Re: Postfix still rejecting with 450 while I have 550 in unverified_recipient_reject_code ?

2019-05-20 Thread Matus UHLAR - fantomas
/postfix_sender_address_verification.shtml - Original Message - From: "Matus UHLAR - fantomas" To: "postfix-users" Sent: Monday, May 20, 2019 9:01:56 AM Subject: Re: Postfix still rejecting with 450 while I have 550 in unverified_recipient_reject_code ? On 20.0

Re: Postfix still rejecting with 450 while I have 550 in unverified_recipient_reject_code ?

2019-05-20 Thread Matus UHLAR - fantomas
= yes. Also, if there is a temporary DNS problem, Postfix automatically converts permanent errors to temporary ones. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: tlsproxy without port-220 tests?

2019-05-09 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: Seems that I assumed too much, e.g. that since TLS isn't mandatory on SMTP port, starttls and thus tlsproxy isn't important. Perhaps starttls could be avoided by setting: postscreen_discard_ehlo_keywords = starttls On 09.05.19 13:34, Wietse Venema wrote: That would

Re: tlsproxy without port-220 tests?

2019-05-09 Thread Matus UHLAR - fantomas
>Matus UHLAR - fantomas: >> does it make sense to run tlsproxy when post-220 tests are not run? On 03.05.19 12:40, Wietse Venema wrote: >tlsproxy is required when: > >- postscreen: always when the server announces STARTTLS. > >- smtp client: always when connection

Re: tlsproxy without port-220 tests?

2019-05-09 Thread Matus UHLAR - fantomas
On 03.05.19 12:40, Wietse Venema wrote: Matus UHLAR - fantomas: does it make sense to run tlsproxy when post-220 tests are not run? tlsproxy is required when: - postscreen: always when the server announces STARTTLS. - smtp client: always when connection reuse for TLS is enabled

tlsproxy without port-220 tests?

2019-05-03 Thread Matus UHLAR - fantomas
Hello, does it make sense to run tlsproxy when post-220 tests are not run? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fucking

Re: limiting content_filter concurrency (ask for advice)

2019-05-03 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: if I didn't set amavisfeed_destination_concurrency_limit, the queue manager would try connect to amavisfeed up to default_destination_concurrency_limit (20) times, until it failed, so effectively it should work the same, correct? On 02.05.19 13:55, Wietse Venema wrote

Re: limiting content_filter concurrency (ask for advice)

2019-05-02 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: I use amavisd-new as content filter on a few mailservers. main.cf: content_filter=amavisfeed:[127.0.0.1]:10024 master.cf: amavisfeed unix- - n - 5 lmtp servers have different number of CPUs and I'd like to avoid overloading them

limiting content_filter concurrency (ask for advice)

2019-05-02 Thread Matus UHLAR - fantomas
mails being checked in parallel. I can limit those by configuring "maxproc" in master.cf or amavisfeed_destination_concurrency_limit in main.cf. Any recommendations for using either one? Thanks -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: How "safe" is reject_unknown_helo_hostname?

2019-04-28 Thread Matus UHLAR - fantomas
e (e.g. my own system's valid hostnames and IPs, *.local, etc.) having local host name there (REJECT) could help much, at least here many spambots in the past have used my hostname trying to spam me. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT

Re: unable to find user

2019-04-27 Thread Matus UHLAR - fantomas
get that error with the username of "john" while mail to jsmith goes through fine. Is it possible to send the user name to the milter after virtual maps have been applied? spamass-milter has the "-x" option which should do just what you want. I just haven't tested

Re: How "safe" is reject_unknown_helo_hostname?

2019-04-26 Thread Matus UHLAR - fantomas
elo_access hash:/etc/postfix/check_helo_access Oddly enough, I have only ever had to whitelist root@mail ~ # cat /etc/postfix/check_helo_access fwd-out.cmp.livemail.co.uk OK The same here (multiple servers). Rarely need it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/

Re: Inserting a Text inside body message

2019-04-26 Thread Matus UHLAR - fantomas
It may be acceptable when your server is used for initial submission, otherwise better don't do that. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu post

Re: postscreen pregreet still testing dnsbl

2019-04-21 Thread Matus UHLAR - fantomas
results ? if the results are in cache, yes. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux is like a teepee: no Windows, no Gates

Re: How to allow the milter first access to recipients?

