[pfx] Question about the DMARC setting for lists

2024-05-29 Thread Northwind via Postfix-users
Hello the list, I saw some open source providers who have these dmarc settings: _dmarc.disroot.org. 3495 IN TXT "v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:ab...@disroot.org; ruf=mailto:ab...@disroot.org;"; _dmarc.autistici.org. 3504 IN TXT "v=DMARC1; p=reject; adkim=s; aspf=s; rua=mail

[pfx] Re: SASL login username in log

2024-05-28 Thread Northwind via Postfix-users
Wietse Venema via Postfix-users: Fixed with Postfix 3.8.3, 3.7.8, 3.6.12, 3.5.22: that's all right. thank you Wietse. ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] SASL login username in log

2024-05-28 Thread Northwind via Postfix-users
Hello, Is it possible to set mail.log for recording sasl login usernames? May 29 06:52:45 mx postfix/smtps/smtpd[3022855]: warning: unknown[138.185.193.64]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 May 29 06:52:57 mx postfix/smtpd[3023133]: warning: unknown[49.156.148.93]: SASL LOGIN aut

[pfx] Re: How to allow only one specific sender to use smtp ?

2024-05-25 Thread Northwind via Postfix-users
great knowledge. thanks Wietse. master.cf: submission ... ... ... ... ... ... smtpd -o { smtpd_client_restrictions = check_sasl_access inline:{{ user@example = OK }} static:{ REJECT this user is not allowed to send mail } } ...

[pfx] Re: How to allow only one specific sender to use smtp ?

2024-05-25 Thread Northwind via Postfix-users
iptables? I have Postfix setup and use dovecot as SASL. Now, all email accounts can use the smtp server to send emails. I want to allow only one email account to send out emails and rest of others can only use POP3 or IMAP. ___ Postfix-users mailin

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Northwind via Postfix-users
yes I am using smtps as service name indeed. and smtps has -o smtpd_sasl_auth_enable=yes enabled. Thanks peter. On postfix 3.4 submissions was actually called smtps so you want to enable it in the smtps section (there won't be a submissions entry in your master.cf unless you added it). _

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Northwind via Postfix-users
just to clarify, submissions is not required to set for enabling sasl_auth on port 465/587. i have tested it, no need to set a separated submissions. my postfix version: version 3.4.13 thanks submissions inet n   -   y   -   -   smtpd __

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Northwind via Postfix-users
Thank you so much. This is really important. > > Le 24/05/2024 à 14:17, Northwind via Postfix-users a écrit : > > > > > so, in main.cf: > > > > smtpd_sasl_auth_enable=no > > > > then in master.cf: > > > > submission inet n  

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Northwind via Postfix-users
ehlo localhost.localdomain 250-mx.domain.xyz 250-PIPELINING 250-SIZE 250-VRFY 250-ETRN 250-STARTTLS 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250 CHUNKING no AUTH was there. so it should be working. :) if you see AUTH in ehlo results it not done yet _

[pfx] how does smtpd know the connection is a submission request, or a MX request?

2024-05-24 Thread Northwind via Postfix-users
my guess, submission clients were using ehlo, and a mx client uses helo command. so postfix differ them based on this command? regards. ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@post

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Northwind via Postfix-users
root@mx:/etc/postfix# vi main.cf root@mx:/etc/postfix# vi master.cf root@mx:/etc/postfix# service postfix restart i have comment out this line in main.cf: #smtpd_sasl_auth_enable = yes And enable this in master.cf: submission inet n - y - - smtpd -o smtpd_sasl_aut

[pfx] Re: disable authentication on port 25

2024-05-24 Thread Northwind via Postfix-users
so, in main.cf: smtpd_sasl_auth_enable=no then in master.cf: submission inet n - y - - smtpd -o smtpd_sasl_auth_enable=yes Am I right? does this disable sasl_auth for port 25, but still authorize users on port 587/465? Thanks a lot. Many moons ago I was tol

[pfx] Re: disable authentication on port 25

2024-05-23 Thread Northwind via Postfix-users
do you mean since I have been using postscreen, there is no need to manually disable authentication on port 25? since postscreen doesn't have auth support. Thanks Wietse. As documnented somewhere, postscreen never announces AUTH support. ___ Postf

[pfx] disable authentication on port 25

2024-05-23 Thread Northwind via Postfix-users
Hello, since my smtp instance is postscreen as showing the follow, smtp inet n - y - 1 postscreen How can I disable authentication on port 25 then? I know if the smtp instance is smtpd, this option should work: -o smtpd_sasl_auth_enable=no Thank you. _

[pfx] Re: Strengthen email system security

2024-05-23 Thread Northwind via Postfix-users
That's great info from all you people. many thanks! > > On 23/05/24 19:02, Jaroslaw Rafa via Postfix-users wrote: > > > > > In addition I can add one idea: > > > > I have had quite a success with a policy server that rejects all > > connections > > > > on submission ports IF it doesn't f

[pfx] Re: Strengthen email system security

2024-05-23 Thread Northwind via Postfix-users
how to implement that a policy server? thanks. In addition I can add one idea: ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] Re: Strengthen email system security

2024-05-22 Thread Northwind via Postfix-users
Good ideas. thanks a lot Peter. Things of note from the log entries above: 1/2 of the entries are from the smtp (port 25) service.  This service should be for MX communication only and should not accept pauthentication.  You can eliminate 1/2 of the attempts just by disabling authenticatio

[pfx] Re: Strengthen email system security

2024-05-22 Thread Northwind via Postfix-users
will this also stop the valid client's SMTP connection? thank you Wietse. Don't accept mail from home networks. For example, use "reject_dbl_client zen.spamhaus.org". For this you must use your own DNS resolver, not the DNSresolver from your ISP. ___

[pfx] Strengthen email system security

2024-05-22 Thread Northwind via Postfix-users
Hello list, In the last two days, my mail system (small size) met attacks. mail.log shows a lot of this stuff: May 23 06:24:29 mx postfix/smtpd[2655149]: warning: unknown[194.169.175.17]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 May 23 06:24:37 mx postfix/smtps/smtpd[2655958]: warning:

[pfx] Re: Disable Non Delivery Notifications only for some adresses

2024-05-21 Thread Northwind via Postfix-users
Can I have multi-smtpd instances by updating master.cf? for example, one instance for handling domain a.com, another instance for b.com. The two instances have different policies for incoming messages. Thanks. Configure a dedicated smtpd servicce in master.cf. Then use

[pfx] Re: Selection of a custom smtp-transport based on recipient addresse's MX with check_recipient_mx_access doesn't work

2024-05-19 Thread Northwind via Postfix-users
This is most likely the issue of outlook, not yours. AFAIK outlook has the policy of IP blacklist. Maybe your IP happens to hit it. regards. After a few hundred mails to different addresses who's domains use a protection.outlook.com MX, the receiving servers respond with "...451 4.7.500 Se

[pfx] Re: Dovecot logging to files causes postfix to break

2024-05-18 Thread Northwind via Postfix-users
Hello When postfix delivery messages to local dovecot, how does the authentication between postfix and dovecot happen? Thanks. You mean, Postfix for SMTP, Dovecot for IMAP. ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscrib