postconf.5.html revision 1.1.1.2 1 1.1 tron <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"
2 1.1 tron "http://www.w3.org/TR/html4/loose.dtd">
3 1.1 tron
4 1.1 tron <html>
5 1.1 tron
6 1.1 tron <head>
7 1.1 tron
8 1.1 tron <title>Postfix Configuration Parameters </title>
9 1.1 tron
10 1.1 tron <meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
11 1.1 tron
12 1.1 tron </head>
13 1.1 tron
14 1.1 tron <body>
15 1.1 tron
16 1.1 tron <h1><img src="postfix-logo.jpg" width="203" height="98" alt="">Postfix Configuration Parameters </h1>
17 1.1 tron
18 1.1 tron <hr>
19 1.1 tron
20 1.1 tron <h2> Postfix main.cf file format </h2>
21 1.1 tron
22 1.1 tron <p> The Postfix main.cf configuration file specifies a very small
23 1.1 tron subset of all the parameters that control the operation of the
24 1.1 tron Postfix mail system. Parameters not explicitly specified are left
25 1.1 tron at their default values. </p>
26 1.1 tron
27 1.1 tron <p> The general format of the main.cf file is as follows: </p>
28 1.1 tron
29 1.1 tron <ul>
30 1.1 tron
31 1.1 tron <li> <p> Each logical line is in the form "parameter = value".
32 1.1 tron Whitespace around the "=" is ignored, as is whitespace at the end
33 1.1 tron of a logical line. </p>
34 1.1 tron
35 1.1 tron <li> <p> Empty lines and whitespace-only lines are ignored, as are
36 1.1 tron lines whose first non-whitespace character is a `#'. </p>
37 1.1 tron
38 1.1 tron <li> <p> A logical line starts with non-whitespace text. A line
39 1.1 tron that starts with whitespace continues a logical line. </p>
40 1.1 tron
41 1.1 tron <li> <p> A parameter value may refer to other parameters. </p>
42 1.1 tron
43 1.1 tron <ul>
44 1.1 tron
45 1.1 tron <li> <p> The expressions "$name", "${name}" or "$(name)" are
46 1.1 tron recursively replaced by the value of the named parameter. </p>
47 1.1 tron
48 1.1 tron <li> <p> The expression "${name?value}" expands to "value" when
49 1.1 tron "$name" is non-empty. This form is supported with Postfix version
50 1.1 tron 2.2 and later. </p>
51 1.1 tron
52 1.1 tron <li> <p> The expression "${name:value}" expands to "value" when
53 1.1 tron "$name" is empty. This form is supported with Postfix version 2.2
54 1.1 tron and later. </p>
55 1.1 tron
56 1.1 tron <li> <p> Specify "$$" to produce a single "$" character. </p>
57 1.1 tron
58 1.1 tron </ul>
59 1.1 tron
60 1.1 tron <li> <p> When the same parameter is defined multiple times, only
61 1.1 tron the last instance is remembered. </p>
62 1.1 tron
63 1.1 tron <li> <p> Otherwise, the order of main.cf parameter definitions does
64 1.1 tron not matter. </p>
65 1.1 tron
66 1.1 tron </ul>
67 1.1 tron
68 1.1 tron <p> The remainder of this document is a description of all Postfix
69 1.1 tron configuration parameters. Default values are shown after the
70 1.1 tron parameter name in parentheses, and can be looked up with the
71 1.1 tron "<b>postconf -d</b>" command. </p>
72 1.1 tron
73 1.1 tron <p> Note: this is not an invitation to make changes to Postfix
74 1.1 tron configuration parameters. Unnecessary changes are likely to impair
75 1.1 tron the operation of the mail system. </p>
76 1.1 tron
77 1.1 tron <dl>
78 1.1 tron <DT><b><a name="2bounce_notice_recipient">2bounce_notice_recipient</a>
79 1.1 tron (default: postmaster)</b></DT><DD>
80 1.1 tron
81 1.1 tron <p> The recipient of undeliverable mail that cannot be returned to
82 1.1 tron the sender. This feature is enabled with the <a href="postconf.5.html#notify_classes">notify_classes</a>
83 1.1 tron parameter. </p>
84 1.1 tron
85 1.1 tron
86 1.1 tron </DD>
87 1.1 tron
88 1.1 tron <DT><b><a name="access_map_defer_code">access_map_defer_code</a>
89 1.1 tron (default: 450)</b></DT><DD>
90 1.1 tron
91 1.1 tron <p>
92 1.1 tron The numerical Postfix SMTP server response code for
93 1.1 tron an <a href="access.5.html">access(5)</a> map "defer" action, including "<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>"
94 1.1 tron or "<a href="postconf.5.html#defer_if_reject">defer_if_reject</a>". Prior to Postfix 2.6, the response
95 1.1 tron is hard-coded as "450".
96 1.1 tron </p>
97 1.1 tron
98 1.1 tron <p>
99 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
100 1.1 tron </p>
101 1.1 tron
102 1.1 tron <p>
103 1.1 tron This feature is available in Postfix 2.6 and later.
104 1.1 tron </p>
105 1.1 tron
106 1.1 tron
107 1.1 tron </DD>
108 1.1 tron
109 1.1 tron <DT><b><a name="access_map_reject_code">access_map_reject_code</a>
110 1.1 tron (default: 554)</b></DT><DD>
111 1.1 tron
112 1.1 tron <p>
113 1.1 tron The numerical Postfix SMTP server response code for
114 1.1 tron an <a href="access.5.html">access(5)</a> map "reject" action.
115 1.1 tron </p>
116 1.1 tron
117 1.1 tron <p>
118 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
119 1.1 tron </p>
120 1.1 tron
121 1.1 tron
122 1.1 tron </DD>
123 1.1 tron
124 1.1 tron <DT><b><a name="address_verify_default_transport">address_verify_default_transport</a>
125 1.1 tron (default: $<a href="postconf.5.html#default_transport">default_transport</a>)</b></DT><DD>
126 1.1 tron
127 1.1 tron <p>
128 1.1 tron Overrides the <a href="postconf.5.html#default_transport">default_transport</a> parameter setting for address
129 1.1 tron verification probes.
130 1.1 tron </p>
131 1.1 tron
132 1.1 tron <p>
133 1.1 tron This feature is available in Postfix 2.1 and later.
134 1.1 tron </p>
135 1.1 tron
136 1.1 tron
137 1.1 tron </DD>
138 1.1 tron
139 1.1 tron <DT><b><a name="address_verify_local_transport">address_verify_local_transport</a>
140 1.1 tron (default: $<a href="postconf.5.html#local_transport">local_transport</a>)</b></DT><DD>
141 1.1 tron
142 1.1 tron <p>
143 1.1 tron Overrides the <a href="postconf.5.html#local_transport">local_transport</a> parameter setting for address
144 1.1 tron verification probes.
145 1.1 tron </p>
146 1.1 tron
147 1.1 tron <p>
148 1.1 tron This feature is available in Postfix 2.1 and later.
149 1.1 tron </p>
150 1.1 tron
151 1.1 tron
152 1.1 tron </DD>
153 1.1 tron
154 1.1 tron <DT><b><a name="address_verify_map">address_verify_map</a>
155 1.1 tron (default: empty)</b></DT><DD>
156 1.1 tron
157 1.1 tron <p>
158 1.1 tron Optional lookup table for persistent address verification status
159 1.1 tron storage. The table is maintained by the <a href="verify.8.html">verify(8)</a> service, and
160 1.1 tron is opened before the process releases privileges.
161 1.1 tron </p>
162 1.1 tron
163 1.1 tron <p>
164 1.1 tron By default, the information is kept in volatile memory, and is lost
165 1.1 tron after "<b>postfix reload</b>" or "<b>postfix stop</b>".
166 1.1 tron </p>
167 1.1 tron
168 1.1 tron <p>
169 1.1 tron Specify a location in a file system that will not fill up. If the
170 1.1 tron database becomes corrupted, the world comes to an end. To recover
171 1.1 tron delete the file and do "<b>postfix reload</b>".
172 1.1 tron </p>
173 1.1 tron
174 1.1 tron <p> As of version 2.5, Postfix no longer uses root privileges when
175 1.1 tron opening this file. The file should now be stored under the Postfix-owned
176 1.1 tron <a href="postconf.5.html#data_directory">data_directory</a>. As a migration aid, an attempt to open the file
177 1.1 tron under a non-Postfix directory is redirected to the Postfix-owned
178 1.1 tron <a href="postconf.5.html#data_directory">data_directory</a>, and a warning is logged. </p>
179 1.1 tron
180 1.1 tron <p>
181 1.1 tron Examples:
182 1.1 tron </p>
183 1.1 tron
184 1.1 tron <pre>
185 1.1 tron <a href="postconf.5.html#address_verify_map">address_verify_map</a> = hash:/var/lib/postfix/verify
186 1.1 tron <a href="postconf.5.html#address_verify_map">address_verify_map</a> = btree:/var/lib/postfix/verify
187 1.1 tron </pre>
188 1.1 tron
189 1.1 tron <p>
190 1.1 tron This feature is available in Postfix 2.1 and later.
191 1.1 tron </p>
192 1.1 tron
193 1.1 tron
194 1.1 tron </DD>
195 1.1 tron
196 1.1 tron <DT><b><a name="address_verify_negative_cache">address_verify_negative_cache</a>
197 1.1 tron (default: yes)</b></DT><DD>
198 1.1 tron
199 1.1 tron <p>
200 1.1 tron Enable caching of failed address verification probe results. When
201 1.1 tron this feature is enabled, the cache may pollute quickly with garbage.
202 1.1 tron When this feature is disabled, Postfix will generate an address
203 1.1 tron probe for every lookup.
204 1.1 tron </p>
205 1.1 tron
206 1.1 tron <p>
207 1.1 tron This feature is available in Postfix 2.1 and later.
208 1.1 tron </p>
209 1.1 tron
210 1.1 tron
211 1.1 tron </DD>
212 1.1 tron
213 1.1 tron <DT><b><a name="address_verify_negative_expire_time">address_verify_negative_expire_time</a>
214 1.1 tron (default: 3d)</b></DT><DD>
215 1.1 tron
216 1.1 tron <p>
217 1.1 tron The time after which a failed probe expires from the address
218 1.1 tron verification cache.
219 1.1 tron </p>
220 1.1 tron
221 1.1 tron <p>
222 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
223 1.1 tron </p>
224 1.1 tron
225 1.1 tron <p>
226 1.1 tron This feature is available in Postfix 2.1 and later.
227 1.1 tron </p>
228 1.1 tron
229 1.1 tron
230 1.1 tron </DD>
231 1.1 tron
232 1.1 tron <DT><b><a name="address_verify_negative_refresh_time">address_verify_negative_refresh_time</a>
233 1.1 tron (default: 3h)</b></DT><DD>
234 1.1 tron
235 1.1 tron <p>
236 1.1 tron The time after which a failed address verification probe needs to
237 1.1 tron be refreshed.
238 1.1 tron </p>
239 1.1 tron
240 1.1 tron <p>
241 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
242 1.1 tron </p>
243 1.1 tron
244 1.1 tron <p>
245 1.1 tron This feature is available in Postfix 2.1 and later.
246 1.1 tron </p>
247 1.1 tron
248 1.1 tron
249 1.1 tron </DD>
250 1.1 tron
251 1.1 tron <DT><b><a name="address_verify_poll_count">address_verify_poll_count</a>
252 1.1 tron (default: 3)</b></DT><DD>
253 1.1 tron
254 1.1 tron <p>
255 1.1 tron How many times to query the <a href="verify.8.html">verify(8)</a> service for the completion
256 1.1 tron of an address verification request in progress.
257 1.1 tron </p>
258 1.1 tron
259 1.1 tron <p>
260 1.1 tron The default poll count is 3.
261 1.1 tron </p>
262 1.1 tron
263 1.1 tron <p>
264 1.1 tron Specify 1 to implement a crude form of greylisting, that is, always
265 1.1 tron defer the first delivery request for a never seen before address.
266 1.1 tron </p>
267 1.1 tron
268 1.1 tron <p>
269 1.1 tron Example:
270 1.1 tron </p>
271 1.1 tron
272 1.1 tron <pre>
273 1.1 tron <a href="postconf.5.html#address_verify_poll_count">address_verify_poll_count</a> = 1
274 1.1 tron </pre>
275 1.1 tron
276 1.1 tron <p>
277 1.1 tron This feature is available in Postfix 2.1 and later.
278 1.1 tron </p>
279 1.1 tron
280 1.1 tron
281 1.1 tron </DD>
282 1.1 tron
283 1.1 tron <DT><b><a name="address_verify_poll_delay">address_verify_poll_delay</a>
284 1.1 tron (default: 3s)</b></DT><DD>
285 1.1 tron
286 1.1 tron <p>
287 1.1 tron The delay between queries for the completion of an address
288 1.1 tron verification request in progress.
289 1.1 tron </p>
290 1.1 tron
291 1.1 tron <p>
292 1.1 tron The default polling delay is 3 seconds.
293 1.1 tron </p>
294 1.1 tron
295 1.1 tron <p>
296 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
297 1.1 tron </p>
298 1.1 tron
299 1.1 tron <p>
300 1.1 tron This feature is available in Postfix 2.1 and later.
301 1.1 tron </p>
302 1.1 tron
303 1.1 tron
304 1.1 tron </DD>
305 1.1 tron
306 1.1 tron <DT><b><a name="address_verify_positive_expire_time">address_verify_positive_expire_time</a>
307 1.1 tron (default: 31d)</b></DT><DD>
308 1.1 tron
309 1.1 tron <p>
310 1.1 tron The time after which a successful probe expires from the address
311 1.1 tron verification cache.
312 1.1 tron </p>
313 1.1 tron
314 1.1 tron <p>
315 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
316 1.1 tron </p>
317 1.1 tron
318 1.1 tron <p>
319 1.1 tron This feature is available in Postfix 2.1 and later.
320 1.1 tron </p>
321 1.1 tron
322 1.1 tron
323 1.1 tron </DD>
324 1.1 tron
325 1.1 tron <DT><b><a name="address_verify_positive_refresh_time">address_verify_positive_refresh_time</a>
326 1.1 tron (default: 7d)</b></DT><DD>
327 1.1 tron
328 1.1 tron <p>
329 1.1 tron The time after which a successful address verification probe needs
330 1.1 tron to be refreshed. The address verification status is not updated
331 1.1 tron when the probe fails (optimistic caching).
332 1.1 tron </p>
333 1.1 tron
334 1.1 tron <p>
335 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
336 1.1 tron </p>
337 1.1 tron
338 1.1 tron <p>
339 1.1 tron This feature is available in Postfix 2.1 and later.
340 1.1 tron </p>
341 1.1 tron
342 1.1 tron
343 1.1 tron </DD>
344 1.1 tron
345 1.1 tron <DT><b><a name="address_verify_relay_transport">address_verify_relay_transport</a>
346 1.1 tron (default: $<a href="postconf.5.html#relay_transport">relay_transport</a>)</b></DT><DD>
347 1.1 tron
348 1.1 tron <p>
349 1.1 tron Overrides the <a href="postconf.5.html#relay_transport">relay_transport</a> parameter setting for address
350 1.1 tron verification probes.
351 1.1 tron </p>
352 1.1 tron
353 1.1 tron <p>
354 1.1 tron This feature is available in Postfix 2.1 and later.
355 1.1 tron </p>
356 1.1 tron
357 1.1 tron
358 1.1 tron </DD>
359 1.1 tron
360 1.1 tron <DT><b><a name="address_verify_relayhost">address_verify_relayhost</a>
361 1.1 tron (default: $<a href="postconf.5.html#relayhost">relayhost</a>)</b></DT><DD>
362 1.1 tron
363 1.1 tron <p>
364 1.1 tron Overrides the <a href="postconf.5.html#relayhost">relayhost</a> parameter setting for address verification
365 1.1 tron probes. This information can be overruled with the <a href="transport.5.html">transport(5)</a> table.
366 1.1 tron </p>
367 1.1 tron
368 1.1 tron <p>
369 1.1 tron This feature is available in Postfix 2.1 and later.
370 1.1 tron </p>
371 1.1 tron
372 1.1 tron
373 1.1 tron </DD>
374 1.1 tron
375 1.1 tron <DT><b><a name="address_verify_sender">address_verify_sender</a>
376 1.1 tron (default: $<a href="postconf.5.html#double_bounce_sender">double_bounce_sender</a>)</b></DT><DD>
377 1.1 tron
378 1.1 tron <p> The sender address to use in address verification probes; prior
379 1.1 tron to Postfix 2.5 the default was "postmaster". To
380 1.1 tron avoid problems with address probes that are sent in response to
381 1.1 tron address probes, the Postfix SMTP server excludes the probe sender
382 1.1 tron address from all SMTPD access blocks. </p>
383 1.1 tron
384 1.1 tron <p>
385 1.1 tron Specify an empty value (<a href="postconf.5.html#address_verify_sender">address_verify_sender</a> =) or <> if you want
386 1.1 tron to use the null sender address. Beware, some sites reject mail from
387 1.1 tron <>, even though RFCs require that such addresses be accepted.
388 1.1 tron </p>
389 1.1 tron
390 1.1 tron <p>
391 1.1 tron Examples:
392 1.1 tron </p>
393 1.1 tron
394 1.1 tron <pre>
395 1.1 tron <a href="postconf.5.html#address_verify_sender">address_verify_sender</a> = <>
396 1.1 tron <a href="postconf.5.html#address_verify_sender">address_verify_sender</a> = postmaster (a] my.domain
397 1.1 tron </pre>
398 1.1 tron
399 1.1 tron <p>
400 1.1 tron This feature is available in Postfix 2.1 and later.
401 1.1 tron </p>
402 1.1 tron
403 1.1 tron
404 1.1 tron </DD>
405 1.1 tron
406 1.1 tron <DT><b><a name="address_verify_sender_dependent_relayhost_maps">address_verify_sender_dependent_relayhost_maps</a>
407 1.1 tron (default: $<a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a>)</b></DT><DD>
408 1.1 tron
409 1.1 tron <p>
410 1.1 tron Overrides the <a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a> parameter setting for address
411 1.1 tron verification probes.
412 1.1 tron </p>
413 1.1 tron
414 1.1 tron <p>
415 1.1 tron This feature is available in Postfix 2.3 and later.
416 1.1 tron </p>
417 1.1 tron
418 1.1 tron
419 1.1 tron </DD>
420 1.1 tron
421 1.1 tron <DT><b><a name="address_verify_service_name">address_verify_service_name</a>
422 1.1 tron (default: verify)</b></DT><DD>
423 1.1 tron
424 1.1 tron <p>
425 1.1 tron The name of the <a href="verify.8.html">verify(8)</a> address verification service. This service
426 1.1 tron maintains the status of sender and/or recipient address verification
427 1.1 tron probes, and generates probes on request by other Postfix processes.
428 1.1 tron </p>
429 1.1 tron
430 1.1 tron
431 1.1 tron </DD>
432 1.1 tron
433 1.1 tron <DT><b><a name="address_verify_transport_maps">address_verify_transport_maps</a>
434 1.1 tron (default: $<a href="postconf.5.html#transport_maps">transport_maps</a>)</b></DT><DD>
435 1.1 tron
436 1.1 tron <p>
437 1.1 tron Overrides the <a href="postconf.5.html#transport_maps">transport_maps</a> parameter setting for address verification
438 1.1 tron probes.
439 1.1 tron </p>
440 1.1 tron
441 1.1 tron <p>
442 1.1 tron This feature is available in Postfix 2.1 and later.
443 1.1 tron </p>
444 1.1 tron
445 1.1 tron
446 1.1 tron </DD>
447 1.1 tron
448 1.1 tron <DT><b><a name="address_verify_virtual_transport">address_verify_virtual_transport</a>
449 1.1 tron (default: $<a href="postconf.5.html#virtual_transport">virtual_transport</a>)</b></DT><DD>
450 1.1 tron
451 1.1 tron <p>
452 1.1 tron Overrides the <a href="postconf.5.html#virtual_transport">virtual_transport</a> parameter setting for address
453 1.1 tron verification probes.
454 1.1 tron </p>
455 1.1 tron
456 1.1 tron <p>
457 1.1 tron This feature is available in Postfix 2.1 and later.
458 1.1 tron </p>
459 1.1 tron
460 1.1 tron
461 1.1 tron </DD>
462 1.1 tron
463 1.1 tron <DT><b><a name="alias_database">alias_database</a>
464 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
465 1.1 tron
466 1.1 tron <p>
467 1.1 tron The alias databases for <a href="local.8.html">local(8)</a> delivery that are updated with
468 1.1 tron "<b>newaliases</b>" or with "<b>sendmail -bi</b>".
469 1.1 tron </p>
470 1.1 tron
471 1.1 tron <p>
472 1.1 tron This is a separate configuration parameter because not all the
473 1.1 tron tables specified with $<a href="postconf.5.html#alias_maps">alias_maps</a> have to be local files.
474 1.1 tron </p>
475 1.1 tron
476 1.1 tron <p>
477 1.1 tron Examples:
478 1.1 tron </p>
479 1.1 tron
480 1.1 tron <pre>
481 1.1 tron <a href="postconf.5.html#alias_database">alias_database</a> = hash:/etc/aliases
482 1.1 tron <a href="postconf.5.html#alias_database">alias_database</a> = hash:/etc/mail/aliases
483 1.1 tron </pre>
484 1.1 tron
485 1.1 tron
486 1.1 tron </DD>
487 1.1 tron
488 1.1 tron <DT><b><a name="alias_maps">alias_maps</a>
489 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
490 1.1 tron
491 1.1 tron <p>
492 1.1 tron The alias databases that are used for <a href="local.8.html">local(8)</a> delivery. See
493 1.1 tron <a href="aliases.5.html">aliases(5)</a> for syntax details.
494 1.1 tron </p>
495 1.1 tron
496 1.1 tron <p>
497 1.1 tron The default list is system dependent. On systems with NIS, the
498 1.1 tron default is to search the local alias database, then the NIS alias
499 1.1 tron database.
500 1.1 tron </p>
501 1.1 tron
502 1.1 tron <p>
503 1.1 tron If you change the alias database, run "<b>postalias /etc/aliases</b>"
504 1.1 tron (or wherever your system stores the mail alias file), or simply
505 1.1 tron run "<b>newaliases</b>" to build the necessary DBM or DB file.
506 1.1 tron </p>
507 1.1 tron
508 1.1 tron <p>
509 1.1 tron The <a href="local.8.html">local(8)</a> delivery agent disallows regular expression substitution
510 1.1 tron of $1 etc. in <a href="postconf.5.html#alias_maps">alias_maps</a>, because that would open a security hole.
511 1.1 tron </p>
512 1.1 tron
513 1.1 tron <p>
514 1.1 tron The <a href="local.8.html">local(8)</a> delivery agent will silently ignore requests to use
515 1.1 tron the <a href="proxymap.8.html">proxymap(8)</a> server within <a href="postconf.5.html#alias_maps">alias_maps</a>. Instead it will open the
516 1.1 tron table directly. Before Postfix version 2.2, the <a href="local.8.html">local(8)</a> delivery
517 1.1 tron agent will terminate with a fatal error.
518 1.1 tron </p>
519 1.1 tron
520 1.1 tron <p>
521 1.1 tron Examples:
522 1.1 tron </p>
523 1.1 tron
524 1.1 tron <pre>
525 1.1 tron <a href="postconf.5.html#alias_maps">alias_maps</a> = hash:/etc/aliases, nis:mail.aliases
526 1.1 tron <a href="postconf.5.html#alias_maps">alias_maps</a> = hash:/etc/aliases
527 1.1 tron </pre>
528 1.1 tron
529 1.1 tron
530 1.1 tron </DD>
531 1.1 tron
532 1.1 tron <DT><b><a name="allow_mail_to_commands">allow_mail_to_commands</a>
533 1.1 tron (default: alias, forward)</b></DT><DD>
534 1.1 tron
535 1.1 tron <p>
536 1.1 tron Restrict <a href="local.8.html">local(8)</a> mail delivery to external commands. The default
537 1.1 tron is to disallow delivery to "|command" in :include: files (see
538 1.1 tron <a href="aliases.5.html">aliases(5)</a> for the text that defines this terminology).
539 1.1 tron </p>
540 1.1 tron
541 1.1 tron <p>
542 1.1 tron Specify zero or more of: <b>alias</b>, <b>forward</b> or <b>include</b>,
543 1.1 tron in order to allow commands in <a href="aliases.5.html">aliases(5)</a>, .forward files or in
544 1.1 tron :include: files, respectively.
545 1.1 tron </p>
546 1.1 tron
547 1.1 tron <p>
548 1.1 tron Example:
549 1.1 tron </p>
550 1.1 tron
551 1.1 tron <pre>
552 1.1 tron <a href="postconf.5.html#allow_mail_to_commands">allow_mail_to_commands</a> = alias,forward,include
553 1.1 tron </pre>
554 1.1 tron
555 1.1 tron
556 1.1 tron </DD>
557 1.1 tron
558 1.1 tron <DT><b><a name="allow_mail_to_files">allow_mail_to_files</a>
559 1.1 tron (default: alias, forward)</b></DT><DD>
560 1.1 tron
561 1.1 tron <p>
562 1.1 tron Restrict <a href="local.8.html">local(8)</a> mail delivery to external files. The default is
563 1.1 tron to disallow "/file/name" destinations in :include: files (see
564 1.1 tron <a href="aliases.5.html">aliases(5)</a> for the text that defines this terminology).
565 1.1 tron </p>
566 1.1 tron
567 1.1 tron <p>
568 1.1 tron Specify zero or more of: <b>alias</b>, <b>forward</b> or <b>include</b>,
569 1.1 tron in order to allow "/file/name" destinations in <a href="aliases.5.html">aliases(5)</a>, .forward
570 1.1 tron files and in :include: files, respectively.
571 1.1 tron </p>
572 1.1 tron
573 1.1 tron <p>
574 1.1 tron Example:
575 1.1 tron </p>
576 1.1 tron
577 1.1 tron <pre>
578 1.1 tron <a href="postconf.5.html#allow_mail_to_files">allow_mail_to_files</a> = alias,forward,include
579 1.1 tron </pre>
580 1.1 tron
581 1.1 tron
582 1.1 tron </DD>
583 1.1 tron
584 1.1 tron <DT><b><a name="allow_min_user">allow_min_user</a>
585 1.1 tron (default: no)</b></DT><DD>
586 1.1 tron
587 1.1 tron <p>
588 1.1 tron Allow a sender or recipient address to have `-' as the first
589 1.1 tron character. By
590 1.1 tron default, this is not allowed, to avoid accidents with software that
591 1.1 tron passes email addresses via the command line. Such software
592 1.1 tron would not be able to distinguish a malicious address from a
593 1.1 tron bona fide command-line option. Although this can be prevented by
594 1.1 tron inserting a "--" option terminator into the command line, this is
595 1.1 tron difficult to enforce consistently and globally. </p>
596 1.1 tron
597 1.1 tron <p> As of Postfix version 2.5, this feature is implemented by
598 1.1 tron <a href="trivial-rewrite.8.html">trivial-rewrite(8)</a>. With earlier versions this feature was implemented
599 1.1 tron by <a href="qmgr.8.html">qmgr(8)</a> and was limited to recipient addresses only. </p>
600 1.1 tron
601 1.1 tron
602 1.1 tron </DD>
603 1.1 tron
604 1.1 tron <DT><b><a name="allow_percent_hack">allow_percent_hack</a>
605 1.1 tron (default: yes)</b></DT><DD>
606 1.1 tron
607 1.1 tron <p>
608 1.1 tron Enable the rewriting of the form "user%domain" to "user@domain".
609 1.1 tron This is enabled by default.
610 1.1 tron </p>
611 1.1 tron
612 1.1 tron <p> Note: with Postfix version 2.2, message header address rewriting
613 1.1 tron happens only when one of the following conditions is true: </p>
614 1.1 tron
615 1.1 tron <ul>
616 1.1 tron
617 1.1 tron <li> The message is received with the Postfix <a href="sendmail.1.html">sendmail(1)</a> command,
618 1.1 tron
619 1.1 tron <li> The message is received from a network client that matches
620 1.1 tron $<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a>,
621 1.1 tron
622 1.1 tron <li> The message is received from the network, and the
623 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> parameter specifies a non-empty value.
624 1.1 tron
625 1.1 tron </ul>
626 1.1 tron
627 1.1 tron <p> To get the behavior before Postfix version 2.2, specify
628 1.1 tron "<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = static:all". </p>
629 1.1 tron
630 1.1 tron <p>
631 1.1 tron Example:
632 1.1 tron </p>
633 1.1 tron
634 1.1 tron <pre>
635 1.1 tron <a href="postconf.5.html#allow_percent_hack">allow_percent_hack</a> = no
636 1.1 tron </pre>
637 1.1 tron
638 1.1 tron
639 1.1 tron </DD>
640 1.1 tron
641 1.1 tron <DT><b><a name="allow_untrusted_routing">allow_untrusted_routing</a>
642 1.1 tron (default: no)</b></DT><DD>
643 1.1 tron
644 1.1 tron <p>
645 1.1 tron Forward mail with sender-specified routing (user[@%!]remote[@%!]site)
646 1.1 tron from untrusted clients to destinations matching $<a href="postconf.5.html#relay_domains">relay_domains</a>.
647 1.1 tron </p>
648 1.1 tron
649 1.1 tron <p>
650 1.1 tron By default, this feature is turned off. This closes a nasty open
651 1.1 tron relay loophole where a backup MX host can be tricked into forwarding
652 1.1 tron junk mail to a primary MX host which then spams it out to the world.
653 1.1 tron </p>
654 1.1 tron
655 1.1 tron <p>
656 1.1 tron This parameter also controls if non-local addresses with sender-specified
657 1.1 tron routing can match Postfix access tables. By default, such addresses
658 1.1 tron cannot match Postfix access tables, because the address is ambiguous.
659 1.1 tron </p>
660 1.1 tron
661 1.1 tron
662 1.1 tron </DD>
663 1.1 tron
664 1.1 tron <DT><b><a name="alternate_config_directories">alternate_config_directories</a>
665 1.1 tron (default: empty)</b></DT><DD>
666 1.1 tron
667 1.1 tron <p>
668 1.1 tron A list of non-default Postfix configuration directories that may
669 1.1 tron be specified with "-c <a href="postconf.5.html#config_directory">config_directory</a>" on the command line, or
670 1.1 tron via the MAIL_CONFIG environment parameter.
671 1.1 tron </p>
672 1.1 tron
673 1.1 tron <p>
674 1.1 tron This list must be specified in the default Postfix configuration
675 1.1 tron directory, and is used by set-gid Postfix commands such as <a href="postqueue.1.html">postqueue(1)</a>
676 1.1 tron and <a href="postdrop.1.html">postdrop(1)</a>.
677 1.1 tron </p>
678 1.1 tron
679 1.1 tron
680 1.1 tron </DD>
681 1.1 tron
682 1.1 tron <DT><b><a name="always_add_missing_headers">always_add_missing_headers</a>
683 1.1 tron (default: no)</b></DT><DD>
684 1.1 tron
685 1.1 tron <p> Always add (Resent-) From:, To:, Date: or Message-ID: headers
686 1.1 tron when not present. Postfix 2.6 and later add these headers only
687 1.1 tron when clients match the <a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> parameter
688 1.1 tron setting. Earlier Postfix versions always add these headers; this
689 1.1 tron may break DKIM signatures that cover non-existent headers. </p>
690 1.1 tron
691 1.1 tron
692 1.1 tron </DD>
693 1.1 tron
694 1.1 tron <DT><b><a name="always_bcc">always_bcc</a>
695 1.1 tron (default: empty)</b></DT><DD>
696 1.1 tron
697 1.1 tron <p>
698 1.1 tron Optional address that receives a "blind carbon copy" of each message
699 1.1 tron that is received by the Postfix mail system.
700 1.1 tron </p>
701 1.1 tron
702 1.1 tron <p>
703 1.1 tron Note: if mail to the BCC address bounces it will be returned to
704 1.1 tron the sender.
705 1.1 tron </p>
706 1.1 tron
707 1.1 tron <p> Note: automatic BCC recipients are produced only for new mail.
708 1.1 tron To avoid mailer loops, automatic BCC recipients are not generated
709 1.1 tron for mail that Postfix forwards internally, nor for mail that Postfix
710 1.1 tron generates itself. </p>
711 1.1 tron
712 1.1 tron
713 1.1 tron </DD>
714 1.1 tron
715 1.1 tron <DT><b><a name="anvil_rate_time_unit">anvil_rate_time_unit</a>
716 1.1 tron (default: 60s)</b></DT><DD>
717 1.1 tron
718 1.1 tron <p>
719 1.1 tron The time unit over which client connection rates and other rates
720 1.1 tron are calculated.
721 1.1 tron </p>
722 1.1 tron
723 1.1 tron <p>
724 1.1 tron This feature is implemented by the <a href="anvil.8.html">anvil(8)</a> service which is available
725 1.1 tron in Postfix version 2.2 and later.
726 1.1 tron </p>
727 1.1 tron
728 1.1 tron <p>
729 1.1 tron The default interval is relatively short. Because of the high
730 1.1 tron frequency of updates, the <a href="anvil.8.html">anvil(8)</a> server uses volatile memory
731 1.1 tron only. Thus, information is lost whenever the process terminates.
732 1.1 tron </p>
733 1.1 tron
734 1.1 tron <p>
735 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
736 1.1 tron The default time unit is s (seconds).
737 1.1 tron </p>
738 1.1 tron
739 1.1 tron
740 1.1 tron </DD>
741 1.1 tron
742 1.1 tron <DT><b><a name="anvil_status_update_time">anvil_status_update_time</a>
743 1.1 tron (default: 600s)</b></DT><DD>
744 1.1 tron
745 1.1 tron <p>
746 1.1 tron How frequently the <a href="anvil.8.html">anvil(8)</a> connection and rate limiting server
747 1.1 tron logs peak usage information.
748 1.1 tron </p>
749 1.1 tron
750 1.1 tron <p>
751 1.1 tron This feature is available in Postfix 2.2 and later.
752 1.1 tron </p>
753 1.1 tron
754 1.1 tron <p>
755 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
756 1.1 tron The default time unit is s (seconds).
757 1.1 tron </p>
758 1.1 tron
759 1.1 tron
760 1.1 tron </DD>
761 1.1 tron
762 1.1 tron <DT><b><a name="append_at_myorigin">append_at_myorigin</a>
763 1.1 tron (default: yes)</b></DT><DD>
764 1.1 tron
765 1.1 tron <p>
766 1.1 tron With locally submitted mail, append the string "@$<a href="postconf.5.html#myorigin">myorigin</a>" to mail
767 1.1 tron addresses without domain information. With remotely submitted mail,
768 1.1 tron append the string "@$<a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a>" instead.
769 1.1 tron </p>
770 1.1 tron
771 1.1 tron <p>
772 1.1 tron Note 1: this feature is enabled by default and must not be turned off.
773 1.1 tron Postfix does not support domain-less addresses.
774 1.1 tron </p>
775 1.1 tron
776 1.1 tron <p> Note 2: with Postfix version 2.2, message header address rewriting
777 1.1 tron happens only when one of the following conditions is true: </p>
778 1.1 tron
779 1.1 tron <ul>
780 1.1 tron
781 1.1 tron <li> The message is received with the Postfix <a href="sendmail.1.html">sendmail(1)</a> command,
782 1.1 tron
783 1.1 tron <li> The message is received from a network client that matches
784 1.1 tron $<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a>,
785 1.1 tron
786 1.1 tron <li> The message is received from the network, and the
787 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> parameter specifies a non-empty value.
788 1.1 tron
789 1.1 tron </ul>
790 1.1 tron
791 1.1 tron <p> To get the behavior before Postfix version 2.2, specify
792 1.1 tron "<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = static:all". </p>
793 1.1 tron
794 1.1 tron
795 1.1 tron </DD>
796 1.1 tron
797 1.1 tron <DT><b><a name="append_dot_mydomain">append_dot_mydomain</a>
798 1.1 tron (default: yes)</b></DT><DD>
799 1.1 tron
800 1.1 tron <p>
801 1.1 tron With locally submitted mail, append the string ".$<a href="postconf.5.html#mydomain">mydomain</a>" to
802 1.1 tron addresses that have no ".domain" information. With remotely submitted
803 1.1 tron mail, append the string ".$<a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a>"
804 1.1 tron instead.
805 1.1 tron </p>
806 1.1 tron
807 1.1 tron <p>
808 1.1 tron Note 1: this feature is enabled by default. If disabled, users will not be
809 1.1 tron able to send mail to "user@partialdomainname" but will have to
810 1.1 tron specify full domain names instead.
811 1.1 tron </p>
812 1.1 tron
813 1.1 tron <p> Note 2: with Postfix version 2.2, message header address rewriting
814 1.1 tron happens only when one of the following conditions is true: </p>
815 1.1 tron
816 1.1 tron <ul>
817 1.1 tron
818 1.1 tron <li> The message is received with the Postfix <a href="sendmail.1.html">sendmail(1)</a> command,
819 1.1 tron
820 1.1 tron <li> The message is received from a network client that matches
821 1.1 tron $<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a>,
822 1.1 tron
823 1.1 tron <li> The message is received from the network, and the
824 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> parameter specifies a non-empty value.
825 1.1 tron
826 1.1 tron </ul>
827 1.1 tron
828 1.1 tron <p> To get the behavior before Postfix version 2.2, specify
829 1.1 tron "<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = static:all". </p>
830 1.1 tron
831 1.1 tron
832 1.1 tron </DD>
833 1.1 tron
834 1.1 tron <DT><b><a name="application_event_drain_time">application_event_drain_time</a>
835 1.1 tron (default: 100s)</b></DT><DD>
836 1.1 tron
837 1.1 tron <p>
838 1.1 tron How long the <a href="postkick.1.html">postkick(1)</a> command waits for a request to enter the
839 1.1 tron server's input buffer before giving up.
840 1.1 tron </p>
841 1.1 tron
842 1.1 tron <p>
843 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
844 1.1 tron The default time unit is s (seconds).
845 1.1 tron </p>
846 1.1 tron
847 1.1 tron <p>
848 1.1 tron This feature is available in Postfix 2.1 and later.
849 1.1 tron </p>
850 1.1 tron
851 1.1 tron
852 1.1 tron </DD>
853 1.1 tron
854 1.1 tron <DT><b><a name="authorized_flush_users">authorized_flush_users</a>
855 1.1 tron (default: static:anyone)</b></DT><DD>
856 1.1 tron
857 1.1 tron <p>
858 1.1 tron List of users who are authorized to flush the queue.
859 1.1 tron </p>
860 1.1 tron
861 1.1 tron <p>
862 1.1 tron By default, all users are allowed to flush the queue. Access is
863 1.1 tron always granted if the invoking user is the super-user or the
864 1.1 tron $<a href="postconf.5.html#mail_owner">mail_owner</a> user. Otherwise, the real UID of the process is looked
865 1.1 tron up in the system password file, and access is granted only if the
866 1.1 tron corresponding login name is on the access list. The username
867 1.1 tron "unknown" is used for processes whose real UID is not found in the
868 1.1 tron password file. </p>
869 1.1 tron
870 1.1 tron <p>
871 1.1 tron Specify a list of user names, "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns,
872 1.1 tron separated by commas and/or whitespace. The list is matched left to
873 1.1 tron right, and the search stops on the first match. A "/file/name"
874 1.1 tron pattern is replaced
875 1.1 tron by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table is matched when a name
876 1.1 tron matches a lookup key (the lookup result is ignored). Continue long
877 1.1 tron lines by starting the next line with whitespace. Specify "!pattern"
878 1.1 tron to exclude a name from the list. The form "!/file/name" is supported
879 1.1 tron only in Postfix version 2.4 and later. </p>
880 1.1 tron
881 1.1 tron <p>
882 1.1 tron This feature is available in Postfix 2.2 and later.
883 1.1 tron </p>
884 1.1 tron
885 1.1 tron
886 1.1 tron </DD>
887 1.1 tron
888 1.1 tron <DT><b><a name="authorized_mailq_users">authorized_mailq_users</a>
889 1.1 tron (default: static:anyone)</b></DT><DD>
890 1.1 tron
891 1.1 tron <p>
892 1.1 tron List of users who are authorized to view the queue.
893 1.1 tron </p>
894 1.1 tron
895 1.1 tron <p>
896 1.1 tron By default, all users are allowed to view the queue. Access is
897 1.1 tron always granted if the invoking user is the super-user or the
898 1.1 tron $<a href="postconf.5.html#mail_owner">mail_owner</a> user. Otherwise, the real UID of the process is looked
899 1.1 tron up in the system password file, and access is granted only if the
900 1.1 tron corresponding login name is on the access list. The username
901 1.1 tron "unknown" is used for processes whose real UID is not found in the
902 1.1 tron password file. </p>
903 1.1 tron
904 1.1 tron <p>
905 1.1 tron Specify a list of user names, "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns,
906 1.1 tron separated by commas and/or whitespace. The list is matched left to
907 1.1 tron right, and the search stops on the first match. A "/file/name"
908 1.1 tron pattern is replaced
909 1.1 tron by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table is matched when a name
910 1.1 tron matches a lookup key (the lookup result is ignored). Continue long
911 1.1 tron lines by starting the next line with whitespace. Specify "!pattern"
912 1.1 tron to exclude a user name from the list. The form "!/file/name" is
913 1.1 tron supported only in Postfix version 2.4 and later. </p>
914 1.1 tron
915 1.1 tron <p>
916 1.1 tron This feature is available in Postfix 2.2 and later.
917 1.1 tron </p>
918 1.1 tron
919 1.1 tron
920 1.1 tron </DD>
921 1.1 tron
922 1.1 tron <DT><b><a name="authorized_submit_users">authorized_submit_users</a>
923 1.1 tron (default: static:anyone)</b></DT><DD>
924 1.1 tron
925 1.1 tron <p>
926 1.1 tron List of users who are authorized to submit mail with the <a href="sendmail.1.html">sendmail(1)</a>
927 1.1 tron command (and with the privileged <a href="postdrop.1.html">postdrop(1)</a> helper command).
928 1.1 tron </p>
929 1.1 tron
930 1.1 tron <p>
931 1.1 tron By default, all users are allowed to submit mail. Otherwise, the
932 1.1 tron real UID of the process is looked up in the system password file,
933 1.1 tron and access is granted only if the corresponding login name is on
934 1.1 tron the access list. The username "unknown" is used for processes
935 1.1 tron whose real UID is not found in the password file. To deny mail
936 1.1 tron submission access to all users specify an empty list. </p>
937 1.1 tron
938 1.1 tron <p>
939 1.1 tron Specify a list of user names, "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns,
940 1.1 tron separated by commas and/or whitespace. The list is matched left to right,
941 1.1 tron and the search stops on the first match. A "/file/name" pattern is
942 1.1 tron replaced by its contents;
943 1.1 tron a "<a href="DATABASE_README.html">type:table</a>" lookup table is matched when a name matches a lookup key
944 1.1 tron (the lookup result is ignored). Continue long lines by starting the
945 1.1 tron next line with whitespace. Specify "!pattern" to exclude a user
946 1.1 tron name from the list. The form "!/file/name" is supported only in
947 1.1 tron Postfix version 2.4 and later. </p>
948 1.1 tron
949 1.1 tron <p>
950 1.1 tron Example:
951 1.1 tron </p>
952 1.1 tron
953 1.1 tron <pre>
954 1.1 tron <a href="postconf.5.html#authorized_submit_users">authorized_submit_users</a> = !www, static:all
955 1.1 tron </pre>
956 1.1 tron
957 1.1 tron <p>
958 1.1 tron This feature is available in Postfix 2.2 and later.
959 1.1 tron </p>
960 1.1 tron
961 1.1 tron
962 1.1 tron </DD>
963 1.1 tron
964 1.1 tron <DT><b><a name="authorized_verp_clients">authorized_verp_clients</a>
965 1.1 tron (default: $<a href="postconf.5.html#mynetworks">mynetworks</a>)</b></DT><DD>
966 1.1 tron
967 1.1 tron <p> What SMTP clients are allowed to specify the XVERP command.
968 1.1 tron This command requests that mail be delivered one recipient at a
969 1.1 tron time with a per recipient return address. </p>
970 1.1 tron
971 1.1 tron <p> By default, only trusted clients are allowed to specify XVERP.
972 1.1 tron </p>
973 1.1 tron
974 1.1 tron <p> This parameter was introduced with Postfix version 1.1. Postfix
975 1.1 tron version 2.1 renamed this parameter to <a href="postconf.5.html#smtpd_authorized_verp_clients">smtpd_authorized_verp_clients</a>
976 1.1 tron and changed the default to none. </p>
977 1.1 tron
978 1.1 tron <p> Specify a list of network/netmask patterns, separated by commas
979 1.1 tron and/or whitespace. The mask specifies the number of bits in the
980 1.1 tron network part of a host address. You can also specify hostnames or
981 1.1 tron .domain names (the initial dot causes the domain to match any name
982 1.1 tron below it), "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns. A "/file/name"
983 1.1 tron pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table
984 1.1 tron is matched when a table entry matches a lookup string (the lookup
985 1.1 tron result is ignored). Continue long lines by starting the next line
986 1.1 tron with whitespace. Specify "!pattern" to exclude an address or network
987 1.1 tron block from the list. The form "!/file/name" is supported only in
988 1.1 tron Postfix version 2.4 and later. </p>
989 1.1 tron
990 1.1 tron <p> Note: IP version 6 address information must be specified inside
991 1.1 tron <tt>[]</tt> in the <a href="postconf.5.html#authorized_verp_clients">authorized_verp_clients</a> value, and in files
992 1.1 tron specified with "/file/name". IP version 6 addresses contain the
993 1.1 tron ":" character, and would otherwise be confused with a "<a href="DATABASE_README.html">type:table</a>"
994 1.1 tron pattern. </p>
995 1.1 tron
996 1.1 tron
997 1.1 tron </DD>
998 1.1 tron
999 1.1 tron <DT><b><a name="backwards_bounce_logfile_compatibility">backwards_bounce_logfile_compatibility</a>
1000 1.1 tron (default: yes)</b></DT><DD>
1001 1.1 tron
1002 1.1 tron <p>
1003 1.1 tron Produce additional <a href="bounce.8.html">bounce(8)</a> logfile records that can be read by
1004 1.1 tron Postfix versions before 2.0. The current and more extensible "name =
1005 1.1 tron value" format is needed in order to implement more sophisticated
1006 1.1 tron functionality.
1007 1.1 tron </p>
1008 1.1 tron
1009 1.1 tron <p>
1010 1.1 tron This feature is available in Postfix 2.1 and later.
1011 1.1 tron </p>
1012 1.1 tron
1013 1.1 tron
1014 1.1 tron </DD>
1015 1.1 tron
1016 1.1 tron <DT><b><a name="berkeley_db_create_buffer_size">berkeley_db_create_buffer_size</a>
1017 1.1 tron (default: 16777216)</b></DT><DD>
1018 1.1 tron
1019 1.1 tron <p>
1020 1.1 tron The per-table I/O buffer size for programs that create Berkeley DB
1021 1.1 tron hash or btree tables. Specify a byte count.
1022 1.1 tron </p>
1023 1.1 tron
1024 1.1 tron <p>
1025 1.1 tron This feature is available in Postfix 2.0 and later.
1026 1.1 tron </p>
1027 1.1 tron
1028 1.1 tron
1029 1.1 tron </DD>
1030 1.1 tron
1031 1.1 tron <DT><b><a name="berkeley_db_read_buffer_size">berkeley_db_read_buffer_size</a>
1032 1.1 tron (default: 131072)</b></DT><DD>
1033 1.1 tron
1034 1.1 tron <p>
1035 1.1 tron The per-table I/O buffer size for programs that read Berkeley DB
1036 1.1 tron hash or btree tables. Specify a byte count.
1037 1.1 tron </p>
1038 1.1 tron
1039 1.1 tron <p>
1040 1.1 tron This feature is available in Postfix 2.0 and later.
1041 1.1 tron </p>
1042 1.1 tron
1043 1.1 tron
1044 1.1 tron </DD>
1045 1.1 tron
1046 1.1 tron <DT><b><a name="best_mx_transport">best_mx_transport</a>
1047 1.1 tron (default: empty)</b></DT><DD>
1048 1.1 tron
1049 1.1 tron <p>
1050 1.1 tron Where the Postfix SMTP client should deliver mail when it detects
1051 1.1 tron a "mail loops back to myself" error condition. This happens when
1052 1.1 tron the local MTA is the best SMTP mail exchanger for a destination
1053 1.1 tron not listed in $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>, $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>,
1054 1.1 tron $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>, or $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>. By default,
1055 1.1 tron the Postfix SMTP client returns such mail as undeliverable.
1056 1.1 tron </p>
1057 1.1 tron
1058 1.1 tron <p>
1059 1.1 tron Specify, for example, "<a href="postconf.5.html#best_mx_transport">best_mx_transport</a> = local" to pass the mail
1060 1.1 tron from the Postfix SMTP client to the <a href="local.8.html">local(8)</a> delivery agent. You
1061 1.1 tron can specify
1062 1.1 tron any message delivery "transport" or "transport:nexthop" that is
1063 1.1 tron defined in the <a href="master.5.html">master.cf</a> file. See the <a href="transport.5.html">transport(5)</a> manual page
1064 1.1 tron for the syntax and meaning of "transport" or "transport:nexthop".
1065 1.1 tron </p>
1066 1.1 tron
1067 1.1 tron <p>
1068 1.1 tron However, this feature is expensive because it ties up a Postfix
1069 1.1 tron SMTP client process while the <a href="local.8.html">local(8)</a> delivery agent is doing its
1070 1.1 tron work. It is more efficient (for Postfix) to list all <a href="VIRTUAL_README.html#canonical">hosted domains</a>
1071 1.1 tron in a table or database.
1072 1.1 tron </p>
1073 1.1 tron
1074 1.1 tron
1075 1.1 tron </DD>
1076 1.1 tron
1077 1.1 tron <DT><b><a name="biff">biff</a>
1078 1.1 tron (default: yes)</b></DT><DD>
1079 1.1 tron
1080 1.1 tron <p>
1081 1.1 tron Whether or not to use the local <a href="postconf.5.html#biff">biff</a> service. This service sends
1082 1.1 tron "new mail" notifications to users who have requested new mail
1083 1.1 tron notification with the UNIX command "<a href="postconf.5.html#biff">biff</a> y".
1084 1.1 tron </p>
1085 1.1 tron
1086 1.1 tron <p>
1087 1.1 tron For compatibility reasons this feature is on by default. On systems
1088 1.1 tron with lots of interactive users, the <a href="postconf.5.html#biff">biff</a> service can be a performance
1089 1.1 tron drain. Specify "<a href="postconf.5.html#biff">biff</a> = no" in <a href="postconf.5.html">main.cf</a> to disable.
1090 1.1 tron </p>
1091 1.1 tron
1092 1.1 tron
1093 1.1 tron </DD>
1094 1.1 tron
1095 1.1 tron <DT><b><a name="body_checks">body_checks</a>
1096 1.1 tron (default: empty)</b></DT><DD>
1097 1.1 tron
1098 1.1 tron <p> Optional lookup tables for content inspection as specified in
1099 1.1 tron the <a href="header_checks.5.html">body_checks(5)</a> manual page. </p>
1100 1.1 tron
1101 1.1 tron <p> Note: with Postfix versions before 2.0, these rules inspect
1102 1.1 tron all content after the primary message headers. </p>
1103 1.1 tron
1104 1.1 tron
1105 1.1 tron </DD>
1106 1.1 tron
1107 1.1 tron <DT><b><a name="body_checks_size_limit">body_checks_size_limit</a>
1108 1.1 tron (default: 51200)</b></DT><DD>
1109 1.1 tron
1110 1.1 tron <p>
1111 1.1 tron How much text in a message body segment (or attachment, if you
1112 1.1 tron prefer to use that term) is subjected to <a href="postconf.5.html#body_checks">body_checks</a> inspection.
1113 1.1 tron The amount of text is limited to avoid scanning huge attachments.
1114 1.1 tron </p>
1115 1.1 tron
1116 1.1 tron <p>
1117 1.1 tron This feature is available in Postfix 2.0 and later.
1118 1.1 tron </p>
1119 1.1 tron
1120 1.1 tron
1121 1.1 tron </DD>
1122 1.1 tron
1123 1.1 tron <DT><b><a name="bounce_notice_recipient">bounce_notice_recipient</a>
1124 1.1 tron (default: postmaster)</b></DT><DD>
1125 1.1 tron
1126 1.1 tron <p>
1127 1.1 tron The recipient of postmaster notifications with the message headers
1128 1.1 tron of mail that Postfix did not deliver and of SMTP conversation
1129 1.1 tron transcripts of mail that Postfix did not receive. This feature is
1130 1.1 tron enabled with the <a href="postconf.5.html#notify_classes">notify_classes</a> parameter. </p>
1131 1.1 tron
1132 1.1 tron
1133 1.1 tron </DD>
1134 1.1 tron
1135 1.1 tron <DT><b><a name="bounce_queue_lifetime">bounce_queue_lifetime</a>
1136 1.1 tron (default: 5d)</b></DT><DD>
1137 1.1 tron
1138 1.1 tron <p>
1139 1.1 tron The maximal time a bounce message is queued before it is considered
1140 1.1 tron undeliverable. By default, this is the same as the queue life time
1141 1.1 tron for regular mail.
1142 1.1 tron </p>
1143 1.1 tron
1144 1.1 tron <p>
1145 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
1146 1.1 tron The default time unit is d (days).
1147 1.1 tron </p>
1148 1.1 tron
1149 1.1 tron <p>
1150 1.1 tron Specify 0 when mail delivery should be tried only once.
1151 1.1 tron </p>
1152 1.1 tron
1153 1.1 tron <p>
1154 1.1 tron This feature is available in Postfix 2.1 and later.
1155 1.1 tron </p>
1156 1.1 tron
1157 1.1 tron
1158 1.1 tron </DD>
1159 1.1 tron
1160 1.1 tron <DT><b><a name="bounce_service_name">bounce_service_name</a>
1161 1.1 tron (default: bounce)</b></DT><DD>
1162 1.1 tron
1163 1.1 tron <p>
1164 1.1 tron The name of the <a href="bounce.8.html">bounce(8)</a> service. This service maintains a record
1165 1.1 tron of failed delivery attempts and generates non-delivery notifications.
1166 1.1 tron </p>
1167 1.1 tron
1168 1.1 tron <p>
1169 1.1 tron This feature is available in Postfix 2.0 and later.
1170 1.1 tron </p>
1171 1.1 tron
1172 1.1 tron
1173 1.1 tron </DD>
1174 1.1 tron
1175 1.1 tron <DT><b><a name="bounce_size_limit">bounce_size_limit</a>
1176 1.1 tron (default: 50000)</b></DT><DD>
1177 1.1 tron
1178 1.1 tron <p> The maximal amount of original message text that is sent in a
1179 1.1 tron non-delivery notification. Specify a byte count. With Postfix 2.4
1180 1.1 tron and later, a message is returned as either message/rfc822 (the
1181 1.1 tron complete original) or as text/rfc822-headers (the headers only).
1182 1.1 tron With earlier Postfix versions, a message is always returned as
1183 1.1 tron message/rfc822 and is truncated when it exceeds the size limit.
1184 1.1 tron </p>
1185 1.1 tron
1186 1.1 tron <p> Notes: </p>
1187 1.1 tron
1188 1.1 tron <ul>
1189 1.1 tron
1190 1.1 tron <li> <p> If you increase this limit, then you should increase the
1191 1.1 tron <a href="postconf.5.html#mime_nesting_limit">mime_nesting_limit</a> value proportionally. </p>
1192 1.1 tron
1193 1.1 tron <li> <p> Be careful when making changes. Excessively large values
1194 1.1 tron will result in the loss of non-delivery notifications, when a bounce
1195 1.1 tron message size exceeds a local or remote MTA's message size limit.
1196 1.1 tron </p>
1197 1.1 tron
1198 1.1 tron </ul>
1199 1.1 tron
1200 1.1 tron
1201 1.1 tron </DD>
1202 1.1 tron
1203 1.1 tron <DT><b><a name="bounce_template_file">bounce_template_file</a>
1204 1.1 tron (default: empty)</b></DT><DD>
1205 1.1 tron
1206 1.1 tron <p> Pathname of a configuration file with bounce message templates.
1207 1.1 tron These override the built-in templates of delivery status notification
1208 1.1 tron (DSN) messages for undeliverable mail, for delayed mail, successful
1209 1.1 tron delivery, or delivery verification. The <a href="bounce.5.html">bounce(5)</a> manual page
1210 1.1 tron describes how to edit and test template files. </p>
1211 1.1 tron
1212 1.1 tron <p> Template message body text may contain $name references to
1213 1.1 tron Postfix configuration parameters. The result of $name expansion can
1214 1.1 tron be previewed with "<b>postconf -b <i>file_name</i></b>" before the file
1215 1.1 tron is placed into the Postfix configuration directory. </p>
1216 1.1 tron
1217 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
1218 1.1 tron
1219 1.1 tron
1220 1.1 tron </DD>
1221 1.1 tron
1222 1.1 tron <DT><b><a name="broken_sasl_auth_clients">broken_sasl_auth_clients</a>
1223 1.1 tron (default: no)</b></DT><DD>
1224 1.1 tron
1225 1.1 tron <p>
1226 1.1 tron Enable inter-operability with SMTP clients that implement an obsolete
1227 1.1 tron version of the AUTH command (<a href="http://tools.ietf.org/html/rfc4954">RFC 4954</a>). Examples of such clients
1228 1.1 tron are MicroSoft Outlook Express version 4 and MicroSoft Exchange
1229 1.1 tron version 5.0.
1230 1.1 tron </p>
1231 1.1 tron
1232 1.1 tron <p>
1233 1.1 tron Specify "<a href="postconf.5.html#broken_sasl_auth_clients">broken_sasl_auth_clients</a> = yes" to have Postfix advertise
1234 1.1 tron AUTH support in a non-standard way.
1235 1.1 tron </p>
1236 1.1 tron
1237 1.1 tron
1238 1.1 tron </DD>
1239 1.1 tron
1240 1.1 tron <DT><b><a name="canonical_classes">canonical_classes</a>
1241 1.1 tron (default: envelope_sender, envelope_recipient, header_sender, header_recipient)</b></DT><DD>
1242 1.1 tron
1243 1.1 tron <p> What addresses are subject to <a href="postconf.5.html#canonical_maps">canonical_maps</a> address mapping.
