Re: Alternative smtp_fallback_relay mechanism

2012-09-08 Thread Ralf Hildebrandt
* Ralf Hildebrandt ralf.hildebra...@charite.de: I'll check the use of the smtp_fallback_relay for different mailing campaigns. machine epsilon: Mails sent directly to MX: == 56423 (93.7%) Mails sent to fallback_relay: = 3735 (6.2%) Bounces

Re: smtpd_proxy_filter (before-queue) per domain?

2012-09-10 Thread Ralf Hildebrandt
there :) -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra...@charite.de | http://www.charite.de

Re: Postscreen Error: /usr/libexec/postfix/postscreen: No such file or directory

2012-09-11 Thread Ralf Hildebrandt
This service was introduced with Postfix version 2.8. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra

Re: Why i cann't email to majord...@openssl.org

2012-09-15 Thread Ralf Hildebrandt
) That's why. Your server doesn't have an reverse DNS entry. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra

Re: Why i cann't email to majord...@openssl.org

2012-09-15 Thread Ralf Hildebrandt
* LEON l...@kingdest.com: Hi, This is my static ip mail server,ISP give me the ip,and i install the bind9 in this mail server,can you tell me how to do ? You ISP needs to setup the reverse DNS entry (I guess). -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité

Re: Why i cann't email to majord...@openssl.org

2012-09-15 Thread Ralf Hildebrandt
Province Network country:CN origin: AS17816 mnt-by: MAINT-CNCGROUP-RR changed:ab...@cnc-noc.net 20060118 source: APNIC So maybe try ab...@cnc-noc.net (although this seems to be a bit over the top, rather contact your sales representative) -- Ralf

Re: Why i cann't email to majord...@openssl.org

2012-09-15 Thread Ralf Hildebrandt
* LEON l...@kingdest.com: What command to get this information? host -t ns 54.107.218.in-addr.arpa -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155

Re: tlsproxy appears to be greylisting - is this normal behaviour?

2012-09-18 Thread Ralf Hildebrandt
postscreen_dnsbl_sites = bl.spamcop.net, zen.spamhaus.org, cbl.abuseat.org postscreen_greet_action = enforce postscreen_non_smtp_command_enable = yes two of them. postscreen_bare_newline_enable and postscreen_non_smtp_command_enable -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité

Re: tlsproxy appears to be greylisting - is this normal behaviour?

2012-09-18 Thread Ralf Hildebrandt
* Chris Horry zer...@wibble.co.uk: Ralf, I knew I'd missed something, thanks for the clarification. Those tests are useful, nonetheless :) -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30

Which server is that?

2012-09-19 Thread Ralf Hildebrandt
know these either. What IS this? aemsg is answered like this: aemsg 500 Command unrecognized: Rejecting command, Not an AE box or source Not Allowed AE box? What's an AE box? -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin

[OT] DNS insights required

2012-09-19 Thread Ralf Hildebrandt
www.pimda.eu Host www.pimda.eu not found: 3(NXDOMAIN) # host -t mx www.pimda.eu Host www.pimda.eu not found: 3(NXDOMAIN) According to the docs, host By default, it looks for A, , and MX records. But why am I getting three results? Usually I'm only getting ONE! -- Ralf Hildebrandt

Re: [OT] DNS insights required

2012-09-19 Thread Ralf Hildebrandt
record and fails. Basically ns1.bdm.microsoftonline.com says I'm not authoritative for that, look at ns1.bdm.microsoftonline.com ... which is of course broken. That's the Microsoft way... -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin

Re: [OT] DNS insights required

2012-09-19 Thread Ralf Hildebrandt
and dig + trace found me the entries. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra...@charite.de | http

Re: [OT] DNS insights required

2012-09-19 Thread Ralf Hildebrandt
.bdm.microsoftonline.com. 3600 IN 2a01:111:f406:1804::59 ;; Query time: 122 msec ;; SERVER: 207.46.15.59#53(207.46.15.59) ;; WHEN: Wed Sep 19 12:35:13 2012 ;; MSG SIZE rcvd: 177 -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin

Re: [OT] DNS insights required

2012-09-19 Thread Ralf Hildebrandt
. IN ;; AUTHORITY SECTION: www.pimda.eu. 1 IN SOA ns1.bdm.microsoftonline.com. msnhst.microsoft.com. 2007070100 10800 1800 691200 3600 NXDOMAIN, empty response set, authoritative (flags: aa) -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung

Re: Proper forwarding behaviour

2012-09-23 Thread Ralf Hildebrandt
nevertheless, since forwarding breaks SPF. As a benefit it allows you to notice bounces and react accordingly. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155

