Postfix still sending bounces

2013-11-04 Thread Ian Evans
Migrating to a new server and decided I would switch to postfix. On my old qmail server, I used validrcptto to drop emails not destines for the virtual accts on our site. I've read tutorials and the backscatter/local recipient pages and my postfix is still sending out bounce message instead of jus

Re: Postfix still sending bounces

2013-11-04 Thread Ian Evans
Argh...gmail and mailing lists. Sent this response directly to Benny instead of the list, so here I go again: Ian Evans skrev den 2013-11-05 00:03: > > Here's my main.cf [1]. Please let me know if there's more info you >> need. >> > > first question from me is

Squirrelmail secure smtp setup and php mail best practices

2013-11-05 Thread Ian Evans
As I'm migrating my site to a new server, my postfix/dovecot setup is currently on the new server, while nginx (and squirrelmail) is on the old. Since I can't use localhost:25 for smtp in Squirrel (since it's on another server) I need to make sure I have postfix and SM correctly configured for sec

Re: Squirrelmail secure smtp setup and php mail best practices

2013-11-05 Thread Ian Evans
On Wed, Nov 6, 2013 at 2:38 AM, LuKreme wrote: > > On 05 Nov 2013, at 17:42 , Ian Evans wrote: > > [snip] > It’s really straight forward, just set SM up to use auth. Updating > Squirrelmail is pretty painless. > > Thanks for the info. Got it set up. You probably do not

Handling repeated lost connections (I assume from zombie/spammer)

2013-11-06 Thread Ian Evans
About three days into my postfix/postgrey experience after migrating from qmail. Enjoying it. Of course, like a new dad, I'm sitting here watching the logs. For the last two hours I've been getting "postfix/smtpd: lost connection after RSET from unknown[x.x.x.x]" from the same IP, apparently in Ic

Config tools?

2014-01-17 Thread Ian Evans
Just curious if there are any config tools or analyzers that are able to parse the config files/logs and make suggestions for tweaks or point out holes, etc. Just thinking of a tool like the ones mysql has. After yrs as a qmail user, I'm not 100% confident everything is in a "best practices" state

Re: Config tools?

2014-01-18 Thread Ian Evans
On Sat, Jan 18, 2014 at 3:07 AM, Patrick Ben Koetter wrote: > * Ian Evans : > > Just curious if there are any config tools or analyzers that are able to > > parse the config files/logs and make suggestions for tweaks or point out > > holes, etc. Just thinking of a tool li

Re: Asking about heartbleed

2014-04-09 Thread Ian Evans
On Wed, Apr 9, 2014 at 7:01 PM, Viktor Dukhovni wrote: > > - Upgrade to 1.0.1g ASAP if running 1.0.1--1.0.1f, and/or re-compile > OpenSSL with -DOPENSSL_NO_HEARTBEATS > > - Replace server TLS private keys and certificates. > > - Consider asking users to change SASL PLAIN/LOGIN auth passw

Re: Asking about heartbleed

2014-04-09 Thread Ian Evans
On Wed, Apr 9, 2014 at 7:26 PM, Viktor Dukhovni wrote: > On Wed, Apr 09, 2014 at 07:05:50PM -0400, Ian Evans wrote: > > > Thanks for this. Since many touch their email servers far less than their > > postfix configs, is there a list of files we absolutely have to check for >

nobody@localhost: Sender address rejected: need fully-qualified address

2014-05-15 Thread Ian Evans
Noticed a few of these in my logs: May 15 23:22:51 carson postfix/smtpd[6768]: NOQUEUE: reject: RCPT from localhost[127.0.0.1]: 504 5.5.2 : Sender address rejected: need fully-qualified address; from= to= proto=ESMTP helo= I'm assuming this is some daemon or something trying to send some report/n

