Re: MAILER-DAEMON and time

2021-03-03 Thread Matus UHLAR - fantomas
On 2021-03-03 16:03, Matus UHLAR - fantomas wrote: On 2021-03-03 10:45, natan wrote: This is server for incomming e-mail with many vdomain and vusers On 03.03.21 11:38, Benny Pedersen wrote: number of domains is irrelevant for backscatter I check rbl in smtpd_recipient_restrictions

Re: MAILER-DAEMON and time

2021-03-03 Thread Matus UHLAR - fantomas
still need postconf -nf perferble to help more, all i can do without it it will be best expirense and google for my part -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: can't send to GSuite mailserver via IPv6 protocol

2021-03-01 Thread Matus UHLAR - fantomas
if the MX points to it and if it's ipv4 or ipv6 ...with ipv6 lack of rDNS may be worse but with ipv4 it's still a problem -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: local system mail

2021-02-25 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One OS to rule them all, One OS to find them, One OS to bring them all and into darkness bind them

Re: Deprecated: white is better than black

2021-02-24 Thread Matus UHLAR - fantomas
oversensitive group of Americans. however, the "allow" and "deny" clearly say something, while for understanding what does "white" and "black" mean, you must have some background (or, worse, prejudice). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; h

Re: smtp_tls_CAfile and smtp_tls_CApath doc

2021-02-11 Thread Matus UHLAR - fantomas
ermediate CA >certificate) does not fit in 'smtp_tls_CAfile' but in >'smtp_tls_CApath'. On Thu, Feb 11, 2021 at 3:11 PM Matus UHLAR - fantomas wrote: huh? On 11.02.21 16:01, bitozoid wrote: 'smtp_tls_CAfile' doc just mentions "root CAs" for the content of the file. yes. smtp_

Re: smtp_tls_CAfile and smtp_tls_CApath doc

2021-02-11 Thread Matus UHLAR - fantomas
ctives smtpd_tls_cert_file smtpd_tls_key_file, smtpd_tls_eccert_file, smtpd_tls_eckey_file supposed to contain certificates and keys. Certificates can be concatenated in cert files, which can also include private keys. http://www.postfix.org/TLS_README.html -- Matus UHLAR - fantomas, uh...@fantomas.s

Re: client and ehlo hostname mismatch

2021-02-11 Thread Matus UHLAR - fantomas
? yes, however that has nothing to do with helo. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Depression is merely anger without

Re: client and ehlo hostname mismatch

2021-02-11 Thread Matus UHLAR - fantomas
can avoid that by not using helo/ehlo at all. there's no setting to reject HELO name that doesn't resolve to IP of a client, mostly because it violates so far all SMTP RFCs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail a

Re: Can I get postfix to use what's returned by dnsdomainname for mydomain?

2021-02-11 Thread Matus UHLAR - fantomas
On 10.02.21 15:55, Chris Green wrote: > I could just edit the value in each system, but then all the main.cf > files would be different. On Wed, Feb 10, 2021 at 05:31:47PM +0100, Matus UHLAR - fantomas wrote: setting "myhostname = $(dnsdomainname)" what Wietse r

Re: Can I get postfix to use what's returned by dnsdomainname for mydomain?

2021-02-10 Thread Matus UHLAR - fantomas
me years ago, when I maintained the same configs for multiple apps on multiple servers. I maintained /etc/hosts and hostnames per-machine and most of the rest was the same. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: disable local delivery for virtual alias domain

2021-02-10 Thread Matus UHLAR - fantomas
to send all email direct to virtual  "x.com" using relayhost and not locally delivered. put it out of virtual_alias_domains or wherever it's defined. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. V

Re: Can I get postfix to use what's returned by dnsdomainname for mydomain?

2021-02-10 Thread Matus UHLAR - fantomas
? the default is get from your myhostname, can't you set up that one? btw are you sure you dont mean myorigin instead of mydomain? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: why people connect clamav as milter in main.cf and smapassassin in master.cf?

