Re: Rewrite recipient when an email is received from a specific sender

2022-04-04 Thread Alexandre Ellert
à 11:17, Alexandre Ellert a écrit : > Hi, > > I have a Postfix inbound MX relay and I'd like to rewrite the recipient(s) > to a single fixed email address but only when the email is sent from a > specific sender. > > Can you please tell me the way to do this ? > > Thanks a lot. > > Alexandre >

Rewrite recipient when an email is received from a specific sender

2022-04-04 Thread Alexandre Ellert
Hi, I have a Postfix inbound MX relay and I'd like to rewrite the recipient(s) to a single fixed email address but only when the email is sent from a specific sender. Can you please tell me the way to do this ? Thanks a lot. Alexandre

Re: Test DANE

2016-06-06 Thread Alexandre Ellert
> Le 6 juin 2016 à 16:46, Viktor Dukhovni a écrit : > > On Mon, Jun 06, 2016 at 03:58:51PM +0200, Alexandre Ellert wrote: > >> I�ve juste enable DANE and https://dane.sys4.de <https://dane.sys4.de/> >> is green when I test my domain numeezy.com <http://num

Test DANE

2016-06-06 Thread Alexandre Ellert
Hello, I’ve juste enable DANE and https://dane.sys4.de is green when I test my domain numeezy.com . Also postfix SMTP client says "Verified TLS connection established to mail-in-1.numeezy.com[188.165.154.163]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-

Rewrite enveloppe From and headers From (only)

2016-02-11 Thread Alexandre Ellert
Hello, I use Postfix as a SMTP mail relay for our web servers to send notifications email. This Postfix relay is also configured to relay through our Google Apps relay (and this one only accept email from our GApps domain) So, I want Postfix to rewrite enveloppe From and header From to a unique

Re: Different message size per domain

2015-08-24 Thread Alexandre Ellert
> Le 22 août 2015 à 15:46, Viktor Dukhovni a écrit > : > > Is the policy service check in "smtpd_recipient_restrictions", in > "smtpd_end_of_data_restrictions" or both? The policy server is called at smtpd_end_of_data_restrictions stage. > The message size is not always known at "RCPT TO" time

Different message size per domain

2015-08-22 Thread Alexandre Ellert
Hello, I have two Postfix inbound servers which serve multiple domain and I'd like to accept 20 Mb email for all domain except one (I want 10 Mb limit for this one). In main.cf I set message_size_limit = 20971520 and I use a policy server (postfwd) to check the recipient and the mail size. I con

Re: Get a copy of email sent by null sender

2015-07-21 Thread Alexandre Ellert
> Le 20 juil. 2015 à 12:46, Wietse Venema a écrit : > > Alexandre Ellert: >> Hello, >> >> I often use sender_bcc_maps to audit suspicious account and it works great. >> Today, I need to have a look at email sent by null sender <> >> >>

Get a copy of email sent by null sender

2015-07-20 Thread Alexandre Ellert
Hello, I often use sender_bcc_maps to audit suspicious account and it works great. Today, I need to have a look at email sent by null sender <> Here is my relevant configuration : # grep sender_bcc_maps /etc/postfix/main.cf sender_bcc_maps = regexp:/etc/postfix/sender_bcc_maps # cat /etc/postf

Re: need to change behavior when remote MTA says reject

2015-07-09 Thread Alexandre Ellert
> Le 9 juil. 2015 à 22:04, Robert Wolfe a écrit : > > Retrieve a listing of what? > A list of all blocked senders, i.e, email adresses that were added by end users using Junk -> Block Sender action I quickly read that a PowerShell command exist (Get-MailboxJunkEmailConfiguration) to list bloc

Re: need to change behavior when remote MTA says reject

2015-07-09 Thread Alexandre Ellert
> Le 9 juil. 2015 à 20:09, Viktor Dukhovni a écrit > : > > On Thu, Jul 09, 2015 at 07:43:17PM +0200, Alexandre Ellert wrote: > >> I have an inbound MX in front of an Exchange Server and I?d like to DISCARD >> email when Exchange answer "554 5.1.0 Sender Denie

need to change behavior when remote MTA says reject

2015-07-09 Thread Alexandre Ellert
Hello, I have an inbound MX in front of an Exchange Server and I’d like to DISCARD email when Exchange answer "554 5.1.0 Sender Denied" (and avoid backscatter) Is it possible to do something like that with Postfix ? Thank you for help Alexandre

Re: How to allow each user on an Ubuntu server use his/her google email and password to send the email via google smtp?