Re: sporadic bouts of lost connections to exchange 2010 hub transport

2012-09-24 Thread Ralf Hildebrandt
stage, before pipelining is even attempted. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra...@charite.de

Re: sporadic bouts of lost connections to exchange 2010 hub transport

2012-09-24 Thread Ralf Hildebrandt
. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra...@charite.de | http://www.charite.de

Re: sporadic bouts of lost connections to exchange 2010 hub transport

2012-09-25 Thread Ralf Hildebrandt
to documents or similar that proves that there is a problem between the two operationg systems with regard to TCP window scaling. This is the first time I hear about this to be honest. I was wondering about this as well. I mean, it doesn't happen THAT often. -- Ralf Hildebrandt Geschäftsbereich

Re: Recipient Address local part starting with - (hyphen) - illegal address?

2012-09-26 Thread Ralf Hildebrandt
* Harakiri harakiri...@yahoo.com: When trying to sent a mail to -u...@domain.com postfix will complain allow_min_user = yes -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin

Re: Can't send mails outside my domain

2012-10-01 Thread Ralf Hildebrandt
* Alumno Etsii todos.somos...@gmail.com: client.devels.es exists (and resolves), but r...@client.devels.es doesn't $ host client.devels.es Host client.devels.es not found: 3(NXDOMAIN) -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin

Re: Can't send mails outside my domain

2012-10-01 Thread Ralf Hildebrandt
* Alumno Etsii todos.somos...@gmail.com: 2012/10/1 Ralf Hildebrandt ralf.hildebra...@charite.de * Alumno Etsii todos.somos...@gmail.com: client.devels.es exists (and resolves), but root@client.devels.esdoesn't $ host client.devels.es Host client.devels.es not found: 3(NXDOMAIN

Re: transport: list of domains

2012-10-02 Thread Ralf Hildebrandt
the smtp_concurrency_limit for these domains without creating thousands of lines with domainnametransport: domainname domainname: domainname is a copy of the smtp...smtp line in master, renamed to domainname...smtp and then use domainname_concurrency_limit -- Ralf

Re: Content filtering messages from sasl authenticated users

2012-10-02 Thread Ralf Hildebrandt
if the user has authenticated (sasl_username attribut is non-empty) See http://www.postfix.org/SMTPD_POLICY_README.html for the policy delegation stuff See http://www.postfix.org/access.5.html for the FILTER: stuff -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité

Re: reject_unknown_sender_domain and DNS SERVFAIL result

2012-10-03 Thread Ralf Hildebrandt
msec ;; SERVER: 127.0.1.1#53(127.0.1.1) ;; WHEN: Wed Oct 3 22:21:22 2012 ;; MSG SIZE rcvd: 100 -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax

Re: MX vs A records

2012-10-11 Thread Ralf Hildebrandt
sitting in the queues, doing nothing. How would one deal with this? 1 of the domains in quetions is: opnet.net opnet.net error:5.1.1 One cannot send mail there in transport_maps -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus

Re: MX vs A records

2012-10-11 Thread Ralf Hildebrandt
has some thousand recors from the last 2 years -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra...@charite.de

Re: Block sending from non-US IPs

2012-10-18 Thread Ralf Hildebrandt
, but this combination has me scratching my head. Is it doable? The best thing I can think of would be a policy daemon which uses libgeoip. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49

Re: Postfix and RBL program in the same server

2012-10-18 Thread Ralf Hildebrandt
. Is it posible to configure that? cat /etc/resolv.conf postfix check -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570 155 | Fax: +49 30 450 570 962 ralf.hildebra

Re: Postfix and RBL program in the same server

2012-10-18 Thread Ralf Hildebrandt
. Configure the DNS on 127.0.0.1 to use itself for RBL queries and XXX.XXX.XXX.XXX YYY.YYY.YYY.YYY as forwarder -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus Benjamin Franklin Hindenburgdamm 30 | D-12203 Berlin Tel. +49 30 450 570

Re: stat=queue and /var/spool/clientmqueue

2012-10-18 Thread Ralf Hildebrandt
, or if postfix simply could be configured to look on this queue too. Maybe you have postfix and sendmail installed side by side and /bin/mail is using the sendmail's sendmail command -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité - Universitätsmedizin Berlin Campus

Re: postfix-user list features undocumented

2012-10-20 Thread Ralf Hildebrandt
acknowledgements. Also something that Mailman does: If a post is held and later released by an admin, one can receive a post acknowledgements (which only makes sense when you're NOT a member or you disabled receiving mails. -- Ralf Hildebrandt Geschäftsbereich IT | Abteilung Netzwerk Charité