2021-02-10 Thread Matus UHLAR - fantomas
run server behing NAT, I ask to NAT 25 from the world to other port where I run postscreen and milters. Note that I usually run amavis which calls both spamassassin and clamav. Either as content_filter, or via amavisd-milter. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warni

Re: Stucked with "unable to look up host"

2021-02-10 Thread Matus UHLAR - fantomas
-- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up essential liberty to obtain a little temporary safety deserve neither

Re: Stucked with "unable to look up host"

2021-02-09 Thread Matus UHLAR - fantomas
2, !SSLv3 should be enough for now. >After adjusting values the recommended way not getting > >connect to correo.dominio.com.ar[]:25: Connection timed out El lun., 8 de febrero de 2021 10:20, Matus UHLAR - fantomas < uh...@fantomas.sk> escribió: % host -t any co

Re: Stucked with "unable to look up host"

2021-02-09 Thread Matus UHLAR - fantomas
On 31.01.21 09:56, Daniel Armando Rodriguez wrote: Indeed, it was running chrooted but resolv.conf has the same content === # postconf -nf smtp_tls_protocols = TLSv1.2, !TLSv1.1, !TLSv1, !SSLv2, !SSLv3 On 08 Feb 2021, at 06:20, Matus UHLAR - fantomas wrote: this is superflous

Re: postscreen

2021-02-08 Thread Matus UHLAR - fantomas
On 08.02.21 14:48, maciejm wrote: What I must set to enable "postscreen" ? On 08.02.2021 14:50, Matus UHLAR - fantomas wrote: it's described on: http://www.postfix.org/POSTSCREEN_README.html I ask because I must use "-o receive_override_options=no_address_mappings" in

Re: Communication between postfix - amavis issues

2021-02-08 Thread Matus UHLAR - fantomas
On 8/2/2021 1:38 μ.μ., Matus UHLAR - fantomas wrote: that's not how milter works, unless you instructed amavisd-milter to deliver mail by server via "-D server" option. The default is "-D client", which means, amavisd instructs postfix what to do with the mail - reject/qua

Re: postscreen

2021-02-08 Thread Matus UHLAR - fantomas
    1   proxymap smtp   unix  -   -   y   -   -   smtp    -o smtp_helo_timeout=5 -o smtp_connect_timeout=5 ... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie:

Re: TCP wrappers and Postfix

2021-02-08 Thread Matus UHLAR - fantomas
with invalid address<->name mapping The last two produce the major bulk of spambot connections. Are there any other means to achieve these? you can block these at smtpd level. Postscreen doesn't (and won't) check for reverse hostname. -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: Stucked with "unable to look up host"

2021-02-08 Thread Matus UHLAR - fantomas
intext, and encryption is not fully standard, so you disable sending mail to part of internet. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Sil

Re: Communication between postfix - amavis issues

2021-02-08 Thread Matus UHLAR - fantomas
H36X5JzLlrw: client=hedgehog.birch.relay.mailchannels.net[23.83.209.81] Feb  8 01:54:56 mailgw1 postfix/cleanup[202468]: 4DYmH36X5JzLlrw: message-id=<464576df-43d0-ecac-5647-99c91a95c...@example.com> ... again, FILTER applies after mail is received, so next lines in log should show how the mail is delivered to amavis on p

Re: Accessing local recipient from within an smtpd policy server: how?

2021-02-05 Thread Matus UHLAR - fantomas
to make script that will resolve aliases to get user from mail address, just because of different reason. hopefully, some day I'll do it. See my discussion with wietse some time ago: https://marc.info/?t=15986316001=1=2 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: Catch a forged Return Path

2021-02-05 Thread Matus UHLAR - fantomas
ressource and i have it setup more or less the way described there + some minor adjustments needed for my setup. I would recommend starting with http://www.postfix.org/POSTSCREEN_README.html to understand what those options mean. I think barracudacentral is subscription-only. -- Matus UHLAR

Re: Catch a forged Return Path

2021-02-04 Thread Matus UHLAR - fantomas
ook up empty envelope sender, unless you changed smtpd_null_access_lookup_key: http://www.postfix.org/postconf.5.html#smtpd_null_access_lookup_key however as I said, rfc 1123 (5.2.9) requires you to support empty sender address and you may get blacklisted if you refuse to do so. -- Matus UHLA

