Re: Rejected mails in mailq

2022-06-16 Thread Matus UHLAR - fantomas
it holding onto the mail for? perhaps you have soft_bounce set to on ? if not, you may have smtp_reply_filter set -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Implementing a delay between connection closing and reopening

2022-06-14 Thread Matus UHLAR - fantomas
ere: https://marc.info/?l=postfix-users=164926643409705=2 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam = (S)tupid (P)eople's (A)dvertising (M)ethod

Re: limit rewriting headers in canonical_maps

2022-06-13 Thread Matus UHLAR - fantomas
On 24 May 2022, at 8:09 am, Matus UHLAR - fantomas wrote: I have customer where incoming messages have the "message was received from external source" banned added. The resulting messages don't have valid DKIM-signature: (or none at all), and the only way to forward without problems

Re: limit rewriting headers in canonical_maps

2022-06-13 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: If there's no way to do this now, I'll have to search for one. On 24.05.22 09:43, Wietse Venema wrote: There is a way to do this, and that involves using a Milter (or any kind of content filter). Postfix does not implement every possible edge case. after some

Re: TLS library problem: error:141FC044 after enabling TLS

2022-06-09 Thread Matus UHLAR - fantomas
at: https://marc.info/?l=postfix-users=2=1=recommended+TLS+settings=b -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "One World. One W

Re: fail2ban filter for spurious connections?

2022-06-09 Thread Matus UHLAR - fantomas
stop most probes. The Postfix question: Is there a reason this is a bad idea, and could it cause legitimate MTAs to be banned? depends on the filter sensibility. the RCPT command may fail because of valid reasons, e.g. someone mistyped recipient address. -- Matus UHLAR - fantomas, uh...@fantomas

Re: Notify user in some way that the mail being received is on old domain

2022-06-08 Thread Matus UHLAR - fantomas
as adding "mail received from outside" disclaimer to incoming mail for which instructions exist and should be useful -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Postfix+SASL chrooted - out of ideas (SASL_README tweak)

2022-06-03 Thread Matus UHLAR - fantomas
On Fri, Jun 03, 2022 at 11:09:08AM +0200, Matus UHLAR - fantomas wrote: this will unpack the tarball in local directory. I use standard debian packages, there's SASL related patch but it doesn't seem to affect this issue https://sources.debian.org/patches/postfix/3.5.6-1/ https

Re: Postfix+SASL chrooted - out of ideas (SASL_README tweak)

2022-06-03 Thread Matus UHLAR - fantomas
On 02.06.22 08:38, raf wrote: >No. Perhaps in the past, but no longer. I grepped for >/etc/postfix/sasl in every file on a debian11 system >and it didn't appear in libsasl2 or anywhere >interesting. On Thu, Jun 02, 2022 at 03:45:01PM +0200, Matus UHLAR - fantomas wrote: maybe

Re: Block MX from recipients

2022-06-03 Thread Matus UHLAR - fantomas
helo= Jun 3 05:07:39 proxy2 postfix/smtpd[10808]: NOQUEUE: reject: RCPT from unknown[192.0.2.1]: 554 5.7.1 : Recipient address rejected: Mail services for this domain removed; from= to= proto=ESMTP helo= El 31/5/22 a las 16:00, Matus UHLAR - fantomas escribió: On 31.05.22 12:55, SysAdmin EM

Re: Postfix+SASL chrooted - out of ideas (SASL_README tweak)

2022-06-02 Thread Matus UHLAR - fantomas
things like saslfinger and apparmor rules and the postfix package file list and augeas-lenses (a config file parser). But nothing in any libsasl files or postfix files. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to t

Re: Milters after local recipient expansion

2022-06-01 Thread Matus UHLAR - fantomas
to trigger? Perhaps there's other way to achieve it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user friendly, it's just selective

Re: Block MX from recipients

2022-06-01 Thread Matus UHLAR - fantomas
On Tue, May 31, 2022 at 09:02:12PM +0200, Matus UHLAR - fantomas wrote: for hotmaul.com and hormail.com use simple check_sender_access and check_recipient_access. On 01.06.22 08:27, Bastian Blank wrote: Or check the recipient domain in the application that receives the e-mail addresses. Just

Re: Block MX from recipients

2022-05-31 Thread Matus UHLAR - fantomas
) negritaa...@hormail.com Any chance of blocking the MX of a recipient? Reading the documentation I found the parameter "check_sender_mx_access" but I think it refers to a sender and not a recipient. On 31.05.22 21:00, Matus UHLAR - fantomas wrote: there's also check_recipient_mx_access,

Re: Block MX from recipients

2022-05-31 Thread Matus UHLAR - fantomas
-- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Atheism is a non-prophet organization.