1244 1.1 tron By default, <a href="postconf.5.html#canonical_maps">canonical_maps</a> address mapping is applied to envelope
1245 1.1 tron sender and recipient addresses, and to header sender and header
1246 1.1 tron recipient addresses. </p>
1247 1.1 tron
1248 1.1 tron <p> Specify one or more of: envelope_sender, envelope_recipient,
1249 1.1 tron header_sender, header_recipient </p>
1250 1.1 tron
1251 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
1252 1.1 tron
1253 1.1 tron
1254 1.1 tron </DD>
1255 1.1 tron
1256 1.1 tron <DT><b><a name="canonical_maps">canonical_maps</a>
1257 1.1 tron (default: empty)</b></DT><DD>
1258 1.1 tron
1259 1.1 tron <p>
1260 1.1 tron Optional address mapping lookup tables for message headers and
1261 1.1 tron envelopes. The mapping is applied to both sender and recipient
1262 1.1 tron addresses, in both envelopes and in headers, as controlled
1263 1.1 tron with the <a href="postconf.5.html#canonical_classes">canonical_classes</a> parameter. This is typically used
1264 1.1 tron to clean up dirty addresses from legacy mail systems, or to replace
1265 1.1 tron login names by Firstname.Lastname. The table format and lookups
1266 1.1 tron are documented in <a href="canonical.5.html">canonical(5)</a>. For an overview of Postfix address
1267 1.1 tron manipulations see the <a href="ADDRESS_REWRITING_README.html">ADDRESS_REWRITING_README</a> document.
1268 1.1 tron </p>
1269 1.1 tron
1270 1.1 tron <p>
1271 1.1 tron If you use this feature, run "<b>postmap /etc/postfix/canonical</b>" to
1272 1.1 tron build the necessary DBM or DB file after every change. The changes
1273 1.1 tron will become visible after a minute or so. Use "<b>postfix reload</b>"
1274 1.1 tron to eliminate the delay.
1275 1.1 tron </p>
1276 1.1 tron
1277 1.1 tron <p> Note: with Postfix version 2.2, message header address mapping
1278 1.1 tron happens only when message header address rewriting is enabled: </p>
1279 1.1 tron
1280 1.1 tron <ul>
1281 1.1 tron
1282 1.1 tron <li> The message is received with the Postfix <a href="sendmail.1.html">sendmail(1)</a> command,
1283 1.1 tron
1284 1.1 tron <li> The message is received from a network client that matches
1285 1.1 tron $<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a>,
1286 1.1 tron
1287 1.1 tron <li> The message is received from the network, and the
1288 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> parameter specifies a non-empty value.
1289 1.1 tron
1290 1.1 tron </ul>
1291 1.1 tron
1292 1.1 tron <p> To get the behavior before Postfix version 2.2, specify
1293 1.1 tron "<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = static:all". </p>
1294 1.1 tron
1295 1.1 tron <p>
1296 1.1 tron Examples:
1297 1.1 tron </p>
1298 1.1 tron
1299 1.1 tron <pre>
1300 1.1 tron <a href="postconf.5.html#canonical_maps">canonical_maps</a> = dbm:/etc/postfix/canonical
1301 1.1 tron <a href="postconf.5.html#canonical_maps">canonical_maps</a> = hash:/etc/postfix/canonical
1302 1.1 tron </pre>
1303 1.1 tron
1304 1.1 tron
1305 1.1 tron </DD>
1306 1.1 tron
1307 1.1 tron <DT><b><a name="cleanup_service_name">cleanup_service_name</a>
1308 1.1 tron (default: cleanup)</b></DT><DD>
1309 1.1 tron
1310 1.1 tron <p>
1311 1.1 tron The name of the <a href="cleanup.8.html">cleanup(8)</a> service. This service rewrites addresses
1312 1.1 tron into the standard form, and performs <a href="canonical.5.html">canonical(5)</a> address mapping
1313 1.1 tron and <a href="virtual.5.html">virtual(5)</a> aliasing.
1314 1.1 tron </p>
1315 1.1 tron
1316 1.1 tron <p>
1317 1.1 tron This feature is available in Postfix 2.0 and later.
1318 1.1 tron </p>
1319 1.1 tron
1320 1.1 tron
1321 1.1 tron </DD>
1322 1.1 tron
1323 1.1 tron <DT><b><a name="command_directory">command_directory</a>
1324 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
1325 1.1 tron
1326 1.1 tron <p>
1327 1.1 tron The location of all postfix administrative commands.
1328 1.1 tron </p>
1329 1.1 tron
1330 1.1 tron
1331 1.1 tron </DD>
1332 1.1 tron
1333 1.1 tron <DT><b><a name="command_execution_directory">command_execution_directory</a>
1334 1.1 tron (default: empty)</b></DT><DD>
1335 1.1 tron
1336 1.1 tron <p> The <a href="local.8.html">local(8)</a> delivery agent working directory for delivery to
1337 1.1 tron external command. Failure to change directory causes the delivery
1338 1.1 tron to be deferred. </p>
1339 1.1 tron
1340 1.1 tron <p> The following $name expansions are done on <a href="postconf.5.html#command_execution_directory">command_execution_directory</a>
1341 1.1 tron before the directory is changed. Expansion happens in the context
1342 1.1 tron of the delivery request. The result of $name expansion is filtered
1343 1.1 tron with the character set that is specified with the
1344 1.1 tron <a href="postconf.5.html#execution_directory_expansion_filter">execution_directory_expansion_filter</a> parameter. </p>
1345 1.1 tron
1346 1.1 tron <dl>
1347 1.1 tron
1348 1.1 tron <dt><b>$user</b></dt>
1349 1.1 tron
1350 1.1 tron <dd>The recipient's username. </dd>
1351 1.1 tron
1352 1.1 tron <dt><b>$shell</b></dt>
1353 1.1 tron
1354 1.1 tron <dd>The recipient's login shell pathname. </dd>
1355 1.1 tron
1356 1.1 tron <dt><b>$home</b></dt>
1357 1.1 tron
1358 1.1 tron <dd>The recipient's home directory. </dd>
1359 1.1 tron
1360 1.1 tron <dt><b>$recipient</b></dt>
1361 1.1 tron
1362 1.1 tron <dd>The full recipient address. </dd>
1363 1.1 tron
1364 1.1 tron <dt><b>$extension</b></dt>
1365 1.1 tron
1366 1.1 tron <dd>The optional recipient address extension. </dd>
1367 1.1 tron
1368 1.1 tron <dt><b>$domain</b></dt>
1369 1.1 tron
1370 1.1 tron <dd>The recipient domain. </dd>
1371 1.1 tron
1372 1.1 tron <dt><b>$local</b></dt>
1373 1.1 tron
1374 1.1 tron <dd>The entire recipient localpart. </dd>
1375 1.1 tron
1376 1.1 tron <dt><b>$<a href="postconf.5.html#recipient_delimiter">recipient_delimiter</a></b></dt>
1377 1.1 tron
1378 1.1 tron <dd>The system-wide recipient address extension delimiter. </dd>
1379 1.1 tron
1380 1.1 tron <dt><b>${name?value}</b></dt>
1381 1.1 tron
1382 1.1 tron <dd>Expands to <i>value</i> when <i>$name</i> is non-empty. </dd>
1383 1.1 tron
1384 1.1 tron <dt><b>${name:value}</b></dt>
1385 1.1 tron
1386 1.1 tron <dd>Expands to <i>value</i> when <i>$name</i> is empty. </dd>
1387 1.1 tron
1388 1.1 tron </dl>
1389 1.1 tron
1390 1.1 tron <p>
1391 1.1 tron Instead of $name you can also specify ${name} or $(name).
1392 1.1 tron </p>
1393 1.1 tron
1394 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
1395 1.1 tron
1396 1.1 tron
1397 1.1 tron </DD>
1398 1.1 tron
1399 1.1 tron <DT><b><a name="command_expansion_filter">command_expansion_filter</a>
1400 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
1401 1.1 tron
1402 1.1 tron <p>
1403 1.1 tron Restrict the characters that the <a href="local.8.html">local(8)</a> delivery agent allows in
1404 1.1 tron $name expansions of $<a href="postconf.5.html#mailbox_command">mailbox_command</a> and $<a href="postconf.5.html#command_execution_directory">command_execution_directory</a>.
1405 1.1 tron Characters outside the
1406 1.1 tron allowed set are replaced by underscores.
1407 1.1 tron </p>
1408 1.1 tron
1409 1.1 tron
1410 1.1 tron </DD>
1411 1.1 tron
1412 1.1 tron <DT><b><a name="command_time_limit">command_time_limit</a>
1413 1.1 tron (default: 1000s)</b></DT><DD>
1414 1.1 tron
1415 1.1 tron <p>
1416 1.1 tron Time limit for delivery to external commands. This limit is used
1417 1.1 tron by the <a href="local.8.html">local(8)</a> delivery agent, and is the default time limit for
1418 1.1 tron delivery by the <a href="pipe.8.html">pipe(8)</a> delivery agent.
1419 1.1 tron </p>
1420 1.1 tron
1421 1.1 tron <p>
1422 1.1 tron Note: if you set this time limit to a large value you must update the
1423 1.1 tron global <a href="postconf.5.html#ipc_timeout">ipc_timeout</a> parameter as well.
1424 1.1 tron </p>
1425 1.1 tron
1426 1.1 tron
1427 1.1 tron </DD>
1428 1.1 tron
1429 1.1 tron <DT><b><a name="config_directory">config_directory</a>
1430 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
1431 1.1 tron
1432 1.1 tron <p> The default location of the Postfix <a href="postconf.5.html">main.cf</a> and <a href="master.5.html">master.cf</a>
1433 1.1 tron configuration files. This can be overruled via the following
1434 1.1 tron mechanisms: </p>
1435 1.1 tron
1436 1.1 tron <ul>
1437 1.1 tron
1438 1.1 tron <li> <p> The MAIL_CONFIG environment variable (daemon processes
1439 1.1 tron and commands). </p>
1440 1.1 tron
1441 1.1 tron <li> <p> The "-c" command-line option (commands only). </p>
1442 1.1 tron
1443 1.1 tron </ul>
1444 1.1 tron
1445 1.1 tron <p> With Postfix command that run with set-gid privileges, a
1446 1.1 tron <a href="postconf.5.html#config_directory">config_directory</a> override requires either root privileges, or it
1447 1.1 tron requires that the directory is listed with the <a href="postconf.5.html#alternate_config_directories">alternate_config_directories</a>
1448 1.1 tron parameter in the default <a href="postconf.5.html">main.cf</a> file. </p>
1449 1.1 tron
1450 1.1 tron
1451 1.1 tron </DD>
1452 1.1 tron
1453 1.1 tron <DT><b><a name="connection_cache_protocol_timeout">connection_cache_protocol_timeout</a>
1454 1.1 tron (default: 5s)</b></DT><DD>
1455 1.1 tron
1456 1.1 tron <p> Time limit for connection cache connect, send or receive
1457 1.1 tron operations. The time limit is enforced in the client. </p>
1458 1.1 tron
1459 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
1460 1.1 tron
1461 1.1 tron
1462 1.1 tron </DD>
1463 1.1 tron
1464 1.1 tron <DT><b><a name="connection_cache_service_name">connection_cache_service_name</a>
1465 1.1 tron (default: scache)</b></DT><DD>
1466 1.1 tron
1467 1.1 tron <p> The name of the <a href="scache.8.html">scache(8)</a> connection cache service. This service
1468 1.1 tron maintains a limited pool of cached sessions. </p>
1469 1.1 tron
1470 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
1471 1.1 tron
1472 1.1 tron
1473 1.1 tron </DD>
1474 1.1 tron
1475 1.1 tron <DT><b><a name="connection_cache_status_update_time">connection_cache_status_update_time</a>
1476 1.1 tron (default: 600s)</b></DT><DD>
1477 1.1 tron
1478 1.1 tron <p> How frequently the <a href="scache.8.html">scache(8)</a> server logs usage statistics with
1479 1.1 tron connection cache hit and miss rates for logical destinations and for
1480 1.1 tron physical endpoints. </p>
1481 1.1 tron
1482 1.1 tron
1483 1.1 tron </DD>
1484 1.1 tron
1485 1.1 tron <DT><b><a name="connection_cache_ttl_limit">connection_cache_ttl_limit</a>
1486 1.1 tron (default: 2s)</b></DT><DD>
1487 1.1 tron
1488 1.1 tron <p> The maximal time-to-live value that the <a href="scache.8.html">scache(8)</a> connection
1489 1.1 tron cache server
1490 1.1 tron allows. Requests that specify a larger TTL will be stored with the
1491 1.1 tron maximum allowed TTL. The purpose of this additional control is to
1492 1.1 tron protect the infrastructure against careless people. The cache TTL
1493 1.1 tron is already bounded by $<a href="postconf.5.html#max_idle">max_idle</a>. </p>
1494 1.1 tron
1495 1.1 tron
1496 1.1 tron </DD>
1497 1.1 tron
1498 1.1 tron <DT><b><a name="content_filter">content_filter</a>
1499 1.1 tron (default: empty)</b></DT><DD>
1500 1.1 tron
1501 1.1 tron <p>
1502 1.1 tron The name of a mail delivery transport that filters mail after
1503 1.1 tron it is queued.
1504 1.1 tron </p>
1505 1.1 tron
1506 1.1 tron <p>
1507 1.1 tron This parameter uses the same syntax as the right-hand side of a
1508 1.1 tron Postfix <a href="transport.5.html">transport(5)</a> table. This setting has a lower precedence
1509 1.1 tron than a content filter that is specified with an <a href="access.5.html">access(5)</a> table or
1510 1.1 tron in a <a href="header_checks.5.html">header_checks(5)</a> or <a href="header_checks.5.html">body_checks(5)</a> table.
1511 1.1 tron </p>
1512 1.1 tron
1513 1.1 tron
1514 1.1 tron </DD>
1515 1.1 tron
1516 1.1 tron <DT><b><a name="cyrus_sasl_config_path">cyrus_sasl_config_path</a>
1517 1.1 tron (default: empty)</b></DT><DD>
1518 1.1 tron
1519 1.1 tron <p> Search path for Cyrus SASL application configuration files,
1520 1.1 tron currently used only to locate the $<a href="postconf.5.html#smtpd_sasl_path">smtpd_sasl_path</a>.conf file.
1521 1.1 tron Specify zero or more directories separated by a colon character,
1522 1.1 tron or an empty value to use Cyrus SASL's built-in search path. </p>
1523 1.1 tron
1524 1.1 tron <p> This feature is available in Postfix 2.5 and later when compiled
1525 1.1 tron with Cyrus SASL 2.1.22 or later. </p>
1526 1.1 tron
1527 1.1 tron
1528 1.1 tron </DD>
1529 1.1 tron
1530 1.1 tron <DT><b><a name="daemon_directory">daemon_directory</a>
1531 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
1532 1.1 tron
1533 1.1 tron <p>
1534 1.1 tron The directory with Postfix support programs and daemon programs.
1535 1.1 tron These should not be invoked directly by humans. The directory must
1536 1.1 tron be owned by root.
1537 1.1 tron </p>
1538 1.1 tron
1539 1.1 tron
1540 1.1 tron </DD>
1541 1.1 tron
1542 1.1 tron <DT><b><a name="daemon_timeout">daemon_timeout</a>
1543 1.1 tron (default: 18000s)</b></DT><DD>
1544 1.1 tron
1545 1.1 tron <p> How much time a Postfix daemon process may take to handle a
1546 1.1 tron request before it is terminated by a built-in watchdog timer. </p>
1547 1.1 tron
1548 1.1 tron <p>
1549 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
1550 1.1 tron The default time unit is s (seconds).
1551 1.1 tron </p>
1552 1.1 tron
1553 1.1 tron
1554 1.1 tron </DD>
1555 1.1 tron
1556 1.1 tron <DT><b><a name="data_directory">data_directory</a>
1557 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
1558 1.1 tron
1559 1.1 tron <p> The directory with Postfix-writable data files (for example:
1560 1.1 tron caches, pseudo-random numbers). This directory must be owned by
1561 1.1 tron the <a href="postconf.5.html#mail_owner">mail_owner</a> account, and must not be shared with non-Postfix
1562 1.1 tron software. </p>
1563 1.1 tron
1564 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
1565 1.1 tron
1566 1.1 tron
1567 1.1 tron </DD>
1568 1.1 tron
1569 1.1 tron <DT><b><a name="debug_peer_level">debug_peer_level</a>
1570 1.1 tron (default: 2)</b></DT><DD>
1571 1.1 tron
1572 1.1 tron <p> The increment in verbose logging level when a remote client or
1573 1.1 tron server matches a pattern in the <a href="postconf.5.html#debug_peer_list">debug_peer_list</a> parameter. </p>
1574 1.1 tron
1575 1.1 tron
1576 1.1 tron </DD>
1577 1.1 tron
1578 1.1 tron <DT><b><a name="debug_peer_list">debug_peer_list</a>
1579 1.1 tron (default: empty)</b></DT><DD>
1580 1.1 tron
1581 1.1 tron <p> Optional list of remote client or server hostname or network
1582 1.1 tron address patterns that cause the verbose logging level to increase
1583 1.1 tron by the amount specified in $<a href="postconf.5.html#debug_peer_level">debug_peer_level</a>. </p>
1584 1.1 tron
1585 1.1 tron <p> Specify domain names, network/netmask patterns, "/file/name"
1586 1.1 tron patterns or "<a href="DATABASE_README.html">type:table</a>" lookup tables. The right-hand side result
1587 1.1 tron from "<a href="DATABASE_README.html">type:table</a>" lookups is ignored. </p>
1588 1.1 tron
1589 1.1 tron <p> Pattern matching of domain names is controlled by the
1590 1.1 tron <a href="postconf.5.html#parent_domain_matches_subdomains">parent_domain_matches_subdomains</a> parameter. </p>
1591 1.1 tron
1592 1.1 tron <p>
1593 1.1 tron Examples:
1594 1.1 tron </p>
1595 1.1 tron
1596 1.1 tron <pre>
1597 1.1 tron <a href="postconf.5.html#debug_peer_list">debug_peer_list</a> = 127.0.0.1
1598 1.1 tron <a href="postconf.5.html#debug_peer_list">debug_peer_list</a> = example.com
1599 1.1 tron </pre>
1600 1.1 tron
1601 1.1 tron
1602 1.1 tron </DD>
1603 1.1 tron
1604 1.1 tron <DT><b><a name="debugger_command">debugger_command</a>
1605 1.1 tron (default: empty)</b></DT><DD>
1606 1.1 tron
1607 1.1 tron <p>
1608 1.1 tron The external command to execute when a Postfix daemon program is
1609 1.1 tron invoked with the -D option.
1610 1.1 tron </p>
1611 1.1 tron
1612 1.1 tron <p>
1613 1.1 tron Use "command .. & sleep 5" so that the debugger can attach before
1614 1.1 tron the process marches on. If you use an X-based debugger, be sure to
1615 1.1 tron set up your XAUTHORITY environment variable before starting Postfix.
1616 1.1 tron </p>
1617 1.1 tron
1618 1.1 tron <p>
1619 1.1 tron Example:
1620 1.1 tron </p>
1621 1.1 tron
1622 1.1 tron <pre>
1623 1.1 tron <a href="postconf.5.html#debugger_command">debugger_command</a> =
1624 1.1 tron PATH=/usr/bin:/usr/X11R6/bin
1625 1.1 tron ddd $<a href="postconf.5.html#daemon_directory">daemon_directory</a>/$<a href="postconf.5.html#process_name">process_name</a> $<a href="postconf.5.html#process_id">process_id</a> & sleep 5
1626 1.1 tron </pre>
1627 1.1 tron
1628 1.1 tron
1629 1.1 tron </DD>
1630 1.1 tron
1631 1.1 tron <DT><b><a name="default_database_type">default_database_type</a>
1632 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
1633 1.1 tron
1634 1.1 tron <p>
1635 1.1 tron The default database type for use in <a href="newaliases.1.html">newaliases(1)</a>, <a href="postalias.1.html">postalias(1)</a>
1636 1.1 tron and <a href="postmap.1.html">postmap(1)</a> commands. On many UNIX systems the default type is
1637 1.1 tron either <b>dbm</b> or <b>hash</b>. The default setting is frozen
1638 1.1 tron when the Postfix system is built.
1639 1.1 tron </p>
1640 1.1 tron
1641 1.1 tron <p>
1642 1.1 tron Examples:
1643 1.1 tron </p>
1644 1.1 tron
1645 1.1 tron <pre>
1646 1.1 tron <a href="postconf.5.html#default_database_type">default_database_type</a> = hash
1647 1.1 tron <a href="postconf.5.html#default_database_type">default_database_type</a> = dbm
1648 1.1 tron </pre>
1649 1.1 tron
1650 1.1 tron
1651 1.1 tron </DD>
1652 1.1 tron
1653 1.1 tron <DT><b><a name="default_delivery_slot_cost">default_delivery_slot_cost</a>
1654 1.1 tron (default: 5)</b></DT><DD>
1655 1.1 tron
1656 1.1 tron <p>
1657 1.1 tron How often the Postfix queue manager's scheduler is allowed to
1658 1.1 tron preempt delivery of one message with another.
1659 1.1 tron </p>
1660 1.1 tron
1661 1.1 tron <p>
1662 1.1 tron Each transport maintains a so-called "available delivery slot counter"
1663 1.1 tron for each message. One message can be preempted by another one when
1664 1.1 tron the other message can be delivered using no more delivery slots
1665 1.1 tron (i.e., invocations of delivery agents) than the current message
1666 1.1 tron counter has accumulated (or will eventually accumulate - see about
1667 1.1 tron slot loans below). This parameter controls how often is the counter
1668 1.1 tron incremented - it happens after each <a href="postconf.5.html#default_delivery_slot_cost">default_delivery_slot_cost</a>
1669 1.1 tron recipients have been delivered.
1670 1.1 tron </p>
1671 1.1 tron
1672 1.1 tron <p>
1673 1.1 tron The cost of 0 is used to disable the preempting scheduling completely.
1674 1.1 tron The minimum value the scheduling algorithm can use is 2 - use it
1675 1.1 tron if you want to maximize the message throughput rate. Although there
1676 1.1 tron is no maximum, it doesn't make much sense to use values above say
1677 1.1 tron 50.
1678 1.1 tron </p>
1679 1.1 tron
1680 1.1 tron <p>
1681 1.1 tron The only reason why the value of 2 is not the default is the way
1682 1.1 tron this parameter affects the delivery of mailing-list mail. In the
1683 1.1 tron worst case, their delivery can take somewhere between (cost+1/cost)
1684 1.1 tron and (cost/cost-1) times more than if the preemptive scheduler was
1685 1.1 tron disabled. The default value of 5 turns out to provide reasonable
1686 1.1 tron message response times while making sure the mailing-list deliveries
1687 1.1 tron are not extended by more than 20-25 percent even in the worst case.
1688 1.1 tron </p>
1689 1.1 tron
1690 1.1 tron <p> Use <a href="postconf.5.html#transport_delivery_slot_cost"><i>transport</i>_delivery_slot_cost</a> to specify a
1691 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1692 1.1 tron name of the message delivery transport.
1693 1.1 tron </p>
1694 1.1 tron
1695 1.1 tron <p>
1696 1.1 tron Examples:
1697 1.1 tron </p>
1698 1.1 tron
1699 1.1 tron <pre>
1700 1.1 tron <a href="postconf.5.html#default_delivery_slot_cost">default_delivery_slot_cost</a> = 0
1701 1.1 tron <a href="postconf.5.html#default_delivery_slot_cost">default_delivery_slot_cost</a> = 2
1702 1.1 tron </pre>
1703 1.1 tron
1704 1.1 tron
1705 1.1 tron </DD>
1706 1.1 tron
1707 1.1 tron <DT><b><a name="default_delivery_slot_discount">default_delivery_slot_discount</a>
1708 1.1 tron (default: 50)</b></DT><DD>
1709 1.1 tron
1710 1.1 tron <p>
1711 1.1 tron The default value for transport-specific _delivery_slot_discount
1712 1.1 tron settings.
1713 1.1 tron </p>
1714 1.1 tron
1715 1.1 tron <p>
1716 1.1 tron This parameter speeds up the moment when a message preemption can
1717 1.1 tron happen. Instead of waiting until the full amount of delivery slots
1718 1.1 tron required is available, the preemption can happen when
1719 1.1 tron transport_delivery_slot_discount percent of the required amount
1720 1.1 tron plus transport_delivery_slot_loan still remains to be accumulated.
1721 1.1 tron Note that the full amount will still have to be accumulated before
1722 1.1 tron another preemption can take place later.
1723 1.1 tron </p>
1724 1.1 tron
1725 1.1 tron <p> Use <a href="postconf.5.html#transport_delivery_slot_discount"><i>transport</i>_delivery_slot_discount</a> to specify a
1726 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1727 1.1 tron name of the message delivery transport.
1728 1.1 tron </p>
1729 1.1 tron
1730 1.1 tron
1731 1.1 tron </DD>
1732 1.1 tron
1733 1.1 tron <DT><b><a name="default_delivery_slot_loan">default_delivery_slot_loan</a>
1734 1.1 tron (default: 3)</b></DT><DD>
1735 1.1 tron
1736 1.1 tron <p>
1737 1.1 tron The default value for transport-specific _delivery_slot_loan
1738 1.1 tron settings.
1739 1.1 tron </p>
1740 1.1 tron
1741 1.1 tron <p>
1742 1.1 tron This parameter speeds up the moment when a message preemption can
1743 1.1 tron happen. Instead of waiting until the full amount of delivery slots
1744 1.1 tron required is available, the preemption can happen when
1745 1.1 tron transport_delivery_slot_discount percent of the required amount
1746 1.1 tron plus transport_delivery_slot_loan still remains to be accumulated.
1747 1.1 tron Note that the full amount will still have to be accumulated before
1748 1.1 tron another preemption can take place later.
1749 1.1 tron </p>
1750 1.1 tron
1751 1.1 tron <p> Use <a href="postconf.5.html#transport_delivery_slot_loan"><i>transport</i>_delivery_slot_loan</a> to specify a
1752 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1753 1.1 tron name of the message delivery transport.
1754 1.1 tron </p>
1755 1.1 tron
1756 1.1 tron
1757 1.1 tron </DD>
1758 1.1 tron
1759 1.1 tron <DT><b><a name="default_destination_concurrency_failed_cohort_limit">default_destination_concurrency_failed_cohort_limit</a>
1760 1.1 tron (default: 1)</b></DT><DD>
1761 1.1 tron
1762 1.1 tron <p> How many pseudo-cohorts must suffer connection or handshake
1763 1.1 tron failure before a specific destination is considered unavailable
1764 1.1 tron (and further delivery is suspended). Specify zero to disable this
1765 1.1 tron feature. A destination's pseudo-cohort failure count is reset each
1766 1.1 tron time a delivery completes without connection or handshake failure
1767 1.1 tron for that specific destination. </p>
1768 1.1 tron
1769 1.1 tron <p> A pseudo-cohort is the number of deliveries equal to a destination's
1770 1.1 tron delivery concurrency. </p>
1771 1.1 tron
1772 1.1 tron <p> Use <a href="postconf.5.html#transport_destination_concurrency_failed_cohort_limit"><i>transport</i>_destination_concurrency_failed_cohort_limit</a> to specify
1773 1.1 tron a transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1774 1.1 tron name of the message delivery transport. </p>
1775 1.1 tron
1776 1.1 tron <p> This feature is available in Postfix 2.5. The default setting
1777 1.1 tron is compatible with earlier Postfix versions. </p>
1778 1.1 tron
1779 1.1 tron
1780 1.1 tron </DD>
1781 1.1 tron
1782 1.1 tron <DT><b><a name="default_destination_concurrency_limit">default_destination_concurrency_limit</a>
1783 1.1 tron (default: 20)</b></DT><DD>
1784 1.1 tron
1785 1.1 tron <p>
1786 1.1 tron The default maximal number of parallel deliveries to the same
1787 1.1 tron destination. This is the default limit for delivery via the <a href="lmtp.8.html">lmtp(8)</a>,
1788 1.1 tron <a href="pipe.8.html">pipe(8)</a>, <a href="smtp.8.html">smtp(8)</a> and <a href="virtual.8.html">virtual(8)</a> delivery agents.
1789 1.1 tron With per-destination recipient limit > 1, a destination is a domain,
1790 1.1 tron otherwise it is a recipient.
1791 1.1 tron </p>
1792 1.1 tron
1793 1.1 tron <p> Use <a href="postconf.5.html#transport_destination_concurrency_limit"><i>transport</i>_destination_concurrency_limit</a> to specify a
1794 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1795 1.1 tron name of the message delivery transport.
1796 1.1 tron </p>
1797 1.1 tron
1798 1.1 tron
1799 1.1 tron </DD>
1800 1.1 tron
1801 1.1 tron <DT><b><a name="default_destination_concurrency_negative_feedback">default_destination_concurrency_negative_feedback</a>
1802 1.1 tron (default: 1)</b></DT><DD>
1803 1.1 tron
1804 1.1 tron <p> The per-destination amount of delivery concurrency negative
1805 1.1 tron feedback, after a delivery completes with a connection or handshake
1806 1.1 tron failure. Feedback values are in the range 0..1 inclusive. With
1807 1.1 tron negative feedback, concurrency is decremented at the beginning of
1808 1.1 tron a sequence of length 1/feedback. This is unlike positive feedback,
1809 1.1 tron where concurrency is incremented at the end of a sequence of length
1810 1.1 tron 1/feedback. </p>
1811 1.1 tron
1812 1.1 tron <p> As of Postfix version 2.5, negative feedback cannot reduce
1813 1.1 tron delivery concurrency to zero. Instead, a destination is marked
1814 1.1 tron dead (further delivery suspended) after the failed pseudo-cohort
1815 1.1 tron count reaches $<a href="postconf.5.html#default_destination_concurrency_failed_cohort_limit">default_destination_concurrency_failed_cohort_limit</a>
1816 1.1 tron (or $<a href="postconf.5.html#transport_destination_concurrency_failed_cohort_limit"><i>transport</i>_destination_concurrency_failed_cohort_limit</a>).
1817 1.1 tron To make the scheduler completely immune to connection or handshake
1818 1.1 tron failures, specify a zero feedback value and a zero failed pseudo-cohort
1819 1.1 tron limit. </p>
1820 1.1 tron
1821 1.1 tron <p> Specify one of the following forms: </p>
1822 1.1 tron
1823 1.1 tron <dl>
1824 1.1 tron
1825 1.1 tron <dt> <b><i>number</i> </b> </dt>
1826 1.1 tron
1827 1.1 tron <dt> <b><i>number</i> / <i>number</i> </b> </dt>
1828 1.1 tron
1829 1.1 tron <dd> Constant feedback. The value must be in the range 0..1 inclusive.
1830 1.1 tron The default setting of "1" is compatible with Postfix versions
1831 1.1 tron before 2.5, where a destination's delivery concurrency is throttled
1832 1.1 tron down to zero (and further delivery suspended) after a single failed
1833 1.1 tron pseudo-cohort. </dd>
1834 1.1 tron
1835 1.1 tron <dt> <b><i>number</i> / concurrency </b> </dt>
1836 1.1 tron
1837 1.1 tron <dd> Variable feedback of "<i>number</i> / (delivery concurrency)".
1838 1.1 tron The <i>number</i> must be in the range 0..1 inclusive. With
1839 1.1 tron <i>number</i> equal to "1", a destination's delivery concurrency
1840 1.1 tron is decremented by 1 after each failed pseudo-cohort. </dd>
1841 1.1 tron
1842 1.1 tron </dl>
1843 1.1 tron
1844 1.1 tron <p> A pseudo-cohort is the number of deliveries equal to a destination's
1845 1.1 tron delivery concurrency. </p>
1846 1.1 tron
1847 1.1 tron <p> Use <a href="postconf.5.html#transport_destination_concurrency_negative_feedback"><i>transport</i>_destination_concurrency_negative_feedback</a>
1848 1.1 tron to specify a transport-specific override, where <i>transport</i>
1849 1.1 tron is the <a href="master.5.html">master.cf</a>
1850 1.1 tron name of the message delivery transport. </p>
1851 1.1 tron
1852 1.1 tron <p> This feature is available in Postfix 2.5. The default setting
1853 1.1 tron is compatible with earlier Postfix versions. </p>
1854 1.1 tron
1855 1.1 tron
1856 1.1 tron </DD>
1857 1.1 tron
1858 1.1 tron <DT><b><a name="default_destination_concurrency_positive_feedback">default_destination_concurrency_positive_feedback</a>
1859 1.1 tron (default: 1)</b></DT><DD>
1860 1.1 tron
1861 1.1 tron <p> The per-destination amount of delivery concurrency positive
1862 1.1 tron feedback, after a delivery completes without connection or handshake
1863 1.1 tron failure. Feedback values are in the range 0..1 inclusive. The
1864 1.1 tron concurrency increases until it reaches the per-destination maximal
1865 1.1 tron concurrency limit. With positive feedback, concurrency is incremented
1866 1.1 tron at the end of a sequence with length 1/feedback. This is unlike
1867 1.1 tron negative feedback, where concurrency is decremented at the start
1868 1.1 tron of a sequence of length 1/feedback. </p>
1869 1.1 tron
1870 1.1 tron <p> Specify one of the following forms: </p>
1871 1.1 tron
1872 1.1 tron <dl>
1873 1.1 tron
1874 1.1 tron <dt> <b><i>number</i> </b> </dt>
1875 1.1 tron
1876 1.1 tron <dt> <b><i>number</i> / <i>number</i> </b> </dt>
1877 1.1 tron
1878 1.1 tron <dd> Constant feedback. The value must be in the range 0..1
1879 1.1 tron inclusive. The default setting of "1" is compatible with Postfix
1880 1.1 tron versions before 2.5, where a destination's delivery concurrency
1881 1.1 tron doubles after each successful pseudo-cohort. </dd>
1882 1.1 tron
1883 1.1 tron <dt> <b><i>number</i> / concurrency </b> </dt>
1884 1.1 tron
1885 1.1 tron <dd> Variable feedback of "<i>number</i> / (delivery concurrency)".
1886 1.1 tron The <i>number</i> must be in the range 0..1 inclusive. With
1887 1.1 tron <i>number</i> equal to "1", a destination's delivery concurrency
1888 1.1 tron is incremented by 1 after each successful pseudo-cohort. </dd>
1889 1.1 tron
1890 1.1 tron </dl>
1891 1.1 tron
1892 1.1 tron <p> A pseudo-cohort is the number of deliveries equal to a destination's
1893 1.1 tron delivery concurrency. </p>
1894 1.1 tron
1895 1.1 tron <p> Use <a href="postconf.5.html#transport_destination_concurrency_positive_feedback"><i>transport</i>_destination_concurrency_positive_feedback</a>
1896 1.1 tron to specify a transport-specific override, where <i>transport</i>
1897 1.1 tron is the <a href="master.5.html">master.cf</a> name of the message delivery transport. </p>
1898 1.1 tron
1899 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
1900 1.1 tron
1901 1.1 tron
1902 1.1 tron </DD>
1903 1.1 tron
1904 1.1 tron <DT><b><a name="default_destination_rate_delay">default_destination_rate_delay</a>
1905 1.1 tron (default: 0s)</b></DT><DD>
1906 1.1 tron
1907 1.1 tron <p> The default amount of delay that is inserted between individual
1908 1.1 tron deliveries to the same destination; with per-destination recipient
1909 1.1 tron limit > 1, a destination is a domain, otherwise it is a recipient.
1910 1.1 tron </p>
1911 1.1 tron
1912 1.1 tron <p> To enable the delay, specify a non-zero time value (an integral
1913 1.1 tron value plus an optional one-letter suffix that specifies the time
1914 1.1 tron unit). </p>
1915 1.1 tron
1916 1.1 tron <p> Time units: s (seconds), m (minutes), h (hours), d (days), w
1917 1.1 tron (weeks). The default time unit is s (seconds). </p>
1918 1.1 tron
1919 1.1 tron <p> NOTE: the delay is enforced by the queue manager. The delay
1920 1.1 tron timer state does not survive "postfix reload" or "postfix stop".
1921 1.1 tron </p>
1922 1.1 tron
1923 1.1 tron <p> Use <a href="postconf.5.html#transport_destination_rate_delay"><i>transport</i>_destination_rate_delay</a> to specify a
1924 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1925 1.1 tron name of the message delivery transport.
1926 1.1 tron </p>
1927 1.1 tron
1928 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
1929 1.1 tron
1930 1.1 tron
1931 1.1 tron </DD>
1932 1.1 tron
1933 1.1 tron <DT><b><a name="default_destination_recipient_limit">default_destination_recipient_limit</a>
1934 1.1 tron (default: 50)</b></DT><DD>
1935 1.1 tron
1936 1.1 tron <p>
1937 1.1 tron The default maximal number of recipients per message delivery.
1938 1.1 tron This is the default limit for delivery via the <a href="lmtp.8.html">lmtp(8)</a>, <a href="pipe.8.html">pipe(8)</a>,
1939 1.1 tron <a href="smtp.8.html">smtp(8)</a> and <a href="virtual.8.html">virtual(8)</a> delivery agents.
1940 1.1 tron </p>
1941 1.1 tron
1942 1.1 tron <p> Setting this parameter to a value of 1 changes the meaning of
1943 1.1 tron the corresponding per-destination concurrency limit from concurrency
1944 1.1 tron per domain into concurrency per recipient. </p>
1945 1.1 tron
1946 1.1 tron <p> Use <a href="postconf.5.html#transport_destination_recipient_limit"><i>transport</i>_destination_recipient_limit</a> to specify a
1947 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1948 1.1 tron name of the message delivery transport.
1949 1.1 tron </p>
1950 1.1 tron
1951 1.1 tron
1952 1.1 tron </DD>
1953 1.1 tron
1954 1.1 tron <DT><b><a name="default_extra_recipient_limit">default_extra_recipient_limit</a>
1955 1.1 tron (default: 1000)</b></DT><DD>
1956 1.1 tron
1957 1.1 tron <p>
1958 1.1 tron The default value for the extra per-transport limit imposed on the
1959 1.1 tron number of in-memory recipients. This extra recipient space is
1960 1.1 tron reserved for the cases when the Postfix queue manager's scheduler
1961 1.1 tron preempts one message with another and suddenly needs some extra
1962 1.1 tron recipients slots for the chosen message in order to avoid performance
1963 1.1 tron degradation.
1964 1.1 tron </p>
1965 1.1 tron
1966 1.1 tron <p> Use <a href="postconf.5.html#transport_extra_recipient_limit"><i>transport</i>_extra_recipient_limit</a> to specify a
1967 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1968 1.1 tron name of the message delivery transport.
1969 1.1 tron </p>
1970 1.1 tron
1971 1.1 tron
1972 1.1 tron </DD>
1973 1.1 tron
1974 1.1 tron <DT><b><a name="default_minimum_delivery_slots">default_minimum_delivery_slots</a>
1975 1.1 tron (default: 3)</b></DT><DD>
1976 1.1 tron
1977 1.1 tron <p>
1978 1.1 tron How many recipients a message must have in order to invoke the
1979 1.1 tron Postfix queue manager's scheduling algorithm at all. Messages
1980 1.1 tron which would never accumulate at least this many delivery slots
1981 1.1 tron (subject to slot cost parameter as well) are never preempted.
1982 1.1 tron </p>
1983 1.1 tron
1984 1.1 tron <p> Use <a href="postconf.5.html#transport_minimum_delivery_slots"><i>transport</i>_minimum_delivery_slots</a> to specify a
1985 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
1986 1.1 tron name of the message delivery transport.
1987 1.1 tron </p>
1988 1.1 tron
1989 1.1 tron
1990 1.1 tron </DD>
1991 1.1 tron
1992 1.1 tron <DT><b><a name="default_privs">default_privs</a>
1993 1.1 tron (default: nobody)</b></DT><DD>
1994 1.1 tron
1995 1.1 tron <p>
1996 1.1 tron The default rights used by the <a href="local.8.html">local(8)</a> delivery agent for delivery
1997 1.1 tron to external file or command. These rights are used when delivery
1998 1.1 tron is requested from an <a href="aliases.5.html">aliases(5)</a> file that is owned by <b>root</b>, or
1999 1.1 tron when delivery is done on behalf of <b>root</b>. <b>DO NOT SPECIFY A
2000 1.1 tron PRIVILEGED USER OR THE POSTFIX OWNER</b>.
2001 1.1 tron </p>
2002 1.1 tron
2003 1.1 tron
2004 1.1 tron </DD>
2005 1.1 tron
2006 1.1 tron <DT><b><a name="default_process_limit">default_process_limit</a>
2007 1.1 tron (default: 100)</b></DT><DD>
2008 1.1 tron
2009 1.1 tron <p>
2010 1.1 tron The default maximal number of Postfix child processes that provide
2011 1.1 tron a given service. This limit can be overruled for specific services
2012 1.1 tron in the <a href="master.5.html">master.cf</a> file.
2013 1.1 tron </p>
2014 1.1 tron
2015 1.1 tron
2016 1.1 tron </DD>
2017 1.1 tron
2018 1.1 tron <DT><b><a name="default_rbl_reply">default_rbl_reply</a>
2019 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
2020 1.1 tron
2021 1.1 tron <p>
2022 1.1 tron The default SMTP server response template for a request that is
2023 1.1 tron rejected by an RBL-based restriction. This template can be overruled
2024 1.1 tron by specific entries in the optional <a href="postconf.5.html#rbl_reply_maps">rbl_reply_maps</a> lookup table.
2025 1.1 tron </p>
2026 1.1 tron
2027 1.1 tron <p>
2028 1.1 tron This feature is available in Postfix 2.0 and later.
2029 1.1 tron </p>
2030 1.1 tron
2031 1.1 tron <p>
2032 1.1 tron The template is subject to exactly one level of $name substitution:
2033 1.1 tron </p>
2034 1.1 tron
2035 1.1 tron <dl>
2036 1.1 tron
2037 1.1 tron <dt><b>$client</b></dt>
2038 1.1 tron
2039 1.1 tron <dd>The client hostname and IP address, formatted as name[address]. </dd>
2040 1.1 tron
2041 1.1 tron <dt><b>$client_address</b></dt>
2042 1.1 tron
2043 1.1 tron <dd>The client IP address. </dd>
2044 1.1 tron
2045 1.1 tron <dt><b>$client_name</b></dt>
2046 1.1 tron
2047 1.1 tron <dd>The client hostname or "unknown". See <a href="postconf.5.html#reject_unknown_client_hostname">reject_unknown_client_hostname</a>
2048 1.1 tron for more details. </dd>
2049 1.1 tron
2050 1.1 tron <dt><b>$reverse_client_name</b></dt>
2051 1.1 tron
2052 1.1 tron <dd>The client hostname from address->name lookup, or "unknown".
2053 1.1 tron See <a href="postconf.5.html#reject_unknown_reverse_client_hostname">reject_unknown_reverse_client_hostname</a> for more details. </dd>
2054 1.1 tron
2055 1.1 tron <dt><b>$helo_name</b></dt>
2056 1.1 tron
2057 1.1 tron <dd>The hostname given in HELO or EHLO command or empty string. </dd>
2058 1.1 tron
2059 1.1 tron <dt><b>$rbl_class</b></dt>
2060 1.1 tron
2061 1.1 tron <dd>The blacklisted entity type: Client host, Helo command, Sender
2062 1.1 tron address, or Recipient address. </dd>
2063 1.1 tron
2064 1.1 tron <dt><b>$rbl_code</b></dt>
2065 1.1 tron
2066 1.1 tron <dd>The numerical SMTP response code, as specified with the
2067 1.1 tron <a href="postconf.5.html#maps_rbl_reject_code">maps_rbl_reject_code</a> configuration parameter. Note: The numerical
2068 1.1 tron SMTP response code is required, and must appear at the start of the
2069 1.1 tron reply. With Postfix version 2.3 and later this information may be followed
2070 1.1 tron by an <a href="http://tools.ietf.org/html/rfc3463">RFC 3463</a> enhanced status code. </dd>
2071 1.1 tron
2072 1.1 tron <dt><b>$rbl_domain</b></dt>
2073 1.1 tron
2074 1.1 tron <dd>The RBL domain where $rbl_what is blacklisted. </dd>
2075 1.1 tron
2076 1.1 tron <dt><b>$rbl_reason</b></dt>
2077 1.1 tron
2078 1.1 tron <dd>The reason why $rbl_what is blacklisted, or an empty string. </dd>
2079 1.1 tron
2080 1.1 tron <dt><b>$rbl_what</b></dt>
2081 1.1 tron
2082 1.1 tron <dd>The entity that is blacklisted (an IP address, a hostname, a domain
2083 1.1 tron name, or an email address whose domain was blacklisted). </dd>
2084 1.1 tron
2085 1.1 tron <dt><b>$recipient</b></dt>
2086 1.1 tron
2087 1.1 tron <dd>The recipient address or <> in case of the null address. </dd>
2088 1.1 tron
2089 1.1 tron <dt><b>$recipient_domain</b></dt>
2090 1.1 tron
2091 1.1 tron <dd>The recipient domain or empty string. </dd>
2092 1.1 tron
2093 1.1 tron <dt><b>$recipient_name</b></dt>
2094 1.1 tron
2095 1.1 tron <dd>The recipient address localpart or <> in case of null address. </dd>
2096 1.1 tron
2097 1.1 tron <dt><b>$sender</b></dt>
2098 1.1 tron
2099 1.1 tron <dd>The sender address or <> in case of the null address. </dd>
2100 1.1 tron
2101 1.1 tron <dt><b>$sender_domain</b></dt>
2102 1.1 tron
2103 1.1 tron <dd>The sender domain or empty string. </dd>
2104 1.1 tron
2105 1.1 tron <dt><b>$sender_name</b></dt>
2106 1.1 tron
2107 1.1 tron <dd>The sender address localpart or <> in case of the null address. </dd>
2108 1.1 tron
2109 1.1 tron <dt><b>${name?text}</b></dt>
2110 1.1 tron
2111 1.1 tron <dd>Expands to `text' if $name is not empty. </dd>
2112 1.1 tron
2113 1.1 tron <dt><b>${name:text}</b></dt>
2114 1.1 tron
2115 1.1 tron <dd>Expands to `text' if $name is empty. </dd>
2116 1.1 tron
2117 1.1 tron </dl>
2118 1.1 tron
2119 1.1 tron <p>
2120 1.1 tron Instead of $name you can also specify ${name} or $(name).
2121 1.1 tron </p>
2122 1.1 tron
2123 1.1 tron <p> Note: when an enhanced status code is specified in an RBL reply
2124 1.1 tron template, it is subject to modification. The following transformations
2125 1.1 tron are needed when the same RBL reply template is used for client,
2126 1.1 tron helo, sender, or recipient access restrictions. </p>
2127 1.1 tron
2128 1.1 tron <ul>
2129 1.1 tron
2130 1.1 tron <li> <p> When rejecting a sender address, the Postfix SMTP server
2131 1.1 tron will transform a recipient DSN status (e.g., 4.1.1-4.1.6) into the
2132 1.1 tron corresponding sender DSN status, and vice versa. </p>
2133 1.1 tron
2134 1.1 tron <li> <p> When rejecting non-address information (such as the HELO
2135 1.1 tron command argument or the client hostname/address), the Postfix SMTP
2136 1.1 tron server will transform a sender or recipient DSN status into a generic
2137 1.1 tron non-address DSN status (e.g., 4.0.0). </p>
2138 1.1 tron
2139 1.1 tron </ul>
2140 1.1 tron
2141 1.1 tron
2142 1.1 tron </DD>
2143 1.1 tron
2144 1.1 tron <DT><b><a name="default_recipient_limit">default_recipient_limit</a>
2145 1.1 tron (default: 20000)</b></DT><DD>
2146 1.1 tron
2147 1.1 tron <p>
2148 1.1 tron The default per-transport upper limit on the number of in-memory
2149 1.1 tron recipients. These limits take priority over the global
2150 1.1 tron <a href="postconf.5.html#qmgr_message_recipient_limit">qmgr_message_recipient_limit</a> after the message has been assigned
2151 1.1 tron to the respective transports. See also <a href="postconf.5.html#default_extra_recipient_limit">default_extra_recipient_limit</a>
2152 1.1 tron and <a href="postconf.5.html#qmgr_message_recipient_minimum">qmgr_message_recipient_minimum</a>.
2153 1.1 tron </p>
2154 1.1 tron
2155 1.1 tron <p> Use <a href="postconf.5.html#transport_recipient_limit"><i>transport</i>_recipient_limit</a> to specify a
2156 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
2157 1.1 tron name of the message delivery transport.
2158 1.1 tron </p>
2159 1.1 tron
2160 1.1 tron
2161 1.1 tron </DD>
2162 1.1 tron
2163 1.1 tron <DT><b><a name="default_recipient_refill_delay">default_recipient_refill_delay</a>
2164 1.1 tron (default: 5s)</b></DT><DD>
2165 1.1 tron
2166 1.1 tron <p>
2167 1.1 tron The default per-transport maximum delay between recipients refills.
2168 1.1 tron When not all message recipients fit into the memory at once, keep loading
2169 1.1 tron more of them at least once every this many seconds. This is used to
2170 1.1 tron make sure the recipients are refilled in timely manner even when
2171 1.1 tron $<a href="postconf.5.html#default_recipient_refill_limit">default_recipient_refill_limit</a> is too high for too slow deliveries.
2172 1.1 tron </p>
2173 1.1 tron
2174 1.1 tron <p> Use <a href="postconf.5.html#transport_recipient_refill_delay"><i>transport</i>_recipient_refill_delay</a> to specify a
2175 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
2176 1.1 tron name of the message delivery transport.
2177 1.1 tron </p>
2178 1.1 tron
2179 1.1 tron <p> This feature is available in Postfix 2.4 and later. </p>
2180 1.1 tron
2181 1.1 tron
2182 1.1 tron </DD>
2183 1.1 tron
2184 1.1 tron <DT><b><a name="default_recipient_refill_limit">default_recipient_refill_limit</a>
2185 1.1 tron (default: 100)</b></DT><DD>
2186 1.1 tron
2187 1.1 tron <p>
2188 1.1 tron The default per-transport limit on the number of recipients refilled at
2189 1.1 tron once. When not all message recipients fit into the memory at once, keep
2190 1.1 tron loading more of them in batches of at least this many at a time. See also
2191 1.1 tron $<a href="postconf.5.html#default_recipient_refill_delay">default_recipient_refill_delay</a>, which may result in recipient batches
2192 1.1 tron lower than this when this limit is too high for too slow deliveries.
2193 1.1 tron </p>
2194 1.1 tron
2195 1.1 tron <p> Use <a href="postconf.5.html#transport_recipient_refill_limit"><i>transport</i>_recipient_refill_limit</a> to specify a
2196 1.1 tron transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
2197 1.1 tron name of the message delivery transport.
2198 1.1 tron </p>
2199 1.1 tron
2200 1.1 tron <p> This feature is available in Postfix 2.4 and later. </p>
2201 1.1 tron
2202 1.1 tron
2203 1.1 tron </DD>
2204 1.1 tron
2205 1.1 tron <DT><b><a name="default_transport">default_transport</a>
2206 1.1 tron (default: smtp)</b></DT><DD>
2207 1.1 tron
2208 1.1 tron <p>
2209 1.1 tron The default mail delivery transport and next-hop destination for
2210 1.1 tron destinations that do not match $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>,
2211 1.1 tron $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>, $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>, $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>,
2212 1.1 tron or $<a href="postconf.5.html#relay_domains">relay_domains</a>. In order of decreasing precedence, the nexthop
2213 1.1 tron destination is taken from $<a href="postconf.5.html#default_transport">default_transport</a>,
2214 1.1 tron $<a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a>, $<a href="postconf.5.html#relayhost">relayhost</a>, or from the recipient
2215 1.1 tron domain. This information can be overruled with the <a href="transport.5.html">transport(5)</a>
2216 1.1 tron table.
2217 1.1 tron </p>
2218 1.1 tron
2219 1.1 tron <p>
2220 1.1 tron Specify a string of the form <i>transport:nexthop</i>, where <i>transport</i>
2221 1.1 tron is the name of a mail delivery transport defined in <a href="master.5.html">master.cf</a>.
2222 1.1 tron The <i>:nexthop</i> part is optional. For more details see the
2223 1.1 tron <a href="transport.5.html">transport(5)</a> manual page.
2224 1.1 tron </p>
2225 1.1 tron
2226 1.1 tron <p>
2227 1.1 tron Example:
2228 1.1 tron </p>
2229 1.1 tron
2230 1.1 tron <pre>
2231 1.1 tron <a href="postconf.5.html#default_transport">default_transport</a> = uucp:relayhostname
2232 1.1 tron </pre>
2233 1.1 tron
2234 1.1 tron
2235 1.1 tron </DD>
2236 1.1 tron
2237 1.1 tron <DT><b><a name="default_verp_delimiters">default_verp_delimiters</a>
2238 1.1 tron (default: +=)</b></DT><DD>
2239 1.1 tron
2240 1.1 tron <p> The two default VERP delimiter characters. These are used when
2241 1.1 tron no explicit delimiters are specified with the SMTP XVERP command
2242 1.1 tron or with the "<b>sendmail -V</b>" command-line option. Specify
2243 1.1 tron characters that are allowed by the <a href="postconf.5.html#verp_delimiter_filter">verp_delimiter_filter</a> setting.
2244 1.1 tron </p>
2245 1.1 tron
2246 1.1 tron <p>
2247 1.1 tron This feature is available in Postfix 1.1 and later.
2248 1.1 tron </p>
2249 1.1 tron
2250 1.1 tron
2251 1.1 tron </DD>
2252 1.1 tron
2253 1.1 tron <DT><b><a name="defer_code">defer_code</a>
2254 1.1 tron (default: 450)</b></DT><DD>
2255 1.1 tron
2256 1.1 tron <p>
2257 1.1 tron The numerical Postfix SMTP server response code when a remote SMTP
2258 1.1 tron client request is rejected by the "defer" restriction.
2259 1.1 tron </p>
2260 1.1 tron
2261 1.1 tron <p>
2262 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
2263 1.1 tron </p>
2264 1.1 tron
2265 1.1 tron
2266 1.1 tron </DD>
2267 1.1 tron
2268 1.1 tron <DT><b><a name="defer_service_name">defer_service_name</a>
2269 1.1 tron (default: defer)</b></DT><DD>
2270 1.1 tron
2271 1.1 tron <p>
2272 1.1 tron The name of the defer service. This service is implemented by the
2273 1.1 tron <a href="bounce.8.html">bounce(8)</a> daemon and maintains a record
2274 1.1 tron of failed delivery attempts and generates non-delivery notifications.
2275 1.1 tron </p>
2276 1.1 tron
2277 1.1 tron <p>
2278 1.1 tron This feature is available in Postfix 2.0 and later.
2279 1.1 tron </p>
2280 1.1 tron
2281 1.1 tron
2282 1.1 tron </DD>
2283 1.1 tron
2284 1.1 tron <DT><b><a name="defer_transports">defer_transports</a>
2285 1.1 tron (default: empty)</b></DT><DD>
2286 1.1 tron
2287 1.1 tron <p>
2288 1.1 tron The names of message delivery transports that should not deliver mail
2289 1.1 tron unless someone issues "<b>sendmail -q</b>" or equivalent. Specify zero
2290 1.1 tron or more names of mail delivery transports names that appear in the
2291 1.1 tron first field of <a href="master.5.html">master.cf</a>.
2292 1.1 tron </p>
2293 1.1 tron
2294 1.1 tron <p>
2295 1.1 tron Example:
2296 1.1 tron </p>
2297 1.1 tron
2298 1.1 tron <pre>
2299 1.1 tron <a href="postconf.5.html#defer_transports">defer_transports</a> = smtp
2300 1.1 tron </pre>
2301 1.1 tron
2302 1.1 tron
2303 1.1 tron </DD>
2304 1.1 tron
2305 1.1 tron <DT><b><a name="delay_logging_resolution_limit">delay_logging_resolution_limit</a>
2306 1.1 tron (default: 2)</b></DT><DD>
2307 1.1 tron
2308 1.1 tron <p> The maximal number of digits after the decimal point when logging
2309 1.1 tron sub-second delay values. Specify a number in the range 0..6. </p>
2310 1.1 tron
2311 1.1 tron <p> Large delay values are rounded off to an integral number seconds;
2312 1.1 tron delay values below the <a href="postconf.5.html#delay_logging_resolution_limit">delay_logging_resolution_limit</a> are logged
2313 1.1 tron as "0", and small delay values are logged with at most two-digit
2314 1.1 tron precision. </p>
2315 1.1 tron
2316 1.1 tron <p> The format of the "delays=a/b/c/d" logging is as follows: </p>
2317 1.1 tron
2318 1.1 tron <ul>
2319 1.1 tron
2320 1.1 tron <li> a = time from message arrival to last <a href="QSHAPE_README.html#active_queue">active queue</a> entry
2321 1.1 tron
2322 1.1 tron <li> b = time from last <a href="QSHAPE_README.html#active_queue">active queue</a> entry to connection setup
2323 1.1 tron
2324 1.1 tron <li> c = time in connection setup, including DNS, EHLO and TLS
2325 1.1 tron
2326 1.1 tron <li> d = time in message transmission
2327 1.1 tron
2328 1.1 tron </ul>
2329 1.1 tron
2330 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
2331 1.1 tron
2332 1.1 tron
2333 1.1 tron </DD>
2334 1.1 tron
2335 1.1 tron <DT><b><a name="delay_notice_recipient">delay_notice_recipient</a>
2336 1.1 tron (default: postmaster)</b></DT><DD>
2337 1.1 tron
2338 1.1 tron <p>
2339 1.1 tron The recipient of postmaster notifications with the message headers
2340 1.1 tron of mail that cannot be delivered within $<a href="postconf.5.html#delay_warning_time">delay_warning_time</a> time
2341 1.1 tron units. </p>
2342 1.1 tron
2343 1.1 tron <p>
2344 1.1 tron This feature is enabled with the <a href="postconf.5.html#delay_warning_time">delay_warning_time</a> parameter.
2345 1.1 tron </p>
2346 1.1 tron
2347 1.1 tron
2348 1.1 tron </DD>
2349 1.1 tron
2350 1.1 tron <DT><b><a name="delay_warning_time">delay_warning_time</a>
2351 1.1 tron (default: 0h)</b></DT><DD>
2352 1.1 tron
2353 1.1 tron <p>
2354 1.1 tron The time after which the sender receives the message headers of
2355 1.1 tron mail that is still queued.
2356 1.1 tron </p>
2357 1.1 tron
2358 1.1 tron <p>
2359 1.1 tron To enable this feature, specify a non-zero time value (an integral
2360 1.1 tron value plus an optional one-letter suffix that specifies the time
2361 1.1 tron unit).
2362 1.1 tron </p>
2363 1.1 tron
2364 1.1 tron <p>
2365 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
2366 1.1 tron The default time unit is h (hours).
2367 1.1 tron </p>
2368 1.1 tron
2369 1.1 tron
2370 1.1 tron </DD>
2371 1.1 tron
2372 1.1 tron <DT><b><a name="deliver_lock_attempts">deliver_lock_attempts</a>
2373 1.1 tron (default: 20)</b></DT><DD>
2374 1.1 tron
2375 1.1 tron <p>
2376 1.1 tron The maximal number of attempts to acquire an exclusive lock on a
2377 1.1 tron mailbox file or <a href="bounce.8.html">bounce(8)</a> logfile.
2378 1.1 tron </p>
2379 1.1 tron
2380 1.1 tron
2381 1.1 tron </DD>
2382 1.1 tron
2383 1.1 tron <DT><b><a name="deliver_lock_delay">deliver_lock_delay</a>
2384 1.1 tron (default: 1s)</b></DT><DD>
2385 1.1 tron
2386 1.1 tron <p>
2387 1.1 tron The time between attempts to acquire an exclusive lock on a mailbox
2388 1.1 tron file or <a href="bounce.8.html">bounce(8)</a> logfile.
