Wietse Venema: > Jose Borges Ferreira: > > On Wed, Dec 3, 2014 at 1:51 PM, Wietse Venema <wie...@porcupine.org> wrote: > > > Jose Borges Ferreira: > > >> This is the scenario. > > >> Box 1 : just receive email from "outside" - inbound flow. > > >> Box 2 : used to sent email to the "outside" - oubound flow. > > > > > > Inbound MTA: primary MX for your domain(s). If mail can't be > > > delivered, use Postfix's relayhost feature to deliver outbound mail > > > via the outbound MTA, if you can't use standard MX logic to deliver > > > directly to the sender's MX hosts. > > > > That's my initially idea, but was afraid that relayhost would "catch" > > more than intended. > > It catches outbound mail. Postfix cannot generate other mail, as > long as all mail from inside has an inside envelope sender address.
And all mail from outside has an outside envelope sender address. > And that is standard firewall hygiene. Wietse