Hi all,
I'm in the process of upgrading an old RHEL 6.6 server running a
hacked postfix 2.11.9 release to something newer, on Ubuntu 21.4 and
using postfix 3.5.6 but I'm running into a minor annoyance.
This server handles incoming email, looks for a match in an NIS
mail.aliases map, and then al
>>>>> "John" == John Stoffel writes:
John> I'm in the process of upgrading an old RHEL 6.6 server running a
John> hacked postfix 2.11.9 release to something newer, on Ubuntu 21.4 and
John> using postfix 3.5.6 but I'm running into a minor annoyanc
> "Girish" == Girish Venkatachalam writes:
Girish> On 04:41 PM 17-Sep-21, Benny Pedersen wrote:
>> On 2021-09-17 14:40, Christian Schmitz wrote:
>> make a spamassassin rule to check dkim, make that dkim score 1000, if
>> you reject high score spam there is nothing more to do
Girish> In thi
> "Jim" == Jim writes:
>> Instead, use Maildir format with one message per file,
Jim> I thought about that once, but I decided I have too many e-mail
Jim> messages for that. (I don't want to run out of inodes, nor do I want to
Jim> make file accesses too slow because of the number of files
> "Simon" == Simon Wilson writes:
Simon> I feel like I'm missing something really obvious here... :(
Simon> Multiple RedHat8 servers, Postfix configured on all of them for
Simon> internal network mail server (primarily server log updates,
Simon> etc. to admin).
Have you restarted syslog (or
>>>>> "Simon" == Simon Wilson writes:
Simon> ----- Message from John Stoffel -
Simon>Date: Sun, 28 Nov 2021 21:37:12 -0500
Simon>From: John Stoffel
Simon> Subject: Re: Logging silence
Simon> To: si...@simonandkate.net
Simon>
> "Simon" == Simon Wilson writes:
John> More details would help us help you.
John> John
Simon> I worked it out. journald.conf was set to MaxLevelStore=notice,
Simon> so it wasn't just postfix not logging, just that was the
Simon> symptom picked up.
Simon> I really was missing something
SH> We have a postfix/dovecot/mysql configuration. We recently
SH> removed one of the users from the database, however when we send
SH> email, it still looks like the address we are sending to is a
SH> local address and bounces with a “no such user” error.
Please post your config values. But I
> "Dhammika" == Dhammika Gunawardena writes:
> We maintain a private relay server to send ebills for a customer.
Please send more details on your setup: OS, postfix version, "postconf
-nf" output, etc. Give more details
> During peak sending hours, we miss about 5-10% of incoming message
> "Henry" == Henry R writes:
> My mailserver once had some issues on sending messages to different
> providers. I have contacted the provders and most of them were kind
> enough to resolve the blocking issue. Thanks for them (ATT, GMX,
> 1and1 etc).
I'm in the same boat with one provider, ch
> "Henry" == Henry R writes:
> I was once charter's customer.
> But I leave them since charter was bought by Spectrum.
> And spectrum blocks all IP from DO and Linode.
Yup, so now I'm trying to setup things so that my postfix routes all
emails to @charter.net users via my charter login, but
Hi all,
I run my own domain @stoffel.org and I'm trying to fix a problem
sending email to @charter.net users, since Spectrum has blocked my
Linode's ASN number completely. My IP passes all the RBL blacklists
their first line support suggested I check, but I find my IP for
mail.stoffel.org in the
--
> Von: owner-postfix-us...@postfix.org Im
> Auftrag von John Stoffel
> Gesendet: Freitag, 2. Dezember 2022 17:37
> An: Postfix users
> Betreff: Send email to one @domain.com via authenticated relay?
> Hi all,
> I run my own domain @stoffel.org and I'm trying to fix a proble
>>>>> "Jim" == Jim Popovitch writes:
> On Fri, 2022-12-02 at 11:36 -0500, John Stoffel wrote:
> I check, but I find my IP for mail.stoffel.org in the UCEPROTECT-3
> spam list. Nothing I can do about it.
