Re: R: R: smtpd_recipient_restrictions in error

2015-12-23 Thread Viktor Dukhovni
On Wed, Dec 23, 2015 at 07:54:22AM +, Nicola Piazzi wrote: > At now my "smtpd_recipient_restrictions" is configured to use sqlgrey and > is working : smtpd_recipient_restrictions = permit_sasl_authenticated, > permit_mynetworks, reject_unauth_destination, reject_non_fqdn_recipient, > reject_u

R: R: R: smtpd_recipient_restrictions in error

2015-12-23 Thread Nicola Piazzi
Do you mean that i must give logging of the problem ? I don't undestrand if you say that there is a solution and I have done some error in typing Nicola Piazzi CED - Sistemi COMET s.p.a. Via Michelino, 105 - 40127 Bologna - Italia Tel.  +39 051.6079.293 Cell. +39 328.21.73.470 Web: www.gruppocom

How to Block EHLO/HELO that has IP Only

2015-12-23 Thread L. D. James
I have many log entries where there are "helo=[1.2.3.4]" entries with no domain name. It has an IP address only. Each of these occasions are unwanted spam messages. Can some one specify a policy restriction that will block these messages. An example from the log is: Dec 22 16:00:52 hera5 po

Re: Example of postfix's pcre \A \z /A false positive

2015-12-23 Thread sb
Re: body_checks(5) > The input string for body_checks is a single message body line. > so "\A" == "^" and "\z" == "$". Both /m and /A are compliant with postfix's pcre_table(5). Therefore, \A and \z *must not* fall back to ^ and $ when using /Am. Postfix's adaptation of pcre leads to false posi

Re: R: R: R: smtpd_recipient_restrictions in error

2015-12-23 Thread wilfried.es...@essignetz.de
Am 23.12.2015 um 09:13 schrieb Nicola Piazzi: > Do you mean that i must give logging of the problem ? I think so. > I don't undestrand if you say that there is a solution and I have done some > error in typing You corrected your misspelling. But now there seems to be another error. Additionally

Deny attachement extension directly in postfix ?

2015-12-23 Thread Olivier CALVANO
Hi it's possible to deny a attachment extension directly into postfix ? and create a database : domaine1.com .exe;.bat;.cab domaine2.com .exe ? thanks for your help Olivier

Re: Deny attachement extension directly in postfix ?

2015-12-23 Thread Nicolás
El 23/12/15 a las 13:29, Olivier CALVANO escribió: Hi it's possible to deny a attachment extension directly into postfix ? and create a database : domaine1.com .exe;.bat;.cab domaine2.com .exe ? thanks for your help Olivier Yes, but to do it pe

R: R: R: R: smtpd_recipient_restrictions in error

2015-12-23 Thread Nicola Piazzi
Error was the word reject_unverified_recipients instead of reject_unverified_recipient Sorry Nicola Piazzi CED - Sistemi COMET s.p.a. Via Michelino, 105 - 40127 Bologna - Italia Tel.  +39 051.6079.293 Cell. +39 328.21.73.470 Web: www.gruppocomet.it -Messaggio originale- Da: owner-p

AW: How to Block EHLO/HELO that has IP Only

2015-12-23 Thread Uwe Drießen
smtpd_helo_required = yes smtpd_recipient_restrictions = .. reject_invalid_helo_hostname Mit freundlichen Grüßen Uwe Drießen -- Software & Computer Netzwerke, Server. Wir vernetzen Sie und Ihre Rechner ! Uwe Drießen Lembergstraße 33 67824 Feilbingert Te

Re: How to Block EHLO/HELO that has IP Only

2015-12-23 Thread Nicolás
El 23/12/15 a las 08:38, L. D. James escribió: I have many log entries where there are "helo=[1.2.3.4]" entries with no domain name. It has an IP address only. Each of these occasions are unwanted spam messages. Can some one specify a policy restriction that will block these messages. An e

RE: How to Block EHLO/HELO that has IP Only

2015-12-23 Thread L . P . H . van Belle
This is how i run it. ( postfix 2.11.x on debian Jessie ) This stops a lot of "spamming" servers, and if anyone sees improvements,... im all ear... ;-) This was a drop op about 90% of all spam, remaining used "good" configured servers.. :-/ but for that spamassassin.. unknown_hostname_r

Re: Deny attachement extension directly in postfix ?

