[pfx] Re: tlsproxy service role client is not available

2025-08-01 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > John Doe: > > Hi Wietse and Viktor, > > > > Replying in one email ... > > > > I'm attaching what You have required from me. and one more fail proof, with > > tlsproxy setting enabled in main.cf (lat time i h

[pfx] Re: tlsproxy service role client is not available

2025-08-01 Thread Wietse Venema via Postfix-users
John Doe: > Hi Wietse and Viktor, > > Replying in one email ... > > I'm attaching what You have required from me. and one more fail proof, with > tlsproxy setting enabled in main.cf (lat time i have forgotten to enable > them back- sorry) > > *I believe issue was fixed,* but it's a bit confusing

[pfx] Re: tlsproxy service role client is not available

2025-07-31 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > You wrote that the old rhel7 server runs Postfix 3.3.6. That version > did not implement smtp_tls_connection_reuse. It was introduced with > Postfix 3.4 and is still disabled by default. Is there a problem > that requires smtp_tls_connection_reuse sup

[pfx] Re: tlsproxy service role client is not available

2025-07-31 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > John Doe via Postfix-users: > > postfix/master[2399665]: warning: process > > /app/PFXpostfix/postfix/usr/libexec/postfix/tlsproxy pid 2399702 killed by > > signal 11 > > > > And it's deferring email to next hop :( > >

[pfx] Re: tlsproxy service role client is not available

2025-07-31 Thread Wietse Venema via Postfix-users
John Doe via Postfix-users: > postfix/master[2399665]: warning: process > /app/PFXpostfix/postfix/usr/libexec/postfix/tlsproxy pid 2399702 killed by > signal 11 > > And it's deferring email to next hop :( # postconf 'smtp_tls_connection_reuse = noS' # postfix reload This is an old problem, and I

[pfx] Re: postqueue output missing information

2025-07-29 Thread Wietse Venema via Postfix-users
Emmett Culley via Postfix-users: > We have a web app we use to find bad email addresses after a > newsletter goes out. We read the mail queue using postqueue -p, > the parse the output of that command to get a list of emails that > failed to successfully send. That will only give you *SOME* of th

[pfx] Re: Keep ESN requests through content_filter

2025-07-27 Thread Wietse Venema via Postfix-users
Sven Scholle via Postfix-users: > Hello, > > unfortunately, I have a legacy system that uses content_filter for > outgoing mail. It is a script called by pipe. > > Because of a current lack of time: Is there a quick way to keep the > request for ESNs (required by marketing)? Or is there another

[pfx] Re: TLS Reports Loop

2025-07-27 Thread Wietse Venema via Postfix-users
https://www.postfix.org/DEBUG_README.html#logging Postfix logs all failed and successful deliveries to a logfile. * When Postfix uses syslog logging (the default), the file is usually called /var/log/maillog, /var/log/mail, or something similar; the exact pathname is configured in a fil

[pfx] Re: Converting a queue file into other formats

2025-07-23 Thread Wietse Venema via Postfix-users
Dan Mahoney via Postfix-users: > Hey there folks. > > I've been debugging a faulty milter, which was crashing due to one particular > malformed message. While trying to figure out how to get it to core (and > replace it with a build with debug symbols), I changed postfix to change the > defaul

[pfx] Re: Centralized Address verification database

2025-07-22 Thread Wietse Venema via Postfix-users
Pedro David Marco via Postfix-users: > Hi everybody... > In theory, it's possible to centralize and share the Postfix > address verification database used by verify daemon across multiple > servers using memcache It should work assuming that there are no changes in te way that Postfix stores addre

[pfx] Re: Strange mailq errors

2025-07-22 Thread Wietse Venema via Postfix-users
Xavier Humbert via Postfix-users: > mailbox_command = /usr/local/libexec/dovecot/dovecot-lda -f "$SENDER" -a > "$RECIPIENT" This runs dovecot-lda with recipient privileges, and dovecot-lda is unable to deliver mail for user 'postfix' because of insufficient permissions for the UNIX_domain socket

[pfx] Re: Strange mailq errors

2025-07-22 Thread Wietse Venema via Postfix-users
Xavier Humbert via Postfix-users: > Hi, > > I recently experienced strange errors in mailq : > > [root@numenor ~]# mailq > -Queue ID- --Size-- Arrival Time -Sender/Recipient--- > 56BF31C93912320 Fri Jul 18 03:42:33 i...@quora.com > (temporary failure. Command output: lda(postfix

[pfx] Re: Recipients not showed in mailq after moving them to hold queue

2025-07-22 Thread Wietse Venema via Postfix-users
Pedro David Marco via Postfix-users: > > Hi, > > I'm using Postfix 3.7.11 and I've noticed that when a message is moved to the > HOLD queue, the mailq command does not display the recipient(s) of that > message. > > Additionally, even after releasing the message from HOLD to the deferred > qu