Re: nobody@localhost: Sender address rejected: need fully-qualified address

2014-05-15 Thread Ian Evans
On Thu, May 15, 2014 at 11:32 PM, Ian Evans wrote: > Noticed a few of these in my logs: > > May 15 23:22:51 carson postfix/smtpd[6768]: NOQUEUE: reject: RCPT from > localhost[127.0.0.1]: 504 5.5.2 : Sender address > rejected: need fully-qualified address; from= > to= proto=E

Re: nobody@localhost: Sender address rejected: need fully-qualified address

2014-05-16 Thread Ian Evans
On Thu, May 15, 2014 at 11:47 PM, Viktor Dukhovni < postfix-us...@dukhovni.org> wrote: > On Thu, May 15, 2014 at 11:32:33PM -0400, Ian Evans wrote: > > > Noticed a few of these in my logs: > > > > May 15 23:22:51 carson postfix/smtpd[6768]: NOQUEUE: reject: RCPT from

Allowing alert messages from home server {Sender address rejected: Domain not found)

2014-07-24 Thread Ian Evans
I'm currently running postfix in two places. I have a fully functioning postfix email server for my site's domain and at home I have postfix installed to allow my home server to send alert messages. The home server is relaying through my home ISP's smtp server, but the messages get rejected by my

Re: Allowing alert messages from home server {Sender address rejected: Domain not found)

2014-07-25 Thread Ian Evans
Thanks for your suggestions.

Some people sending to us getting 451 4.3.5 Server configuration rejections

2014-08-26 Thread Ian Evans
Our mail server is still getting a nice steady supply of email, so I didn't realize anything was wrong. The a freind said that emails from her office address were getting rejected. I checked the logs and noticed that she wasn't the only one getting the message. Before the line below, my friend's e

Re: Some people sending to us getting 451 4.3.5 Server configuration rejections

2014-08-26 Thread Ian Evans
On Tue, Aug 26, 2014 at 7:21 PM, Wietse Venema wrote: > Ian Evans: > > Our mail server is still getting a nice steady supply of email, so I > didn't > > realize anything was wrong. The a freind said that emails from her office > > address were getting rejected. I

Re: Some people sending to us getting 451 4.3.5 Server configuration rejections

2014-08-26 Thread Ian Evans
On Tue, Aug 26, 2014 at 8:21 PM, Wietse Venema wrote: > Ian Evans: > > Aug 26 08:34:05 carson postfix/smtpd[16374]: warning: problem talking to > server private/policy-spf: Connection timed out > > This Postfix SMTP server time limit is specified with the > smtpd_policy_serv

Re: Some people sending to us getting 451 4.3.5 Server configuration rejections

2014-08-26 Thread Ian Evans
On Tue, Aug 26, 2014 at 8:21 PM, Wietse Venema wrote: > Ian Evans: > > Aug 26 08:34:05 carson postfix/smtpd[16374]: warning: problem talking to > server private/policy-spf: Connection timed out > > This Postfix SMTP server time limit is specified with the > smtpd_policy_serv

Problems emailing bell.net or sympatico.ca addresses

2021-09-17 Thread Ian Evans
Just curious if anyone on the list has ever had issues with their postfix server communicating with bell.net or their related sympatico.ca email addresses? I've been trying to send to a few but keep getting "421 Connection limit reached" followed by an eventual failure days later. I've seen people

Re: Problems emailing bell.net or sympatico.ca addresses

2021-09-17 Thread Ian Evans
On Fri, Sep 17, 2021, 7:28 PM raf, wrote: > On Fri, Sep 17, 2021 at 05:48:24PM -0400, Ian Evans > wrote: > > > Just curious if anyone on the list has ever had issues with their postfix > > server communicating with bell.net or their related sympatico.ca email > > a

Workaround for sender address rejected: domain not found

2022-04-21 Thread Ian Evans
I've seen this a few times with some companies. I'm expecting an email from, say, example.com They say it's bouncing. I check the logs and there's a RCPT 450 Sender address rejected: domain not found. The email is being sent from email.example.com, but that subdomain doesn't exist, can't be pinged

Re: Workaround for sender address rejected: domain not found

2022-04-21 Thread Ian Evans
On Thu, Apr 21, 2022 at 5:19 PM Noel Jones wrote: > > On 4/21/2022 3:34 PM, Ian Evans wrote: > > I've seen this a few times with some companies. I'm expecting an > > email from, say, example.com <http://example.com> > > > > They say it'

How long do legit servers try to deliver email?

