That feeling is based on a misreading and/or misinterpretation of the
documentation.
Ok, can you help me in understanding the man page better?
reject_authenticated_sender_login_mismatch
Reject the request when the client is authenticated with SASL, but
either the MAIL FROM address is not listed in $smtpd_sender_login_maps,
or the SASL login name is not an owner for that address.
This prevents an authenticated client from using a MAIL FROM
address that they do not explicitly own.
Note: to enforce that the From: header address matches the envelope
sender (MAIL FROM) address, use an external filter such as a Milter, for
the submission or submissions (formerly called smtps) services. For
example: https://github.com/magcks/milterfrom.
This feature is available in Postfix version 2.1 and later.
... because what I read from "but either the MAIL FROM address is not
listed in $smtpd_sender_login_maps, or the SASL login name is not an
owner for that address" is "but either the MAIL FROM address is not
listed in $smtpd_sender_login_maps, or the SASL login name is not equal
to that address".
What does "is not an owner of" implies that I'm missing?
Thanks,
Luca
On 30/09/26 10:14, Viktor Dukhovni via Postfix-users wrote:
On Wed, Sep 30, 2026 at 05:30:58AM +0200, Luca Cavana via Postfix-users wrote:
Now, it does work. But by reading the man 5 postconf I have the feeling that
reject_authenticated_sender_login_mismatch should already match the SASL
login name to the MAIL FROM: address implicitly:
That feeling is based on a misreading and/or misinterpretation of the
documentation.
NOQUEUE: reject: RCPT from unknown[2001:67c:d68:13::e]: 553 5.7.1
<[email protected]>: Sender address rejected: not owned by user
[email protected]; from=<[email protected]>
to=<redacted> proto=ESMTP helo=<[IPV6:2001:67c:d68:13::e]>
As expected.
... how is so? What I'm doing wrong?
You're deleting the table entry required to match the sender to the
associated SASL login.
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]