Re: gradual shift of traffic

2022-02-17 Thread Matthew Richardson
Wietse Venema wrote:- >>> Is it possible to accomplish a gradual shift of traffic from one mail relay >> to another via postfix? > >The randmap() feature comes to mind. > >Instead of "relayhost = old.example" or "relayhost = new.example" use: > >default_transport = > randmap:{smtp:old.e

Re: TLS ciphers

2022-01-11 Thread Matthew Richardson
Charlotte ? Delenk wrote:- >We are talking about systems that should not be running in prod anymore, >but still are due to inertia. Mails not being delivered may hopefully be >the push that kickstarts upgrading efforts. But it is not that the email fails delivery, rather it is transmitted unen

Re: AUTH rate limit

2021-11-03 Thread Matthew Richardson
Markus Schönhaber wrote:- >03.11.21, 10:53 +0100, @lbutlr: > >> postfix/smtps/smtpd[5554] warning: AUTH command rate limit exceeded: 4 >> >> Where is this limit set? I looked through postconf -d | grep auth looking >> for something but did not find anything. > >My guess would be >http://www.post

Re: Enforced TLS with Opportunistic DANE

2021-05-28 Thread Matthew Richardson
On Thu, 27 May 2021 13:07:39 -0400, Viktor Dukhovni wrote:- >On Thu, May 27, 2021 at 05:42:34PM +0100, Matthew Richardson wrote: > >> and I am wanting to enhance this for certain specific domains to >> require mandatory encryption, without neutering DANE if present. >> Th

Re: Enforced TLS with Opportunistic DANE

2021-05-27 Thread Matthew Richardson
Dear Viktor, Thank you for your (as usual!) most helpful response below, which was much appreciated. On Thu, 27 May 2021 11:57:41 -0400, Viktor Dukhovni wrote:- >On Thu, May 27, 2021 at 04:48:15PM +0100, Matthew Richardson wrote: > >> I am trying to work out the correct incantation

Enforced TLS with Opportunistic DANE

2021-05-27 Thread Matthew Richardson
I am trying to work out the correct incantation in order to specify for a given outgoing domain that:- * TLS is mandatory, the message is not sent unencrypted; and * if DANE is present AND if it fails to match, the message is not sent The way to do this seems to be with "smtp_tls_policy_maps". T

Re: passing mail through postfix/spamassassin system

2021-05-25 Thread Matthew Richardson
At Tue, 25 May 2021 12:56:15 -0400 (EDT), pnew...@toosan.com wrote:- >Good afternoon! > >I have set up a postfix/spamassassin (PF/SA) system that is handling mail for >three of my domains enroute to the system that end-users ultimately retrieve >mail from (rackspace). It is working but I had to