2019-04-18 Thread Matus UHLAR - fantomas
is sent back. the common behaviour is to reject the recipient/mail in which case sending bounce is up to the mail client. Abusers won't bounce. discarding the e-mail may be fine instead, but only for valid recipients. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I

Re: Misconfiguration and documentation clarification help

2019-04-18 Thread Matus UHLAR - fantomas
e program continue (having logged that parameter value was unacceptable) than refuse to operate at all. You apparently want postfix to work even if it's clearly misconfigured. Well, you can patch it locally then. and then deal with consequences. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I don't have lysdexia. The Dog wouldn't allow that.

Re: LMTP not working

2019-04-16 Thread Matus UHLAR - fantomas
" in the system. you should configure postfix to look at dovecot's virtual address database, so it knows which users exist and which do not. Look at: http://www.postfix.org/VIRTUAL_README.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receiv

Re: I need some help with the correct value for myhostname in main.cf

2019-04-08 Thread Matus UHLAR - fantomas
, different view explained. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Remember half the people you know are below average.

Re: MAILER DAEMON email address question

2019-04-03 Thread Matus UHLAR - fantomas
direct mail to postmaster account? And if I don't, will I get double-bounce? Matus UHLAR - fantomas: is there a reason to accept replies to DSNs, which should not be replied to? On 03.04.19 08:45, Wietse Venema wrote: So as not to make a bad situation worse. This may be an unnatuural approach for

Re: MAILER DAEMON email address question

2019-04-03 Thread Matus UHLAR - fantomas
MON (or whatever empty_address_recipient says). is there a reason to accept replies to DSNs, which should not be replied to? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Authentication attempts for x...@com.au addresses

2019-04-03 Thread Matus UHLAR - fantomas
tunnel received. 4. postfix would not try to ban localhost. just remove that stunnel. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where

Re: DMARC mitigation for mailing list server

2019-03-27 Thread Matus UHLAR - fantomas
On 26 Mar 2019, at 14:47, Matus UHLAR - fantomas wrote: if the mailing list doesn't modify existing headers, DKIM signatures are valid but they don't align, so DMARC policy is violated. On 26.03.19 15:40, Bill Cole wrote: No: without modification of From, the original DKIM signature does

Re: DMARC mitigation for mailing list server

2019-03-26 Thread Matus UHLAR - fantomas
om header does not align with the domain value in the DKIM-Signature header, the DMARC policy of the signing domain is irrelevant. if the mailing list doesn't modify existing headers, DKIM signatures are valid but they don't align, so DMARC policy is violated. DMARC sucks pretty much. -- Matus UH

Re: DMARC mitigation for mailing list server

2019-03-26 Thread Matus UHLAR - fantomas
der:" header but they generate new one. DMARC required the From: to be aligned with SPF mailfrom. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: pishing from ME

2019-03-23 Thread Matus UHLAR - fantomas
are generally completely fake. They are spammed indiscriminately to users the scammer knows nothing about. one of my accounts leaked some time ago too. I recommend to do that, we can't be sure if the alert is fake -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Understanding the importance of submission

2019-03-21 Thread Matus UHLAR - fantomas
smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination On 3/21/19 1:44 PM, Matus UHLAR - fantomas wrote: neither does this.  this only disables unauthenticated relaying, but allows incoming mail/spam from unauthenticated clients. On 21.03.19 16

Re: Understanding the importance of submission

2019-03-21 Thread Matus UHLAR - fantomas
their ISP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Windows 2000: 640 MB ought to be enough for anybody

Re: Understanding the importance of submission

2019-03-21 Thread Matus UHLAR - fantomas
On 3/20/19 7:35 PM, Matus UHLAR - fantomas wrote: On 20.03.19 16:26, Yassine Chaouche wrote: Requiring authentication to relay on 25 will also get rid of spam. it will also get rid of incoming mail from other mail servers... On 21.03.19 09:18, Yassine Chaouche wrote: Which we want anyway

Re: Understanding the importance of submission

2019-03-20 Thread Matus UHLAR - fantomas
login/pass – something most spammers don't have. On 20.03.19 16:26, Yassine Chaouche wrote: Requiring authentication to relay on 25 will also get rid of spam. it will also get rid of incoming mail from other mail servers... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: Howto reject only one recipient and not drop entire email?