Re: Catch a forged Return Path

2021-02-04 Thread Matus UHLAR - fantomas
reject_non_fqdn_sender into smtpd_sender_restrictions: Jan 18 09:17:31 smtp1 postfix/smtpd[13065]: NOQUEUE: reject: RCPT from xxx.xxx.xxx[a.b.c.d]: 504 5.5.2 : Sender address rejected: need fully-qualified address; from= to= proto=ESMTP helo= -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: srs rewrite

2021-02-02 Thread Matus UHLAR - fantomas
forwarding’s supposed to work? mail from null address is not supposed to be returned back. This is done to avoid mail loops and double bounces. Therefore, no SRS is needed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Postfix - Check SPF for outgoing email

2021-02-01 Thread Matus UHLAR - fantomas
nding mail from other domains than those allowed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up essential liberty

Re: batching all mails to one or more domains to a non-permanently-powered machine with dynamic addresses

2021-01-30 Thread Matus UHLAR - fantomas
Dnia 29.01.2021 o godz. 19:29:14 Matus UHLAR - fantomas pisze: yes, but OTOH I'm not sure if fetchmail or getmail support single mail for multiple recipients. On 29.01.21 22:24, Jaroslaw Rafa wrote: From fetchmail website: "Fetchmail can be used as a POP/IMAP-to-SMTP gateway for an e

Re: Trouble with STARTTLS...Connection lost

2021-01-30 Thread Matus UHLAR - fantomas
>> smtpd_tls_exclude_ciphers=MD5,SRP,PSK,aDSS,kECDH,kDH,SEED,IDEA,RC2,RC5,RC4,3DES >> smtpd_tls_mandatory_exclude_ciphers=aNULL > >Mostly harmless, but not necessary. On Fri, Jan 29, 2021 at 06:53:09PM +0100, Matus UHLAR - fantomas wrote: yes, but when the policy is e

Re: batching all mails to one or more domains to a non-permanently-powered machine with dynamic addresses

2021-01-29 Thread Matus UHLAR - fantomas
On 29.01.21 12:39, Matus UHLAR - fantomas wrote: I'd recommend considering domain mailboxes. On 29.01.21 19:00, Hadmut Danisch wrote: Is there any better way to do this than local(8) and X-Original-To: ? I don't know of any As far as I know, local(8) cannot cope with mails to multiple

Re: Trouble with STARTTLS...Connection lost

2021-01-29 Thread Matus UHLAR - fantomas
On Fri, Jan 29, 2021 at 02:08:48PM +0100, Matus UHLAR - fantomas wrote: Excluding aNULL should not be needed on smtp port, but apparently is useful on ports with mandatory encryption. On 29.01.21 11:53, Viktor Dukhovni wrote: It is only ever *needed* on the client side, when *authenticating

Re: Trouble with STARTTLS...Connection lost

2021-01-29 Thread Matus UHLAR - fantomas
ile with intermediate certificate to our certificate specified by smtpd_tls_cert_file, the authority gets added to certificate chain. I'm curious if this is intentional. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addr

Re: batching all mails to one or more domains to a non-permanently-powered machine with dynamic addresses

2021-01-29 Thread Matus UHLAR - fantomas
hable from Internet due to firewall restrictions) ATRN would be answer to this but I don't know about implementation working with postfix. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na t

Re: Spam relay problems - need some config assistance

2021-01-24 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Despite the cost of living, have you noticed how popular it remains?

Re: restricted inbound on 587

2021-01-19 Thread Matus UHLAR - fantomas
rs on port 25 - you can spam them that way. simply said, by blocking port 25 your provider prevents you from sending spam and requires you to use mail service of them or other providers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail a

Re: virtual_alias_maps ignored after switching from spamassassin (amavis) to rspamd (milter)

2021-01-18 Thread Matus UHLAR - fantomas
On 18.01.21 12:45, Daniel Caillibaud wrote: >After switching to rspamd (was amavis+spamassassin), virtual_alias_maps seems to be ignored >(mail to aliases address are bounced with "user unknown"), and I don't find why… Le 18/01/21 à 13:13, Matus UHLAR - fantomas a écr

Re: virtual_alias_maps ignored after switching from spamassassin (amavis) to rspamd (milter)

2021-01-18 Thread Matus UHLAR - fantomas
d (user unknown) postfix/bounce[24922]: 6DD04222ED4: sender non-delivery notification: 87950222EDA postfix/qmgr[24883]: 6DD04222ED4: removed -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na t

Re: SASL auth cache?