2389 1.1 tron </p>
2390 1.1 tron
2391 1.1 tron <p>
2392 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
2393 1.1 tron The default time unit is s (seconds).
2394 1.1 tron </p>
2395 1.1 tron
2396 1.1 tron
2397 1.1 tron </DD>
2398 1.1 tron
2399 1.1 tron <DT><b><a name="destination_concurrency_feedback_debug">destination_concurrency_feedback_debug</a>
2400 1.1 tron (default: no)</b></DT><DD>
2401 1.1 tron
2402 1.1 tron <p> Make the queue manager's feedback algorithm verbose for performance
2403 1.1 tron analysis purposes. </p>
2404 1.1 tron
2405 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
2406 1.1 tron
2407 1.1 tron
2408 1.1 tron </DD>
2409 1.1 tron
2410 1.1 tron <DT><b><a name="detect_8bit_encoding_header">detect_8bit_encoding_header</a>
2411 1.1 tron (default: yes)</b></DT><DD>
2412 1.1 tron
2413 1.1 tron <p> Automatically detect 8BITMIME body content by looking at
2414 1.1 tron Content-Transfer-Encoding: message headers; historically, this
2415 1.1 tron behavior was hard-coded to be "always on". </p>
2416 1.1 tron
2417 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
2418 1.1 tron
2419 1.1 tron
2420 1.1 tron </DD>
2421 1.1 tron
2422 1.1 tron <DT><b><a name="disable_dns_lookups">disable_dns_lookups</a>
2423 1.1 tron (default: no)</b></DT><DD>
2424 1.1 tron
2425 1.1 tron <p>
2426 1.1 tron Disable DNS lookups in the Postfix SMTP and LMTP clients. When
2427 1.1 tron disabled, hosts are looked up with the getaddrinfo() system
2428 1.1 tron library routine which normally also looks in /etc/hosts.
2429 1.1 tron </p>
2430 1.1 tron
2431 1.1 tron <p>
2432 1.1 tron DNS lookups are enabled by default.
2433 1.1 tron </p>
2434 1.1 tron
2435 1.1 tron
2436 1.1 tron </DD>
2437 1.1 tron
2438 1.1 tron <DT><b><a name="disable_mime_input_processing">disable_mime_input_processing</a>
2439 1.1 tron (default: no)</b></DT><DD>
2440 1.1 tron
2441 1.1 tron <p>
2442 1.1 tron Turn off MIME processing while receiving mail. This means that no
2443 1.1 tron special treatment is given to Content-Type: message headers, and
2444 1.1 tron that all text after the initial message headers is considered to
2445 1.1 tron be part of the message body.
2446 1.1 tron </p>
2447 1.1 tron
2448 1.1 tron <p>
2449 1.1 tron This feature is available in Postfix 2.0 and later.
2450 1.1 tron </p>
2451 1.1 tron
2452 1.1 tron <p>
2453 1.1 tron Mime input processing is enabled by default, and is needed in order
2454 1.1 tron to recognize MIME headers in message content.
2455 1.1 tron </p>
2456 1.1 tron
2457 1.1 tron
2458 1.1 tron </DD>
2459 1.1 tron
2460 1.1 tron <DT><b><a name="disable_mime_output_conversion">disable_mime_output_conversion</a>
2461 1.1 tron (default: no)</b></DT><DD>
2462 1.1 tron
2463 1.1 tron <p>
2464 1.1 tron Disable the conversion of 8BITMIME format to 7BIT format. Mime
2465 1.1 tron output conversion is needed when the destination does not advertise
2466 1.1 tron 8BITMIME support.
2467 1.1 tron </p>
2468 1.1 tron
2469 1.1 tron <p>
2470 1.1 tron This feature is available in Postfix 2.0 and later.
2471 1.1 tron </p>
2472 1.1 tron
2473 1.1 tron
2474 1.1 tron </DD>
2475 1.1 tron
2476 1.1 tron <DT><b><a name="disable_verp_bounces">disable_verp_bounces</a>
2477 1.1 tron (default: no)</b></DT><DD>
2478 1.1 tron
2479 1.1 tron <p>
2480 1.1 tron Disable sending one bounce report per recipient.
2481 1.1 tron </p>
2482 1.1 tron
2483 1.1 tron <p>
2484 1.1 tron The default, one per recipient, is what ezmlm needs.
2485 1.1 tron </p>
2486 1.1 tron
2487 1.1 tron <p>
2488 1.1 tron This feature is available in Postfix 1.1 and later.
2489 1.1 tron </p>
2490 1.1 tron
2491 1.1 tron
2492 1.1 tron </DD>
2493 1.1 tron
2494 1.1 tron <DT><b><a name="disable_vrfy_command">disable_vrfy_command</a>
2495 1.1 tron (default: no)</b></DT><DD>
2496 1.1 tron
2497 1.1 tron <p>
2498 1.1 tron Disable the SMTP VRFY command. This stops some techniques used to
2499 1.1 tron harvest email addresses.
2500 1.1 tron </p>
2501 1.1 tron
2502 1.1 tron <p>
2503 1.1 tron Example:
2504 1.1 tron </p>
2505 1.1 tron
2506 1.1 tron <pre>
2507 1.1 tron <a href="postconf.5.html#disable_vrfy_command">disable_vrfy_command</a> = no
2508 1.1 tron </pre>
2509 1.1 tron
2510 1.1 tron
2511 1.1 tron </DD>
2512 1.1 tron
2513 1.1 tron <DT><b><a name="dont_remove">dont_remove</a>
2514 1.1 tron (default: 0)</b></DT><DD>
2515 1.1 tron
2516 1.1 tron <p>
2517 1.1 tron Don't remove queue files and save them to the "saved" mail queue.
2518 1.1 tron This is a debugging aid. To inspect the envelope information and
2519 1.1 tron content of a Postfix queue file, use the <a href="postcat.1.html">postcat(1)</a> command.
2520 1.1 tron </p>
2521 1.1 tron
2522 1.1 tron
2523 1.1 tron </DD>
2524 1.1 tron
2525 1.1 tron <DT><b><a name="double_bounce_sender">double_bounce_sender</a>
2526 1.1 tron (default: double-bounce)</b></DT><DD>
2527 1.1 tron
2528 1.1 tron <p> The sender address of postmaster notifications that are generated
2529 1.1 tron by the mail system. All mail to this address is silently discarded,
2530 1.1 tron in order to terminate mail bounce loops. </p>
2531 1.1 tron
2532 1.1 tron
2533 1.1 tron </DD>
2534 1.1 tron
2535 1.1 tron <DT><b><a name="duplicate_filter_limit">duplicate_filter_limit</a>
2536 1.1 tron (default: 1000)</b></DT><DD>
2537 1.1 tron
2538 1.1 tron <p> The maximal number of addresses remembered by the address
2539 1.1 tron duplicate filter for <a href="aliases.5.html">aliases(5)</a> or <a href="virtual.5.html">virtual(5)</a> alias expansion, or
2540 1.1 tron for <a href="showq.8.html">showq(8)</a> queue displays. </p>
2541 1.1 tron
2542 1.1 tron
2543 1.1 tron </DD>
2544 1.1 tron
2545 1.1 tron <DT><b><a name="empty_address_recipient">empty_address_recipient</a>
2546 1.1 tron (default: MAILER-DAEMON)</b></DT><DD>
2547 1.1 tron
2548 1.1 tron <p>
2549 1.1 tron The recipient of mail addressed to the null address. Postfix does
2550 1.1 tron not accept such addresses in SMTP commands, but they may still be
2551 1.1 tron created locally as the result of configuration or software error.
2552 1.1 tron </p>
2553 1.1 tron
2554 1.1 tron
2555 1.1 tron </DD>
2556 1.1 tron
2557 1.1 tron <DT><b><a name="empty_address_relayhost_maps_lookup_key">empty_address_relayhost_maps_lookup_key</a>
2558 1.1 tron (default: <>)</b></DT><DD>
2559 1.1 tron
2560 1.1 tron <p> The <a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a> search string that will be
2561 1.1 tron used instead of the null sender address. </p>
2562 1.1 tron
2563 1.1 tron <p> This feature is available in Postfix 2.5 and later. With
2564 1.1 tron earlier versions, <a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a> lookups were
2565 1.1 tron skipped for the null sender address. </p>
2566 1.1 tron
2567 1.1 tron
2568 1.1 tron </DD>
2569 1.1 tron
2570 1.1 tron <DT><b><a name="enable_errors_to">enable_errors_to</a>
2571 1.1 tron (default: no)</b></DT><DD>
2572 1.1 tron
2573 1.1 tron <p> Report mail delivery errors to the address specified with the
2574 1.1 tron non-standard Errors-To: message header, instead of the envelope
2575 1.1 tron sender address (this feature is removed with Postfix version 2.2, is
2576 1.1 tron turned off by default with Postfix version 2.1, and is always turned on
2577 1.1 tron with older Postfix versions). </p>
2578 1.1 tron
2579 1.1 tron
2580 1.1 tron </DD>
2581 1.1 tron
2582 1.1 tron <DT><b><a name="enable_original_recipient">enable_original_recipient</a>
2583 1.1 tron (default: yes)</b></DT><DD>
2584 1.1 tron
2585 1.1 tron <p> Enable support for the X-Original-To message header. This header
2586 1.1 tron is needed for multi-recipient mailboxes. </p>
2587 1.1 tron
2588 1.1 tron <p> When this parameter is set to yes, the <a href="cleanup.8.html">cleanup(8)</a> daemon performs
2589 1.1 tron duplicate elimination on distinct pairs of (original recipient,
2590 1.1 tron rewritten recipient), and generates non-empty original recipient
2591 1.1 tron queue file records. </p>
2592 1.1 tron
2593 1.1 tron <p> When this parameter is set to no, the <a href="cleanup.8.html">cleanup(8)</a> daemon performs
2594 1.1 tron duplicate elimination on the rewritten recipient address only, and
2595 1.1 tron generates empty original recipient queue file records. </p>
2596 1.1 tron
2597 1.1 tron <p> This feature is available in Postfix 2.1 and later. With Postfix
2598 1.1 tron version 2.0, support for the X-Original-To message header is always turned
2599 1.1 tron on. Postfix versions before 2.0 have no support for the X-Original-To
2600 1.1 tron message header. </p>
2601 1.1 tron
2602 1.1 tron
2603 1.1 tron </DD>
2604 1.1 tron
2605 1.1 tron <DT><b><a name="error_notice_recipient">error_notice_recipient</a>
2606 1.1 tron (default: postmaster)</b></DT><DD>
2607 1.1 tron
2608 1.1 tron <p> The recipient of postmaster notifications about mail delivery
2609 1.1 tron problems that are caused by policy, resource, software or protocol
2610 1.1 tron errors. These notifications are enabled with the <a href="postconf.5.html#notify_classes">notify_classes</a>
2611 1.1 tron parameter. </p>
2612 1.1 tron
2613 1.1 tron
2614 1.1 tron </DD>
2615 1.1 tron
2616 1.1 tron <DT><b><a name="error_service_name">error_service_name</a>
2617 1.1 tron (default: error)</b></DT><DD>
2618 1.1 tron
2619 1.1 tron <p>
2620 1.1 tron The name of the <a href="error.8.html">error(8)</a> pseudo delivery agent. This service always
2621 1.1 tron returns mail as undeliverable.
2622 1.1 tron </p>
2623 1.1 tron
2624 1.1 tron <p>
2625 1.1 tron This feature is available in Postfix 2.0 and later.
2626 1.1 tron </p>
2627 1.1 tron
2628 1.1 tron
2629 1.1 tron </DD>
2630 1.1 tron
2631 1.1 tron <DT><b><a name="execution_directory_expansion_filter">execution_directory_expansion_filter</a>
2632 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
2633 1.1 tron
2634 1.1 tron <p> Restrict the characters that the <a href="local.8.html">local(8)</a> delivery agent allows
2635 1.1 tron in $name expansions of $<a href="postconf.5.html#command_execution_directory">command_execution_directory</a>. Characters
2636 1.1 tron outside the allowed set are replaced by underscores. </p>
2637 1.1 tron
2638 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
2639 1.1 tron
2640 1.1 tron
2641 1.1 tron </DD>
2642 1.1 tron
2643 1.1 tron <DT><b><a name="expand_owner_alias">expand_owner_alias</a>
2644 1.1 tron (default: no)</b></DT><DD>
2645 1.1 tron
2646 1.1 tron <p>
2647 1.1 tron When delivering to an alias "aliasname" that has an "owner-aliasname"
2648 1.1 tron companion alias, set the envelope sender address to the expansion
2649 1.1 tron of the "owner-aliasname" alias. Normally, Postfix sets the envelope
2650 1.1 tron sender address to the name of the "owner-aliasname" alias.
2651 1.1 tron </p>
2652 1.1 tron
2653 1.1 tron
2654 1.1 tron </DD>
2655 1.1 tron
2656 1.1 tron <DT><b><a name="export_environment">export_environment</a>
2657 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
2658 1.1 tron
2659 1.1 tron <p>
2660 1.1 tron The list of environment variables that a Postfix process will export
2661 1.1 tron to non-Postfix processes. The TZ variable is needed for sane
2662 1.1 tron time keeping on System-V-ish systems.
2663 1.1 tron </p>
2664 1.1 tron
2665 1.1 tron <p>
2666 1.1 tron Specify a list of names and/or name=value pairs, separated by
2667 1.1 tron whitespace or comma. The name=value form is supported with
2668 1.1 tron Postfix version 2.1 and later.
2669 1.1 tron </p>
2670 1.1 tron
2671 1.1 tron <p>
2672 1.1 tron Example:
2673 1.1 tron </p>
2674 1.1 tron
2675 1.1 tron <pre>
2676 1.1 tron <a href="postconf.5.html#export_environment">export_environment</a> = TZ PATH=/bin:/usr/bin
2677 1.1 tron </pre>
2678 1.1 tron
2679 1.1 tron
2680 1.1 tron </DD>
2681 1.1 tron
2682 1.1 tron <DT><b><a name="extract_recipient_limit">extract_recipient_limit</a>
2683 1.1 tron (default: 10240)</b></DT><DD>
2684 1.1 tron
2685 1.1 tron <p>
2686 1.1 tron The maximal number of recipient addresses that Postfix will extract
2687 1.1 tron from message headers when mail is submitted with "<b>sendmail -t</b>".
2688 1.1 tron </p>
2689 1.1 tron
2690 1.1 tron <p>
2691 1.1 tron This feature was removed in Postfix version 2.1.
2692 1.1 tron </p>
2693 1.1 tron
2694 1.1 tron
2695 1.1 tron </DD>
2696 1.1 tron
2697 1.1 tron <DT><b><a name="fallback_relay">fallback_relay</a>
2698 1.1 tron (default: empty)</b></DT><DD>
2699 1.1 tron
2700 1.1 tron <p>
2701 1.1 tron Optional list of relay hosts for SMTP destinations that can't be
2702 1.1 tron found or that are unreachable. With Postfix 2.3 this parameter
2703 1.1 tron is renamed to <a href="postconf.5.html#smtp_fallback_relay">smtp_fallback_relay</a>. </p>
2704 1.1 tron
2705 1.1 tron <p>
2706 1.1 tron By default, mail is returned to the sender when a destination is
2707 1.1 tron not found, and delivery is deferred when a destination is unreachable.
2708 1.1 tron </p>
2709 1.1 tron
2710 1.1 tron <p> The fallback relays must be SMTP destinations. Specify a domain,
2711 1.1 tron host, host:port, [host]:port, [address] or [address]:port; the form
2712 1.1 tron [host] turns off MX lookups. If you specify multiple SMTP
2713 1.1 tron destinations, Postfix will try them in the specified order. </p>
2714 1.1 tron
2715 1.1 tron <p> Note: before Postfix 2.2, do not use the <a href="postconf.5.html#fallback_relay">fallback_relay</a> feature
2716 1.1 tron when relaying mail
2717 1.1 tron for a backup or primary MX domain. Mail would loop between the
2718 1.1 tron Postfix MX host and the <a href="postconf.5.html#fallback_relay">fallback_relay</a> host when the final destination
2719 1.1 tron is unavailable. </p>
2720 1.1 tron
2721 1.1 tron <ul>
2722 1.1 tron
2723 1.1 tron <li> In <a href="postconf.5.html">main.cf</a> specify "<a href="postconf.5.html#relay_transport">relay_transport</a> = relay",
2724 1.1 tron
2725 1.1 tron <li> In <a href="master.5.html">master.cf</a> specify "-o <a href="postconf.5.html#fallback_relay">fallback_relay</a> =" (i.e., empty) at
2726 1.1 tron the end of the <tt>relay</tt> entry.
2727 1.1 tron
2728 1.1 tron <li> In transport maps, specify "relay:<i>nexthop...</i>"
2729 1.1 tron as the right-hand side for backup or primary MX domain entries.
2730 1.1 tron
2731 1.1 tron </ul>
2732 1.1 tron
2733 1.1 tron <p> Postfix version 2.2 and later will not use the <a href="postconf.5.html#fallback_relay">fallback_relay</a> feature
2734 1.1 tron for destinations that it is MX host for.
2735 1.1 tron </p>
2736 1.1 tron
2737 1.1 tron
2738 1.1 tron </DD>
2739 1.1 tron
2740 1.1 tron <DT><b><a name="fallback_transport">fallback_transport</a>
2741 1.1 tron (default: empty)</b></DT><DD>
2742 1.1 tron
2743 1.1 tron <p>
2744 1.1 tron Optional message delivery transport that the <a href="local.8.html">local(8)</a> delivery
2745 1.1 tron agent should use for names that are not found in the <a href="aliases.5.html">aliases(5)</a>
2746 1.1 tron or UNIX password database.
2747 1.1 tron </p>
2748 1.1 tron
2749 1.1 tron <p> The precedence of <a href="local.8.html">local(8)</a> delivery features from high to low
2750 1.1 tron is: aliases, .forward files, <a href="postconf.5.html#mailbox_transport_maps">mailbox_transport_maps</a>, <a href="postconf.5.html#mailbox_transport">mailbox_transport</a>,
2751 1.1 tron <a href="postconf.5.html#mailbox_command_maps">mailbox_command_maps</a>, <a href="postconf.5.html#mailbox_command">mailbox_command</a>, <a href="postconf.5.html#home_mailbox">home_mailbox</a>, <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a>,
2752 1.1 tron <a href="postconf.5.html#fallback_transport_maps">fallback_transport_maps</a>, <a href="postconf.5.html#fallback_transport">fallback_transport</a> and <a href="postconf.5.html#luser_relay">luser_relay</a>. </p>
2753 1.1 tron
2754 1.1 tron
2755 1.1 tron </DD>
2756 1.1 tron
2757 1.1 tron <DT><b><a name="fallback_transport_maps">fallback_transport_maps</a>
2758 1.1 tron (default: empty)</b></DT><DD>
2759 1.1 tron
2760 1.1 tron <p> Optional lookup tables with per-recipient message delivery
2761 1.1 tron transports for recipients that the <a href="local.8.html">local(8)</a> delivery agent could
2762 1.1 tron not find in the <a href="aliases.5.html">aliases(5)</a> or UNIX password database. </p>
2763 1.1 tron
2764 1.1 tron <p> The precedence of <a href="local.8.html">local(8)</a> delivery features from high to low
2765 1.1 tron is: aliases, .forward files, <a href="postconf.5.html#mailbox_transport_maps">mailbox_transport_maps</a>, <a href="postconf.5.html#mailbox_transport">mailbox_transport</a>,
2766 1.1 tron <a href="postconf.5.html#mailbox_command_maps">mailbox_command_maps</a>, <a href="postconf.5.html#mailbox_command">mailbox_command</a>, <a href="postconf.5.html#home_mailbox">home_mailbox</a>, <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a>,
2767 1.1 tron <a href="postconf.5.html#fallback_transport_maps">fallback_transport_maps</a>, <a href="postconf.5.html#fallback_transport">fallback_transport</a> and <a href="postconf.5.html#luser_relay">luser_relay</a>. </p>
2768 1.1 tron
2769 1.1 tron <p> For safety reasons, this feature does not allow $number
2770 1.1 tron substitutions in regular expression maps. </p>
2771 1.1 tron
2772 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
2773 1.1 tron
2774 1.1 tron
2775 1.1 tron </DD>
2776 1.1 tron
2777 1.1 tron <DT><b><a name="fast_flush_domains">fast_flush_domains</a>
2778 1.1 tron (default: $<a href="postconf.5.html#relay_domains">relay_domains</a>)</b></DT><DD>
2779 1.1 tron
2780 1.1 tron <p>
2781 1.1 tron Optional list of destinations that are eligible for per-destination
2782 1.1 tron logfiles with mail that is queued to those destinations.
2783 1.1 tron </p>
2784 1.1 tron
2785 1.1 tron <p>
2786 1.1 tron By default, Postfix maintains "fast flush" logfiles only for
2787 1.1 tron destinations that the Postfix SMTP server is willing to relay to
2788 1.1 tron (i.e. the default is: "<a href="postconf.5.html#fast_flush_domains">fast_flush_domains</a> = $<a href="postconf.5.html#relay_domains">relay_domains</a>"; see
2789 1.1 tron the <a href="postconf.5.html#relay_domains">relay_domains</a> parameter in the <a href="postconf.5.html">postconf(5)</a> manual).
2790 1.1 tron </p>
2791 1.1 tron
2792 1.1 tron <p> Specify a list of hosts or domains, "/file/name" patterns or
2793 1.1 tron "<a href="DATABASE_README.html">type:table</a>" lookup tables, separated by commas and/or whitespace.
2794 1.1 tron Continue long lines by starting the next line with whitespace. A
2795 1.1 tron "/file/name" pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>"
2796 1.1 tron lookup table is matched when the domain or its parent domain appears
2797 1.1 tron as lookup key. </p>
2798 1.1 tron
2799 1.1 tron <p>
2800 1.1 tron Specify "<a href="postconf.5.html#fast_flush_domains">fast_flush_domains</a> =" (i.e., empty) to disable the feature
2801 1.1 tron altogether.
2802 1.1 tron </p>
2803 1.1 tron
2804 1.1 tron
2805 1.1 tron </DD>
2806 1.1 tron
2807 1.1 tron <DT><b><a name="fast_flush_purge_time">fast_flush_purge_time</a>
2808 1.1 tron (default: 7d)</b></DT><DD>
2809 1.1 tron
2810 1.1 tron <p>
2811 1.1 tron The time after which an empty per-destination "fast flush" logfile
2812 1.1 tron is deleted.
2813 1.1 tron </p>
2814 1.1 tron
2815 1.1 tron <p>
2816 1.1 tron You can specify the time as a number, or as a number followed by
2817 1.1 tron a letter that indicates the time unit: s=seconds, m=minutes, h=hours,
2818 1.1 tron d=days, w=weeks. The default time unit is days.
2819 1.1 tron </p>
2820 1.1 tron
2821 1.1 tron
2822 1.1 tron </DD>
2823 1.1 tron
2824 1.1 tron <DT><b><a name="fast_flush_refresh_time">fast_flush_refresh_time</a>
2825 1.1 tron (default: 12h)</b></DT><DD>
2826 1.1 tron
2827 1.1 tron <p>
2828 1.1 tron The time after which a non-empty but unread per-destination "fast
2829 1.1 tron flush" logfile needs to be refreshed. The contents of a logfile
2830 1.1 tron are refreshed by requesting delivery of all messages listed in the
2831 1.1 tron logfile.
2832 1.1 tron </p>
2833 1.1 tron
2834 1.1 tron <p>
2835 1.1 tron You can specify the time as a number, or as a number followed by
2836 1.1 tron a letter that indicates the time unit: s=seconds, m=minutes, h=hours,
2837 1.1 tron d=days, w=weeks. The default time unit is hours.
2838 1.1 tron </p>
2839 1.1 tron
2840 1.1 tron
2841 1.1 tron </DD>
2842 1.1 tron
2843 1.1 tron <DT><b><a name="fault_injection_code">fault_injection_code</a>
2844 1.1 tron (default: 0)</b></DT><DD>
2845 1.1 tron
2846 1.1 tron <p>
2847 1.1 tron Force specific internal tests to fail, to test the handling of
2848 1.1 tron errors that are difficult to reproduce otherwise.
2849 1.1 tron </p>
2850 1.1 tron
2851 1.1 tron
2852 1.1 tron </DD>
2853 1.1 tron
2854 1.1 tron <DT><b><a name="flush_service_name">flush_service_name</a>
2855 1.1 tron (default: flush)</b></DT><DD>
2856 1.1 tron
2857 1.1 tron <p>
2858 1.1 tron The name of the <a href="flush.8.html">flush(8)</a> service. This service maintains per-destination
2859 1.1 tron logfiles with the queue file names of mail that is queued for those
2860 1.1 tron destinations.
2861 1.1 tron </p>
2862 1.1 tron
2863 1.1 tron <p>
2864 1.1 tron This feature is available in Postfix 2.0 and later.
2865 1.1 tron </p>
2866 1.1 tron
2867 1.1 tron
2868 1.1 tron </DD>
2869 1.1 tron
2870 1.1 tron <DT><b><a name="fork_attempts">fork_attempts</a>
2871 1.1 tron (default: 5)</b></DT><DD>
2872 1.1 tron
2873 1.1 tron <p> The maximal number of attempts to fork() a child process. </p>
2874 1.1 tron
2875 1.1 tron
2876 1.1 tron </DD>
2877 1.1 tron
2878 1.1 tron <DT><b><a name="fork_delay">fork_delay</a>
2879 1.1 tron (default: 1s)</b></DT><DD>
2880 1.1 tron
2881 1.1 tron <p> The delay between attempts to fork() a child process. </p>
2882 1.1 tron
2883 1.1 tron <p> Time units: s (seconds), m (minutes), h (hours), d (days), w
2884 1.1 tron (weeks). The default time unit is s (seconds). </p>
2885 1.1 tron
2886 1.1 tron
2887 1.1 tron </DD>
2888 1.1 tron
2889 1.1 tron <DT><b><a name="forward_expansion_filter">forward_expansion_filter</a>
2890 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
2891 1.1 tron
2892 1.1 tron <p>
2893 1.1 tron Restrict the characters that the <a href="local.8.html">local(8)</a> delivery agent allows in
2894 1.1 tron $name expansions of $<a href="postconf.5.html#forward_path">forward_path</a>. Characters outside the
2895 1.1 tron allowed set are replaced by underscores.
2896 1.1 tron </p>
2897 1.1 tron
2898 1.1 tron
2899 1.1 tron </DD>
2900 1.1 tron
2901 1.1 tron <DT><b><a name="forward_path">forward_path</a>
2902 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
2903 1.1 tron
2904 1.1 tron <p> The <a href="local.8.html">local(8)</a> delivery agent search list for finding a .forward
2905 1.1 tron file with user-specified delivery methods. The first file that is
2906 1.1 tron found is used. </p>
2907 1.1 tron
2908 1.1 tron <p> The following $name expansions are done on <a href="postconf.5.html#forward_path">forward_path</a> before
2909 1.1 tron the search actually happens. The result of $name expansion is
2910 1.1 tron filtered with the character set that is specified with the
2911 1.1 tron <a href="postconf.5.html#forward_expansion_filter">forward_expansion_filter</a> parameter. </p>
2912 1.1 tron
2913 1.1 tron <dl>
2914 1.1 tron
2915 1.1 tron <dt><b>$user</b></dt>
2916 1.1 tron
2917 1.1 tron <dd>The recipient's username. </dd>
2918 1.1 tron
2919 1.1 tron <dt><b>$shell</b></dt>
2920 1.1 tron
2921 1.1 tron <dd>The recipient's login shell pathname. </dd>
2922 1.1 tron
2923 1.1 tron <dt><b>$home</b></dt>
2924 1.1 tron
2925 1.1 tron <dd>The recipient's home directory. </dd>
2926 1.1 tron
2927 1.1 tron <dt><b>$recipient</b></dt>
2928 1.1 tron
2929 1.1 tron <dd>The full recipient address. </dd>
2930 1.1 tron
2931 1.1 tron <dt><b>$extension</b></dt>
2932 1.1 tron
2933 1.1 tron <dd>The optional recipient address extension. </dd>
2934 1.1 tron
2935 1.1 tron <dt><b>$domain</b></dt>
2936 1.1 tron
2937 1.1 tron <dd>The recipient domain. </dd>
2938 1.1 tron
2939 1.1 tron <dt><b>$local</b></dt>
2940 1.1 tron
2941 1.1 tron <dd>The entire recipient localpart. </dd>
2942 1.1 tron
2943 1.1 tron <dt><b>$<a href="postconf.5.html#recipient_delimiter">recipient_delimiter</a></b></dt>
2944 1.1 tron
2945 1.1 tron <dd>The system-wide recipient address extension delimiter. </dd>
2946 1.1 tron
2947 1.1 tron <dt><b>${name?value}</b></dt>
2948 1.1 tron
2949 1.1 tron <dd>Expands to <i>value</i> when <i>$name</i> is non-empty. </dd>
2950 1.1 tron
2951 1.1 tron <dt><b>${name:value}</b></dt>
2952 1.1 tron
2953 1.1 tron <dd>Expands to <i>value</i> when <i>$name</i> is empty. </dd>
2954 1.1 tron
2955 1.1 tron </dl>
2956 1.1 tron
2957 1.1 tron <p>
2958 1.1 tron Instead of $name you can also specify ${name} or $(name).
2959 1.1 tron </p>
2960 1.1 tron
2961 1.1 tron <p>
2962 1.1 tron Examples:
2963 1.1 tron </p>
2964 1.1 tron
2965 1.1 tron <pre>
2966 1.1 tron <a href="postconf.5.html#forward_path">forward_path</a> = /var/forward/$user
2967 1.1 tron <a href="postconf.5.html#forward_path">forward_path</a> =
2968 1.1 tron /var/forward/$user/.forward$<a href="postconf.5.html#recipient_delimiter">recipient_delimiter</a>$extension,
2969 1.1 tron /var/forward/$user/.forward
2970 1.1 tron </pre>
2971 1.1 tron
2972 1.1 tron
2973 1.1 tron </DD>
2974 1.1 tron
2975 1.1 tron <DT><b><a name="frozen_delivered_to">frozen_delivered_to</a>
2976 1.1 tron (default: yes)</b></DT><DD>
2977 1.1 tron
2978 1.1 tron <p> Update the <a href="local.8.html">local(8)</a> delivery agent's idea of the Delivered-To:
2979 1.1 tron address (see <a href="postconf.5.html#prepend_delivered_header">prepend_delivered_header</a>) only once, at the start of
2980 1.1 tron a delivery attempt; do not update the Delivered-To: address while
2981 1.1 tron expanding aliases or .forward files. </p>
2982 1.1 tron
2983 1.1 tron <p> This feature is available in Postfix 2.3 and later. With older
2984 1.1 tron Postfix releases, the behavior is as if this parameter is set to
2985 1.1 tron "no". The old setting can be expensive with deeply nested aliases
2986 1.1 tron or .forward files. When an alias or .forward file changes the
2987 1.1 tron Delivered-To: address, it ties up one queue file and one cleanup
2988 1.1 tron process instance while mail is being forwarded. </p>
2989 1.1 tron
2990 1.1 tron
2991 1.1 tron </DD>
2992 1.1 tron
2993 1.1 tron <DT><b><a name="hash_queue_depth">hash_queue_depth</a>
2994 1.1 tron (default: 1)</b></DT><DD>
2995 1.1 tron
2996 1.1 tron <p>
2997 1.1 tron The number of subdirectory levels for queue directories listed with
2998 1.1 tron the <a href="postconf.5.html#hash_queue_names">hash_queue_names</a> parameter.
2999 1.1 tron </p>
3000 1.1 tron
3001 1.1 tron <p>
3002 1.1 tron After changing the <a href="postconf.5.html#hash_queue_names">hash_queue_names</a> or <a href="postconf.5.html#hash_queue_depth">hash_queue_depth</a> parameter,
3003 1.1 tron execute the command "<b>postfix reload</b>".
3004 1.1 tron </p>
3005 1.1 tron
3006 1.1 tron
3007 1.1 tron </DD>
3008 1.1 tron
3009 1.1 tron <DT><b><a name="hash_queue_names">hash_queue_names</a>
3010 1.1 tron (default: deferred, defer)</b></DT><DD>
3011 1.1 tron
3012 1.1 tron <p>
3013 1.1 tron The names of queue directories that are split across multiple
3014 1.1 tron subdirectory levels.
3015 1.1 tron </p>
3016 1.1 tron
3017 1.1 tron <p> Before Postfix version 2.2, the default list of hashed queues
3018 1.1 tron was significantly larger. Claims about improvements in file system
3019 1.1 tron technology suggest that hashing of the <a href="QSHAPE_README.html#incoming_queue">incoming</a> and <a href="QSHAPE_README.html#active_queue">active queues</a>
3020 1.1 tron is no longer needed. Fewer hashed directories speed up the time
3021 1.1 tron needed to restart Postfix. </p>
3022 1.1 tron
3023 1.1 tron <p>
3024 1.1 tron After changing the <a href="postconf.5.html#hash_queue_names">hash_queue_names</a> or <a href="postconf.5.html#hash_queue_depth">hash_queue_depth</a> parameter,
3025 1.1 tron execute the command "<b>postfix reload</b>".
3026 1.1 tron </p>
3027 1.1 tron
3028 1.1 tron
3029 1.1 tron </DD>
3030 1.1 tron
3031 1.1 tron <DT><b><a name="header_address_token_limit">header_address_token_limit</a>
3032 1.1 tron (default: 10240)</b></DT><DD>
3033 1.1 tron
3034 1.1 tron <p>
3035 1.1 tron The maximal number of address tokens are allowed in an address
3036 1.1 tron message header. Information that exceeds the limit is discarded.
3037 1.1 tron The limit is enforced by the <a href="cleanup.8.html">cleanup(8)</a> server.
3038 1.1 tron </p>
3039 1.1 tron
3040 1.1 tron
3041 1.1 tron </DD>
3042 1.1 tron
3043 1.1 tron <DT><b><a name="header_checks">header_checks</a>
3044 1.1 tron (default: empty)</b></DT><DD>
3045 1.1 tron
3046 1.1 tron <p>
3047 1.1 tron Optional lookup tables for content inspection of primary non-MIME
3048 1.1 tron message headers, as specified in the <a href="header_checks.5.html">header_checks(5)</a> manual page.
3049 1.1 tron </p>
3050 1.1 tron
3051 1.1 tron
3052 1.1 tron </DD>
3053 1.1 tron
3054 1.1 tron <DT><b><a name="header_size_limit">header_size_limit</a>
3055 1.1 tron (default: 102400)</b></DT><DD>
3056 1.1 tron
3057 1.1 tron <p>
3058 1.1 tron The maximal amount of memory in bytes for storing a message header.
3059 1.1 tron If a header is larger, the excess is discarded. The limit is
3060 1.1 tron enforced by the <a href="cleanup.8.html">cleanup(8)</a> server.
3061 1.1 tron </p>
3062 1.1 tron
3063 1.1 tron
3064 1.1 tron </DD>
3065 1.1 tron
3066 1.1 tron <DT><b><a name="helpful_warnings">helpful_warnings</a>
3067 1.1 tron (default: yes)</b></DT><DD>
3068 1.1 tron
3069 1.1 tron <p>
3070 1.1 tron Log warnings about problematic configuration settings, and provide
3071 1.1 tron helpful suggestions.
3072 1.1 tron </p>
3073 1.1 tron
3074 1.1 tron <p>
3075 1.1 tron This feature is available in Postfix 2.0 and later.
3076 1.1 tron </p>
3077 1.1 tron
3078 1.1 tron
3079 1.1 tron </DD>
3080 1.1 tron
3081 1.1 tron <DT><b><a name="home_mailbox">home_mailbox</a>
3082 1.1 tron (default: empty)</b></DT><DD>
3083 1.1 tron
3084 1.1 tron <p>
3085 1.1 tron Optional pathname of a mailbox file relative to a <a href="local.8.html">local(8)</a> user's
3086 1.1 tron home directory.
3087 1.1 tron </p>
3088 1.1 tron
3089 1.1 tron <p>
3090 1.1 tron Specify a pathname ending in "/" for qmail-style delivery.
3091 1.1 tron </p>
3092 1.1 tron
3093 1.1 tron <p> The precedence of <a href="local.8.html">local(8)</a> delivery features from high to low
3094 1.1 tron is: aliases, .forward files, <a href="postconf.5.html#mailbox_transport_maps">mailbox_transport_maps</a>, <a href="postconf.5.html#mailbox_transport">mailbox_transport</a>,
3095 1.1 tron <a href="postconf.5.html#mailbox_command_maps">mailbox_command_maps</a>, <a href="postconf.5.html#mailbox_command">mailbox_command</a>, <a href="postconf.5.html#home_mailbox">home_mailbox</a>, <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a>,
3096 1.1 tron <a href="postconf.5.html#fallback_transport_maps">fallback_transport_maps</a>, <a href="postconf.5.html#fallback_transport">fallback_transport</a> and <a href="postconf.5.html#luser_relay">luser_relay</a>. </p>
3097 1.1 tron
3098 1.1 tron <p>
3099 1.1 tron Examples:
3100 1.1 tron </p>
3101 1.1 tron
3102 1.1 tron <pre>
3103 1.1 tron <a href="postconf.5.html#home_mailbox">home_mailbox</a> = Mailbox
3104 1.1 tron <a href="postconf.5.html#home_mailbox">home_mailbox</a> = Maildir/
3105 1.1 tron </pre>
3106 1.1 tron
3107 1.1 tron
3108 1.1 tron </DD>
3109 1.1 tron
3110 1.1 tron <DT><b><a name="hopcount_limit">hopcount_limit</a>
3111 1.1 tron (default: 50)</b></DT><DD>
3112 1.1 tron
3113 1.1 tron <p>
3114 1.1 tron The maximal number of Received: message headers that is allowed
3115 1.1 tron in the primary message headers. A message that exceeds the limit
3116 1.1 tron is bounced, in order to stop a mailer loop.
3117 1.1 tron </p>
3118 1.1 tron
3119 1.1 tron
3120 1.1 tron </DD>
3121 1.1 tron
3122 1.1 tron <DT><b><a name="html_directory">html_directory</a>
3123 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
3124 1.1 tron
3125 1.1 tron <p>
3126 1.1 tron The location of Postfix HTML files that describe how to build,
3127 1.1 tron configure or operate a specific Postfix subsystem or feature.
3128 1.1 tron </p>
3129 1.1 tron
3130 1.1 tron
3131 1.1 tron </DD>
3132 1.1 tron
3133 1.1 tron <DT><b><a name="ignore_mx_lookup_error">ignore_mx_lookup_error</a>
3134 1.1 tron (default: no)</b></DT><DD>
3135 1.1 tron
3136 1.1 tron <p> Ignore DNS MX lookups that produce no response. By default,
3137 1.1 tron the Postfix SMTP client defers delivery and tries again after some
3138 1.1 tron delay. This behavior is required by the SMTP standard. </p>
3139 1.1 tron
3140 1.1 tron <p>
3141 1.1 tron Specify "<a href="postconf.5.html#ignore_mx_lookup_error">ignore_mx_lookup_error</a> = yes" to force a DNS A record
3142 1.1 tron lookup instead. This violates the SMTP standard and can result in
3143 1.1 tron mis-delivery of mail.
3144 1.1 tron </p>
3145 1.1 tron
3146 1.1 tron
3147 1.1 tron </DD>
3148 1.1 tron
3149 1.1 tron <DT><b><a name="import_environment">import_environment</a>
3150 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
3151 1.1 tron
3152 1.1 tron <p>
3153 1.1 tron The list of environment parameters that a Postfix process will
3154 1.1 tron import from a non-Postfix parent process. Examples of relevant
3155 1.1 tron parameters:
3156 1.1 tron </p>
3157 1.1 tron
3158 1.1 tron <dl>
3159 1.1 tron
3160 1.1 tron <dt><b>TZ</b></dt>
3161 1.1 tron
3162 1.1 tron <dd>Needed for sane time keeping on most System-V-ish systems. </dd>
3163 1.1 tron
3164 1.1 tron <dt><b>DISPLAY</b></dt>
3165 1.1 tron
3166 1.1 tron <dd>Needed for debugging Postfix daemons with an X-windows debugger. </dd>
3167 1.1 tron
3168 1.1 tron <dt><b>XAUTHORITY</b></dt>
3169 1.1 tron
3170 1.1 tron <dd>Needed for debugging Postfix daemons with an X-windows debugger. </dd>
3171 1.1 tron
3172 1.1 tron <dt><b>MAIL_CONFIG</b></dt>
3173 1.1 tron
3174 1.1 tron <dd>Needed to make "<b>postfix -c</b>" work. </dd>
3175 1.1 tron
3176 1.1 tron </dl>
3177 1.1 tron
3178 1.1 tron <p> Specify a list of names and/or name=value pairs, separated by
3179 1.1 tron whitespace or comma. The name=value form is supported with
3180 1.1 tron Postfix version 2.1 and later. </p>
3181 1.1 tron
3182 1.1 tron
3183 1.1 tron </DD>
3184 1.1 tron
3185 1.1 tron <DT><b><a name="in_flow_delay">in_flow_delay</a>
3186 1.1 tron (default: 1s)</b></DT><DD>
3187 1.1 tron
3188 1.1 tron <p> Time to pause before accepting a new message, when the message
3189 1.1 tron arrival rate exceeds the message delivery rate. This feature is
3190 1.1 tron turned on by default (it's disabled on SCO UNIX due to an SCO bug).
3191 1.1 tron </p>
3192 1.1 tron
3193 1.1 tron <p>
3194 1.1 tron With the default 100 SMTP server process limit, "<a href="postconf.5.html#in_flow_delay">in_flow_delay</a>
3195 1.1 tron = 1s" limits the mail inflow to 100 messages per second above the
3196 1.1 tron number of messages delivered per second.
3197 1.1 tron </p>
3198 1.1 tron
3199 1.1 tron <p>
3200 1.1 tron Specify 0 to disable the feature. Valid delays are 0..10.
3201 1.1 tron </p>
3202 1.1 tron
3203 1.1 tron
3204 1.1 tron </DD>
3205 1.1 tron
3206 1.1 tron <DT><b><a name="inet_interfaces">inet_interfaces</a>
3207 1.1 tron (default: all)</b></DT><DD>
3208 1.1 tron
3209 1.1 tron <p> The network interface addresses that this mail system receives
3210 1.1 tron mail on. Specify "all" to receive mail on all network
3211 1.1 tron interfaces (default), and "loopback-only" to receive mail
3212 1.1 tron on loopback network interfaces only (Postfix version 2.2 and later). The
3213 1.1 tron parameter also controls delivery of mail to <tt>user@[ip.address]</tt>.
3214 1.1 tron </p>
3215 1.1 tron
3216 1.1 tron <p>
3217 1.1 tron Note 1: you need to stop and start Postfix when this parameter changes.
3218 1.1 tron </p>
3219 1.1 tron
3220 1.1 tron <p> Note 2: address information may be enclosed inside <tt>[]</tt>,
3221 1.1 tron but this form is not required here. </p>
3222 1.1 tron
3223 1.1 tron <p> When <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> specifies just one IPv4 and/or IPv6 address
3224 1.1 tron that is not a loopback address, the Postfix SMTP client will use
3225 1.1 tron this address as the IP source address for outbound mail. Support
3226 1.1 tron for IPv6 is available in Postfix version 2.2 and later. </p>
3227 1.1 tron
3228 1.1 tron <p>
3229 1.1 tron On a multi-homed firewall with separate Postfix instances listening on the
3230 1.1 tron "inside" and "outside" interfaces, this can prevent each instance from
3231 1.1 tron being able to reach servers on the "other side" of the firewall. Setting
3232 1.1 tron <a href="postconf.5.html#smtp_bind_address">smtp_bind_address</a> to 0.0.0.0 avoids the potential problem for
3233 1.1 tron IPv4, and setting <a href="postconf.5.html#smtp_bind_address6">smtp_bind_address6</a> to :: solves the problem
3234 1.1 tron for IPv6. </p>
3235 1.1 tron
3236 1.1 tron <p>
3237 1.1 tron A better solution for multi-homed firewalls is to leave <a href="postconf.5.html#inet_interfaces">inet_interfaces</a>
3238 1.1 tron at the default value and instead use explicit IP addresses in
3239 1.1 tron the <a href="master.5.html">master.cf</a> SMTP server definitions. This preserves the Postfix
3240 1.1 tron SMTP client's
3241 1.1 tron loop detection, by ensuring that each side of the firewall knows that the
3242 1.1 tron other IP address is still the same host. Setting $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a> to a
3243 1.1 tron single IPv4 and/or IPV6 address is primarily useful with virtual
3244 1.1 tron hosting of domains on
3245 1.1 tron secondary IP addresses, when each IP address serves a different domain
3246 1.1 tron (and has a different $<a href="postconf.5.html#myhostname">myhostname</a> setting). </p>
3247 1.1 tron
3248 1.1 tron <p>
3249 1.1 tron See also the <a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a> parameter, for network addresses that
3250 1.1 tron are forwarded to Postfix by way of a proxy or address translator.
3251 1.1 tron </p>
3252 1.1 tron
3253 1.1 tron <p>
3254 1.1 tron Examples:
3255 1.1 tron </p>
3256 1.1 tron
3257 1.1 tron <pre>
3258 1.1 tron <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> = all (DEFAULT)
3259 1.1 tron <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> = loopback-only (Postfix version 2.2 and later)
3260 1.1 tron <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> = 127.0.0.1
3261 1.1 tron <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> = 127.0.0.1, [::1] (Postfix version 2.2 and later)
3262 1.1 tron <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> = 192.168.1.2, 127.0.0.1
3263 1.1 tron </pre>
3264 1.1 tron
3265 1.1 tron
3266 1.1 tron </DD>
3267 1.1 tron
3268 1.1 tron <DT><b><a name="inet_protocols">inet_protocols</a>
3269 1.1 tron (default: ipv4)</b></DT><DD>
3270 1.1 tron
3271 1.1 tron <p> The Internet protocols Postfix will attempt to use when making
3272 1.1 tron or accepting connections. Specify one or more of "ipv4"
3273 1.1 tron or "ipv6", separated by whitespace or commas. The form
3274 1.1 tron "all" is equivalent to "ipv4, ipv6" or "ipv4", depending
3275 1.1 tron on whether the operating system implements IPv6. </p>
3276 1.1 tron
3277 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
3278 1.1 tron
3279 1.1 tron <p> Note: you MUST stop and start Postfix after changing this
3280 1.1 tron parameter. </p>
3281 1.1 tron
3282 1.1 tron <p> On systems that pre-date IPV6_V6ONLY support (<a href="http://tools.ietf.org/html/rfc3493">RFC 3493</a>), an
3283 1.1 tron IPv6 server will also accept IPv4 connections, even when IPv4 is
3284 1.1 tron turned off with the <a href="postconf.5.html#inet_protocols">inet_protocols</a> parameter. On systems with
3285 1.1 tron IPV6_V6ONLY support, Postfix will use separate server sockets for
3286 1.1 tron IPv6 and IPv4, and each will accept only connections for the
3287 1.1 tron corresponding protocol. </p>
3288 1.1 tron
3289 1.1 tron <p> When IPv4 support is enabled via the <a href="postconf.5.html#inet_protocols">inet_protocols</a> parameter,
3290 1.1 tron Postfix will to DNS type A record lookups, and will convert
3291 1.1 tron IPv4-in-IPv6 client IP addresses (::ffff:1.2.3.4) to their original
3292 1.1 tron IPv4 form (1.2.3.4). The latter is needed on hosts that pre-date
3293 1.1 tron IPV6_V6ONLY support (<a href="http://tools.ietf.org/html/rfc3493">RFC 3493</a>). </p>
3294 1.1 tron
3295 1.1 tron <p> When IPv6 support is enabled via the <a href="postconf.5.html#inet_protocols">inet_protocols</a> parameter,
3296 1.1 tron Postfix will do DNS type AAAA record lookups. </p>
3297 1.1 tron
3298 1.1 tron <p> When both IPv4 and IPv6 support are enabled, the Postfix SMTP
3299 1.1 tron client will attempt to connect via IPv6 before attempting to use
3300 1.1 tron IPv4. </p>
3301 1.1 tron
3302 1.1 tron <p>
3303 1.1 tron Examples:
3304 1.1 tron </p>
3305 1.1 tron
3306 1.1 tron <pre>
3307 1.1 tron <a href="postconf.5.html#inet_protocols">inet_protocols</a> = ipv4 (DEFAULT)
3308 1.1 tron <a href="postconf.5.html#inet_protocols">inet_protocols</a> = all
3309 1.1 tron <a href="postconf.5.html#inet_protocols">inet_protocols</a> = ipv6
3310 1.1 tron <a href="postconf.5.html#inet_protocols">inet_protocols</a> = ipv4, ipv6
3311 1.1 tron </pre>
3312 1.1 tron
3313 1.1 tron
3314 1.1 tron </DD>
3315 1.1 tron
3316 1.1 tron <DT><b><a name="initial_destination_concurrency">initial_destination_concurrency</a>
3317 1.1 tron (default: 5)</b></DT><DD>
3318 1.1 tron
3319 1.1 tron <p>
3320 1.1 tron The initial per-destination concurrency level for parallel delivery
3321 1.1 tron to the same destination.
3322 1.1 tron With per-destination recipient limit > 1, a destination is a domain,
3323 1.1 tron otherwise it is a recipient.
3324 1.1 tron </p>
3325 1.1 tron
3326 1.1 tron <p> Use <a href="postconf.5.html#transport_initial_destination_concurrency"><i>transport</i>_initial_destination_concurrency</a> to specify
3327 1.1 tron a transport-specific override, where <i>transport</i> is the <a href="master.5.html">master.cf</a>
3328 1.1 tron name of the message delivery transport (Postfix 2.5 and later). </p>
3329 1.1 tron
3330 1.1 tron <p>
3331 1.1 tron Warning: with concurrency of 1, one bad message can be enough to
3332 1.1 tron block all mail to a site.
3333 1.1 tron </p>
3334 1.1 tron
3335 1.1 tron
3336 1.1 tron </DD>
3337 1.1 tron
3338 1.1 tron <DT><b><a name="internal_mail_filter_classes">internal_mail_filter_classes</a>
3339 1.1 tron (default: empty)</b></DT><DD>
3340 1.1 tron
3341 1.1 tron <p> What categories of Postfix-generated mail are subject to
3342 1.1 tron before-queue content inspection by <a href="postconf.5.html#non_smtpd_milters">non_smtpd_milters</a>, <a href="postconf.5.html#header_checks">header_checks</a>
3343 1.1 tron and <a href="postconf.5.html#body_checks">body_checks</a>. Specify zero or more of the following, separated
3344 1.1 tron by whitespace or comma. </p>
3345 1.1 tron
3346 1.1 tron <dl>
3347 1.1 tron
3348 1.1 tron <dt><b>bounce</b></dt> <dd> Inspect the content of delivery
3349 1.1 tron status notifications. </dd>
3350 1.1 tron
3351 1.1 tron <dt><b>notify</b></dt> <dd> Inspect the content of postmaster
3352 1.1 tron notifications by the <a href="smtp.8.html">smtp(8)</a> and <a href="smtpd.8.html">smtpd(8)</a> processes. </dd>
3353 1.1 tron
3354 1.1 tron </dl>
3355 1.1 tron
3356 1.1 tron <p> NOTE: It's generally not safe to enable content inspection of
3357 1.1 tron Postfix-generated email messages. The user is warned. </p>
3358 1.1 tron
3359 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3360 1.1 tron
3361 1.1 tron
3362 1.1 tron </DD>
3363 1.1 tron
3364 1.1 tron <DT><b><a name="invalid_hostname_reject_code">invalid_hostname_reject_code</a>
3365 1.1 tron (default: 501)</b></DT><DD>
3366 1.1 tron
3367 1.1 tron <p>
3368 1.1 tron The numerical Postfix SMTP server response code when the client
3369 1.1 tron HELO or EHLO command parameter is rejected by the <a href="postconf.5.html#reject_invalid_helo_hostname">reject_invalid_helo_hostname</a>
3370 1.1 tron restriction.
3371 1.1 tron </p>
3372 1.1 tron
3373 1.1 tron <p>
3374 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
3375 1.1 tron </p>
3376 1.1 tron
3377 1.1 tron
3378 1.1 tron </DD>
3379 1.1 tron
3380 1.1 tron <DT><b><a name="ipc_idle">ipc_idle</a>
3381 1.1 tron (default: version dependent)</b></DT><DD>
3382 1.1 tron
3383 1.1 tron <p>
3384 1.1 tron The time after which a client closes an idle internal communication
3385 1.1 tron channel. The purpose is to allow servers to terminate voluntarily
3386 1.1 tron after they become idle. This is used, for example, by the address
3387 1.1 tron resolving and rewriting clients.
3388 1.1 tron </p>
3389 1.1 tron
3390 1.1 tron <p> With Postfix 2.4 the default value was reduced from 100s to 5s. </p>
3391 1.1 tron
3392 1.1 tron <p>
3393 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3394 1.1 tron The default time unit is s (seconds).
3395 1.1 tron </p>
3396 1.1 tron
3397 1.1 tron
3398 1.1 tron </DD>
3399 1.1 tron
3400 1.1 tron <DT><b><a name="ipc_timeout">ipc_timeout</a>
3401 1.1 tron (default: 3600s)</b></DT><DD>
3402 1.1 tron
3403 1.1 tron <p>
3404 1.1 tron The time limit for sending or receiving information over an internal
3405 1.1 tron communication channel. The purpose is to break out of deadlock
3406 1.1 tron situations. If the time limit is exceeded the software aborts with a
3407 1.1 tron fatal error.
3408 1.1 tron </p>
3409 1.1 tron
3410 1.1 tron <p>
3411 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3412 1.1 tron The default time unit is s (seconds).
3413 1.1 tron </p>
3414 1.1 tron
3415 1.1 tron
3416 1.1 tron </DD>
3417 1.1 tron
3418 1.1 tron <DT><b><a name="ipc_ttl">ipc_ttl</a>
3419 1.1 tron (default: 1000s)</b></DT><DD>
3420 1.1 tron
3421 1.1 tron <p>
3422 1.1 tron The time after which a client closes an active internal communication
3423 1.1 tron channel. The purpose is to allow servers to terminate voluntarily
3424 1.1 tron after reaching their client limit. This is used, for example, by
3425 1.1 tron the address resolving and rewriting clients.
3426 1.1 tron </p>
3427 1.1 tron
3428 1.1 tron <p>
3429 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3430 1.1 tron The default time unit is s (seconds).
3431 1.1 tron </p>
3432 1.1 tron
3433 1.1 tron <p>
3434 1.1 tron This feature is available in Postfix 2.1 and later.
3435 1.1 tron </p>
3436 1.1 tron
3437 1.1 tron
3438 1.1 tron </DD>
3439 1.1 tron
3440 1.1 tron <DT><b><a name="line_length_limit">line_length_limit</a>
3441 1.1 tron (default: 2048)</b></DT><DD>
3442 1.1 tron
3443 1.1 tron <p> Upon input, long lines are chopped up into pieces of at most
3444 1.1 tron this length; upon delivery, long lines are reconstructed. </p>
3445 1.1 tron
3446 1.1 tron
3447 1.1 tron </DD>
3448 1.1 tron
3449 1.1 tron <DT><b><a name="lmtp_assume_final">lmtp_assume_final</a>
3450 1.1 tron (default: no)</b></DT><DD>
3451 1.1 tron
3452 1.1 tron <p> When an LMTP server announces no DSN support, assume that the
3453 1.1 tron server performs final delivery, and send "delivered" delivery status
3454 1.1 tron notifications instead of "relayed". The default setting is backwards
3455 1.1 tron compatible to avoid the infinetisimal possibility of breaking
3456 1.1 tron existing LMTP-based content filters. </p>
3457 1.1 tron
3458 1.1 tron
3459 1.1 tron </DD>
3460 1.1 tron
3461 1.1 tron <DT><b><a name="lmtp_bind_address">lmtp_bind_address</a>
3462 1.1 tron (default: empty)</b></DT><DD>
3463 1.1 tron
3464 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_bind_address">smtp_bind_address</a> configuration
3465 1.1 tron parameter. See there for details. </p>
3466 1.1 tron
3467 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3468 1.1 tron
3469 1.1 tron
3470 1.1 tron </DD>
3471 1.1 tron
3472 1.1 tron <DT><b><a name="lmtp_bind_address6">lmtp_bind_address6</a>
3473 1.1 tron (default: empty)</b></DT><DD>
3474 1.1 tron
3475 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_bind_address6">smtp_bind_address6</a> configuration
3476 1.1 tron parameter. See there for details. </p>
3477 1.1 tron
3478 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3479 1.1 tron
3480 1.1 tron
3481 1.1 tron </DD>
3482 1.1 tron
3483 1.1 tron <DT><b><a name="lmtp_cache_connection">lmtp_cache_connection</a>
3484 1.1 tron (default: yes)</b></DT><DD>
3485 1.1 tron
3486 1.1 tron <p>
3487 1.1 tron Keep Postfix LMTP client connections open for up to $<a href="postconf.5.html#max_idle">max_idle</a>
3488 1.1 tron seconds. When the LMTP client receives a request for the same
3489 1.1 tron connection the connection is reused.
3490 1.1 tron </p>
3491 1.1 tron
3492 1.1 tron <p> This parameter is available in Postfix version 2.2 and earlier.
3493 1.1 tron With Postfix version 2.3 and later, see <a href="postconf.5.html#lmtp_connection_cache_on_demand">lmtp_connection_cache_on_demand</a>,
3494 1.1 tron <a href="postconf.5.html#lmtp_connection_cache_destinations">lmtp_connection_cache_destinations</a>, or <a href="postconf.5.html#lmtp_connection_reuse_time_limit">lmtp_connection_reuse_time_limit</a>.
3495 1.1 tron </p>
3496 1.1 tron
3497 1.1 tron <p>
3498 1.1 tron The effectiveness of cached connections will be determined by the
3499 1.1 tron number of LMTP servers in use, and the concurrency limit specified
3500 1.1 tron for the LMTP client. Cached connections are closed under any of
3501 1.1 tron the following conditions:
3502 1.1 tron </p>
3503 1.1 tron
3504 1.1 tron <ul>
3505 1.1 tron
3506 1.1 tron <li> The LMTP client idle time limit is reached. This limit is
3507 1.1 tron specified with the Postfix <a href="postconf.5.html#max_idle">max_idle</a> configuration parameter.
3508 1.1 tron
3509 1.1 tron <li> A delivery request specifies a different destination than the
3510 1.1 tron one currently cached.
3511 1.1 tron
3512 1.1 tron <li> The per-process limit on the number of delivery requests is
3513 1.1 tron reached. This limit is specified with the Postfix <a href="postconf.5.html#max_use">max_use</a>
3514 1.1 tron configuration parameter.
3515 1.1 tron
3516 1.1 tron <li> Upon the onset of another delivery request, the LMTP server
3517 1.1 tron associated with the current session does not respond to the RSET
3518 1.1 tron command.
