[pfx] Re: Reduce rbldns use? postscreen_dnsbl_sites

2025-01-24 Thread Wietse Venema via Postfix-users
Nothing in Postfix prevents you from developing stateful policies where repated 'good' clients become longer-term allowlisted, and repated 'bad' clients become longer-term denylisted, for some subjective definitions of 'good', 'bad', 'long' and 'short'. In the case of botnet spam, this will make li

[pfx] Re: Interpreted configuration value

2025-01-24 Thread Matus UHLAR - fantomas via Postfix-users
On 24.01.25 11:13, Narcis Garcia via Postfix-users wrote: When I ask a configuration value with command: $ postconf -h ParameterName I get raw value from text file /etc/postfix/main.cf Is there some way to get effective value with variables already replaced? Example of behaviour I find: $ postc

[pfx] Re: Reduce rbldns use? postscreen_dnsbl_sites

2025-01-24 Thread Tomasz Pala via Postfix-users
On 2025-01-24 16:35, Wietse Venema via Postfix-users wrote: > > This perceived problem is already optimized away with caching. On > my system 93% of connections are from repeat clients. $ journalctl -t postfix/postscreen | grep -i ']: CONNECT from' | cut -f4 -d':' | wc -l 13973 $ journalctl -t p

[pfx] OpenDMARC question

2025-01-24 Thread Andreas Kuhlen via Postfix-users
Hi, dear list members! I don't know if I'm asking in the right place, but since opendmarc is configured as a milter in Postfix, I'll just ask it. Today I received a mail that did not have a dmarc signature. 2025-01-24T21:52:15.374433+01:00 crosis opendkim[1183]: C01D06003F: m6.so-net.net.tw

[pfx] Re: OpenDMARC question

2025-01-24 Thread Bill Cole via Postfix-users
On 2025-01-24 at 16:56:40 UTC-0500 (Fri, 24 Jan 2025 22:56:40 +0100) Andreas Kuhlen via Postfix-users is rumored to have said: Hi, dear list members! I don't know if I'm asking in the right place, but since opendmarc is configured as a milter in Postfix, I'll just ask it. Today I received a

[pfx] Re: Incorrect CN Being Reported When Using Postfix With MariaDB

2025-01-24 Thread duluxoz via Postfix-users
Thanks Victor, As I said, I didn't know if it was a Postfix, TLS Cert, or MariaDB issue. I'll post over in the MariaDB lists. On 24/1/25 18:24, Viktor Dukhovni via Postfix-users wrote: On Fri, Jan 24, 2025 at 03:30:43PM +1100, duluxoz via Postfix-users wrote: I'm using a MariaDB backend to

[pfx] Re: Reduce rbldns use? postscreen_dnsbl_sites

2025-01-24 Thread Wietse Venema via Postfix-users
MRob via Postfix-users: > On 2025-01-23 20:25, Randy Bush via Postfix-users wrote: > >> I'm using zen.spamhaus.org for blocking and list.dnswl.org (with > >> filter) > >> for allowlisting. > >> > >> zen.spamhaus.org*2 list.dnswl.org=127.0.[0..255].[1..3]*-2 > > > > Question occur to me, is

[pfx] Re: OpenDMARC question

2025-01-24 Thread Andreas Kuhlen via Postfix-users
Hi Geert, thanks for your reply! Am 25.01.2025 um 00:17 schrieb Geert Hendrickx via Postfix-users: On Fri, Jan 24, 2025 at 22:56:40 +0100, Andreas Kuhlen via Postfix-users wrote: I have set ‘RejectFailures true’ in /etc/opendmarc.conf. My expectation was that mails without a dmarc signature wou

[pfx] Re: OpenDMARC question

2025-01-24 Thread Andreas Kuhlen via Postfix-users
Many thanks for your reply, Bill. Am 24.01.2025 um 23:41 schrieb Bill Cole via Postfix-users: On 2025-01-24 at 16:56:40 UTC-0500 (Fri, 24 Jan 2025 22:56:40 +0100) Andreas Kuhlen via Postfix-users is rumored to have said: Hi, dear list members! I don't know if I'm asking in the right place, b

[pfx] Interpreted configuration value

2025-01-24 Thread Narcis Garcia via Postfix-users
Hello, When I ask a configuration value with command: $ postconf -h ParameterName I get raw value from text file /etc/postfix/main.cf Is there some way to get effective value with variables already replaced? Example of behaviour I find: $ postconf -h tls_server_sni_maps ${indexed}sni $ postconf

[pfx] Re: Reduce rbldns use? postscreen_dnsbl_sites

2025-01-24 Thread MRob via Postfix-users
On 2025-01-23 20:25, Randy Bush via Postfix-users wrote: I'm using zen.spamhaus.org for blocking and list.dnswl.org (with filter) for allowlisting. zen.spamhaus.org*2 list.dnswl.org=127.0.[0..255].[1..3]*-2 Question occur to me, is there way to cease dnsrbl lookups once threshold is me

[pfx] Re: Reduce rbldns use? postscreen_dnsbl_sites

2025-01-24 Thread Tomasz Pala via Postfix-users
On 2025-01-24 11:04, MRob via Postfix-users wrote: > > Question occur to me, is there way to cease dnsrbl lookups once > threshold is met? I think answer is "no" because Postscreen canot guess > if there will be whitelist next. > > Could be nice if there's trick to do: > * keep whitelist/blackl

[pfx] Re: OpenDMARC question

2025-01-24 Thread Geert Hendrickx via Postfix-users
On Fri, Jan 24, 2025 at 22:56:40 +0100, Andreas Kuhlen via Postfix-users wrote: > I have set ‘RejectFailures true’ in /etc/opendmarc.conf. My expectation > was that mails without a dmarc signature would then be rejected. Only if the domain publishes a DMARC p=reject policy. > 2025-01-24T21:52:1