Re: Problem with TLS and multiple emails over same connection

2016-12-15 Thread Stefan Moravcik
Thanks for the detailed replies. Yes we had the feeling that this task would be non trivial to put it mildly. We need to decide how we will proceed based on the this info. Again Thanks -- View this message in context: http://postfix.1071664.n5.nabble.com/Problem-with-TLS-and-multiple-emails-ove

Re: Recipient verification with sending IP equal to probe IP

2016-12-15 Thread Wietse Venema
Pedro David Marco: > Hi! > I am doing recipient address verification with reject_unverified _recipient > and it works pretty well, but i havenoticed that when the sending IP is the > same as the vrfy probing IP address, then this restriction is not applied. > does it make sense? > i have this

DNS round robin on helo?

2016-12-15 Thread L . P . H . van Belle
Hello,   I couldnt find this on the internet and is was thinking, the postfix list wil know this. Customer send email which are rejected by my server.  I thinks that is correctly rejected.   Now i digged into this and i found the following but i dont know if this is allowed by RFC. To

Re: DNS round robin on helo?

2016-12-15 Thread Noel Jones
On 12/15/2016 8:56 AM, L.P.H. van Belle wrote: > Hello, > > > > I couldnt find this on the internet and is was thinking, the postfix > list wil know this. > > Customer send email which are rejected by my server. I thinks that > is correctly rejected. > > > > Now i digged into this and i f

Re: DNS round robin on helo?

2016-12-15 Thread Jim Reid
> On 15 Dec 2016, at 14:56, L.P.H. van Belle wrote: > > Now the thing i dont get. > > 1) if both ipnumbers have a hostname, why do i see : unknown[1.2.3.4] Your starting assumption is wrong or mistaken. If the postfix logs are saying "unknown[1.2.3.4]” it means reverse lookups of tha

RE: DNS round robin on helo?

2016-12-15 Thread L . P . H . van Belle
Hello Noel/Jim,   Thank you for the replies.   Ok, thats clear, so multple A are allowed but i thing its the way around here. I'll explain bit more.   I did run also that way, one host multiple ip's but both ip's has a different helo name to match a/ptr and mx records with it. But this

Re: DNS round robin on helo?

2016-12-15 Thread Jim Reid
> On 15 Dec 2016, at 16:01, L.P.H. van Belle wrote: > > Hello Noel/Jim, > > Thank you for the replies. If you’re going to continue hiding the actual names and addresses, don’t bother posting followups. As far as I know, nobody on this list is a mind reader. How do you expect anyone to hel

Re: DNS round robin on helo?

2016-12-15 Thread Viktor Dukhovni
> On Dec 15, 2016, at 9:56 AM, L.P.H. van Belle wrote: > > I couldnt find this on the internet and is was thinking, the postfix list wil > know this. > Customer send email which are rejected by my server. I thinks that is > correctly rejected. > > Now i digged into this and i found the fo

Re: Recipient verification with sending IP equal to probe IP

2016-12-15 Thread Pedro David Marco
Thanks Wietse but the sending IP is not listed in $mytetworks...   ---Pedro. From: Wietse Venema To: Postfix users Sent: Thursday, December 15, 2016 1:15 PM Subject: Re: Recipient verification with sending IP equal to probe IP Pedro David Marco: > Hi! > I am doing recipient address

Re: Recipient verification with sending IP equal to probe IP

2016-12-15 Thread Wietse Venema
Pedro David Marco: > Thanks Wietse but the sending IP is not listed in $mytetworks... ? Given your smtpd_mumble_restrictions rule, permit_mynetworks allows a client to skip the reject_unverified_whatever check. Oh, and of course this check does not apply at all for mail that is received with the

Re: DNS round robin on helo?

2016-12-15 Thread Noel Jones
On 12/15/2016 10:01 AM, L.P.H. van Belle wrote: ... > I looks to me and incorrect implementation, what do you guys think. ... All this is allowed, legal, and unsurprising. Not everything that is allowed is wise. Ideally, each host (or each connection on a multi-homed host) should have its own uni

How to send outbound mail if port 25 outbound is blocked?

2016-12-15 Thread Ramon F Herrera
I am a longtime sendmail sysadmin who has seen the writing on the wall. I have been persuaded to learn Postfix. I have 2 rented servers: one running sendmail (for a while, works fine) and the other running Postfix (going through the learning curve)/./ My VPS provider (1and1.com) gives me the

Re: How to send outbound mail if port 25 outbound is blocked?

2016-12-15 Thread Viktor Dukhovni
On Thu, Dec 15, 2016 at 02:23:02PM -0600, Ramon F Herrera wrote: > I have 2 rented servers: one running sendmail (for a while, works fine) and > the other running Postfix (going through the learning curve)/./ Two servers, potentially two firewall policies. > My VPS provider (1and1.com) gives me

RE: DNS round robin on helo?

2016-12-15 Thread L . P . H . van Belle
Hai, First sorry to have the ips and name anonymized, i had to do that. I cant expose details until i first talked to the company in question. Thas a moral thing to do in my believe. And i need to be sure that i tell the right info when i do that. The "helo=" space was a copy past error, sorry

quick DANE question

2016-12-15 Thread Alice Wonder
When an SMTP server publishes a TLSA record, will DANE enforcing SMTP servers refuse to connect if the TLSA record matches the certificate but the certificate has expired?