Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Gerben Wierda
My standard DNS forwards to cloud9 (9.9.9.9) because cloud9 blocks bad actors. But that means that DNSBL from spamhaus doesn’t work as the query to comes from a public DNS server. I am using: # Drop any SMTP client that talks before its turn (spam botnets in a hurry) postscreen_greet_action = d

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Wietse Venema
Gerben Wierda: > My standard DNS forwards to cloud9 (9.9.9.9) because cloud9 blocks bad > actors. But that means that DNSBL from spamhaus doesn?t work as the query to > comes from a public DNS server. > > I am using: > # Drop any SMTP client that talks before its turn (spam botnets in a hurry)

ETRN recorded in log but no mail moves

2021-10-21 Thread K.J. Petrie
I have a server which is on 24 hours/day and a desktop which is on when I'm using it. Both have postfix used for delivering mail. On server I have a virtual user "m...@mydomain.com" relayed to "me@mydesktop.localdomain". This works well once the desktop's been up a few hours. However, when I try

Re: ETRN recorded in log but no mail moves

2021-10-21 Thread Viktor Dukhovni
On Thu, Oct 21, 2021 at 07:15:19PM +0100, K.J. Petrie wrote: > I have a server which is on 24 hours/day and a desktop which is on when > I'm using it. Both have postfix used for delivering mail. For ETRN to be useful, the frequently unreachable domain has to be listed in $fast_flush_domains.

Windows Powershell and Postfix TLS authentication

2021-10-21 Thread Craig Huckabee
Hi, We’ve setup postfix on our RHEL7 SMTP servers with TLS fingerprint authentication for the SMTP submission process. It works great for our other Linux and OSX hosts. We’ve had requests for help making it work with Windows, specifically from Powershell. We tried connecting using the Po

Re: Windows Powershell and Postfix TLS authentication

2021-10-21 Thread Wietse Venema
/raig Huckabee: > Hi, > > We've setup postfix on our RHEL7 SMTP servers with TLS fingerprint > authentication for the SMTP submission process. It works great > for our other Linux and OSX hosts. > > We've had requests for help making it work with Windows, > specifically from Powershell.

Re: Windows Powershell and Postfix TLS authentication

2021-10-21 Thread Viktor Dukhovni
On Thu, Oct 21, 2021 at 04:34:23PM -0400, Craig Huckabee wrote: > We’ve had requests for help making it work with Windows, specifically > from Powershell. We tried connecting using the Powershell methods > described by Microsoft for SMTP TLS auth, but while debugging from the > Postfix side the c

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Simon Wilson
- Message from Wietse Venema - Date: Thu, 21 Oct 2021 08:35:20 -0400 (EDT) From: Wietse Venema Reply-To: Postfix users Subject: Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info? To: Postfix users Gerben Wierda: My standard DNS forwards to cloud9 (9

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Viktor Dukhovni
On Fri, Oct 22, 2021 at 08:38:40AM +1000, Simon Wilson wrote: > I have now setup Unbound as a caching name server on the Postfix > server so it can resolve *anything*, but with Unbound configured to > fwd to my local network BIND server for local domain addresses > (private-address, private-

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Gerben Wierda
> On 21 Oct 2021, at 14:35, Wietse Venema wrote: > > Gerben Wierda: >> My standard DNS forwards to cloud9 (9.9.9.9) because cloud9 blocks bad >> actors. But that means that DNSBL from spamhaus doesn?t work as the query to >> comes from a public DNS server. >> >> I am using: >> # Drop any SMT

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Wietse Venema
Gerben Wierda: > My standard DNS forwards to cloud9 (9.9.9.9) because cloud9 blocks > bad actors. But that means that DNSBL from spamhaus doesn?t work > as the query to comes from a public DNS server. Do not use a public resolver for a free Spamhaus service. They will rate-limit your queries. When

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Bob Proulx
Gerben Wierda wrote: > Actually, the whole question was based on a misunderstanding what was going > wrong. Glad to hear that you think the problem is resolved. > My standard DNS forwards to cloud9 (9.9.9.9) because cloud9 blocks > bad actors. But that means that DNSBL from spamhaus doesn?t work

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-21 Thread Gerben Wierda
On 22 Oct 2021, at 01:09, Gerben Wierda wrote: > >> >> On 21 Oct 2021, at 14:35, Wietse Venema > > wrote: >> >> Gerben Wierda: >>> My standard DNS forwards to cloud9 (9.9.9.9) because cloud9 blocks bad >>> actors. But that means that DNSBL from spamhaus doesn?t wor