3519 1.1 tron
3520 1.1 tron </ul>
3521 1.1 tron
3522 1.1 tron <p>
3523 1.1 tron Most of these limitations will be removed after Postfix implements
3524 1.1 tron a connection cache that is shared among multiple LMTP client
3525 1.1 tron programs.
3526 1.1 tron </p>
3527 1.1 tron
3528 1.1 tron
3529 1.1 tron </DD>
3530 1.1 tron
3531 1.1 tron <DT><b><a name="lmtp_cname_overrides_servername">lmtp_cname_overrides_servername</a>
3532 1.1 tron (default: yes)</b></DT><DD>
3533 1.1 tron
3534 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_cname_overrides_servername">smtp_cname_overrides_servername</a>
3535 1.1 tron configuration parameter. See there for details. </p>
3536 1.1 tron
3537 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3538 1.1 tron
3539 1.1 tron
3540 1.1 tron </DD>
3541 1.1 tron
3542 1.1 tron <DT><b><a name="lmtp_connect_timeout">lmtp_connect_timeout</a>
3543 1.1 tron (default: 0s)</b></DT><DD>
3544 1.1 tron
3545 1.1 tron <p> The LMTP client time limit for completing a TCP connection, or
3546 1.1 tron zero (use the operating system built-in time limit). When no
3547 1.1 tron connection can be made within the deadline, the LMTP client tries
3548 1.1 tron the next address on the mail exchanger list. </p>
3549 1.1 tron
3550 1.1 tron <p>
3551 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3552 1.1 tron The default time unit is s (seconds).
3553 1.1 tron </p>
3554 1.1 tron
3555 1.1 tron <p>
3556 1.1 tron Example:
3557 1.1 tron </p>
3558 1.1 tron
3559 1.1 tron <pre>
3560 1.1 tron <a href="postconf.5.html#lmtp_connect_timeout">lmtp_connect_timeout</a> = 30s
3561 1.1 tron </pre>
3562 1.1 tron
3563 1.1 tron
3564 1.1 tron </DD>
3565 1.1 tron
3566 1.1 tron <DT><b><a name="lmtp_connection_cache_destinations">lmtp_connection_cache_destinations</a>
3567 1.1 tron (default: empty)</b></DT><DD>
3568 1.1 tron
3569 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_connection_cache_destinations">smtp_connection_cache_destinations</a>
3570 1.1 tron configuration parameter. See there for details. </p>
3571 1.1 tron
3572 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3573 1.1 tron
3574 1.1 tron
3575 1.1 tron </DD>
3576 1.1 tron
3577 1.1 tron <DT><b><a name="lmtp_connection_cache_on_demand">lmtp_connection_cache_on_demand</a>
3578 1.1 tron (default: yes)</b></DT><DD>
3579 1.1 tron
3580 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_connection_cache_on_demand">smtp_connection_cache_on_demand</a>
3581 1.1 tron configuration parameter. See there for details. </p>
3582 1.1 tron
3583 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3584 1.1 tron
3585 1.1 tron
3586 1.1 tron </DD>
3587 1.1 tron
3588 1.1 tron <DT><b><a name="lmtp_connection_cache_time_limit">lmtp_connection_cache_time_limit</a>
3589 1.1 tron (default: 2s)</b></DT><DD>
3590 1.1 tron
3591 1.1 tron <p> The LMTP-specific version of the
3592 1.1 tron <a href="postconf.5.html#smtp_connection_cache_time_limit">smtp_connection_cache_time_limit</a> configuration parameter.
3593 1.1 tron See there for details. </p>
3594 1.1 tron
3595 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3596 1.1 tron
3597 1.1 tron
3598 1.1 tron </DD>
3599 1.1 tron
3600 1.1 tron <DT><b><a name="lmtp_connection_reuse_time_limit">lmtp_connection_reuse_time_limit</a>
3601 1.1 tron (default: 300s)</b></DT><DD>
3602 1.1 tron
3603 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_connection_reuse_time_limit">smtp_connection_reuse_time_limit</a>
3604 1.1 tron configuration parameter. See there for details. </p>
3605 1.1 tron
3606 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3607 1.1 tron
3608 1.1 tron
3609 1.1 tron </DD>
3610 1.1 tron
3611 1.1 tron <DT><b><a name="lmtp_data_done_timeout">lmtp_data_done_timeout</a>
3612 1.1 tron (default: 600s)</b></DT><DD>
3613 1.1 tron
3614 1.1 tron <p> The LMTP client time limit for sending the LMTP ".", and for
3615 1.1 tron receiving the server response. When no response is received within
3616 1.1 tron the deadline, a warning is logged that the mail may be delivered
3617 1.1 tron multiple times. </p>
3618 1.1 tron
3619 1.1 tron <p>
3620 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3621 1.1 tron The default time unit is s (seconds).
3622 1.1 tron </p>
3623 1.1 tron
3624 1.1 tron
3625 1.1 tron </DD>
3626 1.1 tron
3627 1.1 tron <DT><b><a name="lmtp_data_init_timeout">lmtp_data_init_timeout</a>
3628 1.1 tron (default: 120s)</b></DT><DD>
3629 1.1 tron
3630 1.1 tron <p>
3631 1.1 tron The LMTP client time limit for sending the LMTP DATA command, and
3632 1.1 tron for receiving the server response.
3633 1.1 tron </p>
3634 1.1 tron
3635 1.1 tron <p>
3636 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3637 1.1 tron The default time unit is s (seconds).
3638 1.1 tron </p>
3639 1.1 tron
3640 1.1 tron
3641 1.1 tron </DD>
3642 1.1 tron
3643 1.1 tron <DT><b><a name="lmtp_data_xfer_timeout">lmtp_data_xfer_timeout</a>
3644 1.1 tron (default: 180s)</b></DT><DD>
3645 1.1 tron
3646 1.1 tron <p>
3647 1.1 tron The LMTP client time limit for sending the LMTP message content.
3648 1.1 tron When the connection stalls for more than $<a href="postconf.5.html#lmtp_data_xfer_timeout">lmtp_data_xfer_timeout</a>
3649 1.1 tron the LMTP client terminates the transfer.
3650 1.1 tron </p>
3651 1.1 tron
3652 1.1 tron <p>
3653 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3654 1.1 tron The default time unit is s (seconds).
3655 1.1 tron </p>
3656 1.1 tron
3657 1.1 tron
3658 1.1 tron </DD>
3659 1.1 tron
3660 1.1 tron <DT><b><a name="lmtp_defer_if_no_mx_address_found">lmtp_defer_if_no_mx_address_found</a>
3661 1.1 tron (default: no)</b></DT><DD>
3662 1.1 tron
3663 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_defer_if_no_mx_address_found">smtp_defer_if_no_mx_address_found</a>
3664 1.1 tron configuration parameter. See there for details. </p>
3665 1.1 tron
3666 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3667 1.1 tron
3668 1.1 tron
3669 1.1 tron </DD>
3670 1.1 tron
3671 1.1 tron <DT><b><a name="lmtp_destination_concurrency_limit">lmtp_destination_concurrency_limit</a>
3672 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_limit">default_destination_concurrency_limit</a>)</b></DT><DD>
3673 1.1 tron
3674 1.1 tron <p> The maximal number of parallel deliveries to the same destination
3675 1.1 tron via the lmtp message delivery transport. This limit is enforced by
3676 1.1 tron the queue manager. The message delivery transport name is the first
3677 1.1 tron field in the entry in the <a href="master.5.html">master.cf</a> file. </p>
3678 1.1 tron
3679 1.1 tron
3680 1.1 tron </DD>
3681 1.1 tron
3682 1.1 tron <DT><b><a name="lmtp_destination_recipient_limit">lmtp_destination_recipient_limit</a>
3683 1.1 tron (default: $<a href="postconf.5.html#default_destination_recipient_limit">default_destination_recipient_limit</a>)</b></DT><DD>
3684 1.1 tron
3685 1.1 tron <p> The maximal number of recipients per message for the lmtp
3686 1.1 tron message delivery transport. This limit is enforced by the queue
3687 1.1 tron manager. The message delivery transport name is the first field in
3688 1.1 tron the entry in the <a href="master.5.html">master.cf</a> file. </p>
3689 1.1 tron
3690 1.1 tron <p> Setting this parameter to a value of 1 changes the meaning of
3691 1.1 tron <a href="postconf.5.html#lmtp_destination_concurrency_limit">lmtp_destination_concurrency_limit</a> from concurrency per domain into
3692 1.1 tron concurrency per recipient. </p>
3693 1.1 tron
3694 1.1 tron
3695 1.1 tron </DD>
3696 1.1 tron
3697 1.1 tron <DT><b><a name="lmtp_discard_lhlo_keyword_address_maps">lmtp_discard_lhlo_keyword_address_maps</a>
3698 1.1 tron (default: empty)</b></DT><DD>
3699 1.1 tron
3700 1.1 tron <p> Lookup tables, indexed by the remote LMTP server address, with
3701 1.1 tron case insensitive lists of LHLO keywords (pipelining, starttls,
3702 1.1 tron auth, etc.) that the LMTP client will ignore in the LHLO response
3703 1.1 tron from a remote LMTP server. See <a href="postconf.5.html#lmtp_discard_lhlo_keywords">lmtp_discard_lhlo_keywords</a> for
3704 1.1 tron details. The table is not indexed by hostname for consistency with
3705 1.1 tron <a href="postconf.5.html#smtpd_discard_ehlo_keyword_address_maps">smtpd_discard_ehlo_keyword_address_maps</a>. </p>
3706 1.1 tron
3707 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3708 1.1 tron
3709 1.1 tron
3710 1.1 tron </DD>
3711 1.1 tron
3712 1.1 tron <DT><b><a name="lmtp_discard_lhlo_keywords">lmtp_discard_lhlo_keywords</a>
3713 1.1 tron (default: empty)</b></DT><DD>
3714 1.1 tron
3715 1.1 tron <p> A case insensitive list of LHLO keywords (pipelining, starttls,
3716 1.1 tron auth, etc.) that the LMTP client will ignore in the LHLO response
3717 1.1 tron from a remote LMTP server. </p>
3718 1.1 tron
3719 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3720 1.1 tron
3721 1.1 tron <p> Notes: </p>
3722 1.1 tron
3723 1.1 tron <ul>
3724 1.1 tron
3725 1.1 tron <li> <p> Specify the <b>silent-discard</b> pseudo keyword to prevent
3726 1.1 tron this action from being logged. </p>
3727 1.1 tron
3728 1.1 tron <li> <p> Use the <a href="postconf.5.html#lmtp_discard_lhlo_keyword_address_maps">lmtp_discard_lhlo_keyword_address_maps</a> feature to
3729 1.1 tron discard LHLO keywords selectively. </p>
3730 1.1 tron
3731 1.1 tron </ul>
3732 1.1 tron
3733 1.1 tron
3734 1.1 tron </DD>
3735 1.1 tron
3736 1.1 tron <DT><b><a name="lmtp_enforce_tls">lmtp_enforce_tls</a>
3737 1.1 tron (default: no)</b></DT><DD>
3738 1.1 tron
3739 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_enforce_tls">smtp_enforce_tls</a> configuration
3740 1.1 tron parameter. See there for details. </p>
3741 1.1 tron
3742 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3743 1.1 tron
3744 1.1 tron
3745 1.1 tron </DD>
3746 1.1 tron
3747 1.1 tron <DT><b><a name="lmtp_generic_maps">lmtp_generic_maps</a>
3748 1.1 tron (default: empty)</b></DT><DD>
3749 1.1 tron
3750 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_generic_maps">smtp_generic_maps</a> configuration
3751 1.1 tron parameter. See there for details. </p>
3752 1.1 tron
3753 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3754 1.1 tron
3755 1.1 tron
3756 1.1 tron </DD>
3757 1.1 tron
3758 1.1 tron <DT><b><a name="lmtp_host_lookup">lmtp_host_lookup</a>
3759 1.1 tron (default: dns)</b></DT><DD>
3760 1.1 tron
3761 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_host_lookup">smtp_host_lookup</a> configuration
3762 1.1 tron parameter. See there for details. </p>
3763 1.1 tron
3764 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3765 1.1 tron
3766 1.1 tron
3767 1.1 tron </DD>
3768 1.1 tron
3769 1.1 tron <DT><b><a name="lmtp_lhlo_name">lmtp_lhlo_name</a>
3770 1.1 tron (default: $<a href="postconf.5.html#myhostname">myhostname</a>)</b></DT><DD>
3771 1.1 tron
3772 1.1 tron <p>
3773 1.1 tron The hostname to send in the LMTP LHLO command.
3774 1.1 tron </p>
3775 1.1 tron
3776 1.1 tron <p>
3777 1.1 tron The default value is the machine hostname. Specify a hostname or
3778 1.1 tron [ip.add.re.ss].
3779 1.1 tron </p>
3780 1.1 tron
3781 1.1 tron <p>
3782 1.1 tron This information can be specified in the <a href="postconf.5.html">main.cf</a> file for all LMTP
3783 1.1 tron clients, or it can be specified in the <a href="master.5.html">master.cf</a> file for a specific
3784 1.1 tron client, for example:
3785 1.1 tron </p>
3786 1.1 tron
3787 1.1 tron <blockquote>
3788 1.1 tron <pre>
3789 1.1 tron /etc/postfix/<a href="master.5.html">master.cf</a>:
3790 1.1 tron mylmtp ... lmtp -o <a href="postconf.5.html#lmtp_lhlo_name">lmtp_lhlo_name</a>=foo.bar.com
3791 1.1 tron </pre>
3792 1.1 tron </blockquote>
3793 1.1 tron
3794 1.1 tron <p>
3795 1.1 tron This feature is available in Postfix 2.3 and later.
3796 1.1 tron </p>
3797 1.1 tron
3798 1.1 tron
3799 1.1 tron </DD>
3800 1.1 tron
3801 1.1 tron <DT><b><a name="lmtp_lhlo_timeout">lmtp_lhlo_timeout</a>
3802 1.1 tron (default: 300s)</b></DT><DD>
3803 1.1 tron
3804 1.1 tron <p> The LMTP client time limit for sending the LHLO command, and
3805 1.1 tron for receiving the initial server response. </p>
3806 1.1 tron
3807 1.1 tron <p> Time units: s (seconds), m (minutes), h (hours), d (days), w
3808 1.1 tron (weeks). The default time unit is s (seconds). </p>
3809 1.1 tron
3810 1.1 tron
3811 1.1 tron </DD>
3812 1.1 tron
3813 1.1 tron <DT><b><a name="lmtp_line_length_limit">lmtp_line_length_limit</a>
3814 1.1 tron (default: 990)</b></DT><DD>
3815 1.1 tron
3816 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_line_length_limit">smtp_line_length_limit</a>
3817 1.1 tron configuration parameter. See there for details. </p>
3818 1.1 tron
3819 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3820 1.1 tron
3821 1.1 tron
3822 1.1 tron </DD>
3823 1.1 tron
3824 1.1 tron <DT><b><a name="lmtp_mail_timeout">lmtp_mail_timeout</a>
3825 1.1 tron (default: 300s)</b></DT><DD>
3826 1.1 tron
3827 1.1 tron <p>
3828 1.1 tron The LMTP client time limit for sending the MAIL FROM command, and
3829 1.1 tron for receiving the server response.
3830 1.1 tron </p>
3831 1.1 tron
3832 1.1 tron <p>
3833 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3834 1.1 tron The default time unit is s (seconds).
3835 1.1 tron </p>
3836 1.1 tron
3837 1.1 tron
3838 1.1 tron </DD>
3839 1.1 tron
3840 1.1 tron <DT><b><a name="lmtp_mx_address_limit">lmtp_mx_address_limit</a>
3841 1.1 tron (default: 5)</b></DT><DD>
3842 1.1 tron
3843 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_mx_address_limit">smtp_mx_address_limit</a> configuration
3844 1.1 tron parameter. See there for details. </p>
3845 1.1 tron
3846 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3847 1.1 tron
3848 1.1 tron
3849 1.1 tron </DD>
3850 1.1 tron
3851 1.1 tron <DT><b><a name="lmtp_mx_session_limit">lmtp_mx_session_limit</a>
3852 1.1 tron (default: 2)</b></DT><DD>
3853 1.1 tron
3854 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_mx_session_limit">smtp_mx_session_limit</a> configuration
3855 1.1 tron parameter. See there for details. </p>
3856 1.1 tron
3857 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3858 1.1 tron
3859 1.1 tron
3860 1.1 tron </DD>
3861 1.1 tron
3862 1.1 tron <DT><b><a name="lmtp_pix_workaround_delay_time">lmtp_pix_workaround_delay_time</a>
3863 1.1 tron (default: 10s)</b></DT><DD>
3864 1.1 tron
3865 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_pix_workaround_delay_time">smtp_pix_workaround_delay_time</a>
3866 1.1 tron configuration parameter. See there for details. </p>
3867 1.1 tron
3868 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3869 1.1 tron
3870 1.1 tron
3871 1.1 tron </DD>
3872 1.1 tron
3873 1.1 tron <DT><b><a name="lmtp_pix_workaround_maps">lmtp_pix_workaround_maps</a>
3874 1.1 tron (default: empty)</b></DT><DD>
3875 1.1 tron
3876 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_pix_workaround_maps">smtp_pix_workaround_maps</a>
3877 1.1 tron configuration parameter. See there for details. </p>
3878 1.1 tron
3879 1.1 tron <p> This feature is available in Postfix 2.4 and later. </p>
3880 1.1 tron
3881 1.1 tron
3882 1.1 tron </DD>
3883 1.1 tron
3884 1.1 tron <DT><b><a name="lmtp_pix_workaround_threshold_time">lmtp_pix_workaround_threshold_time</a>
3885 1.1 tron (default: 500s)</b></DT><DD>
3886 1.1 tron
3887 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_pix_workaround_threshold_time">smtp_pix_workaround_threshold_time</a>
3888 1.1 tron configuration parameter. See there for details. </p>
3889 1.1 tron
3890 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3891 1.1 tron
3892 1.1 tron
3893 1.1 tron </DD>
3894 1.1 tron
3895 1.1 tron <DT><b><a name="lmtp_pix_workarounds">lmtp_pix_workarounds</a>
3896 1.1 tron (default: empty)</b></DT><DD>
3897 1.1 tron
3898 1.1 tron <p> The LMTP-specific version of the smtp_pix_workaround
3899 1.1 tron configuration parameter. See there for details. </p>
3900 1.1 tron
3901 1.1 tron <p> This feature is available in Postfix 2.4 and later. </p>
3902 1.1 tron
3903 1.1 tron
3904 1.1 tron </DD>
3905 1.1 tron
3906 1.1 tron <DT><b><a name="lmtp_quit_timeout">lmtp_quit_timeout</a>
3907 1.1 tron (default: 300s)</b></DT><DD>
3908 1.1 tron
3909 1.1 tron <p>
3910 1.1 tron The LMTP client time limit for sending the QUIT command, and for
3911 1.1 tron receiving the server response.
3912 1.1 tron </p>
3913 1.1 tron
3914 1.1 tron <p>
3915 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3916 1.1 tron The default time unit is s (seconds).
3917 1.1 tron </p>
3918 1.1 tron
3919 1.1 tron
3920 1.1 tron </DD>
3921 1.1 tron
3922 1.1 tron <DT><b><a name="lmtp_quote_rfc821_envelope">lmtp_quote_rfc821_envelope</a>
3923 1.1 tron (default: yes)</b></DT><DD>
3924 1.1 tron
3925 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_quote_rfc821_envelope">smtp_quote_rfc821_envelope</a>
3926 1.1 tron configuration parameter. See there for details. </p>
3927 1.1 tron
3928 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3929 1.1 tron
3930 1.1 tron
3931 1.1 tron </DD>
3932 1.1 tron
3933 1.1 tron <DT><b><a name="lmtp_randomize_addresses">lmtp_randomize_addresses</a>
3934 1.1 tron (default: yes)</b></DT><DD>
3935 1.1 tron
3936 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_randomize_addresses">smtp_randomize_addresses</a>
3937 1.1 tron configuration parameter. See there for details. </p>
3938 1.1 tron
3939 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
3940 1.1 tron
3941 1.1 tron
3942 1.1 tron </DD>
3943 1.1 tron
3944 1.1 tron <DT><b><a name="lmtp_rcpt_timeout">lmtp_rcpt_timeout</a>
3945 1.1 tron (default: 300s)</b></DT><DD>
3946 1.1 tron
3947 1.1 tron <p>
3948 1.1 tron The LMTP client time limit for sending the RCPT TO command, and
3949 1.1 tron for receiving the server response.
3950 1.1 tron </p>
3951 1.1 tron
3952 1.1 tron <p>
3953 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3954 1.1 tron The default time unit is s (seconds).
3955 1.1 tron </p>
3956 1.1 tron
3957 1.1 tron
3958 1.1 tron </DD>
3959 1.1 tron
3960 1.1 tron <DT><b><a name="lmtp_rset_timeout">lmtp_rset_timeout</a>
3961 1.1 tron (default: 20s)</b></DT><DD>
3962 1.1 tron
3963 1.1 tron <p> The LMTP client time limit for sending the RSET command, and
3964 1.1 tron for receiving the server response. The LMTP client sends RSET in
3965 1.1 tron order to finish a recipient address probe, or to verify that a
3966 1.1 tron cached connection is still alive. </p>
3967 1.1 tron
3968 1.1 tron <p>
3969 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
3970 1.1 tron The default time unit is s (seconds).
3971 1.1 tron </p>
3972 1.1 tron
3973 1.1 tron
3974 1.1 tron </DD>
3975 1.1 tron
3976 1.1 tron <DT><b><a name="lmtp_sasl_auth_cache_name">lmtp_sasl_auth_cache_name</a>
3977 1.1 tron (default: empty)</b></DT><DD>
3978 1.1 tron
3979 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_sasl_auth_cache_name">smtp_sasl_auth_cache_name</a>
3980 1.1 tron configuration parameter. See there for details. </p>
3981 1.1 tron
3982 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
3983 1.1 tron
3984 1.1 tron
3985 1.1 tron </DD>
3986 1.1 tron
3987 1.1 tron <DT><b><a name="lmtp_sasl_auth_cache_time">lmtp_sasl_auth_cache_time</a>
3988 1.1 tron (default: 90d)</b></DT><DD>
3989 1.1 tron
3990 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_sasl_auth_cache_time">smtp_sasl_auth_cache_time</a>
3991 1.1 tron configuration parameter. See there for details. </p>
3992 1.1 tron
3993 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
3994 1.1 tron
3995 1.1 tron
3996 1.1 tron </DD>
3997 1.1 tron
3998 1.1 tron <DT><b><a name="lmtp_sasl_auth_enable">lmtp_sasl_auth_enable</a>
3999 1.1 tron (default: no)</b></DT><DD>
4000 1.1 tron
4001 1.1 tron <p>
4002 1.1 tron Enable SASL authentication in the Postfix LMTP client.
4003 1.1 tron </p>
4004 1.1 tron
4005 1.1 tron
4006 1.1 tron </DD>
4007 1.1 tron
4008 1.1 tron <DT><b><a name="lmtp_sasl_auth_soft_bounce">lmtp_sasl_auth_soft_bounce</a>
4009 1.1 tron (default: yes)</b></DT><DD>
4010 1.1 tron
4011 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_sasl_auth_soft_bounce">smtp_sasl_auth_soft_bounce</a>
4012 1.1 tron configuration parameter. See there for details. </p>
4013 1.1 tron
4014 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
4015 1.1 tron
4016 1.1 tron
4017 1.1 tron </DD>
4018 1.1 tron
4019 1.1 tron <DT><b><a name="lmtp_sasl_mechanism_filter">lmtp_sasl_mechanism_filter</a>
4020 1.1 tron (default: empty)</b></DT><DD>
4021 1.1 tron
4022 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_sasl_mechanism_filter">smtp_sasl_mechanism_filter</a>
4023 1.1 tron configuration parameter. See there for details. </p>
4024 1.1 tron
4025 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4026 1.1 tron
4027 1.1 tron
4028 1.1 tron </DD>
4029 1.1 tron
4030 1.1 tron <DT><b><a name="lmtp_sasl_password_maps">lmtp_sasl_password_maps</a>
4031 1.1 tron (default: empty)</b></DT><DD>
4032 1.1 tron
4033 1.1 tron <p>
4034 1.1 tron Optional LMTP client lookup tables with one username:password entry
4035 1.1 tron per host or domain. If a remote host or domain has no username:password
4036 1.1 tron entry, then the Postfix LMTP client will not attempt to authenticate
4037 1.1 tron to the remote host.
4038 1.1 tron </p>
4039 1.1 tron
4040 1.1 tron
4041 1.1 tron </DD>
4042 1.1 tron
4043 1.1 tron <DT><b><a name="lmtp_sasl_path">lmtp_sasl_path</a>
4044 1.1 tron (default: empty)</b></DT><DD>
4045 1.1 tron
4046 1.1 tron <p> Implementation-specific information that is passed through to
4047 1.1 tron the SASL plug-in implementation that is selected with
4048 1.1 tron <b><a href="postconf.5.html#lmtp_sasl_type">lmtp_sasl_type</a></b>. Typically this specifies the name of a
4049 1.1 tron configuration file or rendezvous point. </p>
4050 1.1 tron
4051 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4052 1.1 tron
4053 1.1 tron
4054 1.1 tron </DD>
4055 1.1 tron
4056 1.1 tron <DT><b><a name="lmtp_sasl_security_options">lmtp_sasl_security_options</a>
4057 1.1 tron (default: noplaintext, noanonymous)</b></DT><DD>
4058 1.1 tron
4059 1.1 tron <p> SASL security options; as of Postfix 2.3 the list of available
4060 1.1 tron features depends on the SASL client implementation that is selected
4061 1.1 tron with <b><a href="postconf.5.html#lmtp_sasl_type">lmtp_sasl_type</a></b>. </p>
4062 1.1 tron
4063 1.1 tron <p> The following security features are defined for the <b>cyrus</b>
4064 1.1 tron client SASL implementation: </p>
4065 1.1 tron
4066 1.1 tron <dl>
4067 1.1 tron
4068 1.1 tron <dt><b>noplaintext</b></dt>
4069 1.1 tron
4070 1.1 tron <dd>Disallow authentication methods that use plaintext passwords. </dd>
4071 1.1 tron
4072 1.1 tron <dt><b>noactive</b></dt>
4073 1.1 tron
4074 1.1 tron <dd>Disallow authentication methods that are vulnerable to non-dictionary
4075 1.1 tron active attacks. </dd>
4076 1.1 tron
4077 1.1 tron <dt><b>nodictionary</b></dt>
4078 1.1 tron
4079 1.1 tron <dd>Disallow authentication methods that are vulnerable to passive
4080 1.1 tron dictionary attack. </dd>
4081 1.1 tron
4082 1.1 tron <dt><b>noanonymous</b></dt>
4083 1.1 tron
4084 1.1 tron <dd>Disallow anonymous logins. </dd>
4085 1.1 tron
4086 1.1 tron </dl>
4087 1.1 tron
4088 1.1 tron <p>
4089 1.1 tron Example:
4090 1.1 tron </p>
4091 1.1 tron
4092 1.1 tron <pre>
4093 1.1 tron <a href="postconf.5.html#lmtp_sasl_security_options">lmtp_sasl_security_options</a> = noplaintext
4094 1.1 tron </pre>
4095 1.1 tron
4096 1.1 tron
4097 1.1 tron </DD>
4098 1.1 tron
4099 1.1 tron <DT><b><a name="lmtp_sasl_tls_security_options">lmtp_sasl_tls_security_options</a>
4100 1.1 tron (default: $<a href="postconf.5.html#lmtp_sasl_security_options">lmtp_sasl_security_options</a>)</b></DT><DD>
4101 1.1 tron
4102 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_sasl_tls_security_options">smtp_sasl_tls_security_options</a>
4103 1.1 tron configuration parameter. See there for details. </p>
4104 1.1 tron
4105 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4106 1.1 tron
4107 1.1 tron
4108 1.1 tron </DD>
4109 1.1 tron
4110 1.1 tron <DT><b><a name="lmtp_sasl_tls_verified_security_options">lmtp_sasl_tls_verified_security_options</a>
4111 1.1 tron (default: $<a href="postconf.5.html#lmtp_sasl_tls_security_options">lmtp_sasl_tls_security_options</a>)</b></DT><DD>
4112 1.1 tron
4113 1.1 tron <p> The LMTP-specific version of the
4114 1.1 tron <a href="postconf.5.html#smtp_sasl_tls_verified_security_options">smtp_sasl_tls_verified_security_options</a> configuration parameter.
4115 1.1 tron See there for details. </p>
4116 1.1 tron
4117 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4118 1.1 tron
4119 1.1 tron
4120 1.1 tron </DD>
4121 1.1 tron
4122 1.1 tron <DT><b><a name="lmtp_sasl_type">lmtp_sasl_type</a>
4123 1.1 tron (default: cyrus)</b></DT><DD>
4124 1.1 tron
4125 1.1 tron <p> The SASL plug-in type that the Postfix LMTP client should use
4126 1.1 tron for authentication. The available types are listed with the
4127 1.1 tron "<b>postconf -A</b>" command. </p>
4128 1.1 tron
4129 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4130 1.1 tron
4131 1.1 tron
4132 1.1 tron </DD>
4133 1.1 tron
4134 1.1 tron <DT><b><a name="lmtp_send_xforward_command">lmtp_send_xforward_command</a>
4135 1.1 tron (default: no)</b></DT><DD>
4136 1.1 tron
4137 1.1 tron <p>
4138 1.1 tron Send an XFORWARD command to the LMTP server when the LMTP LHLO
4139 1.1 tron server response announces XFORWARD support. This allows an <a href="lmtp.8.html">lmtp(8)</a>
4140 1.1 tron delivery agent, used for content filter message injection, to
4141 1.1 tron forward the name, address, protocol and HELO name of the original
4142 1.1 tron client to the content filter and downstream queuing LMTP server.
4143 1.1 tron Before you change the value to yes, it is best to make sure that
4144 1.1 tron your content filter supports this command.
4145 1.1 tron </p>
4146 1.1 tron
4147 1.1 tron <p>
4148 1.1 tron This feature is available in Postfix 2.1 and later.
4149 1.1 tron </p>
4150 1.1 tron
4151 1.1 tron
4152 1.1 tron </DD>
4153 1.1 tron
4154 1.1 tron <DT><b><a name="lmtp_sender_dependent_authentication">lmtp_sender_dependent_authentication</a>
4155 1.1 tron (default: no)</b></DT><DD>
4156 1.1 tron
4157 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_sender_dependent_authentication">smtp_sender_dependent_authentication</a>
4158 1.1 tron configuration parameter. See there for details. </p>
4159 1.1 tron
4160 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4161 1.1 tron
4162 1.1 tron
4163 1.1 tron </DD>
4164 1.1 tron
4165 1.1 tron <DT><b><a name="lmtp_skip_5xx_greeting">lmtp_skip_5xx_greeting</a>
4166 1.1 tron (default: yes)</b></DT><DD>
4167 1.1 tron
4168 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_skip_5xx_greeting">smtp_skip_5xx_greeting</a>
4169 1.1 tron configuration parameter. See there for details. </p>
4170 1.1 tron
4171 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4172 1.1 tron
4173 1.1 tron
4174 1.1 tron </DD>
4175 1.1 tron
4176 1.1 tron <DT><b><a name="lmtp_skip_quit_response">lmtp_skip_quit_response</a>
4177 1.1 tron (default: no)</b></DT><DD>
4178 1.1 tron
4179 1.1 tron <p>
4180 1.1 tron Wait for the response to the LMTP QUIT command.
4181 1.1 tron </p>
4182 1.1 tron
4183 1.1 tron
4184 1.1 tron </DD>
4185 1.1 tron
4186 1.1 tron <DT><b><a name="lmtp_starttls_timeout">lmtp_starttls_timeout</a>
4187 1.1 tron (default: 300s)</b></DT><DD>
4188 1.1 tron
4189 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_starttls_timeout">smtp_starttls_timeout</a> configuration
4190 1.1 tron parameter. See there for details. </p>
4191 1.1 tron
4192 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4193 1.1 tron
4194 1.1 tron
4195 1.1 tron </DD>
4196 1.1 tron
4197 1.1 tron <DT><b><a name="lmtp_tcp_port">lmtp_tcp_port</a>
4198 1.1 tron (default: 24)</b></DT><DD>
4199 1.1 tron
4200 1.1 tron <p>
4201 1.1 tron The default TCP port that the Postfix LMTP client connects to.
4202 1.1 tron </p>
4203 1.1 tron
4204 1.1 tron
4205 1.1 tron </DD>
4206 1.1 tron
4207 1.1 tron <DT><b><a name="lmtp_tls_CAfile">lmtp_tls_CAfile</a>
4208 1.1 tron (default: empty)</b></DT><DD>
4209 1.1 tron
4210 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_CAfile">smtp_tls_CAfile</a>
4211 1.1 tron configuration parameter. See there for details. </p>
4212 1.1 tron
4213 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4214 1.1 tron
4215 1.1 tron
4216 1.1 tron </DD>
4217 1.1 tron
4218 1.1 tron <DT><b><a name="lmtp_tls_CApath">lmtp_tls_CApath</a>
4219 1.1 tron (default: empty)</b></DT><DD>
4220 1.1 tron
4221 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_CApath">smtp_tls_CApath</a>
4222 1.1 tron configuration parameter. See there for details. </p>
4223 1.1 tron
4224 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4225 1.1 tron
4226 1.1 tron
4227 1.1 tron </DD>
4228 1.1 tron
4229 1.1 tron <DT><b><a name="lmtp_tls_cert_file">lmtp_tls_cert_file</a>
4230 1.1 tron (default: empty)</b></DT><DD>
4231 1.1 tron
4232 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a>
4233 1.1 tron configuration parameter. See there for details. </p>
4234 1.1 tron
4235 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4236 1.1 tron
4237 1.1 tron
4238 1.1 tron </DD>
4239 1.1 tron
4240 1.1 tron <DT><b><a name="lmtp_tls_ciphers">lmtp_tls_ciphers</a>
4241 1.1 tron (default: export)</b></DT><DD>
4242 1.1 tron
4243 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_ciphers">smtp_tls_ciphers</a> configuration
4244 1.1 tron parameter. See there for details. </p>
4245 1.1 tron
4246 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
4247 1.1 tron
4248 1.1 tron
4249 1.1 tron </DD>
4250 1.1 tron
4251 1.1 tron <DT><b><a name="lmtp_tls_dcert_file">lmtp_tls_dcert_file</a>
4252 1.1 tron (default: empty)</b></DT><DD>
4253 1.1 tron
4254 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_dcert_file">smtp_tls_dcert_file</a>
4255 1.1 tron configuration parameter. See there for details. </p>
4256 1.1 tron
4257 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4258 1.1 tron
4259 1.1 tron
4260 1.1 tron </DD>
4261 1.1 tron
4262 1.1 tron <DT><b><a name="lmtp_tls_dkey_file">lmtp_tls_dkey_file</a>
4263 1.1 tron (default: $<a href="postconf.5.html#lmtp_tls_dcert_file">lmtp_tls_dcert_file</a>)</b></DT><DD>
4264 1.1 tron
4265 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_dkey_file">smtp_tls_dkey_file</a>
4266 1.1 tron configuration parameter. See there for details. </p>
4267 1.1 tron
4268 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4269 1.1 tron
4270 1.1 tron
4271 1.1 tron </DD>
4272 1.1 tron
4273 1.1 tron <DT><b><a name="lmtp_tls_eccert_file">lmtp_tls_eccert_file</a>
4274 1.1 tron (default: empty)</b></DT><DD>
4275 1.1 tron
4276 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_eccert_file">smtp_tls_eccert_file</a> configuration
4277 1.1 tron parameter. See there for details. </p>
4278 1.1 tron
4279 1.1 tron <p> This feature is available in Postfix 2.6 and later, when Postfix is
4280 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
4281 1.1 tron
4282 1.1 tron
4283 1.1 tron </DD>
4284 1.1 tron
4285 1.1 tron <DT><b><a name="lmtp_tls_eckey_file">lmtp_tls_eckey_file</a>
4286 1.1 tron (default: empty)</b></DT><DD>
4287 1.1 tron
4288 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_eckey_file">smtp_tls_eckey_file</a> configuration
4289 1.1 tron parameter. See there for details. </p>
4290 1.1 tron
4291 1.1 tron <p> This feature is available in Postfix 2.6 and later, when Postfix is
4292 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
4293 1.1 tron
4294 1.1 tron
4295 1.1 tron </DD>
4296 1.1 tron
4297 1.1 tron <DT><b><a name="lmtp_tls_enforce_peername">lmtp_tls_enforce_peername</a>
4298 1.1 tron (default: yes)</b></DT><DD>
4299 1.1 tron
4300 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_enforce_peername">smtp_tls_enforce_peername</a>
4301 1.1 tron configuration parameter. See there for details. </p>
4302 1.1 tron
4303 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4304 1.1 tron
4305 1.1 tron
4306 1.1 tron </DD>
4307 1.1 tron
4308 1.1 tron <DT><b><a name="lmtp_tls_exclude_ciphers">lmtp_tls_exclude_ciphers</a>
4309 1.1 tron (default: empty)</b></DT><DD>
4310 1.1 tron
4311 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a>
4312 1.1 tron configuration parameter. See there for details. </p>
4313 1.1 tron
4314 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4315 1.1 tron
4316 1.1 tron
4317 1.1 tron </DD>
4318 1.1 tron
4319 1.1 tron <DT><b><a name="lmtp_tls_fingerprint_cert_match">lmtp_tls_fingerprint_cert_match</a>
4320 1.1 tron (default: empty)</b></DT><DD>
4321 1.1 tron
4322 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_fingerprint_cert_match">smtp_tls_fingerprint_cert_match</a>
4323 1.1 tron configuration parameter. See there for details. </p>
4324 1.1 tron
4325 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
4326 1.1 tron
4327 1.1 tron
4328 1.1 tron </DD>
4329 1.1 tron
4330 1.1 tron <DT><b><a name="lmtp_tls_fingerprint_digest">lmtp_tls_fingerprint_digest</a>
4331 1.1 tron (default: md5)</b></DT><DD>
4332 1.1 tron
4333 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a>
4334 1.1 tron configuration parameter. See there for details. </p>
4335 1.1 tron
4336 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
4337 1.1 tron
4338 1.1 tron
4339 1.1 tron </DD>
4340 1.1 tron
4341 1.1 tron <DT><b><a name="lmtp_tls_key_file">lmtp_tls_key_file</a>
4342 1.1 tron (default: $<a href="postconf.5.html#lmtp_tls_cert_file">lmtp_tls_cert_file</a>)</b></DT><DD>
4343 1.1 tron
4344 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_key_file">smtp_tls_key_file</a>
4345 1.1 tron configuration parameter. See there for details. </p>
4346 1.1 tron
4347 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4348 1.1 tron
4349 1.1 tron
4350 1.1 tron </DD>
4351 1.1 tron
4352 1.1 tron <DT><b><a name="lmtp_tls_loglevel">lmtp_tls_loglevel</a>
4353 1.1 tron (default: 0)</b></DT><DD>
4354 1.1 tron
4355 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_loglevel">smtp_tls_loglevel</a>
4356 1.1 tron configuration parameter. See there for details. </p>
4357 1.1 tron
4358 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4359 1.1 tron
4360 1.1 tron
4361 1.1 tron </DD>
4362 1.1 tron
4363 1.1 tron <DT><b><a name="lmtp_tls_mandatory_ciphers">lmtp_tls_mandatory_ciphers</a>
4364 1.1 tron (default: empty)</b></DT><DD>
4365 1.1 tron
4366 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a>
4367 1.1 tron configuration parameter. See there for details. </p>
4368 1.1 tron
4369 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4370 1.1 tron
4371 1.1 tron
4372 1.1 tron </DD>
4373 1.1 tron
4374 1.1 tron <DT><b><a name="lmtp_tls_mandatory_exclude_ciphers">lmtp_tls_mandatory_exclude_ciphers</a>
4375 1.1 tron (default: empty)</b></DT><DD>
4376 1.1 tron
4377 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_mandatory_exclude_ciphers">smtp_tls_mandatory_exclude_ciphers</a>
4378 1.1 tron configuration parameter. See there for details. </p>
4379 1.1 tron
4380 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4381 1.1 tron
4382 1.1 tron
4383 1.1 tron </DD>
4384 1.1 tron
4385 1.1 tron <DT><b><a name="lmtp_tls_mandatory_protocols">lmtp_tls_mandatory_protocols</a>
4386 1.1 tron (default: SSLv3, TLSv1)</b></DT><DD>
4387 1.1 tron
4388 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a>
4389 1.1 tron configuration parameter. See there for details. </p>
4390 1.1 tron
4391 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4392 1.1 tron
4393 1.1 tron
4394 1.1 tron </DD>
4395 1.1 tron
4396 1.1 tron <DT><b><a name="lmtp_tls_note_starttls_offer">lmtp_tls_note_starttls_offer</a>
4397 1.1 tron (default: no)</b></DT><DD>
4398 1.1 tron
4399 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_note_starttls_offer">smtp_tls_note_starttls_offer</a>
4400 1.1 tron configuration parameter. See there for details. </p>
4401 1.1 tron
4402 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4403 1.1 tron
4404 1.1 tron
4405 1.1 tron </DD>
4406 1.1 tron
4407 1.1 tron <DT><b><a name="lmtp_tls_per_site">lmtp_tls_per_site</a>
4408 1.1 tron (default: empty)</b></DT><DD>
4409 1.1 tron
4410 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_per_site">smtp_tls_per_site</a> configuration
4411 1.1 tron parameter. See there for details. </p>
4412 1.1 tron
4413 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4414 1.1 tron
4415 1.1 tron
4416 1.1 tron </DD>
4417 1.1 tron
4418 1.1 tron <DT><b><a name="lmtp_tls_policy_maps">lmtp_tls_policy_maps</a>
4419 1.1 tron (default: empty)</b></DT><DD>
4420 1.1 tron
4421 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a>
4422 1.1 tron configuration parameter. See there for details. </p>
4423 1.1 tron
4424 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4425 1.1 tron
4426 1.1 tron
4427 1.1 tron </DD>
4428 1.1 tron
4429 1.1 tron <DT><b><a name="lmtp_tls_protocols">lmtp_tls_protocols</a>
4430 1.1 tron (default: empty)</b></DT><DD>
4431 1.1 tron
4432 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a> configuration
4433 1.1 tron parameter. See there for details. </p>
4434 1.1 tron
4435 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
4436 1.1 tron
4437 1.1 tron
4438 1.1 tron </DD>
4439 1.1 tron
4440 1.1 tron <DT><b><a name="lmtp_tls_scert_verifydepth">lmtp_tls_scert_verifydepth</a>
4441 1.1 tron (default: 9)</b></DT><DD>
4442 1.1 tron
4443 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_scert_verifydepth">smtp_tls_scert_verifydepth</a>
4444 1.1 tron configuration parameter. See there for details. </p>
4445 1.1 tron
4446 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4447 1.1 tron
4448 1.1 tron
4449 1.1 tron </DD>
4450 1.1 tron
4451 1.1 tron <DT><b><a name="lmtp_tls_secure_cert_match">lmtp_tls_secure_cert_match</a>
4452 1.1 tron (default: nexthop)</b></DT><DD>
4453 1.1 tron
4454 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_secure_cert_match">smtp_tls_secure_cert_match</a>
4455 1.1 tron configuration parameter. See there for details. </p>
4456 1.1 tron
4457 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4458 1.1 tron
4459 1.1 tron
4460 1.1 tron </DD>
4461 1.1 tron
4462 1.1 tron <DT><b><a name="lmtp_tls_security_level">lmtp_tls_security_level</a>
4463 1.1 tron (default: empty)</b></DT><DD>
4464 1.1 tron
4465 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> configuration
4466 1.1 tron parameter. See there for details. </p>
4467 1.1 tron
4468 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4469 1.1 tron
4470 1.1 tron
4471 1.1 tron </DD>
4472 1.1 tron
4473 1.1 tron <DT><b><a name="lmtp_tls_session_cache_database">lmtp_tls_session_cache_database</a>
4474 1.1 tron (default: empty)</b></DT><DD>
4475 1.1 tron
4476 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_session_cache_database">smtp_tls_session_cache_database</a>
4477 1.1 tron configuration parameter. See there for details. </p>
4478 1.1 tron
4479 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4480 1.1 tron
4481 1.1 tron
4482 1.1 tron </DD>
4483 1.1 tron
4484 1.1 tron <DT><b><a name="lmtp_tls_session_cache_timeout">lmtp_tls_session_cache_timeout</a>
4485 1.1 tron (default: 3600s)</b></DT><DD>
4486 1.1 tron
4487 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_session_cache_timeout">smtp_tls_session_cache_timeout</a>
4488 1.1 tron configuration parameter. See there for details. </p>
4489 1.1 tron
4490 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4491 1.1 tron
4492 1.1 tron
4493 1.1 tron </DD>
4494 1.1 tron
4495 1.1 tron <DT><b><a name="lmtp_tls_verify_cert_match">lmtp_tls_verify_cert_match</a>
4496 1.1 tron (default: hostname)</b></DT><DD>
4497 1.1 tron
4498 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_tls_verify_cert_match">smtp_tls_verify_cert_match</a>
4499 1.1 tron configuration parameter. See there for details. </p>
4500 1.1 tron
4501 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4502 1.1 tron
4503 1.1 tron
4504 1.1 tron </DD>
4505 1.1 tron
4506 1.1 tron <DT><b><a name="lmtp_use_tls">lmtp_use_tls</a>
4507 1.1 tron (default: no)</b></DT><DD>
4508 1.1 tron
4509 1.1 tron <p> The LMTP-specific version of the <a href="postconf.5.html#smtp_use_tls">smtp_use_tls</a> configuration
4510 1.1 tron parameter. See there for details. </p>
4511 1.1 tron
4512 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
4513 1.1 tron
4514 1.1 tron
4515 1.1 tron </DD>
4516 1.1 tron
4517 1.1 tron <DT><b><a name="lmtp_xforward_timeout">lmtp_xforward_timeout</a>
4518 1.1 tron (default: 300s)</b></DT><DD>
4519 1.1 tron
4520 1.1 tron <p>
4521 1.1 tron The LMTP client time limit for sending the XFORWARD command, and
4522 1.1 tron for receiving the server response.
4523 1.1 tron </p>
4524 1.1 tron
4525 1.1 tron <p>
4526 1.1 tron In case of problems the client does NOT try the next address on
4527 1.1 tron the mail exchanger list.
4528 1.1 tron </p>
4529 1.1 tron
4530 1.1 tron <p>
4531 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
4532 1.1 tron The default time unit is s (seconds).
4533 1.1 tron </p>
4534 1.1 tron
4535 1.1 tron <p>
4536 1.1 tron This feature is available in Postfix 2.1 and later.
4537 1.1 tron </p>
4538 1.1 tron
4539 1.1 tron
4540 1.1 tron </DD>
4541 1.1 tron
4542 1.1 tron <DT><b><a name="local_command_shell">local_command_shell</a>
4543 1.1 tron (default: empty)</b></DT><DD>
4544 1.1 tron
4545 1.1 tron <p>
4546 1.1 tron Optional shell program for <a href="local.8.html">local(8)</a> delivery to non-Postfix command.
4547 1.1 tron By default, non-Postfix commands are executed directly; commands
4548 1.1 tron are given to given to /bin/sh only when they contain shell meta
4549 1.1 tron characters or shell built-in commands. </p>
4550 1.1 tron
4551 1.1 tron <p> "sendmail's restricted shell" (smrsh) is what most people will
4552 1.1 tron use in order to restrict what programs can be run from e.g. .forward
4553 1.1 tron files (smrsh is part of the Sendmail distribution). </p>
4554 1.1 tron
4555 1.1 tron <p> Note: when a shell program is specified, it is invoked even
4556 1.1 tron when the command contains no shell built-in commands or meta
4557 1.1 tron characters. </p>
4558 1.1 tron
4559 1.1 tron <p>
4560 1.1 tron Example:
4561 1.1 tron </p>
4562 1.1 tron
4563 1.1 tron <pre>
4564 1.1 tron <a href="postconf.5.html#local_command_shell">local_command_shell</a> = /some/where/smrsh -c
4565 1.1 tron </pre>
4566 1.1 tron
4567 1.1 tron
4568 1.1 tron </DD>
4569 1.1 tron
4570 1.1 tron <DT><b><a name="local_destination_concurrency_limit">local_destination_concurrency_limit</a>
4571 1.1 tron (default: 2)</b></DT><DD>
4572 1.1 tron
4573 1.1 tron <p> The maximal number of parallel deliveries via the local mail
4574 1.1 tron delivery transport to the same recipient (when
4575 1.1 tron "<a href="postconf.5.html#local_destination_recipient_limit">local_destination_recipient_limit</a> = 1") or the maximal number of
4576 1.1 tron parallel deliveries to the same <a href="ADDRESS_CLASS_README.html#local_domain_class">local domain</a> (when
4577 1.1 tron "<a href="postconf.5.html#local_destination_recipient_limit">local_destination_recipient_limit</a> > 1"). This limit is enforced by
4578 1.1 tron the queue manager. The message delivery transport name is the first
4579 1.1 tron field in the entry in the <a href="master.5.html">master.cf</a> file. </p>
4580 1.1 tron
4581 1.1 tron <p> A low limit of 2 is recommended, just in case someone has an
4582 1.1 tron expensive shell command in a .forward file or in an alias (e.g.,
4583 1.1 tron a mailing list manager). You don't want to run lots of those at
4584 1.1 tron the same time. </p>
4585 1.1 tron
4586 1.1 tron
4587 1.1 tron </DD>
4588 1.1 tron
4589 1.1 tron <DT><b><a name="local_destination_recipient_limit">local_destination_recipient_limit</a>
4590 1.1 tron (default: 1)</b></DT><DD>
4591 1.1 tron
4592 1.1 tron <p> The maximal number of recipients per message delivery via the
4593 1.1 tron local mail delivery transport. This limit is enforced by the queue
4594 1.1 tron manager. The message delivery transport name is the first field in
4595 1.1 tron the entry in the <a href="master.5.html">master.cf</a> file. </p>
4596 1.1 tron
4597 1.1 tron <p> Setting this parameter to a value > 1 changes the meaning of
4598 1.1 tron <a href="postconf.5.html#local_destination_concurrency_limit">local_destination_concurrency_limit</a> from concurrency per recipient
4599 1.1 tron into concurrency per domain. </p>
4600 1.1 tron
4601 1.1 tron
4602 1.1 tron </DD>
4603 1.1 tron
4604 1.1 tron <DT><b><a name="local_header_rewrite_clients">local_header_rewrite_clients</a>
4605 1.1 tron (default: <a href="postconf.5.html#permit_inet_interfaces">permit_inet_interfaces</a>)</b></DT><DD>
4606 1.1 tron
4607 1.1 tron <p> Rewrite message header addresses in mail from these clients and
4608 1.1 tron update incomplete addresses with the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> or
4609 1.1 tron $<a href="postconf.5.html#mydomain">mydomain</a>; either don't rewrite message headers from other clients
4610 1.1 tron at all, or rewrite message headers and update incomplete addresses
4611 1.1 tron with the domain specified in the <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a>
4612 1.1 tron parameter. </p>
4613 1.1 tron
4614 1.1 tron <p> See the <a href="postconf.5.html#append_at_myorigin">append_at_myorigin</a> and <a href="postconf.5.html#append_dot_mydomain">append_dot_mydomain</a> parameters
4615 1.1 tron for details of how domain names are appended to incomplete addresses.
4616 1.1 tron </p>
4617 1.1 tron
4618 1.1 tron <p> Specify a list of zero or more of the following: </p>
4619 1.1 tron
4620 1.1 tron <dl>
4621 1.1 tron
4622 1.1 tron <dt><b><a href="postconf.5.html#permit_inet_interfaces">permit_inet_interfaces</a></b></dt>
4623 1.1 tron
4624 1.1 tron <dd> Append the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> or $<a href="postconf.5.html#mydomain">mydomain</a> when the
4625 1.1 tron client IP address matches $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>. This is enabled by
4626 1.1 tron default. </dd>
4627 1.1 tron
4628 1.1 tron <dt><b><a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a></b></dt>
4629 1.1 tron
4630 1.1 tron <dd> Append the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> or $<a href="postconf.5.html#mydomain">mydomain</a> when the
4631 1.1 tron client IP address matches any network or network address listed in
4632 1.1 tron $<a href="postconf.5.html#mynetworks">mynetworks</a>. This setting will not prevent remote mail header
4633 1.1 tron address rewriting when mail from a remote client is forwarded by
4634 1.1 tron a neighboring system. </dd>
4635 1.1 tron
4636 1.1 tron <dt><b><a href="postconf.5.html#permit_sasl_authenticated">permit_sasl_authenticated</a> </b></dt>
4637 1.1 tron
4638 1.1 tron <dd> Append the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> or $<a href="postconf.5.html#mydomain">mydomain</a> when the
4639 1.1 tron client is successfully authenticated via the <a href="http://tools.ietf.org/html/rfc4954">RFC 4954</a> (AUTH)
4640 1.1 tron protocol. </dd>
4641 1.1 tron
4642 1.1 tron <dt><b><a href="postconf.5.html#permit_tls_clientcerts">permit_tls_clientcerts</a> </b></dt>
4643 1.1 tron
4644 1.1 tron <dd> Append the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> or $<a href="postconf.5.html#mydomain">mydomain</a> when the
4645 1.1 tron client TLS certificate fingerprint is listed in $<a href="postconf.5.html#relay_clientcerts">relay_clientcerts</a>.
4646 1.1 tron The fingerprint digest algorithm is configurable via the
4647 1.1 tron <a href="postconf.5.html#smtpd_tls_fingerprint_digest">smtpd_tls_fingerprint_digest</a> parameter (hard-coded as md5 prior to
4648 1.1 tron Postfix version 2.5). </dd>
4649 1.1 tron
4650 1.1 tron <dt><b><a href="postconf.5.html#permit_tls_all_clientcerts">permit_tls_all_clientcerts</a> </b></dt>
4651 1.1 tron
4652 1.1 tron <dd> Append the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> or $<a href="postconf.5.html#mydomain">mydomain</a> when the
4653 1.1 tron client TLS certificate is successfully verified, regardless of
4654 1.1 tron whether it is listed on the server, and regardless of the certifying
4655 1.1 tron authority. </dd>
4656 1.1 tron
4657 1.1 tron <dt><b><a name="check_address_map">check_address_map</a> <i><a href="DATABASE_README.html">type:table</a></i> </b></dt>
4658 1.1 tron
4659 1.1 tron <dt><b><i><a href="DATABASE_README.html">type:table</a></i> </b></dt>
4660 1.1 tron
4661 1.1 tron <dd> Append the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> or $<a href="postconf.5.html#mydomain">mydomain</a> when the
4662 1.1 tron client IP address matches the specified lookup table.
4663 1.1 tron The lookup result is ignored, and no subnet lookup is done. This
4664 1.1 tron is suitable for, e.g., pop-before-smtp lookup tables. </dd>
4665 1.1 tron
4666 1.1 tron </dl>
4667 1.1 tron
4668 1.1 tron <p> Examples: </p>
4669 1.1 tron
4670 1.1 tron <p> The Postfix < 2.2 backwards compatible setting: always rewrite
4671 1.1 tron message headers, and always append my own domain to incomplete
4672 1.1 tron header addresses. </p>
4673 1.1 tron
4674 1.1 tron <blockquote>
4675 1.1 tron <pre>
4676 1.1 tron <a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = static:all
4677 1.1 tron </pre>
4678 1.1 tron </blockquote>
4679 1.1 tron
4680 1.1 tron <p> The purist (and default) setting: rewrite headers only in mail
4681 1.1 tron from Postfix sendmail and in SMTP mail from this machine. </p>
4682 1.1 tron
4683 1.1 tron <blockquote>
4684 1.1 tron <pre>
4685 1.1 tron <a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = <a href="postconf.5.html#permit_inet_interfaces">permit_inet_interfaces</a>
4686 1.1 tron </pre>
4687 1.1 tron </blockquote>
4688 1.1 tron
4689 1.1 tron <p> The intermediate setting: rewrite header addresses and append
4690 1.1 tron $<a href="postconf.5.html#myorigin">myorigin</a> or $<a href="postconf.5.html#mydomain">mydomain</a> information only with mail from Postfix
4691 1.1 tron sendmail, from local clients, or from authorized SMTP clients. </p>
4692 1.1 tron
4693 1.1 tron <p> Note: this setting will not prevent remote mail header address
4694 1.1 tron rewriting when mail from a remote client is forwarded by a neighboring
4695 1.1 tron system. </p>
4696 1.1 tron
4697 1.1 tron <blockquote>
4698 1.1 tron <pre>
4699 1.1 tron <a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>,
4700 1.1 tron <a href="postconf.5.html#permit_sasl_authenticated">permit_sasl_authenticated</a> <a href="postconf.5.html#permit_tls_clientcerts">permit_tls_clientcerts</a>
4701 1.1 tron <a href="postconf.5.html#check_address_map">check_address_map</a> hash:/etc/postfix/pop-before-smtp
4702 1.1 tron </pre>
4703 1.1 tron </blockquote>
4704 1.1 tron
4705 1.1 tron
4706 1.1 tron </DD>
4707 1.1 tron
4708 1.1 tron <DT><b><a name="local_recipient_maps">local_recipient_maps</a>
4709 1.1 tron (default: <a href="proxymap.8.html">proxy</a>:unix:passwd.byname $<a href="postconf.5.html#alias_maps">alias_maps</a>)</b></DT><DD>
4710 1.1 tron
4711 1.1 tron <p> Lookup tables with all names or addresses of local recipients:
4712 1.1 tron a recipient address is local when its domain matches $<a href="postconf.5.html#mydestination">mydestination</a>,
4713 1.1 tron $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a> or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>. Specify @domain as a
4714 1.1 tron wild-card for domains that do not have a valid recipient list.
4715 1.1 tron Technically, tables listed with $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> are used as
4716 1.1 tron lists: Postfix needs to know only if a lookup string is found or
4717 1.1 tron not, but it does not use the result from table lookup. </p>
4718 1.1 tron
4719 1.1 tron <p>
4720 1.1 tron If this parameter is non-empty (the default), then the Postfix SMTP
4721 1.1 tron server will reject mail for unknown local users.
4722 1.1 tron </p>
4723 1.1 tron
4724 1.1 tron <p>
4725 1.1 tron To turn off local recipient checking in the Postfix SMTP server,
4726 1.1 tron specify "<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> =" (i.e. empty).
4727 1.1 tron </p>
4728 1.1 tron
4729 1.1 tron <p>
4730 1.1 tron The default setting assumes that you use the default Postfix local
4731 1.1 tron delivery agent for local delivery. You need to update the
4732 1.1 tron <a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> setting if:
4733 1.1 tron </p>
4734 1.1 tron
4735 1.1 tron <ul>
4736 1.1 tron
4737 1.1 tron <li>You redefine the local delivery agent in <a href="master.5.html">master.cf</a>.