Re: Postfix Move Emails to TMP Queue Directory if recipent limit is more than 5

2012-10-25 Thread Ralf Hildebrandt
* Prashanth P.Nair prashanth...@gmail.com: Is it possible to Move any Emails to TMP Queue Directory if recipients are more than 5 in Postfix 2.6 ? What is the function of the TMP Queue Directory? -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz

Re: Postfix Move Emails to TMP Queue Directory if recipent limit is more than 5

2012-10-25 Thread Ralf Hildebrandt
* Prashanth P.Nair prashanth...@gmail.com: Exact Requirement is ,If any email's have more than 10 recipient's ,I don't want to deliver those mail's to recipient's instead of that I want to move those email to tmp queue folder. Later then Administrator manually check the tmp queue and process

Re: Postfix Move Emails to TMP Queue Directory if recipent limit is more than 5

2012-10-25 Thread Ralf Hildebrandt
* Prashanth P.Nair prashanth...@gmail.com: ok..Is it Possible Hold the queue If recipient Limit is more than 10 Yes. and process the HOLD queue using Perl script? You can use mailq to get queueIDs and then use postcat postsuper from perl. -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46

Re: Specify alternate delivery for expired mails

2012-10-29 Thread Ralf Hildebrandt
* Ram r...@netcore.co.in: The problem is when the mail has been on my postfix relay server for 5 days and then the mail bounces back, postfix does not log for which recipient the mail failed Really? What DOES it say? -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße

Re: upgrade behavior when smtpd_relay_restrictions is explicitly empty in main.cf

2012-10-31 Thread Ralf Hildebrandt
* Sahil Tandon postfix-users@postfix.org: In Postfix 2.10 Snapshot 20121022, conf/post-install tests whether smtpd_relay_restrictions is already set with: test -n `$POSTCONF -c $config_directory -nh smtpd_relay_restrictions` This evaluates to false when smtpd_relay_restrictions is

Re: Only check_policy_service for authenticated / relayed emails

2012-10-31 Thread Ralf Hildebrandt
* Tobia Conforto tobia.confo...@gruppo4.eu: Hello Can I configure Postfix 2.7 to only run check_policy_service for SASL authenticated emails? Not really. You can if SASL authenticated email come in via an alternate port. As an alternative you can make your policy daemon CHECK for the

Re: postfix delivery delay causing duplicate mail delivery

2012-10-31 Thread Ralf Hildebrandt
* Fred Ho f...@fredho.net: Hi, I am running Postfix version 2.5.6 on RedHat 4 and is experiencing periodic duplicated mails.The RedHat mailserver is the mailhub receiving incoming mails from the ISP and forward mails to the internal mail server. Occasionally, users are complaining receiving

Re: postfix delivery delay causing duplicate mail delivery

2012-10-31 Thread Ralf Hildebrandt
* Fred Ho f...@fredho.net: Hi, There's the SonicWall FW in between. What should I look for?I have the LAN MTU = 1420 on the RedHat server matching that of the ISP router. I thought it might have something to do with smtp protocol fixup, which is horrible broken on PIX/ASA firewalls. Oct

Re: postfix delivery delay causing duplicate mail delivery

2012-10-31 Thread Ralf Hildebrandt
* Fred Ho f...@fredho.net: Hi, Between 10:15:17 and 13:04:23 there's no 4803D7F20 related items like that of F097C7F1F. Oct 31 10:15:14 mailgate2 postfix/smtp[9660]: 2C9897F20: to=chen...@crownever.com.cn, relay=outbound10.ttasia.com[210.17.183.10]:25, delay=2.2, delays=0.05/0/0.05/2.1,

Re: /var/log/mail.info

2012-11-01 Thread Ralf Hildebrandt
* thorso...@lavabit.com thorso...@lavabit.com: Hi, I'm getting the following connections from suspicious IPs. $ sudo more /var/log/mail.info DATE MACHINE postfix/smtpd[PID]: connect from unknown[IP] DATE MACHINE postfix/smtpd[PID]: lost connection after UNKNOWN from unknown[IP] DATE

Re: dnsblog lookup error questions

2012-11-01 Thread Ralf Hildebrandt
* Alex mysqlstud...@gmail.com: Hi, I have a fc15 server with postfix-2.8.10 and have enabled postscreen. I've enabled it before without any difficulty, so I'm not sure what I'm doing wrong in this case. For some reason it is printing these errors periodically: Oct 31 23:41:15 portal

Re: dnsblog lookup error questions

2012-11-01 Thread Ralf Hildebrandt
* Alex mysqlstud...@gmail.com: cat /etc/resolv.conf postfix check what's the output of those? It's set up to use the local caching server, good. Which server is the caching server asking? and doesn't otherwise have any resolution issues. Even when I try to resolve that host using

Re: Does an option include exist?

