[pfx] Looking for a neat way to determine the time a mail sits in active queue

2024-06-07 Thread Tobi via Postfix-users
ge into active queue? Beside parsing the whole mail.log as this takes too long (it's a zabbix check and our zabbix waits at most 3s for a check to return) Or would it be possible in future postfix releases to teach the postqueue command to return the "last time taken into active q

[pfx] Re: Enforce TLS in smtp client sender based?

2024-04-25 Thread Tobi via Postfix-users
we want it :-) Have a nice weekend tobi On Fri, 2024-04-26 at 01:46 -0400, Viktor Dukhovni via Postfix-users wrote: > On Fri, Apr 26, 2024 at 07:21:24AM +0200, Tobi via Postfix-users > wrote: > > > Or would it be possible to use a sender_dependent_relayhost_maps > > an

[pfx] Enforce TLS in smtp client sender based?

2024-04-25 Thread Tobi via Postfix-users
transport (to be defined in master.cf) and the normal MX of recipient domain? Have a good one tobi ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] Logging of SMTP smuggling mitigation

2024-01-11 Thread Tobi via Postfix-users
[115.236.121.165] Would it be possible to log at least the queue-id as well? Also sender and/or recipient would be nice ;-) Or is it for security that no more information is logged? Have a good one tobi ___ Postfix-users mailing list -- postfix-user

[pfx] Re: Is it possible to add a dynamic value to a heder by header_checks?

2023-03-23 Thread Tobi via Postfix-users
the header via the milter app then :-) Cheers tobi On 23/03/2023 13:27, Matus UHLAR - fantomas via Postfix-users wrote: Dnia 23.03.2023 o godz. 12:48:36 Tobi via Postfix-users pisze: I wonder if the following is possible: can postfix add a header with a dynamic value? My goal would be to add a

[pfx] Is it possible to add a dynamic value to a heder by header_checks?

2023-03-23 Thread Tobi via Postfix-users
Hi there I wonder if the following is possible: can postfix add a header with a dynamic value? My goal would be to add a header with the current unix timestamp on the edge system and then check that header against current time on last system in the delivery chain. Have a good one tobi

Re: SMTP Relay

2021-08-07 Thread tobi
> relayhost = [mx.krowverse.services] If I got your first post right you only have nat rules for port 465 and 587 but the setting above implies usage of port 25. Ever tried to add :587 to your postfix relayhost setting? Am 7. August 2021 11:51:33 UTC schrieb masstransitk...@365stops.org: >When

Re: reject_sender_login_mismatch

2021-07-30 Thread tobi
you could add a sender access map in your relay config which rejects those domains. Place it before your sender login maps Am 31. Juli 2021 06:06:17 UTC schrieb Simon Wilson : >A quick query on smtpd_sender_login_maps format. > >I have this working well on port 587 to ensure that specified >SA

Re: Best current practice to analyze brute force login attempts?

2021-07-30 Thread tobi
If dovecot is in play as auth backend then weakforced could be a viable option. Quite a powerful tool tailored to fight/detect brute force attacks: https://github.com/PowerDNS/weakforced Am 30. Juli 2021 15:12:40 UTC schrieb post...@ptld.com: >> Unfortunately, the required data, i.e. client IP a

Re: Has rfc2487 been obsoleted and mandatory TLS in smtpd is now kosher?

2021-07-29 Thread Tobi
Just take the case when they loose a huge customer order because customer still operates an Exchange 2003 server, which by best can talk TLS 1.0. Then Management will soon show up in IT department and highly probably ignore the fact that it was them pushing this policy in first place ;-) Cheers

Re: Has rfc2487 been obsoleted and mandatory TLS in smtpd is now kosher?

2021-07-28 Thread Tobi
on may and deploy a proper DANE setup instead. Sure it's their servers so their rules applies. Everyone is allowed to shot own foot ;-) Cheers tobi On 7/28/21 4:39 PM, Josh Good wrote: > Hello everybody. > > I've been made aware of this communication recently received at some

Re: Restrict Senders for some recipient addresses

2021-04-26 Thread Tobi
something like this? http://www.postfix.org/RESTRICTION_CLASS_README.html#internal On 4/26/21 10:11 AM, George Papas wrote: > Hi  list, > > > what the title says actually,   I have an alias  for all current users > of an SMTP server but > > I want to restrict sending to this alias address to some

Re: timed server greeting

2021-04-26 Thread Tobi
On 4/23/21 3:33 PM, natan wrote: > for test I send (this same method) from old server (debian8 postfix > 2.11.x) and works ok does the old server have another ip address than the new one? Smells to me that your new server ip maybe blocked at destination -- Cheers tobi

Re: Specific DNS server

2021-04-22 Thread Tobi
Would it be an option to configure a policy for your DNS server to **not** send queries from postfix host(s) through the add&tracker filter? Cheers tobi On 4/22/21 12:20 PM, Simon Wilson wrote: > Is there a way to make Postfix/postscreen use a specific DNS server? > > Reason for

Re: Possible to "import" a file into postfix queue?

2021-02-11 Thread Tobi
ur external content filter and is fixed now. Was an error that had been undetected in our content-filter for more than 10 years :-) Cheers tobi

Possible to "import" a file into postfix queue?

2021-02-11 Thread Tobi
nd to "import" a file as message directly into postfix queues? Thanks for any idea as we really need to be able to reproduce it or else debugging will be very hard :-) Cheers tobi

Re: Segfaults libpcre in cleanup

2020-05-14 Thread Tobi
of .$2 is not allowed > endif the pattern above now runs without any changes to stack size :-) -- Cheers tobi

Re: Segfaults libpcre in cleanup

2020-05-14 Thread Tobi
roducing limits where we can in our patterns. Anyway I think that this should not end in such an ugly error where postfix cleanup goes south because of such header/pattern combination. -- Cheers tobi Am 14.05.20 um 09:13 schrieb Viktor Dukhovni: > On Thu, May 14, 2020 at 08:53:42AM +0200, T

Re: Segfaults libpcre in cleanup

2020-05-13 Thread Tobi
.* without any limits :-) Thanks a lot for your appreciated help -- Cheers tobi Am 13.05.20 um 16:05 schrieb Wietse Venema: > Tobi: >> Hi >> >> as usual: thanks to Wietse :-) >> >> Adding the info rule to the pcre maps solved more than expected. After >>

Re: Segfaults libpcre in cleanup

2020-05-12 Thread Tobi
84 > %C3%82; First of all any idea why cleanup did not segfault with the info rule in place? 2nd: could such mime headers be the reason for a pcre pattern to let libpcre segfault? -- Cheers tobi Am 12.05.20 um 15:20 schrieb Wietse Venema: > Tobi: >> Hi list >> >> we

Re: Postfix "IPv6-only" - experience/recommendation question

2020-05-12 Thread Tobi
g My 5 cents: never rely on the reputation of a domain if you do not have control over parent domain. So if others from eu.org zone sending spam one should not wonder why the own subdomain of eu.org might be listed/blocked/seen as spam. -- Cheers tobi

Segfaults libpcre in cleanup

2020-05-12 Thread Tobi
pcre maps. There is no suspicious logging prior to cleanup "crash". Is there a way to narrow down which pcre rule may is problematic, given the fact that we do not have access to message source? -- Thanks and have a good one tobi

Re: Graphing

2020-01-24 Thread Tobi
h the effort :-) [1] https://mailgraph.schweikert.ch/ Cheers -- tobi Am 24.01.20 um 09:47 schrieb Cédric Gallo: > Hello, > > Munin server and munin nodes with standards and home-made plugins (for > bounces). > http://munin-monitoring.org/ > > Bye > > Le 24/01/202

Re: Possible to enforce 4XX error upon dns lookups which result in NXDomain?