[pfx] Re: GhettoForge link on "Packages and Ports" page

2025-07-22 Thread Wietse Venema via Postfix-users
Peter via Postfix-users: > You put a quotation mark (") at the end of the link, making it invalid, > can you please fix that? There was a missing quote at the left of the URL. Wietse ___ Postfix-users mailing list -- postfix-users@postfix.org T

[pfx] Re: Routing based on number of recipients

2025-07-21 Thread Wietse Venema via Postfix-users
Emmanuel BILLOT via Postfix-users: > Hi, > > Is it possible to route messages on others servers based on numbers of > recipients ? > > Ex : > if number of recipient <10 then relayhost is A > if number of recipient >10 and <50 then relayhost is B > if number of recipient >50 then relayhost is C P

[pfx] Re: GhettoForge link on "Packages and Ports" page

2025-07-21 Thread Wietse Venema via Postfix-users
Peter via Postfix-users: > Can you please update the link for GhettoForge on the "Packages and > Ports" web page to the following? > http://www.ghettoforge.net/index.php/Postfix3 Done. Wietse ___ Postfix-users mailing list -- postfix-users@post

[pfx] Re: [pfx-dev] [PATCH] Prevent timestamp formatting overflow by replacing long with intmax_t

2025-07-17 Thread Wietse Venema via Postfix-users
Song, Jiaying (CN) via Postfix-devel: > From: Jiaying Song > > This patch replaces "%010ld" with "%019" PRIdMAX and casts time() to > intmax_t, to prevent formatting overflow on systems where long is 32-bit > but time_t is 64-bit. > > The previous formatting could truncate high-bit time values,

[pfx] Re: sending emails times out

2025-07-16 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > Sure. Very much so. As a matter i found even that shitty > Wikipedia quoting a good thing not too far ago (one in a thousand) Let's stop here, or risk being unsubscribed. Wietse ___ Postfix-users mailing l

[pfx] Re: sending emails times out

2025-07-15 Thread Wietse Venema via Postfix-users
Curtis Vaughan via Postfix-users: > delay=52012, delays=51997/0/15/0, dsn=4.4.2, status=deferred > (conversation with satcomdv.ru[83.222.5.141] timed out while receiving > the initial server greeting) Upon closer reading the time limit for the greeting is set with smtp_helo_timeout (default: 300

[pfx] Re: sending emails times out

2025-07-15 Thread Wietse Venema via Postfix-users
Curtis Vaughan via Postfix-users: > We've been postfix pretty much forever, but suddenly a new problem has > arisen, for which I haven't been able to find a solution. The postfix > server is located in the USA. A lot of mail goes to Russian addresses > and it is to those addresses that the issue

[pfx] Re: Make postfix additionally relay?

2025-07-15 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Mon, Jul 14, 2025 at 01:36:00PM -0400, Wietse Venema via Postfix-users > wrote: > > > > Looks very interesting. But unfortunately there's no regexp support > > > available. > > > And the installations of pos

[pfx] Re: Make postfix additionally relay?

2025-07-14 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Steffen Nurpmeso via Postfix-users: > > |Verified with > > | > > |postmap -q - > > 'pipemap:{regexp:rcpt-bcc.regexp,regexp:bcc-generic.regexp\ > > |}' > > | > > |for quoted and unquoted loca

[pfx] Re: Make postfix additionally relay?

2025-07-14 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > |Verified with > | > |postmap -q - 'pipemap:{regexp:rcpt-bcc.regexp,regexp:bcc-generic.regexp\ > |}' > | > |for quoted and unquoted localparts. > > And partially quoted? I have a bit of problems with ABNF, so Postfix transforms envelope addres

[pfx] Re: Make postfix additionally relay?

2025-07-14 Thread Wietse Venema via Postfix-users
oftl--- via Postfix-users: > On Mon, Jul 14, 2025 at 06:01:20PM +1000, Viktor Dukhovni via Postfix-users > wrote: > > On Sun, Jul 13, 2025 at 09:12:28PM +0200, oftl--- via Postfix-users wrote: > > > > > Have an already up and running postfix *also* relay everything to another > > > postfix. > >

[pfx] Re: include dir for config snippets?

2025-07-14 Thread Wietse Venema via Postfix-users
Matt Zagrabelny via Postfix-users: > Greetings Postfix-users, > > I've grepped the man page (man 5 postconf) and performed some searching on > the internet regarding the idea of an include directory for config snippets. > > For instance, openssh has: > > /etc/ssh/sshd_config.d/*.conf > > for ad

[pfx] Re: postfix-3.11-20250713 build failure

2025-07-14 Thread Wietse Venema via Postfix-users
Eray Aslan via Postfix-users: > Hi, > > postfix-3.11-20250713 build fails with > [...] > multi_server.c: In function ?multi_server_drain?: > event_server.c: In function ?event_server_drain?: > multi_server.c:300:9: error: ?return? with no value, in function returning > non-void [-Wreturn-mismatch

