Re: How to send 10 messages, per second, through my relayhost?

2022-02-23 Thread Matus UHLAR - fantomas
ing? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Due to unexpected conditions Windows 2000 will be released in first quarter of year 1901

Re: virtual_mailbox_maps & virtual_alias_maps

2022-02-20 Thread Matus UHLAR - fantomas
to dovecotu...@example.com should be rejected.) you must take care of this differently. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "To

Re: canonical_maps vs. *_recipient_maps

2022-02-20 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I'm not interested in your website anymore. If you need cookies, bake them yourself.

Re: SASL hacking ?

2022-02-19 Thread Matus UHLAR - fantomas
. We have listed all IPs. We can use a FW rule, but its heavy and hard to manage. A Postfix list may be easier. you can block these using fail2ban. it maintains IP addresses and blocklists. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: canonical_maps vs. *_recipient_maps

2022-02-18 Thread Matus UHLAR - fantomas
On 2/17/2022 6:47 AM, Matus UHLAR - fantomas wrote: last week's discussions showed that using *canonical_maps to e.g. map to different domains can result into taking all addresses as existing: https://marc.info/?l=postfix-users=164459031004167=2 https://marc.info/?l=postfix-users

canonical_maps vs. *_recipient_maps

2022-02-17 Thread Matus UHLAR - fantomas
to the docs or perhaps proper web search? Thanks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 42.7 percent of all statistics are made up

Re: gradual shift of traffic

2022-02-15 Thread Matus UHLAR - fantomas
much complexity needed to pass only part of your e-mail to relayhost. perhaps you could use smtp_fallback_relay http://www.postfix.org/postconf.5.html#smtp_fallback_relay which has a different meaning, but perhaps could to what you mean by "warming up" the new relay. -- Matus UH

Re: Rewriting @localhost to @$myhostname

2022-02-13 Thread Matus UHLAR - fantomas
uld make the rule more specific (a collection of 1:1 mappings) then that would help. excuse me, how does this work related to *_recipient_maps? Thank you -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varova

SRS implementing questions

2022-02-11 Thread Matus UHLAR - fantomas
curious, if I define TCP map that returns: % echo 'get postmas...@example.com' | nc -N localhost 10001 500 Domain excluded py policy - will this simply cause canonical maps not to hit? (500 looks like error) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Preserve milter_mail_macros

2022-02-09 Thread Matus UHLAR - fantomas
On 2022-02-09 21:03, Matus UHLAR - fantomas wrote: milter always gets its macros, they apparently don't contain what you want because mail is processed with amavis first. amavis can do DKIM-signing too, perhaps you should use it there. On 09.02.22 21:07, Michael Hallager wrote: I can

Re: Preserve milter_mail_macros

2022-02-09 Thread Matus UHLAR - fantomas
first. amavis can do DKIM-signing too, perhaps you should use it there. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Windows found: (R

Re: Received-SPF: Temperror

2022-02-06 Thread Matus UHLAR - fantomas
nse generates the Tempfail error. That's bad SW design. If one nameserver returns fail, you should try another one. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukol

Re: Add a disclaimer for all senders

2022-02-06 Thread Matus UHLAR - fantomas
ntent_filter=disclaimer: are you aware that submission only applies to mail submitted via port 587? It's seems yes but not sure. I mean, this way mail sent via port 587 will only be run through your disclaimer, the rest (25 465) only through amavis. I'm asking if this is what you wanted. -- Matus UH

Re: Add a disclaimer for all senders

2022-02-05 Thread Matus UHLAR - fantomas
claimer. Logically, I would advise you to use both, where amavis can feed the mail to another port with disclaimer service running. It depends on which mail you want to have disclaimer added to, but the Subject: says "all" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas

Re: Add a disclaimer for all senders

2022-02-04 Thread Matus UHLAR - fantomas
f access lists. also, it may misbehave. Any observations to the contrary are user errors. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. It's n