2019-10-18 Thread Tobi
Hi Wietse thanks a lot for your hint :-) Deployed and first tests show it works as it should: changing 5xx to 4xx in case of NX domain for nexthop. Cheers tobi Am 15.10.19 um 21:58 schrieb Wietse Venema: > Wietse Venema: >> Wietse Venema: >>> Tobi: >>>> I w

Re: Postfix is not open relay but send spam

2019-10-15 Thread Tobi
eject. That should be a 5xx. I think postfix complains about something in its logs. Cheers -- tobi Am 15.10.19 um 09:27 schrieb Julien Michaux: > Hi everyone, > > I have a problem with postfix. > > I use OBM as a mail server (postfix + cyrus + ldap, etc...). My postfix is > no

Possible to enforce 4XX error upon dns lookups which result in NXDomain?

2019-10-15 Thread Tobi
esults and return a DEFER action? Thanks for any idea and have a good one -- tobi signature.asc Description: OpenPGP digital signature

Re: Performing rcpt_verification based on sender possible?

2018-11-15 Thread Tobi
self-healing" to kick in ;-), I removed the file and postfix reload and it works Thanks a lot for your help and have a good one tobi Am 14.11.18 um 16:29 schrieb Noel Jones: > On 11/14/2018 2:50 AM, Tobi wrote: > >> >> $ postconf -d|grep parent_domain_matches >>

Re: Performing rcpt_verification based on sender possible?

2018-11-14 Thread Tobi
ctions = reject_unknown_sender_domain, reject_non_fqdn_sender, check_sender_access hash:/etc/postfix/do_callahead, . Will set postfix to debug as described this evening and see if I can get more information about this issue. Thanks a lot tobi Am 13.11.18 um 18:22 schrieb Noel Jones: > On 11/13/2018 10:46

Re: Performing rcpt_verification based on sender possible?

2018-11-13 Thread Tobi
restriction that could ACCEPT the mail. postmap tells me that it gets the correct value from the map $ postmap -q 'example.com' /etc/postfix/do_callahead reject_unverified_recipient Am 13.11.18 um 17:18 schrieb Noel Jones: > On 11/13/2018 9:43 AM, Tobi wrote: >> Hello list >>

Performing rcpt_verification based on sender possible?

2018-11-13 Thread Tobi
with rcpt verification. Is there a way to achieve that with postfix? Thanks for any idea tobi

Re: check if envelope from and from is the same

2018-10-03 Thread Tobi
if your auth senders spoof from headers: block their login account and terminate their service Am 02.10.18 um 21:17 schrieb Stefan Bauer: > Hi, > > we're running a small smtp send only service for authenticated users > only. Even though we only accept allowed combinations of authenticated > user

Re: Authenticating 'From' header to match envelope

2018-10-03 Thread Tobi
nd from header) are changed to the value I defined in "custom from address" Btw: at least the Thunderbird question should go to a thunderbird mailing list. Not really a postfix issue here :-) Cheers tobi Am 03.10.18 um 17:33 schrieb Stefan Bauer: > Johannes, > > did you double ch

Re: Prioritize header checks

2017-11-09 Thread Tobi
spamassassin and several other plugins of that filter software. Much work for a message that after proxy filter will be rejected by postfix header checks anyway :-) So if I got you right: it's not possible to run header checks before proxy filter. Cheers and thanks tobi

Prioritize header checks

2017-11-09 Thread Tobi
**before** msg is passed to the content filter? Cheers tobi

Customize log message of postfix proxy?

2017-10-24 Thread Tobi
sl_method=LOGIN, sasl_username=REDACTED but I can see no way to correlate these messages with the proxy-reject message. As I guess that the same smtpd PID is used for several mailtransactions? Thanks for any idea tobi

Re: Is it possible to suppress NDR/Delayed delivery messages generated by messages to a particular RCPT?

2017-08-03 Thread Tobi
imit that messages over 2mb are not even passed to my scripts Again thanks for your help Wietse Cheers tobi

Is it possible to suppress NDR/Delayed delivery messages generated by messages to a particular RCPT?