2021-01-17 Thread Matus UHLAR - fantomas
re-auth? I've had this problem with cyrus sasl IIRC. restarting saslauthd helped. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Posli tento ma

Re: restricted inbound on 587

2021-01-17 Thread Matus UHLAR - fantomas
d. I don't see any incoming traffic on port 587 at all. I wonder, internet bots try port 587 on any hosts within minutes. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: behavior when connecting client triggers several errors

2021-01-14 Thread Matus UHLAR - fantomas
strings for authenticated mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. It's now safe to throw off your computer.

Re: Using header_checks to file mail into junk folder

2020-12-31 Thread Matus UHLAR - fantomas
ilter file. the solution can be restricting what user can do in their rules. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Your mouse has moved.

Re: resolve virtual aliases from cmdline

2020-12-23 Thread Matus UHLAR - fantomas
til no expansions are made or cycle through all maps with all lookups? thanks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfamiliar territory.

Re: Filename in main.cf, specifically myorigin = /etc/mailname

2020-12-23 Thread Matus UHLAR - fantomas
use of a file) in man 5 postconf. On 06.12.20 12:10, Wietse Venema wrote: >That's a DEBIAN-specific feature. Matus UHLAR - fantomas: but debian-specific is only the defaut value, postfix support /file/name for myorigin by default, correct? On 22.12.20 10:30, Wietse Venema wrote: THIS CO

Re: Filename in main.cf, specifically myorigin = /etc/mailname

2020-12-22 Thread Matus UHLAR - fantomas
*origin = read_param_from_file(var_myorigin); if (*origin == 0) msg_fatal("%s file %s is empty", VAR_MYORIGIN, var_myorigin); myfree(var_myorigin); /* FIX 20070501 */ var_myorigin = origin; } #endif -- Matus UHLAR - fa

Re: spf failures on forwarded emails

2020-12-11 Thread Matus UHLAR - fantomas
simply change mail from: to your locl address, but it will get the errors for delivery failures then. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: Immediate NDR on Domain Typos

2020-12-07 Thread Matus UHLAR - fantomas
I'm not sure if the right place is check_recipient_access and if things are different under the current version vs the older 2.11.x nail.com. 900 IN MX 10 mx.hover.com.cust.hostedemail.com. this must be rejected explicitly. -- Matus UHLAR - fantomas, uh

Re: postfix with mysql - too many connections

2020-12-04 Thread Matus UHLAR - fantomas
tc/postfix/memcache_recipient_whitelist_cache.cf you need to increate maximum connections available to mysql server. parameter max_connections on mysql conig. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: About messages bounced due name resolution issues using IPv6

2020-12-04 Thread Matus UHLAR - fantomas
oint. the point is, especially with allow/blocklists and spam filters, using own DNS resolvers is important, since shared DNS servers are often blocked by public DNS lists and the effectivity of filtering lowers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: Adding route to Gateway server

2020-12-03 Thread Matus UHLAR - fantomas
, but our Cyber team wanted us to implement a journaling mailbox/server and bcc all inbound and outbound to/from the internet emails to this mail...@server.com<mailto:mail...@server.com>. they need to forward syslog as well, since the original recipient information is lost this way. -- Matus

Re: adding transport functionality causes a mail loop

2020-11-25 Thread Matus UHLAR - fantomas
to mailman ie the list it gets re-directed to the other postfix server, which sends it back and we get a mail loop. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: empty message-ID

2020-11-25 Thread Matus UHLAR - fantomas
On 25/11/20 1:53 am, Matus UHLAR - fantomas wrote: However, this thread is off-topic. We should close it with conclusion: don't avoid duplicate mail based on Message-Id: On 25.11.20 15:04, Peter wrote: A better conclusion would be to not consider messages with a missing or empty Message-Id

Re: empty message-ID

2020-11-24 Thread Matus UHLAR - fantomas
On 24.11.20 13:50, Matus UHLAR - fantomas wrote: note that it's possible to Bcc: message to mailing list so it does not contain list address in To:/Cc: ... as this message clearly shows. I set mailing lists not to avoid duplicate messages (and usually drop direct mail). However, this thread

Re: empty message-ID

2020-11-24 Thread Matus UHLAR - fantomas
in To:/Cc: -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "The box said 'Requires Windows 95 or better', so I bought a Macintosh".

Re: empty message-ID

2020-11-23 Thread Matus UHLAR - fantomas
ame=bi...@domain2.ltd Nov 23 13:13:53 smtp1 postfix/cleanup[46909]: 4CfmKF1CSDz5MwK: message-id=<> Nov 23 13:13:53 smtp1 postfix/qmgr[25287]: 4CfmKF1CSDz5MwK: from=, size=94874, nrcpt=3 (queue active) . client's MUA apparently does not generate Message-Id: header. -- Matus UHLAR -

Re: DKIM signature only for a certain login - sender domain combination

2020-11-22 Thread Matus UHLAR - fantomas
map with a FILTER: destination: http://www.postfix.org/access.5.html However, since signing is based on From: address and directives above use envelope address (mail from:), you should verify that they match before you sign. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: Receiving domain only hase MX records and no A records.

2020-11-18 Thread Matus UHLAR - fantomas
to receive emails? Would just MX records be enough? A is needed for sending mail over ipv4, is needed for sending mail over ipv6. What's your inet_protocols settings? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Getting 'Relay access denied' from one LAN host but not from another - why?

2020-11-11 Thread Matus UHLAR - fantomas
tworks allow E-Mail from 2820n.zbmc.eu[192.168.1.20] as it does allow it from pibackup.zbmc.eu[192.168.1.108]? Can anyone suggest what might be wrong? only if 192.168.1.20 was in your mynetworks list, and it is not. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I

Re: rewriting subject text into body

2020-11-11 Thread Matus UHLAR - fantomas
should happen before this and when forwarging altered message outside, you may get such mail rejected, so you must use DKIM-aware forwarder -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: limit connections

2020-11-08 Thread Matus UHLAR - fantomas
, they will get 4xx information about exceeding the limit once again: On 06.11.20 12:08, Matus UHLAR - fantomas wrote: So, are your sending mail to them or receiving mail from them? who is sending mail where? Apparently you receive lots of e-mail from/to nonexistent users, you should configure

Re: Receiving emails from my own address

2020-11-07 Thread Matus UHLAR - fantomas
ly works for MAIL FROM, see http://www.postfix.org/postconf.5.html#smtpd_sender_restrictions http://www.postfix.org/postconf.5.html#check_sender_access -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie:

Re: Receiving emails from my own address

2020-11-06 Thread Matus UHLAR - fantomas
ter that you can use directives like: reject_sender_login_mismatch reject_known_sender_login_mismatch reject_unauthenticated_sender_login_mismatch in smtpd_sender_restrictions, which should do what you want. Em sex., 6 de nov. de 2020 às 10:42, Matus UHLAR - fantomas < uh...@fantomas.sk> esc

Re: Receiving emails from my own address

2020-11-06 Thread Matus UHLAR - fantomas
on the internet. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "One World. One Web. One Program." - Microsoft promotional adv

Re: limit connections

2020-11-06 Thread Matus UHLAR - fantomas
, they will get 4xx information about exceeding the limit So, are your sending mail to them or receiving mail from them? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Block spam messages to Unknown receiver

2020-11-06 Thread Matus UHLAR - fantomas
-spf[15576]: prepend Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=198.144.154.163; helo=a.benient.com; envelope-from=qbc...@benient.com; receiver= read policyd-spf documentation. It apparently did not start processing the recipient yet. -- Matus UHLAR - fantomas, uh...@fantomas

Re: limiting connections to a single host

2020-11-05 Thread Matus UHLAR - fantomas
enty_limit for that destination to required limit. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only substitute for good manners is fast reflexes.