4738 1.1 tron
4739 1.1 tron <li>You redefine the "<a href="postconf.5.html#local_transport">local_transport</a>" setting in <a href="postconf.5.html">main.cf</a>.
4740 1.1 tron
4741 1.1 tron <li>You use the "<a href="postconf.5.html#luser_relay">luser_relay</a>", "<a href="postconf.5.html#mailbox_transport">mailbox_transport</a>", or "<a href="postconf.5.html#fallback_transport">fallback_transport</a>"
4742 1.1 tron feature of the Postfix <a href="local.8.html">local(8)</a> delivery agent.
4743 1.1 tron
4744 1.1 tron </ul>
4745 1.1 tron
4746 1.1 tron <p>
4747 1.1 tron Details are described in the <a href="LOCAL_RECIPIENT_README.html">LOCAL_RECIPIENT_README</a> file.
4748 1.1 tron </p>
4749 1.1 tron
4750 1.1 tron <p>
4751 1.1 tron Beware: if the Postfix SMTP server runs chrooted, you need to access
4752 1.1 tron the passwd file via the <a href="proxymap.8.html">proxymap(8)</a> service, in order to overcome
4753 1.1 tron chroot access restrictions. The alternative, maintaining a copy of
4754 1.1 tron the system password file in the chroot jail is not practical.
4755 1.1 tron </p>
4756 1.1 tron
4757 1.1 tron <p>
4758 1.1 tron Examples:
4759 1.1 tron </p>
4760 1.1 tron
4761 1.1 tron <pre>
4762 1.1 tron <a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> =
4763 1.1 tron </pre>
4764 1.1 tron
4765 1.1 tron
4766 1.1 tron </DD>
4767 1.1 tron
4768 1.1 tron <DT><b><a name="local_transport">local_transport</a>
4769 1.1 tron (default: <a href="local.8.html">local</a>:$<a href="postconf.5.html#myhostname">myhostname</a>)</b></DT><DD>
4770 1.1 tron
4771 1.1 tron <p> The default mail delivery transport and next-hop destination
4772 1.1 tron for final delivery to domains listed with <a href="postconf.5.html#mydestination">mydestination</a>, and for
4773 1.1 tron [ipaddress] destinations that match $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a> or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>.
4774 1.1 tron This information can be overruled with the <a href="transport.5.html">transport(5)</a> table. </p>
4775 1.1 tron
4776 1.1 tron <p>
4777 1.1 tron By default, local mail is delivered to the transport called "local",
4778 1.1 tron which is just the name of a service that is defined the <a href="master.5.html">master.cf</a> file.
4779 1.1 tron </p>
4780 1.1 tron
4781 1.1 tron <p>
4782 1.1 tron Specify a string of the form <i>transport:nexthop</i>, where <i>transport</i>
4783 1.1 tron is the name of a mail delivery transport defined in <a href="master.5.html">master.cf</a>.
4784 1.1 tron The <i>:nexthop</i> part is optional. For more details see the
4785 1.1 tron <a href="transport.5.html">transport(5)</a> manual page.
4786 1.1 tron </p>
4787 1.1 tron
4788 1.1 tron <p>
4789 1.1 tron Beware: if you override the default local delivery agent then you
4790 1.1 tron need to review the <a href="LOCAL_RECIPIENT_README.html">LOCAL_RECIPIENT_README</a> document, otherwise the
4791 1.1 tron SMTP server may reject mail for local recipients.
4792 1.1 tron </p>
4793 1.1 tron
4794 1.1 tron
4795 1.1 tron </DD>
4796 1.1 tron
4797 1.1 tron <DT><b><a name="luser_relay">luser_relay</a>
4798 1.1 tron (default: empty)</b></DT><DD>
4799 1.1 tron
4800 1.1 tron <p>
4801 1.1 tron Optional catch-all destination for unknown <a href="local.8.html">local(8)</a> recipients.
4802 1.1 tron By default, mail for unknown recipients in domains that match
4803 1.1 tron $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a> or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a> is returned
4804 1.1 tron as undeliverable.
4805 1.1 tron </p>
4806 1.1 tron
4807 1.1 tron <p>
4808 1.1 tron The following $name expansions are done on <a href="postconf.5.html#luser_relay">luser_relay</a>:
4809 1.1 tron </p>
4810 1.1 tron
4811 1.1 tron <dl>
4812 1.1 tron
4813 1.1 tron <dt><b>$domain</b></dt>
4814 1.1 tron
4815 1.1 tron <dd>The recipient domain. </dd>
4816 1.1 tron
4817 1.1 tron <dt><b>$extension</b></dt>
4818 1.1 tron
4819 1.1 tron <dd>The recipient address extension. </dd>
4820 1.1 tron
4821 1.1 tron <dt><b>$home</b></dt>
4822 1.1 tron
4823 1.1 tron <dd>The recipient's home directory. </dd>
4824 1.1 tron
4825 1.1 tron <dt><b>$local</b></dt>
4826 1.1 tron
4827 1.1 tron <dd>The entire recipient address localpart. </dd>
4828 1.1 tron
4829 1.1 tron <dt><b>$recipient</b></dt>
4830 1.1 tron
4831 1.1 tron <dd>The full recipient address. </dd>
4832 1.1 tron
4833 1.1 tron <dt><b>$<a href="postconf.5.html#recipient_delimiter">recipient_delimiter</a></b></dt>
4834 1.1 tron
4835 1.1 tron <dd>The system-wide recipient address extension delimiter. </dd>
4836 1.1 tron
4837 1.1 tron <dt><b>$shell</b></dt>
4838 1.1 tron
4839 1.1 tron <dd>The recipient's login shell. </dd>
4840 1.1 tron
4841 1.1 tron <dt><b>$user</b></dt>
4842 1.1 tron
4843 1.1 tron <dd>The recipient username. </dd>
4844 1.1 tron
4845 1.1 tron <dt><b>${name?value}</b></dt>
4846 1.1 tron
4847 1.1 tron <dd>Expands to <i>value</i> when <i>$name</i> has a non-empty value. </dd>
4848 1.1 tron
4849 1.1 tron <dt><b>${name:value}</b></dt>
4850 1.1 tron
4851 1.1 tron <dd>Expands to <i>value</i> when <i>$name</i> has an empty value. </dd>
4852 1.1 tron
4853 1.1 tron </dl>
4854 1.1 tron
4855 1.1 tron <p>
4856 1.1 tron Instead of $name you can also specify ${name} or $(name).
4857 1.1 tron </p>
4858 1.1 tron
4859 1.1 tron <p>
4860 1.1 tron Note: <a href="postconf.5.html#luser_relay">luser_relay</a> works only for the Postfix <a href="local.8.html">local(8)</a> delivery agent.
4861 1.1 tron </p>
4862 1.1 tron
4863 1.1 tron <p>
4864 1.1 tron Note: if you use this feature for accounts not in the UNIX password
4865 1.1 tron file, then you must specify "<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> =" (i.e. empty)
4866 1.1 tron in the <a href="postconf.5.html">main.cf</a> file, otherwise the Postfix SMTP server will reject mail
4867 1.1 tron for non-UNIX accounts with "User unknown in local recipient table".
4868 1.1 tron </p>
4869 1.1 tron
4870 1.1 tron <p>
4871 1.1 tron Examples:
4872 1.1 tron </p>
4873 1.1 tron
4874 1.1 tron <pre>
4875 1.1 tron <a href="postconf.5.html#luser_relay">luser_relay</a> = $user (a] other.host
4876 1.1 tron <a href="postconf.5.html#luser_relay">luser_relay</a> = $local (a] other.host
4877 1.1 tron <a href="postconf.5.html#luser_relay">luser_relay</a> = admin+$local
4878 1.1 tron </pre>
4879 1.1 tron
4880 1.1 tron
4881 1.1 tron </DD>
4882 1.1 tron
4883 1.1 tron <DT><b><a name="mail_name">mail_name</a>
4884 1.1 tron (default: Postfix)</b></DT><DD>
4885 1.1 tron
4886 1.1 tron <p>
4887 1.1 tron The mail system name that is displayed in Received: headers, in
4888 1.1 tron the SMTP greeting banner, and in bounced mail.
4889 1.1 tron </p>
4890 1.1 tron
4891 1.1 tron
4892 1.1 tron </DD>
4893 1.1 tron
4894 1.1 tron <DT><b><a name="mail_owner">mail_owner</a>
4895 1.1 tron (default: postfix)</b></DT><DD>
4896 1.1 tron
4897 1.1 tron <p>
4898 1.1 tron The UNIX system account that owns the Postfix queue and most Postfix
4899 1.1 tron daemon processes. Specify the name of a user account that does
4900 1.1 tron not share a group with other accounts and that owns no other files
4901 1.1 tron or processes on the system. In particular, don't specify nobody
4902 1.1 tron or daemon. PLEASE USE A DEDICATED USER ID AND GROUP ID.
4903 1.1 tron </p>
4904 1.1 tron
4905 1.1 tron <p>
4906 1.1 tron When this parameter value is changed you need to re-run "<b>postfix
4907 1.1 tron set-permissions</b>" (with Postfix version 2.0 and earlier:
4908 1.1 tron "<b>/etc/postfix/post-install set-permissions</b>".
4909 1.1 tron </p>
4910 1.1 tron
4911 1.1 tron
4912 1.1 tron </DD>
4913 1.1 tron
4914 1.1 tron <DT><b><a name="mail_release_date">mail_release_date</a>
4915 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
4916 1.1 tron
4917 1.1 tron <p>
4918 1.1 tron The Postfix release date, in "YYYYMMDD" format.
4919 1.1 tron </p>
4920 1.1 tron
4921 1.1 tron
4922 1.1 tron </DD>
4923 1.1 tron
4924 1.1 tron <DT><b><a name="mail_spool_directory">mail_spool_directory</a>
4925 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
4926 1.1 tron
4927 1.1 tron <p>
4928 1.1 tron The directory where <a href="local.8.html">local(8)</a> UNIX-style mailboxes are kept. The
4929 1.1 tron default setting depends on the system type. Specify a name ending
4930 1.1 tron in / for maildir-style delivery.
4931 1.1 tron </p>
4932 1.1 tron
4933 1.1 tron <p>
4934 1.1 tron Note: maildir delivery is done with the privileges of the recipient.
4935 1.1 tron If you use the <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a> setting for maildir style
4936 1.1 tron delivery, then you must create the top-level maildir directory in
4937 1.1 tron advance. Postfix will not create it.
4938 1.1 tron </p>
4939 1.1 tron
4940 1.1 tron <p>
4941 1.1 tron Examples:
4942 1.1 tron </p>
4943 1.1 tron
4944 1.1 tron <pre>
4945 1.1 tron <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a> = /var/mail
4946 1.1 tron <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a> = /var/spool/mail
4947 1.1 tron </pre>
4948 1.1 tron
4949 1.1 tron
4950 1.1 tron </DD>
4951 1.1 tron
4952 1.1 tron <DT><b><a name="mail_version">mail_version</a>
4953 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
4954 1.1 tron
4955 1.1 tron <p>
4956 1.1 tron The version of the mail system. Stable releases are named
4957 1.1 tron <i>major</i>.<i>minor</i>.<i>patchlevel</i>. Experimental releases
4958 1.1 tron also include the release date. The version string can be used in,
4959 1.1 tron for example, the SMTP greeting banner.
4960 1.1 tron </p>
4961 1.1 tron
4962 1.1 tron
4963 1.1 tron </DD>
4964 1.1 tron
4965 1.1 tron <DT><b><a name="mailbox_command">mailbox_command</a>
4966 1.1 tron (default: empty)</b></DT><DD>
4967 1.1 tron
4968 1.1 tron <p>
4969 1.1 tron Optional external command that the <a href="local.8.html">local(8)</a> delivery agent should
4970 1.1 tron use for mailbox delivery. The command is run with the user ID and
4971 1.1 tron the primary group ID privileges of the recipient. Exception:
4972 1.1 tron command delivery for root executes with $<a href="postconf.5.html#default_privs">default_privs</a> privileges.
4973 1.1 tron This is not a problem, because 1) mail for root should always be
4974 1.1 tron aliased to a real user and 2) don't log in as root, use "su" instead.
4975 1.1 tron </p>
4976 1.1 tron
4977 1.1 tron <p>
4978 1.1 tron The following environment variables are exported to the command:
4979 1.1 tron </p>
4980 1.1 tron
4981 1.1 tron <dl>
4982 1.1 tron
4983 1.1 tron <dt><b>CLIENT_ADDRESS</b></dt>
4984 1.1 tron
4985 1.1 tron <dd>Remote client network address. Available in Postfix version 2.2 and
4986 1.1 tron later. </dd>
4987 1.1 tron
4988 1.1 tron <dt><b>CLIENT_HELO</b></dt>
4989 1.1 tron
4990 1.1 tron <dd>Remote client EHLO command parameter. Available in Postfix version 2.2
4991 1.1 tron and later.</dd>
4992 1.1 tron
4993 1.1 tron <dt><b>CLIENT_HOSTNAME</b></dt>
4994 1.1 tron
4995 1.1 tron <dd>Remote client hostname. Available in Postfix version 2.2 and later.
4996 1.1 tron </dd>
4997 1.1 tron
4998 1.1 tron <dt><b>CLIENT_PROTOCOL</b></dt>
4999 1.1 tron
5000 1.1 tron <dd>Remote client protocol. Available in Postfix version 2.2 and later.
5001 1.1 tron </dd>
5002 1.1 tron
5003 1.1 tron <dt><b>DOMAIN</b></dt>
5004 1.1 tron
5005 1.1 tron <dd>The domain part of the recipient address. </dd>
5006 1.1 tron
5007 1.1 tron <dt><b>EXTENSION</b></dt>
5008 1.1 tron
5009 1.1 tron <dd>The optional address extension. </dd>
5010 1.1 tron
5011 1.1 tron <dt><b>HOME</b></dt>
5012 1.1 tron
5013 1.1 tron <dd>The recipient home directory. </dd>
5014 1.1 tron
5015 1.1 tron <dt><b>LOCAL</b></dt>
5016 1.1 tron
5017 1.1 tron <dd>The recipient address localpart. </dd>
5018 1.1 tron
5019 1.1 tron <dt><b>LOGNAME</b></dt>
5020 1.1 tron
5021 1.1 tron <dd>The recipient's username. </dd>
5022 1.1 tron
5023 1.1 tron <dt><b>ORIGINAL_RECIPIENT</b></dt>
5024 1.1 tron
5025 1.1 tron <dd>The entire recipient address, before any address rewriting or
5026 1.1 tron aliasing. </dd>
5027 1.1 tron
5028 1.1 tron <dt><b>RECIPIENT</b></dt>
5029 1.1 tron
5030 1.1 tron <dd>The full recipient address. </dd>
5031 1.1 tron
5032 1.1 tron <dt><b>SASL_METHOD</b></dt>
5033 1.1 tron
5034 1.1 tron <dd>SASL authentication method specified in the remote client AUTH
5035 1.1 tron command. Available in Postfix version 2.2 and later. </dd>
5036 1.1 tron
5037 1.1 tron <dt><b>SASL_SENDER</b></dt>
5038 1.1 tron
5039 1.1 tron <dd>SASL sender address specified in the remote client MAIL FROM
5040 1.1 tron command. Available in Postfix version 2.2 and later. </dd>
5041 1.1 tron
5042 1.1 tron <dt><b>SASL_USER</b></dt>
5043 1.1 tron
5044 1.1 tron <dd>SASL username specified in the remote client AUTH command.
5045 1.1 tron Available in Postfix version 2.2 and later. </dd>
5046 1.1 tron
5047 1.1 tron <dt><b>SENDER</b></dt>
5048 1.1 tron
5049 1.1 tron <dd>The full sender address. </dd>
5050 1.1 tron
5051 1.1 tron <dt><b>SHELL</b></dt>
5052 1.1 tron
5053 1.1 tron <dd>The recipient's login shell. </dd>
5054 1.1 tron
5055 1.1 tron <dt><b>USER</b></dt>
5056 1.1 tron
5057 1.1 tron <dd>The recipient username. </dd>
5058 1.1 tron
5059 1.1 tron </dl>
5060 1.1 tron
5061 1.1 tron <p>
5062 1.1 tron Unlike other Postfix configuration parameters, the <a href="postconf.5.html#mailbox_command">mailbox_command</a>
5063 1.1 tron parameter is not subjected to $name substitutions. This is to make
5064 1.1 tron it easier to specify shell syntax (see example below).
5065 1.1 tron </p>
5066 1.1 tron
5067 1.1 tron <p>
5068 1.1 tron If you can, avoid shell meta characters because they will force
5069 1.1 tron Postfix to run an expensive shell process. If you're delivering
5070 1.1 tron via Procmail then running a shell won't make a noticeable difference
5071 1.1 tron in the total cost.
5072 1.1 tron </p>
5073 1.1 tron
5074 1.1 tron <p>
5075 1.1 tron Note: if you use the <a href="postconf.5.html#mailbox_command">mailbox_command</a> feature to deliver mail
5076 1.1 tron system-wide, you must set up an alias that forwards mail for root
5077 1.1 tron to a real user.
5078 1.1 tron </p>
5079 1.1 tron
5080 1.1 tron <p> The precedence of <a href="local.8.html">local(8)</a> delivery features from high to low
5081 1.1 tron is: aliases, .forward files, <a href="postconf.5.html#mailbox_transport_maps">mailbox_transport_maps</a>, <a href="postconf.5.html#mailbox_transport">mailbox_transport</a>,
5082 1.1 tron <a href="postconf.5.html#mailbox_command_maps">mailbox_command_maps</a>, <a href="postconf.5.html#mailbox_command">mailbox_command</a>, <a href="postconf.5.html#home_mailbox">home_mailbox</a>, <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a>,
5083 1.1 tron <a href="postconf.5.html#fallback_transport_maps">fallback_transport_maps</a>, <a href="postconf.5.html#fallback_transport">fallback_transport</a> and <a href="postconf.5.html#luser_relay">luser_relay</a>. </p>
5084 1.1 tron
5085 1.1 tron <p>
5086 1.1 tron Examples:
5087 1.1 tron </p>
5088 1.1 tron
5089 1.1 tron <pre>
5090 1.1 tron <a href="postconf.5.html#mailbox_command">mailbox_command</a> = /some/where/procmail
5091 1.1 tron <a href="postconf.5.html#mailbox_command">mailbox_command</a> = /some/where/procmail -a "$EXTENSION"
5092 1.1 tron <a href="postconf.5.html#mailbox_command">mailbox_command</a> = /some/where/maildrop -d "$USER"
5093 1.1 tron -f "$SENDER" "$EXTENSION"
5094 1.1 tron </pre>
5095 1.1 tron
5096 1.1 tron
5097 1.1 tron </DD>
5098 1.1 tron
5099 1.1 tron <DT><b><a name="mailbox_command_maps">mailbox_command_maps</a>
5100 1.1 tron (default: empty)</b></DT><DD>
5101 1.1 tron
5102 1.1 tron <p>
5103 1.1 tron Optional lookup tables with per-recipient external commands to use
5104 1.1 tron for <a href="local.8.html">local(8)</a> mailbox delivery. Behavior is as with <a href="postconf.5.html#mailbox_command">mailbox_command</a>.
5105 1.1 tron </p>
5106 1.1 tron
5107 1.1 tron <p> The precedence of <a href="local.8.html">local(8)</a> delivery features from high to low
5108 1.1 tron is: aliases, .forward files, <a href="postconf.5.html#mailbox_transport_maps">mailbox_transport_maps</a>, <a href="postconf.5.html#mailbox_transport">mailbox_transport</a>,
5109 1.1 tron <a href="postconf.5.html#mailbox_command_maps">mailbox_command_maps</a>, <a href="postconf.5.html#mailbox_command">mailbox_command</a>, <a href="postconf.5.html#home_mailbox">home_mailbox</a>, <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a>,
5110 1.1 tron <a href="postconf.5.html#fallback_transport_maps">fallback_transport_maps</a>, <a href="postconf.5.html#fallback_transport">fallback_transport</a> and <a href="postconf.5.html#luser_relay">luser_relay</a>. </p>
5111 1.1 tron
5112 1.1 tron
5113 1.1 tron </DD>
5114 1.1 tron
5115 1.1 tron <DT><b><a name="mailbox_delivery_lock">mailbox_delivery_lock</a>
5116 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5117 1.1 tron
5118 1.1 tron <p>
5119 1.1 tron How to lock a UNIX-style <a href="local.8.html">local(8)</a> mailbox before attempting delivery.
5120 1.1 tron For a list of available file locking methods, use the "<b>postconf
5121 1.1 tron -l</b>" command.
5122 1.1 tron </p>
5123 1.1 tron
5124 1.1 tron <p>
5125 1.1 tron This setting is ignored with <b>maildir</b> style delivery,
5126 1.1 tron because such deliveries are safe without explicit locks.
5127 1.1 tron </p>
5128 1.1 tron
5129 1.1 tron <p>
5130 1.1 tron Note: The <b>dotlock</b> method requires that the recipient UID or
5131 1.1 tron GID has write access to the parent directory of the mailbox file.
5132 1.1 tron </p>
5133 1.1 tron
5134 1.1 tron <p>
5135 1.1 tron Note: the default setting of this parameter is system dependent.
5136 1.1 tron </p>
5137 1.1 tron
5138 1.1 tron
5139 1.1 tron </DD>
5140 1.1 tron
5141 1.1 tron <DT><b><a name="mailbox_size_limit">mailbox_size_limit</a>
5142 1.1 tron (default: 51200000)</b></DT><DD>
5143 1.1 tron
5144 1.1 tron <p> The maximal size of any <a href="local.8.html">local(8)</a> individual mailbox or maildir
5145 1.1 tron file, or zero (no limit). In fact, this limits the size of any
5146 1.1 tron file that is written to upon local delivery, including files written
5147 1.1 tron by external commands that are executed by the <a href="local.8.html">local(8)</a> delivery
5148 1.1 tron agent. </p>
5149 1.1 tron
5150 1.1 tron <p>
5151 1.1 tron This limit must not be smaller than the message size limit.
5152 1.1 tron </p>
5153 1.1 tron
5154 1.1 tron
5155 1.1 tron </DD>
5156 1.1 tron
5157 1.1 tron <DT><b><a name="mailbox_transport">mailbox_transport</a>
5158 1.1 tron (default: empty)</b></DT><DD>
5159 1.1 tron
5160 1.1 tron <p>
5161 1.1 tron Optional message delivery transport that the <a href="local.8.html">local(8)</a> delivery
5162 1.1 tron agent should use for mailbox delivery to all local recipients,
5163 1.1 tron whether or not they are found in the UNIX passwd database.
5164 1.1 tron </p>
5165 1.1 tron
5166 1.1 tron <p> The precedence of <a href="local.8.html">local(8)</a> delivery features from high to low
5167 1.1 tron is: aliases, .forward files, <a href="postconf.5.html#mailbox_transport_maps">mailbox_transport_maps</a>, <a href="postconf.5.html#mailbox_transport">mailbox_transport</a>,
5168 1.1 tron <a href="postconf.5.html#mailbox_command_maps">mailbox_command_maps</a>, <a href="postconf.5.html#mailbox_command">mailbox_command</a>, <a href="postconf.5.html#home_mailbox">home_mailbox</a>, <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a>,
5169 1.1 tron <a href="postconf.5.html#fallback_transport_maps">fallback_transport_maps</a>, <a href="postconf.5.html#fallback_transport">fallback_transport</a> and <a href="postconf.5.html#luser_relay">luser_relay</a>. </p>
5170 1.1 tron
5171 1.1 tron
5172 1.1 tron </DD>
5173 1.1 tron
5174 1.1 tron <DT><b><a name="mailbox_transport_maps">mailbox_transport_maps</a>
5175 1.1 tron (default: empty)</b></DT><DD>
5176 1.1 tron
5177 1.1 tron <p> Optional lookup tables with per-recipient message delivery
5178 1.1 tron transports to use for <a href="local.8.html">local(8)</a> mailbox delivery, whether or not the
5179 1.1 tron recipients are found in the UNIX passwd database. </p>
5180 1.1 tron
5181 1.1 tron <p> The precedence of <a href="local.8.html">local(8)</a> delivery features from high to low
5182 1.1 tron is: aliases, .forward files, <a href="postconf.5.html#mailbox_transport_maps">mailbox_transport_maps</a>, <a href="postconf.5.html#mailbox_transport">mailbox_transport</a>,
5183 1.1 tron <a href="postconf.5.html#mailbox_command_maps">mailbox_command_maps</a>, <a href="postconf.5.html#mailbox_command">mailbox_command</a>, <a href="postconf.5.html#home_mailbox">home_mailbox</a>, <a href="postconf.5.html#mail_spool_directory">mail_spool_directory</a>,
5184 1.1 tron <a href="postconf.5.html#fallback_transport_maps">fallback_transport_maps</a>, <a href="postconf.5.html#fallback_transport">fallback_transport</a> and <a href="postconf.5.html#luser_relay">luser_relay</a>. </p>
5185 1.1 tron
5186 1.1 tron <p> For safety reasons, this feature does not allow $number
5187 1.1 tron substitutions in regular expression maps. </p>
5188 1.1 tron
5189 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5190 1.1 tron
5191 1.1 tron
5192 1.1 tron </DD>
5193 1.1 tron
5194 1.1 tron <DT><b><a name="mailq_path">mailq_path</a>
5195 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5196 1.1 tron
5197 1.1 tron <p>
5198 1.1 tron Sendmail compatibility feature that specifies where the Postfix
5199 1.1 tron <a href="mailq.1.html">mailq(1)</a> command is installed. This command can be used to
5200 1.1 tron list the Postfix mail queue.
5201 1.1 tron </p>
5202 1.1 tron
5203 1.1 tron
5204 1.1 tron </DD>
5205 1.1 tron
5206 1.1 tron <DT><b><a name="manpage_directory">manpage_directory</a>
5207 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5208 1.1 tron
5209 1.1 tron <p>
5210 1.1 tron Where the Postfix manual pages are installed.
5211 1.1 tron </p>
5212 1.1 tron
5213 1.1 tron
5214 1.1 tron </DD>
5215 1.1 tron
5216 1.1 tron <DT><b><a name="maps_rbl_domains">maps_rbl_domains</a>
5217 1.1 tron (default: empty)</b></DT><DD>
5218 1.1 tron
5219 1.1 tron <p>
5220 1.1 tron Obsolete feature: use the <a href="postconf.5.html#reject_rbl_client">reject_rbl_client</a> feature instead.
5221 1.1 tron </p>
5222 1.1 tron
5223 1.1 tron
5224 1.1 tron </DD>
5225 1.1 tron
5226 1.1 tron <DT><b><a name="maps_rbl_reject_code">maps_rbl_reject_code</a>
5227 1.1 tron (default: 554)</b></DT><DD>
5228 1.1 tron
5229 1.1 tron <p>
5230 1.1 tron The numerical Postfix SMTP server response code when a remote SMTP
5231 1.1 tron client request is blocked by the <a href="postconf.5.html#reject_rbl_client">reject_rbl_client</a>, <a href="postconf.5.html#reject_rhsbl_client">reject_rhsbl_client</a>,
5232 1.1 tron <a href="postconf.5.html#reject_rhsbl_sender">reject_rhsbl_sender</a> or <a href="postconf.5.html#reject_rhsbl_recipient">reject_rhsbl_recipient</a> restriction.
5233 1.1 tron </p>
5234 1.1 tron
5235 1.1 tron <p>
5236 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
5237 1.1 tron </p>
5238 1.1 tron
5239 1.1 tron
5240 1.1 tron </DD>
5241 1.1 tron
5242 1.1 tron <DT><b><a name="masquerade_classes">masquerade_classes</a>
5243 1.1 tron (default: envelope_sender, header_sender, header_recipient)</b></DT><DD>
5244 1.1 tron
5245 1.1 tron <p>
5246 1.1 tron What addresses are subject to address masquerading.
5247 1.1 tron </p>
5248 1.1 tron
5249 1.1 tron <p>
5250 1.1 tron By default, address masquerading is limited to envelope sender
5251 1.1 tron addresses, and to header sender and header recipient addresses.
5252 1.1 tron This allows you to use address masquerading on a mail gateway while
5253 1.1 tron still being able to forward mail to users on individual machines.
5254 1.1 tron </p>
5255 1.1 tron
5256 1.1 tron <p>
5257 1.1 tron Specify zero or more of: envelope_sender, envelope_recipient,
5258 1.1 tron header_sender, header_recipient
5259 1.1 tron </p>
5260 1.1 tron
5261 1.1 tron
5262 1.1 tron </DD>
5263 1.1 tron
5264 1.1 tron <DT><b><a name="masquerade_domains">masquerade_domains</a>
5265 1.1 tron (default: empty)</b></DT><DD>
5266 1.1 tron
5267 1.1 tron <p>
5268 1.1 tron Optional list of domains whose subdomain structure will be stripped
5269 1.1 tron off in email addresses.
5270 1.1 tron </p>
5271 1.1 tron
5272 1.1 tron <p>
5273 1.1 tron The list is processed left to right, and processing stops at the
5274 1.1 tron first match. Thus,
5275 1.1 tron </p>
5276 1.1 tron
5277 1.1 tron <blockquote>
5278 1.1 tron <pre>
5279 1.1 tron <a href="postconf.5.html#masquerade_domains">masquerade_domains</a> = foo.example.com example.com
5280 1.1 tron </pre>
5281 1.1 tron </blockquote>
5282 1.1 tron
5283 1.1 tron <p>
5284 1.1 tron strips "user (a] any.thing.foo.example.com" to "user (a] foo.example.com",
5285 1.1 tron but strips "user (a] any.thing.else.example.com" to "user (a] example.com".
5286 1.1 tron </p>
5287 1.1 tron
5288 1.1 tron <p>
5289 1.1 tron A domain name prefixed with ! means do not masquerade this domain
5290 1.1 tron or its subdomains. Thus,
5291 1.1 tron </p>
5292 1.1 tron
5293 1.1 tron <blockquote>
5294 1.1 tron <pre>
5295 1.1 tron <a href="postconf.5.html#masquerade_domains">masquerade_domains</a> = !foo.example.com example.com
5296 1.1 tron </pre>
5297 1.1 tron </blockquote>
5298 1.1 tron
5299 1.1 tron <p>
5300 1.1 tron does not change "user (a] any.thing.foo.example.com" or "user (a] foo.example.com",
5301 1.1 tron but strips "user (a] any.thing.else.example.com" to "user (a] example.com".
5302 1.1 tron </p>
5303 1.1 tron
5304 1.1 tron <p> Note: with Postfix version 2.2, message header address masquerading
5305 1.1 tron happens only when message header address rewriting is enabled: </p>
5306 1.1 tron
5307 1.1 tron <ul>
5308 1.1 tron
5309 1.1 tron <li> The message is received with the Postfix <a href="sendmail.1.html">sendmail(1)</a> command,
5310 1.1 tron
5311 1.1 tron <li> The message is received from a network client that matches
5312 1.1 tron $<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a>,
5313 1.1 tron
5314 1.1 tron <li> The message is received from the network, and the
5315 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> parameter specifies a non-empty value.
5316 1.1 tron
5317 1.1 tron </ul>
5318 1.1 tron
5319 1.1 tron <p> To get the behavior before Postfix version 2.2, specify
5320 1.1 tron "<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = static:all". </p>
5321 1.1 tron
5322 1.1 tron <p>
5323 1.1 tron Example:
5324 1.1 tron </p>
5325 1.1 tron
5326 1.1 tron <pre>
5327 1.1 tron <a href="postconf.5.html#masquerade_domains">masquerade_domains</a> = $<a href="postconf.5.html#mydomain">mydomain</a>
5328 1.1 tron </pre>
5329 1.1 tron
5330 1.1 tron
5331 1.1 tron </DD>
5332 1.1 tron
5333 1.1 tron <DT><b><a name="masquerade_exceptions">masquerade_exceptions</a>
5334 1.1 tron (default: empty)</b></DT><DD>
5335 1.1 tron
5336 1.1 tron <p>
5337 1.1 tron Optional list of user names that are not subjected to address
5338 1.1 tron masquerading, even when their address matches $<a href="postconf.5.html#masquerade_domains">masquerade_domains</a>.
5339 1.1 tron </p>
5340 1.1 tron
5341 1.1 tron <p>
5342 1.1 tron By default, address masquerading makes no exceptions.
5343 1.1 tron </p>
5344 1.1 tron
5345 1.1 tron <p>
5346 1.1 tron Specify a list of user names, "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns,
5347 1.1 tron separated by commas and/or whitespace. The list is matched left to
5348 1.1 tron right, and the search stops on the first match. A "/file/name"
5349 1.1 tron pattern is replaced
5350 1.1 tron by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table is matched when a name
5351 1.1 tron matches a lookup key (the lookup result is ignored). Continue long
5352 1.1 tron lines by starting the next line with whitespace. Specify "!pattern"
5353 1.1 tron to exclude a name from the list. The form "!/file/name" is supported
5354 1.1 tron only in Postfix version 2.4 and later. </p>
5355 1.1 tron
5356 1.1 tron <p>
5357 1.1 tron Examples:
5358 1.1 tron </p>
5359 1.1 tron
5360 1.1 tron <pre>
5361 1.1 tron <a href="postconf.5.html#masquerade_exceptions">masquerade_exceptions</a> = root, mailer-daemon
5362 1.1 tron <a href="postconf.5.html#masquerade_exceptions">masquerade_exceptions</a> = root
5363 1.1 tron </pre>
5364 1.1 tron
5365 1.1 tron
5366 1.1 tron </DD>
5367 1.1 tron
5368 1.1 tron <DT><b><a name="master_service_disable">master_service_disable</a>
5369 1.1 tron (default: empty)</b></DT><DD>
5370 1.1 tron
5371 1.1 tron <p> Selectively disable <a href="master.8.html">master(8)</a> listener ports by service type
5372 1.1 tron or by service name and type. Specify a list of service types
5373 1.1 tron ("inet", "unix", "fifo", or "pass") or "name.type" tuples, where
5374 1.1 tron "name" is the first field of a <a href="master.5.html">master.cf</a> entry and "type" is a
5375 1.1 tron service type. As with other Postfix matchlists, a search stops at
5376 1.1 tron the first match. Specify "!pattern" to exclude a service from the
5377 1.1 tron list. By default, all <a href="master.8.html">master(8)</a> listener ports are enabled. </p>
5378 1.1 tron
5379 1.1 tron <p> Note: this feature does not support "/file/name" or "<a href="DATABASE_README.html">type:table</a>"
5380 1.1 tron patterns, nor does it support wildcards such as "*" or "all". This
5381 1.1 tron is intentional. </p>
5382 1.1 tron
5383 1.1 tron <p> Examples: </p>
5384 1.1 tron
5385 1.1 tron <pre>
5386 1.1 tron # Turn on all <a href="master.8.html">master(8)</a> listener ports (the default).
5387 1.1 tron <a href="postconf.5.html#master_service_disable">master_service_disable</a> =
5388 1.1 tron # Turn off only the main SMTP listener port.
5389 1.1 tron <a href="postconf.5.html#master_service_disable">master_service_disable</a> = smtp.inet
5390 1.1 tron # Turn off all TCP/IP listener ports.
5391 1.1 tron <a href="postconf.5.html#master_service_disable">master_service_disable</a> = inet
5392 1.1 tron # Turn off all TCP/IP listener ports except "foo".
5393 1.1 tron <a href="postconf.5.html#master_service_disable">master_service_disable</a> = !foo.inet, inet
5394 1.1 tron </pre>
5395 1.1 tron
5396 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
5397 1.1 tron
5398 1.1 tron
5399 1.1 tron </DD>
5400 1.1 tron
5401 1.1 tron <DT><b><a name="max_idle">max_idle</a>
5402 1.1 tron (default: 100s)</b></DT><DD>
5403 1.1 tron
5404 1.1 tron <p>
5405 1.1 tron The maximum amount of time that an idle Postfix daemon process waits
5406 1.1 tron for an incoming connection before terminating voluntarily. This
5407 1.1 tron parameter
5408 1.1 tron is ignored by the Postfix queue manager and by other long-lived
5409 1.1 tron Postfix daemon processes.
5410 1.1 tron </p>
5411 1.1 tron
5412 1.1 tron <p>
5413 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
5414 1.1 tron The default time unit is s (seconds).
5415 1.1 tron </p>
5416 1.1 tron
5417 1.1 tron
5418 1.1 tron </DD>
5419 1.1 tron
5420 1.1 tron <DT><b><a name="max_use">max_use</a>
5421 1.1 tron (default: 100)</b></DT><DD>
5422 1.1 tron
5423 1.1 tron <p>
5424 1.1 tron The maximal number of incoming connections that a Postfix daemon
5425 1.1 tron process will service before terminating voluntarily. This parameter
5426 1.1 tron is ignored by the Postfix queue
5427 1.1 tron manager and by other long-lived Postfix daemon processes.
5428 1.1 tron </p>
5429 1.1 tron
5430 1.1 tron
5431 1.1 tron </DD>
5432 1.1 tron
5433 1.1 tron <DT><b><a name="maximal_backoff_time">maximal_backoff_time</a>
5434 1.1 tron (default: 4000s)</b></DT><DD>
5435 1.1 tron
5436 1.1 tron <p>
5437 1.1 tron The maximal time between attempts to deliver a deferred message.
5438 1.1 tron </p>
5439 1.1 tron
5440 1.1 tron <p> This parameter should be set to a value greater than or equal
5441 1.1 tron to $<a href="postconf.5.html#minimal_backoff_time">minimal_backoff_time</a>. See also $<a href="postconf.5.html#queue_run_delay">queue_run_delay</a>. </p>
5442 1.1 tron
5443 1.1 tron <p>
5444 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
5445 1.1 tron The default time unit is s (seconds).
5446 1.1 tron </p>
5447 1.1 tron
5448 1.1 tron
5449 1.1 tron </DD>
5450 1.1 tron
5451 1.1 tron <DT><b><a name="maximal_queue_lifetime">maximal_queue_lifetime</a>
5452 1.1 tron (default: 5d)</b></DT><DD>
5453 1.1 tron
5454 1.1 tron <p>
5455 1.1 tron The maximal time a message is queued before it is sent back as
5456 1.1 tron undeliverable.
5457 1.1 tron </p>
5458 1.1 tron
5459 1.1 tron <p>
5460 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
5461 1.1 tron The default time unit is d (days).
5462 1.1 tron </p>
5463 1.1 tron
5464 1.1 tron <p>
5465 1.1 tron Specify 0 when mail delivery should be tried only once.
5466 1.1 tron </p>
5467 1.1 tron
5468 1.1 tron
5469 1.1 tron </DD>
5470 1.1 tron
5471 1.1 tron <DT><b><a name="message_reject_characters">message_reject_characters</a>
5472 1.1 tron (default: empty)</b></DT><DD>
5473 1.1 tron
5474 1.1 tron <p> The set of characters that Postfix will reject in message
5475 1.1 tron content. The usual C-like escape sequences are recognized: <tt>\a
5476 1.1 tron \b \f \n \r \t \v \<i>ddd</i></tt> (up to three octal digits) and
5477 1.1 tron <tt>\\</tt>. </p>
5478 1.1 tron
5479 1.1 tron <p> Example: </p>
5480 1.1 tron
5481 1.1 tron <pre>
5482 1.1 tron <a href="postconf.5.html#message_reject_characters">message_reject_characters</a> = \0
5483 1.1 tron </pre>
5484 1.1 tron
5485 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5486 1.1 tron
5487 1.1 tron
5488 1.1 tron </DD>
5489 1.1 tron
5490 1.1 tron <DT><b><a name="message_size_limit">message_size_limit</a>
5491 1.1 tron (default: 10240000)</b></DT><DD>
5492 1.1 tron
5493 1.1 tron <p>
5494 1.1 tron The maximal size in bytes of a message, including envelope information.
5495 1.1 tron </p>
5496 1.1 tron
5497 1.1 tron <p> Note: be careful when making changes. Excessively small values
5498 1.1 tron will result in the loss of non-delivery notifications, when a bounce
5499 1.1 tron message size exceeds the local or remote MTA's message size limit.
5500 1.1 tron </p>
5501 1.1 tron
5502 1.1 tron
5503 1.1 tron </DD>
5504 1.1 tron
5505 1.1 tron <DT><b><a name="message_strip_characters">message_strip_characters</a>
5506 1.1 tron (default: empty)</b></DT><DD>
5507 1.1 tron
5508 1.1 tron <p> The set of characters that Postfix will remove from message
5509 1.1 tron content. The usual C-like escape sequences are recognized: <tt>\a
5510 1.1 tron \b \f \n \r \t \v \<i>ddd</i></tt> (up to three octal digits) and
5511 1.1 tron <tt>\\</tt>. </p>
5512 1.1 tron
5513 1.1 tron <p> Example: </p>
5514 1.1 tron
5515 1.1 tron <pre>
5516 1.1 tron <a href="postconf.5.html#message_strip_characters">message_strip_characters</a> = \0
5517 1.1 tron </pre>
5518 1.1 tron
5519 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5520 1.1 tron
5521 1.1 tron
5522 1.1 tron </DD>
5523 1.1 tron
5524 1.1 tron <DT><b><a name="milter_command_timeout">milter_command_timeout</a>
5525 1.1 tron (default: 30s)</b></DT><DD>
5526 1.1 tron
5527 1.1 tron <p> The time limit for sending an SMTP command to a Milter (mail
5528 1.1 tron filter) application, and for receiving the response. </p>
5529 1.1 tron
5530 1.1 tron <p> Specify a non-zero time value (an integral value plus an optional
5531 1.1 tron one-letter suffix that specifies the time unit). </p>
5532 1.1 tron
5533 1.1 tron <p> Time units: s (seconds), m (minutes), h (hours), d (days), w
5534 1.1 tron (weeks). The default time unit is s (seconds). </p>
5535 1.1 tron
5536 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5537 1.1 tron
5538 1.1 tron
5539 1.1 tron </DD>
5540 1.1 tron
5541 1.1 tron <DT><b><a name="milter_connect_macros">milter_connect_macros</a>
5542 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5543 1.1 tron
5544 1.1 tron <p> The macros that are sent to Milter (mail filter) applications
5545 1.1 tron after completion of an SMTP connection. See <a href="MILTER_README.html">MILTER_README</a>
5546 1.1 tron for a list of available macro names and their meanings. </p>
5547 1.1 tron
5548 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5549 1.1 tron
5550 1.1 tron
5551 1.1 tron </DD>
5552 1.1 tron
5553 1.1 tron <DT><b><a name="milter_connect_timeout">milter_connect_timeout</a>
5554 1.1 tron (default: 30s)</b></DT><DD>
5555 1.1 tron
5556 1.1 tron <p> The time limit for connecting to a Milter (mail filter)
5557 1.1 tron application, and for negotiating protocol options. </p>
5558 1.1 tron
5559 1.1 tron <p> Specify a non-zero time value (an integral value plus an optional
5560 1.1 tron one-letter suffix that specifies the time unit). </p>
5561 1.1 tron
5562 1.1 tron <p> Time units: s (seconds), m (minutes), h (hours), d (days), w
5563 1.1 tron (weeks). The default time unit is s (seconds). </p>
5564 1.1 tron
5565 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5566 1.1 tron
5567 1.1 tron
5568 1.1 tron </DD>
5569 1.1 tron
5570 1.1 tron <DT><b><a name="milter_content_timeout">milter_content_timeout</a>
5571 1.1 tron (default: 300s)</b></DT><DD>
5572 1.1 tron
5573 1.1 tron <p> The time limit for sending message content to a Milter (mail
5574 1.1 tron filter) application, and for receiving the response. </p>
5575 1.1 tron
5576 1.1 tron <p> Specify a non-zero time value (an integral value plus an optional
5577 1.1 tron one-letter suffix that specifies the time unit). </p>
5578 1.1 tron
5579 1.1 tron <p> Time units: s (seconds), m (minutes), h (hours), d (days), w
5580 1.1 tron (weeks). The default time unit is s (seconds). </p>
5581 1.1 tron
5582 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5583 1.1 tron
5584 1.1 tron
5585 1.1 tron </DD>
5586 1.1 tron
5587 1.1 tron <DT><b><a name="milter_data_macros">milter_data_macros</a>
5588 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5589 1.1 tron
5590 1.1 tron <p> The macros that are sent to version 4 or higher Milter (mail
5591 1.1 tron filter) applications after the SMTP DATA command. See <a href="MILTER_README.html">MILTER_README</a>
5592 1.1 tron for a list of available macro names and their meanings. </p>
5593 1.1 tron
5594 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5595 1.1 tron
5596 1.1 tron
5597 1.1 tron </DD>
5598 1.1 tron
5599 1.1 tron <DT><b><a name="milter_default_action">milter_default_action</a>
5600 1.1 tron (default: tempfail)</b></DT><DD>
5601 1.1 tron
5602 1.1 tron <p> The default action when a Milter (mail filter) application is
5603 1.1 tron unavailable or mis-configured. Specify one of the following: </p>
5604 1.1 tron
5605 1.1 tron <dl compact>
5606 1.1 tron
5607 1.1 tron <dt>accept</dt> <dd>Proceed as if the mail filter was not present.
5608 1.1 tron </dd>
5609 1.1 tron
5610 1.1 tron <dt>reject</dt> <dd>Reject all further commands in this session
5611 1.1 tron with a permanent status code.</dd>
5612 1.1 tron
5613 1.1 tron <dt>tempfail</dt> <dd>Reject all further commands in this session
5614 1.1 tron with a temporary status code. </dd>
5615 1.1 tron
5616 1.1 tron <dt>quarantine</dt> <dd>Like "accept", but freeze the message in
5617 1.1 tron the "<a href="QSHAPE_README.html#hold_queue">hold" queue</a>. Available with Postfix 2.6 and later. </dd>
5618 1.1 tron
5619 1.1 tron </dl>
5620 1.1 tron
5621 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5622 1.1 tron
5623 1.1 tron
5624 1.1 tron </DD>
5625 1.1 tron
5626 1.1 tron <DT><b><a name="milter_end_of_data_macros">milter_end_of_data_macros</a>
5627 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5628 1.1 tron
5629 1.1 tron <p> The macros that are sent to Milter (mail filter) applications
5630 1.1 tron after the message end-of-data. See <a href="MILTER_README.html">MILTER_README</a> for a list of
5631 1.1 tron available macro names and their meanings. </p>
5632 1.1 tron
5633 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5634 1.1 tron
5635 1.1 tron
5636 1.1 tron </DD>
5637 1.1 tron
5638 1.1 tron <DT><b><a name="milter_end_of_header_macros">milter_end_of_header_macros</a>
5639 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5640 1.1 tron
5641 1.1 tron <p> The macros that are sent to Milter (mail filter) applications
5642 1.1 tron after the end of the message header. See <a href="MILTER_README.html">MILTER_README</a> for a list
5643 1.1 tron of available macro names and their meanings. </p>
5644 1.1 tron
5645 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
5646 1.1 tron
5647 1.1 tron
5648 1.1 tron </DD>
5649 1.1 tron
5650 1.1 tron <DT><b><a name="milter_helo_macros">milter_helo_macros</a>
5651 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5652 1.1 tron
5653 1.1 tron <p> The macros that are sent to Milter (mail filter) applications
5654 1.1 tron after the SMTP HELO or EHLO command. See
5655 1.1 tron <a href="MILTER_README.html">MILTER_README</a> for a list of available macro names and their meanings.
5656 1.1 tron </p>
5657 1.1 tron
5658 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5659 1.1 tron
5660 1.1 tron
5661 1.1 tron </DD>
5662 1.1 tron
5663 1.1 tron <DT><b><a name="milter_macro_daemon_name">milter_macro_daemon_name</a>
5664 1.1 tron (default: $<a href="postconf.5.html#myhostname">myhostname</a>)</b></DT><DD>
5665 1.1 tron
5666 1.1 tron <p> The {daemon_name} macro value for Milter (mail filter) applications.
5667 1.1 tron See <a href="MILTER_README.html">MILTER_README</a> for a list of available macro names and their
5668 1.1 tron meanings. </p>
5669 1.1 tron
5670 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5671 1.1 tron
5672 1.1 tron
5673 1.1 tron </DD>
5674 1.1 tron
5675 1.1 tron <DT><b><a name="milter_macro_v">milter_macro_v</a>
5676 1.1 tron (default: $<a href="postconf.5.html#mail_name">mail_name</a> $<a href="postconf.5.html#mail_version">mail_version</a>)</b></DT><DD>
5677 1.1 tron
5678 1.1 tron <p> The {v} macro value for Milter (mail filter) applications.
5679 1.1 tron See <a href="MILTER_README.html">MILTER_README</a> for a list of available macro names and their
5680 1.1 tron meanings. </p>
5681 1.1 tron
5682 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5683 1.1 tron
5684 1.1 tron
5685 1.1 tron </DD>
5686 1.1 tron
5687 1.1 tron <DT><b><a name="milter_mail_macros">milter_mail_macros</a>
5688 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5689 1.1 tron
5690 1.1 tron <p> The macros that are sent to Milter (mail filter) applications
5691 1.1 tron after the SMTP MAIL FROM command. See <a href="MILTER_README.html">MILTER_README</a>
5692 1.1 tron for a list of available macro names and their meanings. </p>
5693 1.1 tron
5694 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5695 1.1 tron
5696 1.1 tron
5697 1.1 tron </DD>
5698 1.1 tron
5699 1.1 tron <DT><b><a name="milter_protocol">milter_protocol</a>
5700 1.1 tron (default: 6)</b></DT><DD>
5701 1.1 tron
5702 1.1 tron <p> The mail filter protocol version and optional protocol extensions
5703 1.1 tron for communication with a Milter application; prior to Postfix 2.6
5704 1.1 tron the default protocol is 2. Postfix
5705 1.1 tron sends this version number during the initial protocol handshake.
5706 1.1 tron It should match the version number that is expected by the mail
5707 1.1 tron filter application (or by its Milter library). </p>
5708 1.1 tron
5709 1.1 tron <p>Protocol versions: </p>
5710 1.1 tron
5711 1.1 tron <dl compact>
5712 1.1 tron
5713 1.1 tron <dt>2</dt> <dd>Use Sendmail 8 mail filter protocol version 2 (default
5714 1.1 tron with Sendmail version 8.11 .. 8.13 and Postfix version 2.3 ..
5715 1.1 tron 2.5).</dd>
5716 1.1 tron
5717 1.1 tron <dt>3</dt> <dd>Use Sendmail 8 mail filter protocol version 3.</dd>
5718 1.1 tron
5719 1.1 tron <dt>4</dt> <dd>Use Sendmail 8 mail filter protocol version 4.</dd>
5720 1.1 tron
5721 1.1 tron <dt>6</dt> <dd>Use Sendmail 8 mail filter protocol version 6 (default
5722 1.1 tron with Sendmail version 8.14 and Postfix version 2.6).</dd>
5723 1.1 tron
5724 1.1 tron </dl>
5725 1.1 tron
5726 1.1 tron <p>Protocol extensions: </p>
5727 1.1 tron
5728 1.1 tron <dl compact>
5729 1.1 tron
5730 1.1 tron <dt>no_header_reply</dt> <dd> Specify this when the Milter application
5731 1.1 tron will not reply for each individual message header.</dd>
5732 1.1 tron
5733 1.1 tron </dl>
5734 1.1 tron
5735 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5736 1.1 tron
5737 1.1 tron
5738 1.1 tron </DD>
5739 1.1 tron
5740 1.1 tron <DT><b><a name="milter_rcpt_macros">milter_rcpt_macros</a>
5741 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5742 1.1 tron
5743 1.1 tron <p> The macros that are sent to Milter (mail filter) applications
5744 1.1 tron after the SMTP RCPT TO command. See <a href="MILTER_README.html">MILTER_README</a>
5745 1.1 tron for a list of available macro names and their meanings. </p>
5746 1.1 tron
5747 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5748 1.1 tron
5749 1.1 tron
5750 1.1 tron </DD>
5751 1.1 tron
5752 1.1 tron <DT><b><a name="milter_unknown_command_macros">milter_unknown_command_macros</a>
5753 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
5754 1.1 tron
5755 1.1 tron <p> The macros that are sent to version 3 or higher Milter (mail
5756 1.1 tron filter) applications after an unknown SMTP command. See <a href="MILTER_README.html">MILTER_README</a>
5757 1.1 tron for a list of available macro names and their meanings. </p>
5758 1.1 tron
5759 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
5760 1.1 tron
5761 1.1 tron
5762 1.1 tron </DD>
5763 1.1 tron
5764 1.1 tron <DT><b><a name="mime_boundary_length_limit">mime_boundary_length_limit</a>
5765 1.1 tron (default: 2048)</b></DT><DD>
5766 1.1 tron
5767 1.1 tron <p>
5768 1.1 tron The maximal length of MIME multipart boundary strings. The MIME
5769 1.1 tron processor is unable to distinguish between boundary strings that
5770 1.1 tron do not differ in the first $<a href="postconf.5.html#mime_boundary_length_limit">mime_boundary_length_limit</a> characters.
5771 1.1 tron </p>
5772 1.1 tron
5773 1.1 tron <p>
5774 1.1 tron This feature is available in Postfix 2.0 and later.
5775 1.1 tron </p>
5776 1.1 tron
5777 1.1 tron
5778 1.1 tron </DD>
5779 1.1 tron
5780 1.1 tron <DT><b><a name="mime_header_checks">mime_header_checks</a>
5781 1.1 tron (default: $<a href="postconf.5.html#header_checks">header_checks</a>)</b></DT><DD>
5782 1.1 tron
5783 1.1 tron <p>
5784 1.1 tron Optional lookup tables for content inspection of MIME related
5785 1.1 tron message headers, as described in the <a href="header_checks.5.html">header_checks(5)</a> manual page.
5786 1.1 tron </p>
5787 1.1 tron
5788 1.1 tron <p>
5789 1.1 tron This feature is available in Postfix 2.0 and later.
5790 1.1 tron </p>
5791 1.1 tron
5792 1.1 tron
5793 1.1 tron </DD>
5794 1.1 tron
5795 1.1 tron <DT><b><a name="mime_nesting_limit">mime_nesting_limit</a>
5796 1.1 tron (default: 100)</b></DT><DD>
5797 1.1 tron
5798 1.1 tron <p>
5799 1.1 tron The maximal recursion level that the MIME processor will handle.
5800 1.1 tron Postfix refuses mail that is nested deeper than the specified limit.
5801 1.1 tron </p>
5802 1.1 tron
5803 1.1 tron <p>
5804 1.1 tron This feature is available in Postfix 2.0 and later.
5805 1.1 tron </p>
5806 1.1 tron
5807 1.1 tron
5808 1.1 tron </DD>
5809 1.1 tron
5810 1.1 tron <DT><b><a name="minimal_backoff_time">minimal_backoff_time</a>
5811 1.1 tron (default: 300s)</b></DT><DD>
5812 1.1 tron
5813 1.1 tron <p>
5814 1.1 tron The minimal time between attempts to deliver a deferred message;
5815 1.1 tron prior to Postfix 2.4 the default value was 1000s.
5816 1.1 tron </p>
5817 1.1 tron
5818 1.1 tron <p>
5819 1.1 tron This parameter also limits the time an unreachable destination is
5820 1.1 tron kept in the short-term, in-memory, destination status cache.
5821 1.1 tron </p>
5822 1.1 tron
5823 1.1 tron <p> This parameter should be set greater than or equal to
5824 1.1 tron $<a href="postconf.5.html#queue_run_delay">queue_run_delay</a>. See also $<a href="postconf.5.html#maximal_backoff_time">maximal_backoff_time</a>. </p>
5825 1.1 tron
5826 1.1 tron <p>
5827 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
5828 1.1 tron The default time unit is s (seconds).
5829 1.1 tron </p>
5830 1.1 tron
5831 1.1 tron
5832 1.1 tron </DD>
5833 1.1 tron
5834 1.1 tron <DT><b><a name="multi_instance_directories">multi_instance_directories</a>
5835 1.1 tron (default: empty)</b></DT><DD>
5836 1.1 tron
5837 1.1 tron <p> An optional list of non-default Postfix configuration directories;
5838 1.1 tron these directories belong to additional Postfix instances that share
5839 1.1 tron the Postfix executable files and documentation with the default
5840 1.1 tron Postfix instance, and that are started, stopped, etc., together
5841 1.1 tron with the default Postfix instance. Specify a list of pathnames
5842 1.1 tron separated by comma or whitespace. </p>
5843 1.1 tron
5844 1.1 tron <p> When $<a href="postconf.5.html#multi_instance_directories">multi_instance_directories</a> is empty, the <a href="postfix.1.html">postfix(1)</a> command
5845 1.1 tron runs in single-instance mode and operates on a single Postfix
5846 1.1 tron instance only. Otherwise, the <a href="postfix.1.html">postfix(1)</a> command runs in multi-instance
5847 1.1 tron mode and invokes the multi-instance manager specified with the
5848 1.1 tron <a href="postconf.5.html#multi_instance_wrapper">multi_instance_wrapper</a> parameter. The multi-instance manager in
5849 1.1 tron turn executes <a href="postfix.1.html">postfix(1)</a> commands for the default instance and for
5850 1.1 tron all Postfix instances in $<a href="postconf.5.html#multi_instance_directories">multi_instance_directories</a>. </p>
5851 1.1 tron
5852 1.1 tron <p> Currently, this parameter setting is ignored except for the
5853 1.1 tron default <a href="postconf.5.html">main.cf</a> file. </p>
5854 1.1 tron
5855 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
5856 1.1 tron
5857 1.1 tron
5858 1.1 tron </DD>
5859 1.1 tron
5860 1.1 tron <DT><b><a name="multi_instance_enable">multi_instance_enable</a>
5861 1.1 tron (default: no)</b></DT><DD>
5862 1.1 tron
5863 1.1 tron <p> Allow this Postfix instance to be started, stopped, etc., by a
5864 1.1 tron multi-instance manager. By default, new instances are created in
5865 1.1 tron a safe state that prevents them from being started inadvertently.
5866 1.1 tron This parameter is reserved for the multi-instance manager. </p>
5867 1.1 tron
5868 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
5869 1.1 tron
5870 1.1 tron
5871 1.1 tron </DD>
5872 1.1 tron
5873 1.1 tron <DT><b><a name="multi_instance_group">multi_instance_group</a>
5874 1.1 tron (default: empty)</b></DT><DD>
5875 1.1 tron
5876 1.1 tron <p> The optional instance group name of this Postfix instance. A
5877 1.1 tron group identifies closely-related Postfix instances that the
5878 1.1 tron multi-instance manager can start, stop, etc., as a unit. This
5879 1.1 tron parameter is reserved for the multi-instance manager. </p>
5880 1.1 tron
5881 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
5882 1.1 tron
5883 1.1 tron
5884 1.1 tron </DD>
5885 1.1 tron
5886 1.1 tron <DT><b><a name="multi_instance_name">multi_instance_name</a>
5887 1.1 tron (default: empty)</b></DT><DD>
5888 1.1 tron
5889 1.1 tron <p> The optional instance name of this Postfix instance. This name
5890 1.1 tron becomes also the default value for the <a href="postconf.5.html#syslog_name">syslog_name</a> parameter. </p>
5891 1.1 tron
5892 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
5893 1.1 tron
5894 1.1 tron
5895 1.1 tron </DD>
5896 1.1 tron
5897 1.1 tron <DT><b><a name="multi_instance_wrapper">multi_instance_wrapper</a>
5898 1.1 tron (default: empty)</b></DT><DD>
5899 1.1 tron
5900 1.1 tron <p> The pathname of a multi-instance manager command that the
5901 1.1 tron <a href="postfix.1.html">postfix(1)</a> command invokes when the <a href="postconf.5.html#multi_instance_directories">multi_instance_directories</a>
5902 1.1 tron parameter value is non-empty. The pathname may be followed by
5903 1.1 tron initial command arguments separated by whitespace; shell
5904 1.1 tron metacharacters such as quotes are not supported in this context.