2017-08-02 Thread Tobi
ivery for a specific address? Thanks and cheers tobi

Re: Specify VPN for postfix

2017-08-02 Thread Tobi
Am 01.08.2017 um 20:39 schrieb Abi Askushi: > Since this is socks proxy and not vpn you could redirect postfix traffic > with iptables to the port your socks proxy listens. Plenty examples on > google. if you redirect the full postfix traffic you might end up in asymetric routing. Most important

AW: Specify VPN for postfix

2017-08-01 Thread Tobi
routing aka source based routing on postfix server to ensure answers from postfix go back via the same gateway they came in. Cheers tobi - Originale Nachricht - Von: Yubin Ruan Gesendet: 01.08.2017 - 06:07 An: postfix-users@postfix.org Betreff: Specify VPN for postfix > Hi, > Can

Re: still use "aNULL:!aNULL:" in Postfix default cipherlists when tls policy is mandatory, == encrypt?

2017-07-31 Thread Tobi
Even with level encrypt the certificates are **NOT** verified which means anyonymous chiphers are still used. To verfiy peer certificates see: http://www.postfix.org/TLS_README.html#client_tls_verify. Or configure postfix smtp server to enforce clients to present a cert: http://www.postfix.org/pos

Re: How to alter content-filter for messages that are already queued

2017-06-13 Thread Tobi
Did you try to re-queue such a message? postsuper -r QUEUE_ID or postsuper -r ALL (to re-queue all) On 06/13/17 13:19, Petr Bena wrote: > Hello, > > Someone smart added garbage to our postfix config, which resulted in > following errors in log: > > postfix/smtp[29793]: fatal: garbage after nume

Re: smtp port issue

2017-06-12 Thread Tobi
Am 12.06.2017 um 15:51 schrieb b...@bitrate.net: > 25025 init n - n - - smtpd typo? signature.asc Description: OpenPGP digital signature

Re: Why does reject_unknown_reverse_client_hostname reject this mail?

2017-05-16 Thread Tobi
lookups that made problems Thanks for your lesson in "how dns resolution works" and your patience :-) Regards tobi

Re: Why does reject_unknown_reverse_client_hostname reject this mail?

2017-05-16 Thread Tobi
Hi Wietse Sorry should have mentioned after your reply that ipv6 is disabled on all my boxes. And have postfix inet_protocol set to ipv4 anyway So no reason for postfix to query a nameserver via ipv6. At least I do not see one :-) Regards tobi - Originale Nachricht - Von: Wietse

Re: Why does reject_unknown_reverse_client_hostname reject this mail?

2017-05-16 Thread Tobi
Am 16.05.2017 um 13:15 schrieb Wietse Venema: > Tobi: >>> Client host rejected: cannot find your reverse hostname, >>> [185.140.48.241] > Here's a hint: > > % host 185.140.48.241 > ;; connection timed out; no servers could be reached I can reliably resolv

Why does reject_unknown_reverse_client_hostname reject this mail?

2017-05-16 Thread Tobi
" it's a unknown/broken rDNS and rejects it? Regards tobi

Re: Telnet auth

2016-05-18 Thread Tobi
If you do not accept submission on port 25, you could add a sender_access map to the service on port 25 smtpd_sender_restrictions = ... check_sender_access hash:/etc/postfix/sender_access ... and in said file list your domains each with action "reject" Am 18.05.2016 um 12:22 schrieb Catalin Bad

Re: underscore in domains

2016-02-17 Thread Tobi
Am 17.02.2016 um 09:30 schrieb Suuuper: > > I tried to add reject_non_fqdn_recipient in > smtpd_recipient_restrictions, but it doesn't work. > use a regexp on recipient and/or sender domain to reject such messages. postfix accepts underscore in domain names as this is a common mistake by many l

Re: Postfix claims "no MX host for ogrj.ch has a valid address record"

2015-06-22 Thread Tobi
Just as an update: Our loadbalancers have troubles with dns responses which contain several hosts. For some domains they corrupt the dns cache on the loadbalancer and therefore deliver such bogus responses. This behaviour even occurs if no dns cache settings are set on the loadbalancer. The manufa

Re: Postfix claims "no MX host for ogrj.ch has a valid address record"

2015-06-11 Thread Tobi
ot of queries manually and NEVER had problems with resolving. Therefore I wonder why postfix "sees" a problem with EVERY mail for the domain ogrj.ch Thanks tobi -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQIcBAEBCAAGBQJVeYmQAAoJEDUc5iWoaKTksJIP/irTXg2pRLImE5uS