Re: Accepting expired client certificate

2022-02-03 Thread Matus UHLAR - fantomas
On Thu, Feb 03, 2022 at 06:51:09PM +0100, Matus UHLAR - fantomas wrote: sorry, the third one is not expired: Issuer: O = Digital Signature Trust Co., CN = DST Root CA X3 Validity Not Before: Jan 20 19:14:03 2021 GMT Not After : Sep 30 18:14:03 2024 GMT

Re: Accepting expired client certificate

2022-02-03 Thread Matus UHLAR - fantomas
On Thu, Feb 03, 2022 at 03:42:39PM +0100, Matus UHLAR - fantomas wrote: Certificate chain 0 s:CN = darwin.bork.org i:C = US, O = Let's Encrypt, CN = R3 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1 2 s:C = US, O = Internet

Re: Accepting expired client certificate

2022-02-03 Thread Matus UHLAR - fantomas
not able to query the certificate from these servers using `openssl s_client`. Because those are connections _to_ you, so those servers would not listen to connections at all. And TLS alerts are the other side is trying to tell you something. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: EHLO/HELO whitelist?

2022-02-03 Thread Matus UHLAR - fantomas
before any used ehlo restrictions you have in smtpd_*_restrictions. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "The box

Re: Inbound Mail Gateway Doubts

2022-01-28 Thread Matus UHLAR - fantomas
4.5.3.2.6. explains that the DATA timeout should be 10 minutes) since the antispam/antiviru filter needs to process the mail before it's delivered, the delay should be no different than with after-queue content filter. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: smtpd_reject_unlisted_recipient

2022-01-23 Thread Matus UHLAR - fantomas
f the mail has been blocked. Thank you for doing it this way. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up essenti

Re: Why would dovecot not be answering

2022-01-23 Thread Matus UHLAR - fantomas
in main.cf Everything I read says this should do it, but I am up against a wall. I have no debugging information or log at all to confirm what postfix is doing. maybe you miss some parts from http://www.postfix.org/SASL_README.html#server_sasl_enable -- Matus UHLAR - fantomas, uh

Re: Adding Additional domains and outgoing email

2022-01-18 Thread Matus UHLAR - fantomas
On Tue, Jan 18, 2022 at 04:50:11PM +0100, Matus UHLAR - fantomas wrote: don't use grep for master.cf, there are usuallu options on next lines # postconf -M smtps submission submission inet n - y - - smtpd -o syslog_name=postfix/submission -o

Re: Adding Additional domains and outgoing email

2022-01-18 Thread Matus UHLAR - fantomas
d_relay_restrictions=permit_sasl_authenticated,reject -o milter_macro_daemon_name=ORIGINATING -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. &qu

Re: nullmx_reject_code gone from source but not from docs

2022-01-17 Thread Matus UHLAR - fantomas
-- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Nothing is fool-proof to a talented fool.

Re: https://www.postfix.org/ in trouble

2022-01-16 Thread Matus UHLAR - fantomas
01=1=2 We will enter in the future when it will be done! I don't think that repeated bugging will get you anywhere. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Can i run postfix on my home IP

2022-01-13 Thread Matus UHLAR - fantomas
ou'll want non-generic name like mail.example.com. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user friendly, it's just selecti

Re: domain owner discourages use of this host

2022-01-11 Thread Matus UHLAR - fantomas
On 2022-01-11 18:16, Matus UHLAR - fantomas wrote: recipient follows what sender domain's admin configured. stop blaming recipient onto sender's problem. On 11.01.22 18:34, Benny Pedersen wrote: what went wrong here ? i dont reject softfails in mta stage, in spamassassin softfails is still

Re: domain owner discourages use of this host

2022-01-11 Thread Matus UHLAR - fantomas
? On 11.01.22 14:36, Benny Pedersen wrote: remote recipient does not like to get mail recipient follows what sender domain's admin configured. stop blaming recipient onto sender's problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Received-SPF: Softfail

