On Tue, Aug 26, 2014 at 08:33:22PM +0200, Ole Heiberg Michaelsen wrote: > # cat sasl_pw > [upstreamrelay]:25 user01:xxxxxxxxxxx
Is the nexthop relay (relayhost in main.cf or transport nexthop) specified as: 1. upstreamrelay 2. [upstreamrelay] 3. upstreamrelay:25 4. [upstreamrelay]:25 Anything other than "4" will not match the sasl_pw table. > Aug 26 13:47:12 xxxxxxxxxxxx mail:info postfix/smtp[10813452]: Verified TLS > connection established to upstreamrelay[xx.xx.xx.xx]:25: TLSv1 with cipher > DHE-RSA-AES256-SHA (256/256 bits) > Aug 26 13:47:24 xxxxxxxxxxxx mail:info postfix/smtp[10813452]: 76B8B1002F: > to=<m...@xxxx.xxx>, relay=upstreamrelay[xx.xx.xx.xx]:25, delay=19, > delays=6.8/0.02/0.34/12, dsn=5.7 .1, status=bounced (host > xxxxxxxxxxxxxxxx[xxx.xxx.xxx.xx] said: 554 5.7.1 <m...@xxxx.xxxx>: Relay > access denied (in reply to RCPT TO command)) Sure looks no attempt to authenticate. Almost certainly because the nexthop is not *verbatim* what is in the sasl_pw table. -- Viktor.