[pfx] Re: Small COMPATIBILITY_README.html typo

2025-07-13 Thread Wietse Venema via Postfix-users
Emmanuel Fust? via Postfix-users: > Hello, > > In the xxx_tls_level section: > Postfix version 3.11 changes the default value for client TLS security > levels from "empty" to "yes". > Should be if I am not mistaken: > Postfix version 3.11 changes the default value for client TLS security > levels

[pfx] Re: A couple questions

2025-07-13 Thread Wietse Venema via Postfix-users
James Lay via Postfix-users: > Is there a way to bypass spamassassin for local addresses? ?My > master.cf has: > > smtp inet n - - - - smtpd > -o content_filter=spamassassin To bypass spamassassin for messages from local clients, use a different 'smtp' service instance in master.cf for local and

[pfx] Postfix stable release 3.10.3

2025-07-10 Thread Wietse Venema via Postfix-users
[An on-line version of this announcement will be available at https://www.postfix.org/announcements/postfix-3.10.3.html] This release fixes defects that were introduced in Postfix 3.10. These were fixed first in the Postfix 3.11 unstable release. The defects exist only with the default configurat

[pfx] Re: Hardcoded "451 4.6.0" error code for Alias expansion error

2025-07-05 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > > but I can guess it would be quite complex change, so well... if there > > would ability to reply with 5xx error for detected expansion loop, I > > think moving alias map to the incoming MX MTA would be enough + > > setting transport map for a next hop of all e

[pfx] Re: Hardcoded "451 4.6.0" error code for Alias expansion error

2025-07-04 Thread Wietse Venema via Postfix-users
Dmytro Alieksieiev via Postfix-users: > Hi Wietse, > > > If you think that Postfix uses the wrong error type, > > then that is a request for a source code change. > It would be nice if there would be option to configure alias expansion > response codes like it have it in many other places that en

[pfx] Re: Hardcoded "451 4.6.0" error code for Alias expansion error

2025-07-04 Thread Wietse Venema via Postfix-users
Dmytro Alieksieiev via Postfix-users: > Hi Postfix community, > > Does anybody know the original reason of why there is no way to adjust > response code for Alias expansion error (internal loop detected) in > Postfix settings? This enhanced staus code codes was chosen 20 years ago based on erro

[pfx] Re: Postfix authentication with LDAP

2025-07-01 Thread Wietse Venema via Postfix-users
Burn Zero via Postfix-users: > Hi, > > I am trying to implement postfix authentication with LDAP (Active > Directory) where the postfix server will act as relay. The expected traffic > is huge (around 400K / day), so is it better to use LDAP as authentication > mode than MySQL? With 400k/day, you

[pfx] Re: sometimes install file is different with previous install when calling post-install in yocto bb

2025-06-30 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > The postconf command will not change the order of parameters that > already exist in main.cf. If a parameeter DOES NOT exist > in main.cf, then postconf appends one at the end of the file. > > If you copy the main.cf file immediately before

[pfx] Re: sometimes install file is different with previous install when calling post-install in yocto bb

2025-06-30 Thread Wietse Venema via Postfix-users
The postconf command will not change the order of parameters that already exist in main.cf. If a parameeter DOES NOT exist in main.cf, then postconf appends one at the end of the file. If you copy the main.cf file immediately before and immediately after the postfconf edit commands you will find t

[pfx] Re: SMTPUTF8 best practices

2025-06-29 Thread Wietse Venema via Postfix-users
H?kon Alstadheim via Postfix-users: > > Den 29.06.2025 15:40, skrev Dmytro Alieksieiev via Postfix-users: > > > > Hi Jorge, > > > > To have SMTPUTF8 enabled in system it should be supported by all > > components of mail system. > > > > If you have LMTP as f.e. Dovecot which not yet production rea

[pfx] Re: SMTPUTF8 best practices

2025-06-29 Thread Wietse Venema via Postfix-users
Dmytro Alieksieiev via Postfix-users: > off SMTPUTF8 due to issues in postfix-postres client that with disabled > SMTPUTF8 due to unclear reason start to speak with PostgresSQL in ASCII > encoding and at same time tried to pass LATIN1 payload (aka ??) which > leading to breaking DB connection fo

[pfx] Re: SMTPUTF8 best practices

2025-06-29 Thread Wietse Venema via Postfix-users
Jorge Bastos via Postfix-users: > Howdy, > > Sometimes i have users that write the emails wrong, and the email client > stops sending with the default message from postfix "555 5.5.4 > Unsupported option: SMTPUTF8". Those clients are buggy. A client can request SMTPUTF8 only if the server has a

[pfx] Re: MySQL access maps returns newline at the end

2025-06-25 Thread Wietse Venema via Postfix-users
JorgeBastos: >root@fastmail:~# postconf -f > smtpd_{client,helo,sender,recipient,relay,data,end_of_data}_restrictions > smtpd_client_restrictions = permit_mynetworks, check_client_access >mysql:/etc/postfix/mysql-client-ip-access.cf, permit_sasl_authenticated, >reject_unknown_rever