2022-01-11 Thread Matus UHLAR - fantomas
On 11.01.22 05:00, Fourhundred Thecat wrote: What I am asking is, are there situations where legitimate sender (non-spam) would generate soft fail? On 2022-01-11 10:40, Matus UHLAR - fantomas wrote: misconfiguratons. On 11.01.22 12:54, Fourhundred Thecat wrote: I am quite happy to ban

Re: domain owner discourages use of this host

2022-01-11 Thread Matus UHLAR - fantomas
em related to my postfix mail server? On Tue, 11 Jan 2022 10:43:14 +0100 Matus UHLAR - fantomas wrote: looks liks SPF error. hard to tell more without logs. On 11.01.22 10:51, Enrico Morelli wrote: The only message in mail.log are the following: Jan 11 09:34:13 genio postfix/smtp[28088]:

Re: domain owner discourages use of this host

2022-01-11 Thread Matus UHLAR - fantomas
server? looks liks SPF error. hard to tell more without logs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is like a steel trap

Re: Re: After smtp authentication failed, is it possible to accecpt and send the email as anonymous?

2022-01-11 Thread Matus UHLAR - fantomas
parameter ignore smtp authentication, and accept the email? permit_mynetworks always ignores authentication, because it generates permis when client IP is in $mynetworks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Received-SPF: Softfail

2022-01-11 Thread Matus UHLAR - fantomas
am asking is, are there situations where legitimate sender (non-spam) would generate soft fail? misconfiguratons. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Default TLS protocols

2022-01-10 Thread Matus UHLAR - fantomas
communication is plaintext which gives even less security than disabling TLSv1 and TLSv1.1 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I

Re: No delivery delay notification for particular recipients?

2022-01-07 Thread Matus UHLAR - fantomas
is a SMTP command. see RFC 3461 section 4.1 this is SMTP transaction command, so you need to separate mail to these two recipients so only mail to those will get ugly-hacked. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to th

Re: SMTPD delay rejects evaluation]

2021-12-29 Thread Matus UHLAR - fantomas
gh I prefer blocking connection from those IPs at firewall level. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Depression is merely anger without enthusiasm.

Re: SMTPD delay rejects evaluation]

2021-12-25 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #98652: Operation completed successfully.

Re: After network outage postfix found not running

2021-12-23 Thread Matus UHLAR - fantomas
e logs were lost because of systemd's log limits there are multiple lined of postfix/master. it also could be systemd restarting postfix and giving up after some time -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this a

Re: How do I prevent bogus HELO ?

2021-12-22 Thread Matus UHLAR - fantomas
"Matus" == Matus UHLAR <- fantomas > writes: Matus> funny, some time ago I found spamrats very unrealiable, junkemailfilter Matus> realiability is imho on level of sorbs/uceprotect (scoring only) On 22.12.21 12:43, Togan Muftuoglu wrote: I am using selective blocklis

Re: How do I prevent bogus HELO ?

2021-12-22 Thread Matus UHLAR - fantomas
net mail.XX.bl.blocklists.de XX stands for the mirror used is US/UK/DE etc. spamrats.com hostkarma.junkemail.com spamrats.com funny, some time ago I found spamrats very unrealiable, junkemailfilter realiability is imho on level of sorbs/uceprotect (scoring only) -- Matus UHLAR - fantomas, uh...@fanto

Re: Assembling log entries for each SMTP session

2021-12-21 Thread Matus UHLAR - fantomas
would hope, so please bear with me. collate could help you: https://github.com/vdukhovni/postfix/tree/master/postfix/auxiliary/collate -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto ad

Re: symp to inn gateway

2021-12-18 Thread Matus UHLAR - fantomas
inn gateway and virtual_alias_maps for other alias expansion. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fucking windows! Bring Bill Gates! (Southpark the movie)

Re: SMTPS and submission protection

2021-12-12 Thread Matus UHLAR - fantomas
? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I feel like I'm diagonally parked in a parallel universe.