5905 1.1 tron </p>
5906 1.1 tron
5907 1.1 tron <p> The <a href="postfix.1.html">postfix(1)</a> command invokes the manager command with the
5908 1.1 tron <a href="postfix.1.html">postfix(1)</a> non-option command arguments on the manager command line,
5909 1.1 tron and with all installation configuration parameters exported into
5910 1.1 tron the manager command process environment. The manager command in
5911 1.1 tron turn invokes the <a href="postfix.1.html">postfix(1)</a> command for individual Postfix instances
5912 1.1 tron as "postfix -c <i><a href="postconf.5.html#config_directory">config_directory</a></i> <i>command</i>". </p>
5913 1.1 tron
5914 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
5915 1.1 tron
5916 1.1 tron
5917 1.1 tron </DD>
5918 1.1 tron
5919 1.1 tron <DT><b><a name="multi_recipient_bounce_reject_code">multi_recipient_bounce_reject_code</a>
5920 1.1 tron (default: 550)</b></DT><DD>
5921 1.1 tron
5922 1.1 tron <p>
5923 1.1 tron The numerical Postfix SMTP server response code when a remote SMTP
5924 1.1 tron client request is blocked by the <a href="postconf.5.html#reject_multi_recipient_bounce">reject_multi_recipient_bounce</a>
5925 1.1 tron restriction.
5926 1.1 tron </p>
5927 1.1 tron
5928 1.1 tron <p>
5929 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
5930 1.1 tron </p>
5931 1.1 tron
5932 1.1 tron <p>
5933 1.1 tron This feature is available in Postfix 2.1 and later.
5934 1.1 tron </p>
5935 1.1 tron
5936 1.1 tron
5937 1.1 tron </DD>
5938 1.1 tron
5939 1.1 tron <DT><b><a name="mydestination">mydestination</a>
5940 1.1 tron (default: $<a href="postconf.5.html#myhostname">myhostname</a>, localhost.$<a href="postconf.5.html#mydomain">mydomain</a>, localhost)</b></DT><DD>
5941 1.1 tron
5942 1.1 tron <p> The list of domains that are delivered via the $<a href="postconf.5.html#local_transport">local_transport</a>
5943 1.1 tron mail delivery transport. By default this is the Postfix <a href="local.8.html">local(8)</a>
5944 1.1 tron delivery agent which looks up all recipients in /etc/passwd and
5945 1.1 tron /etc/aliases. The SMTP server validates recipient addresses with
5946 1.1 tron $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> and rejects non-existent recipients. See also
5947 1.1 tron the <a href="ADDRESS_CLASS_README.html#local_domain_class">local domain</a> class in the <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a> file.
5948 1.1 tron </p>
5949 1.1 tron
5950 1.1 tron <p>
5951 1.1 tron The default <a href="postconf.5.html#mydestination">mydestination</a> value specifies names for the local
5952 1.1 tron machine only. On a mail domain gateway, you should also include
5953 1.1 tron $<a href="postconf.5.html#mydomain">mydomain</a>.
5954 1.1 tron </p>
5955 1.1 tron
5956 1.1 tron <p>
5957 1.1 tron The $<a href="postconf.5.html#local_transport">local_transport</a> delivery method is also selected for mail
5958 1.1 tron addressed to user@[the.net.work.address] of the mail system (the
5959 1.1 tron IP addresses specified with the <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> and <a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>
5960 1.1 tron parameters).
5961 1.1 tron </p>
5962 1.1 tron
5963 1.1 tron <p>
5964 1.1 tron Warnings:
5965 1.1 tron </p>
5966 1.1 tron
5967 1.1 tron <ul>
5968 1.1 tron
5969 1.1 tron <li><p>Do not specify the names of virtual domains - those domains
5970 1.1 tron are specified elsewhere. See <a href="VIRTUAL_README.html">VIRTUAL_README</a> for more information. </p>
5971 1.1 tron
5972 1.1 tron <li><p>Do not specify the names of domains that this machine is
5973 1.1 tron backup MX host for. See <a href="STANDARD_CONFIGURATION_README.html">STANDARD_CONFIGURATION_README</a> for how to
5974 1.1 tron set up backup MX hosts. </p>
5975 1.1 tron
5976 1.1 tron <li><p>By default, the Postfix SMTP server rejects mail for recipients
5977 1.1 tron not listed with the <a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> parameter. See the
5978 1.1 tron <a href="postconf.5.html">postconf(5)</a> manual for a description of the <a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a>
5979 1.1 tron and <a href="postconf.5.html#unknown_local_recipient_reject_code">unknown_local_recipient_reject_code</a> parameters. </p>
5980 1.1 tron
5981 1.1 tron </ul>
5982 1.1 tron
5983 1.1 tron <p>
5984 1.1 tron Specify a list of host or domain names, "/file/name" or "<a href="DATABASE_README.html">type:table</a>"
5985 1.1 tron patterns, separated by commas and/or whitespace. A "/file/name"
5986 1.1 tron pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table
5987 1.1 tron is matched when a name matches a lookup key (the lookup result is
5988 1.1 tron ignored). Continue long lines by starting the next line with
5989 1.1 tron whitespace. </p>
5990 1.1 tron
5991 1.1 tron <p>
5992 1.1 tron Examples:
5993 1.1 tron </p>
5994 1.1 tron
5995 1.1 tron <pre>
5996 1.1 tron <a href="postconf.5.html#mydestination">mydestination</a> = $<a href="postconf.5.html#myhostname">myhostname</a>, localhost.$<a href="postconf.5.html#mydomain">mydomain</a> $<a href="postconf.5.html#mydomain">mydomain</a>
5997 1.1 tron <a href="postconf.5.html#mydestination">mydestination</a> = $<a href="postconf.5.html#myhostname">myhostname</a>, localhost.$<a href="postconf.5.html#mydomain">mydomain</a> www.$<a href="postconf.5.html#mydomain">mydomain</a>, ftp.$<a href="postconf.5.html#mydomain">mydomain</a>
5998 1.1 tron </pre>
5999 1.1 tron
6000 1.1 tron
6001 1.1 tron </DD>
6002 1.1 tron
6003 1.1 tron <DT><b><a name="mydomain">mydomain</a>
6004 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6005 1.1 tron
6006 1.1 tron <p>
6007 1.1 tron The internet domain name of this mail system. The default is to
6008 1.1 tron use $<a href="postconf.5.html#myhostname">myhostname</a> minus the first component. $<a href="postconf.5.html#mydomain">mydomain</a> is used as
6009 1.1 tron a default value for many other configuration parameters.
6010 1.1 tron </p>
6011 1.1 tron
6012 1.1 tron <p>
6013 1.1 tron Example:
6014 1.1 tron </p>
6015 1.1 tron
6016 1.1 tron <pre>
6017 1.1 tron <a href="postconf.5.html#mydomain">mydomain</a> = domain.tld
6018 1.1 tron </pre>
6019 1.1 tron
6020 1.1 tron
6021 1.1 tron </DD>
6022 1.1 tron
6023 1.1 tron <DT><b><a name="myhostname">myhostname</a>
6024 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6025 1.1 tron
6026 1.1 tron <p>
6027 1.1 tron The internet hostname of this mail system. The default is to use
6028 1.1 tron the fully-qualified domain name from gethostname(). $<a href="postconf.5.html#myhostname">myhostname</a> is
6029 1.1 tron used as a default value for many other configuration parameters.
6030 1.1 tron </p>
6031 1.1 tron
6032 1.1 tron <p>
6033 1.1 tron Example:
6034 1.1 tron </p>
6035 1.1 tron
6036 1.1 tron <pre>
6037 1.1 tron <a href="postconf.5.html#myhostname">myhostname</a> = host.example.com
6038 1.1 tron </pre>
6039 1.1 tron
6040 1.1 tron
6041 1.1 tron </DD>
6042 1.1 tron
6043 1.1 tron <DT><b><a name="mynetworks">mynetworks</a>
6044 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6045 1.1 tron
6046 1.1 tron <p>
6047 1.1 tron The list of "trusted" SMTP clients that have more privileges than
6048 1.1 tron "strangers".
6049 1.1 tron </p>
6050 1.1 tron
6051 1.1 tron <p>
6052 1.1 tron In particular, "trusted" SMTP clients are allowed to relay mail
6053 1.1 tron through Postfix. See the <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a> parameter
6054 1.1 tron description in the <a href="postconf.5.html">postconf(5)</a> manual.
6055 1.1 tron </p>
6056 1.1 tron
6057 1.1 tron <p>
6058 1.1 tron You can specify the list of "trusted" network addresses by hand
6059 1.1 tron or you can let Postfix do it for you (which is the default).
6060 1.1 tron See the description of the <a href="postconf.5.html#mynetworks_style">mynetworks_style</a> parameter for more
6061 1.1 tron information.
6062 1.1 tron </p>
6063 1.1 tron
6064 1.1 tron <p>
6065 1.1 tron If you specify the <a href="postconf.5.html#mynetworks">mynetworks</a> list by hand,
6066 1.1 tron Postfix ignores the <a href="postconf.5.html#mynetworks_style">mynetworks_style</a> setting.
6067 1.1 tron </p>
6068 1.1 tron
6069 1.1 tron <p> Specify a list of network addresses or network/netmask patterns,
6070 1.1 tron separated by commas and/or whitespace. Continue long lines by
6071 1.1 tron starting the next line with whitespace. </p>
6072 1.1 tron
6073 1.1 tron <p> The netmask specifies the number of bits in the network part
6074 1.1 tron of a host address. You can also specify "/file/name" or "<a href="DATABASE_README.html">type:table</a>"
6075 1.1 tron patterns. A "/file/name" pattern is replaced by its contents; a
6076 1.1 tron "<a href="DATABASE_README.html">type:table</a>" lookup table is matched when a table entry matches a
6077 1.1 tron lookup string (the lookup result is ignored). </p>
6078 1.1 tron
6079 1.1 tron <p> The list is matched left to right, and the search stops on the
6080 1.1 tron first match. Specify "!pattern" to exclude an address or network
6081 1.1 tron block from the list. The form "!/file/name" is supported only
6082 1.1 tron in Postfix version 2.4 and later. </p>
6083 1.1 tron
6084 1.1 tron <p> Note: IP version 6 address information must be specified inside
6085 1.1 tron <tt>[]</tt> in the <a href="postconf.5.html#mynetworks">mynetworks</a> value, and in files specified with
6086 1.1 tron "/file/name". IP version 6 addresses contain the ":" character,
6087 1.1 tron and would otherwise be confused with a "<a href="DATABASE_README.html">type:table</a>" pattern. </p>
6088 1.1 tron
6089 1.1 tron <p> Examples: </p>
6090 1.1 tron
6091 1.1 tron <pre>
6092 1.1 tron <a href="postconf.5.html#mynetworks">mynetworks</a> = 127.0.0.0/8 168.100.189.0/28
6093 1.1 tron <a href="postconf.5.html#mynetworks">mynetworks</a> = !192.168.0.1, 192.168.0.0/28
6094 1.1 tron <a href="postconf.5.html#mynetworks">mynetworks</a> = 127.0.0.0/8 168.100.189.0/28 [::1]/128 [2001:240:587::]/64
6095 1.1 tron <a href="postconf.5.html#mynetworks">mynetworks</a> = $<a href="postconf.5.html#config_directory">config_directory</a>/mynetworks
6096 1.1 tron <a href="postconf.5.html#mynetworks">mynetworks</a> = hash:/etc/postfix/network_table
6097 1.1 tron </pre>
6098 1.1 tron
6099 1.1 tron
6100 1.1 tron </DD>
6101 1.1 tron
6102 1.1 tron <DT><b><a name="mynetworks_style">mynetworks_style</a>
6103 1.1 tron (default: subnet)</b></DT><DD>
6104 1.1 tron
6105 1.1 tron <p>
6106 1.1 tron The method to generate the default value for the <a href="postconf.5.html#mynetworks">mynetworks</a> parameter.
6107 1.1 tron This is the list of trusted networks for relay access control etc.
6108 1.1 tron </p>
6109 1.1 tron
6110 1.1 tron <ul>
6111 1.1 tron
6112 1.1 tron <li><p>Specify "<a href="postconf.5.html#mynetworks_style">mynetworks_style</a> = host" when Postfix should
6113 1.1 tron "trust" only the local machine. </p>
6114 1.1 tron
6115 1.1 tron <li><p>Specify "<a href="postconf.5.html#mynetworks_style">mynetworks_style</a> = subnet" when Postfix
6116 1.1 tron should "trust" SMTP clients in the same IP subnetworks as the local
6117 1.1 tron machine. On Linux, this works correctly only with interfaces
6118 1.1 tron specified with the "ifconfig" command. </p>
6119 1.1 tron
6120 1.1 tron <li><p>Specify "<a href="postconf.5.html#mynetworks_style">mynetworks_style</a> = class" when Postfix should
6121 1.1 tron "trust" SMTP clients in the same IP class A/B/C networks as the
6122 1.1 tron local machine. Don't do this with a dialup site - it would cause
6123 1.1 tron Postfix to "trust" your entire provider's network. Instead, specify
6124 1.1 tron an explicit <a href="postconf.5.html#mynetworks">mynetworks</a> list by hand, as described with the <a href="postconf.5.html#mynetworks">mynetworks</a>
6125 1.1 tron configuration parameter. </p>
6126 1.1 tron
6127 1.1 tron </ul>
6128 1.1 tron
6129 1.1 tron
6130 1.1 tron </DD>
6131 1.1 tron
6132 1.1 tron <DT><b><a name="myorigin">myorigin</a>
6133 1.1 tron (default: $<a href="postconf.5.html#myhostname">myhostname</a>)</b></DT><DD>
6134 1.1 tron
6135 1.1 tron <p>
6136 1.1 tron The domain name that locally-posted mail appears to come
6137 1.1 tron from, and that locally posted mail is delivered to. The default,
6138 1.1 tron $<a href="postconf.5.html#myhostname">myhostname</a>, is adequate for small sites. If you run a domain with
6139 1.1 tron multiple machines, you should (1) change this to $<a href="postconf.5.html#mydomain">mydomain</a> and (2)
6140 1.1 tron set up a domain-wide alias database that aliases each user to
6141 1.1 tron user (a] that.users.mailhost.
6142 1.1 tron </p>
6143 1.1 tron
6144 1.1 tron <p>
6145 1.1 tron Example:
6146 1.1 tron </p>
6147 1.1 tron
6148 1.1 tron <pre>
6149 1.1 tron <a href="postconf.5.html#myorigin">myorigin</a> = $<a href="postconf.5.html#mydomain">mydomain</a>
6150 1.1 tron </pre>
6151 1.1 tron
6152 1.1 tron
6153 1.1 tron </DD>
6154 1.1 tron
6155 1.1 tron <DT><b><a name="nested_header_checks">nested_header_checks</a>
6156 1.1 tron (default: $<a href="postconf.5.html#header_checks">header_checks</a>)</b></DT><DD>
6157 1.1 tron
6158 1.1 tron <p>
6159 1.1 tron Optional lookup tables for content inspection of non-MIME message
6160 1.1 tron headers in attached messages, as described in the <a href="header_checks.5.html">header_checks(5)</a>
6161 1.1 tron manual page.
6162 1.1 tron </p>
6163 1.1 tron
6164 1.1 tron <p>
6165 1.1 tron This feature is available in Postfix 2.0 and later.
6166 1.1 tron </p>
6167 1.1 tron
6168 1.1 tron
6169 1.1 tron </DD>
6170 1.1 tron
6171 1.1 tron <DT><b><a name="newaliases_path">newaliases_path</a>
6172 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6173 1.1 tron
6174 1.1 tron <p>
6175 1.1 tron Sendmail compatibility feature that specifies the location of the
6176 1.1 tron <a href="newaliases.1.html">newaliases(1)</a> command. This command can be used to rebuild the
6177 1.1 tron <a href="local.8.html">local(8)</a> <a href="aliases.5.html">aliases(5)</a> database.
6178 1.1 tron </p>
6179 1.1 tron
6180 1.1 tron
6181 1.1 tron </DD>
6182 1.1 tron
6183 1.1 tron <DT><b><a name="non_fqdn_reject_code">non_fqdn_reject_code</a>
6184 1.1 tron (default: 504)</b></DT><DD>
6185 1.1 tron
6186 1.1 tron <p>
6187 1.1 tron The numerical Postfix SMTP server reply code when a client request
6188 1.1 tron is rejected by the <a href="postconf.5.html#reject_non_fqdn_helo_hostname">reject_non_fqdn_helo_hostname</a>, <a href="postconf.5.html#reject_non_fqdn_sender">reject_non_fqdn_sender</a>
6189 1.1 tron or <a href="postconf.5.html#reject_non_fqdn_recipient">reject_non_fqdn_recipient</a> restriction.
6190 1.1 tron </p>
6191 1.1 tron
6192 1.1 tron
6193 1.1 tron </DD>
6194 1.1 tron
6195 1.1 tron <DT><b><a name="non_smtpd_milters">non_smtpd_milters</a>
6196 1.1 tron (default: empty)</b></DT><DD>
6197 1.1 tron
6198 1.1 tron <p> A list of Milter (mail filter) applications for new mail that
6199 1.1 tron does not arrive via the Postfix <a href="smtpd.8.html">smtpd(8)</a> server. This includes local
6200 1.1 tron submission via the <a href="sendmail.1.html">sendmail(1)</a> command line, new mail that arrives
6201 1.1 tron via the Postfix <a href="qmqpd.8.html">qmqpd(8)</a> server, and old mail that is re-injected
6202 1.1 tron into the queue with "postsuper -r". See the <a href="MILTER_README.html">MILTER_README</a> document
6203 1.1 tron for details. </p>
6204 1.1 tron
6205 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
6206 1.1 tron
6207 1.1 tron
6208 1.1 tron </DD>
6209 1.1 tron
6210 1.1 tron <DT><b><a name="notify_classes">notify_classes</a>
6211 1.1 tron (default: resource, software)</b></DT><DD>
6212 1.1 tron
6213 1.1 tron <p>
6214 1.1 tron The list of error classes that are reported to the postmaster. The
6215 1.1 tron default is to report only the most serious problems. The paranoid
6216 1.1 tron may wish to turn on the policy (UCE and mail relaying) and protocol
6217 1.1 tron error (broken mail software) reports.
6218 1.1 tron </p>
6219 1.1 tron
6220 1.1 tron <p> NOTE: postmaster notifications may contain confidential information
6221 1.1 tron such as SASL passwords or message content. It is the system
6222 1.1 tron administrator's responsibility to treat such information with care.
6223 1.1 tron </p>
6224 1.1 tron
6225 1.1 tron <p>
6226 1.1 tron The error classes are:
6227 1.1 tron </p>
6228 1.1 tron
6229 1.1 tron <dl>
6230 1.1 tron
6231 1.1 tron <dt><b>bounce</b> (also implies <b>2bounce</b>)</dt>
6232 1.1 tron
6233 1.1 tron <dd>Send the postmaster copies of the headers of bounced mail, and
6234 1.1 tron send transcripts of SMTP sessions when Postfix rejects mail. The
6235 1.1 tron notification is sent to the address specified with the
6236 1.1 tron <a href="postconf.5.html#bounce_notice_recipient">bounce_notice_recipient</a> configuration parameter (default: postmaster).
6237 1.1 tron </dd>
6238 1.1 tron
6239 1.1 tron <dt><b>2bounce</b></dt>
6240 1.1 tron
6241 1.1 tron <dd>Send undeliverable bounced mail to the postmaster. The notification
6242 1.1 tron is sent to the address specified with the <a href="postconf.5.html#2bounce_notice_recipient">2bounce_notice_recipient</a>
6243 1.1 tron configuration parameter (default: postmaster). </dd>
6244 1.1 tron
6245 1.1 tron <dt><b>delay</b></dt>
6246 1.1 tron
6247 1.1 tron <dd>Send the postmaster copies of the headers of delayed mail. The
6248 1.1 tron notification is sent to the address specified with the
6249 1.1 tron <a href="postconf.5.html#delay_notice_recipient">delay_notice_recipient</a> configuration parameter (default: postmaster).
6250 1.1 tron </dd>
6251 1.1 tron
6252 1.1 tron <dt><b>policy</b></dt>
6253 1.1 tron
6254 1.1 tron <dd>Send the postmaster a transcript of the SMTP session when a
6255 1.1 tron client request was rejected because of (UCE) policy. The notification
6256 1.1 tron is sent to the address specified with the <a href="postconf.5.html#error_notice_recipient">error_notice_recipient</a>
6257 1.1 tron configuration parameter (default: postmaster). </dd>
6258 1.1 tron
6259 1.1 tron <dt><b>protocol</b></dt>
6260 1.1 tron
6261 1.1 tron <dd>Send the postmaster a transcript of the SMTP session in case
6262 1.1 tron of client or server protocol errors. The notification is sent to
6263 1.1 tron the address specified with the <a href="postconf.5.html#error_notice_recipient">error_notice_recipient</a> configuration
6264 1.1 tron parameter (default: postmaster). </dd>
6265 1.1 tron
6266 1.1 tron <dt><b>resource</b></dt>
6267 1.1 tron
6268 1.1 tron <dd>Inform the postmaster of mail not delivered due to resource
6269 1.1 tron problems. The notification is sent to the address specified with
6270 1.1 tron the <a href="postconf.5.html#error_notice_recipient">error_notice_recipient</a> configuration parameter (default:
6271 1.1 tron postmaster). </dd>
6272 1.1 tron
6273 1.1 tron <dt><b>software</b></dt>
6274 1.1 tron
6275 1.1 tron <dd>Inform the postmaster of mail not delivered due to software
6276 1.1 tron problems. The notification is sent to the address specified with
6277 1.1 tron the <a href="postconf.5.html#error_notice_recipient">error_notice_recipient</a> configuration parameter (default:
6278 1.1 tron postmaster). </dd>
6279 1.1 tron
6280 1.1 tron </dl>
6281 1.1 tron
6282 1.1 tron <p>
6283 1.1 tron Examples:
6284 1.1 tron </p>
6285 1.1 tron
6286 1.1 tron <pre>
6287 1.1 tron <a href="postconf.5.html#notify_classes">notify_classes</a> = bounce, delay, policy, protocol, resource, software
6288 1.1 tron <a href="postconf.5.html#notify_classes">notify_classes</a> = 2bounce, resource, software
6289 1.1 tron </pre>
6290 1.1 tron
6291 1.1 tron
6292 1.1 tron </DD>
6293 1.1 tron
6294 1.1 tron <DT><b><a name="owner_request_special">owner_request_special</a>
6295 1.1 tron (default: yes)</b></DT><DD>
6296 1.1 tron
6297 1.1 tron <p>
6298 1.1 tron Give special treatment to owner-listname and listname-request
6299 1.1 tron address localparts: don't split such addresses when the
6300 1.1 tron <a href="postconf.5.html#recipient_delimiter">recipient_delimiter</a> is set to "-". This feature is useful for
6301 1.1 tron mailing lists.
6302 1.1 tron </p>
6303 1.1 tron
6304 1.1 tron
6305 1.1 tron </DD>
6306 1.1 tron
6307 1.1 tron <DT><b><a name="parent_domain_matches_subdomains">parent_domain_matches_subdomains</a>
6308 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6309 1.1 tron
6310 1.1 tron <p>
6311 1.1 tron What Postfix features match subdomains of "domain.tld" automatically,
6312 1.1 tron instead of requiring an explicit ".domain.tld" pattern. This is
6313 1.1 tron planned backwards compatibility: eventually, all Postfix features
6314 1.1 tron are expected to require explicit ".domain.tld" style patterns when
6315 1.1 tron you really want to match subdomains.
6316 1.1 tron </p>
6317 1.1 tron
6318 1.1 tron
6319 1.1 tron </DD>
6320 1.1 tron
6321 1.1 tron <DT><b><a name="permit_mx_backup_networks">permit_mx_backup_networks</a>
6322 1.1 tron (default: empty)</b></DT><DD>
6323 1.1 tron
6324 1.1 tron <p>
6325 1.1 tron Restrict the use of the <a href="postconf.5.html#permit_mx_backup">permit_mx_backup</a> SMTP access feature to
6326 1.1 tron only domains whose primary MX hosts match the listed networks.
6327 1.1 tron The parameter value syntax is the same as with the <a href="postconf.5.html#mynetworks">mynetworks</a>
6328 1.1 tron parameter; note, however, that the default value is empty. </p>
6329 1.1 tron
6330 1.1 tron
6331 1.1 tron </DD>
6332 1.1 tron
6333 1.1 tron <DT><b><a name="pickup_service_name">pickup_service_name</a>
6334 1.1 tron (default: pickup)</b></DT><DD>
6335 1.1 tron
6336 1.1 tron <p>
6337 1.1 tron The name of the <a href="pickup.8.html">pickup(8)</a> service. This service picks up local mail
6338 1.1 tron submissions from the Postfix <a href="QSHAPE_README.html#maildrop_queue">maildrop queue</a>.
6339 1.1 tron </p>
6340 1.1 tron
6341 1.1 tron <p>
6342 1.1 tron This feature is available in Postfix 2.0 and later.
6343 1.1 tron </p>
6344 1.1 tron
6345 1.1 tron
6346 1.1 tron </DD>
6347 1.1 tron
6348 1.1 tron <DT><b><a name="plaintext_reject_code">plaintext_reject_code</a>
6349 1.1 tron (default: 450)</b></DT><DD>
6350 1.1 tron
6351 1.1 tron <p>
6352 1.1 tron The numerical Postfix SMTP server response code when a request
6353 1.1 tron is rejected by the <b><a href="postconf.5.html#reject_plaintext_session">reject_plaintext_session</a></b> restriction.
6354 1.1 tron </p>
6355 1.1 tron
6356 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
6357 1.1 tron
6358 1.1 tron
6359 1.1 tron </DD>
6360 1.1 tron
6361 1.1 tron <DT><b><a name="postmulti_control_commands">postmulti_control_commands</a>
6362 1.1 tron (default: reload flush)</b></DT><DD>
6363 1.1 tron
6364 1.1 tron <p> The <a href="postfix.1.html">postfix(1)</a> commands that the <a href="postmulti.1.html">postmulti(1)</a> instance manager
6365 1.1 tron treats as "control" commands, that operate on running instances. For
6366 1.1 tron these commands, disabled instances are skipped. </p>
6367 1.1 tron
6368 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
6369 1.1 tron
6370 1.1 tron
6371 1.1 tron </DD>
6372 1.1 tron
6373 1.1 tron <DT><b><a name="postmulti_start_commands">postmulti_start_commands</a>
6374 1.1 tron (default: start)</b></DT><DD>
6375 1.1 tron
6376 1.1 tron <p> The <a href="postfix.1.html">postfix(1)</a> commands that the <a href="postmulti.1.html">postmulti(1)</a> instance manager treats
6377 1.1 tron as "start" commands. For these commands, disabled instances are "checked"
6378 1.1 tron rather than "started", and failure to "start" a member instance of an
6379 1.1 tron instance group will abort the start-up of later instances. </p>
6380 1.1 tron
6381 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
6382 1.1 tron
6383 1.1 tron
6384 1.1 tron </DD>
6385 1.1 tron
6386 1.1 tron <DT><b><a name="postmulti_stop_commands">postmulti_stop_commands</a>
6387 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6388 1.1 tron
6389 1.1 tron <p> The <a href="postfix.1.html">postfix(1)</a> commands that the <a href="postmulti.1.html">postmulti(1)</a> instance manager treats
6390 1.1 tron as "stop" commands. For these commands, disabled instances are skipped,
6391 1.1 tron and enabled instances are processed in reverse order. </p>
6392 1.1 tron
6393 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
6394 1.1 tron
6395 1.1 tron
6396 1.1 tron </DD>
6397 1.1 tron
6398 1.1 tron <DT><b><a name="prepend_delivered_header">prepend_delivered_header</a>
6399 1.1 tron (default: command, file, forward)</b></DT><DD>
6400 1.1 tron
6401 1.1 tron <p> The message delivery contexts where the Postfix <a href="local.8.html">local(8)</a> delivery
6402 1.1 tron agent prepends a Delivered-To: message header with the address
6403 1.1 tron that the mail was delivered to. This information is used for mail
6404 1.1 tron delivery loop detection. </p>
6405 1.1 tron
6406 1.1 tron <p>
6407 1.1 tron By default, the Postfix local delivery agent prepends a Delivered-To:
6408 1.1 tron header when forwarding mail and when delivering to file (mailbox)
6409 1.1 tron and command. Turning off the Delivered-To: header when forwarding
6410 1.1 tron mail is not recommended.
6411 1.1 tron </p>
6412 1.1 tron
6413 1.1 tron <p>
6414 1.1 tron Specify zero or more of <b>forward</b>, <b>file</b>, or <b>command</b>.
6415 1.1 tron </p>
6416 1.1 tron
6417 1.1 tron <p>
6418 1.1 tron Example:
6419 1.1 tron </p>
6420 1.1 tron
6421 1.1 tron <pre>
6422 1.1 tron <a href="postconf.5.html#prepend_delivered_header">prepend_delivered_header</a> = forward
6423 1.1 tron </pre>
6424 1.1 tron
6425 1.1 tron
6426 1.1 tron </DD>
6427 1.1 tron
6428 1.1 tron <DT><b><a name="process_id">process_id</a>
6429 1.1 tron (read-only)</b></DT><DD>
6430 1.1 tron
6431 1.1 tron <p>
6432 1.1 tron The process ID of a Postfix command or daemon process.
6433 1.1 tron </p>
6434 1.1 tron
6435 1.1 tron
6436 1.1 tron </DD>
6437 1.1 tron
6438 1.1 tron <DT><b><a name="process_id_directory">process_id_directory</a>
6439 1.1 tron (default: pid)</b></DT><DD>
6440 1.1 tron
6441 1.1 tron <p>
6442 1.1 tron The location of Postfix PID files relative to $<a href="postconf.5.html#queue_directory">queue_directory</a>.
6443 1.1 tron This is a read-only parameter.
6444 1.1 tron </p>
6445 1.1 tron
6446 1.1 tron
6447 1.1 tron </DD>
6448 1.1 tron
6449 1.1 tron <DT><b><a name="process_name">process_name</a>
6450 1.1 tron (read-only)</b></DT><DD>
6451 1.1 tron
6452 1.1 tron <p>
6453 1.1 tron The process name of a Postfix command or daemon process.
6454 1.1 tron </p>
6455 1.1 tron
6456 1.1 tron
6457 1.1 tron </DD>
6458 1.1 tron
6459 1.1 tron <DT><b><a name="propagate_unmatched_extensions">propagate_unmatched_extensions</a>
6460 1.1 tron (default: canonical, virtual)</b></DT><DD>
6461 1.1 tron
6462 1.1 tron <p>
6463 1.1 tron What address lookup tables copy an address extension from the lookup
6464 1.1 tron key to the lookup result.
6465 1.1 tron </p>
6466 1.1 tron
6467 1.1 tron <p>
6468 1.1 tron For example, with a <a href="virtual.5.html">virtual(5)</a> mapping of "<i>joe (a] example.com =>
6469 1.1 tron joe.user (a] example.net</i>", the address "<i>joe+foo (a] example.com</i>"
6470 1.1 tron would rewrite to "<i>joe.user+foo (a] example.net</i>".
6471 1.1 tron </p>
6472 1.1 tron
6473 1.1 tron <p>
6474 1.1 tron Specify zero or more of <b>canonical</b>, <b>virtual</b>, <b>alias</b>,
6475 1.1 tron <b>forward</b>, <b>include</b> or <b>generic</b>. These cause
6476 1.1 tron address extension
6477 1.1 tron propagation with <a href="canonical.5.html">canonical(5)</a>, <a href="virtual.5.html">virtual(5)</a>, and <a href="aliases.5.html">aliases(5)</a> maps,
6478 1.1 tron with <a href="local.8.html">local(8)</a> .forward and :include: file lookups, and with <a href="smtp.8.html">smtp(8)</a>
6479 1.1 tron generic maps, respectively. </p>
6480 1.1 tron
6481 1.1 tron <p>
6482 1.1 tron Note: enabling this feature for types other than <b>canonical</b>
6483 1.1 tron and <b>virtual</b> is likely to cause problems when mail is forwarded
6484 1.1 tron to other sites, especially with mail that is sent to a mailing list
6485 1.1 tron exploder address.
6486 1.1 tron </p>
6487 1.1 tron
6488 1.1 tron <p>
6489 1.1 tron Examples:
6490 1.1 tron </p>
6491 1.1 tron
6492 1.1 tron <pre>
6493 1.1 tron <a href="postconf.5.html#propagate_unmatched_extensions">propagate_unmatched_extensions</a> = canonical, virtual, alias,
6494 1.1 tron forward, include
6495 1.1 tron <a href="postconf.5.html#propagate_unmatched_extensions">propagate_unmatched_extensions</a> = canonical, virtual
6496 1.1 tron </pre>
6497 1.1 tron
6498 1.1 tron
6499 1.1 tron </DD>
6500 1.1 tron
6501 1.1 tron <DT><b><a name="proxy_interfaces">proxy_interfaces</a>
6502 1.1 tron (default: empty)</b></DT><DD>
6503 1.1 tron
6504 1.1 tron <p>
6505 1.1 tron The network interface addresses that this mail system receives mail
6506 1.1 tron on by way of a proxy or network address translation unit.
6507 1.1 tron </p>
6508 1.1 tron
6509 1.1 tron <p>
6510 1.1 tron This feature is available in Postfix 2.0 and later.
6511 1.1 tron </p>
6512 1.1 tron
6513 1.1 tron <p> You must specify your "outside" proxy/NAT addresses when your
6514 1.1 tron system is a backup MX host for other domains, otherwise mail delivery
6515 1.1 tron loops will happen when the primary MX host is down. </p>
6516 1.1 tron
6517 1.1 tron <p>
6518 1.1 tron Example:
6519 1.1 tron </p>
6520 1.1 tron
6521 1.1 tron <pre>
6522 1.1 tron <a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a> = 1.2.3.4
6523 1.1 tron </pre>
6524 1.1 tron
6525 1.1 tron
6526 1.1 tron </DD>
6527 1.1 tron
6528 1.1 tron <DT><b><a name="proxy_read_maps">proxy_read_maps</a>
6529 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6530 1.1 tron
6531 1.1 tron <p>
6532 1.1 tron The lookup tables that the <a href="proxymap.8.html">proxymap(8)</a> server is allowed to
6533 1.1 tron access for the read-only service.
6534 1.1 tron Table references that don't begin with <a href="proxymap.8.html">proxy</a>: are ignored.
6535 1.1 tron </p>
6536 1.1 tron
6537 1.1 tron <p>
6538 1.1 tron This feature is available in Postfix 2.0 and later.
6539 1.1 tron </p>
6540 1.1 tron
6541 1.1 tron
6542 1.1 tron </DD>
6543 1.1 tron
6544 1.1 tron <DT><b><a name="proxy_write_maps">proxy_write_maps</a>
6545 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6546 1.1 tron
6547 1.1 tron <p> The lookup tables that the <a href="proxymap.8.html">proxymap(8)</a> server is allowed to
6548 1.1 tron access for the read-write service. Postfix-owned local database
6549 1.1 tron files should be stored under the Postfix-owned <a href="postconf.5.html#data_directory">data_directory</a>.
6550 1.1 tron Table references that don't begin with <a href="proxymap.8.html">proxy</a>: are ignored. </p>
6551 1.1 tron
6552 1.1 tron <p>
6553 1.1 tron This feature is available in Postfix 2.5 and later.
6554 1.1 tron </p>
6555 1.1 tron
6556 1.1 tron
6557 1.1 tron </DD>
6558 1.1 tron
6559 1.1 tron <DT><b><a name="proxymap_service_name">proxymap_service_name</a>
6560 1.1 tron (default: proxymap)</b></DT><DD>
6561 1.1 tron
6562 1.1 tron <p> The name of the proxymap read-only table lookup service. This
6563 1.1 tron service is normally implemented by the <a href="proxymap.8.html">proxymap(8)</a> daemon. </p>
6564 1.1 tron
6565 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
6566 1.1 tron
6567 1.1 tron
6568 1.1 tron </DD>
6569 1.1 tron
6570 1.1 tron <DT><b><a name="proxywrite_service_name">proxywrite_service_name</a>
6571 1.1 tron (default: proxywrite)</b></DT><DD>
6572 1.1 tron
6573 1.1 tron <p> The name of the proxywrite read-write table lookup service.
6574 1.1 tron This service is normally implemented by the <a href="proxymap.8.html">proxymap(8)</a> daemon.
6575 1.1 tron </p>
6576 1.1 tron
6577 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
6578 1.1 tron
6579 1.1 tron
6580 1.1 tron </DD>
6581 1.1 tron
6582 1.1 tron <DT><b><a name="qmgr_clog_warn_time">qmgr_clog_warn_time</a>
6583 1.1 tron (default: 300s)</b></DT><DD>
6584 1.1 tron
6585 1.1 tron <p>
6586 1.1 tron The minimal delay between warnings that a specific destination is
6587 1.1 tron clogging up the Postfix <a href="QSHAPE_README.html#active_queue">active queue</a>. Specify 0 to disable.
6588 1.1 tron </p>
6589 1.1 tron
6590 1.1 tron <p>
6591 1.1 tron This feature is enabled with the <a href="postconf.5.html#helpful_warnings">helpful_warnings</a> parameter.
6592 1.1 tron </p>
6593 1.1 tron
6594 1.1 tron <p>
6595 1.1 tron This feature is available in Postfix 2.0 and later.
6596 1.1 tron </p>
6597 1.1 tron
6598 1.1 tron
6599 1.1 tron </DD>
6600 1.1 tron
6601 1.1 tron <DT><b><a name="qmgr_fudge_factor">qmgr_fudge_factor</a>
6602 1.1 tron (default: 100)</b></DT><DD>
6603 1.1 tron
6604 1.1 tron <p>
6605 1.1 tron Obsolete feature: the percentage of delivery resources that a busy
6606 1.1 tron mail system will use up for delivery of a large mailing list
6607 1.1 tron message.
6608 1.1 tron </p>
6609 1.1 tron
6610 1.1 tron <p>
6611 1.1 tron This feature exists only in the <a href="qmgr.8.html">oqmgr(8)</a> old queue manager. The
6612 1.1 tron current queue manager solves the problem in a better way.
6613 1.1 tron </p>
6614 1.1 tron
6615 1.1 tron
6616 1.1 tron </DD>
6617 1.1 tron
6618 1.1 tron <DT><b><a name="qmgr_message_active_limit">qmgr_message_active_limit</a>
6619 1.1 tron (default: 20000)</b></DT><DD>
6620 1.1 tron
6621 1.1 tron <p>
6622 1.1 tron The maximal number of messages in the <a href="QSHAPE_README.html#active_queue">active queue</a>.
6623 1.1 tron </p>
6624 1.1 tron
6625 1.1 tron
6626 1.1 tron </DD>
6627 1.1 tron
6628 1.1 tron <DT><b><a name="qmgr_message_recipient_limit">qmgr_message_recipient_limit</a>
6629 1.1 tron (default: 20000)</b></DT><DD>
6630 1.1 tron
6631 1.1 tron <p> The maximal number of recipients held in memory by the Postfix
6632 1.1 tron queue manager, and the maximal size of the size of the short-term,
6633 1.1 tron in-memory "dead" destination status cache. </p>
6634 1.1 tron
6635 1.1 tron
6636 1.1 tron </DD>
6637 1.1 tron
6638 1.1 tron <DT><b><a name="qmgr_message_recipient_minimum">qmgr_message_recipient_minimum</a>
6639 1.1 tron (default: 10)</b></DT><DD>
6640 1.1 tron
6641 1.1 tron <p>
6642 1.1 tron The minimal number of in-memory recipients for any message. This
6643 1.1 tron takes priority over any other in-memory recipient limits (i.e.,
6644 1.1 tron the global <a href="postconf.5.html#qmgr_message_recipient_limit">qmgr_message_recipient_limit</a> and the per transport
6645 1.1 tron _recipient_limit) if necessary. The minimum value allowed for this
6646 1.1 tron parameter is 1.
6647 1.1 tron </p>
6648 1.1 tron
6649 1.1 tron
6650 1.1 tron </DD>
6651 1.1 tron
6652 1.1 tron <DT><b><a name="qmqpd_authorized_clients">qmqpd_authorized_clients</a>
6653 1.1 tron (default: empty)</b></DT><DD>
6654 1.1 tron
6655 1.1 tron <p>
6656 1.1 tron What clients are allowed to connect to the QMQP server port.
6657 1.1 tron </p>
6658 1.1 tron
6659 1.1 tron <p>
6660 1.1 tron By default, no client is allowed to use the service. This is
6661 1.1 tron because the QMQP server will relay mail to any destination.
6662 1.1 tron </p>
6663 1.1 tron
6664 1.1 tron <p>
6665 1.1 tron Specify a list of client patterns. A list pattern specifies a host
6666 1.1 tron name, a domain name, an internet address, or a network/mask pattern,
6667 1.1 tron where the mask specifies the number of bits in the network part.
6668 1.1 tron When a pattern specifies a file name, its contents are substituted
6669 1.1 tron for the file name; when a pattern is a "<a href="DATABASE_README.html">type:table</a>" table specification,
6670 1.1 tron table lookup is used instead. </p>
6671 1.1 tron
6672 1.1 tron <p>
6673 1.1 tron Patterns are separated by whitespace and/or commas. In order to
6674 1.1 tron reverse the result, precede a pattern with an
6675 1.1 tron exclamation point (!). The form "!/file/name" is supported only
6676 1.1 tron in Postfix version 2.4 and later.
6677 1.1 tron </p>
6678 1.1 tron
6679 1.1 tron <p>
6680 1.1 tron Example:
6681 1.1 tron </p>
6682 1.1 tron
6683 1.1 tron <pre>
6684 1.1 tron <a href="postconf.5.html#qmqpd_authorized_clients">qmqpd_authorized_clients</a> = !192.168.0.1, 192.168.0.0/24
6685 1.1 tron </pre>
6686 1.1 tron
6687 1.1 tron
6688 1.1 tron </DD>
6689 1.1 tron
6690 1.1 tron <DT><b><a name="qmqpd_client_port_logging">qmqpd_client_port_logging</a>
6691 1.1 tron (default: no)</b></DT><DD>
6692 1.1 tron
6693 1.1 tron <p> Enable logging of the remote QMQP client port in addition to
6694 1.1 tron the hostname and IP address. The logging format is "host[address]:port".
6695 1.1 tron </p>
6696 1.1 tron
6697 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
6698 1.1 tron
6699 1.1 tron
6700 1.1 tron </DD>
6701 1.1 tron
6702 1.1 tron <DT><b><a name="qmqpd_error_delay">qmqpd_error_delay</a>
6703 1.1 tron (default: 1s)</b></DT><DD>
6704 1.1 tron
6705 1.1 tron <p>
6706 1.1 tron How long the QMQP server will pause before sending a negative reply
6707 1.1 tron to the client. The purpose is to slow down confused or malicious
6708 1.1 tron clients.
6709 1.1 tron </p>
6710 1.1 tron
6711 1.1 tron <p>
6712 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
6713 1.1 tron The default time unit is s (seconds).
6714 1.1 tron </p>
6715 1.1 tron
6716 1.1 tron
6717 1.1 tron </DD>
6718 1.1 tron
6719 1.1 tron <DT><b><a name="qmqpd_timeout">qmqpd_timeout</a>
6720 1.1 tron (default: 300s)</b></DT><DD>
6721 1.1 tron
6722 1.1 tron <p>
6723 1.1 tron The time limit for sending or receiving information over the network.
6724 1.1 tron If a read or write operation blocks for more than $<a href="postconf.5.html#qmqpd_timeout">qmqpd_timeout</a>
6725 1.1 tron seconds the QMQP server gives up and disconnects.
6726 1.1 tron </p>
6727 1.1 tron
6728 1.1 tron <p>
6729 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
6730 1.1 tron The default time unit is s (seconds).
6731 1.1 tron </p>
6732 1.1 tron
6733 1.1 tron
6734 1.1 tron </DD>
6735 1.1 tron
6736 1.1 tron <DT><b><a name="queue_directory">queue_directory</a>
6737 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6738 1.1 tron
6739 1.1 tron <p>
6740 1.1 tron The location of the Postfix top-level queue directory. This is the
6741 1.1 tron root directory of Postfix daemon processes that run chrooted.
6742 1.1 tron </p>
6743 1.1 tron
6744 1.1 tron
6745 1.1 tron </DD>
6746 1.1 tron
6747 1.1 tron <DT><b><a name="queue_file_attribute_count_limit">queue_file_attribute_count_limit</a>
6748 1.1 tron (default: 100)</b></DT><DD>
6749 1.1 tron
6750 1.1 tron <p>
6751 1.1 tron The maximal number of (name=value) attributes that may be stored
6752 1.1 tron in a Postfix queue file. The limit is enforced by the <a href="cleanup.8.html">cleanup(8)</a>
6753 1.1 tron server.
6754 1.1 tron </p>
6755 1.1 tron
6756 1.1 tron <p>
6757 1.1 tron This feature is available in Postfix 2.0 and later.
6758 1.1 tron </p>
6759 1.1 tron
6760 1.1 tron
6761 1.1 tron </DD>
6762 1.1 tron
6763 1.1 tron <DT><b><a name="queue_minfree">queue_minfree</a>
6764 1.1 tron (default: 0)</b></DT><DD>
6765 1.1 tron
6766 1.1 tron <p>
6767 1.1 tron The minimal amount of free space in bytes in the queue file system
6768 1.1 tron that is needed to receive mail. This is currently used by the SMTP
6769 1.1 tron server to decide if it will accept any mail at all.
6770 1.1 tron </p>
6771 1.1 tron
6772 1.1 tron <p>
6773 1.1 tron By default, the Postfix version 2.1 SMTP server rejects MAIL FROM commands
6774 1.1 tron when the amount of free space is less than 1.5*$<a href="postconf.5.html#message_size_limit">message_size_limit</a>.
6775 1.1 tron To specify a higher minimum free space limit, specify a <a href="postconf.5.html#queue_minfree">queue_minfree</a>
6776 1.1 tron value that is at least 1.5*$<a href="postconf.5.html#message_size_limit">message_size_limit</a>.
6777 1.1 tron </p>
6778 1.1 tron
6779 1.1 tron <p>
6780 1.1 tron With Postfix versions 2.0 and earlier, a <a href="postconf.5.html#queue_minfree">queue_minfree</a> value of
6781 1.1 tron zero means there is no minimum required amount of free space.
6782 1.1 tron </p>
6783 1.1 tron
6784 1.1 tron
6785 1.1 tron </DD>
6786 1.1 tron
6787 1.1 tron <DT><b><a name="queue_run_delay">queue_run_delay</a>
6788 1.1 tron (default: 300s)</b></DT><DD>
6789 1.1 tron
6790 1.1 tron <p>
6791 1.1 tron The time between <a href="QSHAPE_README.html#deferred_queue">deferred queue</a> scans by the queue manager;
6792 1.1 tron prior to Postfix 2.4 the default value was 1000s.
6793 1.1 tron </p>
6794 1.1 tron
6795 1.1 tron <p> This parameter should be set less than or equal to
6796 1.1 tron $<a href="postconf.5.html#minimal_backoff_time">minimal_backoff_time</a>. See also $<a href="postconf.5.html#maximal_backoff_time">maximal_backoff_time</a>. </p>
6797 1.1 tron
6798 1.1 tron <p>
6799 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
6800 1.1 tron The default time unit is s (seconds).
6801 1.1 tron </p>
6802 1.1 tron
6803 1.1 tron
6804 1.1 tron </DD>
6805 1.1 tron
6806 1.1 tron <DT><b><a name="queue_service_name">queue_service_name</a>
6807 1.1 tron (default: qmgr)</b></DT><DD>
6808 1.1 tron
6809 1.1 tron <p>
6810 1.1 tron The name of the <a href="qmgr.8.html">qmgr(8)</a> service. This service manages the Postfix
6811 1.1 tron queue and schedules delivery requests.
6812 1.1 tron </p>
6813 1.1 tron
6814 1.1 tron <p>
6815 1.1 tron This feature is available in Postfix 2.0 and later.
6816 1.1 tron </p>
6817 1.1 tron
6818 1.1 tron
6819 1.1 tron </DD>
6820 1.1 tron
6821 1.1 tron <DT><b><a name="rbl_reply_maps">rbl_reply_maps</a>
6822 1.1 tron (default: empty)</b></DT><DD>
6823 1.1 tron
6824 1.1 tron <p>
6825 1.1 tron Optional lookup tables with RBL response templates. The tables are
6826 1.1 tron indexed by the RBL domain name. By default, Postfix uses the default
6827 1.1 tron template as specified with the <a href="postconf.5.html#default_rbl_reply">default_rbl_reply</a> configuration
6828 1.1 tron parameter. See there for a discussion of the syntax of RBL reply
6829 1.1 tron templates.
6830 1.1 tron </p>
6831 1.1 tron
6832 1.1 tron <p>
6833 1.1 tron This feature is available in Postfix 2.0 and later.
6834 1.1 tron </p>
6835 1.1 tron
6836 1.1 tron
6837 1.1 tron </DD>
6838 1.1 tron
6839 1.1 tron <DT><b><a name="readme_directory">readme_directory</a>
6840 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
6841 1.1 tron
6842 1.1 tron <p>
6843 1.1 tron The location of Postfix README files that describe how to build,
6844 1.1 tron configure or operate a specific Postfix subsystem or feature.
6845 1.1 tron </p>
6846 1.1 tron
6847 1.1 tron
6848 1.1 tron </DD>
6849 1.1 tron
6850 1.1 tron <DT><b><a name="receive_override_options">receive_override_options</a>
6851 1.1 tron (default: empty)</b></DT><DD>
6852 1.1 tron
6853 1.1 tron <p> Enable or disable recipient validation, built-in content
6854 1.1 tron filtering, or address mapping. Typically, these are specified in
6855 1.1 tron <a href="master.5.html">master.cf</a> as command-line arguments for the <a href="smtpd.8.html">smtpd(8)</a>, <a href="qmqpd.8.html">qmqpd(8)</a> or
6856 1.1 tron <a href="pickup.8.html">pickup(8)</a> daemons. </p>
6857 1.1 tron
6858 1.1 tron <p> Specify zero or more of the following options. The options
6859 1.1 tron override <a href="postconf.5.html">main.cf</a> settings and are either implemented by <a href="smtpd.8.html">smtpd(8)</a>,
6860 1.1 tron <a href="qmqpd.8.html">qmqpd(8)</a>, or <a href="pickup.8.html">pickup(8)</a> themselves, or they are forwarded to the
6861 1.1 tron cleanup server. </p>
6862 1.1 tron
6863 1.1 tron <dl>
6864 1.1 tron
6865 1.1 tron <dt><b><a name="no_unknown_recipient_checks">no_unknown_recipient_checks</a></b></dt>
6866 1.1 tron
6867 1.1 tron <dd>Do not try to reject unknown recipients (SMTP server only).
6868 1.1 tron This is typically specified AFTER an external content filter.
6869 1.1 tron </dd>
6870 1.1 tron
6871 1.1 tron <dt><b><a name="no_address_mappings">no_address_mappings</a></b></dt>
6872 1.1 tron
6873 1.1 tron <dd>Disable canonical address mapping, virtual alias map expansion,
6874 1.1 tron address masquerading, and automatic BCC (blind carbon-copy)
6875 1.1 tron recipients. This is typically specified BEFORE an external content
6876 1.1 tron filter. </dd>
6877 1.1 tron
6878 1.1 tron <dt><b><a name="no_header_body_checks">no_header_body_checks</a></b></dt>
6879 1.1 tron
6880 1.1 tron <dd>Disable header/body_checks. This is typically specified AFTER
6881 1.1 tron an external content filter. </dd>
6882 1.1 tron
6883 1.1 tron <dt><b><a name="no_milters">no_milters</a></b></dt>
6884 1.1 tron
6885 1.1 tron <dd>Disable Milter (mail filter) applications. This is typically
6886 1.1 tron specified AFTER an external content filter. </dd>
6887 1.1 tron
6888 1.1 tron </dl>
6889 1.1 tron
6890 1.1 tron <p>
6891 1.1 tron Note: when the "BEFORE content filter" <a href="postconf.5.html#receive_override_options">receive_override_options</a>
6892 1.1 tron setting is specified in the <a href="postconf.5.html">main.cf</a> file, specify the "AFTER content
6893 1.1 tron filter" <a href="postconf.5.html#receive_override_options">receive_override_options</a> setting in <a href="master.5.html">master.cf</a> (and vice
6894 1.1 tron versa).
6895 1.1 tron </p>
6896 1.1 tron
6897 1.1 tron <p>
6898 1.1 tron Examples:
6899 1.1 tron </p>
6900 1.1 tron
6901 1.1 tron <pre>
6902 1.1 tron <a href="postconf.5.html#receive_override_options">receive_override_options</a> =
6903 1.1 tron <a href="postconf.5.html#no_unknown_recipient_checks">no_unknown_recipient_checks</a>, <a href="postconf.5.html#no_header_body_checks">no_header_body_checks</a>
6904 1.1 tron <a href="postconf.5.html#receive_override_options">receive_override_options</a> = <a href="postconf.5.html#no_address_mappings">no_address_mappings</a>
6905 1.1 tron </pre>
6906 1.1 tron
6907 1.1 tron <p>
6908 1.1 tron This feature is available in Postfix 2.1 and later.
6909 1.1 tron </p>
6910 1.1 tron
6911 1.1 tron
6912 1.1 tron </DD>
6913 1.1 tron
6914 1.1 tron <DT><b><a name="recipient_bcc_maps">recipient_bcc_maps</a>
6915 1.1 tron (default: empty)</b></DT><DD>
6916 1.1 tron
6917 1.1 tron <p>
6918 1.1 tron Optional BCC (blind carbon-copy) address lookup tables, indexed by
6919 1.1 tron recipient address. The BCC address (multiple results are not
6920 1.1 tron supported) is added when mail enters from outside of Postfix.
6921 1.1 tron </p>
6922 1.1 tron
6923 1.1 tron <p>
6924 1.1 tron This feature is available in Postfix 2.1 and later.
6925 1.1 tron </p>
6926 1.1 tron
6927 1.1 tron <p>
6928 1.1 tron The table search order is as follows:
6929 1.1 tron </p>
6930 1.1 tron
6931 1.1 tron <ul>
6932 1.1 tron
6933 1.1 tron <li> Look up the "user+extension (a] domain.tld" address including the
6934 1.1 tron optional address extension.
6935 1.1 tron
6936 1.1 tron <li> Look up the "user (a] domain.tld" address without the optional
6937 1.1 tron address extension.
6938 1.1 tron
6939 1.1 tron <li> Look up the "user+extension" address local part when the
6940 1.1 tron recipient domain equals $<a href="postconf.5.html#myorigin">myorigin</a>, $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>
6941 1.1 tron or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>.
6942 1.1 tron
6943 1.1 tron <li> Look up the "user" address local part when the recipient domain
6944 1.1 tron equals $<a href="postconf.5.html#myorigin">myorigin</a>, $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a> or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>.
6945 1.1 tron
6946 1.1 tron <li> Look up the "@domain.tld" part.
6947 1.1 tron
6948 1.1 tron </ul>
6949 1.1 tron
6950 1.1 tron <p>
6951 1.1 tron Specify the types and names of databases to use. After change,
6952 1.1 tron run "<b>postmap /etc/postfix/recipient_bcc</b>".
6953 1.1 tron </p>
6954 1.1 tron
6955 1.1 tron <p>
6956 1.1 tron Note: if mail to the BCC address bounces it will be returned to
6957 1.1 tron the sender.
6958 1.1 tron </p>
6959 1.1 tron
6960 1.1 tron <p> Note: automatic BCC recipients are produced only for new mail.
6961 1.1 tron To avoid mailer loops, automatic BCC recipients are not generated
6962 1.1 tron for mail that Postfix forwards internally, nor for mail that Postfix
6963 1.1 tron generates itself. </p>
6964 1.1 tron
6965 1.1 tron <p>
6966 1.1 tron Example:
6967 1.1 tron </p>
6968 1.1 tron
6969 1.1 tron <pre>
6970 1.1 tron <a href="postconf.5.html#recipient_bcc_maps">recipient_bcc_maps</a> = hash:/etc/postfix/recipient_bcc
6971 1.1 tron </pre>
6972 1.1 tron
6973 1.1 tron
6974 1.1 tron </DD>
6975 1.1 tron
6976 1.1 tron <DT><b><a name="recipient_canonical_classes">recipient_canonical_classes</a>
6977 1.1 tron (default: envelope_recipient, header_recipient)</b></DT><DD>
6978 1.1 tron
6979 1.1 tron <p> What addresses are subject to <a href="postconf.5.html#recipient_canonical_maps">recipient_canonical_maps</a> address
6980 1.1 tron mapping. By default, <a href="postconf.5.html#recipient_canonical_maps">recipient_canonical_maps</a> address mapping is
6981 1.1 tron applied to envelope recipient addresses, and to header recipient
6982 1.1 tron addresses. </p>
6983 1.1 tron
6984 1.1 tron <p> Specify one or more of: envelope_recipient, header_recipient
6985 1.1 tron </p>
6986 1.1 tron
6987 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
6988 1.1 tron
6989 1.1 tron
6990 1.1 tron </DD>
6991 1.1 tron
6992 1.1 tron <DT><b><a name="recipient_canonical_maps">recipient_canonical_maps</a>
6993 1.1 tron (default: empty)</b></DT><DD>
6994 1.1 tron
6995 1.1 tron <p>
6996 1.1 tron Optional address mapping lookup tables for envelope and header
6997 1.1 tron recipient addresses.
6998 1.1 tron The table format and lookups are documented in <a href="canonical.5.html">canonical(5)</a>.
6999 1.1 tron </p>
7000 1.1 tron
7001 1.1 tron <p>
7002 1.1 tron Note: $<a href="postconf.5.html#recipient_canonical_maps">recipient_canonical_maps</a> is processed before $<a href="postconf.5.html#canonical_maps">canonical_maps</a>.
7003 1.1 tron </p>
7004 1.1 tron
7005 1.1 tron <p>
7006 1.1 tron Example:
7007 1.1 tron </p>
7008 1.1 tron
7009 1.1 tron <pre>
7010 1.1 tron <a href="postconf.5.html#recipient_canonical_maps">recipient_canonical_maps</a> = hash:/etc/postfix/recipient_canonical
7011 1.1 tron </pre>
7012 1.1 tron
7013 1.1 tron
7014 1.1 tron </DD>
7015 1.1 tron
7016 1.1 tron <DT><b><a name="recipient_delimiter">recipient_delimiter</a>
7017 1.1 tron (default: empty)</b></DT><DD>
7018 1.1 tron
7019 1.1 tron <p>
7020 1.1 tron The separator between user names and address extensions (user+foo).