> I doubt that many sites block by using U
>>>>> "Wietse" == Wietse Venema writes:
> Viktor Dukhovni:
>> On Fri, Dec 02, 2022 at 11:36:30AM -0500, John Stoffel wrote:
>>
>> > I tried setting up /etc/postfix/transport_maps like this:
>> >
>> >cha
>>>>> "Rob" == Rob McGee writes:
> On 12/3/2022 9:37 AM, John Stoffel wrote:
>>>>>>> "Jim" == Jim Popovitch writes:
>>
>>> On Fri, 2022-12-02 at 11:36 -0500, John Stoffel wrote:
>>> I check, but I find my IP
> "Bill" == Bill Cole writes:
> On 2022-12-04 at 20:57:49 UTC-0500 (Sun, 4 Dec 2022 20:57:49 -0500)
> You are missing the point here.
> NO ONE running a serious mailserver will reject mail based on a
> UCEPROTECT level 3 listing. It is a waste of your energy to focus on
> that listing.
I
> "Richard" == Richard Rasker writes:
Richard> Hello,
Richard> I just installed a new mail server on Debian 9 (Stretch) with the
following setup:
Richard> - postfix
Richard> - courier-imap + courier-imap-ssl
Richard> - amavis + spamassassin
Richard> - courier-maildrop for delivery to Mai
> "Richard" == Richard Rasker writes:
Richard> Hell John,
Richard> Package versions:
Richard> # apt list postfix
Richard> Listing... Done
Richard> postfix/oldstable,now 3.1.12-0+deb9u1 i386 [installed]
Richard> #apt list courier-imap
Richard> Listing... Done
Richard> courier-imap/oldstable,
> "Bob" == Bob Proulx writes:
Bob> What's the best configuration for a web server that does not
Bob> receive mail but needs to send mail? Password resets. Bug
Bob> ticket update notifications. That type of email. (Plus admin
Bob> mail such as cron output to root. But I can ensure that is
> "Wietse" == Wietse Venema writes:
Wietse> Viktor Dukhovni:
>> > On Oct 25, 2020, at 9:08 PM, Wietse Venema wrote:
>> >
>> > What about making the '#' a suffix instead? That is still unlikely
>> > to clash with existing user naming schemes. BTW I realize that there
>> > is no unit test for
>>>>> "Viktor" == Viktor Dukhovni writes:
>> On Oct 27, 2020, at 11:42 PM, John Stoffel wrote:
>>
>> Could someone have an email address of "uid:j...@some.place.home" down
>> the line?
Viktor> The lookup key is a login name, giv
Samuel> I encountered some issues with postfix when the
Samuel> /var/spool/postfix is on a glusterfs. The postfix queue is
Samuel> blocked suddenly and no more mail is sent.
Please see http://www.postfix.org/DEBUG_README.html and re-send your
problem with the right details.
Samuel> I don't kno
> "James" == James B Byrne writes:
James> On Mon, December 21, 2020 20:00, Jaroslaw Rafa wrote:
>>
>> If you are able to connect via 465, then maybe the application just isn't
>> designed to use "inline" TLS, but rather uses only SMTP-over-TLS? The latter
>> is supported on port 465, while s
>>>>> "James" == James B Byrne writes:
James> On Fri, December 25, 2020 12:43, John Stoffel wrote:
>>
>> Why don't you setup a local only postfix instance on the same host as
>> the application, which only listed on 127.0.0.1:25, which the du
> "Ganael" == Ganael Laplanche writes:
Ganael> On Tuesday, January 19, 2021 1:59:42 PM CET Wietse Venema wrote:
Ganael> Hello Wietse,
Ganael> Thanks for your reply,
>> > Ignoring errors would result in misdelivery of email. You may have
>> expectations that it is OK for software to randomly
> "Ganael" == Ganael Laplanche writes:
Ganael> H... If we put the dump before, we will loose our 7-days
Ganael> window to react. What could be done maybe is have 2 hash maps
Ganael> and not use LDAP at all : 1 file generated every hour and our
Ganael> 7-days old dump as a second choice.