Re: are my helo restrictions too strict ?

2021-12-05 Thread Matus UHLAR - fantomas
k.com OK I also have permit_mynetworks and permit_sasl_authenticated at the start of smtpd_helo_restrictions. i would recommend using check_client_access instead of check_helo_access to allow anything, so you will whitelist client IP addresses, not helo strings they provide. -- Matus UHLAR - fantomas, uh.

Re: are my helo restrictions too strict ?

2021-12-03 Thread Matus UHLAR - fantomas
has IPv6 address 2a01:111:f400:7d00::200 c) or, is the domain really misconfigured? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE

Re: Sender Rewriting Scheme and backup MX

2021-11-19 Thread Matus UHLAR - fantomas
"Matus" == Matus UHLAR <- fantomas > writes: Matus> is it not. To be precise: Matus> SRS is to be used when you accept mail for one address and re-send to Matus> another address (in different domain/on different server). Matus> this is not the case for backup MX

Re: Sender Rewriting Scheme and backup MX

2021-11-18 Thread Matus UHLAR - fantomas
it is not a forwarder. (or is it ?) is it not. To be precise: SRS is to be used when you accept mail for one address and re-send to another address (in different domain/on different server). this is not the case for backup MX. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: feature request: improve vague/incorrect error message

2021-11-16 Thread Matus UHLAR - fantomas
a concern for me. (The last time I considered doing this I don't think I had such a surplus of inodes.) last time I checked the average file size was ~13KB (I guess it's gonna be more now), the inode_ratio in my mke2fs.conf is 16k, it should be enough. -- Matus UHLAR - fantomas, uh...@fantomas

Re: I need problem tu]o understand

2021-11-16 Thread Matus UHLAR - fantomas
rep postfix/filtered/smtpd /var/log/mail.log -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user friendly, it's just selective who its friends are...

Re: I need problem tu]o understand

2021-11-16 Thread Matus UHLAR - fantomas
On 16.11.21 10:06, natan wrote: I need some help about uderstand log: I have FILTER smtp-amavis:[127.0.0.1]:10628 On 16.11.2021 10:22, Matus UHLAR - fantomas wrote: you have this where? On 16.11.21 10:41, natan wrote: in master.cf: smtp-amavis unix

Re: I need problem tu]o understand

2021-11-16 Thread Matus UHLAR - fantomas
after retry the mail went well. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I wonder how much deeper the ocean would be without sponges.

Re: Postfix not talking to postgrey

2021-11-16 Thread Matus UHLAR - fantomas
, bot detection etc. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only substitute for good manners is fast reflexes.

Re: How to reject generic FCrDNS clients

2021-11-11 Thread Matus UHLAR - fantomas
refused" (trailing . should avoid matching IP Addresses) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Nothing is fool-proof to a talented fool.

Re: Nessus says I have an open relay

2021-11-09 Thread Matus UHLAR - fantomas
On 09.11.21 13:47, White, Daniel E. (GSFC-770.0)[NICS] wrote: On 11/9/21, 08:20, "owner-postfix-us...@postfix.org on behalf of Matus UHLAR - fantomas" wrote: so the server successfully accepted mail to remote recipient. That's called open relay. Note that nessus can't kn

Re: Nessus says I have an open relay

2021-11-09 Thread Matus UHLAR - fantomas
, dsn=4.7.1, status=deferred (host LOCAL_MDA[aaa.bbb.ccc.ddd] said: 454 4.7.1 : Relay access denied (in reply to RCPT TO command)) This means that the mailserver is not able to deliver the mail. The problem described by nessus is that it is willing to deliver it. exclude nessus's IP from $myne

Re: Nessus says I have an open relay

2021-11-09 Thread Matus UHLAR - fantomas
empts made by the scanner were rejected. I went through the logs with a fine-toothed comb and verified this. The stpid scanner is NOT seeing the rejections. I may need to wireshark this before submitting a bug report to Tenable. how were they rejected? -- Matus UHLAR - fantomas, uh...@fantomas