2019-03-20 Thread Matus UHLAR - fantomas
) So if the blame is on the client, what replacements for msmtp do you recommend? this is clearly the msmtp issue. I would think that the msmtp author expects you to clear the list of recipients to only contain valid addresses. I don't know about any other SW with msmtp's functionality. -- Matus UH

Re: smtpd_recipient_restrictions reject_unknown_client_hostname

2019-03-15 Thread Matus UHLAR - fantomas
the trusted IPs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "The box said 'Requires Windows 95 or better', so I bought a Macintosh".

Re: postscreen_dnsbl_action "drop" not working correctly?

2019-03-06 Thread Matus UHLAR - fantomas
it's really uncertain whether it wouldn't make bigger load than just rechecking. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam

Re: postscreen_dnsbl_action "drop" not working correctly?

2019-03-06 Thread Matus UHLAR - fantomas
. It doesn't pick up much, but every little helps. looking at it now, I got error 522 between cloudflare and abuseipdb reported :) and it looks like just another blacklist. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising t

Re: Expires Header(RFC-5536) implementation

2019-03-05 Thread Matus UHLAR - fantomas
ttribute', just like MAIL_ATTR_ENCODING. Then have the queue manager read it ffrom queue file just like MAIL_ATTR_ENCODING. You may want to do some sanity checks such that Postfix will not accept mail that is already expired.     Wietse -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.

Re: Is there any way to add whitelist to ranges or ips domains so that dnsbl are skipped?

2019-03-04 Thread Matus UHLAR - fantomas
mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Eagles may soar, but weasels don't get sucked into jet engines.

Re: postscreen_dnsbl_action "drop" not working correctly?

2019-03-04 Thread Matus UHLAR - fantomas
to drop the connection until the TTL has expired? spamhaus provides records with 60s TTL. Since the next connect came 10 minutes later, the TTL expired already. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: postscreen_dnsbl_action "drop" not working correctly?

2019-03-03 Thread Matus UHLAR - fantomas
_dnsbl_threshold = 1 postscreen_dnsbl_timeout = 10s postscreen_dnsbl_whitelist_threshold = 0 postscreen_greet_action = enforce postscreen_greet_banner = $smtpd_banner postscreen_greet_ttl = 1d postscreen_greet_wait = ${stress?{2}:{6}}s -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas

Re: Unexpected directories in virtual_mailbox_base

2019-03-03 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Honk if you love peace and quiet.

Re: how to use (open)dmarc when already doing before-queue content filtering?

2019-02-26 Thread Matus UHLAR - fantomas
of receiving problems. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfamiliar territory.

Re: how to use (open)dmarc when already doing before-queue content filtering?

2019-02-26 Thread Matus UHLAR - fantomas
On Feb 25, 2019, at 2:46 PM, Matus UHLAR - fantomas wrote: Milter is BQCF. It processes the mail during scanning, and afaik its functionality can replace both smtp_proxy and check_policy_service. And, you can do multiple milters. It just can't modify mail body, only headers, but you usually

Re: how to use (open)dmarc when already doing before-queue content filtering?

2019-02-25 Thread Matus UHLAR - fantomas
Anyway is there any alternative to opendmarc that would be compatible with BQCF? I realize a good place for that would be inside Amavisd-new, but this feature is not available :/ On 23 févr. 2019, at 23:03, Matus UHLAR - fantomas wrote: whatever it is, running it as milter with your setup

Re: how to use (open)dmarc when already doing before-queue content filtering?

2019-02-23 Thread Matus UHLAR - fantomas
realize a good place for that would be inside Amavisd-new, but this feature is not available :/ whatever it is, running it as milter with your setup won't help. post-queue filter might do that, or get rid of pre-queue filter, e.g. use amavisd-new through amavis-milter. -- Matus UHLAR - fantomas, uh

Re: how to use (open)dmarc when already doing before-queue content filtering?

2019-02-23 Thread Matus UHLAR - fantomas
via spamassassin rules. btw I would consider replacing milter-greylist with postscreen. http://www.postfix.org/POSTSCREEN_README.html Thus you could reduce number of third party software and complexity of your mail server setup. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantoma

Re: Old linux / postfix version - how add DKIM ?

2019-02-21 Thread Matus UHLAR - fantomas
. Current opendkim versions may require newer libraries, newer postfix etc. However, this is not a postfix issue. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: How to protect against compromised email account password

2019-02-21 Thread Matus UHLAR - fantomas
help much, as long as other rate limiting tricks and other techniques mentioned in this thread. Unfortunately I have already encountered case where account was used dor spreading spam, slowly to notice, where rate limiting wouldn't (i think it didn't) help. -- Matus UHLAR - fantomas, uh

Re: Cannot get sasl auth working on ubuntu 18.04

2019-02-21 Thread Matus UHLAR - fantomas
t port 465 default options contain also another options: "-o smtpd_client_restrictions=permit_sasl_authenticated,reject" that should be used there. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varov

Re: How to protect against compromised email account password

2019-02-21 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas skrev den 2019-02-20 10:59: Christos Chatzaras skrev den 2019-02-19 12:23: Also we use Postfix relays with Rspamd checking the From header (we don't allow users to spoof From address) and doing rate limits (500 e-mails / hour). If someones tries to send more e-mails

Re: about single bounce and double bounce.

2019-02-20 Thread Matus UHLAR - fantomas
and it will be sent to 2bounce_notice_recipient (which is postmaster by default) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "To Bo

Re: How to protect against compromised email account password

2019-02-20 Thread Matus UHLAR - fantomas
we have some time to manually check. On 19.02.19 14:02, Benny Pedersen wrote: you have users that can write 500 emails in one hour ? yes, bigger companies that send newsletters or notifications to even their users. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: about single bounce and double bounce.

2019-02-20 Thread Matus UHLAR - fantomas
iginal sender. When double bounce occurred, I thought that "from = " would be output, but as far as I confirmed it was "from = <>". If double bounce occurs, will not "from = " appear? the double bounce did not occur, at least not in the logs above. -- Mat

Re: SMTP_HELO_NAME can cause Blacklist triggers

2019-02-11 Thread Matus UHLAR - fantomas
rently good enough for the CBL. It is not. As you said, your reverse DNS was "ip-XX.aws.internal", and thus generic name. the HELO name was just "smtp". They were two different reasons leading to CBL listing. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http:/

Re: SMTP_HELO_NAME can cause Blacklist triggers

2019-02-07 Thread Matus UHLAR - fantomas
we can continue without error. yes, apparently some of the docs could be little more explicit about $hostname or $smtp_helo_name should be a FQDN. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: Rethinking the Postfix release schedule

2019-01-31 Thread Matus UHLAR - fantomas
On January 31, 2019 11:10:50 AM UTC, Matus UHLAR - fantomas wrote: while debian and ubuntu LTS have 2-year cycle and 5-year LTS support, yes, that can get near 8 years behind. On 31.01.19 11:22, Jim Popovitch wrote: Debian has no strict release cycles, and Debian's LTS is based on several

Re: Rethinking the Postfix release schedule

2019-01-31 Thread Matus UHLAR - fantomas
support, yes, that can get near 8 years behind. otoh, it may be acceptable to drop support if a release is very hard to maintain -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Accept email with 5xx status code

2019-01-20 Thread Matus UHLAR - fantomas
uld be used for this purpose. what exactly do you want to achieve? If you want to store mail but pretend it has been rejected (5xx code), postfix does not support this and you must do this outside of postfix. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I w

Re: Query about restriction scenario in RESTRICTION_CLASS_README

2019-01-19 Thread Matus UHLAR - fantomas
that it's hard for us to know why does gmail say that your mail server is misconfigured. Especially when you haven't provided any such message. It's gmail or other servers who say that and we (at least some of us) don't maintain gmail servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: pflogsumm milter patch

2019-01-15 Thread Matus UHLAR - fantomas
Hello, does anyone use pflogsumm and reject based on header/body checks? If so, can you test or provide me (privately) same logs of those rejections? On 11.01.19 15:43, Matus UHLAR - fantomas wrote: I have made a small patch for counting milter rejections in pflogsumm. I put it on http

pflogsumm milter patch

2019-01-11 Thread Matus UHLAR - fantomas
at made it into debian package, available here: http://test.fantomas.sk/pflogsumm-postscreen.patch seems that original author doesn't care (have tried to contact him at least 3 times). I will try with people having repositories on github (where the original author doesn't maintain it anymore).

