Postfix in DMZ: Really?

2022-08-27 Thread lutz . niederer
Hi. Normally, I would say it is a good idea to set up a DMZ, put relaying postfix in there and the final postfix into the LAN. This is the design that was planned in the current project and implemented many times before. But now, some believe that postfix is mature and secure enough to not

milter with disable_mime_output_conversion=yes: HOW?

2022-08-11 Thread lutz . niederer
Hi. Maybe a simple thing but my head is running in circles. I'm integrating rspamd as milter like this: smtpd_milters = inet:localhost:11332 MILTER_README says that one should use disable_mime_output_conversion=yes for milters and shows an example (in Workarounds): scan unix -

masquerade_domains map?

2022-08-02 Thread lutz . niederer
Hi! I found this from 2018, and I wanted to ask if maps for masquerade_domains are now supported. Thanx, -lutzn Marco: > Hello Postfix users, > > while "masquerade_exceptions" supports "type:table" patterns, > "masquerade_domains" supports only a static list of domain names in main.cf. > >

one PREPEND action per rule: {prepend foo} {prepend bar}

2022-06-02 Thread lutz . niederer
Hi Wietse, about 7 years before you wrote: > As implemented, there is one PREPEND action per rule, so you would > need multiple rules. > ... > I have an unfinished implementation for multiple actions in access > maps or header/body_checks. Instead of "prepend foo" you would say > "{prepend foo}

Aw: Re: dropping emails

2022-05-27 Thread lutz . niederer
> Von: "Benny Pedersen" > > On 2022-05-27 13:40, Wietse Venema wrote: > > > 4) Make Postfix smarter so that it can predict the future. > >This is not yet implemented. > > +1 > > rfc 7505 subdomain does not solve it ? > > du...@nullmx.example.org > > in dns make nullmx.example.org mx 0 . > >

Aw: Re: Re: moving to virtual: some questions

2022-05-27 Thread lutz . niederer
> Von: "Wietse Venema" > > > > 1. x-original-to header > > I still have no clue why the domain part is missing. > > But this is still a test and at the end we will use pipe to > > dovecot. Maybe this changes things. > > X-Original-To has always been the address before any rewriting, > i.e. the

Aw: Re: moving to virtual: some questions

2022-05-26 Thread lutz . niederer
  > 1. x-original-to header  I still have no clue why the domain part is missing.  But this is still a test and at the end we will use pipe to dovecot.  Maybe this changes things.   > 2. catch-all dovecot/postfix https://wiki.dovecot.org/LDA/Postfix  (Backscatter seems to give hints).   >  

moving to virtual: some questions

2022-05-25 Thread lutz . niederer
Hi,   the very, very old postfix/dovecot setup will be moved from account based to virtual in a completely new setup.   I have a few questions, not not only about this.   1. x-original-to header When mail is sent by local processes without the domain part in the to address it will be

Alias and user same name: What happens?

2022-05-10 Thread lutz . niederer
Hi, userA and userB are real local users with a mailbox. What happens in case of an aliases line like this: userA: userA, userB Does it deliver to local users userA and userB? I assume that it does not loop. Thanks & cheers! -lutzn

Aw: Re: Add Header only if sent via sendmail

2019-03-22 Thread lutz . niederer
It seems to work. Thank you!   Gesendet: Freitag, 22. März 2019 um 16:15 Uhr Von: "Viktor Dukhovni" An: "Postfix users" Betreff: Re: Add Header only if sent via sendmail > On Mar 22, 2019, at 3:00 AM, lutz.niede...@gmx.net wrote: > > But how can I do this? As noted below. > In master.cf I

Aw: Re: Add Header only if sent via sendmail

2019-03-22 Thread lutz . niederer
But how can I do this? In master.cf I add a service eg called "mycleanup" with mycleanup unix ... cleanup -o header_checks=file Essentially a renamed copy of the cleanup service with -o header_checks Then I add the parameter -o cleanup_service_name=mycleanup to existing pickup I don't need