Re: aliasgroup

2021-11-08 Thread Matus UHLAR - fantomas
.postfix.org/FILTER_README.html version for postfix+amavis users: https://www.ijs.si/software/amavisd/README.postfix.html#basics_smtpd-daemon -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

IP ranges in mynetworks

2021-11-04 Thread Matus UHLAR - fantomas
I've read something like this described in postfix docs, but I'm struggling to find an example. thanks -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: AUTH rate limit

2021-11-03 Thread Matus UHLAR - fantomas
far you can use fail2ban -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. LSD will make your ECS screen display 16.7 million colors

FYI SMTP/25 security (was: "Correct" way to override cipher list?)

2021-10-30 Thread Matus UHLAR - fantomas
-kontroluje-zranitelnosti-svojich-it-systemov-vyvinul-si-ho-sam/ -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R)etry, (A)bort, (C)ancer

Re: Nessus says I have an open relay

2021-10-29 Thread Matus UHLAR - fantomas
: [...] mynetworks = 127.0.0.0/8 is it possible that IP of your nessus server is here? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The 3

Re: delete from hold queue

2021-10-28 Thread Matus UHLAR - fantomas
guess. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about cholesterol.

Re: Using a different DNS to ask zen.spamhaus.org for DNSBL info?

2021-10-22 Thread Matus UHLAR - fantomas
of DNS servers (BIND, unbound, knot-resolver) can do that properly, I think that dnsmasq is the one that can's (it's not designed to do that). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: postfix vpn problem

2021-10-20 Thread Matus UHLAR - fantomas
this only happens with postfix, but I'll find out somewhere else. I guess your VPN provider is hijacking your TCP connections to port 25. have you tried using port 465 for authenticated submission? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: Way to apply a postfix rule to both FROM and TO?

2021-10-18 Thread Matus UHLAR - fantomas
ostfix.org/RESTRICTION_CLASS_README.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Two words: Windows survives." - Craig Mundie, Microsoft senior

Re: DKIM signed by other domains breaks DMARC?

2021-10-17 Thread Matus UHLAR - fantomas
set up DMARC for your domain, DMARC won't pass, but Yahoo DKIM should not break anything. DMARC and DKIM apply for your sending domain (the one in From:). signing by other domains usually make no sense. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: knocking - still exist - how to block?

2021-10-13 Thread Matus UHLAR - fantomas
212.70.149.71 there. And, postfix/smtps is on port 465 - I don't think you run postscreen on port 465 (you should not do that) but without success* use fail2ban -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: turning off spamass-milter for authenticated submissions? SPF for submitted emails?

2021-10-13 Thread Matus UHLAR - fantomas
-I Ignores messages if the sender has authenticated via SMTP AUTH. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Quantum mechanics: The dreams stuff is made of.

Re: any staff from the provider 5x2.de?

2021-10-10 Thread Matus UHLAR - fantomas
ly doing something that breaks forwarding, which is especially silly when they were able to do SRS in order not to break SPF. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: About "transport_maps" : when this paraméter is set smtp does not deliver mail localy

2021-10-07 Thread Matus UHLAR - fantomas
ad of delivering via relay_host or other host(t) in transport_maps. in order to deliver mail locally, the destination domain must be treated as local domain. You can't do that via transport_maps. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receiv

Re: cleanup services cpu overload

2021-10-01 Thread Matus UHLAR - fantomas
nt than pcre:. The reason for having regexp support in Postfix is that every system library must support that, while pcre support is an addon. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tut

Re: Filtering MAIL FROM for autenticated users

2021-09-28 Thread Matus UHLAR - fantomas
m" for autenticated users to prevent sending emails with a "third party" domain. I have read the documentation and did not reached any conclusion. My best guess is that is some configuration that may be passed as an option to submission and smtps. What is the proper way to do somethin

Re: Spam pass the filter

2021-09-20 Thread Matus UHLAR - fantomas
not contain) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux is like a teepee: no Windows, no Gates and an apache inside...