Re: postscreen_dnsbl_sites questions about multiple matches.

2022-05-30 Thread Matus UHLAR - fantomas
On 30.05.22 14:02, Peter wrote: Next question: What happens if zen returns multiple responses: 127.0.0.10 127.0.0.3 postscreen_dnsbl_sites = zen.spamhaus.org=127.0.0.[1..2]*3 zen.spamhaus.org=127.0.0.3*2 zen.spamhaus.org=127.0.0.[4..255]*3 On 30.05.22 10:06, Matus UHLAR - fantomas wrote

Re: postscreen_dnsbl_sites questions about multiple matches.

2022-05-30 Thread Matus UHLAR - fantomas
= zen.spamhaus.org=127.0.0.[1..2]*3 zen.spamhaus.org=127.0.0.3*2 zen.spamhaus.org=127.0.0.[4..255]*3 How would that affect the answer to the above two questions? this should produce score 6 for the example above -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: limit rewriting headers in canonical_maps

2022-05-25 Thread Matus UHLAR - fantomas
>Matus UHLAR - fantomas: >> If there's no way to do this now, I'll have to search for one. On 24.05.22 09:43, Wietse Venema wrote: >There is a way to do this, and that involves using a Milter (or any >kind of content filter). Postfix does not implement every possible >edge ca

Re: limit rewriting headers in canonical_maps

2022-05-25 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: If there's no way to do this now, I'll have to search for one. On 24.05.22 09:43, Wietse Venema wrote: There is a way to do this, and that involves using a Milter (or any kind of content filter). Postfix does not implement every possible edge case. I probably should

Re: Milter_Readme - Documentation Edit Request - "order", "reject" and "override" - multiple message modifications?

2022-05-24 Thread Matus UHLAR - fantomas
n the mail message? On 5/24/22 03:36, Matus UHLAR - fantomas wrote: subsequent milters will see message as modified with previous milter. On 24.05.22 08:12, James Feeney wrote: That simple but important point seems to be missing from the Postfix "Milter Readme". What I'm wonderin

Re: limit rewriting headers in canonical_maps

2022-05-24 Thread Matus UHLAR - fantomas
On 24 May 2022, at 8:09 am, Matus UHLAR - fantomas wrote: I have customer where incoming messages have the "message was received from external source" banned added. The resulting messages don't have valid DKIM-signature: (or none at all), and the only way to forward withou

Re: limit rewriting headers in canonical_maps

2022-05-24 Thread Matus UHLAR - fantomas
e that one is used for DKIM signatures. I haven't expected more headers to be rewritten. If there's no way to do this now, I'll have to search for one. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Var

Re: Milter_Readme - Documentation Edit Request - "order", "reject" and "override" - multiple message modifications?

2022-05-24 Thread Matus UHLAR - fantomas
s received, every message processed by milter is by definition incoming. note that when you submit message to postfix, it's "incoming". opendkim has ways to decide when the message is to be signed, check its docs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

limit rewriting headers in canonical_maps

2022-05-24 Thread Matus UHLAR - fantomas
on Debian 11. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The early bird may get the worm, but the second mouse gets the cheese.

Re: Change Recipient Case?

2022-05-21 Thread Matus UHLAR - fantomas
addresses from uppercase to lowercate AND still use virtual_mailbox_maps to deliver mail to virtual mailboxes. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: sender_canonical_maps, but only for particular recipient domain?

2022-05-18 Thread Matus UHLAR - fantomas
Dnia 18.05.2022 o godz. 15:01:45 Matus UHLAR - fantomas pisze: are you trying to implement SRS when sending to gmail? On 2022-05-18 15:44, Jaroslaw Rafa wrote: No, I just want to change the domain, because Gmail keeps putting mail originating from my domain (rafa.eu.org) to recipients Spam

Re: sender_canonical_maps, but only for particular recipient domain?