[pfx] Re: MySQL access maps returns newline at the end

2025-06-25 Thread Wietse Venema via Postfix-users
Wietse: > Good. Now, what is the complete 'reject' message from Postfix? > I am asking for Postfix output, not for your opinion. Jorge Bastos via Postfix-users: > Wietse, > > I sent you the outlook in the previous email, What you sent was this: No error, it just get's rejected by one of the

[pfx] Re: MySQL access maps returns newline at the end

2025-06-25 Thread Wietse Venema via Postfix-users
Good. Now, what is the complete 'reject' message from Postfix? I am asking for Postfix output, not for your opinion. Wietse ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.o

[pfx] Re: MySQL access maps returns newline at the end

2025-06-25 Thread Wietse Venema via Postfix-users
Jorge Bastos via Postfix-users: > Benny, > > I think my main issue is that PERMIT still continues evaluation and i'm > thinking that it stops when it doesn't. > So no way to have a PERMIT that stops evaluation right? only the > negative options stop evaluation the next ones? > > * > > DU

[pfx] Re: MySQL access maps returns newline at the end

2025-06-25 Thread Wietse Venema via Postfix-users
What is the complete error message? Wietse ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] Re: MySQL access maps returns newline at the end

2025-06-25 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Jorge Bastos via Postfix-users: > > root@fastmail:/etc/postfix# postmap -q 188.250.172.222 > > mysql:/etc/postfix/mysql-client-ip-access.cf | hexdump -C > > 50 45 52 4d 49 54 0a |PERMIT.| > > 0007 > > root@fastmail:/

[pfx] Re: Parallel dovecot-lda delivery

2025-06-25 Thread Wietse Venema via Postfix-users
Marek Podmaka via Postfix-users: > Hello, > > I am using dovecot-lda as delivery for virtual users, Since upgrading > from debian 10 (postfix 3.4.23, dovecot 2.3.16) to debian 11 (postfix > 3.5.25, dovecot 2.3.21), it seems postfix is using parallel delivery > of multiple emails to the same recipi

[pfx] Re: MySQL access maps returns newline at the end

2025-06-25 Thread Wietse Venema via Postfix-users
Jorge Bastos via Postfix-users: > root@fastmail:/etc/postfix# postmap -q 188.250.172.222 > mysql:/etc/postfix/mysql-client-ip-access.cf | hexdump -C > 50 45 52 4d 49 54 0a |PERMIT.| > 0007 > root@fastmail:/etc/postfix# That newline is not in your database. The *postmap* command appe

[pfx] Re: smtp_tls_security_level defaults question

2025-06-23 Thread Wietse Venema via Postfix-users
I'm simplifying the implementation. If built with TLS the SMTP client default is: smtp_tls_security_level = may With compatibility_level < 3.11, the Postfix SMTP client will log: postfix/smtp[...] using backwards-compatible default setting smtp_tls_security_level=(empty) This ma

[pfx] Re: smtpd_sasl_auth_enable=no and smtpd_sender_restrictions=reject_sender_login_mismatch

2025-06-22 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > One thing the OP said is perhaps a general misconception, that could, > FWIW, be written down a bit more explicitly, though unlikely to help > prevent misunderstandings, because unlikely to be read. Rather it > may be helpful after the fact, to help some see th

[pfx] Re: smtpd_sasl_auth_enable=no and smtpd_sender_restrictions=reject_sender_login_mismatch

2025-06-22 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Sun, Jun 22, 2025 at 01:02:44PM -0400, Wietse Venema via Postfix-users > wrote: > > > > What I am talking about is the comment about the meaning "when SASL is > > > enabled", as possibly applying to SASL being en

[pfx] Re: smtpd_sasl_auth_enable=no and smtpd_sender_restrictions=reject_sender_login_mismatch

2025-06-22 Thread Wietse Venema via Postfix-users
Matthew via Postfix-users: > Hi Viktor, > > I think it is more: > > 1. "reject_unauthenticated_sender_login_mismatch" implies to a > reasonable person that "unauthenticated senders" for our trusted domains > would be rejected (not logging in is a form of login mismatch). reject_unauthen

[pfx] Re: submission has no resolv.conf

2025-06-21 Thread Wietse Venema via Postfix-users
Setting up operating system files such as resolv.conf in a Postfix chroot jail is outside the scope of Postfix. You can ask your distro maintainer to make their multi-instance support more complete, or you can avoid the hassle and disable the chroot feature in master.cf. To see what services are

[pfx] Re: No DNS found

2025-06-20 Thread Wietse Venema via Postfix-users
Christian H. Kuhn via Postfix-users: > Dear Wietse, > > Am 20.06.2025 um 22:26 schrieb Wietse Venema via Postfix-users: > > Christian H. Kuhn via Postfix-users: > > I see only one inet_interfaces setting, and two differfent myhostname > > settings. The Postfix SMTP clie

[pfx] Re: No DNS found

2025-06-20 Thread Wietse Venema via Postfix-users
Christian H. Kuhn via Postfix-users: > 2025-06-20T21:30:02.124789+02:00 bywater postfix/smtp[668080]: > 121921E4995: to=, relay=none, delay=0.03, > delays=0.03/0/0/0, dsn=5.4.6, status=bounced (mail for qno.de loops back > to myself) I see only one inet_interfaces setting, and two differfent my

[pfx] Re: Postscreen STARTTLS bug?