2015-03-18 Thread Alexandre Ellert
Le 18 mars 2015 à 11:19, Peng Yu a écrit : > Does anybody know a simplest solution to send emails via gmail on command > line (no receiving emails needed)? Yes, have a look at msmtp. It has TLS support, can do SMTP authentication and works perfectly with gmail.

Re: prevent certain email from ending in defer queue

2014-10-29 Thread Alexandre Ellert
Le 29 oct. 2014 à 15:49, Noel Jones a écrit : > I assume you're talking about unidentified spam delivered to an > over-quota mailbox. Intentionally bouncing spam, such as a with an > after-queue or delivery time spam filter, is a very bad idea and > will eventually get you blacklisted as a back

Re: Rate limiting users?

2014-09-24 Thread Alexandre Ellert
Hello, You should have a look at this postfix policy server : http://postfwd.org Le 24 sept. 2014 18:46, "LuKreme" a écrit : > Not sure if this is even a postfix question, but let's say for the sake of > argument I want to set the following limits for user accounts: > > 1) maximum 100 mails in x

Re: Allow only my servers to send mail from my domain

2014-08-05 Thread Alexandre Ellert
Hello, You should have a look at DMARC. If you announce a reject policy in your DNS and configure opendmarc milter on your inbound MX, that will do what you want. Alexandre Quoting Andre Luiz Paiz : Quoting DTNX Postmaster : On 04 Aug 2014, at 19:25, Andre Luiz Paiz wrote: I´m receiving some

Sender Rewrite Scheme : bounce back to the original sender

2014-06-26 Thread Alexandre Ellert
Hello, Some of our users are using forward to get a copy of their emails in a third party mailbox (gmail, yahoo, …). That’s why I have implemented the Sender Rewrite Scheme to be SPF compliant in that case. But the solution I have is actually half working and I have some problem when he final d

Re: canonical and milter

2014-04-28 Thread Alexandre Ellert
Le 28 avr. 2014 à 08:33, Christian Rößner a écrit : > > Does it mean I can not do canonicalization with Postfix when using milters? > > The only solution I see is to forward mail to a second Postfix instance, > after mail has passed milters. And that second instance would do canonical. > But

Re: prepend header by policy server, action taken in milter

2014-04-22 Thread Alexandre Ellert
2014-04-22 9:35 GMT+02:00 Andreas Schulze : > also consider using a milter based SPF checker. Lock at the opendmarc-users > archive for suggestions. > > Andreas I already tried with a SPF milter but the result is the same. Do you have working implementation with a milter ? If so, does this milter

Re: prepend header by policy server, action taken in milter

2014-04-21 Thread Alexandre Ellert
> For bizarre Sendmail compatibility reasons, Milters don't see the > first header in the message. Changing that would cost me at least > a day to ensure that it breaks nothing with "add header", "delete > header", etc. requests. > > Wietse Thanks for your prompt answer. I'm going to test

prepend header by policy server, action taken in milter

2014-04-21 Thread Alexandre Ellert
Hello, I have a policy server which do SPF verification at smtpd_recipient_restrictions stage and prepend a header. For exemple : spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=209.85.128.179; helo=mail-ve0-f179.google.com; envelope-from=[hidden]@gmail.com; receiver=[hidden]@n

Limit number of Cci recipient

2014-03-17 Thread Alexandre Ellert
Hello, Some of our customers have bad malling practices and I want to limit the max number of Cci recipient. I already use smtpd_recipient_limit but I would like to use a lower value for Cci. Do you know how can I achieve this using Postfix ? Thanks. Alexandre

mail forwarding loop exploit

2014-02-25 Thread Alexandre Ellert
Hello, I have a working setup with a dedicated MX inbound which deliver via transport to a postfix / dovecot backend server. I found some mail, probably with forged "Delivered-To" header that make the backend bounce with "mail forwarding loop" Here is the log of the backend : Feb 25 05:19:37

