Lost connection after DATA and queue IDs

2014-06-19 Thread Alvaro Marín
Hello, one question about connection errors...for example: Jun 19 08:43:37 postfix/smtpd[26460]: connect from unknown[x] Jun 19 08:43:46 postfix/smtpd[26460]: 7EAD855B8355: client=unknown[x] Jun 19 08:43:55 postfix/smtpd[26460]: lost connection after DATA (17 bytes) from unknown[x] Jun 19

Re: Lost connection after DATA and queue IDs

2014-06-19 Thread Viktor Dukhovni
On Thu, Jun 19, 2014 at 09:06:34AM +0200, Alvaro Mar?n wrote: Jun 19 08:43:37 postfix/smtpd[26460]: connect from unknown[x] Jun 19 08:43:46 postfix/smtpd[26460]: 7EAD855B8355: client=unknown[x] Jun 19 08:43:55 postfix/smtpd[26460]: lost connection after DATA (17 bytes) from unknown[x] Jun

Re: Lost connection after DATA and queue IDs

2014-06-19 Thread Alvaro Marín
El 19/06/14 09:24, Viktor Dukhovni escribió: On Thu, Jun 19, 2014 at 09:06:34AM +0200, Alvaro Mar?n wrote: Jun 19 08:43:37 postfix/smtpd[26460]: connect from unknown[x] Jun 19 08:43:46 postfix/smtpd[26460]: 7EAD855B8355: client=unknown[x] Jun 19 08:43:55 postfix/smtpd[26460]: lost connection

Re: Regarding reject_authenticated_sender_login_mismatch domain matching

2014-06-19 Thread Wietse Venema
Vytenis Sabaliauskas: [ Charset UTF-8 unsupported, converting... ] Hello everybody, I'm struggling to stop abusing SASL usernames. My idea is to allow any particular SASL username send only from his domain, that is u...@example.com can send from anyth...@example.com, but not from

Re: Regarding reject_authenticated_sender_login_mismatch domain matching

2014-06-19 Thread D'Arcy J.M. Cain
On Thu, 19 Jun 2014 08:17:49 +0300 Vytenis Sabaliauskas vytenis.sabaliaus...@gmail.com wrote: I'm struggling to stop abusing SASL usernames. My idea is to allow any particular SASL username send only from his domain, that is u...@example.com can send from anyth...@example.com, but not from

blocking spam IP with netfitler good idea or not ?

2014-06-19 Thread Giuseppe De Nicolo'
Hi, I have a question for you more experienced admin , I have some good abuse on my servers by IP listed in spam list , since I am using postscreen to block those all is good , anyway I thought then a good idea to just drop that traffic and avoid myself thousand of log line with 450

Re: blocking spam IP with netfitler good idea or not ?

2014-06-19 Thread Birta Levente
On 19/06/2014 16:57, Giuseppe De Nicolo' wrote: Hi, I have a question for you more experienced admin , I have some good abuse on my servers by IP listed in spam list , since I am using postscreen to block those all is good , anyway I thought then a good idea to just drop that traffic

Re: blocking spam IP with netfitler good idea or not ?

2014-06-19 Thread Jeffrey 'jf' Lim
On Thu, Jun 19, 2014 at 10:04 PM, Birta Levente blevi.li...@gmail.com wrote: On 19/06/2014 16:57, Giuseppe De Nicolo' wrote: Hi, I have a question for you more experienced admin , I have some good abuse on my servers by IP listed in spam list , since I am using postscreen to block

Re: Regarding reject_authenticated_sender_login_mismatch domain matching

2014-06-19 Thread Larry Stone
On Thu, 19 Jun 2014, D'Arcy J.M. Cain wrote: On Thu, 19 Jun 2014 08:17:49 +0300 Vytenis Sabaliauskas vytenis.sabaliaus...@gmail.com wrote: I'm struggling to stop abusing SASL usernames. My idea is to allow any particular SASL username send only from his domain, that is u...@example.com can

Re: Regarding reject_authenticated_sender_login_mismatch domain matching

2014-06-19 Thread D'Arcy J.M. Cain
On Thu, 19 Jun 2014 09:23:45 -0500 (CDT) Larry Stone lston...@stonejongleux.com wrote: On Thu, 19 Jun 2014, D'Arcy J.M. Cain wrote: I don't know how to do that but I wonder why you want to. The whole point of authentication is to allow your users to get email without having to trust the

Re: [OT] Re: Before rushing into writing my own policy daemon for postfix, what are the options?