2025-06-19 Thread Wietse Venema via Postfix-users
Nick Tait via Postfix-users: > The following command illustrates this: > > $ ( echo -en "EHLO foo.local\r\nSTARTTLS\r\n" ; sleep 0 ; echo -en "QUIT\r\n" > ) | nc mx.tait.net.nz 25 > > Note the "sleep 0" (which does nothing). For me, running the command > above terminates 50% of the time and han

[pfx] Re: Postscreen STARTTLS bug?

2025-06-19 Thread Wietse Venema via Postfix-users
Nick Tait via Postfix-users: > $ ( echo -en "EHLO foo.local\r\nSTARTTLS\r\n" ; sleep 0 ; echo -en "QUIT\r\n" > ) | nc mx.tait.net.nz 25 > > Note the "sleep 0" (which does nothing). For me, running the command > above terminates 50% of the time and hangs 50% of the time, but it all > depends on

[pfx] Re: header_checks syntax question

2025-06-18 Thread Wietse Venema via Postfix-users
Stephen Satchell via Postfix-users: > Is there any way to specify a rule that takes the AND of two different > tests? For example, "from:*paypal" and "subject:*invoice"? This is not documented, and therefore not implemented. > Or do I need to write a milter to perform more complex checks? > My

[pfx] Re: Postscreen STARTTLS bug?

2025-06-18 Thread Wietse Venema via Postfix-users
Nick Tait via Postfix-users: > On 18/06/2025 22:33, Nick Tait via Postfix-users wrote: > > Prior to making the configuration change, the response to the STARTTLS > > was "454 4.7.0 TLS not available due to local problem", and the SMTP > > session remained operational, meaning if the client then s

[pfx] Re: more SELinux denials - fifo_file

2025-06-18 Thread Wietse Venema via Postfix-users
lejeczek via Postfix-users: > hi guys. > All these SELinux denials were caused by an external tool > (part of the HA management actually & running on the same > box as postfix), a script which part is: > > ??? sendmail) > ??? sendmail -t -r "${email_sender}" <<__EOF__ > From: ${ema

[pfx] Re: more SELinux denials - fifo_file

2025-06-17 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > lejeczek via Postfix-users: > > -> $ postconf -Mf | egrep -i '(pickup|qmgr)' > > pickup unix n - n 60 1 pickup > > qmgr unix n - n 300 1 qmgr > > W

[pfx] Re: more SELinux denials - fifo_file

2025-06-17 Thread Wietse Venema via Postfix-users
lejeczek via Postfix-users: > -> $ postconf -Mf | egrep -i '(pickup|qmgr)' > pickup unix n - n 60 1 pickup > qmgr unix n - n 300 1 qmgr With a similar configuration on my Fedora system the postconf command makes no atttmpt to wri

[pfx] Re: more SELinux denials - fifo_file

2025-06-17 Thread Wietse Venema via Postfix-users
lejeczek via Postfix-users: > Hi guys. > > I have a seemingly healthy, working postfix yet logs are > full of denials, one specific denial, so I wonder if that is > perhaps some misconfiguration on my part, although again, > all seem to work. > Any/all thoughts are much appreciated. Thanks. Th

[pfx] Re: Closing smtpd idle connections

2025-06-11 Thread Wietse Venema via Postfix-users
Pedro David Marco via Postfix-users: > Hi everyone, > I'm running a Postfix server and have encountered an issue where some SMTP > clients (usually Amazon servers) keep their connections open even after > successfully sending a message. Over time, this behavior causes all available > smtpd conne

[pfx] Re: blacklistd issues

2025-06-09 Thread Wietse Venema via Postfix-users
On Jun 9, 2025, at 05:21, Wietse Venema via Postfix-users wrote: > blacklistd support is a *BSD feature. Doug Hardie: > Indeed it is just that. I dug into the port and found that > blacklistd support was an added patch. It only is called for > failed authentication, not for the

[pfx] Re: smtp_tls_security_level defaults question

2025-06-09 Thread Wietse Venema via Postfix-users
Viktor Dukhovni via Postfix-users: > On Sun, Jun 08, 2025 at 07:29:22PM +0200, Geert Hendrickx via Postfix-users > wrote: > > On Mon, Jun 09, 2025 at 00:42:20 +1000, Viktor Dukhovni via Postfix-users > > wrote: > > > On Sun, Jun 08, 2025 at 09:29:17AM -0400, Wiet