Re: aliasgroup + lmtp + Connection timed out

2020-11-03 Thread Matus UHLAR - fantomas
ion server has reached limit and does not accept connections. increasing concurrency limit on the postfix side does not help here. Increasing maximum number of servers on port 24 could help in the last case. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I w

Re: Configuration problem — Postfix + Sympa

2020-11-03 Thread Matus UHLAR - fantomas
is DKIM designed. that's not fault of mailman. On 02.11.20 15:24, Phil Stracchino wrote: Sympa *explicitly supports* DKIM and ARC. Another reason for switching. :) mailman supports DKIM. it's not mailman who breaks it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: 'temporary error condition' overrides of unknown_client_reject_code 450?

2020-10-30 Thread Matus UHLAR - fantomas
IP address<->hostname mapping what you want here is unknown_address_reject_code -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: warning: Connection rate limit exceeded: 10 from localhost[127.0.0.1] for service 127.0.0.1:10025

2020-10-29 Thread Matus UHLAR - fantomas
] for service 127.0.0.1:10025 What did I miss? smtpd_client_connection_rate_limit -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Posli

Re: Verify the proper configuration for blocking/whitelisting a sender.

2020-10-28 Thread Matus UHLAR - fantomas
- you can replace 1.5.6.0/24 by 1.5.6 in hash maps but cidr is more comfort -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do

resolve virtual aliases from cmdline

2020-08-28 Thread Matus UHLAR - fantomas
Pass all remaining options to spamc. This allows you to connect to a remote spamd with -d or -p. Anyone's got an idea how to get this with postfix? Postfix's "sendmail -bv" sends real mail to recipient. only expanding virtual aliases should be fine. -- Matus

Re: TLS Settings and Mobile Clients

2020-08-03 Thread Matus UHLAR - fantomas
) mobile operability? Or, does anyone have any better general guidelines for hardening Postfix? to allow clients you should enable ports submission (587) and submissions (465) in master.cf. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: Cached postscreen blacklist bypass

2020-07-15 Thread Matus UHLAR - fantomas
enforce. Drop makes clients retry. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I wonder how much deeper the ocean would be without sponges.

Re: User doesn't exist via lmtp

2020-07-15 Thread Matus UHLAR - fantomas
to use only the domainpart in users address to deliver mail? you apparently mean only the localpart, and I think it's not posible. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Cached postscreen blacklist bypass

2020-07-14 Thread Matus UHLAR - fantomas
]:37300 Jul 13 23:50:33 mx1 postfix/smtpd[3580]: connect from pupiledition.club[84.54.12.227] Is that intentional? Fixable? Work-aroundable? your postscreen_blacklist_action is apparently set to ignore (default). set it to enforce to reject the client. -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: How To Rewrite "Mail From:"?

2020-07-07 Thread Matus UHLAR - fantomas
by implementing SRS (forwarding that keeps SPF working). Domains that configure DMARC but not DKIM (are there such?) are of course in trouble when their mail is forwarded this way. The simplest thing to do is to encapsulate the original message as attachment to a new message. yes, this should work

Re: Can I further block dodgy attempts at passwording

2020-07-06 Thread Matus UHLAR - fantomas
illog" | sed 's/.*\[\([^]]*\)\].*/\1/g' | sort -V | uniq > "/tmp/Bad_IP.txt" you will miss any that tries multiple passwords in one session I guess... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this

Re: Content filter replied to HELO/EHLO with my own hostname

2020-07-06 Thread Matus UHLAR - fantomas
with the same hostname? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Remember half the people you know are below average.

Re: Move queue to another Server, it's possible?

2020-07-03 Thread Matus UHLAR - fantomas
unholded so postfix will retry delivery when configuring a new interface, let's call interface number 5, it is possible to move the mails assigned to interface number 1 and number 2 to interface number 5? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: content_filter with external script and virtual_alias_maps

2020-07-03 Thread Matus UHLAR - fantomas
other delivers it to mail store. you can do this in virtual alias table, alias table, in .forward file etc. Note that with alias table or .forward, failure to deliver to the script can result in multiple delivery. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning:

Re: Checking my understanding of TLS-related settings, and a possible feature request

2020-07-03 Thread Matus UHLAR - fantomas
were told that our mail relays must accept only TLSv1.2 when doing TLS, and not any prior versions. I would say this is acceptable for ports with required encryption and authentication, not for standard SMTP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT

Re: postfix: Undelivered Mail Returned to Sender error

2020-07-02 Thread Matus UHLAR - fantomas
through your ISP server? postfix tries to deliver mail directly by default, so it's apparently your home address that is blacklisted. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Postfix behind NAT -> failover IP -> wrong HELO

2020-07-02 Thread Matus UHLAR - fantomas
it yourself. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Eagles may soar, but weasels don't get sucked into jet engines.