2022-05-18 Thread Matus UHLAR - fantomas
to gmail? I'm just working on this issue (not only to gmail) - conditionally rewrite sender if it's not from local domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Sanity Check Request: smtpd_*_restrictions

2022-05-17 Thread Matus UHLAR - fantomas
while you can of course add upstream servers to mynetworks and make mail receiving work, it's a bad idea because this variable is used for outgoing mail. if you need to block accepting mail from unauthorized IP address, I recommend you doing it using access lists http://www.postfix.org/

Re: Sanity Check Request: smtpd_*_restrictions

2022-05-17 Thread Matus UHLAR - fantomas
ast reject, again. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "One World. One Web. One Program." - Microsoft promotional adv

Re: First world problem ...

2022-05-16 Thread Matus UHLAR - fantomas
W dniu 16.05.2022 o 15:14, Matus UHLAR - fantomas pisze: Any idea to whitlist ? On 16 May 2022, at 9:35 pm, Matus UHLAR - fantomas wrote: perhaps the null address at outgoing server, so you don't reject your own bounces W dniu 16.05.2022 o 14:46, Viktor Dukhovni pisze: No.  Better

Re: First world problem ...

2022-05-16 Thread Matus UHLAR - fantomas
Any idea to whitlist ? On 16 May 2022, at 9:35 pm, Matus UHLAR - fantomas wrote: perhaps the null address at outgoing server, so you don't reject your own bounces W dniu 16.05.2022 o 14:46, Viktor Dukhovni pisze: No. Better to apply the reject rule only on the inbound side, where

Re: First world problem ...

2022-05-16 Thread Matus UHLAR - fantomas
Any idea to whitlist ? On 16 May 2022, at 9:35 pm, Matus UHLAR - fantomas wrote: perhaps the null address at outgoing server, so you don't reject your own bounces On 16.05.22 22:46, Viktor Dukhovni wrote: No. Better to apply the reject rule only on the inbound side, where it should only

Re: First world problem ...

2022-05-16 Thread Matus UHLAR - fantomas
elf and a bounce is generated, second time the bounce gets rejected. Any idea to whitlist ? perhaps the null address at outgoing server, so you don't reject your own bounces -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: postfix-policyd-spf-python

2022-05-16 Thread Matus UHLAR - fantomas
From: owner-postfix-us...@postfix.org <> On Behalf Of Matus UHLAR - fantomas perhaps a but I don't see On 15.05.22 14:21, Dino Edwards wrote: So you agree, it should be passing but it's not for some reason. it was supposed to be a "bug I don't see". can you install with cur

Re: reject_*sender_login_mismatch and "no SASL support"

2022-05-14 Thread Matus UHLAR - fantomas
On 2022-05-05 19:41, Matus UHLAR - fantomas wrote: non-existing and unknown addresses can hardly be listed in smtpd_sender_login_maps so I can't exactly see how they are protected. (and RTFS didn't help me) On 05.05.22 20:18, Benny Pedersen wrote: envelope senders can be rejected on port 25

Re: reject_*sender_login_mismatch and "no SASL support"

2022-05-14 Thread Matus UHLAR - fantomas
Hello, Matus UHLAR - fantomas: note that this is mentioned in reject_sender_login_mismatch: MAIL FROM address," reject_sender_login_mismatch Reject the request when $smtpd_sender_login_maps specifies an owner for the MAIL FROM address, but the c

Re: rejection of backup MX mail

2022-05-14 Thread Matus UHLAR - fantomas
and internal_networks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is like a steel trap - rusty and illegal in 37 states.

Re: postfix-policyd-spf-python

2022-05-13 Thread Matus UHLAR - fantomas
e-from="oemcustomerc...@acuitybrands.com"; client-ip=13.110.78.238 perhaps a but I don't see -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Depr

Re: postfix-policyd-spf-python

2022-05-13 Thread Matus UHLAR - fantomas
that was using SPF macros. I tried to find out if our version of spf (2.0.0) supported SPF macros but I can't seem to find any information on that. Can someone shed some lights on this? perhaps you can post logs? local part of mail address may be censored... -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-10 Thread Matus UHLAR - fantomas
his with gmail", as it's generally very hard to confirm *anything* with gmail, i.e. the reason why a certain mail will be rejected or land in junk. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varov

Re: dnswl.org lookup error

2022-05-09 Thread Matus UHLAR - fantomas
sed blocklists etc. I only use non-systemd systems and have no idea of that one. ('Can understand why you would want to put everything in one, but do not like it.) I guess systemd-resolved does the same, just different way. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.