Re: It is possible for Postfix logging to bypass journald?

2019-01-10 Thread Matus UHLAR - fantomas
both have rate limits. https://support.asperasoft.com/hc/en-us/articles/216128628-How-to-disable-rsyslog-rate-limiting It is time to update the Postfix page on LINUX logging brain damage. oh, please... systemd and rsyslog. I use sysvinit+syslog-ng wherever possible, on linux -- Matus UHLAR

Re: how to balance outgoing emails with multiple IP addresses with postfix

2019-01-07 Thread Matus UHLAR - fantomas
On 07.01.19 14:11, Paul Martin wrote: Do you know how to balance outgoing emails with multiple IP addresses with postfix ? (I do not have randmap on my postfix) what exactly are you trying to achieve? To delay outgoing mail for anyone using greylisting? -- Matus UHLAR - fantomas, uh

Re: SMTP filter using geo-localization

2019-01-06 Thread Matus UHLAR - fantomas
On 05.01.19 22:26, Philippe - Forums wrote: I would like to filter SMTP access using geo-localization. tried searching in your SW distribution? % apt-cache search geoip postfix mtpolicyd - modular policy daemon for postfix https://www.mtpolicyd.org/ -- Matus UHLAR - fantomas, uh

Re: Content filter - reijnect message back into queue

2019-01-05 Thread Matus UHLAR - fantomas
On 05.01.19 08:37, Rafael Azevedo wrote: Can the reinjection port be other than 10025 ? it can be any port, but it has to be configured not to send mail back to the filter not to create a loop. there are other recommended options for such port, documented in filter readme. -- Matus UHLAR

Re: Content filter - reijnect message back into queue

2019-01-04 Thread Matus UHLAR - fantomas
sex, 4 de jan de 2019 às 18:36, Matus UHLAR - fantomas escreveu: >> You forgot to send it back into Postfix. On 04.01.19 16:47, Rafael Azevedo wrote: >Would you please tell me how to send it back to POSTFIX ? call sendmail and pass te message to it, or sent it to postfix via

Re: Content filter - reijnect message back into queue

2019-01-04 Thread Matus UHLAR - fantomas
postfix doesn't send it to your content filter again. it's explained in http://www.postfix.org/FILTER_README.html#principles -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Slowness after upgrading from postfix 2.x to 3.1.8

2019-01-04 Thread Matus UHLAR - fantomas
is this milter running properly? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam is for losers who can't get business any other way.

Re: policy server, TLS only exeptions and restrictions

2019-01-04 Thread Matus UHLAR - fantomas
cy server doesn't look to your "smtp_tls_policy_maps" settings, usually it does not read postfix configuration at all. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT a

Re: Use relayhost or not ? What is the best strategy ?

2019-01-02 Thread Matus UHLAR - fantomas
it's safe to use them as relay. However, the mail is less in your hands then, and you may need their help to solve problems. I would use ISPs relay only in cases of blacklisting. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Good sender name

2018-12-29 Thread Matus UHLAR - fantomas
stion is, how do you send the mail? if you sre using script that calls "mail" command, it's possible that the mail command generates From: using full host name instead of domain name. that may not be postfix's fault -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Wa

Re: More secure postfix

2018-12-22 Thread Matus UHLAR - fantomas
DNS records -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The 3 biggets disasters: Hiroshima 45, Tschernobyl 86, Windows 95

Re: capture information for internal generated mails

2018-12-20 Thread Matus UHLAR - fantomas
. unfortunately it doesn't cover all the situation yet. I need more hack suggestion.. Matus UHLAR - fantomas it's better (and often safer) to archive logs instead of while mail. On 20.12.18 22:22, d tbsky wrote: I need to archive the whole mails and related info. I think it's a common

Re: capture information for internal generated mails

2018-12-20 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas isn;t it easier to save one copy of mail with the logs, instead of two copied of mail, without logs? Note that logs will show e.g. when mail was refused by destination server, mail won't. On 20.12.18 21:50, d tbsky wrote: I don't know if it is easier. but what I want

