September 21, 2026 at 22:40, "Wietse Venema via Postfix-users"
<[email protected]
mailto:[email protected]?to=%22Wietse%20Venema%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E
> wrote:
>
> patpro--- via Postfix-users:
> Next `best idea' I have is to use postfix on the VPS to act as a relay,
> but it means that - unless I'm mistaken - I need to set up signing on
> the VPS. That's the role-splitting I wish I can avoid.
> You can sign DKIM locally before sending to the relay.
>
> To eliminate the MTA on the relay host, Postfix would need to have
> Socks support: in the Postfix SMTP client to send mail, and in the
> Postfix SMTP and postscreen server to listen on port 25. I have
> never tried that, but TOR people do at least the client side.
>
Well, if it’s actually OK to sign then forward, I might actually do that. This
is really the path of least resistance for me: I just copy all my setup and add
a transport pointing to my VPS. Call me paranoid, I’ve always concidered one
has to sign at edge, just before releasing the message :D
Socks is a nice idea too, but unless I find an already-made solution I fear it
might be too fragile.
Thanks
patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]