On Tue, Aug 26, 2014 at 08:33:22PM +0200, Ole Heiberg Michaelsen wrote:

> # cat sasl_pw
> [upstreamrelay]:25 user01:xxxxxxxxxxx

Is the nexthop relay (relayhost in main.cf or transport
nexthop) specified as:

    1. upstreamrelay
    2. [upstreamrelay] 
    3. upstreamrelay:25
    4. [upstreamrelay]:25

Anything other than "4" will not match the sasl_pw table.

> Aug 26 13:47:12 xxxxxxxxxxxx mail:info postfix/smtp[10813452]: Verified TLS 
> connection established to upstreamrelay[xx.xx.xx.xx]:25: TLSv1 with cipher 
> DHE-RSA-AES256-SHA (256/256 bits)
> Aug 26 13:47:24 xxxxxxxxxxxx mail:info postfix/smtp[10813452]: 76B8B1002F: 
> to=<m...@xxxx.xxx>, relay=upstreamrelay[xx.xx.xx.xx]:25, delay=19, 
> delays=6.8/0.02/0.34/12, dsn=5.7 .1, status=bounced (host 
> xxxxxxxxxxxxxxxx[xxx.xxx.xxx.xx] said: 554 5.7.1 <m...@xxxx.xxxx>: Relay 
> access denied (in reply to RCPT TO command))

Sure looks no attempt to authenticate.  Almost certainly because
the nexthop is not *verbatim* what is in the sasl_pw table.

-- 
        Viktor.

Reply via email to