2022-10-11 Thread Ian Evans
Sorry if this is OT. My hosting service is migrating our VPS to new hardware. I plan to shut down postfix (it's just me and the missus) and create a snapshot prior to the shutdown. How long do servers try to resend email if your server is temporarily down? The host has given themselves an 8 hour o

Re: How long do legit servers try to deliver email?

2022-10-11 Thread Ian Evans
On Tue, Oct 11, 2022, 1:00 PM Wietse Venema, wrote: > > > How long do servers try to resend email if your server is temporarily > down? > > The host has given themselves an 8 hour overnight window. > > "It depends". There is a difference between wat rules say (in this > case https://www.rfc-edit

Using Postfix to send home server alerts

2020-02-14 Thread Ian Evans
Hi, Just looking for a pointer to a recommended tutorial on setting up Postfix as a send only service to be able to send alert emails from a home server like smartmontools drive warnings etc. I have seen several tutorials that touch on this, but the part I'm not clear on is the FQDN setting. It's

Re: Using Postfix to send home server alerts

2020-02-15 Thread Ian Evans
On Sat, Feb 15, 2020, 11:09 AM Chris Green, wrote: > On Sat, Feb 15, 2020 at 07:59:21PM +1300, Peter wrote: > > On 15/02/20 10:31 am, Ian Evans wrote: > > > Hi, > > > > > > Just looking for a pointer to a recommended tutorial on setting up > > > Post

Re: Using Postfix to send home server alerts

2020-02-15 Thread Ian Evans
On Sat, Feb 15, 2020, 1:55 PM Bob Proulx, wrote: > Ian Evans wrote: > > Just looking for a pointer to a recommended tutorial on setting up > Postfix > > as a send only service to be able to send alert emails from a home server > > like smartmontools drive warnings etc.

TLS best practices

2020-05-14 Thread Ian Evans
As some test suite recommendations might be harsher than what is practical I thought I'd check with the people who actually work on Postfix. 1) some test sites say TLS 1.0 should be disabled for NIST compliance. Is that recommended? What about 1.1? 2) is there a page that has up-to-date recommend

Uninstalling postgrey

2020-05-24 Thread Ian Evans
Based on another thread here, I want to move to using postscreen/postwhite and ditch postgrey. Just want to make sure I don't bungle stopping postgrey. So... - edit main.cf and remove "check_policy_service inet:127.0.0.1:10023" from smtpd_recipient_restrictions. - restart Postfix - purge the pos

Re: Uninstalling postgrey

2020-05-25 Thread Ian Evans
On Mon, May 25, 2020 at 4:09 AM Matus UHLAR - fantomas wrote: > On 24.05.20 21:04, Ian Evans wrote: > >Based on another thread here, I want to move to using postscreen/postwhite > >and ditch postgrey. > > > >Just want to make sure I don't bungle stopping post

Re: Uninstalling postgrey

2020-05-25 Thread Ian Evans
On Mon, May 25, 2020 at 3:35 PM Ian Evans wrote: > On Mon, May 25, 2020 at 4:09 AM Matus UHLAR - fantomas > wrote: > >> On 24.05.20 21:04, Ian Evans wrote: >> >Based on another thread here, I want to move to using >> postscreen/postwhite >> >and ditch post