[pfx] Re: blacklistd issues

2025-06-09 Thread Wietse Venema via Postfix-users
blacklistd support is a *BSD feature. Wietse ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] Re: Just checking: smtputf8

2025-06-08 Thread Wietse Venema via Postfix-users
Phil Stracchino: > On 6/8/25 13:57, Wietse Venema wrote: > > Phil Stracchino via Postfix-users: > >> Just checking: > >> > >> I just updated from Postfix 3.9.1 to 3.10.2 and found (a) that the > >> smtputf8 directive now generates a warning, unexpected attribute > >> smtputf8 from local socket (exp

[pfx] Re: Just checking: smtputf8

2025-06-08 Thread Wietse Venema via Postfix-users
Phil Stracchino via Postfix-users: > Just checking: > > I just updated from Postfix 3.9.1 to 3.10.2 and found (a) that the > smtputf8 directive now generates a warning, unexpected attribute > smtputf8 from local socket (expecting: sendopts), and (b) that it's no > longer present in the sample m

[pfx] Re: smtp_tls_security_level defaults question

2025-06-08 Thread Wietse Venema via Postfix-users
Geert Hendrickx via Postfix-users: > On Sat, Jun 07, 2025 at 18:51:21 -0400, Wietse Venema via Postfix-users wrote: > > > > For the Postfix SMTP client the new default would look like: > > > > > > > > smtp_tls_security_level = > > >

[pfx] Re: smtp_tls_security_level defaults question

2025-06-07 Thread Wietse Venema via Postfix-users
Geert Hendrickx via Postfix-users: > On Thu, Oct 24, 2024 at 11:33:22 -0400, Wietse Venema via Postfix-users wrote: > > The compatibility-level guard is a good idea. To take out some of the > > guesswork, I'm considering to add a read-only configuration parameter > > that

[pfx] Re: Postfix interaction between access map, .forward and aliases

2025-06-05 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Paul Raines via Postfix-users: > > > > I moved from an old sendmail based mail server to a new Postfix one > > recently. On the old system when a user account was closed I would put an > > entry in a access map for sendmail like &g

[pfx] Re: Postfix interaction between access map, .forward and aliases

2025-06-05 Thread Wietse Venema via Postfix-users
Paul Raines via Postfix-users: > > I moved from an old sendmail based mail server to a new Postfix one > recently. On the old system when a user account was closed I would put an > entry in a access map for sendmail like > > To:olduser@ERROR:"505 Disabled user account" > > and this would w

[pfx] Re: MTA-STS / DANE - postfix-tlspol

2025-06-05 Thread Wietse Venema via Postfix-users
Luca vom Bruch via Postfix-users: > The log message when using postfix-tlspol > Evaluated policy for "learndmarc.com": dane-only (from cache, 15m2s > remaining) postfix-tlspol says that TLSA records must be used. And I can confirm that they exist. Command: > And mail log: > to=, relay=none, delay

[pfx] Re: TLSRPT support

2025-06-02 Thread Wietse Venema via Postfix-users
Luca vom Bruch via Postfix-users: > Hi, > > I wanted to implement TLSRPT and added the Ghettoforge repo to Alma9 to get > the latest 3.10.x release of Postfix, but now I found out that TLSRPT > support is not compiled in the RPM > > Will it ever find its way into a regular .rpm? You need to fil

[pfx] Re: Understanding postfix/cleanup message in logs

2025-05-30 Thread Wietse Venema via Postfix-users
BuzzSaw Code via Postfix-users: > I've read the Postfix documentation trying to understand what the logs > are telling me, but this may still be a dumb question, so apologies in > advance. > > Another mail server within our own organization sends periodic > messages to us, and in the logs for tho

[pfx] Re: Pflogsumm: Postscreen Logging Questions And Request For Log Samples

2025-05-30 Thread Wietse Venema via Postfix-users
Jim Seymour via Postfix-users: > Secondly: Does the occurrence of any of them, following a CONNECT > message, imply the connection has been dropped by postscreen? No. You know that postscreen drops a conenction (i.e. does not pass it to an smtpd process) when it logs: HANGUP from clientaddr

[pfx] Re: Oder of submission client

2025-05-30 Thread Wietse Venema via Postfix-users
Laura Steynes via Postfix-users: > if I telnet mailserver 587 with milter-regex in debug mode from localhost, > I see the connection, however, when running from internet,I > don't,milter-regex is ignored and it hits the rbls where it should have > been caught, have I got something out of order her

[pfx] Re: Oder of submission client

2025-05-30 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Laura Steynes via Postfix-users: > > Hi Wietse, > > Thanks, as I suspect, it is doing the >>> START Client host RESTRICTIONS > > <<< > > generic_checks: name=reject_rbl_client, etc etc and then calling > >

