On 2026-08-13 at 12:41:08 UTC-0400 (Thu, 13 Aug 2026 18:41:08 +0200)
Matus UHLAR - fantomas via Postfix-users <[email protected]>
is rumored to have said:

>>> On 13.08.26 15:48, Peymaneh Nejad via Postfix-users wrote:

[...]

>> The spamassassin documentation does not provide any hints on its 
>> usage/configuration as a "delivery agent"
>
> spamassassin is only a mail filter, it does not receive nor deliver mail.

Correct. It exists both as a suite of Perl modules that other programs (like 
Milters) can load and a 'spamd' executable which runs as a daemon and accepts 
connections on either a TCP port or a unix-domain socket by clients speaking a 
simple protocol to have it check messages. A very simple sample client named 
'spamc' is included, which is widely used by other programs to check messages, 
rather than  using the Perl modules themselves. Neither spamd nor spamc nor any 
of the other tools in the SpamAssassin distribution understand how to deliver 
mail in any way. A message check by SA only returns a message score and 
optionally message headers to add.

> You need a glue application that pushed mail to spamassassin and back.
> Common glue apps are amavis, spamass-milter, rspamd.

The best list of glue choices is at 
https://cwiki.apache.org/confluence/spaces/SPAMASSASSIN/pages/119543772/IntegratedInMta
 but a lot of people with minimal volume can get away with using the Postfix 
"content-filter" or "pipe" interfaces with very simple shell scripts using 
either spamc or even running the spamassassin Perl script (which imposes a 
costly overhead) and then re-injecting a modified message back into the mail 
delivery cycle using the 'sendmail' binary.

> your glue application causes mail being reinjected to postfix the way it 
> get's DKIM-signed.

This is a common issue with "simple" content filters which follow the example 
in the Postfix FILTER_README.

With OpenDKIM, the solution is to set "Domain" correctly and use the 
KeyTable+SigningTable mechanism rather than a simple KeyFile. If you can't 
figure out why OpenDKIM is signing a message, set "LogWhy" to "Yes" in its 
configuration and restart it for enlightenment.


-- 
 Bill Cole
 [email protected] or [email protected]
 (AKA @[email protected] and many *@billmail.scconsult.com addresses)
 Please keep discussion mailing list replies *on-list*
 Not Currently Available For Hire
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to