Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Wietse Venema
Viktor Dukhovni: > On Sun, Feb 07, 2021 at 05:33:10PM +0100, Marek Kozlowski wrote: > > > Presumably it's my fault but I cannot find such an option. If so - thank > > you for directing me to it. I'm wondering if it possible to limit > > incoming mail with '...@somedomain.tld' specified as a

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Viktor Dukhovni
On Sun, Feb 07, 2021 at 05:33:10PM +0100, Marek Kozlowski wrote: > Presumably it's my fault but I cannot find such an option. If so - thank > you for directing me to it. I'm wondering if it possible to limit > incoming mail with '...@somedomain.tld' specified as a sender address*) > to IPs

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Bill Cole
On 7 Feb 2021, at 14:33, Marek Kozlowski wrote: :-) On 2/7/21 7:51 PM, Bill Cole wrote: On 7 Feb 2021, at 12:52, Marek Kozlowski wrote: :-) On 2/7/21 6:34 PM, Benny Pedersen wrote: On 2021-02-07 18:28, Marek Kozlowski wrote: Mail from 192.168.3/24 with sender's address 'sth3.tld' should

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Marek Kozlowski
:-) On 2/7/21 7:51 PM, Bill Cole wrote: On 7 Feb 2021, at 12:52, Marek Kozlowski wrote: :-) On 2/7/21 6:34 PM, Benny Pedersen wrote: On 2021-02-07 18:28, Marek Kozlowski wrote: Mail from 192.168.3/24 with sender's address 'sth3.tld' should be accepted even if the user is not

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Bill Cole
On 7 Feb 2021, at 12:52, Marek Kozlowski wrote: :-) On 2/7/21 6:34 PM, Benny Pedersen wrote: On 2021-02-07 18:28, Marek Kozlowski wrote: Mail from 192.168.3/24 with sender's address 'sth3.tld' should be accepted even if the user is not authenticated, and rejected without authentication for

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Marek Kozlowski
:-) On 2/7/21 6:34 PM, Benny Pedersen wrote: On 2021-02-07 18:28, Marek Kozlowski wrote: Mail from 192.168.3/24 with sender's address 'sth3.tld' should be accepted even if the user is not authenticated, and rejected without authentication for other CIDR blocks. add 192.168.0.0/16 to

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Benny Pedersen
On 2021-02-07 18:28, Marek Kozlowski wrote: Mail from 192.168.3/24 with sender's address 'sth3.tld' should be accepted even if the user is not authenticated, and rejected without authentication for other CIDR blocks. add 192.168.0.0/16 to mynetworks you show bogus logs btw

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Benny Pedersen
On 2021-02-07 18:08, Curtis Maurand wrote: I would suggest giving higher preference to SPF. You can even reject if SPF fails. sure spf is the network policy, but i do not need network policy to reject local domains in port 25 world would be perfect if spf was used more even on postfix

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Marek Kozlowski
:-) No, misunderstanding. I'm not asking about SPF, DKIM etc. smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination, ... I have a mail server for a few domains. I need something more general that

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Curtis Maurand
Sent from my iPhone > On Feb 7, 2021, at 11:44 AM, Benny Pedersen wrote: > > On 2021-02-07 17:33, Marek Kozlowski wrote: >> :-) > > +1 > >> Presumably it's my fault but I cannot find such an option. If so - >> thank you for directing me to it. I'm wondering if it possible to >> limit

Re: Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Benny Pedersen
On 2021-02-07 17:33, Marek Kozlowski wrote: :-) +1 Presumably it's my fault but I cannot find such an option. If so - thank you for directing me to it. I'm wondering if it possible to limit incoming mail with '...@somedomain.tld' specified as a sender address*) to IPs belonging from some

Mail from @somedomain.tld allowed only from some CIDR ranges?

2021-02-07 Thread Marek Kozlowski
:-) Presumably it's my fault but I cannot find such an option. If so - thank you for directing me to it. I'm wondering if it possible to limit incoming mail with '...@somedomain.tld' specified as a sender address*) to IPs belonging from some CIDR ranges: - if addresses from the ranges belong