Re: Uninstalling postgrey

2020-05-27 Thread Ian Evans
On Wed, May 27, 2020, 11:44 AM @lbutlr, wrote: > On 24 May 2020, at 19:04, Ian Evans wrote: > > Based on another thread here, I want to move to using > postscreen/postwhite and ditch postgrey. > > > > Just want to make sure I don't bungle stopping postgrey. > &g

The historical roots of our computer terms

2020-06-06 Thread Ian Evans
Food for thought from the co-author of OAuth and oEmbed. How easy would it be for Postfix/Postscreen configs/docs to, say, refer to allow/deny lists? Leah Culver (@leahculver) tweeted at 11:32 PM on Fri, Jun 05, 2020: I refuse to use “whitelist”/“blacklist” or “master”/“slave” terminology for comp

Re: [External] Re: The historical roots of our computer terms

2020-06-06 Thread Ian Evans
On Sat, Jun 6, 2020, 10:28 AM Kevin A. McGrail, wrote: > Thanks for the reminder on this. The Apache SpamAssassin project voted to > do this change on May 3rd and I'm taking the baton to bring it to fruition. > > > > > Kevin, that's interesting that SpamAssassin had already voted on this back i

Re: Uninstalling postgrey

2020-06-06 Thread Ian Evans
On Wed, May 27, 2020, 8:49 PM Ian Evans, wrote: > On Wed, May 27, 2020, 11:44 AM @lbutlr, wrote: > >> On 24 May 2020, at 19:04, Ian Evans wrote: >> > Based on another thread here, I want to move to using >> postscreen/postwhite and ditch postgrey. >> >

Re: The historical roots of our computer terms

2020-06-06 Thread Ian Evans
On Sat, Jun 6, 2020, 3:09 PM Ralph Seichter, wrote: > * Ian Evans: > > > Leah Culver (@leahculver) tweeted at 11:32 PM on Fri, Jun 05, 2020: > > I refuse to use “whitelist”/“blacklist” or “master”/“slave” terminology > > for computers. Join me. Words matter. > > (

Siteprotect.com and cp20.com dmarc/SPF fail

2020-07-27 Thread Ian Evans
I'm a reviewer and sent an email from my site responding to one of their coverage requests. A few minutes later, my postmaster acct received this message: A message claiming to be from you has failed the published DMARC policy for your domain. Sender Domain: digitalhit.com Sender IP Address: 2

Re: Siteprotect.com and cp20.com dmarc/SPF fail

2020-07-27 Thread Ian Evans
On Mon, Jul 27, 2020, 5:32 PM Wietse Venema, wrote: > Ian Evans: > > I'm a reviewer and sent an email from my site responding to one of their > > coverage requests. > > > > A few minutes later, my postmaster acct received this message: > > > > A me

Re: Siteprotect.com and cp20.com dmarc/SPF fail

2020-07-27 Thread Ian Evans
On Mon, Jul 27, 2020, 6:59 PM Wietse Venema, wrote: > Ian Evans: > > Looking at the Postfix logs it appears the email was sent to the same ip > > address for cp20.com: > > > > Jul 27 15:14:22 carson postfix/smtp[13747]: 9323F20309D: to=<[some coded > > le

Recommended milters for small setup

2020-10-15 Thread Ian Evans
The long story short is that due to dealing with family medical issues over the past few years, my Combo web/postfix server is still on Ubuntu 14.04. In a couple of months I will have some time to upgrade. Instead of risking an in place upgrade, I am going to fire up a new droplet on Digitalocean,

Re: Recommended milters for small setup

2020-10-16 Thread Ian Evans
On Thu, Oct 15, 2020 at 12:44 PM PGNet Dev wrote: > On 10/15/20 8:19 AM, Ian Evans wrote: > > > Is there a more efficient, memory stingy, faster milter way to run > spamassassin, clamav, etc, or would you recommend sticking with amavis? > > > > very much personal ch