Re: Restricting MAIL_FROM based on SASL login

2022-05-06 Thread Matus UHLAR - fantomas
: (putting original From: to Reply-To:). I plan to use this in the next step of my mail improvements. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rekl

Re: reject_*sender_login_mismatch and "no SASL support"

2022-05-05 Thread Matus UHLAR - fantomas
I'm trying to RTFS now, but I'm not a programmer... On 2022-05-04 at 12:20:49 UTC-0400 (Wed, 4 May 2022 18:20:49 +0200) Matus UHLAR - fantomas is rumored to have said: May 1 02:04:15 fantomas postfix/smtpd[31415]: warning: restriction `reject_authenticated_sender_login_mismatch' ignored

Re: reject_*sender_login_mismatch and "no SASL support"

2022-05-05 Thread Matus UHLAR - fantomas
On 2022-05-04 at 12:20:49 UTC-0400 (Wed, 4 May 2022 18:20:49 +0200) Matus UHLAR - fantomas is rumored to have said: I have tried to restrict users only to be able to send mail with their own e-mail addresses. (I am aware of difference between envelope from: and header From: but I have

reject_*sender_login_mismatch and "no SASL support"

2022-05-04 Thread Matus UHLAR - fantomas
er reject_*sender_login_mismatch? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. - Have you got anything without Spam in it? - Well, there'

Re: Restricting MAIL_FROM based on SASL login

2022-05-04 Thread Matus UHLAR - fantomas
mail from: using check_sender_access. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Christian Science Programming: "Let God Debug It!".

Re: why does gmail accept and bounce ?

2022-05-02 Thread Matus UHLAR - fantomas
failed Status: 5.7.26 Remote-MTA: DNS; gmail-smtp-in.l.google.com Diagnostic-Code: SMTP; 550-5.7.26 This message does not have authentication information or fails to Last-Attempt-Date: Mon, 2 May 2022 09:24:27 -0700 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning:

Re: PIX workarounds incorrectly triggering?

2022-05-02 Thread Matus UHLAR - fantomas
LAIN LOGIN DIGEST-MD5 250-XXXA 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-PIPELINING 250-ETRN 250-DSN 250 XXXB the second line may originally be "STARTTLS" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varo

Re: SRS and sender_dependent_relayhost_maps

2022-04-28 Thread Matus UHLAR - fantomas
>> > On 21.04.22 17:51, Matus UHLAR - fantomas wrote: >> > >I'm trying to implement SRS using postsrsd. Since it always rewrites >> > >non-local sender (even for incoming mail) I'm trying to restrict it >> > >only for outgoing mail. >Wietse Venem

Re: SRS and sender_dependent_relayhost_maps

2022-04-28 Thread Matus UHLAR - fantomas
> On 21.04.22 17:51, Matus UHLAR - fantomas wrote: > >I'm trying to implement SRS using postsrsd. Since it always rewrites > >non-local sender (even for incoming mail) I'm trying to restrict it > >only for outgoing mail. Wietse Venema: SRS sender rewriting

Re: SRS and sender_dependent_relayhost_maps

2022-04-28 Thread Matus UHLAR - fantomas
bumping if anyone has a better idea. On 21.04.22 17:51, Matus UHLAR - fantomas wrote: I'm trying to implement SRS using postsrsd. Since it always rewrites non-local sender (even for incoming mail) I'm trying to restrict it only for outgoing mail. I managed configuring local SMTP server

Re: password security

2022-04-25 Thread Matus UHLAR - fantomas
fabulously well abuse reports have worked with preventing spam, don't we !! As I said. Fail2ban is a waste of time whack-a-mole. Sure your logs might be quieter, but quieter logs does not equal better security ! yes, cutting all clients' access is anything but lazy... -- Matus UHLAR - fantomas, uh

Re: warning: process /usr/local/libexec/postfix/postscreen pid xxxxx killed by signal 11

2022-04-25 Thread Matus UHLAR - fantomas
cause signal 11 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. - Have you got anything without Spam in it? - Well, there's Spam egg sausage

Re: how other MTA talks to me

2022-04-24 Thread Matus UHLAR - fantomas
by smtpd_tls_security_level smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache remove, as client is supposed to keep the data -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: SRS and sender_dependent_relayhost_maps

