024-04-25 Thread Benny Pedersen via Postfix-users
Peter via Postfix-users skrev den 2024-04-25 09:22: You make a confusing, factually incomplete post with claims that are incorrect and then complain about a lack of clear response on a different list? If you're going to run down the postfix list for your own failure at least have the decency

[pfx] Re: hmm spf is missing :)

2024-04-25 Thread Benny Pedersen via Postfix-users
Peter via Postfix-users skrev den 2024-04-25 09:19: On 15/04/24 10:14, Benny Pedersen via Postfix-users wrote: Authentication-Results    list.sys4.de; dkim=pass header.d=porcupine.org; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=porcupine.org

[pfx] Re: postfix-users suscribe

2024-04-16 Thread Benny Pedersen via Postfix-users
Iker SAENZ via Postfix-users skrev den 2024-04-16 14:14: postfix-users suscribe you are already but incase you like to have one more email address subscribed follow links below here List-Id: "For discussions about using Postfix: questions, problem reports, or feature requests. Open subsc

[pfx] Re: Forward mail

2024-04-15 Thread Benny Pedersen via Postfix-users
Dimitris via Postfix-users skrev den 2024-04-15 16:22: a totally different approach : you could advise those with gmail accounts to use gmail as an email client and pull emails from your server. maybe not ideal (=trusting their email credentials within google), but eitherway, people using gmai

[pfx] Re: hmm spf is missing :)

2024-04-15 Thread Benny Pedersen via Postfix-users
Wietse Venema via Postfix-users skrev den 2024-04-15 15:21: Benny Pedersen via Postfix-users: Authentication-Results list.sys4.de; dkim=pass header.d=porcupine.org; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=porcupine.org policy.dmarc=none intended

[pfx] hmm spf is missing :)

2024-04-14 Thread Benny Pedersen via Postfix-users
Authentication-Results list.sys4.de; dkim=pass header.d=porcupine.org; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=porcupine.org policy.dmarc=none intended ? dmarc can't be aligned with this missing, i just complain for the authres in spamassassin ca

[pfx] Re: Is there a way to just quickly deliver "everything" to a file somewhere

2024-04-02 Thread Benny Pedersen via Postfix-users
Dan Mahoney via Postfix-users skrev den 2024-04-02 10:14: Hey there all, I’m setting up a staging version of dayjob’s ticket system, and we’d basically like postfix to still function, but instead of touching the internet at all, just deliver everything to a single file (or a maildir, I suppos

[pfx] Re: dane.sys4.de

2024-03-24 Thread Benny Pedersen via Postfix-users
Viktor Dukhovni via Postfix-users skrev den 2024-03-24 02:31: The code should be fixed, but nobody has complained loudly enough. time out or not, dnssec is green, tlsa is yellow, should smtp test be needed when tlsa is not green ? if smtp test is not done without tlsa green i think problem

[pfx] dane.sys4.de

2024-03-23 Thread Benny Pedersen via Postfix-users
it go into endless loop if mx is missing, so it does not do a/ failback testing, is this a bug ? ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] Re: Help please on converting SENDMAIL VIRTUSERTABLE to postfix

2024-03-18 Thread Benny Pedersen via Postfix-users
Glenn Tenney via Postfix-users skrev den 2024-03-18 08:50: Thanks. I’m hosting several domains: a couple need to accept any user@ except some that specifically need to be rejected delivering locally; some domains are more normal, just accept specific users & deliver to some local user (sometimes

[pfx] Re: Help please on converting SENDMAIL VIRTUSERTABLE to postfix

2024-03-18 Thread Benny Pedersen via Postfix-users
Glenn Tenney via Postfix-users skrev den 2024-03-18 03:52: My question in one, hopefully simple sentence, is: In Postfix, how do I configure Postfix such that all email to "user@some.domain" will return an error code (e.g. 550 user unknown) to bounce that email Victor gave a vierd config

[pfx] Re: Dumb question about logging

2024-03-08 Thread Benny Pedersen via Postfix-users
Stephen Satchell via Postfix-users skrev den 2024-03-08 06:52: grep relay= mail.log | grep -v relay=local I can then use the message ID to get all the log information for each questioned transaction. Am I on the right road? Please disabuse me of any incorrect notions. is it not grep -i r

[pfx] Re: A functional lightweight reverse alias?