Re: How can I temporarily defer internal delivery of e-mails?

2021-09-11 Thread Matus UHLAR - fantomas
On 11.09.21 13:57, Nick Howitt wrote: So putting your restriction at the beginning. cat /etc/postfix/recipient_checks.pcre /.*\@.*/ HOLD are you two aware, that simple '.' would match as well? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive

Re: Validating FROM address against users

2021-09-02 Thread Matus UHLAR - fantomas
And thanks for the initial issue of figuring out I had smtpd_reject_unlisted_sender incorrectly set. Im done with this issue. On 09-02-2021 10:24 am, Matus UHLAR - fantomas wrote: incorrectly? Unless you tend to send mail from non-existing addresses, I recommend you setting

Re: Validating FROM address against users

2021-09-02 Thread Matus UHLAR - fantomas
addresses, I recommend you setting smtpd_reject_unlisted_sender=yes. This way you won't need to help with bounces to non-existing addresses. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: Whitelist sender if past recipient

2021-09-01 Thread Matus UHLAR - fantomas
-archive.com/amavis-user@lists.sourceforge.net/msg04896.html penpal that could work... in spamassassin it could be added via TxRep ...but txrep is completely different functionality. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Error appended to bounce.cf

2021-08-26 Thread Matus UHLAR - fantomas
and it's quite impossible to catch them all -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The early bird may get the worm, but the second

Re: Mail spool issues with Postfix

2021-08-25 Thread Matus UHLAR - fantomas
an intended feature or not, but I'd like to disable it and remove the mail in /var/mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: Rate limit exception?

2021-08-23 Thread Matus UHLAR - fantomas
]: disconnect from mxc01.zoneedit.com[64.68.198.23] commands=0/0 Is there a way I could except that server from the rate limit? And could that be misused (a lot of spammers already send to the backup MX anyway) http://www.postfix.org/postconf.5.html#smtpd_client_event_limit_exceptions -- Matus UHLAR

Re: Hostname DNS error

2021-08-21 Thread Matus UHLAR - fantomas
this whenever you run spam filter and/or DNS blocklist -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. LSD will make your ECS screen display

Re: Question on DKIM signature

2021-08-16 Thread Matus UHLAR - fantomas
DKIM safe. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do you want to go to die?" [Microsoft]

Re: Question on DKIM signature

2021-08-16 Thread Matus UHLAR - fantomas
with mailing lists. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only substitute for good manners is fast reflexes.

Re: How to force remote deliver agent to send messages via SSL only

2021-08-15 Thread Matus UHLAR - fantomas
for getting mail (IMAPS/POPS), rather than for sending mail (SMTP/STARTTLS). I don't know. If so, it might only affect e.g. Dovecot's choice of certificate rather than Postfix's. But chances are, if you use both, you'll probably want them to use the same certificate. -- Matus UHLAR - fantomas, uh

Re: How to force remote deliver agent to send messages via SSL only

2021-08-15 Thread Matus UHLAR - fantomas
On Sat, Aug 14, 2021 at 02:43:29PM +0200, Matus UHLAR - fantomas wrote: - dedicated port for smtp/ssl was deprecated (in fact never standrdized) On 15.08.21 09:04, raf wrote: I think that used to be true, but they had a rethink. This proposed standard (Jan 2018) indicates so: 3.3

Re: How to force remote deliver agent to send messages via SSL only

2021-08-14 Thread Matus UHLAR - fantomas
) - nowadays, dedicated port is for clients, not for server-server communication - so far most of systems try on port 25 and upgrade to SSL via STARTTLS, when possible. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: will this break DMARC?