Add Header only if sent via sendmail

2019-03-21 Thread lutz . niederer
Hello,   I am looking for a simple way to add a header if and only if mail is sent locally via sendmail (mail/mailx) command. We need to know who/what sent an email.  We already get the client's IP address if sent using smtp via smtpd_client_restrictions, but if it is not sent via smtp I have

relay_transport backup/secondary

2018-01-14 Thread lutz . niederer
Hi,   we are using two external MX servers in separate data centers.  Both of them are running postfix since many years without problems.   Internally we do have a postfix server as final destination for all domains.  On each MX we have defined a relay_transport with specific settings that

Address rewriting

2012-07-19 Thread lutz . niederer
Hi! We do have several domains listed with mydomains. The users are the same for all domains and exist locally, means mail gets delivered locally. Aliases file is used to expand to lists of recipients. This works ok and we only have one set of files (aliases) that works for all domains. We

Postfix and subaddressing (plus) problem

2012-07-08 Thread lutz . niederer
Hi! We use Postfix and Dovecot (with Dovecot LDA). Normal subaddressing works. So if I send to john+foo the mail comes up in john's folder foo. How about subfolders of foo? Can/should that work, too? How do I write the subfolder of a folder in an email address? We did change the imap

backup/fallback for default_transport ?

2012-06-26 Thread lutz . niederer
Hi! We do have two external mail relays (MX 10 mx1 MX 20 mx2) that accept mails for our domains, do lots of checks and relay them via a secure channel through the firewall into our network. Inside and outside we use postfix. When sending mails out, we use the same way: send them from our

Re: backup/fallback for default_transport ?

2012-06-26 Thread lutz . niederer
We do have two external mail relays (MX 10 mx1 MX 20 mx2) that accept mails for our domains, do lots of checks and relay them via a secure channel through the firewall into our network. Inside and outside we use postfix. When sending mails out, we use the same way: send them from our

Re: backup/fallback for default_transport ?

2012-06-26 Thread lutz . niederer
We need a way to specify a second relay if the first does not answer. This is exactly what MX records are for. On the internal server specify something like #main.cf relayhost = gateway.example.com and arrange for appropriate MX records for gateway.example.com. These can be private

Re: fallback_relay not triggered

2011-12-13 Thread lutz . niederer
Hi Wietse, we don't need to check fallback_relay anymore. As I found out, uucp transport will be turned off in near future on my backup smarthost site. I thank you for your help! -lutzn -- Empfehlen Sie GMX DSL Ihren Freunden und Bekannten und wir belohnen Sie mit bis zu 50,- Euro!

Re: fallback_relay not triggered

2011-12-13 Thread lutz . niederer
Hi, this is still an open issue. Ah, and another thing. I see the following in the logs: Dec 12 16:38:39 hostname postfix/smtpd[1374]: warning: network_biopair_interop: error reading 5 bytes from the network: Connection reset by peer I already googled and found some hints but none that

fallback_relay not triggered

2011-12-12 Thread lutz . niederer
Hi, I have a working setup of postfix that sends all mail not for me to a relayhost via smtp. I want to use a fallback_relay to send mail via uucp. Ok, I know that does not work out of the box. So I set up another instance listening on port 10027 on 127.0.0.1. This sends mail via uucp. I

Re: fallback_relay not triggered

2011-12-12 Thread lutz . niederer
The mails going to the uucp transport are going into the world. All other mails are handled by the first postfix instance. This machine is not the MX for the destinations the uucp transport / instance handles. It is my own MX, but the mails for me are not handled in the uucp instance. Are

Re: fallback_relay not triggered

2011-12-12 Thread lutz . niederer
lutz.niede...@gmx.net: The mails going to the uucp transport are going into the world. Wietse: You are sending mail to some other host, and want Postfix to use the smtp_fallback_feature when that host is down. Why does Postfix believe that it is MX host for the destination? Something

Re: fallback_relay not triggered

2011-12-12 Thread lutz . niederer
Why does Postfix believe that it is MX for those domains? If it didn't, then it would use the smtp_fallback_relay. I have no clue! If I send a mail to someone at live.com it does not pass to the fallback_relay if relayhost is down. In theory this should only happen if my machine