Re: smtpd_end_of_data_restrictions check_policy_service called even after REJECT in header_checks

2015-11-08 Thread Robert Mueller
> I see that there are smtp_header_checks that must run during the smtp > sending phase, would it be worth adding smtpd_header_checks (with some > restrictions likes the smtp_* ones) that run in smtpd during the message > reading phase? Having a look at the code, this appears annoying. It appears

Re: smtpd_end_of_data_restrictions check_policy_service called even after REJECT in header_checks

2015-11-05 Thread Robert Mueller
> One might imagine cleanup sending a negative reply as soon as it > is available, and smtpd(8) peeking at the cleanup(8) socket before > calling end-of-data checks, which can short-circuit end-of-data > checks for mail rejected by header/body checks and content processing > in milters. However n

smtpd_end_of_data_restrictions check_policy_service called even after REJECT in header_checks

2015-11-05 Thread Robert Mueller
Hi We have a setup where we use a check_policy_service in smtpd_end_of_data_restrictions to track the rate users are receiving emails. Recently a user came under attack from someone using a distributed set of compromised websites. Fortunately it was fairly easy to find a header in the majority of