Postfix claims "no MX host for ogrj.ch has a valid address record"

2015-06-11 Thread Tobi
problem? Thanks for any idea Cheers tobi -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQIcBAEBCAAGBQJVeXn2AAoJEDUc5iWoaKTkFnEP/jjKrJRzSrcUDLsc1LKDtR+y vKSLAj6cc79HsOIIWQGmuUPFuTrFddes+ztnonzBINqAoGt3xfvkj8cTqYGmICkm h4C4sByip4lVhROndgT57fmxN0e5+mxAkhE8MAkC197cvkiaWCe9ziLcpxfMunju hRLEhKJxc3+Wt75

Re: SQL table lookup

2015-05-08 Thread Tobi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Am 07.05.2015 um 18:43 schrieb Rod K: > I'm trying to implement > > check_client_restrictions = check_client_access > pgsql:/path/to/local_blacklist-sql.cf, ... > have you had a look at postfix postscreen featue? http://www.postfix.org/POSTSCREEN_R

Re: Send copy of incoming email to old mail server

2015-05-07 Thread Tobi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I would suggest you to have a look into the doc http://www.postfix.org/ADDRESS_REWRITING_README.html#receiving in our case eigther alias or auto bcc should solve the problem Am 07.05.2015 um 12:56 schrieb Kashif Ali Bukhari: > Hi list fellows >

Re: postfix-policyd-spf-perl and troubles with Amazon? [SOLVED]

2015-05-06 Thread Tobi
unbound the queries for spf1.amazon.com TXT were properly answered properly. Amazon did not retry yet, but I'm sure that this solved the problem. Thanks a iot tobi Am 06.05.2015 um 16:11 schrieb Scott Kitterman: On Wednesday, May 06, 2015 09:58:57 AM James B. Byrne wrote: On Wed, May 6,

postfix-policyd-spf-perl and troubles with Amazon?

2015-05-06 Thread Tobi
m too with Amazon? Or does anyone have an idea how to solve it? Thanks tobi -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQIcBAEBCAAGBQJVShrmAAoJEDUc5iWoaKTkd7kP/RxLTO0uzrxcPg348cnm9yjG l2fIodQqvyRG2BgloKd3ldseVhc5B1+f/Ee+xFiofjMI5KSMYf9UbiH2cmmbfBZq /AyZesUwwDUsHWHw6vhY9DwXP/

Re: [SOLVED] Alias expansion when relay possible?

2014-11-06 Thread Tobi
ovecot-lmtp on all backends. That works as it should :-) tobi Am 06.11.2014 um 13:57 schrieb Tobi: > Hello list > > I have a postfix setup with a frontend and two backend servers. The > problem is that one user has forward (ex forwards to his mailbox and to > another one). The proble

Alias expansion when relay possible?

2014-11-06 Thread Tobi
But I could not find a parameter to do this like relay_alias_maps or something like that. Is there a way to perform the alias on the frontend before it relays to the respective backend? Thanks a lot for any idea :-) tobi

Re: Why is there msg id in logs but no recipient?

2014-11-05 Thread Tobi
Am 05.11.2014 um 11:40 schrieb li...@rhsoft.net: > Am 05.11.2014 um 11:37 schrieb Tobi: >> I got a imho weird problem with understanding the logs. We have an >> client that authenticates correctly which generates an id from postfix. >> If I grep this id through the logs I can

Why is there msg id in logs but no recipient?

2014-11-05 Thread Tobi
m client? But then there should be a RCPT TO or not? Thanks tobi

Re: 20-40+ second delays. Is this normal?

2014-03-18 Thread tobi
Am 18.03.2014 17:13, schrieb jmct: I spoke with one of our Linux administrators and he advised that SELinux didn't even cross his mind because he's so used to disabling it on install. :P Just curious: normally postfix runs quite well with selinux enabled. Have you checked the audit logs where

Re: Compromised Passwords

2014-03-05 Thread tobi
Am 04.03.2014 23:38, schrieb Homer Wilson Smith: Change their password? from my experience the only thing that really stops the spam Maybe it's anoying for the account owner but it works most reliable. Counting IPs might help also but what if the spammer uses the same src ip for its garbage?

