Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Gedalya via Exim-users
On 3/14/23 08:07, Jeremy Harris via Exim-users wrote: > Only authentication methods which are self-encrypted should be used on a  > cleartext channel. Further, I'm not aware of clients which have the specific behavior of switching to TLS after authentication. While we're at it, will Exim or oth

Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Gedalya via Exim-users
On 3/14/23 08:07, Jeremy Harris via Exim-users wrote: > On 13/03/2023 23:43, Gedalya via Exim-users wrote: >> 4. On ports 587, authentication should not be advertised before STARTTLS is >> issued. > > A slight suggested relaxation of that rule:  Only authentication met

Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Gedalya via Exim-users
On 3/14/23 05:57, Yves via Exim-users wrote: > Yes, it is just that most emails I receive are sent through ISPs or from > commercial companies, and go through a bunch of internal relays. Although > completely standard, such direct emails are rare enough for me that I noticed… Spam is very often

Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Gedalya via Exim-users
On 3/14/23 03:12, Yves via Exim-users wrote: > Could it be that the message is signed when I receive it Try to run: exim -bV See if the output includes a line resembling -- Configuration file is /etc/exim4/exim4.conf Examine the file and look for lines containing "dkim_private_key", "dkim_sel

Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Gedalya via Exim-users
On 3/14/23 03:12, Yves via Exim-users wrote: > > opendkim-testmsg <./"Hey, what's up? - - 2023-03-12 2223.eml" > > which returned nothing, and $?==0. So the signature is valid! > > [root@seuil3 etc]# journalctl --grep 640E42D8.7020207 > mars 12 20:23:47 seuil3 spamd[522247]: spamd: checking messa

Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Gedalya via Exim-users
On 3/13/23 05:34, Yves via Exim-users wrote: > > I am surprised by a few things: > > — This email went through very few intermediaries to reach my server > (yalis.fr). Apparently, it actually came directly from the sender (a > Palestinian ISP). Why would that surprise you? They just did exactly

Re: [exim] who starts the delivery process?

2022-12-26 Thread Gedalya via Exim-users
On 12/26/22 18:08, Askhat Tokabay wrote: Do I understand correctly that the reception process start a delivery process? Yes, when immediate deliveries are done, which is the usual case. Sometimes exim will queue a message instead, and then no delivery attempt will be made until the next queue

Re: [exim] who starts the delivery process?

2022-12-26 Thread Gedalya via Exim-users
On 12/26/22 12:12, Askhat Tokabay via Exim-users wrote: Helo I found in the documentation: Delivery processes may be started as a result of a message’s arrival, by a queue runner process, or by an administrator using the -M option. The question is the following: Can you tell me who starts the de

Re: [exim] Idea: a retry which is more expansive, uses the set of mx hosts

2022-10-20 Thread Gedalya via Exim-users
On 10/21/22 05:07, Ian Kelling via Exim-users wrote: > Sorry for the long email here. Let me know if anything isn't clear. > > In the spec, 32.4 sending to a.b.c.example is retried to another mx > host. I've had yahoo return a temporary error which says roughly "don't > email any of our mx hosts fo

Re: [exim] tip: use -odf when calling exim from a systemd oneshot service

2022-06-14 Thread Gedalya via Exim-users
On 6/15/22 04:14, Ian Kelling via Exim-users wrote: > If calling exim is the last thing the service does, systemd will kill > off exim's background delivery process Try Type=forking (keep everything else the same) -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exi

Re: [exim] Blocking a Class C

2022-06-07 Thread Gedalya via Exim-users
On 6/7/22 14:37, Laura Williamson via Exim-users wrote: > are those 3 not supposed to resolve in DNS? None of them does in my end.. You prefix the IP address in reverse order to the domain. The query is e.g. 99.39.133.195.dnsbl-1.uceprotect.net. IN A to look up 195.133.39.99 If listed. the A re

Re: [exim] message has lines too long for transport

2022-05-31 Thread Gedalya via Exim-users
On 6/1/22 05:06, Randy Bush via Exim-users wrote: 2022-05-31 21:02:45 Exim configuration error in line 67 of /usr/local/etc/ex im/configure: main option "message_linelength_limit" unknown It's an option for the SMTP transport -- ## List details at https://lists.exim.org/mailman/l