2024-03-03 Thread Benny Pedersen via Postfix-users
David Bürgin via Postfix-users skrev den 2024-03-03 17:59: Gerben Wierda: Aliases are nice, to receive mail. But when you reply, the address behind the alias is exposed. I’m puzzling a bit over this statement … I also use aliases but was not aware that they would expose my real address? As a

[pfx] Re: Implementing From: field heuristic when sending messages?

2024-03-03 Thread Benny Pedersen via Postfix-users
Matus UHLAR - fantomas via Postfix-users skrev den 2024-03-03 15:59: milters vrfydmn and milterfrom, which allow you to reject mail where envelope and header from: are different ok if smtpd_milter_maps knows all maillist ips to not use milters, it could be ok neither of these controls the

[pfx] Re: rbl override doesn't work perhaps due to sender using relay

2024-02-24 Thread Benny Pedersen via Postfix-users
lists--- via Postfix-users skrev den 2024-02-24 09:49: check_client_access hash:/etc/postfix/client_checks, check_sender_access hash:/etc/postfix/sender_checks, check_client_access hash:/etc/postfix/rbl_override, reject_rbl_client bl.spamcop.net, check_policy_service unix:private/polic

[pfx] Re: postfix alternating between mail.example.com and real hostname?

2024-02-12 Thread Benny Pedersen via Postfix-users
Joachim Lindenberg via Postfix-users skrev den 2024-02-12 13:07: Any idea for the cause and a fix? http://www.postfix.org/DEBUG_README.html#mail ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-use

[pfx] Re: useful error messages! Thank you!

2024-02-02 Thread Benny Pedersen via Postfix-users
Carl Brewer via Postfix-users skrev den 2024-02-03 03:09: In a world where error messages are increasingly being obfuscated, it's great to see : Feb 3 00:00:28 rollcage13 postfix/postscreen[22418]: warning: postscreen_access_list: non-null host address bits in "2403:5814:f681:ab0c::0/48", pe

[pfx] voues at sys4

2024-01-14 Thread Benny Pedersen via Postfix-users
ARC-Authentication-Results i=1; list.sys4.de; dkim=pass header.d=junc.eu; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=junc.eu policy.dmarc=reject Authentication-Results mx.junc.eu (amavisd-new); dkim=pass (2048-bit key) header.d=postfix.org header.b="ip

[pfx] Re: DKIM => Undelivered Mail Returned to Sender

2024-01-14 Thread Benny Pedersen via Postfix-users
Gerd Hoerst via Postfix-users skrev den 2024-01-14 18:05: Hi ! Still no success.. sorry then, i just use amavisd :=) but what are logged from opendkim ? grep -r MTA /path/to/logdir/ note is try to help get MTA working ___ Postfix-users mailing li

[pfx] Re: DKIM => Undelivered Mail Returned to Sender

2024-01-14 Thread Benny Pedersen via Postfix-users
Gerd Hoerst via Postfix-users skrev den 2024-01-14 16:20: Hi ! OK is set now RejectFailures false in /etc/opendmarc.conf and 127.0.0.1 localhost hoerst.net .hoerst.net in /etc/opendkim/trusted.hosts How can i check if its now correct with my setup, that mail which is not coming from smpt o

[pfx] Re: postfix repo

2024-01-11 Thread Benny Pedersen via Postfix-users
Wietse Venema via Postfix-users skrev den 2024-01-11 15:56: natan via Postfix-users: Hi Wietse Have you thought about postfix repo for Debian, just like dovecot has for his relase ? I'm asking by the way Yes. It will happen some time. so next is gentoo ebuilds ? :)

[pfx] Re: recipient_bcc_maps clarification.

2024-01-08 Thread Benny Pedersen via Postfix-users
John Fawcett via Postfix-users skrev den 2024-01-08 18:09: #/etc/postfix/regexp_recipient_bcc a...@xx.com    devnull d...@xx.com    devnull @xx.com    zz...@xx.com Postfix will still generate bcc messages for emails to abc and def but they won't actually get sent out. this is why always_bcc

[pfx] Re: How to configure lmtp delivery

2023-12-31 Thread Benny Pedersen via Postfix-users
Togan Muftuoglu via Postfix-users skrev den 2023-12-31 11:56: mailbox_transport = lmtp:172.16.0.216:24 virtual_transport = lmtp:172.16.0.216:24 this it is transport_destination_recipient_limit = 1 imho not needed How do I achieve that postfix sends all mail both for the virtual domains a

  1   2   >