Re: Postfix 2.9.6-2 on debian wheezy with a mysql problem?

2013-11-08 Thread Tobi
Am 08.11.2013 16:18, schrieb Viktor Dukhovni: > On Fri, Nov 08, 2013 at 03:45:03PM +0100, Tobi wrote: > >> The error message is 99.999% not from mysql. Because when I remove the >> backticks around the table name then I get an error from mysql which >> looks different &

Re: Postfix 2.9.6-2 on debian wheezy with a mysql problem?

2013-11-08 Thread Tobi
Am 08.11.2013 15:59, schrieb Wietse Venema: > Tobi: >> Am 07.11.2013 23:55, schrieb Viktor Dukhovni: >>> On Thu, Nov 07, 2013 at 11:46:43PM +0100, Tobi wrote: >>> >>>>> If the ip/port are different, it is not the *SAME* configuration. >>>>

Re: Postfix 2.9.6-2 on debian wheezy with a mysql problem?

2013-11-08 Thread Tobi
Am 07.11.2013 23:55, schrieb Viktor Dukhovni: > On Thu, Nov 07, 2013 at 11:46:43PM +0100, Tobi wrote: > >>> If the ip/port are different, it is not the *SAME* configuration. >> I know but it's not possible otherwise. The two other server reach >> the mysql-cluster

Re: Postfix 2.9.6-2 on debian wheezy with a mysql problem?

2013-11-07 Thread Tobi
Am 07.11.2013 23:26, schrieb Viktor Dukhovni: On Thu, Nov 07, 2013 at 11:21:15PM +0100, Tobi wrote: Copy the *SAME* config file to different machines and try: $ postmap -q '192.167.34.21' mysql:/path/to/config-file Are the results different? Yes they are. On the two other machine

Re: Postfix 2.9.6-2 on debian wheezy with a mysql problem?

2013-11-07 Thread Tobi
Am 07.11.2013 23:02, schrieb Wietse Venema: Tobi: Hi list I really got a weird problem with one of my postfix installations and the mysql lookup. The weird thing is that it works on two of my three postfix installtions. Have the following .cnf file for the mysql lookup << Copy th

Postfix 2.9.6-2 on debian wheezy with a mysql problem?

2013-11-07 Thread Tobi
t_aton('192.167.34.21') BETWEEN `network` AND `broadcast`; Empty set (0.12 sec) >> I know I could rename the table which I would do for sure if the problem would have shown up on all of my servers :-) It seems that on the affected server the backtick is handled differently by postfix from the two others. tobi

Re: Recipient rewrite based on sender

2013-09-05 Thread Tobi
Am 04.09.2013 21:01, schrieb Wietse Venema: > Tobi: >> Hello list, >> >> I have been asked if the following is possible somehow with postfix, but >> as I'm quite unsure I try to ask the "gurus" :-) >> The goal is something like a conditional r

Recipient rewrite based on sender

2013-09-04 Thread Tobi
at script. Even those that would not have met the conditions for rewrite. Is there a way to achieve this without piping to an external script? thanks for any idea tobi

Re: Find "overquota" mailboxes

2012-08-19 Thread tobi
much time ;-) Other postfix servers were already replaced by atmail, which I personally not really like ;-) > > Safer: > postmap /etc/postfix/overquota.new && mv /etc/postfix/overquota.new.db > /etc/postfix/overquota.db > Thanks for that I will change it tomorrow. Cheers tobi

Find "overquota" mailboxes

2012-08-18 Thread tobi
w happen that my mailq... line matches something wrong? My main concern is to write something "wrong" in the overquota file and break postfix (like rejecting everything or something similar) Thanks for any hints and enjoy the weekend tobi

Re: Best way to protect backup-mx?

2012-08-08 Thread tobi
ossible to my main-mx. It's just annoying if spammers try my backups first but not a real problem ;-) Anyway because of the example that Harald sent I throw my idea over board Thanks and cheers tobi

Re: Best way to protect backup-mx?