2014-06-19 Thread Eliezer Croitoru
On 06/16/2014 01:09 PM, li...@rhsoft.net wrote: the point is relaying via the foreign domain's MSA service thats why sender_dependent_relayhost_maps exists in postfix we do the same and feed sender_dependent_relayhost_maps as well as local_recipient_maps and smtpd_sender_login_maps from

Re: blocking spam IP with netfitler good idea or not ?

2014-06-19 Thread Eliezer Croitoru
You can implement a RBL system to share with others. Eliezer On 06/19/2014 05:23 PM, Jeffrey 'jf' Lim wrote: I sort of do this myself... except I dont use automated stuff like fail2ban. When I see a pattern, I investigate, and if it comes down to a known (or somewhat known) spammer-hosting or

Fwd: 2 emails per minute on Postfix

2014-06-19 Thread EyeLand
Hi, on virtual server Debian, I installed Postfix and Mailman, I need to set up to sending 2 emails per minute on mail server, can advise how can I do that? I found in Webmin - Services - Configuring Postfix - Edit Config Files string smtpd_client_message_rate_limit = 2 does this mean that in a

Re: 2 emails per minute on Postfix

2014-06-19 Thread li...@rhsoft.net
Am 19.06.2014 17:53, schrieb EyeLand: Hi, on virtual server Debian, I installed Postfix and Mailman, I need to set up to sending 2 emails per minute on mail server, can advise how can I do that? I found in Webmin - Services - Configuring Postfix - Edit Config Files string

Re: Fwd: 2 emails per minute on Postfix

2014-06-19 Thread Viktor Dukhovni
On Thu, Jun 19, 2014 at 06:53:21PM +0300, EyeLand wrote: Hi, on virtual server Debian, I installed Postfix and Mailman, I need to set up to sending 2 emails per minute on mail server, can advise how can I do that? This description of your goal is too cryptic. Can you explain this in a couple

Re: Lost connection after DATA and queue IDs

2014-06-19 Thread Viktor Dukhovni
On Thu, Jun 19, 2014 at 09:51:39AM +0200, Alvaro Mar?n wrote: The problem is that there is no way to see what has happened with an email searching the queue ID in the logs (in scripts or apps to trace emails, for example). It would be usefull add that queue ID to the lost connection error,

Re: Lost connection after DATA and queue IDs

2014-06-19 Thread Paul C
Just scanning this thread, are you seeing the mail is actually failing or is the log just concerning you? I had a similar issue not too long ago that sounds like it could be the same issue, where there's no obvious problem but you get an smtp error at different parts of the injection process,

Re: Lost connection after DATA and queue IDs

2014-06-19 Thread Wietse Venema
Viktor Dukhovni: On Thu, Jun 19, 2014 at 09:51:39AM +0200, Alvaro Mar?n wrote: The problem is that there is no way to see what has happened with an email searching the queue ID in the logs (in scripts or apps to trace emails, for example). It would be usefull add that queue ID to the lost

Re: Regarding reject_authenticated_sender_login_mismatch domain matching

2014-06-19 Thread Vytenis Sabaliauskas
Perhaps I have expressed it wrong. Many of our users use alias'es as FROM, office scanners, scripts, etc. I have implemented this solution in our legacy systems. Limiting to a domain had a lower impact. Most of leaked SMTP credentials use spoofed senders ( telekom.de, gmail.com, etc.). This