7021 1.1 tron See <a href="canonical.5.html">canonical(5)</a>, <a href="local.8.html">local(8)</a>, <a href="relocated.5.html">relocated(5)</a> and <a href="virtual.5.html">virtual(5)</a> for the
7022 1.1 tron effects this has on aliases, canonical, virtual, relocated and
7023 1.1 tron on .forward file lookups. Basically, the software tries user+foo
7024 1.1 tron and .forward+foo before trying user and .forward.
7025 1.1 tron </p>
7026 1.1 tron
7027 1.1 tron <p>
7028 1.1 tron Example:
7029 1.1 tron </p>
7030 1.1 tron
7031 1.1 tron <pre>
7032 1.1 tron <a href="postconf.5.html#recipient_delimiter">recipient_delimiter</a> = +
7033 1.1 tron </pre>
7034 1.1 tron
7035 1.1 tron
7036 1.1 tron </DD>
7037 1.1 tron
7038 1.1 tron <DT><b><a name="reject_code">reject_code</a>
7039 1.1 tron (default: 554)</b></DT><DD>
7040 1.1 tron
7041 1.1 tron <p>
7042 1.1 tron The numerical Postfix SMTP server response code when a remote SMTP
7043 1.1 tron client request is rejected by the "reject" restriction.
7044 1.1 tron </p>
7045 1.1 tron
7046 1.1 tron <p>
7047 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
7048 1.1 tron </p>
7049 1.1 tron
7050 1.1 tron
7051 1.1 tron </DD>
7052 1.1 tron
7053 1.1 tron <DT><b><a name="reject_tempfail_action">reject_tempfail_action</a>
7054 1.1 tron (default: <a href="postconf.5.html#defer_if_permit">defer_if_permit</a>)</b></DT><DD>
7055 1.1 tron
7056 1.1 tron <p> The Postfix SMTP server's action when a reject-type restriction
7057 1.1 tron fails due to a temporary error condition. Specify "defer" to defer
7058 1.1 tron the remote SMTP client request immediately. With the default
7059 1.1 tron "<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>" action, the Postfix SMTP server continues to look
7060 1.1 tron for opportunities to reject mail, and defers the client request
7061 1.1 tron only if it would otherwise be accepted. </p>
7062 1.1 tron
7063 1.1 tron <p> For finer control, see: <a href="postconf.5.html#unverified_recipient_tempfail_action">unverified_recipient_tempfail_action</a>,
7064 1.1 tron <a href="postconf.5.html#unverified_sender_tempfail_action">unverified_sender_tempfail_action</a>, <a href="postconf.5.html#unknown_address_tempfail_action">unknown_address_tempfail_action</a>,
7065 1.1 tron and <a href="postconf.5.html#unknown_helo_hostname_tempfail_action">unknown_helo_hostname_tempfail_action</a>. </p>
7066 1.1 tron
7067 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
7068 1.1 tron
7069 1.1 tron
7070 1.1 tron </DD>
7071 1.1 tron
7072 1.1 tron <DT><b><a name="relay_clientcerts">relay_clientcerts</a>
7073 1.1 tron (default: empty)</b></DT><DD>
7074 1.1 tron
7075 1.1 tron <p> List of tables with remote SMTP client-certificate fingerprints
7076 1.1 tron for which the Postfix SMTP server will allow access with the
7077 1.1 tron <a href="postconf.5.html#permit_tls_clientcerts">permit_tls_clientcerts</a> feature.
7078 1.1 tron The fingerprint digest algorithm is configurable via the
7079 1.1 tron <a href="postconf.5.html#smtpd_tls_fingerprint_digest">smtpd_tls_fingerprint_digest</a> parameter (hard-coded as md5 prior to
7080 1.1 tron Postfix version 2.5). </p>
7081 1.1 tron
7082 1.1 tron <p> Postfix lookup tables are in the form of (key, value) pairs.
7083 1.1 tron Since we only need the key, the value can be chosen freely, e.g.
7084 1.1 tron the name of the user or host:
7085 1.1 tron D7:04:2F:A7:0B:8C:A5:21:FA:31:77:E1:41:8A:EE:80 lutzpc.at.home </p>
7086 1.1 tron
7087 1.1 tron <p> Example: </p>
7088 1.1 tron
7089 1.1 tron <pre>
7090 1.1 tron <a href="postconf.5.html#relay_clientcerts">relay_clientcerts</a> = hash:/etc/postfix/relay_clientcerts
7091 1.1 tron </pre>
7092 1.1 tron
7093 1.1 tron <p>For more fine-grained control, use <a href="postconf.5.html#check_ccert_access">check_ccert_access</a> to select
7094 1.1 tron an appropriate <a href="access.5.html">access(5)</a> policy for each client.
7095 1.1 tron See <a href="RESTRICTION_CLASS_README.html">RESTRICTION_CLASS_README</a>.</p>
7096 1.1 tron
7097 1.1 tron <p>This feature is available with Postfix version 2.2.</p>
7098 1.1 tron
7099 1.1 tron
7100 1.1 tron </DD>
7101 1.1 tron
7102 1.1 tron <DT><b><a name="relay_destination_concurrency_limit">relay_destination_concurrency_limit</a>
7103 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_limit">default_destination_concurrency_limit</a>)</b></DT><DD>
7104 1.1 tron
7105 1.1 tron <p> The maximal number of parallel deliveries to the same destination
7106 1.1 tron via the relay message delivery transport. This limit is enforced
7107 1.1 tron by the queue manager. The message delivery transport name is the
7108 1.1 tron first field in the entry in the <a href="master.5.html">master.cf</a> file. </p>
7109 1.1 tron
7110 1.1 tron <p> This feature is available in Postfix 2.0 and later. </p>
7111 1.1 tron
7112 1.1 tron
7113 1.1 tron </DD>
7114 1.1 tron
7115 1.1 tron <DT><b><a name="relay_destination_recipient_limit">relay_destination_recipient_limit</a>
7116 1.1 tron (default: $<a href="postconf.5.html#default_destination_recipient_limit">default_destination_recipient_limit</a>)</b></DT><DD>
7117 1.1 tron
7118 1.1 tron <p> The maximal number of recipients per message for the relay
7119 1.1 tron message delivery transport. This limit is enforced by the queue
7120 1.1 tron manager. The message delivery transport name is the first field in
7121 1.1 tron the entry in the <a href="master.5.html">master.cf</a> file. </p>
7122 1.1 tron
7123 1.1 tron <p> Setting this parameter to a value of 1 changes the meaning of
7124 1.1 tron <a href="postconf.5.html#relay_destination_concurrency_limit">relay_destination_concurrency_limit</a> from concurrency per domain
7125 1.1 tron into concurrency per recipient. </p>
7126 1.1 tron
7127 1.1 tron <p> This feature is available in Postfix 2.0 and later. </p>
7128 1.1 tron
7129 1.1 tron
7130 1.1 tron </DD>
7131 1.1 tron
7132 1.1 tron <DT><b><a name="relay_domains">relay_domains</a>
7133 1.1 tron (default: $<a href="postconf.5.html#mydestination">mydestination</a>)</b></DT><DD>
7134 1.1 tron
7135 1.1 tron <p> What destination domains (and subdomains thereof) this system
7136 1.1 tron will relay mail to. Subdomain matching is controlled with the
7137 1.1 tron <a href="postconf.5.html#parent_domain_matches_subdomains">parent_domain_matches_subdomains</a> parameter. For details about how
7138 1.1 tron the <a href="postconf.5.html#relay_domains">relay_domains</a> value is used, see the description of the
7139 1.1 tron <a href="postconf.5.html#permit_auth_destination">permit_auth_destination</a> and <a href="postconf.5.html#reject_unauth_destination">reject_unauth_destination</a> SMTP recipient
7140 1.1 tron restrictions. </p>
7141 1.1 tron
7142 1.1 tron <p> Domains that match $<a href="postconf.5.html#relay_domains">relay_domains</a> are delivered with the
7143 1.1 tron $<a href="postconf.5.html#relay_transport">relay_transport</a> mail delivery transport. The SMTP server validates
7144 1.1 tron recipient addresses with $<a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a> and rejects non-existent
7145 1.1 tron recipients. See also the <a href="ADDRESS_CLASS_README.html#relay_domain_class">relay domains</a> address class in the
7146 1.1 tron <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a> file. </p>
7147 1.1 tron
7148 1.1 tron <p> Note: Postfix will not automatically forward mail for domains
7149 1.1 tron that list this system as their primary or backup MX host. See the
7150 1.1 tron <a href="postconf.5.html#permit_mx_backup">permit_mx_backup</a> restriction in the <a href="postconf.5.html">postconf(5)</a> manual page. </p>
7151 1.1 tron
7152 1.1 tron <p> Specify a list of host or domain names, "/file/name" patterns
7153 1.1 tron or "<a href="DATABASE_README.html">type:table</a>" lookup tables, separated by commas and/or whitespace.
7154 1.1 tron Continue long lines by starting the next line with whitespace. A
7155 1.1 tron "/file/name" pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>"
7156 1.1 tron lookup table is matched when a (parent) domain appears as lookup
7157 1.1 tron key. Specify "!pattern" to exclude a domain from the list. The form
7158 1.1 tron "!/file/name" is supported only in Postfix version 2.4 and later.
7159 1.1 tron </p>
7160 1.1 tron
7161 1.1 tron
7162 1.1 tron </DD>
7163 1.1 tron
7164 1.1 tron <DT><b><a name="relay_domains_reject_code">relay_domains_reject_code</a>
7165 1.1 tron (default: 554)</b></DT><DD>
7166 1.1 tron
7167 1.1 tron <p>
7168 1.1 tron The numerical Postfix SMTP server response code when a client
7169 1.1 tron request is rejected by the <a href="postconf.5.html#reject_unauth_destination">reject_unauth_destination</a> recipient
7170 1.1 tron restriction.
7171 1.1 tron </p>
7172 1.1 tron
7173 1.1 tron <p>
7174 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
7175 1.1 tron </p>
7176 1.1 tron
7177 1.1 tron
7178 1.1 tron </DD>
7179 1.1 tron
7180 1.1 tron <DT><b><a name="relay_recipient_maps">relay_recipient_maps</a>
7181 1.1 tron (default: empty)</b></DT><DD>
7182 1.1 tron
7183 1.1 tron <p> Optional lookup tables with all valid addresses in the domains
7184 1.1 tron that match $<a href="postconf.5.html#relay_domains">relay_domains</a>. Specify @domain as a wild-card for
7185 1.1 tron domains that have no valid recipient list, and become a source of
7186 1.1 tron backscatter mail: Postfix accepts spam for non-existent recipients
7187 1.1 tron and then floods innocent people with undeliverable mail. Technically,
7188 1.1 tron tables
7189 1.1 tron listed with $<a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a> are used as lists: Postfix needs
7190 1.1 tron to know only if a lookup string is found or not, but it does not
7191 1.1 tron use the result from table lookup. </p>
7192 1.1 tron
7193 1.1 tron <p>
7194 1.1 tron If this parameter is non-empty, then the Postfix SMTP server will reject
7195 1.1 tron mail to unknown relay users. This feature is off by default.
7196 1.1 tron </p>
7197 1.1 tron
7198 1.1 tron <p>
7199 1.1 tron See also the <a href="ADDRESS_CLASS_README.html#relay_domain_class">relay domains</a> address class in the <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a>
7200 1.1 tron file.
7201 1.1 tron </p>
7202 1.1 tron
7203 1.1 tron <p>
7204 1.1 tron Example:
7205 1.1 tron </p>
7206 1.1 tron
7207 1.1 tron <pre>
7208 1.1 tron <a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a> = hash:/etc/postfix/relay_recipients
7209 1.1 tron </pre>
7210 1.1 tron
7211 1.1 tron <p>
7212 1.1 tron This feature is available in Postfix 2.0 and later.
7213 1.1 tron </p>
7214 1.1 tron
7215 1.1 tron
7216 1.1 tron </DD>
7217 1.1 tron
7218 1.1 tron <DT><b><a name="relay_transport">relay_transport</a>
7219 1.1 tron (default: relay)</b></DT><DD>
7220 1.1 tron
7221 1.1 tron <p>
7222 1.1 tron The default mail delivery transport and next-hop destination for
7223 1.1 tron remote delivery to domains listed with $<a href="postconf.5.html#relay_domains">relay_domains</a>. In order of
7224 1.1 tron decreasing precedence, the nexthop destination is taken from
7225 1.1 tron $<a href="postconf.5.html#relay_transport">relay_transport</a>, $<a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a>, $<a href="postconf.5.html#relayhost">relayhost</a>, or
7226 1.1 tron from the recipient domain. This information can be overruled with
7227 1.1 tron the <a href="transport.5.html">transport(5)</a> table.
7228 1.1 tron </p>
7229 1.1 tron
7230 1.1 tron <p>
7231 1.1 tron Specify a string of the form <i>transport:nexthop</i>, where <i>transport</i>
7232 1.1 tron is the name of a mail delivery transport defined in <a href="master.5.html">master.cf</a>.
7233 1.1 tron The <i>:nexthop</i> part is optional. For more details see the
7234 1.1 tron <a href="transport.5.html">transport(5)</a> manual page.
7235 1.1 tron </p>
7236 1.1 tron
7237 1.1 tron <p>
7238 1.1 tron See also the <a href="ADDRESS_CLASS_README.html#relay_domain_class">relay domains</a> address class in the <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a>
7239 1.1 tron file.
7240 1.1 tron </p>
7241 1.1 tron
7242 1.1 tron <p>
7243 1.1 tron This feature is available in Postfix 2.0 and later.
7244 1.1 tron </p>
7245 1.1 tron
7246 1.1 tron
7247 1.1 tron </DD>
7248 1.1 tron
7249 1.1 tron <DT><b><a name="relayhost">relayhost</a>
7250 1.1 tron (default: empty)</b></DT><DD>
7251 1.1 tron
7252 1.1 tron <p>
7253 1.1 tron The next-hop destination of non-local mail; overrides non-local
7254 1.1 tron domains in recipient addresses. This information is overruled with
7255 1.1 tron <a href="postconf.5.html#relay_transport">relay_transport</a>, <a href="postconf.5.html#default_transport">default_transport</a>, <a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a>
7256 1.1 tron and with the <a href="transport.5.html">transport(5)</a> table.
7257 1.1 tron </p>
7258 1.1 tron
7259 1.1 tron <p>
7260 1.1 tron On an intranet, specify the organizational domain name. If your
7261 1.1 tron internal DNS uses no MX records, specify the name of the intranet
7262 1.1 tron gateway host instead.
7263 1.1 tron </p>
7264 1.1 tron
7265 1.1 tron <p>
7266 1.1 tron In the case of SMTP, specify a domain name, hostname, hostname:port,
7267 1.1 tron [hostname]:port, [hostaddress] or [hostaddress]:port. The form
7268 1.1 tron [hostname] turns off MX lookups.
7269 1.1 tron </p>
7270 1.1 tron
7271 1.1 tron <p>
7272 1.1 tron If you're connected via UUCP, see the <a href="UUCP_README.html">UUCP_README</a> file for useful
7273 1.1 tron information.
7274 1.1 tron </p>
7275 1.1 tron
7276 1.1 tron <p>
7277 1.1 tron Examples:
7278 1.1 tron </p>
7279 1.1 tron
7280 1.1 tron <pre>
7281 1.1 tron <a href="postconf.5.html#relayhost">relayhost</a> = $<a href="postconf.5.html#mydomain">mydomain</a>
7282 1.1 tron <a href="postconf.5.html#relayhost">relayhost</a> = [gateway.example.com]
7283 1.1 tron <a href="postconf.5.html#relayhost">relayhost</a> = uucphost
7284 1.1 tron <a href="postconf.5.html#relayhost">relayhost</a> = [an.ip.add.ress]
7285 1.1 tron </pre>
7286 1.1 tron
7287 1.1 tron
7288 1.1 tron </DD>
7289 1.1 tron
7290 1.1 tron <DT><b><a name="relocated_maps">relocated_maps</a>
7291 1.1 tron (default: empty)</b></DT><DD>
7292 1.1 tron
7293 1.1 tron <p>
7294 1.1 tron Optional lookup tables with new contact information for users or
7295 1.1 tron domains that no longer exist. The table format and lookups are
7296 1.1 tron documented in <a href="relocated.5.html">relocated(5)</a>.
7297 1.1 tron </p>
7298 1.1 tron
7299 1.1 tron <p>
7300 1.1 tron If you use this feature, run "<b>postmap /etc/postfix/relocated</b>" to
7301 1.1 tron build the necessary DBM or DB file after change, then "<b>postfix
7302 1.1 tron reload</b>" to make the changes visible.
7303 1.1 tron </p>
7304 1.1 tron
7305 1.1 tron <p>
7306 1.1 tron Examples:
7307 1.1 tron </p>
7308 1.1 tron
7309 1.1 tron <pre>
7310 1.1 tron <a href="postconf.5.html#relocated_maps">relocated_maps</a> = dbm:/etc/postfix/relocated
7311 1.1 tron <a href="postconf.5.html#relocated_maps">relocated_maps</a> = hash:/etc/postfix/relocated
7312 1.1 tron </pre>
7313 1.1 tron
7314 1.1 tron
7315 1.1 tron </DD>
7316 1.1 tron
7317 1.1 tron <DT><b><a name="remote_header_rewrite_domain">remote_header_rewrite_domain</a>
7318 1.1 tron (default: empty)</b></DT><DD>
7319 1.1 tron
7320 1.1 tron <p> Don't rewrite message headers from remote clients at all when
7321 1.1 tron this parameter is empty; otherwise, rewrite message headers and
7322 1.1 tron append the specified domain name to incomplete addresses. The
7323 1.1 tron <a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> parameter controls what clients Postfix
7324 1.1 tron considers local. </p>
7325 1.1 tron
7326 1.1 tron <p> Examples: </p>
7327 1.1 tron
7328 1.1 tron <p> The safe setting: append "domain.invalid" to incomplete header
7329 1.1 tron addresses from remote SMTP clients, so that those addresses cannot
7330 1.1 tron be confused with local addresses. </p>
7331 1.1 tron
7332 1.1 tron <blockquote>
7333 1.1 tron <pre>
7334 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> = domain.invalid
7335 1.1 tron </pre>
7336 1.1 tron </blockquote>
7337 1.1 tron
7338 1.1 tron <p> The default, purist, setting: don't rewrite headers from remote
7339 1.1 tron clients at all. </p>
7340 1.1 tron
7341 1.1 tron <blockquote>
7342 1.1 tron <pre>
7343 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> =
7344 1.1 tron </pre>
7345 1.1 tron </blockquote>
7346 1.1 tron
7347 1.1 tron
7348 1.1 tron </DD>
7349 1.1 tron
7350 1.1 tron <DT><b><a name="require_home_directory">require_home_directory</a>
7351 1.1 tron (default: no)</b></DT><DD>
7352 1.1 tron
7353 1.1 tron <p>
7354 1.1 tron Whether or not a <a href="local.8.html">local(8)</a> recipient's home directory must exist
7355 1.1 tron before mail delivery is attempted. By default this test is disabled.
7356 1.1 tron It can be useful for environments that import home directories to
7357 1.1 tron the mail server (NOT RECOMMENDED).
7358 1.1 tron </p>
7359 1.1 tron
7360 1.1 tron
7361 1.1 tron </DD>
7362 1.1 tron
7363 1.1 tron <DT><b><a name="resolve_dequoted_address">resolve_dequoted_address</a>
7364 1.1 tron (default: yes)</b></DT><DD>
7365 1.1 tron
7366 1.1 tron <p> Resolve a recipient address safely instead of correctly, by
7367 1.1 tron looking inside quotes. </p>
7368 1.1 tron
7369 1.1 tron <p> By default, the Postfix address resolver does not quote the
7370 1.1 tron address localpart as per <a href="http://tools.ietf.org/html/rfc822">RFC 822</a>, so that additional @ or % or !
7371 1.1 tron operators remain visible. This behavior is safe but it is also
7372 1.1 tron technically incorrect. </p>
7373 1.1 tron
7374 1.1 tron <p> If you specify "<a href="postconf.5.html#resolve_dequoted_address">resolve_dequoted_address</a> = no", then
7375 1.1 tron the Postfix
7376 1.1 tron resolver will not know about additional @ etc. operators in the
7377 1.1 tron address localpart. This opens opportunities for obscure mail relay
7378 1.1 tron attacks with user@domain@domain addresses when Postfix provides
7379 1.1 tron backup MX service for Sendmail systems. </p>
7380 1.1 tron
7381 1.1 tron
7382 1.1 tron </DD>
7383 1.1 tron
7384 1.1 tron <DT><b><a name="resolve_null_domain">resolve_null_domain</a>
7385 1.1 tron (default: no)</b></DT><DD>
7386 1.1 tron
7387 1.1 tron <p> Resolve an address that ends in the "@" null domain as if the
7388 1.1 tron local hostname were specified, instead of rejecting the address as
7389 1.1 tron invalid. </p>
7390 1.1 tron
7391 1.1 tron <p> This feature is available in Postfix 2.1 and later.
7392 1.1 tron Earlier versions always resolve the null domain as the local
7393 1.1 tron hostname. </p>
7394 1.1 tron
7395 1.1 tron <p> The Postfix SMTP server uses this feature to reject mail from
7396 1.1 tron or to addresses that end in the "@" null domain, and from addresses
7397 1.1 tron that rewrite into a form that ends in the "@" null domain. </p>
7398 1.1 tron
7399 1.1 tron
7400 1.1 tron </DD>
7401 1.1 tron
7402 1.1 tron <DT><b><a name="resolve_numeric_domain">resolve_numeric_domain</a>
7403 1.1 tron (default: no)</b></DT><DD>
7404 1.1 tron
7405 1.1 tron <p> Resolve "user@ipaddress" as "user@[ipaddress]", instead of
7406 1.1 tron rejecting the address as invalid. </p>
7407 1.1 tron
7408 1.1 tron <p> This feature is available in Postfix 2.3 and later.
7409 1.1 tron
7410 1.1 tron
7411 1.1 tron </DD>
7412 1.1 tron
7413 1.1 tron <DT><b><a name="rewrite_service_name">rewrite_service_name</a>
7414 1.1 tron (default: rewrite)</b></DT><DD>
7415 1.1 tron
7416 1.1 tron <p>
7417 1.1 tron The name of the address rewriting service. This service rewrites
7418 1.1 tron addresses to standard form and resolves them to a (delivery method,
7419 1.1 tron next-hop host, recipient) triple.
7420 1.1 tron </p>
7421 1.1 tron
7422 1.1 tron <p>
7423 1.1 tron This feature is available in Postfix 2.0 and later.
7424 1.1 tron </p>
7425 1.1 tron
7426 1.1 tron
7427 1.1 tron </DD>
7428 1.1 tron
7429 1.1 tron <DT><b><a name="sample_directory">sample_directory</a>
7430 1.1 tron (default: /etc/postfix)</b></DT><DD>
7431 1.1 tron
7432 1.1 tron <p>
7433 1.1 tron The name of the directory with example Postfix configuration files.
7434 1.1 tron </p>
7435 1.1 tron
7436 1.1 tron
7437 1.1 tron </DD>
7438 1.1 tron
7439 1.1 tron <DT><b><a name="send_cyrus_sasl_authzid">send_cyrus_sasl_authzid</a>
7440 1.1 tron (default: no)</b></DT><DD>
7441 1.1 tron
7442 1.1 tron <p> When authenticating to a remote SMTP or LMTP server with the
7443 1.1 tron default setting "no", send no SASL authoriZation ID (authzid); send
7444 1.1 tron only the SASL authentiCation ID (authcid) plus the authcid's password.
7445 1.1 tron </p>
7446 1.1 tron
7447 1.1 tron <p> The non-default setting "yes" enables the behavior of older
7448 1.1 tron Postfix versions. These always send a SASL authzid that is equal
7449 1.1 tron to the SASL authcid, but this causes inter-operability problems
7450 1.1 tron with some SMTP servers. </p>
7451 1.1 tron
7452 1.1 tron <p> This feature is available in Postfix 2.4.4 and later. </p>
7453 1.1 tron
7454 1.1 tron
7455 1.1 tron </DD>
7456 1.1 tron
7457 1.1 tron <DT><b><a name="sender_based_routing">sender_based_routing</a>
7458 1.1 tron (default: no)</b></DT><DD>
7459 1.1 tron
7460 1.1 tron <p>
7461 1.1 tron This parameter should not be used. It was replaced by <a href="postconf.5.html#sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a>
7462 1.1 tron in Postfix version 2.3.
7463 1.1 tron </p>
7464 1.1 tron
7465 1.1 tron
7466 1.1 tron </DD>
7467 1.1 tron
7468 1.1 tron <DT><b><a name="sender_bcc_maps">sender_bcc_maps</a>
7469 1.1 tron (default: empty)</b></DT><DD>
7470 1.1 tron
7471 1.1 tron <p> Optional BCC (blind carbon-copy) address lookup tables, indexed
7472 1.1 tron by sender address. The BCC address (multiple results are not
7473 1.1 tron supported) is added when mail enters from outside of Postfix. </p>
7474 1.1 tron
7475 1.1 tron <p>
7476 1.1 tron This feature is available in Postfix 2.1 and later.
7477 1.1 tron </p>
7478 1.1 tron
7479 1.1 tron <p>
7480 1.1 tron The table search order is as follows:
7481 1.1 tron </p>
7482 1.1 tron
7483 1.1 tron <ul>
7484 1.1 tron
7485 1.1 tron <li> Look up the "user+extension (a] domain.tld" address including the
7486 1.1 tron optional address extension.
7487 1.1 tron
7488 1.1 tron <li> Look up the "user (a] domain.tld" address without the optional
7489 1.1 tron address extension.
7490 1.1 tron
7491 1.1 tron <li> Look up the "user+extension" address local part when the
7492 1.1 tron sender domain equals $<a href="postconf.5.html#myorigin">myorigin</a>, $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>
7493 1.1 tron or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>.
7494 1.1 tron
7495 1.1 tron <li> Look up the "user" address local part when the sender domain
7496 1.1 tron equals $<a href="postconf.5.html#myorigin">myorigin</a>, $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a> or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>.
7497 1.1 tron
7498 1.1 tron <li> Look up the "@domain.tld" part.
7499 1.1 tron
7500 1.1 tron </ul>
7501 1.1 tron
7502 1.1 tron <p>
7503 1.1 tron Specify the types and names of databases to use. After change,
7504 1.1 tron run "<b>postmap /etc/postfix/sender_bcc</b>".
7505 1.1 tron </p>
7506 1.1 tron
7507 1.1 tron <p>
7508 1.1 tron Note: if mail to the BCC address bounces it will be returned to
7509 1.1 tron the sender.
7510 1.1 tron </p>
7511 1.1 tron
7512 1.1 tron <p> Note: automatic BCC recipients are produced only for new mail.
7513 1.1 tron To avoid mailer loops, automatic BCC recipients are not generated
7514 1.1 tron for mail that Postfix forwards internally, nor for mail that Postfix
7515 1.1 tron generates itself. </p>
7516 1.1 tron
7517 1.1 tron <p>
7518 1.1 tron Example:
7519 1.1 tron </p>
7520 1.1 tron
7521 1.1 tron <pre>
7522 1.1 tron <a href="postconf.5.html#sender_bcc_maps">sender_bcc_maps</a> = hash:/etc/postfix/sender_bcc
7523 1.1 tron </pre>
7524 1.1 tron
7525 1.1 tron
7526 1.1 tron </DD>
7527 1.1 tron
7528 1.1 tron <DT><b><a name="sender_canonical_classes">sender_canonical_classes</a>
7529 1.1 tron (default: envelope_sender, header_sender)</b></DT><DD>
7530 1.1 tron
7531 1.1 tron <p> What addresses are subject to <a href="postconf.5.html#sender_canonical_maps">sender_canonical_maps</a> address
7532 1.1 tron mapping. By default, <a href="postconf.5.html#sender_canonical_maps">sender_canonical_maps</a> address mapping is
7533 1.1 tron applied to envelope sender addresses, and to header sender addresses.
7534 1.1 tron </p>
7535 1.1 tron
7536 1.1 tron <p> Specify one or more of: envelope_sender, header_sender </p>
7537 1.1 tron
7538 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
7539 1.1 tron
7540 1.1 tron
7541 1.1 tron </DD>
7542 1.1 tron
7543 1.1 tron <DT><b><a name="sender_canonical_maps">sender_canonical_maps</a>
7544 1.1 tron (default: empty)</b></DT><DD>
7545 1.1 tron
7546 1.1 tron <p>
7547 1.1 tron Optional address mapping lookup tables for envelope and header
7548 1.1 tron sender addresses.
7549 1.1 tron The table format and lookups are documented in <a href="canonical.5.html">canonical(5)</a>.
7550 1.1 tron </p>
7551 1.1 tron
7552 1.1 tron <p>
7553 1.1 tron Example: you want to rewrite the SENDER address "user (a] ugly.domain"
7554 1.1 tron to "user (a] pretty.domain", while still being able to send mail to
7555 1.1 tron the RECIPIENT address "user (a] ugly.domain".
7556 1.1 tron </p>
7557 1.1 tron
7558 1.1 tron <p>
7559 1.1 tron Note: $<a href="postconf.5.html#sender_canonical_maps">sender_canonical_maps</a> is processed before $<a href="postconf.5.html#canonical_maps">canonical_maps</a>.
7560 1.1 tron </p>
7561 1.1 tron
7562 1.1 tron <p>
7563 1.1 tron Example:
7564 1.1 tron </p>
7565 1.1 tron
7566 1.1 tron <pre>
7567 1.1 tron <a href="postconf.5.html#sender_canonical_maps">sender_canonical_maps</a> = hash:/etc/postfix/sender_canonical
7568 1.1 tron </pre>
7569 1.1 tron
7570 1.1 tron
7571 1.1 tron </DD>
7572 1.1 tron
7573 1.1 tron <DT><b><a name="sender_dependent_relayhost_maps">sender_dependent_relayhost_maps</a>
7574 1.1 tron (default: empty)</b></DT><DD>
7575 1.1 tron
7576 1.1 tron <p> A sender-dependent override for the global <a href="postconf.5.html#relayhost">relayhost</a> parameter
7577 1.1 tron setting. The tables are searched by the envelope sender address and
7578 1.1 tron @domain. A lookup result of DUNNO terminates the search without
7579 1.1 tron overriding the global <a href="postconf.5.html#relayhost">relayhost</a> parameter setting (Postfix 2.6 and
7580 1.1 tron later). This information is overruled with <a href="postconf.5.html#relay_transport">relay_transport</a>,
7581 1.1 tron <a href="postconf.5.html#default_transport">default_transport</a> and with the <a href="transport.5.html">transport(5)</a> table. </p>
7582 1.1 tron
7583 1.1 tron <p> For safety reasons, this feature does not allow $number
7584 1.1 tron substitutions in regular expression maps. </p>
7585 1.1 tron
7586 1.1 tron <p>
7587 1.1 tron This feature is available in Postfix 2.3 and later.
7588 1.1 tron </p>
7589 1.1 tron
7590 1.1 tron
7591 1.1 tron </DD>
7592 1.1 tron
7593 1.1 tron <DT><b><a name="sendmail_path">sendmail_path</a>
7594 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
7595 1.1 tron
7596 1.1 tron <p>
7597 1.1 tron A Sendmail compatibility feature that specifies the location of
7598 1.1 tron the Postfix <a href="sendmail.1.html">sendmail(1)</a> command. This command can be used to
7599 1.1 tron submit mail into the Postfix queue.
7600 1.1 tron </p>
7601 1.1 tron
7602 1.1 tron
7603 1.1 tron </DD>
7604 1.1 tron
7605 1.1 tron <DT><b><a name="service_throttle_time">service_throttle_time</a>
7606 1.1 tron (default: 60s)</b></DT><DD>
7607 1.1 tron
7608 1.1 tron <p>
7609 1.1 tron How long the Postfix <a href="master.8.html">master(8)</a> waits before forking a server that
7610 1.1 tron appears to be malfunctioning.
7611 1.1 tron </p>
7612 1.1 tron
7613 1.1 tron <p>
7614 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
7615 1.1 tron The default time unit is s (seconds).
7616 1.1 tron </p>
7617 1.1 tron
7618 1.1 tron
7619 1.1 tron </DD>
7620 1.1 tron
7621 1.1 tron <DT><b><a name="setgid_group">setgid_group</a>
7622 1.1 tron (default: postdrop)</b></DT><DD>
7623 1.1 tron
7624 1.1 tron <p>
7625 1.1 tron The group ownership of set-gid Postfix commands and of group-writable
7626 1.1 tron Postfix directories. When this parameter value is changed you need
7627 1.1 tron to re-run "<b>postfix set-permissions</b>" (with Postfix version 2.0 and
7628 1.1 tron earlier: "<b>/etc/postfix/post-install set-permissions</b>".
7629 1.1 tron </p>
7630 1.1 tron
7631 1.1 tron
7632 1.1 tron </DD>
7633 1.1 tron
7634 1.1 tron <DT><b><a name="show_user_unknown_table_name">show_user_unknown_table_name</a>
7635 1.1 tron (default: yes)</b></DT><DD>
7636 1.1 tron
7637 1.1 tron <p>
7638 1.1 tron Display the name of the recipient table in the "User unknown"
7639 1.1 tron responses. The extra detail makes trouble shooting easier but also
7640 1.1 tron reveals information that is nobody elses business.
7641 1.1 tron </p>
7642 1.1 tron
7643 1.1 tron <p>
7644 1.1 tron This feature is available in Postfix 2.0 and later.
7645 1.1 tron </p>
7646 1.1 tron
7647 1.1 tron
7648 1.1 tron </DD>
7649 1.1 tron
7650 1.1 tron <DT><b><a name="showq_service_name">showq_service_name</a>
7651 1.1 tron (default: showq)</b></DT><DD>
7652 1.1 tron
7653 1.1 tron <p>
7654 1.1 tron The name of the <a href="showq.8.html">showq(8)</a> service. This service produces mail queue
7655 1.1 tron status reports.
7656 1.1 tron </p>
7657 1.1 tron
7658 1.1 tron <p>
7659 1.1 tron This feature is available in Postfix 2.0 and later.
7660 1.1 tron </p>
7661 1.1 tron
7662 1.1 tron
7663 1.1 tron </DD>
7664 1.1 tron
7665 1.1 tron <DT><b><a name="smtp_always_send_ehlo">smtp_always_send_ehlo</a>
7666 1.1 tron (default: yes)</b></DT><DD>
7667 1.1 tron
7668 1.1 tron <p>
7669 1.1 tron Always send EHLO at the start of an SMTP session.
7670 1.1 tron </p>
7671 1.1 tron
7672 1.1 tron <p>
7673 1.1 tron With "<a href="postconf.5.html#smtp_always_send_ehlo">smtp_always_send_ehlo</a> = no", Postfix sends EHLO only when
7674 1.1 tron the word "ESMTP" appears in the server greeting banner (example:
7675 1.1 tron 220 spike.porcupine.org ESMTP Postfix).
7676 1.1 tron </p>
7677 1.1 tron
7678 1.1 tron
7679 1.1 tron </DD>
7680 1.1 tron
7681 1.1 tron <DT><b><a name="smtp_bind_address">smtp_bind_address</a>
7682 1.1 tron (default: empty)</b></DT><DD>
7683 1.1 tron
7684 1.1 tron <p>
7685 1.1 tron An optional numerical network address that the Postfix SMTP client
7686 1.1 tron should bind to when making an IPv4 connection.
7687 1.1 tron </p>
7688 1.1 tron
7689 1.1 tron <p>
7690 1.1 tron This can be specified in the <a href="postconf.5.html">main.cf</a> file for all SMTP clients, or
7691 1.1 tron it can be specified in the <a href="master.5.html">master.cf</a> file for a specific client,
7692 1.1 tron for example:
7693 1.1 tron </p>
7694 1.1 tron
7695 1.1 tron <blockquote>
7696 1.1 tron <pre>
7697 1.1 tron /etc/postfix/<a href="master.5.html">master.cf</a>:
7698 1.1 tron smtp ... smtp -o <a href="postconf.5.html#smtp_bind_address">smtp_bind_address</a>=11.22.33.44
7699 1.1 tron </pre>
7700 1.1 tron </blockquote>
7701 1.1 tron
7702 1.1 tron <p> Note 1: when <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> specifies no more than one IPv4
7703 1.1 tron address, and that address is a non-loopback address, it is
7704 1.1 tron automatically used as the <a href="postconf.5.html#smtp_bind_address">smtp_bind_address</a>. This supports virtual
7705 1.1 tron IP hosting, but can be a problem on multi-homed firewalls. See the
7706 1.1 tron <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> documentation for more detail. </p>
7707 1.1 tron
7708 1.1 tron <p> Note 2: address information may be enclosed inside <tt>[]</tt>,
7709 1.1 tron but this form is not required here. </p>
7710 1.1 tron
7711 1.1 tron
7712 1.1 tron </DD>
7713 1.1 tron
7714 1.1 tron <DT><b><a name="smtp_bind_address6">smtp_bind_address6</a>
7715 1.1 tron (default: empty)</b></DT><DD>
7716 1.1 tron
7717 1.1 tron <p>
7718 1.1 tron An optional numerical network address that the Postfix SMTP client
7719 1.1 tron should bind to when making an IPv6 connection.
7720 1.1 tron </p>
7721 1.1 tron
7722 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
7723 1.1 tron
7724 1.1 tron <p>
7725 1.1 tron This can be specified in the <a href="postconf.5.html">main.cf</a> file for all SMTP clients, or
7726 1.1 tron it can be specified in the <a href="master.5.html">master.cf</a> file for a specific client,
7727 1.1 tron for example:
7728 1.1 tron </p>
7729 1.1 tron
7730 1.1 tron <blockquote>
7731 1.1 tron <pre>
7732 1.1 tron /etc/postfix/<a href="master.5.html">master.cf</a>:
7733 1.1 tron smtp ... smtp -o <a href="postconf.5.html#smtp_bind_address6">smtp_bind_address6</a>=1:2:3:4:5:6:7:8
7734 1.1 tron </pre>
7735 1.1 tron </blockquote>
7736 1.1 tron
7737 1.1 tron <p> Note 1: when <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> specifies no more than one IPv6
7738 1.1 tron address, and that address is a non-loopback address, it is
7739 1.1 tron automatically used as the <a href="postconf.5.html#smtp_bind_address6">smtp_bind_address6</a>. This supports virtual
7740 1.1 tron IP hosting, but can be a problem on multi-homed firewalls. See the
7741 1.1 tron <a href="postconf.5.html#inet_interfaces">inet_interfaces</a> documentation for more detail. </p>
7742 1.1 tron
7743 1.1 tron <p> Note 2: address information may be enclosed inside <tt>[]</tt>,
7744 1.1 tron but this form is not recommended here. </p>
7745 1.1 tron
7746 1.1 tron
7747 1.1 tron </DD>
7748 1.1 tron
7749 1.1 tron <DT><b><a name="smtp_body_checks">smtp_body_checks</a>
7750 1.1 tron (default: empty)</b></DT><DD>
7751 1.1 tron
7752 1.1 tron <p> Restricted <a href="header_checks.5.html">body_checks(5)</a> tables for the Postfix SMTP client.
7753 1.1 tron These tables are searched while mail is being delivered. Actions
7754 1.1 tron that change the delivery time or destination are not available.
7755 1.1 tron </p>
7756 1.1 tron
7757 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
7758 1.1 tron
7759 1.1 tron
7760 1.1 tron </DD>
7761 1.1 tron
7762 1.1 tron <DT><b><a name="smtp_cname_overrides_servername">smtp_cname_overrides_servername</a>
7763 1.1 tron (default: version dependent)</b></DT><DD>
7764 1.1 tron
7765 1.1 tron <p> Allow DNS CNAME records to override the servername that the
7766 1.1 tron Postfix SMTP client uses for logging, SASL password lookup, TLS
7767 1.1 tron policy decisions, or TLS certificate verification. The value "no"
7768 1.1 tron hardens Postfix <a href="postconf.5.html#smtp_tls_per_site">smtp_tls_per_site</a> hostname-based policies against
7769 1.1 tron false hostname information in DNS CNAME records, and makes SASL
7770 1.1 tron password file lookups more predictable. This is the default setting
7771 1.1 tron as of Postfix 2.3. </p>
7772 1.1 tron
7773 1.1 tron <p> This feature is available in Postfix 2.2.9 and later. </p>
7774 1.1 tron
7775 1.1 tron
7776 1.1 tron </DD>
7777 1.1 tron
7778 1.1 tron <DT><b><a name="smtp_connect_timeout">smtp_connect_timeout</a>
7779 1.1 tron (default: 30s)</b></DT><DD>
7780 1.1 tron
7781 1.1 tron <p>
7782 1.1 tron The SMTP client time limit for completing a TCP connection, or
7783 1.1 tron zero (use the operating system built-in time limit).
7784 1.1 tron </p>
7785 1.1 tron
7786 1.1 tron <p>
7787 1.1 tron When no connection can be made within the deadline, the Postfix
7788 1.1 tron SMTP client
7789 1.1 tron tries the next address on the mail exchanger list. Specify 0 to
7790 1.1 tron disable the time limit (i.e. use whatever timeout is implemented by
7791 1.1 tron the operating system).
7792 1.1 tron </p>
7793 1.1 tron
7794 1.1 tron <p>
7795 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
7796 1.1 tron The default time unit is s (seconds).
7797 1.1 tron </p>
7798 1.1 tron
7799 1.1 tron
7800 1.1 tron </DD>
7801 1.1 tron
7802 1.1 tron <DT><b><a name="smtp_connection_cache_destinations">smtp_connection_cache_destinations</a>
7803 1.1 tron (default: empty)</b></DT><DD>
7804 1.1 tron
7805 1.1 tron <p> Permanently enable SMTP connection caching for the specified
7806 1.1 tron destinations. With SMTP connection caching, a connection is not
7807 1.1 tron closed immediately after completion of a mail transaction. Instead,
7808 1.1 tron the connection is kept open for up to $<a href="postconf.5.html#smtp_connection_cache_time_limit">smtp_connection_cache_time_limit</a>
7809 1.1 tron seconds. This allows connections to be reused for other deliveries,
7810 1.1 tron and can improve mail delivery performance. </p>
7811 1.1 tron
7812 1.1 tron <p> Specify a comma or white space separated list of destinations
7813 1.1 tron or pseudo-destinations: </p>
7814 1.1 tron
7815 1.1 tron <ul>
7816 1.1 tron
7817 1.1 tron <li> if mail is sent without a <a href="postconf.5.html#relayhost">relay host</a>: a domain name (the
7818 1.1 tron right-hand side of an email address, without the [] around a numeric
7819 1.1 tron IP address),
7820 1.1 tron
7821 1.1 tron <li> if mail is sent via a <a href="postconf.5.html#relayhost">relay host</a>: a <a href="postconf.5.html#relayhost">relay host</a> name (without
7822 1.1 tron [] or non-default TCP port), as specified in <a href="postconf.5.html">main.cf</a> or in the
7823 1.1 tron transport map,
7824 1.1 tron
7825 1.1 tron <li> if mail is sent via a UNIX-domain socket: a pathname (without
7826 1.1 tron the unix: prefix),
7827 1.1 tron
7828 1.1 tron <li> a /file/name with domain names and/or <a href="postconf.5.html#relayhost">relay host</a> names as
7829 1.1 tron defined above,
7830 1.1 tron
7831 1.1 tron <li> a "<a href="DATABASE_README.html">type:table</a>" with domain names and/or <a href="postconf.5.html#relayhost">relay host</a> names on
7832 1.1 tron the left-hand side. The right-hand side result from "<a href="DATABASE_README.html">type:table</a>"
7833 1.1 tron lookups is ignored.
7834 1.1 tron
7835 1.1 tron </ul>
7836 1.1 tron
7837 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
7838 1.1 tron
7839 1.1 tron
7840 1.1 tron </DD>
7841 1.1 tron
7842 1.1 tron <DT><b><a name="smtp_connection_cache_on_demand">smtp_connection_cache_on_demand</a>
7843 1.1 tron (default: yes)</b></DT><DD>
7844 1.1 tron
7845 1.1 tron <p> Temporarily enable SMTP connection caching while a destination
7846 1.1 tron has a high volume of mail in the <a href="QSHAPE_README.html#active_queue">active queue</a>. With SMTP connection
7847 1.1 tron caching, a connection is not closed immediately after completion
7848 1.1 tron of a mail transaction. Instead, the connection is kept open for
7849 1.1 tron up to $<a href="postconf.5.html#smtp_connection_cache_time_limit">smtp_connection_cache_time_limit</a> seconds. This allows
7850 1.1 tron connections to be reused for other deliveries, and can improve mail
7851 1.1 tron delivery performance. </p>
7852 1.1 tron
7853 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
7854 1.1 tron
7855 1.1 tron
7856 1.1 tron </DD>
7857 1.1 tron
7858 1.1 tron <DT><b><a name="smtp_connection_cache_reuse_limit">smtp_connection_cache_reuse_limit</a>
7859 1.1 tron (default: 10)</b></DT><DD>
7860 1.1 tron
7861 1.1 tron <p> When SMTP connection caching is enabled, the number of times that
7862 1.1 tron an SMTP session may be reused before it is closed.
7863 1.1 tron </p>
7864 1.1 tron
7865 1.1 tron <p> This feature is available in Postfix 2.2. In Postfix 2.3 it is
7866 1.1 tron replaced by $<a href="postconf.5.html#smtp_connection_reuse_time_limit">smtp_connection_reuse_time_limit</a>.</p>
7867 1.1 tron
7868 1.1 tron
7869 1.1 tron </DD>
7870 1.1 tron
7871 1.1 tron <DT><b><a name="smtp_connection_cache_time_limit">smtp_connection_cache_time_limit</a>
7872 1.1 tron (default: 2s)</b></DT><DD>
7873 1.1 tron
7874 1.1 tron <p> When SMTP connection caching is enabled, the amount of time that
7875 1.1 tron an unused SMTP client socket is kept open before it is closed. Do
7876 1.1 tron not specify larger values without permission from the remote sites.
7877 1.1 tron </p>
7878 1.1 tron
7879 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
7880 1.1 tron
7881 1.1 tron
7882 1.1 tron </DD>
7883 1.1 tron
7884 1.1 tron <DT><b><a name="smtp_connection_reuse_time_limit">smtp_connection_reuse_time_limit</a>
7885 1.1 tron (default: 300s)</b></DT><DD>
7886 1.1 tron
7887 1.1 tron <p> The amount of time during which Postfix will use an SMTP
7888 1.1 tron connection repeatedly. The timer starts when the connection is
7889 1.1 tron initiated (i.e. it includes the connect, greeting and helo latency,
7890 1.1 tron in addition to the latencies of subsequent mail delivery transactions).
7891 1.1 tron </p>
7892 1.1 tron
7893 1.1 tron <p> This feature addresses a performance stability problem with
7894 1.1 tron remote SMTP servers. This problem is not specific to Postfix: it
7895 1.1 tron can happen when any MTA sends large amounts of SMTP email to a site
7896 1.1 tron that has multiple MX hosts. </p>
7897 1.1 tron
7898 1.1 tron <p> The problem starts when one of a set of MX hosts becomes slower
7899 1.1 tron than the rest. Even though SMTP clients connect to fast and slow
7900 1.1 tron MX hosts with equal probability, the slow MX host ends up with more
7901 1.1 tron simultaneous inbound connections than the faster MX hosts, because
7902 1.1 tron the slow MX host needs more time to serve each client request. </p>
7903 1.1 tron
7904 1.1 tron <p> The slow MX host becomes a connection attractor. If one MX
7905 1.1 tron host becomes N times slower than the rest, it dominates mail delivery
7906 1.1 tron latency unless there are more than N fast MX hosts to counter the
7907 1.1 tron effect. And if the number of MX hosts is smaller than N, the mail
7908 1.1 tron delivery latency becomes effectively that of the slowest MX host
7909 1.1 tron divided by the total number of MX hosts. </p>
7910 1.1 tron
7911 1.1 tron <p> The solution uses connection caching in a way that differs from
7912 1.1 tron Postfix version 2.2. By limiting the amount of time during which a connection
7913 1.1 tron can be used repeatedly (instead of limiting the number of deliveries
7914 1.1 tron over that connection), Postfix not only restores fairness in the
7915 1.1 tron distribution of simultaneous connections across a set of MX hosts,
7916 1.1 tron it also favors deliveries over connections that perform well, which
7917 1.1 tron is exactly what we want. </p>
7918 1.1 tron
7919 1.1 tron <p> The default reuse time limit, 300s, is comparable to the various
7920 1.1 tron smtp transaction timeouts which are fair estimates of maximum excess
7921 1.1 tron latency for a slow delivery. Note that hosts may accept thousands
7922 1.1 tron of messages over a single connection within the default connection
7923 1.1 tron reuse time limit. This number is much larger than the default Postfix
7924 1.1 tron version 2.2 limit of 10 messages per cached connection. It may prove necessary
7925 1.1 tron to lower the limit to avoid interoperability issues with MTAs that
7926 1.1 tron exhibit bugs when many messages are delivered via a single connection.
7927 1.1 tron A lower reuse time limit risks losing the benefit of connection
7928 1.1 tron reuse when the average connection and mail delivery latency exceeds
7929 1.1 tron the reuse time limit. </p>
7930 1.1 tron
7931 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
7932 1.1 tron
7933 1.1 tron
7934 1.1 tron </DD>
7935 1.1 tron
7936 1.1 tron <DT><b><a name="smtp_data_done_timeout">smtp_data_done_timeout</a>
7937 1.1 tron (default: 600s)</b></DT><DD>
7938 1.1 tron
7939 1.1 tron <p>
7940 1.1 tron The SMTP client time limit for sending the SMTP ".", and for receiving
7941 1.1 tron the server response.
7942 1.1 tron </p>
7943 1.1 tron
7944 1.1 tron <p>
7945 1.1 tron When no response is received within the deadline, a warning is
7946 1.1 tron logged that the mail may be delivered multiple times.
7947 1.1 tron </p>
7948 1.1 tron
7949 1.1 tron <p>
7950 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
7951 1.1 tron The default time unit is s (seconds).
7952 1.1 tron </p>
7953 1.1 tron
7954 1.1 tron
7955 1.1 tron </DD>
7956 1.1 tron
7957 1.1 tron <DT><b><a name="smtp_data_init_timeout">smtp_data_init_timeout</a>
7958 1.1 tron (default: 120s)</b></DT><DD>
7959 1.1 tron
7960 1.1 tron <p>
7961 1.1 tron The SMTP client time limit for sending the SMTP DATA command, and for
7962 1.1 tron receiving the server response.
7963 1.1 tron </p>
7964 1.1 tron
7965 1.1 tron <p>
7966 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
7967 1.1 tron The default time unit is s (seconds).
7968 1.1 tron </p>
7969 1.1 tron
7970 1.1 tron
7971 1.1 tron </DD>
7972 1.1 tron
7973 1.1 tron <DT><b><a name="smtp_data_xfer_timeout">smtp_data_xfer_timeout</a>
7974 1.1 tron (default: 180s)</b></DT><DD>
7975 1.1 tron
7976 1.1 tron <p>
7977 1.1 tron The SMTP client time limit for sending the SMTP message content.
7978 1.1 tron When the connection makes no progress for more than $<a href="postconf.5.html#smtp_data_xfer_timeout">smtp_data_xfer_timeout</a>
7979 1.1 tron seconds the Postfix SMTP client terminates the transfer.
7980 1.1 tron </p>
7981 1.1 tron
7982 1.1 tron <p>
7983 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
7984 1.1 tron The default time unit is s (seconds).
7985 1.1 tron </p>
7986 1.1 tron
7987 1.1 tron
7988 1.1 tron </DD>
7989 1.1 tron
7990 1.1 tron <DT><b><a name="smtp_defer_if_no_mx_address_found">smtp_defer_if_no_mx_address_found</a>
7991 1.1 tron (default: no)</b></DT><DD>
7992 1.1 tron
7993 1.1 tron <p>
7994 1.1 tron Defer mail delivery when no MX record resolves to an IP address.
7995 1.1 tron </p>
7996 1.1 tron
7997 1.1 tron <p>
7998 1.1 tron The default (no) is to return the mail as undeliverable. With older
7999 1.1 tron Postfix versions the default was to keep trying to deliver the mail
8000 1.1 tron until someone fixed the MX record or until the mail was too old.
8001 1.1 tron </p>
8002 1.1 tron
8003 1.1 tron <p>
8004 1.1 tron Note: Postfix always ignores MX records with equal or worse preference
8005 1.1 tron than the local MTA itself.
8006 1.1 tron </p>
8007 1.1 tron
8008 1.1 tron <p>
8009 1.1 tron This feature is available in Postfix 2.1 and later.
8010 1.1 tron </p>
8011 1.1 tron
8012 1.1 tron
8013 1.1 tron </DD>
8014 1.1 tron
8015 1.1 tron <DT><b><a name="smtp_destination_concurrency_limit">smtp_destination_concurrency_limit</a>
8016 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_limit">default_destination_concurrency_limit</a>)</b></DT><DD>
8017 1.1 tron
8018 1.1 tron <p> The maximal number of parallel deliveries to the same destination
8019 1.1 tron via the smtp message delivery transport. This limit is enforced by
8020 1.1 tron the queue manager. The message delivery transport name is the first
8021 1.1 tron field in the entry in the <a href="master.5.html">master.cf</a> file. </p>
8022 1.1 tron
8023 1.1 tron
8024 1.1 tron </DD>
8025 1.1 tron
8026 1.1 tron <DT><b><a name="smtp_destination_recipient_limit">smtp_destination_recipient_limit</a>
8027 1.1 tron (default: $<a href="postconf.5.html#default_destination_recipient_limit">default_destination_recipient_limit</a>)</b></DT><DD>
8028 1.1 tron
8029 1.1 tron <p> The maximal number of recipients per message for the smtp
8030 1.1 tron message delivery transport. This limit is enforced by the queue
8031 1.1 tron manager. The message delivery transport name is the first field in
8032 1.1 tron the entry in the <a href="master.5.html">master.cf</a> file. </p>
8033 1.1 tron
8034 1.1 tron <p> Setting this parameter to a value of 1 changes the meaning of
8035 1.1 tron <a href="postconf.5.html#smtp_destination_concurrency_limit">smtp_destination_concurrency_limit</a> from concurrency per domain
8036 1.1 tron into concurrency per recipient. </p>
8037 1.1 tron
8038 1.1 tron
8039 1.1 tron </DD>
8040 1.1 tron
8041 1.1 tron <DT><b><a name="smtp_discard_ehlo_keyword_address_maps">smtp_discard_ehlo_keyword_address_maps</a>
8042 1.1 tron (default: empty)</b></DT><DD>
8043 1.1 tron
8044 1.1 tron <p> Lookup tables, indexed by the remote SMTP server address, with
8045 1.1 tron case insensitive lists of EHLO keywords (pipelining, starttls, auth,
8046 1.1 tron etc.) that the Postfix SMTP client will ignore in the EHLO response from a
8047 1.1 tron remote SMTP server. See <a href="postconf.5.html#smtp_discard_ehlo_keywords">smtp_discard_ehlo_keywords</a> for details. The
8048 1.1 tron table is not indexed by hostname for consistency with
8049 1.1 tron <a href="postconf.5.html#smtpd_discard_ehlo_keyword_address_maps">smtpd_discard_ehlo_keyword_address_maps</a>. </p>
8050 1.1 tron
8051 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8052 1.1 tron
8053 1.1 tron
8054 1.1 tron </DD>
8055 1.1 tron
8056 1.1 tron <DT><b><a name="smtp_discard_ehlo_keywords">smtp_discard_ehlo_keywords</a>
8057 1.1 tron (default: empty)</b></DT><DD>
8058 1.1 tron
8059 1.1 tron <p> A case insensitive list of EHLO keywords (pipelining, starttls,
8060 1.1 tron auth, etc.) that the Postfix SMTP client will ignore in the EHLO
8061 1.1 tron response from a remote SMTP server. </p>
8062 1.1 tron
8063 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8064 1.1 tron
8065 1.1 tron <p> Notes: </p>
8066 1.1 tron
8067 1.1 tron <ul>
8068 1.1 tron
8069 1.1 tron <li> <p> Specify the <b>silent-discard</b> pseudo keyword to prevent
8070 1.1 tron this action from being logged. </p>
8071 1.1 tron
8072 1.1 tron <li> <p> Use the <a href="postconf.5.html#smtp_discard_ehlo_keyword_address_maps">smtp_discard_ehlo_keyword_address_maps</a> feature to
8073 1.1 tron discard EHLO keywords selectively. </p>
8074 1.1 tron
8075 1.1 tron </ul>
8076 1.1 tron
8077 1.1 tron
8078 1.1 tron </DD>
8079 1.1 tron
8080 1.1 tron <DT><b><a name="smtp_enforce_tls">smtp_enforce_tls</a>
8081 1.1 tron (default: no)</b></DT><DD>
8082 1.1 tron
8083 1.1 tron <p> Enforcement mode: require that remote SMTP servers use TLS
8084 1.1 tron encryption, and never send mail in the clear. This also requires
8085 1.1 tron that the remote SMTP server hostname matches the information in
8086 1.1 tron the remote server certificate, and that the remote SMTP server
8087 1.1 tron certificate was issued by a CA that is trusted by the Postfix SMTP
8088 1.1 tron client. If the certificate doesn't verify or the hostname doesn't
8089 1.1 tron match, delivery is deferred and mail stays in the queue. </p>
8090 1.1 tron
8091 1.1 tron <p> The server hostname is matched against all names provided as
8092 1.1 tron dNSNames in the SubjectAlternativeName. If no dNSNames are specified,
8093 1.1 tron the CommonName is checked. The behavior may be changed with the
8094 1.1 tron <a href="postconf.5.html#smtp_tls_enforce_peername">smtp_tls_enforce_peername</a> option. </p>
8095 1.1 tron
8096 1.1 tron <p> This option is useful only if you are definitely sure that you
8097 1.1 tron will only connect to servers that support <a href="http://tools.ietf.org/html/rfc2487">RFC 2487</a> _and_ that
8098 1.1 tron provide valid server certificates. Typical use is for clients that
8099 1.1 tron send all their email to a dedicated mailhub. </p>
8100 1.1 tron
8101 1.1 tron <p> This feature is available in Postfix 2.2 and later. With
8102 1.1 tron Postfix 2.3 and later use <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> instead. </p>
8103 1.1 tron
8104 1.1 tron
8105 1.1 tron </DD>
8106 1.1 tron
8107 1.1 tron <DT><b><a name="smtp_fallback_relay">smtp_fallback_relay</a>
8108 1.1 tron (default: $<a href="postconf.5.html#fallback_relay">fallback_relay</a>)</b></DT><DD>
8109 1.1 tron
8110 1.1 tron <p>
8111 1.1 tron Optional list of relay hosts for SMTP destinations that can't be
8112 1.1 tron found or that are unreachable. With Postfix 2.2 and earlier this
8113 1.1 tron parameter is called <a href="postconf.5.html#fallback_relay">fallback_relay</a>. </p>
8114 1.1 tron
8115 1.1 tron <p>
8116 1.1 tron By default, mail is returned to the sender when a destination is
8117 1.1 tron not found, and delivery is deferred when a destination is unreachable.