> "Ralph" == Ralph Seichter writes:
Ralph> * Wietse Venema:
>> What problem are you trying to solve?
Ralph> Milters A, B and C in my example scenario can trigger
Ralph> asynchronous actions in backend systems, the results of which
Ralph> become available only after a delay caused by processi
> "Karel" == Karel writes:
Karel> I am running small Postfix server for personal use. My logs are flooded
Karel> with:
Karel> relay access denied
Karel> hello rejects
Karel> connection rate limit exceeded ...
Karel> lost connection after AUTH from ...
Karel> Often there are hundred
> "Dietrich" == Dietrich Streifert
> writes:
Dietrich> I'm running centos 7.2 with postfix 2.10.1, installed from the
standard
Dietrich> centos 7 repo which corresponds to rhel 7.
Dietrich> I'm using php mail to send mails which uses /usr/sbin/sendmail -t -i
to
Dietrich> send the m
Hi Guys,
I'm trying to replace an old Sun 5.8 box running Sendmail 8.12.x with
a newer RHEL 6 box running Postfix 2.6.6, which I know is unsupported
and I should upgrade. But it's what comes from RedHat and it's what
I'm working with right now.
Anyway, I'm going nuts trying to make my crazy env
>>>>> "Noel" == Noel Jones writes:
Noel> On 4/6/2016 8:06 AM, John Stoffel wrote:
>> Can I force the fallback_transport to re-write, before using the
>> fallback, john.t...@foo.bar.com into john.t...@hdqmta.foo.bar.com?
>> Since I think that'
>>>>> "Noel" == Noel Jones writes:
Noel> On 4/6/2016 10:11 AM, John Stoffel wrote:
>>>>>>> "Noel" == Noel Jones writes:
>>
Noel> On 4/6/2016 8:06 AM, John Stoffel wrote:
>>>> Can I force the fallback_transpor
> "Tom" == Tom Horsley writes:
Tom> On Wed, 31 Aug 2016 18:32:03 -0400
Tom> Tom Horsley wrote:
>> I'm just reading about the pickup program and the
>> receive_override_options to turn off mapping.
>> I think that might work, only the mail from
>> fetchmail is being locally delivered via pick
Mark> I'd like to configure Postfix such that I can prevent certain
Mark> IP's/networks from sending email to 'external' recipients. I'm
Mark> basically trying to set it so that our dev and test web
Mark> application servers can't email any domains other than our own -
Mark> so developers can test
The problem is only going to get worse, so any guidance and probably even some
more general error messages giving more direct hints would be appreciated.
The guy who just posted his solution to interoperable with old postfix and the
Windows patch he could us is a perfect example.
Sent from my
Wietse,
Thank you so much for postfix. I'm a recovering Sendmail user and I
thank you every day. I've been migrating my $WORK servers to postfix
too, and it just makes life much much much simpler.
John
Hi all,
We're running postfix-2.6.6-6.el6_5.x86_64 on RHEL 6.6 and running
into a problem where emails that have been released from our outside
spam protection company, *.protection.outlook.com, are getting
rejected with messages like this:
Mar 26 06:00:56 mailhost postfix/smtpd[2270]: connect
>>>>> "Dominic" == Dominic Raferd writes:
Dominic> On 30 March 2017 at 15:26, John Stoffel wrote:
Dominic> Hi all,
Dominic> We're running postfix-2.6.6-6.el6_5.x86_64 on RHEL 6.6 and running
Dominic> into a problem where emails that ha
> "Wietse" == Wietse Venema writes:
Wietse> Postfix reports this error because it is responsible for 'example.com'
Wietse> and the message has 'Delivered-To: u...@example.com'.
Thank you for your reply! And thank you for postfix in general, it's
made my life simpler in so many ways.