2012-11-02 Thread Ralf Hildebrandt
* /dev/rob0 postfix-users@postfix.org: I'm not saying it is a bad idea. It might even be something for Wietse to consider if/when work begins on a non-compatible Postfix 3.0. I think it would be difficult to ensure downgradability with such a feature. I sure is a way of making the config

Re: Postfix Move Emails to TMP Queue Directory if recipent limit is more than 5

2012-11-05 Thread Ralf Hildebrandt
* Prashanth P.Nair prashanth...@gmail.com: Thanks for the advise. I found that we can achieve this using header_check . # restrict based on message header content header_checks = pcre:/etc/postfix/header_checks /etc/postfix/header_checks: /^To:([^@]*@){1,}/HOLD Sorry, your

Re: Postfix Move Emails to TMP Queue Directory if recipent limit is more than 5

2012-11-05 Thread Ralf Hildebrandt
* /dev/rob0 postfix-users@postfix.org: But what happens when some smartaleck uses an @ sign in the RFC 5322 display-name field, as I did, above? It will break. Joe@work j...@example.com Joe@home j...@example.com Amen to that. I've seen that even in the From: header! -- [*] sys4 AG

Re: Verify cache missing?

2012-11-08 Thread Ralf Hildebrandt
* Nikolaos Milas nmi...@noa.gr: On 8/11/2012 2:42 μμ, Nikolaos Milas wrote: So, I conclude that in this case there is no such cache because reject_unverified_recipient is at the end of smtpd_recipient_restrictions, so in essence it is never used... Now that I re-think it over, in fact

Re: FROM: Address re-writing using regexp:/etc/postfix/sender_canonical for particular emails.

2012-11-12 Thread Ralf Hildebrandt
* Prashanth P.Nair prashanth...@gmail.com: How to re-write From: My Self mys...@thisdomain.com to From: My Self mys...@thatdomain.com using regexp . I know the sender_canonical_maps changes both the envelop sender address and header sender address according to the sender_canonical_classes.

Re: pcre:header_check

2012-11-21 Thread Ralf Hildebrandt
* prashuppp p prashanthpnai...@gmail.com: I was trying to HOLD all the emails which has more then 2 recipient's using header_checks = pcre:/etc/postfix/header_checks /^(Cc|To):([^@]*@){2,}/ HOLD header_checks only apply (AS THE NAME SAYS!) to... the headers. No header, no match. But not

Re: pcre:header_check

2012-11-21 Thread Ralf Hildebrandt
* prashanth p prashanthpnai...@gmail.com: ok..great..Is there any other method to do for envelope also..I need it for both.. You'd need a policy_daemon for that. Didn't you ask that before? postfwd can easily do that. -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15,

Re: reporting

2012-11-21 Thread Ralf Hildebrandt
* Muhammad Yousuf Khan sir...@gmail.com: is there any way that i can collect reports in which i can check who is the sender who is the receiver what was the mail subject, if You can log this using header_checks with: /^Subject:/ WARN and mime_header_checks with: /filename=\(.*)\.(...)\$/

Re: reporting

2012-11-21 Thread Ralf Hildebrandt
* Muhammad Yousuf Khan sir...@gmail.com: and mime_header_checks with: /filename=\(.*)\.(...)\$/ WARN Attachment $1.$2 Thanks for the help. but any suggestion for the attachment size. Not possible with postfix alone. If you put Amavis in the loop, you get to see the attachment names

Re: NDR not received while relaying

2012-11-22 Thread Ralf Hildebrandt
* Muhammad Yousuf Khan sir...@gmail.com: i am using my ISP relay. and i don't receive NDRs for any invalid or unknown account. is this default. or i must be doing some config mistakes. Maybe your ISP relay is blocking bounces. however, in log files i can see that my message has been relayed

Re: Configure open relay on specific port

2012-11-22 Thread Ralf Hildebrandt
* Patric Falinder patric.falin...@omg.nu: So it's not possible to have Postfix listening on another port with different settings, like skipping the authentication bit and have it act like an open relay? Well of course: -o smtpd_recipient_restrictions=... -o ... -- [*] sys4 AG