2022-04-22 Thread Matus UHLAR - fantomas
On 2022-04-21 17:51, Matus UHLAR - fantomas wrote: I'm trying to keep configuration and mail flow as simple as possible. On 22.04.22 01:44, Benny Pedersen wrote: so dont use SRS ? SRS is crucial to implement some functionalities our customers require. Especially since google started

Re: Workaround for sender address rejected: domain not found

2022-04-22 Thread Matus UHLAR - fantomas
, if possible. Nobody should send mail from domain that does not exist. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Atheism is a non

SRS and sender_dependent_relayhost_maps

2022-04-21 Thread Matus UHLAR - fantomas
mail flow as simple as possible. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE = Mad Cow Desease ... BSA = Mad Software Producents Desease

Re: Virtual domains

2022-04-15 Thread Matus UHLAR - fantomas
ddresses, and server only needs certificate for mail.example.org. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. You have the right to remain

Re: milter_header_checks, pcre, chroot

2022-04-14 Thread Matus UHLAR - fantomas
On 2022-03-19 17:49, Matus UHLAR - fantomas wrote: this should be fixable by using proxymap, better than disabling chroot http://www.postfix.org/proxymap.8.html On 20.03.22 17:29, Jesper Dybdal wrote: Thanks.  As far as I can see, I need to add    proxy:regexp:/etc/postfix

Re: match empty sender in hash: sender access map?

2022-04-14 Thread Matus UHLAR - fantomas
'postmap regexp:filename' is not useful: postmap: fatal: unsupported dictionary type: regexp. Is the postfix-regexp package installed? given I know I have regexp installed. On April 13, 2022 Matus UHLAR <- fantomas > wrote: regexp and postfix-regexp are two different things. s

Re: connection timeout ?

2022-04-13 Thread Matus UHLAR - fantomas
ADER<<- opcode: QUERY, status: NXDOMAIN, id: 58935 ;_domainkeys.gmail.dk. IN ANY so: deny based SPF, no DKIM key, DMARC reject. however, they miss the nullmx record: gmail.dk. 300 IN MX 0 . -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.f

Re: Pre- or post-queue filter for authenticated submission

2022-04-13 Thread Matus UHLAR - fantomas
, separate port of course achieved via NAT) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Nothing is fool-proof to a talented fool.

Re: match empty sender in hash: sender access map?

2022-04-13 Thread Matus UHLAR - fantomas
compiled with regexp map type, try running: postconf -m -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Emacs is a complicated operating

Re: Do not use alternate MX in case of a specific message

2022-04-12 Thread Matus UHLAR - fantomas
there any possibility, if we see the first message, to put it in a deferred status with this message ? "status=deferred" does defer a message, but only the one you tried to deliver. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Solving reverse DNS problem with Postfix configuration?

2022-04-11 Thread Matus UHLAR - fantomas
more than one reverse pointer per IP the VPS (Digital Ocean) says it can't be done. you can but it's rarely a good idea. And it's not a solution for the OP, because his original PTR causes problems, which means he needs to replace it, not to add another. -- Matus UHLAR - fantomas, uh

Re: Solving reverse DNS problem with Postfix configuration?

2022-04-11 Thread Matus UHLAR - fantomas
for my IP address now points to the ISP's generic name 77-172-184-9.fixed.kpn.net Could I solve this by setting smtp_helo_name in main.cf to 77-172-184-9.fixed.kpn.net ? Or is this a bad idea? Op 11-04-22 om 16:17 schreef Matus UHLAR - fantomas: this will not help your problem. many ISPs

Re: Solving reverse DNS problem with Postfix configuration?

2022-04-11 Thread Matus UHLAR - fantomas
way (without host=>IP resoluntion) by reject_unknown_reverse_client_hostname the helo check is done by reject_unknown_helo_hostname. however there are many mailservers who consider "77-172-184-9.fixed.kpn.net" generic (because it contains the IP address) and refuse talking to server. -- Matus UHLAR - fanto

Re: Solving reverse DNS problem with Postfix configuration?