Wiets
>>>>> "Noel" == Noel Jones writes:
Noel> On 3/30/2017 9:26 AM, John Stoffel wrote:
>>
>> Hi all,
>>
>> We're running postfix-2.6.6-6.el6_5.x86_64 on RHEL 6.6 and running
>> into a problem where emails that have been released from o
>>>>> "John" == John Stoffel writes:
>>>>> "Noel" == Noel Jones writes:
Noel> On 3/30/2017 9:26 AM, John Stoffel wrote:
>>>
>>> Hi all,
>>>
>>> We're running postfix-2.6.6-6.el6_5.x86_64 on RHEL 6.6
>>>>> "Noel" == Noel Jones writes:
Noel> On 3/31/2017 3:50 PM, John Stoffel wrote:
>> So I created the following entry in my header_checks file:
>>
>> /^Delivered-To:/ WARN Found email with Delivered-To: header already in it!
>>
>> And
Well, I've confirmed that EOP (protection.outloko.com, our external
Spam filter provider) is adding in the "Delivered-To:" head when
emails that have been quarrantined are released to be delivered in to
us.
I'm amazed others haven't seen this problem yet, but maybe we're
strange. In any case, no
t instance via the firewall...
Mike> Quoting John Stoffel :
>> Well, I've confirmed that EOP (protection.outloko.com, our external
>> Spam filter provider) is adding in the "Delivered-To:" head when
>> emails that have been quarrantined are released to be deliv
Robert> It seems postfix is impatient with connecting with mysql, as I see in
Robert> maillog entries like:
Robert> Apr 6 11:48:30 z9m9z dovecot: dict: Error: mysql(localhost): Connect
Robert> failed to database (postfix): Can't connect to local MySQL server
Robert> through socket '/var/lib/m
>>>>> "Robert" == Robert Moskowitz writes:
Robert> On 04/06/2017 02:17 PM, John Stoffel wrote:
Robert> It seems postfix is impatient with connecting with mysql, as I see in
Robert> maillog entries like:
>>
Robert> Apr 6 11:48:30 z9m9z dovecot: di
>>>>> "Viktor" == Viktor Dukhovni writes:
>> On Apr 4, 2017, at 5:26 PM, John Stoffel wrote:
>>
>> But I only want this replamcent to happen for email that comes from a
>> specific set of outside servers. I think I might have to run my own
>
>>>>> "Viktor" == Viktor Dukhovni writes:
>> On Apr 10, 2017, at 4:01 PM, John Stoffel wrote:
>>
>> Since I built 2.11.9 by hand, I'm willing to do this hack as well I
>> think. It's a total hack too... and I'm still amazed
> "Wietse" == Wietse Venema writes:
Wietse> DecebalICT:
>> I went from an openSUSE system to a Debian 9 system.
How did you do this upgrade? A clean install of Debian onto new
partitions?
I suggest that you instead purge postfix on the debian system and then
re-install, getting the default
Cecil> That was a good idea yes. I have postfix running, but I cannot
Cecil> send email to an external domain. But that is better in another
Cecil> thread I think.
Now you need to send details of your setup from the DEBUGGING docs.
postconf -n, etc. Do you have a mail server you send all email
Could it be that you mail server is looking up and finding IPv6
addresses, but you don't have IPv6 enabled on your setup? Try forcing
postfix to only use IPv4.
John
> "Sven" == Sven Schwedas writes:
Sven> On 2017-12-12 10:55, J Doe wrote:
>> Hi,
>>
>> I was wondering if fellow Postfix users would still recommend using
>> amavisd-new when integrating AV (ClamAV), and spam filtering (SpamAssasin) ?
Sven> There's nothing wrong with Amavis. The only decen
> "Voytek" == Voytek writes:
Voytek> I have old server Postfix 2.x with MySQL, migrating to Postfix
Voytek> 3.x on a new Centos 7 MariaDB 10.2, virtual user/domain, maybe
Voytek> 20 domain/100 users, see abbreviated usage summary [1]
So what is the advantage of using mysql here? Ease of ad
> "Dino" == Dino Edwards writes:
>> The main question is, why do you need port other than 25?
