[pfx] Re: non_smtpd relayhost ?

2024-06-21 Thread Geert Hendrickx via Postfix-users
On Fri, Jun 21, 2024 at 16:22:24 -0400, Wietse Venema wrote: > Locally-generated bounces are generated by the Postfix bounce > daemon which talks to a cleanup service to queue a message. > One could run bounce daemons with a cleanup_service override > in master.cf: Thanks Wietse, that makes sens

[pfx] Re: non_smtpd relayhost ?

2024-06-21 Thread Wietse Venema via Postfix-users
Geert Hendrickx via Postfix-users: > Hi > > We have few different sets of Postfix mailservers with different roles; > inbound servers, outbound servers that DKIM sign outgoing mail with a > milter, and some other servers that just relay mail that is already signed > elsewhere. > > The first and t

[pfx] non_smtpd relayhost ?

2024-06-21 Thread Geert Hendrickx via Postfix-users
Hi We have few different sets of Postfix mailservers with different roles; inbound servers, outbound servers that DKIM sign outgoing mail with a milter, and some other servers that just relay mail that is already signed elsewhere. The first and third types of mailservers don't need to sign mail p

[pfx] Re: question for a directive in master.cf

2024-06-21 Thread Jan Ceuleers via Postfix-users
On 21/06/2024 13:06, Jeff Peng via Postfix-users wrote: > >> If you want to enable them, you have to uncomment ALL lines for >> submission >> service to work correctly. > > just further, for smtps service, can i just comment out all of options > to enable it? > > #smtps inet  n   -   y 

[pfx] Re: question for a directive in master.cf

2024-06-21 Thread Jaroslaw Rafa via Postfix-users
Dnia 21.06.2024 o godz. 19:06:38 Jeff Peng via Postfix-users pisze: > > >If you want to enable them, you have to uncomment ALL lines for > >submission > >service to work correctly. > > just further, for smtps service, can i just comment out all of > options to enable it? Yes, you should. -- Reg

[pfx] Re: SPF hostname and domainname

2024-06-21 Thread Wietse Venema via Postfix-users
Peter via Postfix-users: > On 21/06/24 07:13, Wietse Venema via Postfix-users wrote: > > Bounces are sent with the null envelope.from address which has no > > domain. Therefore, SPF applies policy to a surrogate: the hostname > > in the SMTP client's HELO/EHLO command (as if the envelope.from > > a

[pfx] Re: SPF hostname and domainname

2024-06-21 Thread Peter via Postfix-users
On 21/06/24 23:10, Matus UHLAR - fantomas via Postfix-users wrote: Peter via Postfix-users skrev den 2024-06-21 08:45: SPF/DKIM/DMARC Checklist for (IMO) the best chance of getting your mail to be accepted: 1.  HELO banner should pass SPF. 2.  Envelope Sender should pass SPF. 3.  Envelope Se

[pfx] Re: question for a directive in master.cf

2024-06-21 Thread Matus UHLAR - fantomas via Postfix-users
On 21.06.24 17:07, Jeff Peng via Postfix-users wrote: I have changed the setting for submission to: submission inet n - y - - smtpd # -o syslog_name=postfix/submission better uncomment this one as well, you should know how the mail was sent without reading firew

[pfx] Re: SPF hostname and domainname

2024-06-21 Thread Peter via Postfix-users
On 21/06/24 21:49, Jaroslaw Rafa via Postfix-users wrote: Dnia 21.06.2024 o godz. 18:45:15 Peter via Postfix-users pisze: SPF/DKIM/DMARC Checklist for (IMO) the best chance of getting your mail to be accepted: 1. HELO banner should pass SPF. 2. Envelope Sender should pass SPF. 3. Envelope

[pfx] Re: SPF hostname and domainname

2024-06-21 Thread Matus UHLAR - fantomas via Postfix-users
Peter via Postfix-users skrev den 2024-06-21 08:45: SPF/DKIM/DMARC Checklist for (IMO) the best chance of getting your mail to be accepted: 1. HELO banner should pass SPF. 2. Envelope Sender should pass SPF. 3. Envelope Sender domain should align with the From: header domain. 4. Message

[pfx] Re: question for a directive in master.cf

2024-06-21 Thread Jeff Peng via Postfix-users
If you want to enable them, you have to uncomment ALL lines for submission service to work correctly. just further, for smtps service, can i just comment out all of options to enable it? #smtps inet n - y - - smtpd # -o syslog_name=postfix/smtps # -o s

[pfx] Re: discard message

2024-06-21 Thread Matus UHLAR - fantomas via Postfix-users
On 20.06.24 22:00, Benny Pedersen via Postfix-users wrote: header checks in postfix is done before content filters, so you would love to reject spam on base of remote spammers own clasificaton ? :) that's why we have milter_header_checks - they work after milter. same reason that spamassassin

[pfx] Re: question for a directive in master.cf

2024-06-21 Thread Jeff Peng via Postfix-users
If you want to enable them, you have to uncomment ALL lines for submission service to work correctly. That's good idea. Thanks Rafa. ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@po

[pfx] Re: question for a directive in master.cf

2024-06-21 Thread Jaroslaw Rafa via Postfix-users
Dnia 21.06.2024 o godz. 07:54:40 Jeff Peng via Postfix-users pisze: > for these options for submission in master.cf: > > submission inet n - y - - smtpd > # -o syslog_name=postfix/submission > # -o smtpd_tls_security_level=encrypt > -o smtpd_sasl_auth_enable=yes >

[pfx] Re: SPF hostname and domainname

2024-06-21 Thread Jaroslaw Rafa via Postfix-users
Dnia 21.06.2024 o godz. 18:45:15 Peter via Postfix-users pisze: > SPF/DKIM/DMARC Checklist for (IMO) the best chance of getting your > mail to be accepted: > > 1. HELO banner should pass SPF. > > 2. Envelope Sender should pass SPF. > > 3. Envelope Sender domain should align with the From: hea

[pfx] Re: question for a directive in master.cf

2024-06-21 Thread Jeff Peng via Postfix-users
The default value is "no", as expected. $ postconf -d smtpd_sasl_auth_enable smtpd_sasl_auth_enable = no Best practice is to enable SASL auth only on the submission ports and NOT on port 25. I have changed the setting for submission to: submission inet n - y -

[pfx] Re: SPF hostname and domainname

2024-06-21 Thread Benny Pedersen via Postfix-users
Peter via Postfix-users skrev den 2024-06-21 08:45: On 21/06/24 07:13, Wietse Venema via Postfix-users wrote: SPF/DKIM/DMARC Checklist for (IMO) the best chance of getting your mail to be accepted: 1. HELO banner should pass SPF. 2. Envelope Sender should pass SPF. 3. Envelope Sender do