2022-04-11 Thread Matus UHLAR - fantomas
reverse DNS format. ask your ISP to change reverse DNS for your IP to mail.linetec.nl when possible. if not possible, you'll need external smtp server, or different ISP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Postfix + rspamd will not rewrite sender

2022-04-08 Thread Matus UHLAR - fantomas
it will not rewrite the sender address and forwarding to my ISP fails. On 8 Apr 2022, at 12:50 am, Matus UHLAR - fantomas wrote: did amavis change the sender when used as milter? i'm not sure milter supports changing sender… On 08.04.22 09:10, Horst Simon wrote: Haven't used milter for amavisd-new only

Re: Fwd: [ANN]ounce of S-postgray v0.6.0

2022-04-07 Thread Matus UHLAR - fantomas
note groff HTML conversion is bad; the ball is ~127KB, the optimized binary package is 44KB on a GNU libc Linux system). fyi, does this provide any functionality better than e.g. postscreen? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: Postfix + rspamd will not rewrite sender

2022-04-07 Thread Matus UHLAR - fantomas
. Is there anything else I need to change in the postfix configuration to get this working again? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: Merging accounts/home directories

2022-04-07 Thread Matus UHLAR - fantomas
g. in a year) you can convert those redirects in virtual_alias_maps to relocated. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only

Re: Merging accounts/home directories

2022-04-07 Thread Matus UHLAR - fantomas
rs and set their home directories to be the same as their old ones, then also add new entries to the check_client_access map. Does that make sense? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: wildcards in smtp_connection_cache_destinations

2022-04-06 Thread Matus UHLAR - fantomas
On Wed, Apr 06, 2022 at 07:33:41PM +0200, Matus UHLAR - fantomas wrote: this is not an internal domain not out client, these are three subdomains of remote domain/organization (different IPs from different IP range) I have no relationship with. I have created special transport for them

Re: wildcards in smtp_connection_cache_destinations

2022-04-06 Thread Matus UHLAR - fantomas
lt settings, which >keep connections open only when they can be reused immediately. Matus UHLAR - fantomas: this unfortunately did not work without listing destinations explicitly in smtp_connection_cache_destinations so I had big backlog of messages for those domains, even if I set smtp_connectio

Re: Mail is being delivered to /var/mail/*user* instead of Maildir

2022-04-06 Thread Matus UHLAR - fantomas
/vmail/user/Maildir but /var/mail* note that different behaviour can be caused by: - destination domain in virtual_mailbox_domains - home_mailbox - mailbox_command etc. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: wildcards in smtp_connection_cache_destinations

2022-04-06 Thread Matus UHLAR - fantomas
>Matus UHLAR - fantomas: >> does prefix ".domain" apply for smtp_connection_cache_destinations? >> (debian's 3.5.6 doesn't seem to accept that). On 05.04.22 10:26, Wietse Venema wrote: >Is it documented to support this? > >What is documented is that smtp_conne

Re: Q: configuring Postfix as a front for Exchange 365

2022-04-06 Thread Matus UHLAR - fantomas
u may want to have username maps in example.cloud do you don't accept and forward non-existing addresses (I did this using LDAP lookups into the customer's Active Directory) that should work. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: wildcards in smtp_connection_cache_destinations

2022-04-05 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas: does prefix ".domain" apply for smtp_connection_cache_destinations? (debian's 3.5.6 doesn't seem to accept that). On 05.04.22 10:26, Wietse Venema wrote: Is it documented to support this? What is documented is that smtp_connection_cache_destinations supports

wildcards in smtp_connection_cache_destinations

2022-04-05 Thread Matus UHLAR - fantomas
dware). I managed to aork around that domain by configuring special transport for them and forching smtp caching for them. I can name all those subdomains in smtp_connection_cache_destinations, set smtp_connection_cache_on_demand=no, but supporting .subdomains would be easier. -- Matus UHLAR

Re: Rewrite recipient when an email is received from a specific sender

2022-04-04 Thread Matus UHLAR - fantomas
http://www.postfix.org/access.5.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Emacs is a complicated operating system without good text

Re: Best way to filter mail when using recipient_delimiter

2022-04-01 Thread Matus UHLAR - fantomas
"Matus" == Matus UHLAR <- fantomas > writes: Matus> the latter can be disabled by calling check_recipient_access Matus> "user+whate...@example.com REJECT" This is what I want to achieve and after reading the documentation at http://www.postfix.org/RESTRICTION_CLA

Re: Best way to filter mail when using recipient_delimiter

2022-04-01 Thread Matus UHLAR - fantomas
eiver. Am I missing the point here or is there a better way of doing this check and reject those mails with the certain +whatever part Thanks -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto a

Re: stupid question about ipv4 and ipv6?