Dino> Cause Verizon blocks all incoming and outgoing traffic to port
Dino> 25 unless it's to their SMTP servers and I have an Exchange
Dino> server that needs to send/receive email through an outsid
> "Ralph" == Ralph Seichter writes:
Ralph> On 02.04.2018 19:55, John Allen wrote:
>> what is the attraction of docker? What does it do that I might need?
Ralph> You might need it because a Docker container is the recommended method
Ralph> to deploy Discourse, which I am doing right now... SC
> "Roger" == Roger Goh writes:
Roger> There is an external app server (that is our service provider)
Roger> that we want them to blast emails to a team/department in our
Roger> organization (email domain @xyz.com ) but these emails will
Roger> have the sender to be in same domain as us ie @xy
> "Matus" == Matus UHLAR <- fantomas > writes:
Matus> On 26.07.18 13:38, Luc Pardon wrote:
>> Recently, my provider forced me from ADSL (being phased out here) to
>> VDSL, and I now find myself sending mail from a "dynamic" IP address...
Matus> is it really dynamic? Was the previous one dynam
ns blacklists).
>>
Matus> Wietse told you the rest. Imho there's no point in playing with what you
Matus> propose inatead of fixing the IP reputation.
Matus> On 26.07.18 11:14, John Stoffel wrote:
>> Or do what I do and spin up a Digital Ocean droplet for $6/mo that
>&g
> "Daniel" == Daniel Ryšlink writes:
Daniel> | You disable cleartext SMTP as well?
Daniel> The rationale here is that by accepting provenly insecure
Daniel> protocols, one provides an illusion of security, which is
Daniel> potentially more dangerous than transparently refuse, and fall
Daniel
> "Chad" == Chad M Stewart writes:
Chad> I want to setup a method by which only senders which are in a defined
Chad> list can send a message to a given recipient.
External or internal recipient? And wouldn't the simplest method just
be a procmail or sieve filter on the receivers end?
C
Michael> I have been using postfix on a local machine for a few years
Michael> to act as a relay for my domain to send email out through
Michael> gmail.
Michael> This has worked well enough, but I noticed recently that I
Michael> had some email queued up and was not getting emails out any
Michae
> "Wietse" == Wietse Venema writes:
Wietse> I'm implementing logfile support for Postfix on MacOS, because not
Wietse> providing results in a bad experience.
Wietse> This is a retrofit workaround, therefore it will have limitations
Wietse> that do not exist with the default syslog-based impl
>>>>> "Wietse" == Wietse Venema writes:
Wietse> John Stoffel:
>> >>>>> "Wietse" == Wietse Venema writes:
>>
Wietse> I'm implementing logfile support for Postfix on MacOS, because not
Wietse> providing results in a
> "Durga" == Durga Prasad Malyala writes:
Durga> Correct. I would recommend linode or digitalocean any time over
Durga> AWS SES. AWS is a good option for heavy transactional mail
Durga> alerts etc.
The only problem with Digital Ocean right now is that Charter/Spectrum
in the US has blocked
>>>>> "Yuval" == Yuval Levy writes:
Yuval> On 2019-01-20 14:40, John Stoffel wrote:
>> The only problem with Digital Ocean right now is that Charter/Spectrum
>> in the US has blocked all (most? At least the one I'm using...) blocks
>> assign
> "Alice" == Alice Wonder writes:
Alice> On 2/7/19 2:52 PM, Bill Cole wrote:
Alice> *snip*
>>
>> But your core point is valid: mailing from an AWS instance (or from
>> anywhere on an IP with a programmatically derived PTR) in general is
>> going to work poorly. There is too little accounta
> "Gary" == Gary writes:
Gary> Number 4 is immensely useful. When I had a hosted service, I got hacked
from someone in Morocco via a Round Cube exploit that wasn't patched. (My
PayPal account subsequently hacked, though I had the account suspended.)
Gary> I saw two problems. One, I only u
Gary> What ISP specifically bans Digital Ocean?
Charter/Spectrum.
