[pfx] python-policyd-spf and whitelisting

2023-10-13 Thread Alex via Postfix-users
Hi, I'm using python-policyd-spf with postfix as a check_policy_service and having some trouble with domains very broadly being whitelisted. My policy is to reject on mailfrom fail. However, we have few domains that need to be whitelisted, like mycuservices.com, because they are sending from an

[pfx] Re: SMTP Require TLS Option?

2023-10-13 Thread John Levine via Postfix-users
It appears that Viktor Dukhovni via Postfix-users said: >Postfix supports DANE, but there's no MTA-STS support. And I've not >seen much by way of receiving MTAs advertising REQUIRETLS as a >capability I did a proof of concept implementation that advertises REQUIRETLS and then ignores it. As

[pfx] Re: SMTP Require TLS Option?

2023-10-13 Thread Wietse Venema via Postfix-users
Joachim Lindenberg via Postfix-users: > Hello, > > are there any ideas or plans to implement SMTP Require TLS Option (RFC 8689) > in postfix? It is not on the calendar. Below is a preliminary analysis of the implementation effort. Rumor has it that there was a preliminary implementation for

[pfx] Re: SMTP Require TLS Option?

2023-10-13 Thread Viktor Dukhovni via Postfix-users
On Fri, Oct 13, 2023 at 11:53:06AM +0200, Joachim Lindenberg via Postfix-users wrote: > Are there any ideas or plans to implement SMTP Require TLS Option (RFC > 8689) in postfix? No current plans. The most viable and useful part of the RFC is the part that allows a message to *opt out* of

[pfx] SMTP Require TLS Option?

2023-10-13 Thread Joachim Lindenberg via Postfix-users
Hello, are there any ideas or plans to implement SMTP Require TLS Option (RFC 8689) in postfix? I am aware of that in order to really leverage that, one needs a MUA using it, plus a MTA supporting SMTP-DANE (RFC 7672) or MTA-STS (RFC 8461), but sure I may be missing something. Thanks,