2012-08-08 Thread tobi
Thanks for this very plausible reason for not doing what I wanted :-) I did not think about such circumstances. Cheers tobi Am 07.08.2012 22:25, schrieb Reindl Harald: > > be carfeul with such things > > that you primary MX is up from the connection of your > backup-MX means vi

Re: Best way to protect backup-mx?

2012-08-07 Thread tobi
onnecting my backup-mx as long as the main-mx is up and running. Like spammers sometimes try by connecting directly to a backup-mx instead trying main-mx first. tobi

Best way to protect backup-mx?

2012-08-07 Thread tobi
ve no idea what the "best" approach would be. Thanks a lot for any input/hints/tips tobi

Re: Custom error msg

2012-06-11 Thread tobi
not be helo checked. I put this map before my helo checks and it works fine tobi

Custom error msg

2012-06-11 Thread tobi
_mynetworks, reject >> which works but I really would like to send customized error messages. Thanks a lot for any hint tobi

Re: Logging of users trying auth on auth-disabled port?

2012-04-25 Thread tobi
uth logins ;-) tobi

Re: Logging of users trying auth on auth-disabled port?

2012-04-25 Thread tobi
On 25.04.2012 13:13, Wietse Venema wrote: tobi: Hi list I have disabled SMTP-Auth on my port 25. so this port is only uses to receive emails for my domains but no relaying is possible. Now I have bots that try to auth on port 25 by issue Out: 250 DSN In: AUTH LOGIN Out: 503 5.5.1 Error

Logging of users trying auth on auth-disabled port?

2012-04-25 Thread tobi
or auth on said port Thanks for any hints tobi

Re: cidr map for a certain receiver address only?

2012-04-09 Thread tobi
On 09.04.2012 15:19, /dev/rob0 wrote: On Mon, Apr 09, 2012 at 02:23:14PM +0200, tobi wrote: I wonder if it's somehow possible to block client ips from a cidr map for a certain receiver address only. I have some addresses for which I do not want clients from certain providers to send ma

cidr map for a certain receiver address only?

2012-04-09 Thread tobi
erver, which is not my intention ;-) Would it be possible to define this via a postfix policy or something similar? My goal would be to get a cidr map that would only be used when certain receiver addresses occur during smtp dialog. Thanks for any hint tobi

Re: Using Spamassassin as content filter

2011-10-19 Thread tobi
ccess the body of a mail before the server sends the accept to the client. It possible to deny messages based on score during the smtp session and the job of creating a bounce is on the sending side :-) I use spamass-milter on two postfix servers running on debian-squeeze. Works really very nice tobi

Re: Permission for delivered messages.

2011-10-19 Thread tobi
dovecot. Then the local user always remains the same and it's fine with chmod 0600. Have a look here http://wiki2.dovecot.org/VirtualUsers if virtual users are an option for you tobi

Conditional use of smtp_fallback_relay?

2011-02-07 Thread tobi
ror (like from greylisting) happend. In the later case the mails should go to the queue and no fallback should be used. Anyway to achieve this? Thanks for any hints and tipps tobi

Re: Added a Check - Asking for a Review

2010-01-20 Thread tobi
the check will anyway be performed only when RCPT TO command is received. Furthermore at the time of HELO there is no SASL auth done yet. So this setting does nothing there. @Ralf would it not make more sense to place check_sender_access before the check_policy_service? Otherwise you might greylist senders you don't want (like maillists) Regards tobi

Re: always get 450 for non-existent domain

2009-12-19 Thread tobi
ibility in handling different scenarios > but I guess not this time. > > --Donald > > I don't know if this might help you but in the manual I found this parameter which should be working from Postfix 2.6 onwards http://www.postfix.org/postconf.5.html#unknown_address_tempfail_action Regards tobi

Re: relayhost and sending some mail directly?