Re: capture information for internal generated mails

2018-12-20 Thread Matus UHLAR - fantomas
il was refused by destination server, mail won't. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux - It's now safe to turn on your comput

Re: dnsbl postscreen - not blocking

2018-12-19 Thread Matus UHLAR - fantomas
dnsbl.sorbs.net*1 postscreen_blacklist_action = drop postscreen_dnsbl_action = enforce Am i missing something obvious? on some systems I have implemented postscreen with especially to avoid refusing mail just because of a single dnsbl listing. on some systems the google ranges are whitelisted. -- Matus UHLAR

Re: part 2 of: SSL not working after unwanted server migration

2018-12-11 Thread Matus UHLAR - fantomas
tfix mailing lists. Since then, and until 4 days ago, it had always worked as expected, and never given me reasons to remember its existence. Do you mean that the "flags=D" setting is obsolete in the current version of postfix? it's not obsolete, but the filtering through procmail like th

Re: Strange TLS error when sending mail from one server to my Postfix SMTP server

2018-12-11 Thread Matus UHLAR - fantomas
n such case, this MTA must accept certificate of your client's postfix server. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I intend to live forever - so far so good.

Re: Treat only one address of a domain as local

2018-12-11 Thread Matus UHLAR - fantomas
will do what you want for all mail passing your server -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Eagles may soar, but weasels don't

Re: Local delivery to mbox / inode issue

2018-12-07 Thread Matus UHLAR - fantomas
On 06.12.18 15:45, Dominic Raferd wrote: >I am using incrond to monitor an mbox file (in /var/mail) for changes, On Fri, 7 Dec 2018 at 09:15, Matus UHLAR - fantomas wrote: hmmm, why? maybe there's other way to implement your requirement On 07.12.18 10:22, Dominic Raferd wrote: The

Re: New install - Temporary lookup failures when trying to send

2018-12-06 Thread Matus UHLAR - fantomas
On Mon Dec 03 2018 04:27:43 Matus UHLAR - fantomas said: pleaase, get a decent MUA, not applemail that tries to encode everything as internet links (and messes up thge plaintext version of mail). On Dec 6, 2018, at 3:00 AM, Matus UHLAR - fantomas wrote: X-Mailer: Apple Mail

Re: client incorrect greeting error, how to resolve?

2018-12-06 Thread Matus UHLAR - fantomas
*_count/rate_limit restrictions, according to: http://www.postfix.org/postconf.5.html#smtpd_client_event_limit_exceptions -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: New install - Temporary lookup failures when trying to send

2018-12-06 Thread Matus UHLAR - fantomas
On Mon Dec 03 2018 04:27:43 Matus UHLAR - fantomas said: pleaase, get a decent MUA, not applemail that tries to encode everything as internet links (and messes up thge plaintext version of mail). On 04.12.18 13:47, @lbutlr wrote: What do you base this statement on? I’ve been using

Re: Relaying based on Souce IP address

2018-12-04 Thread Matus UHLAR - fantomas
to split this? to allow relaying some domains only when coming from IP 'A' and some other domains only when coming from IP 'B'  -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: New install - Temporary lookup failures when trying to send

2018-12-03 Thread Matus UHLAR - fantomas
I believe many could be left default. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Boost your system's speed by 500% - DEL C:\WINDOWS\*.*

Re: possibly stupid question

2018-11-29 Thread Matus UHLAR - fantomas
On 29.11.18 09:09, Francesc Peñalvez wrote: it may be a silly question but.Which option is appropriate to reject emails from ip without ip resolved you apparently mean "reject_unknown_client_hostname" in smtpd_*_restrictions settings -- Matus UHLAR - fantomas, uh...@fantomas

Re: Installing LetsEncrypt For Postfix and Dovecot

2018-11-29 Thread Matus UHLAR - fantomas
On Wed, 2018-11-28 at 10:03 +0100, Matus UHLAR - fantomas wrote: But I prefer dehydrated over bloated certbot. On 28.11.18 09:49, Jim P. wrote: This comes up enough to warrant the following questions: 1) What do you do about restarting services after automatic cert renewals in the middle

Re: a lot of spam or something?