Re: mail forwarding loop from certain spam only

2012-11-29 Thread Ralf Hildebrandt
* Noel Jones postfix-users@postfix.org: On 11/28/2012 1:17 PM, Will Yardley wrote: [Apologies in advance for the less than complete information below; hoping someone may have an idea of what's happening anyway] I'm having a problem where messages are accepted but then seem to generate

DNS issue

2012-11-29 Thread Ralf Hildebrandt
I'm seeing a DNS problem I cannot fathom: # host 65.171.152.29 Host 29.152.171.65.in-addr.arpa not found: 2(SERVFAIL) Hm. So who's authoritative? # host -t ns 171.65.in-addr.arpa 171.65.in-addr.arpa name server ns1-auth.sprintlink.net. 171.65.in-addr.arpa name server ns3-auth.sprintlink.net.

Re: Bad address syntax

2012-11-29 Thread Ralf Hildebrandt
* Muzaffer Tolga Özses to...@ozses.net: Hi, I'm getting the log entry in my to=root@/etc/mailname, relay=none, delay=0, delays=0/0/0/0, dsn=5.1.3, status=bounced (bad address syntax). Googling says I should add allow_min_users = yes, which I would like to confirm. root@/etc/mailname is

Re: Bad address syntax

2012-11-29 Thread Ralf Hildebrandt
* Ralf Hildebrandt r...@sys4.de: * Muzaffer Tolga Özses to...@ozses.net: Hi, I'm getting the log entry in my to=root@/etc/mailname, relay=none, delay=0, delays=0/0/0/0, dsn=5.1.3, status=bounced (bad address syntax). Googling says I should add allow_min_users = yes, which I would

Re: Bad address syntax

2012-11-29 Thread Ralf Hildebrandt
* Ralf Hildebrandt r...@sys4.de: * Ralf Hildebrandt r...@sys4.de: * Muzaffer Tolga Özses to...@ozses.net: Hi, I'm getting the log entry in my to=root@/etc/mailname, relay=none, delay=0, delays=0/0/0/0, dsn=5.1.3, status=bounced (bad address syntax). Googling says I should add

Re: avoiding overload on port 587

2012-11-30 Thread Ralf Hildebrandt
* Robert Schetterer r...@sys4.de: Am 30.11.2012 11:44, schrieb Tomas Macek: I cannot apply firewall rules on 587, because our clients travel with their notebooks and still want to send their emails through our mailserver. use fail2ban etc for blocking dynamic, brute force attacks to

Re: Problem migrating a mail domain (loops back)

2012-12-04 Thread Ralf Hildebrandt
* d.davo...@mastertraining.it d.davo...@mastertraining.it: This is from /var/log/syslog: Dec 4 15:13:41 mail2 postfix/smtpd[26204]: 4E21EA735A: client=unknown[192.168.2.203] Dec 4 15:13:41 mail2 postfix/cleanup[26207]: 4E21EA735A:

Re: Problem migrating a mail domain (loops back)

2012-12-04 Thread Ralf Hildebrandt
* d.davo...@mastertraining.it d.davo...@mastertraining.it: Dec 4 15:13:41 mail2 postfix/smtp[26167]: 4E21EA735A: to=e.bos...@mastervoice.it, relay=none, delay=0.1, delays=0.1/0/0/0, dsn=5.4.6, status=bounced (mail for mastervoice.it loops back to myself) What is the result of % host -t mx

Re: timeout problem

2012-12-18 Thread Ralf Hildebrandt
* ml m...@smtp.fakessh.eu: (host ks3.kimsufi.com[/var/run/dspam/dspam.sock] said: 421 4.3.0 fake...@localhost.ks3.kimsufi.com Deferred: 451-4.7.0 DNS timeout (in reply to end of DATA command)) Looks like a problem within dspam -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64

Re: postconf expansion

2012-12-28 Thread Ralf Hildebrandt
* Wietse Venema postfix-users@postfix.org: OK, the 20121224 Christmas edition does this and more, and it also produces more warnings. As for the latter I wonder if it will freak out people and would need to be shut up at install/upgrade time. Didn't freak me out, but instead it listed an

Re: Question About Log entries

2013-01-28 Thread Ralf Hildebrandt
* Bob Cohen b...@bobjcohen.com: Follows are several maillog entries. I'm not clear on how to read them. warning: restriction `reject_rbl_client' after `permit' is ignored Does this mean, Postfix rejected an email based on the reject_rbl_client rule, which was placed in the main.cf after

smtpd_command_filter counterpart?

