Togan Muftuoglu:
> >>>>> "JR" == Jaroslaw Rafa <[email protected]> writes:
>
> JR> Dnia 1.12.2021 o godz. 14:09:49 Togan Muftuoglu pisze:
> >>
> >> Glad that I put HOLD rather than REJECT as IOS devices are producing this
> >> format
> >>
> >> Message-Id: <[email protected]>
> >>
> >> Is there a way to change the Message-Id for authenticated users and how can
> >> I do it?
>
> JR> Don't do this check for authenticated users (ie. submission ports).
>
> After searching through the document with the help of strong coffee I ended up
> adding the following to submission
>
> -o receive_override_options=no_header_body_checks
That addresses the immediate problem, but...
> Yet I thought maybe there is a better way.
It comes back and bites when one of your users signs up to an
external mailing list, in which case postings from that user will
be rejected because the external list server does not use your
authenticated submssion or smtps service.
If you musr reject 'forged' Message-ID strings from the Internet
then you need to 'fix' the Message-ID strings in authenticated
submissions.
Something like this:
/etc/postfix/master.cf:
submission . . . smtpd
-o cleanup_service_name=cleanup_submission
cleanup_submission . . cleanup
-o header_checks=pcre:/etc/postfix/submission_header_checks.pcre
/etc/postfix/submission_header_checks.pcre
/^(Message-ID:.+@)(mydomain\.com>.*)/ replace $(1)mail.$(2)
As y9ou see this complicates configuration.
Instead, consider life without the forged Message-ID check.
It almost never blocks mail for me.
Wietse