2021-08-14 Thread Matus UHLAR - fantomas
headers changes on transit here, dont sign every header at signing stata Sender: changed by postfix mailing list and it was in thesignature, that's why it failed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: delivery rules question

2021-08-13 Thread Matus UHLAR - fantomas
/reserved domain name -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "To Boot or not to Boot, that's the question." [WD1270 Caviar]

Re: EHLO argument validation

2021-08-09 Thread Matus UHLAR - fantomas
On 2021-08-08, at 16:13 (UTC+0200), Matus UHLAR - fantomas had the following to say: : are you searching for disabling particular strings in helo/ehlo command? On 08.08.21 22:04, Mono DHS wrote: No, I would like to validate the argument to the EHLO command (actually, to both the EHLO

Re: EHLO argument validation

2021-08-08 Thread Matus UHLAR - fantomas
strings are in clients' control and anyone can change them as they wish (I personally did disable using of my hostname in HELO strings because abusers used it but that's apparently the only usage I can think of). - If not, please rephrase. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: Inbound/Outbound Settings on a Postfix Relay-Only

2021-08-07 Thread Matus UHLAR - fantomas
estination, so the local transport was selected. You have disabled it above. relay_transport = hash:/etc/postfix/transport .our.local.domain relay:[MDA server IP] if it has to be .our.local.domain, keep .our.local.domain out ot $mydestination -- Matus UHLAR - fantomas, uh...@f

Re: SMTP Relay

2021-08-07 Thread Matus UHLAR - fantomas
to IP 172.16.101.1 why? the DNAT is apparenly what makes it not work, SNAT (or MASQUERADE) should be enough. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: "parameter inet_interfaces: no local interface found for 127.0.0.2" at reboot, but not on manual systemctl start

2021-07-30 Thread Matus UHLAR - fantomas
AM, Matus UHLAR - fantomas wrote: sorry, but this manpage says that localhost resolvs to 127.0.0.1 (as it always should). according to systemd-resolved manpage, the local host name is resolved to 127.0.0.2 (not localhost) maybe a just mistake in your description? On 29.07.21 12:18, Jim Garrison

Re: Has rfc2487 been obsoleted and mandatory TLS in smtpd is now kosher?

2021-07-29 Thread Matus UHLAR - fantomas
ed and they'll only support TLSv1.2+. The only alternative would be to close port 25, use port 465 (TLS-only) instead, and hope that all mail servers that want to send them email try to use port 465. But that's not going to happen. many of mailservers refuse unauthenticated mail on port 465, so

Re: "parameter inet_interfaces: no local interface found for 127.0.0.2" at reboot, but not on manual systemctl start

2021-07-29 Thread Matus UHLAR - fantomas
, but this manpage says that localhost resolvs to 127.0.0.1 (as it always should). according to systemd-resolved manpage, the local host name is resolved to 127.0.0.2 (not localhost) maybe a just mistake in your description? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: My sender_access file is not working

2021-07-28 Thread Matus UHLAR - fantomas
Magalu - Aproveite! - [ 95271443633 ] From: Ofertas Magazine Luiza-38 header From: if often different from envelope from. postfix directives are related to envelope from. We don't see envelope from here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: mail for 'root' delivery blocked :(

2021-07-28 Thread Matus UHLAR - fantomas
Le 28/07/2021 à 09:36, Matus UHLAR - fantomas a écrit : this mean that your server is going to send mail to "server.mydomain.com" and your postfix sees it should deliver domain to itself, but postfix does not know how to handle mail for server.mydomain.com - you h

Re: mail for 'root' delivery blocked :(

2021-07-28 Thread Matus UHLAR - fantomas
- here you define smtpd_recipient_restrictions again -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Despite the cost of living, have you

Re: receiving mail for other hosts...

2021-07-16 Thread Matus UHLAR - fantomas
serB@host2 ? How can I make our mail server accept mail for all our local hosts? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. If Ba

<    1   2   3   4   5   6   7   8   9   10   >