Re: [exim] message has lines too long for transport

2022-05-31 Thread Gedalya via Exim-users
On 5/31/22 16:21, Odhiambo Washington via Exim-users wrote: > I checked https://github.com/Exim/exim/blob/master/doc/doc-txt/ChangeLog > and did not find it. https://github.com/Exim/exim/blob/master/doc/doc-txt/NewStuff#L48 https://www.exim.org/exim-html-current/doc/html/spec_html/ch-the_smtp_tra

Re: [exim] message has lines too long for transport

2022-05-30 Thread Gedalya via Exim-users
On 5/30/22 03:42, Jarland Donnell via Exim-users wrote: > This defaults to RFC spec which is 998 characters, but that's not where the > conversation should end. Absolutely no one out there is creating software > that adheres to the RFC standard. You can send an email from Outlook, > Roundcube, T

Re: [exim] Exim proxy / relay for disaster recovery for lost connectivity

2022-05-23 Thread Gedalya via Exim-users
On 5/23/22 21:02, Sebastian Arcus via Exim-users wrote: > but keeps the connection open until the final server accepts the message or > not https://www.exim.org/exim-html-current/doc/html/spec_html/ch-access_control_lists.html#SECTcontrols Look for: control = cutthrough_delivery Read thoroughly

Re: [exim] Routing instead of smarthost

2022-05-20 Thread Gedalya via Exim-users
On 5/20/22 22:05, R-VISOR-TOVIS wrote: > One more short question. > Is it enough if I save (now working as is) configuration from /etc/ecim4 ? I don't quite understand, sorry! :-) -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/ #

Re: [exim] Routing instead of smarthost

2022-05-20 Thread Gedalya via Exim-users
On 5/20/22 22:10, exim-users--- via Exim-users wrote: > I would check if it is possible to get rid of the smarthost style config > completely and configure as "internet site; mail is sent and received directly > using SMTP". Exim will lookup MX for outgoing mail in DNS and take care of > delivery

Re: [exim] Routing instead of smarthost

2022-05-20 Thread Gedalya via Exim-users
On 5/20/22 22:16, R-VISOR-TOVIS wrote: > > In Debian seems to be all configuration files (there are) for exim in the > directory > /etc/exim4 > Is it enough to save every thing from this directory, it would be enough to > restore the exim configuration? Almost enough. Other files that can affe

Re: [exim] Routing instead of smarthost

2022-05-20 Thread Gedalya via Exim-users
On 5/20/22 21:42, R-VISOR-TOVIS wrote: > Thank you for response! > > In /etc/exim4/passwd.client file I can place many rows? > >> a.smart.host:username:password >   b.smart.host:username:password >   c.smart.host:username:password Yes, you must in fact include an entry for every smarthost used. I

Re: [exim] Routing instead of smarthost

2022-05-20 Thread Gedalya via Exim-users
On 5/20/22 00:01, R-VISOR-TOVIS via Exim-users wrote: > Hi! > > I'm running exim 4.92-8+deb10u6 on Debian version 10.11 > Default configuration "smart_host" > > Unfortunately, with more and more restrictions in mailing systems I need to > address every emails to appropriate smtp server, not one "s

Re: [exim] help with syntax to disable AUTH on port 25

2022-02-26 Thread Gedalya via Exim-users
On 2/27/22 07:40, v via Exim-users wrote: {!eq {$tls_cipher}{}} AND ( {eq {$received_port}{465}} OR {eq {$received_po rt}{587}} OR connection is from localhost ) server_advertise_condition = ${if and { \ {!eq{$tls_cipher}{}} \ {or { \ {inlist {$received_port}

Re: [exim] getting exim to accept mail on a domain without an MX DNS record.

2021-11-20 Thread Gedalya via Exim-users
On 11/20/21 05:47, russellbell--- via Exim-users wrote: > 'They can not have MX records.' > Why not? If an SMTP server at the address handles mail... If, let's say, a new top level domain (TLD) is created which is numerical, and of a value in the range of 0..255, say 128. for example

Re: [exim] getting exim to accept mail on a domain without an MX DNS record.