Re: Cannot assign requested address -- with "inet_protocol = ipv4" in main.cf

2020-06-26 Thread Matus UHLAR - fantomas
xx.xxx.199 scope global secondary noprefixroute ens4:8 valid_lft forever preferred_lft forever I did notice 74.xxx.xxx.192 does not have the keyword "secondary" above -- the network-script that created ens4:1 is the same as all the other seven secondaries. -- Matus UHLAR - fantoma

Re: postfix smtp only with sasl auth

2020-06-24 Thread Matus UHLAR - fantomas
. This is the worst idea. If any of servers will be hacked or password somehow revealed, you will have to change it on all servers, maybe repeatedly. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie

Re: Unable to connect Apple mail client but not thunderbird

2020-06-23 Thread Matus UHLAR - fantomas
. configure thunderbird to authenticate. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The early bird may get the worm, but the second

Re: Unable to receive emails from btinternet.com

2020-06-21 Thread Matus UHLAR - fantomas
be blocked safely. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Silvester Stallone: Father of the RISC concept.

Re: Discard message with blank subject

2020-06-19 Thread Matus UHLAR - fantomas
"postconf header_checks" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about cholesterol.

Re: SMTPUTF8 problem with Exchange servers

2020-06-17 Thread Matus UHLAR - fantomas
reformat 8-bit headers but I'm not entirely sure if it should and if it supports that. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: [postfix] error / mail for mail.mydomain.fr loops back to myself

2020-06-14 Thread Matus UHLAR - fantomas
l as local. and there is a line proxy_interfaces = myexternalinternetipadress this help a bit, but the problem lies elsewhere. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Disable virtual_alias_maps after amavis

2020-06-10 Thread Matus UHLAR - fantomas
the messages from there. On 10.06.20 12:51, Matus UHLAR - fantomas wrote: This is what "no_address_mappings" in "receive_override_options" is for: http://www.postfix.org/postconf.5.html#no_address_mappings See: http://www.postfix.org/FILTER_README.html FYI, the amavis d

Re: Disable virtual_alias_maps after amavis

2020-06-10 Thread Matus UHLAR - fantomas
the messages from there. This is what "no_address_mappings" in "receive_override_options" is for: http://www.postfix.org/postconf.5.html#no_address_mappings See: http://www.postfix.org/FILTER_README.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas

Re: Reject RCPT TO addresses with no domain

2020-06-09 Thread Matus UHLAR - fantomas
On 09.06.20 23:41, Nathan Ward wrote: I am trying to figure out the best way to reject RCPT TO addresses with no domain part - i.e. "RCPT TO: " or similar. I do not want to rewrite to $myhostname or $mydomain or similar. I am on postfix 2.10. On 10/06/2020, at 00:07, Matus UHLAR

Re: Reject RCPT TO addresses with no domain

2020-06-09 Thread Matus UHLAR - fantomas
ient" into your smtpd_recipient_restrictions - if you want to deny everyone from doing that, put it before common permit_mynetworks and permit_sasl_authenticated -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Alternative SMTP server

2020-06-08 Thread Matus UHLAR - fantomas
towards dynamic IPS (and even from them). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is like a steel trap - rusty and illegal

Re: Postfix restrictions

2020-06-08 Thread Matus UHLAR - fantomas
on=enforce) does great job. ... and it does not introduce delays. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Remember half the peopl

Re: Postfix restrictions

2020-06-07 Thread Matus UHLAR - fantomas
and are able to reject spam at SMTP level. some of those recommendations are fine, but you get much more by using two above described techniques. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: How to deliver only once at a time to a mailbox

2020-06-03 Thread Matus UHLAR - fantomas
tus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do you want to go to die?" [Microsoft]

<    3   4   5   6   7   8   9   10   11   12   >