2013-02-06 Thread Ralf Hildebrandt
I can use smtpd_command_filter to add NOTIFY=NEVER and thus suppress bounces from my own Postfix. But how can I remove the NOTIFY=NEVER again when sending mail (maybe via a specific SMTP transport) to some external host? Sounds like I'm looking for smtp_command_filter? -- [*] sys4 AG

Re: Archiving mails based on subject - Was: Re: sometimes_bcc?

2013-02-07 Thread Ralf Hildebrandt
* Robert Schetterer r...@sys4.de: Am 07.02.2013 14:38, schrieb Marcio Merlone: Em 07-02-2013 11:19, Noel Jones escreveu: Regardless of how you state the problem, it should already be clear that postfix does not have native capability to do selective BCC based on the subject. Yes, it was

Re: questions about functions in postfix

2013-02-07 Thread Ralf Hildebrandt
* deconya deco...@riseup.net: Hi list Im looking to activate a smarthost in my postfix, and for this I need to use the function smtp_sasl_password_maps. I have and old server 2.5.5 and Im not sure if was supported in this old version. Where can I see the changelogs to confirm this?

Re: Our postfix works fine, but it is very slow when we send newsletter

2013-02-21 Thread Ralf Hildebrandt
* Vince Wang vw...@nwp.org: Hello, We have a configured postfix email server worked well when we had it on the public IP. After we moved it behind our firewall on a intranet with ip 192.168.xxx.xxx, we found it is very slow when we send newsletter. Logs? As I just start learning about

Re: reject empty sender address for authenticated users

2013-02-27 Thread Ralf Hildebrandt
* Piotr Rotter piotr.rot...@active24.pl: I want to disallow this because is rarely (probably poor mail clients) and make more difficult to automatic parsing amavis logs like this 2013-02-25T04:29:47+01:00 kurier4 amavis[20204]: (20204-10) Passed CLEAN, - u...@domain.tld, Hits: -2.56,

Serving Dovecot mailbox quota status to Postfix

2013-04-11 Thread Ralf Hildebrandt
I wrote a little something about how to prevent delivery to mailboxes over quota while still being in the SMTP dialogue: http://sys4.de/en/blog/2013/04/08/postfix-dovecot-mailbox-quota/ (Postfix/Dovecot) -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München

Re: Serving Dovecot mailbox quota status to Postfix

2013-04-11 Thread Ralf Hildebrandt
* Ralf Hildebrandt r...@sys4.de: I wrote a little something about how to prevent delivery to mailboxes over quota while still being in the SMTP dialogue: http://sys4.de/en/blog/2013/04/08/postfix-dovecot-mailbox-quota/ (Postfix/Dovecot) To be precise: Postfix/Dovecot-2.2 -- [*] sys4 AG

Re: Serving Dovecot mailbox quota status to Postfix

2013-04-12 Thread Ralf Hildebrandt
* Titanus Eramius tita...@aptget.dk: Very useful, thank you for writing and sharing. May I suggest the english Wiki-article for background on backscatter? URL? -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München,

Re: Serving Dovecot mailbox quota status to Postfix

2013-04-13 Thread Ralf Hildebrandt
* Titanus Eramius tita...@aptget.dk: Fri, 12 Apr 2013 15:27:26 +0200 skrev Ralf Hildebrandt r...@sys4.de: * Titanus Eramius tita...@aptget.dk: Very useful, thank you for writing and sharing. May I suggest the english Wiki-article for background on backscatter? URL? Sorry

Re: Secure relay from specific internet host to internet

2013-04-18 Thread Ralf Hildebrandt
* L.W. van Braam van Vloten luc...@dds.nl: Hello list, I would like to to use my postfix implementation to relay mail from one specific host on the internet, to any address on the internet. The idea is that the external host will send name in my name, i.e. it will appear to come from my

Strange conversion of 5.2.2 into 4.1.0 error

2013-05-03 Thread Ralf Hildebrandt
On our Postfix gateway we're using a policy query to our backend dovecot server to check if the mail would fit into the mailbox. Recently I noticed that the hu-berlin.de Mailserver keeps retrying in spite of a 522 error: May 1 05:32:36 mail postfix/smtpd[5185]: NOQUEUE: reject: RCPT from

Re: Strange conversion of 5.2.2 into 4.1.0 error

2013-05-03 Thread Ralf Hildebrandt
* Bastian Blank bastian+postfix-users=postfix@waldi.eu.org: On Fri, May 03, 2013 at 10:18:43AM +0200, Ralf Hildebrandt wrote: Tue Apr 30 20:05:04 2013 Info: Delivery start DCID 4678286 MID 15335505 to RID [0] Tue Apr 30 20:05:06 2013 Info: Delayed: DCID 4678286 MID 15335505 to RID 0