2021-11-19 Thread Gedalya via Exim-users
On 11/19/21 14:53, russellbell--- via Exim-users wrote: > I'm trying to configure a domain that has never accepted mail > from external sources to start. The server runs exim, which I've > never used. I send a message to the domain using its IP, for example > fred@123.456.789.012. That is

Re: [exim] Outlook and Exim filter

2021-09-26 Thread Gedalya via Exim-users
On 9/24/21 21:07, Hung Pham via Exim-users wrote: > Hi. > > I have a filter likes this in /etc/system_filter.exim file > > if > $h_to: is "a...@mydomain.com" You might want to make that: foranyaddress $header_to: ( $thisaddress contains "a...@mydomain.com" ) or something like that. I think tha

Re: [exim] Please help me to understand the roles and purposes of an Exim Smarthost

2021-08-26 Thread Gedalya via Exim-users
On 8/26/21 9:47 PM, Turritopsis Dohrnii Teo En Ming via Exim-users wrote: > My boss said that the Exchange server in the same private internal > network was rejecting emails from the Linux server because the emails > were marked as spam. He told me I would need to configure Exim SMTP > server to re

Re: [exim] How to make that spamassassin rules take effect in exim

2021-08-19 Thread Gedalya via Exim-users
On 8/20/21 2:10 AM, Jorge Listas wrote: > After making the changes I just restart exim. Should I also restart > spamassassin or some other service? If the changes are to spamassassin rules / configuration, there is no reason to restart exim at all. If the rules are in files and are applying to

Re: [exim] How to make that spamassassin rules take effect in exim

2021-08-19 Thread Gedalya via Exim-users
On 8/19/21 11:02 PM, Jorge Listas via Exim-users wrote: > > Should I also restart spamassassin? I am not doing it because I have not > found spamassassin within running processes. > Should I restart it with "/etc/init.d/spamassassin restart" for it to take  > the rule changes? That's about right

Re: [exim] How to make that spamassassin rules take effect in exim

2021-08-19 Thread Gedalya via Exim-users
On 8/19/21 11:02 PM, Jorge Listas via Exim-users wrote: > In exim's configure file, the spamd_address instruction does not appear, so I  > interpret that it is using locale instance: > > spamd_address = 127.0.0.1 783 That is indeed the default value per the documentation. It might help if you al

Re: [exim] DKIM: validation error: LONG_LINE

2021-04-21 Thread Gedalya via Exim-users
On 4/22/21 5:39 AM, Wayne via Exim-users wrote: > On Thu, Apr 22, 2021 at 05:11:30AM +0800, Gedalya via Exim-users wrote: >> On 4/22/21 4:39 AM, Wayne via Exim-users wrote: >>> I'm still confused as it seems like EXIM should be signing based on just >>> headers cont

Re: [exim] DKIM: validation error: LONG_LINE

2021-04-21 Thread Gedalya via Exim-users
On 4/22/21 4:39 AM, Wayne via Exim-users wrote: > I'm still confused as it seems like EXIM should be signing based on just > headers content and not message body content What makes you say that? DKIM normally signs the header and the body. -- ## List details at https://lists.exim.org/mailman/l

Re: [exim] DKIM: validation error: LONG_LINE

2021-04-21 Thread Gedalya via Exim-users
On 4/22/21 3:37 AM, Wayne via Exim-users wrote: > On Wed, Apr 21, 2021 at 08:21:02PM +0100, Jeremy Harris via Exim-users wrote: >> On 21/04/2021 19:59, Wayne via Exim-users wrote: >>> 2021-04-21 14:34:48 1lZDwB-0003pb-TY DKIM: validation error: LONG_LINE >>> 2021-04-21 14:34:48 1lZDwB-0003pb-TY DKI

Re: [exim] System time correction during or after Exim startup affects queue time

2021-03-16 Thread Gedalya via Exim-users
On 3/16/21 10:13 PM, Matt Rubright via Exim-users wrote: Today, I discovered that NTP is stepping the time pretty significantly when the service starts on boot. Would this happen to be running under Xen HVM? When starting a new guest under Xen HVM, the time is apparently initialized from

Re: [exim] Exim authentication on port 465, 587

2021-02-07 Thread Gedalya via Exim-users
On 2/7/21 7:25 PM, Heiko Schlittermann via Exim-users wrote: > The `condition = … tls_cipher` can be omitted, if your authenticator > itself requires a secure connection, like in most examples. My advertise condition for the authenticator requires the port to be 587 or 465, and TLS. The conditio