2015-12-23 Thread Noel Jones
On 12/23/2015 7:29 AM, Olivier CALVANO wrote: > Hi > > it's possible to deny a attachment extension directly into postfix ? You can block attachment extensions using either header_checks or mime_header_checks. There's a nice working example at the end of the header_checks man page (the example a

Bounces and dmarc reports

2015-12-23 Thread Alex
Hi, I've recently implemented dmarc on my system. I've implemented both rua and ruf reports. I'm trying to understand why my postfix queue is being inundated with undeliverable messages such as these: E45A5182C7E 2700 Wed Dec 23 11:11:52 postmas...@cheatcodes.com (connect to mulish.yachtspec

Re: check_sender_access and pattern matching

2015-12-23 Thread Bill Cole
On 21 Dec 2015, at 12:38, Alex wrote: Perhaps the ordering of restrictions is not correct? smtpd_client_restrictions = permit_mynetworks, check_client_access hash:/etc/postfix/client_checks, check_reverse_client_hostname_access pcre:/etc/postfix/fqrdns-042715a.pcre, check_reverse_client_ho

Re: How to Block EHLO/HELO that has IP Only

2015-12-23 Thread L. D. James
On 12/23/2015 10:10 AM, Nicolás wrote: El 23/12/15 a las 08:38, L. D. James escribió: I have many log entries where there are "helo=[1.2.3.4]" entries with no domain name. It has an IP address only. Each of these occasions are unwanted spam messages. Can some one specify a policy restricti

Re: check_sender_access and pattern matching

2015-12-23 Thread Alex
Hi, On Wed, Dec 23, 2015 at 12:53 PM, Bill Cole wrote: > On 21 Dec 2015, at 12:38, Alex wrote: > >> Perhaps the ordering of restrictions is not correct? >> >> smtpd_client_restrictions = permit_mynetworks, >> check_client_access hash:/etc/postfix/client_checks, >> check_reverse_client_hostname_

Re: Blank EHLO/HELO commands

2015-12-23 Thread Bill Cole
On 21 Dec 2015, at 17:54, Wolfe, Robert wrote: Hi all. This is not a postfix-specific question, but rather a generic one, but I hope I can get the answer I am searching for here. I run a third part SMTP filtering program in which I have "EHLO/HELO Must Resolve" turned on. I am amazed at th

Re: check_sender_access and pattern matching

2015-12-23 Thread Bill Cole
On 23 Dec 2015, at 13:53, Alex wrote: [...] Okay, I understand. So if the list wasn't also included in smtpd_sender_restrictions, would it have been rejected there, due to the reject_unknown_sender_domain at the end? Yes. How can I get around the duplication? If you don't duplicate reject

Re: Example of postfix's pcre \A \z /A false positive

2015-12-23 Thread Bill Cole
On 23 Dec 2015, at 5:26, sb wrote: Re: body_checks(5) > The input string for body_checks is a single message body line. > so "\A" == "^" and "\z" == "$". Both /m and /A are compliant with postfix's pcre_table(5). Therefore, \A and \z *must not* fall back to ^ and $ when using /Am. That appar

Re: Example of postfix's pcre \A \z /A false positive

2015-12-23 Thread Viktor Dukhovni
On Wed, Dec 23, 2015 at 05:29:12PM -0500, Bill Cole wrote: > The /m modifier may in fact never be useful in a Postfix pcre maps and I'm > not sure how one would test for whether it is actually functional. I cannot > think of any circumstance where Postfix might want to pass pcre a truly > multilin

Re: Example of postfix's pcre \A \z /A false positive

2015-12-23 Thread Bill Cole
On 23 Dec 2015, at 18:05, Viktor Dukhovni wrote: On Wed, Dec 23, 2015 at 05:29:12PM -0500, Bill Cole wrote: The /m modifier may in fact never be useful in a Postfix pcre maps and I'm not sure how one would test for whether it is actually functional. I cannot think of any circumstance where Po