Re: Some people sending to us getting 451 4.3.5 Server configuration rejections

2014-08-27 Thread Ian Evans
On Wed, Aug 27, 2014 at 7:12 AM, Wietse Venema wrote: > Ian Evans: > > > First. the script should limit the time for DNS lookups. > > > > > > Second, the script should not die after BrokenPipeError exceptions. > > > > > > try: sys.stdout.flush() &g

Dovecot,seive and postfix master.cf

2017-02-22 Thread Ian Evans
Background: Have a postfix/dovecot/amavisd-new system that has been running smoothly for several years. Just a handful of virtual users, ie: /home/vmail/example.com/ianevans/Maildir As we are starting to use multiple devices finally, decided to move away from pop3/imap to all imap. sieve plugin h

Re: Dovecot,seive and postfix master.cf

2017-02-22 Thread Ian Evans
On Wed, Feb 22, 2017 at 4:21 PM, Ian Evans wrote: > Background: Have a postfix/dovecot/amavisd-new system that has been > running smoothly for several years. Just a handful of virtual users, ie: > /home/vmail/example.com/ianevans/Maildir > > As we are starting to use multiple

Re: Dovecot,seive and postfix master.cf

2017-02-26 Thread Ian Evans
On Feb 22, 2017 6:46 PM, wrote: On Feb 22, 2017, at 16.21, Ian Evans wrote: > > Background: Have a postfix/dovecot/amavisd-new system that has been running smoothly for several years. Just a handful of virtual users, ie: > /home/vmail/example.com/ianevans/Maildir > > As we are

dovecot lda bouncing postfix aliases

2017-03-01 Thread Ian Evans
Recently configured postfix to use the dovecot lda as I wanted to use sieve. Got that working a few days ago but noticed that I wasn't getting any emails to aliases. Checked the logs and saw messages like: Mar 1 08:19:59 carson postfix/lmtp[16949]: 0DCD22016BE: to=< sa...@example.com>, relay=cars

Re: dovecot lda bouncing postfix aliases

2017-03-01 Thread Ian Evans
On Wed, Mar 1, 2017 at 2:47 PM, Viktor Dukhovni wrote: > > > On Mar 1, 2017, at 8:42 AM, Ian Evans wrote: > > > > Mar 1 08:19:59 carson postfix/lmtp[16949]: 0DCD22016BE: to=< > sa...@example.com>, relay=carson.example.com[private/dovecot-lmtp], > delay=0.07, d

Re: dovecot lda bouncing postfix aliases

2017-03-01 Thread Ian Evans
On Wed, Mar 1, 2017 at 3:32 PM, Viktor Dukhovni wrote: > > > On Mar 1, 2017, at 3:20 PM, Ian Evans wrote: > > > > virtual_mailbox_base = /home/vmail > > virtual_mailbox_domains = example.com > > virtual_mailbox_limit = 0 > > virtual_mailbox_maps = hash:/

Re: dovecot lda bouncing postfix aliases

2017-03-01 Thread Ian Evans
On Mar 1, 2017 4:30 PM, "Viktor Dukhovni" wrote: > On Mar 1, 2017, at 4:14 PM, Ian Evans wrote: > > Okay...lack of caffeine and hospital distraction is probably not the best time to be doing this, > > Created /etc/virtual with: > > example.com this-text-

Re: dovecot lda bouncing postfix aliases

2017-03-05 Thread Ian Evans
On Mar 1, 2017 4:37 PM, "Ian Evans" wrote: On Mar 1, 2017 4:30 PM, "Viktor Dukhovni" wrote: > On Mar 1, 2017, at 4:14 PM, Ian Evans wrote: > > Okay...lack of caffeine and hospital distraction is probably not the best time to be doing this, > > Created

dmarc fail on internal emails

2017-04-20 Thread Ian Evans
I apologize for cross-posting this here but a) the opendmarc list seems to be very low volume and I'm wondering if a reader on this busier list has come across this, b) not sure if the mechanism of internal emails and testing is different than if postfix is sending externally and c) clutching at st