2018-11-28 Thread Matus UHLAR - fantomas
not explain what's happening. I guess you got all you really need to handle the problem. - fix invalid forward/redirect -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: hostnames in postscreen_access_list

2018-11-28 Thread Matus UHLAR - fantomas
it exactly what is needed in these cases. Those ports were even designed for this purpose... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: Installing LetsEncrypt For Postfix and Dovecot

2018-11-28 Thread Matus UHLAR - fantomas
have experience with this? I have no problem with Let's Encrypt certificates and postfix/whatever. I'm just not sure if iphones have the root CA (DST Root CA X3) installed - just yesterday noticed a complaint. But I prefer dehydrated over bloated certbot. -- Matus UHLAR - fantomas, uh

Re: Convert quoted-printable headers

2018-11-24 Thread Matus UHLAR - fantomas
=3DA9=3F=3D_Rodier?= this looks to me like encoded twice, so all clients that decode it once will show once encoded string. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: a lot of spam or something?

2018-11-23 Thread Matus UHLAR - fantomas
are sending too much mail to www-d...@allegro.pl and they refuse it. It's send from MAILER-DAEMON which means someone send mail from www-d...@allegro.pl to you. search for such mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: how block specific ip address in Postfix

2018-11-19 Thread Matus UHLAR - fantomas
, that do not exist. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #98652: Operation completed successfully.

Re: smtpd_delay_reject with rspamd milter

2018-11-08 Thread Matus UHLAR - fantomas
On 08.11.18 01:31, Kai Schaetzl wrote: Thanks for the answer. But, please look again. /etc/mail/access: createsend.com REJECT cmail20.com REJECT On 08.11.18 12:06, Matus UHLAR - fantomas wrote: you should specify .createsend.com, because the connecting domain is mx17

Re: smtpd_delay_reject with rspamd milter

2018-11-08 Thread Matus UHLAR - fantomas
lient_access hash:/etc/mail/access, -> this is first in order and contains matching data! > check_sender_access hash:/etc/mail/access, -> but it matches only in the next step! -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to recei

Re: Postscreen blacklist question

2018-10-31 Thread Matus UHLAR - fantomas
/POSTSCREEN_README.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "They say when you play that M$ CD backward you can hear satanic messages.&quo

Re: myorigin isn't appended to local senders

2018-10-28 Thread Matus UHLAR - fantomas
ail package. Apparently the one provided in solaris 11.3. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R)etry, (A)bort, (C)ancer

Re: how set postfix server as non-functional

2018-10-27 Thread Matus UHLAR - fantomas
On 26.10.18 09:27, Poliman - Serwis wrote: I have one more question which is more less related with main thread. I would like to know can I block port 25 on firewall? 2018-10-26 10:01 GMT+02:00 Matus UHLAR - fantomas : not if you want to send and receive mail. [...] However, if you

Re: how set postfix server as non-functional

2018-10-26 Thread Matus UHLAR - fantomas
er, if you are not a service provider, don't simply block 25, if you want to send/receive mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. &qu

Re: TLSv1.2 only for auth connection

2018-10-25 Thread Matus UHLAR - fantomas
it as such. for now, many companies use port 465 as authenticated submission-only port. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: how set postfix server as non-functional

2018-10-25 Thread Matus UHLAR - fantomas
yes, such projects should test that, too. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The 3 biggets disasters: Hiroshima 45, Tschernobyl 86, Windows 95

Re: Enabling TLSv1.2 support in postfix 2.8.2

2018-10-25 Thread Matus UHLAR - fantomas
protocol:s23_srvr.c:578: On Wed, Oct 24, 2018 at 5:01 PM Matus UHLAR - fantomas wrote: which OS/distribution do you use? On 24.10.18 17:50, Burn Zero wrote: I use CentOS 6.5 On 25.10.18 09:10, Matus UHLAR - fantomas wrote: I haven't find centos 6.5 nor redhat 6.5 here, but on one of our

Re: how set postfix server as non-functional

2018-10-25 Thread Matus UHLAR - fantomas
/POSTSCREEN_README.html#white_veto -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One OS to rule them all, One OS to find them, One OS to bring them all

<    6   7   8   9   10   11   12   13   14   >