Re: Strange conversion of 5.2.2 into 4.1.0 error

2013-05-03 Thread Ralf Hildebrandt
* Viktor Dukhovni postfix-users@postfix.org: In the interim you can use 554 5.2.2 ... which won't be misunderstood. Yeah, I'll do that instead. -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB

Re: Probleme with bounce

2013-05-05 Thread Ralf Hildebrandt
* Phibee Network Operation Center n...@phibee.net: Hi we have installed today Postfix and we have a small problems with bounce. All email genered by Postfix, for Mailbox Unknow sample, put a blank from: May 3 15:01:27 smtp-1 postfix/qmgr[9482]: EDA7D281D2: from=, size=5511, nrcpt=1

Re: Probleme with bounce

2013-05-05 Thread Ralf Hildebrandt
* Phibee Network Operation Center n...@phibee.net: Hi we have installed today Postfix and we have a small problems with bounce. All email genered by Postfix, for Mailbox Unknow sample, put a blank from: May 3 15:01:27 smtp-1 postfix/qmgr[9482]: EDA7D281D2: from=, size=5511, nrcpt=1

signal 11 with postfix-2.11-20130426-nonprod

2013-05-05 Thread Ralf Hildebrandt
I gave postfix-2.11-20130426-nonprod a spin and got this: May 5 20:35:30 mail postfix/qmgr[2890]: warning: private/smtp socket: malformed response May 5 20:35:30 mail postfix/qmgr[2890]: warning: transport smtp failure -- see a previous warning/fatal/panic logfile record for the problem

Re: signal 11 with postfix-2.11-20130426-nonprod

2013-05-05 Thread Ralf Hildebrandt
* Viktor Dukhovni postfix-users@postfix.org: On Sun, May 05, 2013 at 08:38:20PM +0200, Ralf Hildebrandt wrote: May 5 20:35:31 mail postfix/qmgr[2890]: warning: transport smtp failure -- see a previous warning/fatal/panic logfile record for the problem description May 5 20:35:31 mail

bad digest length:s3_both.c:239: when sending to mail.vex.net?

2013-05-08 Thread Ralf Hildebrandt
Anybody seen this one before? May 8 00:30:04 albatross postfix/smtp[29327]: SSL_connect error to mail.vex.net[98.158.139.68]:25: 0 May 8 00:30:04 albatross postfix/smtp[29327]: warning: TLS library problem: 29327:error:1408C06F:SSL routines:SSL3_GET_FINISHED:bad digest length:s3_both.c:239:

Re: bad digest length:s3_both.c:239: when sending to mail.vex.net?

2013-05-09 Thread Ralf Hildebrandt
* Viktor Dukhovni postfix-users@postfix.org: Does this happen consistently, or intermittently? consistently Can you reproduce this with: openssl s_client \ -cipher $(postconf -xh tls_export_cipher_list) \ -sslv2 \ -starttls smtp -connect mail.vex.net:25 #

Re: bad digest length:s3_both.c:239: when sending to mail.vex.net?

2013-05-09 Thread Ralf Hildebrandt
* Viktor Dukhovni postfix-users@postfix.org: On Wed, May 08, 2013 at 03:54:35PM +, Viktor Dukhovni wrote: Can you reproduce this with: openssl s_client \ -cipher $(postconf -xh tls_export_cipher_list) \ -sslv2 \ -starttls smtp -connect mail.vex.net:25 Sorry

Re: bad digest length:s3_both.c:239: when sending to mail.vex.net?

2013-05-09 Thread Ralf Hildebrandt
* Jukka Salmi j+post...@salmi.ch: Funny, I was just going to report the probably same issue... :) When sending several mails in succession, failure and success seem to alternate (i.e. exactly one failed handshake, then a successful one, then a failed one again, etc.). And not using a TLS

Re: bad digest length:s3_both.c:239: when sending to mail.vex.net?

2013-05-09 Thread Ralf Hildebrandt
* Viktor Dukhovni postfix-users@postfix.org: Any information on the server's O/S, OpenSSL and Postfix version and whether the Postfix TLS session cache database is enabled would be most helpful. If I get any info about this from vex, I'll share it with you -- [*] sys4 AG http://sys4.de,

Re: bad digest length:s3_both.c:239: when sending to mail.vex.net?