Re: avoid outgoing mail sent to unknown users

2014-01-12 Thread Alexandre Ellert
> but that *does not* help in case of the OP > read the thread start > > it is simply impossible doing on one hand RCPT-verification because > no verification on the root-cause (webserver) but at the same time > not reject messages from the webserver in case verification on the > final destination

Re: avoid outgoing mail sent to unknown users

2014-01-10 Thread Alexandre Ellert
> I made more tests and greylisting is still a problem. > > I've tried with : > unverified_recipient_tempfail_action = permit > in main.cf > > But I got : > fatal: bad configuration > in mail.log > > How can I tell Postfix to queue the mail in case of remote reply 4xx ? > I answer to myself, i

Re: avoid outgoing mail sent to unknown users

2014-01-10 Thread Alexandre Ellert
> Wietse : > If the remote SMTP server uses greylisting, then the address > verification result will be "don't know" (*) and the Postfix SMTP server > will reply with 4xx (unless you configure Postfix otherwise). > > Wietse > (*) The Postfix SMTP client does not distiunguish between differen

Re: avoid outgoing mail sent to unknown users

2014-01-10 Thread Alexandre Ellert
> Wietse : > If the remote SMTP server uses greylisting, then the address > verification result will be "don't know" (*) and the Postfix SMTP server > will reply with 4xx (unless you configure Postfix otherwise). > > Wietse > (*) The Postfix SMTP client does not distiunguish between differe

Re: avoid outgoing mail sent to unknown users

2014-01-10 Thread Alexandre Ellert
> This works like a charm. > > One last thing, concerning order of smtpd_recipient_restrictions, I currently > have this in master.cf : > > submission inet n - - - - smtpd > ... > -o > smtpd_recipient_restrictions=permit_mynetworks,permit_sasl_authenticated,reject

Re: avoid outgoing mail sent to unknown users

2014-01-10 Thread Alexandre Ellert
> Wietse : > In that case use: > > /etc/postfix/main.cf: >smtpd_recipient_restrictions = >... >check_sender_access hash:/etc/postfix/sender_access >... > > /etc/postfix/sender_access: >x...@example.com reject_unverified_recipient >example.net reject_unverif

Re: avoid outgoing mail sent to unknown users

2014-01-10 Thread Alexandre Ellert
> Wietse : > You can push the problem back to the webservers, by using the the > Postfix SMTP server's "reject_unverified_recipient" feature. > > With this, Postfix will make one connection for the recipient > address, and then the Postfix SMTP server answers with 5XX to the > web application when

avoid outgoing mail sent to unknown users

2014-01-09 Thread Alexandre Ellert
Hi, I relay transactional mail for my customer's web sites. Each website has it's own SASL authenticated account and mail are sent via submission or smtps. But, some website doesn't verify email existence when a user submit a web form or 'create an account'. That's why I often see my postfix r

Re: sign auto-reply vacation with OpenDKIM

2013-10-20 Thread Alexandre Ellert
Right now, I added : main.cf non_smtpd_milters = inet:localhost:8891 master.cf (avoid double skim signature after amavis check) 127.0.0.1:10025 inet n - n - - smtpd -o receive_override_options=no_milters I can confirm that auto-reply vacation and mail sent by /usr/sbin/sendmail command li

Re: sign auto-reply vacation with OpenDKIM

2013-10-19 Thread Alexandre Ellert
is:[127.0.0.1]:10024 sender_transport : @domain1.com out_domain1: @domain2.com out_domain2: Let me know if you need more information and thanks for your precious advices. Alexandre Le 18/10/2013 23:25, Viktor Dukhovni a écrit : > On Fri, Oct 18, 2013 at 10:49:33PM +0200, Alexandre Eller

sign auto-reply vacation with OpenDKIM

2013-10-18 Thread Alexandre Ellert
Hi, in MILTER_README : "Postfix currently does not apply content filters to mail that is forwarded or aliased internally, or to mail that is generated internally such as bounces or Postmaster notifications. This may be a problem when you want to apply a signing Milter to such mail" So, can