Gary> What you need is some other email account, say proton, to start
Gary> the dialog with the ISP that bans your Digital Ocean account. Or
Gary> you look for some online form or forum. I had this problem with
Gary> SBC (AT&T
> "Ian!" == Ian! D Allen writes:
Ian!> On Sun, Mar 03, 2019 at 03:51:35PM -0500, Wietse Venema wrote:
>> smtp unix - - n - - smtp
>> -o { smtp_generic_maps = inline:{{idal...@idallen.ca = you@college}}}
Ian!> Am I right that since my master.cf already has
> "PGNet" == PGNet Dev writes:
PGNet> On 3/10/19 3:19 PM, Wietse Venema wrote:
>> * LINUX5 is supported, based on sanity checks with a Rawhide
>> prerelease.
PGNet> fyi, still
PGNet> cd postfix-3.4.2
PGNet> make tidy
PGNet> make -f Makefile.in MAKELEVEL= Makefiles
PGNet>
De> Can you tell me witch param I need to change in main.cf to mount
De> the nfs to the mailq?
As others have said, you need to mount the NFS data store holding your
mailq onto the server. But then you need to make sure your NFS server
is robust and reliable as well. This starts to get into sy
> "Phil" == Phil Stracchino writes:
Phil> On 4/23/19 2:40 PM, lists wrote:
>> I would investigate using rspamd rather than spamassassin. At the moment
>> I run neither since I have settled upon a nice mix of RBLs and check the
>> reverse pointer. That Perl code to get rid of dynamic domains r
> "Viktor" == Viktor Dukhovni writes:
Viktor> On an mostly unrelated note, OpenSSL 3.0 (~Q4 2020) is changing the
Viktor> error API, so we'll eventually need:
Viktor> --- src/tls/tls_misc.c
Viktor> +++ src/tls/tls_misc.c
Viktor> @@ -1332,6 +1332,18 @@ voidtls_print_errors(void)
Viktor>
>>>>> "Wietse" == Wietse Venema writes:
Wietse> John Stoffel:
>> >>>>> "Viktor" == Viktor Dukhovni writes:
>>
Viktor> On an mostly unrelated note, OpenSSL 3.0 (~Q4 2020) is changing the
Viktor> error API, so we
> "mailmary---" == mailmary--- via Postfix-users
> writes:
> Unfortunately I've seen this crash as well, its actually quite
> frequent in my case and I'm using a newer version of OpenDMARC than
> you:
> # opendmarc -V
> opendmarc: OpenDMARC Filter v1.4.2
> SMFI_VERSION 0x101
>
>>>>> "Phil" == Phil Stracchino via Postfix-users
>>>>> writes:
> On 3/7/23 15:36, Bernardo Reino via Postfix-users wrote:
>> On Tue, 7 Mar 2023, John Stoffel via Postfix-users wrote:
>>
>>> So what's the option for a more
> "Jim" == Jim Wright via Postfix-users writes:
> Hey all. Recently my ISP (Spectrum) decided (after this was working for
> me for almost 20 years) to make it impossible for a self hosted domain
> to relay through their SMTP server unless it was actually a spectrum.com
> email address bei
> "Wietse" == Wietse Venema via Postfix-users
> writes:
> As a few on this list may recall, it is 25 years ago today that the
> "IBM secure mailer" had its public beta release. This was accompanied
> by a nice article in the New York Times business section.
As a recovering sendmail user
> "Ken" == Ken Gillett via Postfix-users writes:
> Thank you for your words of wisdom Wietse. 😉
> I rather thought you understood how 'silly' it would be to run a find command
> for postconf as I had already clearly explained (at least 3 times 🙂) I knew
> where both versions were located an
> "Wietse" == Wietse Venema via Postfix-users
> writes:
> Postfix lists are run by Mailman3, configured to replace the From:
> addres with the list address; Mailman3 then unconditionally adds
> the original From: addres to Reply-to:. This is standard Mailman
> damage control for DMARC.
>>>>> "Wietse" == Wietse Venema via Postfix-users
>>>>> writes:
> John Stoffel:
>> >>>>> "Wietse" == Wietse Venema via Postfix-users
>> >>>>> writes:
>>
>> > Postfix lists are run
82 matches
Mail list logo