2013-05-09 Thread Ralf Hildebrandt
* Viktor Dukhovni postfix-users@postfix.org: On Thu, May 09, 2013 at 07:28:09PM +0200, Ralf Hildebrandt wrote: * Jukka Salmi j+post...@salmi.ch: Funny, I was just going to report the probably same issue... :) When sending several mails in succession, failure and success seem

Re: bad digest length:s3_both.c:239: when sending to mail.vex.net?

2013-05-09 Thread Ralf Hildebrandt
First: Thanks for answering at all. It's not commonplace nowadays to find a contact and if one does to get an answer at all! :) The whole thread (two people have similar issues with vex.net) can be found here: http://archives.neohapsis.com/archives/postfix/2013-05/thread.html#160 Odd.

smtp_fallback_relay question

2013-05-14 Thread Ralf Hildebrandt
If a SMTP destination is unreachable, is the smtp_fallback_relay tried IMMEDATELY after not reaching the real destination or is the mail being deferred and thus subject to queue_run_delay / minimal_backoff_time? -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669

Using resolve_numeric_domain=yes in master.cf

2013-05-20 Thread Ralf Hildebrandt
Tryied to whitelist a SUN ILOM interface sending non-compliant mails like this: May 18 18:19:24 root1 postfix/smtpd[9998]: connect from mail1[80.XXX.XXX.XXX] May 18 18:19:25 root1 postfix/smtpd[9998]: warning: Illegal address syntax from mail1[80.XXX.XXX.XXX] in MAIL command:

Re: Documentation patch: [Re: Using resolve_numeric_domain=yes in master.cf]

2013-05-21 Thread Ralf Hildebrandt
* Viktor Dukhovni postfix-users@postfix.org: On Mon, May 20, 2013 at 05:04:32PM +, Viktor Dukhovni wrote: On Mon, May 20, 2013 at 06:37:19PM +0200, Ralf Hildebrandt wrote: So I added resolve_numeric_domain=yes to a specific smtpd listening on port 10026 - since I don'T want

Re: Timeouts sending to a particular server

2013-05-30 Thread Ralf Hildebrandt
* Nikolaos Milas nmi...@noa.gr: mail.cospico.gr[62.38.156.203] timed out while sending end of data -- message may be sent more than once) Can you please advise me on what may be the cause of this problem? I usually disable ESMTP when encountering those problems: transport_maps: cospico.gr

Re: question about postfix queue scheduler

2013-06-04 Thread Ralf Hildebrandt
* Wietse Venema postfix-users@postfix.org: Maybe you can automatically HOLD all his mail and then automatically release all his mail in the evening. I even have a script for that... -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der

smtp_fallback_relay

2013-06-13 Thread Ralf Hildebrandt
Currently, smtp_fallback_relay is being used after the first failed delivery. http://www.postfix.org/postconf.5.html#smtp_fallback_relay explicitly mentions: With bulk email deliveries, it can be beneficial to run the fallback relay MTA on the same host, so that it can reuse the sender IP

Re: smtp_fallback_relay

2013-06-14 Thread Ralf Hildebrandt
Alternative/additional approach: smtp_fallback_relay_threshold_time (compare to smtp_pix_workaround_threshold_time) How long a message must be queued before the Postfix SMTP client passes the mail to the smtp_fallback_relay. A threshold would work, with the default of 0 meaning

Re: Deliver to sender instead of recipient

2013-07-25 Thread Ralf Hildebrandt
* Wietse Venema wie...@porcupine.org: Fernando Gozalo: Hi, How can I deliver the messages to the mailbox of the sender instead of the mailbox of the recipient? /etc/postfix/main.cf: smtpd_sender_restrictions = pcre:/etc/postfix/sender_access /etc/postfix/sender_access:

Re: mail transport unavailable

2013-08-01 Thread Ralf Hildebrandt
* LuKreme krem...@kreme.com: On 31 Jul 2013, at 21:52 , Noel Jones njo...@megan.vbhcs.org wrote: Looks as if you clobbered your smtp transport smtp unix ... smtp smtp inet n - n - 1 postscreen smtpd pass - - n - -

Re: local(8) file size misunderstanding

2013-08-09 Thread Ralf Hildebrandt
* Vincent McIntyre vincent.mcint...@csiro.au: mailbox_size_limit = 512000 #5-ish Gb ... Aug 8 14:22:17 ursa postfix/local[24324]: A88FA35028: to=hapl...@mailserver.atnf.csiro.au, relay=local, delay=0.71, delays=0.59/0/0/0.13, dsn=5.2.2, status=bounced (cannot update mailbox

<    7   8   9   10   11   12   13   14   >