[pfx] Re: using fallback_transport for user migration

2025-05-30 Thread Wietse Venema via Postfix-users
XLn4zwqzKsZS: > >> to=, relay=local, delay=0.16, delays=0.06/0.01/0/0.09, > >> dsn=5.1.1, status=bounced (unknown user: "test") > > On 29.05.25 14:40, Wietse Venema via Postfix-users wrote: > >fallback_transport_maps is searched with the local part not localp

[pfx] Re: Oder of submission client

2025-05-30 Thread Wietse Venema via Postfix-users
Laura Steynes via Postfix-users: > Hi Wietse, > Thanks, as I suspect, it is doing the >>> START Client host RESTRICTIONS > <<< > generic_checks: name=reject_rbl_client, etc etc and then calling > milter8_connect: transport=unix endpoint=/var/run/milter/milter-regex.sock > > I swapped this debug

[pfx] Re: using fallback_transport for user migration

2025-05-29 Thread Wietse Venema via Postfix-users
Matus UHLAR - fantomas via Postfix-users: > Hello, > > out customer reported that they started migrating users to 365 services > (yeah, after they started). > > Of course, this means that they are unable to send mail from local system to > addresses in local domain that are created in 365. > >

[pfx] Re: Postfix denies regular mail

2025-05-29 Thread Wietse Venema via Postfix-users
Christian H. Kuhn via Postfix-users: > Dear Wietse, > > thank you for your answer. > > Am 28.05.2025 um 21:57 schrieb Wietse Venema via Postfix-users: > > (There should be warnings logged that saywhich table lookup failed. > > Does your system perhaps log erro

[pfx] Re: Postfix denies regular mail

2025-05-28 Thread Wietse Venema via Postfix-users
Christian H. Kuhn via Postfix-users: > from mailout1-87.xing.com[109.233.158.87] > 2025-05-28T19:05:24.783884+02:00 bywater postfix/smtpd[1610483]: > NOQUEUE: reject: RCPT from mailout1-87.xing.com[109.233 > .158.87]: 451 4.3.0 : Temporary lookup failure; > from= to= proto > =ESMTP helo= (There

[pfx] Re: Sender rewrite for Azure SMTP

2025-05-22 Thread Wietse Venema via Postfix-users
Matthew Kitchin via Postfix-users: > On 5/22/2025 3:33 PM, Wietse Venema via Postfix-users wrote: > > To be precise, Postfix delivers the message with the 'good' display > > name in the From: header. The unexpected change happens after Postfix > > has delivered t

[pfx] Re: Sender rewrite for Azure SMTP

2025-05-22 Thread Wietse Venema via Postfix-users
Matthew Kitchin via Postfix-users: > On 5/22/2025 2:34 PM, Wietse Venema via Postfix-users wrote: > >> > > Postfix receives the message with > > > > From: John Doe > > > >> May 22 16:58:23 vm-prod-netbox postfix/qmgr[265519]: 6A63814A356

[pfx] Re: Sender rewrite for Azure SMTP

2025-05-22 Thread Wietse Venema via Postfix-users
Matthew Kitchin via Postfix-users: > On Thu, May 22, 2025 at 11:55?AM Wietse Venema via Postfix-users > wrote: > > > What is the "Case 2" Postfix From: logging? > > > > - The logging from the cleanup proccess shows the From: display > >name as re

[pfx] Re: Sender rewrite for Azure SMTP

2025-05-22 Thread Wietse Venema via Postfix-users
Matthew Kitchin: > On Thu, May 22, 2025 at 10:46?AM Wietse Venema wrote: > > > > How can I help? The purpose of my request is to find out if the > > unexpected display name change happens before Postfix receives the > > message, while Postfix processes the message, or after Postfix > > delivers th

[pfx] Re: Sender rewrite for Azure SMTP

2025-05-21 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Matthew Kitchin via Postfix-users: > > Hey all, former longtime user, but been away from Postfix for about 13 > > years. > > I'm migrating a datacenter to Azure. We have a variety of things > > (websites, copiers, monitoring a

[pfx] Re: Sender rewrite for Azure SMTP

2025-05-21 Thread Wietse Venema via Postfix-users
Matthew Kitchin via Postfix-users: > Hey all, former longtime user, but been away from Postfix for about 13 years. > I'm migrating a datacenter to Azure. We have a variety of things > (websites, copiers, monitoring apps, etc.) that send emails that don't > need to be replied to. In an Azure environ

[pfx] Re: Questions on a couple of log entries

2025-05-20 Thread Wietse Venema via Postfix-users
Dan Mahoney via Postfix-users: > Hey folks, > > We're in the process of trolling all our logs to figure out what we can > ignore/filter/take action on, and we have a couple entries that I'm wondering > what's happening under the hood: > > 2025-05-18T15:42:07+00:00 post.dayjob.org postfix/smtpd