2009-12-18 Thread tobi
ain.cf then Postfix should not relay the mail. If you want that Postfix smtp client sends emails based on sender to different relay servers then http://www.postfix.org/SASL_README.html would be something for you Cheers tobi

Re: postfix address rewritting

2009-12-09 Thread tobi
Castagnet Adrien schrieb: > Hi tobi, > thank you for your reply. > In my main.cf > I uncommented a line mydestination, it's now like this : > mydestination = $myhostname, localhost.$mydomain, localhost > So then $myhostname must be your domain name (mydomain.local) or it

Re: postfix address rewritting

2009-12-08 Thread tobi
Adripop schrieb: Hi everybody ! Could someone help me, i've been searching everywhere around without results. Almost every local email account has its own email account provided by an email provider. I use fetchmail to retreive them and store them locally on my server. This configuration pe

Re: Should Anyone Be Able To Send Telnet Email

2009-12-04 Thread tobi
look at http://www.postfix.org/SASL_README.html Only allow authenticated users to relay through your Postfix Server and set mynetworks on a local IP like 127.0.0.1 Cheers tobi

Re: Something like address based relay just the other way around

2009-11-30 Thread tobi
tobi schrieb: > Wietse Venema schrieb: > >> tobi: >> [ Charset ISO-8859-1 unsupported, converting... ] >> >> >>> Wietse Venema schrieb: >>> >>> >>>> Tobi: >>>> >>>> &

Re: Something like address based relay just the other way around

2009-11-30 Thread tobi
Wietse Venema schrieb: > tobi: > [ Charset ISO-8859-1 unsupported, converting... ] > >> Wietse Venema schrieb: >> >>> Tobi: >>> >>> >>>> Hello >>>> >>>> I just wonder whether my idea is technical

Re: Something like address based relay just the other way around

2009-11-30 Thread tobi
Wietse Venema schrieb: > Tobi: > >> Hello >> >> I just wonder whether my idea is technically possible to fullfill with >> Postfix. I already use sender based relaying which works fine. >> My problem is that I'm running a Postfix Server on my dynamic

Something like address based relay just the other way around

2009-11-30 Thread Tobi
nally relay emails based on the receivers address/domain? So I could send emails for defined addresses/domains via my ISP mailserver instead of direct-mx. Is there a way to do this in Postfix? Thanks a lot for all tipps/hints Cheers tobi

Re: Mail to non system account

2009-11-23 Thread tobi
Sam Wootton schrieb: > 2009/11/22 Magnus Bäck > > >> On Sunday, November 22, 2009 at 17:34 CET, >> Sam Wootton wrote: >> >> >>> I nearly have Postfix working on Opensuse 11.1. >>> >>> For a non system account user, it works. For example: >>> >>> /var/mail/vhosts/samwootton.com/bruno

Re: Backscatter being generated from mail aliased to other servers.

2009-11-16 Thread tobi
ur control should not accept messages for > example to non-existant user. So if you're doing verification even > when spammer connects to your server should recieve an ansewer from > REMOTE SERVER "user not known" or something similar. I've got similar > situation as I had to smart host for a lot of domains and connection, > but let's say I know people on that remote site, or even if not I've > got any contact details like email addres so simply... I'm trying to > explain people that if they will not protect the end server I will > block them in the smart host as I can't take a risk of block. So > generally you should use reject_unverified_recipient and additionally > you can build a database... you can limit connections, check RBLs, > CBLs, there is really a lot of things but first of all you would need > to check which hosts on the other end couses a problem and find out > what you can do more to prevent spam coming through. > I know that it's impossible to block all SPAM without being too harsh, > but there is always something what you can do to prevent it. > > Regards, > Jarek This page (http://www.postfix.org/ADDRESS_VERIFICATION_README.html) looks like it describes part of your problem. Could be the solution Regards tobi

Re: Mail not delivered to local users: status=deferred (mail transport unavailable)

2009-03-29 Thread Tobi
On Mar 29, 2009, at 5:10 PM, Wietse Venema wrote: Tobi: Hi All, I set up an after-queue content filter following the instructions on http://www.postfix.org/FILTER_README.html . Everything works fine except that mail directed to local users is deferred when it is re-injected to postfix after

Mail not delivered to local users: status=deferred (mail transport unavailable)

2009-03-29 Thread Tobi
ain is included in mydestination. My transport map has only one entry for an external domain. I tried removing the '-o receive_override_options=no_address_mappings' and '-o local_recipient_maps=', but nothing changed. I'm out of ideas. I really appreciate your help. Thanks, Tobi