Re: [exim] Exim authentication on port 465, 587

2021-02-07 Thread Gedalya via Exim-users
On 2/7/21 3:39 PM, Kevin Shell via Exim-users wrote: > Hello users list. > > How to make the Exim smtp server side > enforce AUTH command before MAIL command policy on ports 465, 587? > > -- > kevin > acl_smtp_rcpt = ${if ={25}{$received_port} {acl_check_rcpt} {acl_check_rcpt_submit} } acl_chec

Re: [exim] Exim authentication on port 465, 587

2021-02-07 Thread Gedalya via Exim-users
On 2/7/21 4:20 PM, Gedalya wrote: > before MAIL command If you mean that literally then of course just use acl_smtp_mail instead of acl_smtp_rcpt -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/ ## Please use the Wiki with this li

Re: [exim] autoreply once on multiple systems

2021-01-28 Thread Gedalya via Exim-users
On 1/29/21 1:01 AM, Cyborg via Exim-users wrote: > In this case, you will need a central sql database that stores the sender and > receiver with a timestamp and if your acl finds an entry within your given  > timeframe, > will need redirect the message to :blackhole: It might be simpler to just

Re: [exim] Getting duplicate deliveries with redirect router

2020-12-01 Thread Gedalya via Exim-users
On 11/12/20 6:55 AM, Gedalya via Exim-users wrote: > Hi, > > When user1 sends a message to user2 and user3, and user3 also gets generated > *twice* by a redirect router, user3 ends up getting the message twice. > > bcc: >   debug_print = "R: bcc for $local_part@$dom

[exim] Getting duplicate deliveries with redirect router

2020-11-13 Thread Gedalya via Exim-users
Hi, When user1 sends a message to user2 and user3, and user3 also gets generated *twice* by a redirect router, user3 ends up getting the message twice. I've created a simplified config that seems to reproduce the core of the issue I'm having on a more complex system. I would like to see the re

Re: [exim] Exim as a backup MX server

2020-04-08 Thread Gedalya via Exim-users
On 4/8/20 4:33 AM, Andrew C Aitchison via Exim-users wrote: > > Exim does recipient callouts and cutthrough delivery. > Are either of these useful for an MX backup ? Callout caching can be potentially useful when the primary is down. Not a complete solution of course. -- ## List details at ht

Re: [exim] DKIM signing

2020-02-11 Thread Gedalya via Exim-users
Here is my simple line folding filter. Going with getc() is a lot simpler but this way seems faster and it was fun to play around with. And it seems to work. This will break long lines exactly at the specified length without regard to whitespace. In the header, a tab (\t) is added after added n

Re: [exim] DKIM signing

2020-02-06 Thread Gedalya via Exim-users
On 2/6/20 7:56 PM, Jeremy Harris via Exim-users wrote: > Exim does not reformat messages, as a matter of policy. I'm aware of that and have been following the conversations surrounding this topic. I didn't intend to suggest that exim should provide a line-wrapping facility. Rather I was referri

Re: [exim] DKIM signing

2020-02-06 Thread Gedalya via Exim-users
On 2016-08-06 21:36, Jeremy Harris wrote: > > Having just gone to look at the code, DKIM requires line-aware > processing of the body being signed, to implement the requirements > on empty- and whitespace-only- lines. The implementation currently > implements this by buffering a full line. > > Han

Re: [exim] SRS still experimental?

2019-10-03 Thread Gedalya via Exim-users
On 10/2/19 9:11 PM, Cyborg via Exim-users wrote: Does anyone have this running? Yes. (I contributed that documentation after implementing it in a live environment). Does it work in dynamic multi-domain environments? Yes. In fact I find that this fits into exim better than it does into postf

Re: [exim] SRS still experimental?

2019-10-02 Thread Gedalya via Exim-users
On 10/2/19 4:03 PM, Kai Bojens via Exim-users wrote: > Is there any chance that SRS[1] moves from "experimental" to "stable and > activated by default" any time soon? I'm just asking because I prefer > to use distribution provided packages instead of compiling exim by > myself every second month. >