[pfx] Re: action=DUNNO with two \n\n gives a server configuration error

2025-05-17 Thread Wietse Venema via Postfix-users
Jorge Bastos via Postfix-users: > Hi thanks, > > even with: > > echo -e "action=DUNNO\n" > > it fails with the same reason Postfix logging? See: https://www.postfix.org/DEBUG_README.html#logging DO NOT turn on debug logging with '-v' options in master.cf. What happens when you replace th

[pfx] Re: action=DUNNO with two \n\n gives a server configuration error

2025-05-17 Thread Wietse Venema via Postfix-users
Jorge Bastos via Postfix-users: > Hi Guys, > > I'm having an issue with my: > > check_policy_service unix:private/policy-dnswl > > That has the information bellow, I've been looking at the docs for two > weeks and cant figure why action=DUNNO still gives me the server > configuration error. >

[pfx] Re: Issues with authenticating after attempting mail

2025-05-15 Thread Wietse Venema via Postfix-users
Bill Cole via Postfix-users: > On 2025-05-15 at 14:53:47 UTC-0400 (Thu, 15 May 2025 19:53:47 +0100) > Maya Copeland via Postfix-users > is rumored to have said: > > > I'd have thought it'd at least try, similar to how it does in when > > using my > > sendmail host. My configuration remained the

[pfx] Re: Issues with authenticating after attempting mail

2025-05-15 Thread Wietse Venema via Postfix-users
Maya Copeland via Postfix-users: > IMAP DEBUG 14:17:19 5/15: 220 hostname ESMTP Postfix > IMAP DEBUG 14:17:19 5/15: EHLO desktop > IMAP DEBUG 14:17:19 5/15: 250-hostname > IMAP DEBUG 14:17:19 5/15: 250-PIPELINING > IMAP DEBUG 14:17:19 5/15: 250-SIZE 25000 > IMAP DEBUG 14:17:19 5/15: 250-VRFY >

[pfx] Re: Incoming OpenDKIM signature verification failing

2025-05-13 Thread Wietse Venema via Postfix-users
be achieved by using separate postfix instance for submitted > > > > mail > > > > - I don't see possibility of configuring separate cleanup instance for > > > > smtpd > > > > On 10.05.25 15:29, Wietse Venema via Postfix-users wrote: > >

[pfx] Re: Incoming OpenDKIM signature verification failing

2025-05-10 Thread Wietse Venema via Postfix-users
Matus UHLAR - fantomas via Postfix-users: > On 10.05.25 13:32, Ken Biggs via Postfix-users wrote: > > So continuing the saga ... digging into /etc/postfix/header_checks I found > > a revision I made back in January to try to keep our outgoing email from > > having headers with the IP address of

[pfx] Re: How does Postfix send data to the milter?

2025-05-06 Thread Wietse Venema via Postfix-users
Steffen Nurpmeso via Postfix-users: > Claus Assmann via Postfix-users wrote in > <20250506184424.ga35...@veps.esmtp.org>: > |On Tue, May 06, 2025, Bill Cole via Postfix-users wrote: > | > |> Sadly, there has never been robust definitive docs for the Milter API. > | > |What is missing from the

[pfx] Re: [pxf] How Postfix send data to the milter?

2025-05-06 Thread Wietse Venema via Postfix-users
The sequence is decsribed in an ancient sendmai document. for example, https://fossies.org/linux/sendmail/libmilter/docs/overview.html I added one comment about the effects of message modifications. For each of N connections { For each filter negotiate MTA/milter capabilit

[pfx] Re: warning: table lmdb key malformed value

2025-05-06 Thread Wietse Venema via Postfix-users
lejeczek via Postfix-users: > May 06 12:31:20 brama.mine.priv > postfix/submission/smtpd[80067]: warning: table > lmdb:/etc/postfix/snis.map: key mail.kupa.xyz: malformed > BASE64 value: /etc/letsencrypt/live/mail.lem You need to follow the instructions (use "postnap -F") for populating the SNI

[pfx] Re: Postfix 3.7.x do not send message Delivery Status Notification of relayed email

2025-05-05 Thread Wietse Venema via Postfix-users
Josef Karliak: >Good afternoon, > >thanks for the answer. > >smtp1 and smtp2 are the servers in the same subnet (demil zone, > perimeter). Client is from local network > >In the mail log of smtp2 is only difference (except different client > IP) that the DSN is generated. > >

[pfx] Re: Postfix 3.7.x do not send message Delivery Status Notification of relayed email

2025-05-05 Thread Wietse Venema via Postfix-users
Matus UHLAR - fantomas via Postfix-users: > >Josef Karliak via Postfix-users: > >>what could cause that Postfix do not send DSN of the mail that is > >> recieved over another server ? > > On 05.05.25 08:16, Wietse Venema via Postfix-users wrote: > >1) As sp

  1   2   3   4   5   6   7   8   9   10   >