2022-03-30 Thread Matus UHLAR - fantomas
is not relevant to the client connection. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Micro random number generator: 0, 0, 0, 4.33e+67, 0

Re: Unexpected Alias Behavior

2022-03-26 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Eagles may soar, but weasels don't get sucked into jet engines.

Re: Is it possible to send email by copying a file or files to an appropriate queue directory?

2022-03-22 Thread Matus UHLAR - fantomas
format into "sendmail -t". why do you need copying? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. There's a long-standing bu

Re: Q: configuring Postfix as a front for Exchange 365

2022-03-22 Thread Matus UHLAR - fantomas
wildcard @example.com going to @example.com.onmicrosoft etc. but this does not seem to work too well. I was hoping to be able to use a transport re-write but if I set it up it is ignored because of the virtual domain settings. Does anyone have any recommendations on how to go about with

Re: milter_header_checks, pcre, chroot

2022-03-22 Thread Matus UHLAR - fantomas
Received: header. pyspf-milter is fine here, so should be policyd-spf-python (same source package) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: milter_header_checks, pcre, chroot

2022-03-19 Thread Matus UHLAR - fantomas
clusion: As so often, it turns out that postfix, in this case "milter_header_checks", can do what is needed.  (Though it would be even better if it also supported PREPEND.) And thanks to Matus and PGNet Dev for interesting suggestions of alternative solutions that I may need if

Re: milter_header_checks, pcre, chroot

2022-03-18 Thread Matus UHLAR - fantomas
ation-Results" header. I would now like to do something (e.g., reject) depending on that header. On 2022-03-18 13:07, Matus UHLAR - fantomas wrote: opendmarc can reject itself, if you configure it to. On 18.03.22 13:46, Jesper Dybdal wrote: Thanks for your response. If the version of

Re: milter_header_checks, pcre, chroot

2022-03-18 Thread Matus UHLAR - fantomas
(s) before opendmarc. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "One World. One Web. One Program." - Microsoft promotional adv

Re: postscreen_dnsbl_sites precedence

2022-03-12 Thread Matus UHLAR - fantomas
ike this: ... list.dnswl.org=127.0.[0..255].[0..255]*-1 list.dnswl.org=127.0.[0..255].3*-1 so for *.3 responses (high) I expect -2 points this way. I can change it if needed, although it won't be so nice this way -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I w

Re: postscreen_dnsbl_sites precedence

2022-03-12 Thread Matus UHLAR - fantomas
= zen.spamhaus.org=127.[0..255].[0..254].[0..255]*2 afaik no. But, if you know you are forwarding DNS requests to any open DNS service, it's better not to use spamhaus and other dnsbls at all. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: Trying to understand this DNSBL blocking issue

2022-03-05 Thread Matus UHLAR - fantomas
rn off all forwarding for servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Your mouse has moved. Windows NT will now restart for chang

Re: Continuous quick connects / disconnects from some servers

2022-03-04 Thread Matus UHLAR - fantomas
sense. Other solution would of course be disabling SMTP connections from the world. Would postscreen help in a situation like the above, if the remote server is in some RBL? yes. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Multiple names for one mail server?

2022-02-27 Thread Matus UHLAR - fantomas
this since I knew they had many domains on single IPs and all were setup with MX records pointing to the domain name and not the host. It seems like it may be more trouble for one domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Multiple names for one mail server?

2022-02-26 Thread Matus UHLAR - fantomas
t server - perhaps add "mail.example.com" to alternative names for certificate of that mailserver. Otherwise their mail clients will complain about invalid certificate when they connect to it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive

Re: Multiple names for one mail server?

2022-02-26 Thread Matus UHLAR - fantomas
r from any errors ) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. M$ Win's are shit, do not use it !

Re: Multiple names for one mail server?

2022-02-25 Thread Matus UHLAR - fantomas
to the server? it does not need, it does not know, it does not care. Neither do spammers/viruses. I've encountered case where malware contacted nameservers of a domain to pass mail to it, despite MX records pointed elsewhere. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: persistent log of sent emails?

2022-02-24 Thread Matus UHLAR - fantomas
= next hop, not necessarily destination)? postfix uses syslog by default, you can filter logs using syslog daemon. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

<    1   2   3   4   5   6   7   8   9   10   >