8118 1.1 tron </p>
8119 1.1 tron
8120 1.1 tron <p> The fallback relays must be SMTP destinations. Specify a domain,
8121 1.1 tron host, host:port, [host]:port, [address] or [address]:port; the form
8122 1.1 tron [host] turns off MX lookups. If you specify multiple SMTP
8123 1.1 tron destinations, Postfix will try them in the specified order. </p>
8124 1.1 tron
8125 1.1 tron <p> To prevent mailer loops between MX hosts and fall-back hosts,
8126 1.1 tron Postfix version 2.2 and later will not use the fallback relays for
8127 1.1 tron destinations that it is MX host for (assuming DNS lookup is turned on).
8128 1.1 tron </p>
8129 1.1 tron
8130 1.1 tron
8131 1.1 tron </DD>
8132 1.1 tron
8133 1.1 tron <DT><b><a name="smtp_generic_maps">smtp_generic_maps</a>
8134 1.1 tron (default: empty)</b></DT><DD>
8135 1.1 tron
8136 1.1 tron <p> Optional lookup tables that perform address rewriting in the
8137 1.1 tron SMTP client, typically to transform a locally valid address into
8138 1.1 tron a globally valid address when sending mail across the Internet.
8139 1.1 tron This is needed when the local machine does not have its own Internet
8140 1.1 tron domain name, but uses something like <i>localdomain.local</i>
8141 1.1 tron instead. </p>
8142 1.1 tron
8143 1.1 tron <p> The table format and lookups are documented in <a href="generic.5.html">generic(5)</a>;
8144 1.1 tron examples are shown in the <a href="ADDRESS_REWRITING_README.html">ADDRESS_REWRITING_README</a> and
8145 1.1 tron <a href="STANDARD_CONFIGURATION_README.html">STANDARD_CONFIGURATION_README</a> documents. </p>
8146 1.1 tron
8147 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8148 1.1 tron
8149 1.1 tron
8150 1.1 tron </DD>
8151 1.1 tron
8152 1.1 tron <DT><b><a name="smtp_header_checks">smtp_header_checks</a>
8153 1.1 tron (default: empty)</b></DT><DD>
8154 1.1 tron
8155 1.1 tron <p> Restricted <a href="header_checks.5.html">header_checks(5)</a> tables for the Postfix SMTP client.
8156 1.1 tron These tables are searched while mail is being delivered. Actions
8157 1.1 tron that change the delivery time or destination are not available.
8158 1.1 tron </p>
8159 1.1 tron
8160 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
8161 1.1 tron
8162 1.1 tron
8163 1.1 tron </DD>
8164 1.1 tron
8165 1.1 tron <DT><b><a name="smtp_helo_name">smtp_helo_name</a>
8166 1.1 tron (default: $<a href="postconf.5.html#myhostname">myhostname</a>)</b></DT><DD>
8167 1.1 tron
8168 1.1 tron <p>
8169 1.1 tron The hostname to send in the SMTP EHLO or HELO command.
8170 1.1 tron </p>
8171 1.1 tron
8172 1.1 tron <p>
8173 1.1 tron The default value is the machine hostname. Specify a hostname or
8174 1.1 tron [ip.add.re.ss].
8175 1.1 tron </p>
8176 1.1 tron
8177 1.1 tron <p>
8178 1.1 tron This information can be specified in the <a href="postconf.5.html">main.cf</a> file for all SMTP
8179 1.1 tron clients, or it can be specified in the <a href="master.5.html">master.cf</a> file for a specific
8180 1.1 tron client, for example:
8181 1.1 tron </p>
8182 1.1 tron
8183 1.1 tron <blockquote>
8184 1.1 tron <pre>
8185 1.1 tron /etc/postfix/<a href="master.5.html">master.cf</a>:
8186 1.1 tron mysmtp ... smtp -o <a href="postconf.5.html#smtp_helo_name">smtp_helo_name</a>=foo.bar.com
8187 1.1 tron </pre>
8188 1.1 tron </blockquote>
8189 1.1 tron
8190 1.1 tron <p>
8191 1.1 tron This feature is available in Postfix 2.0 and later.
8192 1.1 tron </p>
8193 1.1 tron
8194 1.1 tron
8195 1.1 tron </DD>
8196 1.1 tron
8197 1.1 tron <DT><b><a name="smtp_helo_timeout">smtp_helo_timeout</a>
8198 1.1 tron (default: 300s)</b></DT><DD>
8199 1.1 tron
8200 1.1 tron <p>
8201 1.1 tron The SMTP client time limit for sending the HELO or EHLO command,
8202 1.1 tron and for receiving the initial server response.
8203 1.1 tron </p>
8204 1.1 tron
8205 1.1 tron <p>
8206 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
8207 1.1 tron The default time unit is s (seconds).
8208 1.1 tron </p>
8209 1.1 tron
8210 1.1 tron
8211 1.1 tron </DD>
8212 1.1 tron
8213 1.1 tron <DT><b><a name="smtp_host_lookup">smtp_host_lookup</a>
8214 1.1 tron (default: dns)</b></DT><DD>
8215 1.1 tron
8216 1.1 tron <p>
8217 1.1 tron What mechanisms when the Postfix SMTP client uses to look up a host's IP
8218 1.1 tron address. This parameter is ignored when DNS lookups are disabled.
8219 1.1 tron </p>
8220 1.1 tron
8221 1.1 tron <p>
8222 1.1 tron Specify one of the following:
8223 1.1 tron </p>
8224 1.1 tron
8225 1.1 tron <dl>
8226 1.1 tron
8227 1.1 tron <dt><b>dns</b></dt>
8228 1.1 tron
8229 1.1 tron <dd>Hosts can be found in the DNS (preferred). </dd>
8230 1.1 tron
8231 1.1 tron <dt><b>native</b></dt>
8232 1.1 tron
8233 1.1 tron <dd>Use the native naming service only (nsswitch.conf, or equivalent
8234 1.1 tron mechanism). </dd>
8235 1.1 tron
8236 1.1 tron <dt><b>dns, native</b></dt>
8237 1.1 tron
8238 1.1 tron <dd>Use the native service for hosts not found in the DNS. </dd>
8239 1.1 tron
8240 1.1 tron </dl>
8241 1.1 tron
8242 1.1 tron <p>
8243 1.1 tron This feature is available in Postfix 2.1 and later.
8244 1.1 tron </p>
8245 1.1 tron
8246 1.1 tron
8247 1.1 tron </DD>
8248 1.1 tron
8249 1.1 tron <DT><b><a name="smtp_line_length_limit">smtp_line_length_limit</a>
8250 1.1 tron (default: 990)</b></DT><DD>
8251 1.1 tron
8252 1.1 tron <p>
8253 1.1 tron The maximal length of message header and body lines that Postfix
8254 1.1 tron will send via SMTP. Longer lines are broken by inserting
8255 1.1 tron "<CR><LF><SPACE>". This minimizes the damage to
8256 1.1 tron MIME formatted mail.
8257 1.1 tron </p>
8258 1.1 tron
8259 1.1 tron <p>
8260 1.1 tron By default, the line length is limited to 990 characters, because
8261 1.1 tron some server implementations cannot receive mail with long lines.
8262 1.1 tron </p>
8263 1.1 tron
8264 1.1 tron
8265 1.1 tron </DD>
8266 1.1 tron
8267 1.1 tron <DT><b><a name="smtp_mail_timeout">smtp_mail_timeout</a>
8268 1.1 tron (default: 300s)</b></DT><DD>
8269 1.1 tron
8270 1.1 tron <p>
8271 1.1 tron The SMTP client time limit for sending the MAIL FROM command, and
8272 1.1 tron for receiving the server response.
8273 1.1 tron </p>
8274 1.1 tron
8275 1.1 tron <p>
8276 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
8277 1.1 tron The default time unit is s (seconds).
8278 1.1 tron </p>
8279 1.1 tron
8280 1.1 tron
8281 1.1 tron </DD>
8282 1.1 tron
8283 1.1 tron <DT><b><a name="smtp_mime_header_checks">smtp_mime_header_checks</a>
8284 1.1 tron (default: empty)</b></DT><DD>
8285 1.1 tron
8286 1.1 tron <p> Restricted mime_<a href="header_checks.5.html">header_checks(5)</a> tables for the Postfix SMTP
8287 1.1 tron client. These tables are searched while mail is being delivered.
8288 1.1 tron Actions that change the delivery time or destination are not
8289 1.1 tron available. </p>
8290 1.1 tron
8291 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
8292 1.1 tron
8293 1.1 tron
8294 1.1 tron </DD>
8295 1.1 tron
8296 1.1 tron <DT><b><a name="smtp_mx_address_limit">smtp_mx_address_limit</a>
8297 1.1 tron (default: 5)</b></DT><DD>
8298 1.1 tron
8299 1.1 tron <p>
8300 1.1 tron The maximal number of MX (mail exchanger) IP addresses that can
8301 1.1 tron result from mail exchanger lookups, or zero (no limit). Prior to
8302 1.1 tron Postfix version 2.3, this limit was disabled by default.
8303 1.1 tron </p>
8304 1.1 tron
8305 1.1 tron <p>
8306 1.1 tron This feature is available in Postfix 2.1 and later.
8307 1.1 tron </p>
8308 1.1 tron
8309 1.1 tron
8310 1.1 tron </DD>
8311 1.1 tron
8312 1.1 tron <DT><b><a name="smtp_mx_session_limit">smtp_mx_session_limit</a>
8313 1.1 tron (default: 2)</b></DT><DD>
8314 1.1 tron
8315 1.1 tron <p> The maximal number of SMTP sessions per delivery request before
8316 1.1 tron giving up or delivering to a fall-back <a href="postconf.5.html#relayhost">relay host</a>, or zero (no
8317 1.1 tron limit). This restriction ignores sessions that fail to complete the
8318 1.1 tron SMTP initial handshake (Postfix version 2.2 and earlier) or that fail to
8319 1.1 tron complete the EHLO and TLS handshake (Postfix version 2.3 and later). </p>
8320 1.1 tron
8321 1.1 tron <p> This feature is available in Postfix 2.1 and later. </p>
8322 1.1 tron
8323 1.1 tron
8324 1.1 tron </DD>
8325 1.1 tron
8326 1.1 tron <DT><b><a name="smtp_nested_header_checks">smtp_nested_header_checks</a>
8327 1.1 tron (default: empty)</b></DT><DD>
8328 1.1 tron
8329 1.1 tron <p> Restricted nested_<a href="header_checks.5.html">header_checks(5)</a> tables for the Postfix SMTP
8330 1.1 tron client. These tables are searched while mail is being delivered.
8331 1.1 tron Actions that change the delivery time or destination are not
8332 1.1 tron available. </p>
8333 1.1 tron
8334 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
8335 1.1 tron
8336 1.1 tron
8337 1.1 tron </DD>
8338 1.1 tron
8339 1.1 tron <DT><b><a name="smtp_never_send_ehlo">smtp_never_send_ehlo</a>
8340 1.1 tron (default: no)</b></DT><DD>
8341 1.1 tron
8342 1.1 tron <p> Never send EHLO at the start of an SMTP session. See also the
8343 1.1 tron <a href="postconf.5.html#smtp_always_send_ehlo">smtp_always_send_ehlo</a> parameter. </p>
8344 1.1 tron
8345 1.1 tron
8346 1.1 tron </DD>
8347 1.1 tron
8348 1.1 tron <DT><b><a name="smtp_pix_workaround_delay_time">smtp_pix_workaround_delay_time</a>
8349 1.1 tron (default: 10s)</b></DT><DD>
8350 1.1 tron
8351 1.1 tron <p>
8352 1.1 tron How long the Postfix SMTP client pauses before sending
8353 1.1 tron ".<CR><LF>" in order to work around the PIX firewall
8354 1.1 tron "<CR><LF>.<CR><LF>" bug.
8355 1.1 tron </p>
8356 1.1 tron
8357 1.1 tron <p>
8358 1.1 tron Choosing a too short time makes this workaround ineffective when
8359 1.1 tron sending large messages over slow network connections.
8360 1.1 tron </p>
8361 1.1 tron
8362 1.1 tron
8363 1.1 tron </DD>
8364 1.1 tron
8365 1.1 tron <DT><b><a name="smtp_pix_workaround_maps">smtp_pix_workaround_maps</a>
8366 1.1 tron (default: empty)</b></DT><DD>
8367 1.1 tron
8368 1.1 tron <p> Lookup tables, indexed by the remote SMTP server address, with
8369 1.1 tron per-destination workarounds for CISCO PIX firewall bugs. The table
8370 1.1 tron is not indexed by hostname for consistency with
8371 1.1 tron <a href="postconf.5.html#smtp_discard_ehlo_keyword_address_maps">smtp_discard_ehlo_keyword_address_maps</a>. </p>
8372 1.1 tron
8373 1.1 tron <p> This feature is available in Postfix 2.4 and later. </p>
8374 1.1 tron
8375 1.1 tron
8376 1.1 tron </DD>
8377 1.1 tron
8378 1.1 tron <DT><b><a name="smtp_pix_workaround_threshold_time">smtp_pix_workaround_threshold_time</a>
8379 1.1 tron (default: 500s)</b></DT><DD>
8380 1.1 tron
8381 1.1 tron <p> How long a message must be queued before the Postfix SMTP client
8382 1.1 tron turns on the PIX firewall "<CR><LF>.<CR><LF>"
8383 1.1 tron bug workaround for delivery through firewalls with "smtp fixup"
8384 1.1 tron mode turned on. </p>
8385 1.1 tron
8386 1.1 tron <p>
8387 1.1 tron By default, the workaround is turned off for mail that is queued
8388 1.1 tron for less than 500 seconds. In other words, the workaround is normally
8389 1.1 tron turned off for the first delivery attempt.
8390 1.1 tron </p>
8391 1.1 tron
8392 1.1 tron <p>
8393 1.1 tron Specify 0 to enable the PIX firewall
8394 1.1 tron "<CR><LF>.<CR><LF>" bug workaround upon the
8395 1.1 tron first delivery attempt.
8396 1.1 tron </p>
8397 1.1 tron
8398 1.1 tron
8399 1.1 tron </DD>
8400 1.1 tron
8401 1.1 tron <DT><b><a name="smtp_pix_workarounds">smtp_pix_workarounds</a>
8402 1.1 tron (default: disable_esmtp, delay_dotcrlf)</b></DT><DD>
8403 1.1 tron
8404 1.1 tron <p> A list that specifies zero or more workarounds for CISCO PIX
8405 1.1 tron firewall bugs. These workarounds are implemented by the Postfix
8406 1.1 tron SMTP client. Workaround names are separated by comma or space, and
8407 1.1 tron are case insensitive. This parameter setting can be overruled with
8408 1.1 tron per-destination <a href="postconf.5.html#smtp_pix_workaround_maps">smtp_pix_workaround_maps</a> settings. </p>
8409 1.1 tron
8410 1.1 tron <dl>
8411 1.1 tron
8412 1.1 tron <dt><b>delay_dotcrlf</b><dd> Insert a delay before sending
8413 1.1 tron ".<CR><LF>" after the end of the message content. The
8414 1.1 tron delay is subject to the <a href="postconf.5.html#smtp_pix_workaround_delay_time">smtp_pix_workaround_delay_time</a> and
8415 1.1 tron <a href="postconf.5.html#smtp_pix_workaround_threshold_time">smtp_pix_workaround_threshold_time</a> parameter settings. </dd>
8416 1.1 tron
8417 1.1 tron <dt><b>disable_esmtp</b><dd> Disable all extended SMTP commands:
8418 1.1 tron send HELO instead of EHLO. </dd>
8419 1.1 tron
8420 1.1 tron </dl>
8421 1.1 tron
8422 1.1 tron <p> This feature is available in Postfix 2.4 and later. The default
8423 1.1 tron settings are backwards compatible with earlier Postfix versions.
8424 1.1 tron </p>
8425 1.1 tron
8426 1.1 tron
8427 1.1 tron </DD>
8428 1.1 tron
8429 1.1 tron <DT><b><a name="smtp_quit_timeout">smtp_quit_timeout</a>
8430 1.1 tron (default: 300s)</b></DT><DD>
8431 1.1 tron
8432 1.1 tron <p>
8433 1.1 tron The SMTP client time limit for sending the QUIT command, and for
8434 1.1 tron receiving the server response.
8435 1.1 tron </p>
8436 1.1 tron
8437 1.1 tron <p>
8438 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
8439 1.1 tron The default time unit is s (seconds).
8440 1.1 tron </p>
8441 1.1 tron
8442 1.1 tron
8443 1.1 tron </DD>
8444 1.1 tron
8445 1.1 tron <DT><b><a name="smtp_quote_rfc821_envelope">smtp_quote_rfc821_envelope</a>
8446 1.1 tron (default: yes)</b></DT><DD>
8447 1.1 tron
8448 1.1 tron <p>
8449 1.1 tron Quote addresses in SMTP MAIL FROM and RCPT TO commands as required
8450 1.1 tron by <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>. This includes putting quotes around an address localpart
8451 1.1 tron that ends in ".".
8452 1.1 tron </p>
8453 1.1 tron
8454 1.1 tron <p>
8455 1.1 tron The default is to comply with <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>. If you have to send mail to
8456 1.1 tron a broken SMTP server, configure a special SMTP client in <a href="master.5.html">master.cf</a>:
8457 1.1 tron </p>
8458 1.1 tron
8459 1.1 tron <blockquote>
8460 1.1 tron <pre>
8461 1.1 tron /etc/postfix/<a href="master.5.html">master.cf</a>:
8462 1.1 tron broken-smtp . . . smtp -o <a href="postconf.5.html#smtp_quote_rfc821_envelope">smtp_quote_rfc821_envelope</a>=no
8463 1.1 tron </pre>
8464 1.1 tron </blockquote>
8465 1.1 tron
8466 1.1 tron <p>
8467 1.1 tron and route mail for the destination in question to the "broken-smtp"
8468 1.1 tron message delivery with a <a href="transport.5.html">transport(5)</a> table.
8469 1.1 tron </p>
8470 1.1 tron
8471 1.1 tron <p>
8472 1.1 tron This feature is available in Postfix 2.1 and later.
8473 1.1 tron </p>
8474 1.1 tron
8475 1.1 tron
8476 1.1 tron </DD>
8477 1.1 tron
8478 1.1 tron <DT><b><a name="smtp_randomize_addresses">smtp_randomize_addresses</a>
8479 1.1 tron (default: yes)</b></DT><DD>
8480 1.1 tron
8481 1.1 tron <p>
8482 1.1 tron Randomize the order of equal-preference MX host addresses. This
8483 1.1 tron is a performance feature of the Postfix SMTP client.
8484 1.1 tron </p>
8485 1.1 tron
8486 1.1 tron
8487 1.1 tron </DD>
8488 1.1 tron
8489 1.1 tron <DT><b><a name="smtp_rcpt_timeout">smtp_rcpt_timeout</a>
8490 1.1 tron (default: 300s)</b></DT><DD>
8491 1.1 tron
8492 1.1 tron <p>
8493 1.1 tron The SMTP client time limit for sending the SMTP RCPT TO command, and
8494 1.1 tron for receiving the server response.
8495 1.1 tron </p>
8496 1.1 tron
8497 1.1 tron <p>
8498 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
8499 1.1 tron The default time unit is s (seconds).
8500 1.1 tron </p>
8501 1.1 tron
8502 1.1 tron
8503 1.1 tron </DD>
8504 1.1 tron
8505 1.1 tron <DT><b><a name="smtp_rset_timeout">smtp_rset_timeout</a>
8506 1.1 tron (default: 20s)</b></DT><DD>
8507 1.1 tron
8508 1.1 tron <p> The SMTP client time limit for sending the RSET command, and
8509 1.1 tron for receiving the server response. The SMTP client sends RSET in
8510 1.1 tron order to finish a recipient address probe, or to verify that a
8511 1.1 tron cached session is still usable. </p>
8512 1.1 tron
8513 1.1 tron <p> This feature is available in Postfix 2.1 and later. </p>
8514 1.1 tron
8515 1.1 tron
8516 1.1 tron </DD>
8517 1.1 tron
8518 1.1 tron <DT><b><a name="smtp_sasl_auth_cache_name">smtp_sasl_auth_cache_name</a>
8519 1.1 tron (default: empty)</b></DT><DD>
8520 1.1 tron
8521 1.1 tron <p> An optional table to prevent repeated SASL authentication
8522 1.1 tron failures with the same remote SMTP server hostname, username and
8523 1.1 tron password. Each table (key, value) pair contains a server name, a
8524 1.1 tron username and password, and the full server response. This information
8525 1.1 tron is stored when a remote SMTP server rejects an authentication attempt
8526 1.1 tron with a 535 reply code. As long as the <a href="postconf.5.html#smtp_sasl_password_maps">smtp_sasl_password_maps</a>
8527 1.1 tron information does no change, and as long as the <a href="postconf.5.html#smtp_sasl_auth_cache_name">smtp_sasl_auth_cache_name</a>
8528 1.1 tron information does not expire (see <a href="postconf.5.html#smtp_sasl_auth_cache_time">smtp_sasl_auth_cache_time</a>) the
8529 1.1 tron Postfix SMTP client avoids SASL authentication attempts with the
8530 1.1 tron same server, username and password, and instead bounces or defers
8531 1.1 tron mail as controlled with the <a href="postconf.5.html#smtp_sasl_auth_soft_bounce">smtp_sasl_auth_soft_bounce</a> configuration
8532 1.1 tron parameter. </p>
8533 1.1 tron
8534 1.1 tron <p> Use a per-destination delivery concurrency of 1 (for example,
8535 1.1 tron "<a href="postconf.5.html#smtp_destination_concurrency_limit">smtp_destination_concurrency_limit</a> = 1",
8536 1.1 tron "<a href="postconf.5.html#relay_destination_concurrency_limit">relay_destination_concurrency_limit</a> = 1", etc.), otherwise multiple
8537 1.1 tron delivery agents may experience a login failure at the same time.
8538 1.1 tron </p>
8539 1.1 tron
8540 1.1 tron <p> The table must be accessed via the proxywrite service, i.e. the
8541 1.1 tron map name must start with "<a href="proxymap.8.html">proxy</a>:". The table should be stored under
8542 1.1 tron the directory specified with the <a href="postconf.5.html#data_directory">data_directory</a> parameter. </p>
8543 1.1 tron
8544 1.1 tron <p> This feature uses cryptographic hashing to protect plain-text
8545 1.1 tron passwords, and requires that Postfix is compiled with TLS support.
8546 1.1 tron </p>
8547 1.1 tron
8548 1.1 tron <p> Example: </p>
8549 1.1 tron
8550 1.1 tron <pre>
8551 1.1 tron <a href="postconf.5.html#smtp_sasl_auth_cache_name">smtp_sasl_auth_cache_name</a> = <a href="proxymap.8.html">proxy</a>:btree:/var/lib/postfix/sasl_auth_cache
8552 1.1 tron </pre>
8553 1.1 tron
8554 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
8555 1.1 tron
8556 1.1 tron
8557 1.1 tron </DD>
8558 1.1 tron
8559 1.1 tron <DT><b><a name="smtp_sasl_auth_cache_time">smtp_sasl_auth_cache_time</a>
8560 1.1 tron (default: 90d)</b></DT><DD>
8561 1.1 tron
8562 1.1 tron <p> The maximal age of an <a href="postconf.5.html#smtp_sasl_auth_cache_name">smtp_sasl_auth_cache_name</a> entry before it
8563 1.1 tron is removed. </p>
8564 1.1 tron
8565 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
8566 1.1 tron
8567 1.1 tron
8568 1.1 tron </DD>
8569 1.1 tron
8570 1.1 tron <DT><b><a name="smtp_sasl_auth_enable">smtp_sasl_auth_enable</a>
8571 1.1 tron (default: no)</b></DT><DD>
8572 1.1 tron
8573 1.1 tron <p>
8574 1.1 tron Enable SASL authentication in the Postfix SMTP client. By default,
8575 1.1 tron the Postfix SMTP client uses no authentication.
8576 1.1 tron </p>
8577 1.1 tron
8578 1.1 tron <p>
8579 1.1 tron Example:
8580 1.1 tron </p>
8581 1.1 tron
8582 1.1 tron <pre>
8583 1.1 tron <a href="postconf.5.html#smtp_sasl_auth_enable">smtp_sasl_auth_enable</a> = yes
8584 1.1 tron </pre>
8585 1.1 tron
8586 1.1 tron
8587 1.1 tron </DD>
8588 1.1 tron
8589 1.1 tron <DT><b><a name="smtp_sasl_auth_soft_bounce">smtp_sasl_auth_soft_bounce</a>
8590 1.1 tron (default: yes)</b></DT><DD>
8591 1.1 tron
8592 1.1 tron <p> When a remote SMTP server rejects a SASL authentication request
8593 1.1 tron with a 535 reply code, defer mail delivery instead of returning
8594 1.1 tron mail as undeliverable. The latter behavior was hard-coded prior to
8595 1.1 tron Postfix version 2.5. </p>
8596 1.1 tron
8597 1.1 tron <p> Note: the setting "yes" overrides the global <a href="postconf.5.html#soft_bounce">soft_bounce</a>
8598 1.1 tron parameter, but the setting "no" does not. </p>
8599 1.1 tron
8600 1.1 tron <p> Example: </p>
8601 1.1 tron
8602 1.1 tron <pre>
8603 1.1 tron # Default as of Postfix 2.5
8604 1.1 tron <a href="postconf.5.html#smtp_sasl_auth_soft_bounce">smtp_sasl_auth_soft_bounce</a> = yes
8605 1.1 tron # The old hard-coded default
8606 1.1 tron <a href="postconf.5.html#smtp_sasl_auth_soft_bounce">smtp_sasl_auth_soft_bounce</a> = no
8607 1.1 tron </pre>
8608 1.1 tron
8609 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
8610 1.1 tron
8611 1.1 tron
8612 1.1 tron </DD>
8613 1.1 tron
8614 1.1 tron <DT><b><a name="smtp_sasl_mechanism_filter">smtp_sasl_mechanism_filter</a>
8615 1.1 tron (default: empty)</b></DT><DD>
8616 1.1 tron
8617 1.1 tron <p>
8618 1.1 tron If non-empty, a Postfix SMTP client filter for the remote SMTP
8619 1.1 tron server's list of offered SASL mechanisms. Different client and
8620 1.1 tron server implementations may support different mechanism lists. By
8621 1.1 tron default, the Postfix SMTP client will use the intersection of the
8622 1.1 tron two. <a href="postconf.5.html#smtp_sasl_mechanism_filter">smtp_sasl_mechanism_filter</a> further restricts what server
8623 1.1 tron mechanisms the client will take into consideration. </p>
8624 1.1 tron
8625 1.1 tron <p> Specify mechanism names, "/file/name" patterns or "<a href="DATABASE_README.html">type:table</a>"
8626 1.1 tron lookup tables. The right-hand side result from "<a href="DATABASE_README.html">type:table</a>" lookups
8627 1.1 tron is ignored. Specify "!pattern" to exclude a mechanism name from the
8628 1.1 tron list. The form "!/file/name" is supported only in Postfix version
8629 1.1 tron 2.4 and later. </p>
8630 1.1 tron
8631 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8632 1.1 tron
8633 1.1 tron <p>
8634 1.1 tron Examples:
8635 1.1 tron </p>
8636 1.1 tron
8637 1.1 tron <pre>
8638 1.1 tron <a href="postconf.5.html#smtp_sasl_mechanism_filter">smtp_sasl_mechanism_filter</a> = plain, login
8639 1.1 tron <a href="postconf.5.html#smtp_sasl_mechanism_filter">smtp_sasl_mechanism_filter</a> = /etc/postfix/smtp_mechs
8640 1.1 tron <a href="postconf.5.html#smtp_sasl_mechanism_filter">smtp_sasl_mechanism_filter</a> = !gssapi, !login, static:rest
8641 1.1 tron </pre>
8642 1.1 tron
8643 1.1 tron
8644 1.1 tron </DD>
8645 1.1 tron
8646 1.1 tron <DT><b><a name="smtp_sasl_password_maps">smtp_sasl_password_maps</a>
8647 1.1 tron (default: empty)</b></DT><DD>
8648 1.1 tron
8649 1.1 tron <p>
8650 1.1 tron Optional SMTP client lookup tables with one username:password entry
8651 1.1 tron per remote hostname or domain, or sender address when sender-dependent
8652 1.1 tron authentication is enabled. If no username:password entry is found,
8653 1.1 tron then the Postfix SMTP client will not
8654 1.1 tron attempt to authenticate to the remote host.
8655 1.1 tron </p>
8656 1.1 tron
8657 1.1 tron <p>
8658 1.1 tron The Postfix SMTP client opens the lookup table before going to
8659 1.1 tron chroot jail, so you can leave the password file in /etc/postfix.
8660 1.1 tron </p>
8661 1.1 tron
8662 1.1 tron
8663 1.1 tron </DD>
8664 1.1 tron
8665 1.1 tron <DT><b><a name="smtp_sasl_path">smtp_sasl_path</a>
8666 1.1 tron (default: empty)</b></DT><DD>
8667 1.1 tron
8668 1.1 tron <p> Implementation-specific information that the Postfix SMTP client
8669 1.1 tron passes through to
8670 1.1 tron the SASL plug-in implementation that is selected with
8671 1.1 tron <b><a href="postconf.5.html#smtp_sasl_type">smtp_sasl_type</a></b>. Typically this specifies the name of a
8672 1.1 tron configuration file or rendezvous point. </p>
8673 1.1 tron
8674 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
8675 1.1 tron
8676 1.1 tron
8677 1.1 tron </DD>
8678 1.1 tron
8679 1.1 tron <DT><b><a name="smtp_sasl_security_options">smtp_sasl_security_options</a>
8680 1.1 tron (default: noplaintext, noanonymous)</b></DT><DD>
8681 1.1 tron
8682 1.1 tron <p> Postfix SMTP client SASL security options; as of Postfix 2.3
8683 1.1 tron the list of available
8684 1.1 tron features depends on the SASL client implementation that is selected
8685 1.1 tron with <b><a href="postconf.5.html#smtp_sasl_type">smtp_sasl_type</a></b>. </p>
8686 1.1 tron
8687 1.1 tron <p> The following security features are defined for the <b>cyrus</b>
8688 1.1 tron client SASL implementation: </p>
8689 1.1 tron
8690 1.1 tron <p>
8691 1.1 tron Specify zero or more of the following:
8692 1.1 tron </p>
8693 1.1 tron
8694 1.1 tron <dl>
8695 1.1 tron
8696 1.1 tron <dt><b>noplaintext</b></dt>
8697 1.1 tron
8698 1.1 tron <dd>Disallow methods that use plaintext passwords. </dd>
8699 1.1 tron
8700 1.1 tron <dt><b>noactive</b></dt>
8701 1.1 tron
8702 1.1 tron <dd>Disallow methods subject to active (non-dictionary) attack.
8703 1.1 tron </dd>
8704 1.1 tron
8705 1.1 tron <dt><b>nodictionary</b></dt>
8706 1.1 tron
8707 1.1 tron <dd>Disallow methods subject to passive (dictionary) attack. </dd>
8708 1.1 tron
8709 1.1 tron <dt><b>noanonymous</b></dt>
8710 1.1 tron
8711 1.1 tron <dd>Disallow methods that allow anonymous authentication. </dd>
8712 1.1 tron
8713 1.1 tron <dt><b>mutual_auth</b></dt>
8714 1.1 tron
8715 1.1 tron <dd>Only allow methods that provide mutual authentication (not
8716 1.1 tron available with SASL version 1). </dd>
8717 1.1 tron
8718 1.1 tron </dl>
8719 1.1 tron
8720 1.1 tron <p>
8721 1.1 tron Example:
8722 1.1 tron </p>
8723 1.1 tron
8724 1.1 tron <pre>
8725 1.1 tron <a href="postconf.5.html#smtp_sasl_security_options">smtp_sasl_security_options</a> = noplaintext
8726 1.1 tron </pre>
8727 1.1 tron
8728 1.1 tron
8729 1.1 tron </DD>
8730 1.1 tron
8731 1.1 tron <DT><b><a name="smtp_sasl_tls_security_options">smtp_sasl_tls_security_options</a>
8732 1.1 tron (default: $<a href="postconf.5.html#smtp_sasl_security_options">smtp_sasl_security_options</a>)</b></DT><DD>
8733 1.1 tron
8734 1.1 tron <p> The SASL authentication security options that the Postfix SMTP
8735 1.1 tron client uses for TLS encrypted SMTP sessions. </p>
8736 1.1 tron
8737 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8738 1.1 tron
8739 1.1 tron
8740 1.1 tron </DD>
8741 1.1 tron
8742 1.1 tron <DT><b><a name="smtp_sasl_tls_verified_security_options">smtp_sasl_tls_verified_security_options</a>
8743 1.1 tron (default: $<a href="postconf.5.html#smtp_sasl_tls_security_options">smtp_sasl_tls_security_options</a>)</b></DT><DD>
8744 1.1 tron
8745 1.1 tron <p> The SASL authentication security options that the Postfix SMTP
8746 1.1 tron client uses for TLS encrypted SMTP sessions with a verified server
8747 1.1 tron certificate. </p>
8748 1.1 tron
8749 1.1 tron <p> When mail is sent to the public MX host for the recipient's
8750 1.1 tron domain, server certificates are by default optional, and delivery
8751 1.1 tron proceeds even if certificate verification fails. For delivery via
8752 1.1 tron a submission service that requires SASL authentication, it may be
8753 1.1 tron appropriate to send plaintext passwords only when the connection
8754 1.1 tron to the server is strongly encrypted <b>and</b> the server identity
8755 1.1 tron is verified. </p>
8756 1.1 tron
8757 1.1 tron <p> The <a href="postconf.5.html#smtp_sasl_tls_verified_security_options">smtp_sasl_tls_verified_security_options</a> parameter makes it
8758 1.1 tron possible to only enable plaintext mechanisms when a secure connection
8759 1.1 tron to the server is available. Submission servers subject to this
8760 1.1 tron policy must either have verifiable certificates or offer suitable
8761 1.1 tron non-plaintext SASL mechanisms. </p>
8762 1.1 tron
8763 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
8764 1.1 tron
8765 1.1 tron
8766 1.1 tron </DD>
8767 1.1 tron
8768 1.1 tron <DT><b><a name="smtp_sasl_type">smtp_sasl_type</a>
8769 1.1 tron (default: cyrus)</b></DT><DD>
8770 1.1 tron
8771 1.1 tron <p> The SASL plug-in type that the Postfix SMTP client should use
8772 1.1 tron for authentication. The available types are listed with the
8773 1.1 tron "<b>postconf -A</b>" command. </p>
8774 1.1 tron
8775 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
8776 1.1 tron
8777 1.1 tron
8778 1.1 tron </DD>
8779 1.1 tron
8780 1.1 tron <DT><b><a name="smtp_send_xforward_command">smtp_send_xforward_command</a>
8781 1.1 tron (default: no)</b></DT><DD>
8782 1.1 tron
8783 1.1 tron <p>
8784 1.1 tron Send the non-standard XFORWARD command when the Postfix SMTP server
8785 1.1 tron EHLO response announces XFORWARD support.
8786 1.1 tron </p>
8787 1.1 tron
8788 1.1 tron <p>
8789 1.1 tron This allows an "smtp" delivery agent, used for injecting mail into
8790 1.1 tron a content filter, to forward the name, address, protocol and HELO
8791 1.1 tron name of the original client to the content filter and downstream
8792 1.1 tron queuing SMTP server. This can produce more useful logging than
8793 1.1 tron localhost[127.0.0.1] etc.
8794 1.1 tron </p>
8795 1.1 tron
8796 1.1 tron <p>
8797 1.1 tron This feature is available in Postfix 2.1 and later.
8798 1.1 tron </p>
8799 1.1 tron
8800 1.1 tron
8801 1.1 tron </DD>
8802 1.1 tron
8803 1.1 tron <DT><b><a name="smtp_sender_dependent_authentication">smtp_sender_dependent_authentication</a>
8804 1.1 tron (default: no)</b></DT><DD>
8805 1.1 tron
8806 1.1 tron <p>
8807 1.1 tron Enable sender-dependent authentication in the Postfix SMTP client; this is
8808 1.1 tron available only with SASL authentication, and disables SMTP connection
8809 1.1 tron caching to ensure that mail from different senders will use the
8810 1.1 tron appropriate credentials. </p>
8811 1.1 tron
8812 1.1 tron <p>
8813 1.1 tron This feature is available in Postfix 2.3 and later.
8814 1.1 tron </p>
8815 1.1 tron
8816 1.1 tron
8817 1.1 tron </DD>
8818 1.1 tron
8819 1.1 tron <DT><b><a name="smtp_skip_4xx_greeting">smtp_skip_4xx_greeting</a>
8820 1.1 tron (default: yes)</b></DT><DD>
8821 1.1 tron
8822 1.1 tron <p>
8823 1.1 tron Skip SMTP servers that greet with a 4XX status code (go away, try
8824 1.1 tron again later).
8825 1.1 tron </p>
8826 1.1 tron
8827 1.1 tron <p>
8828 1.1 tron By default, Postfix moves on the next mail exchanger. Specify
8829 1.1 tron "<a href="postconf.5.html#smtp_skip_4xx_greeting">smtp_skip_4xx_greeting</a> = no" if Postfix should defer delivery
8830 1.1 tron immediately.
8831 1.1 tron </p>
8832 1.1 tron
8833 1.1 tron <p> This feature is available in Postfix 2.0 and earlier.
8834 1.1 tron Later Postfix versions always skip SMTP servers that greet with a
8835 1.1 tron 4XX status code. </p>
8836 1.1 tron
8837 1.1 tron
8838 1.1 tron </DD>
8839 1.1 tron
8840 1.1 tron <DT><b><a name="smtp_skip_5xx_greeting">smtp_skip_5xx_greeting</a>
8841 1.1 tron (default: yes)</b></DT><DD>
8842 1.1 tron
8843 1.1 tron <p>
8844 1.1 tron Skip SMTP servers that greet with a 5XX status code (go away, do
8845 1.1 tron not try again later).
8846 1.1 tron </p>
8847 1.1 tron
8848 1.1 tron <p> By default, the Postfix SMTP client moves on the next mail
8849 1.1 tron exchanger. Specify "<a href="postconf.5.html#smtp_skip_5xx_greeting">smtp_skip_5xx_greeting</a> = no" if Postfix should
8850 1.1 tron bounce the mail immediately. The default setting is incorrect, but
8851 1.1 tron it is what a lot of people expect to happen. </p>
8852 1.1 tron
8853 1.1 tron
8854 1.1 tron </DD>
8855 1.1 tron
8856 1.1 tron <DT><b><a name="smtp_skip_quit_response">smtp_skip_quit_response</a>
8857 1.1 tron (default: yes)</b></DT><DD>
8858 1.1 tron
8859 1.1 tron <p>
8860 1.1 tron Do not wait for the response to the SMTP QUIT command.
8861 1.1 tron </p>
8862 1.1 tron
8863 1.1 tron
8864 1.1 tron </DD>
8865 1.1 tron
8866 1.1 tron <DT><b><a name="smtp_starttls_timeout">smtp_starttls_timeout</a>
8867 1.1 tron (default: 300s)</b></DT><DD>
8868 1.1 tron
8869 1.1 tron <p> Time limit for Postfix SMTP client write and read operations
8870 1.1 tron during TLS startup and shutdown handshake procedures. </p>
8871 1.1 tron
8872 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8873 1.1 tron
8874 1.1 tron
8875 1.1 tron </DD>
8876 1.1 tron
8877 1.1 tron <DT><b><a name="smtp_tls_CAfile">smtp_tls_CAfile</a>
8878 1.1 tron (default: empty)</b></DT><DD>
8879 1.1 tron
8880 1.1 tron <p> A file containing CA certificates of root CAs trusted to sign
8881 1.1 tron either remote SMTP server certificates or intermediate CA certificates.
8882 1.1 tron These are loaded into memory before the <a href="smtp.8.html">smtp(8)</a> client enters the
8883 1.1 tron chroot jail. If the number of trusted roots is large, consider using
8884 1.1 tron <a href="postconf.5.html#smtp_tls_CApath">smtp_tls_CApath</a> instead, but note that the latter directory must be
8885 1.1 tron present in the chroot jail if the <a href="smtp.8.html">smtp(8)</a> client is chrooted. This
8886 1.1 tron file may also be used to augment the client certificate trust chain,
8887 1.1 tron but it is best to include all the required certificates directly in
8888 1.1 tron $<a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a>. </p>
8889 1.1 tron
8890 1.1 tron <p> Example: </p>
8891 1.1 tron
8892 1.1 tron <pre>
8893 1.1 tron <a href="postconf.5.html#smtp_tls_CAfile">smtp_tls_CAfile</a> = /etc/postfix/CAcert.pem
8894 1.1 tron </pre>
8895 1.1 tron
8896 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8897 1.1 tron
8898 1.1 tron
8899 1.1 tron </DD>
8900 1.1 tron
8901 1.1 tron <DT><b><a name="smtp_tls_CApath">smtp_tls_CApath</a>
8902 1.1 tron (default: empty)</b></DT><DD>
8903 1.1 tron
8904 1.1 tron <p> Directory with PEM format certificate authority certificates
8905 1.1 tron that the Postfix SMTP client uses to verify a remote SMTP server
8906 1.1 tron certificate. Don't forget to create the necessary "hash" links
8907 1.1 tron with, for example, "$OPENSSL_HOME/bin/c_rehash /etc/postfix/certs".
8908 1.1 tron </p>
8909 1.1 tron
8910 1.1 tron <p> To use this option in chroot mode, this directory (or a copy)
8911 1.1 tron must be inside the chroot jail. </p>
8912 1.1 tron
8913 1.1 tron <p> Example: </p>
8914 1.1 tron
8915 1.1 tron <pre>
8916 1.1 tron <a href="postconf.5.html#smtp_tls_CApath">smtp_tls_CApath</a> = /etc/postfix/certs
8917 1.1 tron </pre>
8918 1.1 tron
8919 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8920 1.1 tron
8921 1.1 tron
8922 1.1 tron </DD>
8923 1.1 tron
8924 1.1 tron <DT><b><a name="smtp_tls_cert_file">smtp_tls_cert_file</a>
8925 1.1 tron (default: empty)</b></DT><DD>
8926 1.1 tron
8927 1.1 tron <p> File with the Postfix SMTP client RSA certificate in PEM format.
8928 1.1 tron This file may also contain the Postfix SMTP client private RSA key,
8929 1.1 tron and these may be the same as the Postfix SMTP server RSA certificate and key
8930 1.1 tron file. </p>
8931 1.1 tron
8932 1.1 tron <p> Do not configure client certificates unless you <b>must</b> present
8933 1.1 tron client TLS certificates to one or more servers. Client certificates are
8934 1.1 tron not usually needed, and can cause problems in configurations that work
8935 1.1 tron well without them. The recommended setting is to let the defaults stand: </p>
8936 1.1 tron
8937 1.1 tron <blockquote>
8938 1.1 tron <pre>
8939 1.1 tron <a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a> =
8940 1.1 tron <a href="postconf.5.html#smtp_tls_key_file">smtp_tls_key_file</a> =
8941 1.1 tron <a href="postconf.5.html#smtp_tls_dcert_file">smtp_tls_dcert_file</a> =
8942 1.1 tron <a href="postconf.5.html#smtp_tls_dkey_file">smtp_tls_dkey_file</a> =
8943 1.1 tron <a href="postconf.5.html#smtp_tls_eccert_file">smtp_tls_eccert_file</a> =
8944 1.1 tron <a href="postconf.5.html#smtp_tls_eckey_file">smtp_tls_eckey_file</a> =
8945 1.1 tron </pre>
8946 1.1 tron </blockquote>
8947 1.1 tron
8948 1.1 tron <p> The best way to use the default settings is to comment out the above
8949 1.1 tron parameters in <a href="postconf.5.html">main.cf</a> if present. </p>
8950 1.1 tron
8951 1.1 tron <p> To enable remote SMTP servers to verify the Postfix SMTP client
8952 1.1 tron certificate, the issuing CA certificates must be made available to the
8953 1.1 tron server. You should include the required certificates in the client
8954 1.1 tron certificate file, the client certificate first, then the issuing
8955 1.1 tron CA(s) (bottom-up order). </p>
8956 1.1 tron
8957 1.1 tron <p> Example: the certificate for "client.example.com" was issued by
8958 1.1 tron "intermediate CA" which itself has a certificate issued by "root CA".
8959 1.1 tron Create the client.pem file with "cat client_cert.pem intermediate_CA.pem
8960 1.1 tron root_CA.pem > client.pem". </p>
8961 1.1 tron
8962 1.1 tron <p> If you also want to verify remote SMTP server certificates issued by
8963 1.1 tron these CAs, you can add the CA certificates to the <a href="postconf.5.html#smtp_tls_CAfile">smtp_tls_CAfile</a>, in
8964 1.1 tron which case it is not necessary to have them in the <a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a>,
8965 1.1 tron <a href="postconf.5.html#smtp_tls_dcert_file">smtp_tls_dcert_file</a> or <a href="postconf.5.html#smtp_tls_eccert_file">smtp_tls_eccert_file</a>. </p>
8966 1.1 tron
8967 1.1 tron <p> A certificate supplied here must be usable as an SSL client certificate
8968 1.1 tron and hence pass the "openssl verify -purpose sslclient ..." test. </p>
8969 1.1 tron
8970 1.1 tron <p> Example: </p>
8971 1.1 tron
8972 1.1 tron <pre>
8973 1.1 tron <a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a> = /etc/postfix/client.pem
8974 1.1 tron </pre>
8975 1.1 tron
8976 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
8977 1.1 tron
8978 1.1 tron
8979 1.1 tron </DD>
8980 1.1 tron
8981 1.1 tron <DT><b><a name="smtp_tls_cipherlist">smtp_tls_cipherlist</a>
8982 1.1 tron (default: empty)</b></DT><DD>
8983 1.1 tron
8984 1.1 tron <p> Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS
8985 1.1 tron cipher list. As this feature applies to all TLS security levels, it is easy
8986 1.1 tron to create inter-operability problems by choosing a non-default cipher
8987 1.1 tron list. Do not use a non-default TLS cipher list on hosts that deliver email
8988 1.1 tron to the public Internet: you will be unable to send email to servers that
8989 1.1 tron only support the ciphers you exclude. Using a restricted cipher list
8990 1.1 tron may be more appropriate for an internal MTA, where one can exert some
8991 1.1 tron control over the TLS software and settings of the peer servers. </p>
8992 1.1 tron
8993 1.1 tron <p> <b>Note:</b> do not use "" quotes around the parameter value. </p>
8994 1.1 tron
8995 1.1 tron <p> This feature is available in Postfix version 2.2. It is not used with
8996 1.1 tron Postfix 2.3 and later; use <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> instead. </p>
8997 1.1 tron
8998 1.1 tron
8999 1.1 tron </DD>
9000 1.1 tron
9001 1.1 tron <DT><b><a name="smtp_tls_ciphers">smtp_tls_ciphers</a>
9002 1.1 tron (default: export)</b></DT><DD>
9003 1.1 tron
9004 1.1 tron <p> The minimum TLS cipher grade that the Postfix SMTP client
9005 1.1 tron will use with opportunistic TLS encryption. Cipher types listed in
9006 1.1 tron <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a> are excluded from the base definition of
9007 1.1 tron the selected cipher grade. The default value "export" ensures maximum
9008 1.1 tron inter-operability. Because encryption is optional, stronger controls
9009 1.1 tron are not appropriate, and this setting SHOULD NOT be changed unless the
9010 1.1 tron change is essential. </p>
9011 1.1 tron
9012 1.1 tron <p> When TLS is mandatory the cipher grade is chosen via the
9013 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> configuration parameter, see there for syntax
9014 1.1 tron details. See <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> for information on how to configure
9015 1.1 tron ciphers on a per-destination basis. </p>
9016 1.1 tron
9017 1.1 tron <p> Example: </p>
9018 1.1 tron <pre>
9019 1.1 tron <a href="postconf.5.html#smtp_tls_ciphers">smtp_tls_ciphers</a> = export
9020 1.1 tron </pre>
9021 1.1 tron
9022 1.1 tron <p> This feature is available in Postfix 2.6 and later. With earlier Postfix
9023 1.1 tron releases only the <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> parameter is implemented,
9024 1.1 tron and opportunistic TLS always uses "export" or better (i.e. all) ciphers. </p>
9025 1.1 tron
9026 1.1 tron
9027 1.1 tron </DD>
9028 1.1 tron
9029 1.1 tron <DT><b><a name="smtp_tls_dcert_file">smtp_tls_dcert_file</a>
9030 1.1 tron (default: empty)</b></DT><DD>
9031 1.1 tron
9032 1.1 tron <p> File with the Postfix SMTP client DSA certificate in PEM format.
9033 1.1 tron This file may also contain the Postfix SMTP client private DSA key. </p>
9034 1.1 tron
9035 1.1 tron <p> See the discussion under <a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a> for more details.
9036 1.1 tron </p>
9037 1.1 tron
9038 1.1 tron <p> Example: </p>
9039 1.1 tron
9040 1.1 tron <pre>
9041 1.1 tron <a href="postconf.5.html#smtp_tls_dcert_file">smtp_tls_dcert_file</a> = /etc/postfix/client-dsa.pem
9042 1.1 tron </pre>
9043 1.1 tron
9044 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9045 1.1 tron
9046 1.1 tron
9047 1.1 tron </DD>
9048 1.1 tron
9049 1.1 tron <DT><b><a name="smtp_tls_dkey_file">smtp_tls_dkey_file</a>
9050 1.1 tron (default: $<a href="postconf.5.html#smtp_tls_dcert_file">smtp_tls_dcert_file</a>)</b></DT><DD>
9051 1.1 tron
9052 1.1 tron <p> File with the Postfix SMTP client DSA private key in PEM format.
9053 1.1 tron This file may be combined with the Postfix SMTP client DSA certificate
9054 1.1 tron file specified with $<a href="postconf.5.html#smtp_tls_dcert_file">smtp_tls_dcert_file</a>. </p>
9055 1.1 tron
9056 1.1 tron <p> The private key must be accessible without a pass-phrase, i.e. it
9057 1.1 tron must not be encrypted. File permissions should grant read-only
9058 1.1 tron access to the system superuser account ("root"), and no access
9059 1.1 tron to anyone else. </p>
9060 1.1 tron
9061 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9062 1.1 tron
9063 1.1 tron
9064 1.1 tron </DD>
9065 1.1 tron
9066 1.1 tron <DT><b><a name="smtp_tls_eccert_file">smtp_tls_eccert_file</a>
9067 1.1 tron (default: empty)</b></DT><DD>
9068 1.1 tron
9069 1.1 tron <p> File with the Postfix SMTP client ECDSA certificate in PEM format.
9070 1.1 tron This file may also contain the Postfix SMTP client ECDSA private key. </p>
9071 1.1 tron
9072 1.1 tron <p> See the discussion under <a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a> for more details.
9073 1.1 tron </p>
9074 1.1 tron
9075 1.1 tron <p> Example: </p>
9076 1.1 tron
9077 1.1 tron <pre>
9078 1.1 tron <a href="postconf.5.html#smtp_tls_eccert_file">smtp_tls_eccert_file</a> = /etc/postfix/ecdsa-ccert.pem
9079 1.1 tron </pre>
9080 1.1 tron
9081 1.1 tron <p> This feature is available in Postfix 2.6 and later, when Postfix is
9082 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
9083 1.1 tron
9084 1.1 tron
9085 1.1 tron </DD>
9086 1.1 tron
9087 1.1 tron <DT><b><a name="smtp_tls_eckey_file">smtp_tls_eckey_file</a>
9088 1.1 tron (default: $<a href="postconf.5.html#smtp_tls_eccert_file">smtp_tls_eccert_file</a>)</b></DT><DD>
9089 1.1 tron
9090 1.1 tron <p> File with the Postfix SMTP client ECDSA private key in PEM format.
9091 1.1 tron This file may be combined with the Postfix SMTP client ECDSA
9092 1.1 tron certificate file specified with $<a href="postconf.5.html#smtp_tls_eccert_file">smtp_tls_eccert_file</a>. </p>
9093 1.1 tron
9094 1.1 tron <p> The private key must be accessible without a pass-phrase, i.e. it
9095 1.1 tron must not be encrypted. File permissions should grant read-only
9096 1.1 tron access to the system superuser account ("root"), and no access
9097 1.1 tron to anyone else. </p>
9098 1.1 tron
9099 1.1 tron <p> This feature is available in Postfix 2.6 and later, when Postfix is
9100 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
9101 1.1 tron
9102 1.1 tron
9103 1.1 tron </DD>
9104 1.1 tron
9105 1.1 tron <DT><b><a name="smtp_tls_enforce_peername">smtp_tls_enforce_peername</a>
9106 1.1 tron (default: yes)</b></DT><DD>
9107 1.1 tron
9108 1.1 tron <p> With mandatory TLS encryption, require that the remote SMTP
9109 1.1 tron server hostname matches the information in the remote SMTP server
9110 1.1 tron certificate. As of <a href="http://tools.ietf.org/html/rfc2487">RFC 2487</a> the requirements for hostname checking
9111 1.1 tron for MTA clients are not specified. </p>
9112 1.1 tron
9113 1.1 tron <p> This option can be set to "no" to disable strict peer name
9114 1.1 tron checking. This setting has no effect on sessions that are controlled
9115 1.1 tron via the <a href="postconf.5.html#smtp_tls_per_site">smtp_tls_per_site</a> table. </p>
9116 1.1 tron
9117 1.1 tron <p> Disabling the hostname verification can make sense in closed
9118 1.1 tron environment where special CAs are created. If not used carefully,
9119 1.1 tron this option opens the danger of a "man-in-the-middle" attack (the
9120 1.1 tron CommonName of this attacker will be logged). </p>
9121 1.1 tron
9122 1.1 tron <p> This feature is available in Postfix 2.2 and later. With
9123 1.1 tron Postfix 2.3 and later use <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> instead. </p>
9124 1.1 tron
9125 1.1 tron
9126 1.1 tron </DD>
9127 1.1 tron
9128 1.1 tron <DT><b><a name="smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a>
9129 1.1 tron (default: empty)</b></DT><DD>
9130 1.1 tron
9131 1.1 tron <p> List of ciphers or cipher types to exclude from the Postfix
9132 1.1 tron SMTP client cipher
9133 1.1 tron list at all TLS security levels. This is not an OpenSSL cipherlist, it is
9134 1.1 tron a simple list separated by whitespace and/or commas. The elements are a
9135 1.1 tron single cipher, or one or more "+" separated cipher properties, in which
9136 1.1 tron case only ciphers matching <b>all</b> the properties are excluded. </p>
9137 1.1 tron
9138 1.1 tron <p> Examples (some of these will cause problems): </p>
9139 1.1 tron
9140 1.1 tron <blockquote>
9141 1.1 tron <pre>
9142 1.1 tron <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a> = aNULL
9143 1.1 tron <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a> = MD5, DES
9144 1.1 tron <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a> = DES+MD5
9145 1.1 tron <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a> = AES256-SHA, DES-CBC3-MD5
9146 1.1 tron <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a> = kEDH+aRSA
9147 1.1 tron </pre>
9148 1.1 tron </blockquote>
9149 1.1 tron
9150 1.1 tron <p> The first setting, disables anonymous ciphers. The next setting
9151 1.1 tron disables ciphers that use the MD5 digest algorithm or the (single) DES
9152 1.1 tron encryption algorithm. The next setting disables ciphers that use MD5 and
9153 1.1 tron DES together. The next setting disables the two ciphers "AES256-SHA"
9154 1.1 tron and "DES-CBC3-MD5". The last setting disables ciphers that use "EDH"
9155 1.1 tron key exchange with RSA authentication. </p>
9156 1.1 tron
9157 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
9158 1.1 tron
9159 1.1 tron
9160 1.1 tron </DD>
9161 1.1 tron
9162 1.1 tron <DT><b><a name="smtp_tls_fingerprint_cert_match">smtp_tls_fingerprint_cert_match</a>
9163 1.1 tron (default: empty)</b></DT><DD>
9164 1.1 tron
9165 1.1 tron <p> List of acceptable remote SMTP server certificate fingerprints
9166 1.1 tron for the "fingerprint" TLS security level (<b><a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a></b> =
9167 1.1 tron fingerprint). At this security level, certificate authorities are
9168 1.1 tron not used, and certificate expiration times are ignored. Instead,
9169 1.1 tron server certificates are verified directly via their "fingerprint". The
9170 1.1 tron fingerprint is a message digest of the server certificate. The digest
9171 1.1 tron algorithm is selected via the <b><a href="postconf.5.html#smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a></b>
9172 1.1 tron parameter. </p>
9173 1.1 tron
9174 1.1 tron <p> When an <b><a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a></b> table entry specifies the
9175 1.1 tron "fingerprint" security level, any "match" attributes in that entry specify
9176 1.1 tron the list of valid fingerprints for the corresponding destination. Multiple
9177 1.1 tron fingerprints can be combined with a "|" delimiter in a single match
9178 1.1 tron attribute, or multiple match attributes can be employed. </p>
9179 1.1 tron
9180 1.1 tron <p> Example: Certificate fingerprint verification with internal mailhub.
9181 1.1 tron Two matching fingerprints are listed. The <a href="postconf.5.html#relayhost">relayhost</a> may be multiple
9182 1.1 tron physical hosts behind a load-balancer, each with its own private/public
9183 1.1 tron key and self-signed certificate. Alternatively, a single <a href="postconf.5.html#relayhost">relayhost</a> may
9184 1.1 tron be in the process of switching from one set of private/public keys to
9185 1.1 tron another, and both keys are trusted just prior to the transition. </p>
9186 1.1 tron
9187 1.1 tron <blockquote>
9188 1.1 tron <pre>
9189 1.1 tron <a href="postconf.5.html#relayhost">relayhost</a> = [mailhub.example.com]
9190 1.1 tron <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> = fingerprint
9191 1.1 tron <a href="postconf.5.html#smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a> = md5
9192 1.1 tron <a href="postconf.5.html#smtp_tls_fingerprint_cert_match">smtp_tls_fingerprint_cert_match</a> =
9193 1.1 tron 3D:95:34:51:24:66:33:B9:D2:40:99:C0:C1:17:0B:D1
9194 1.1 tron EC:3B:2D:B0:5B:B1:FB:6D:20:A3:9D:72:F6:8D:12:35
9195 1.1 tron </pre>
9196 1.1 tron </blockquote>
9197 1.1 tron
9198 1.1 tron <p> Example: Certificate fingerprint verification with selected destinations.
9199 1.1 tron As in the example above, we show two matching fingerprints: </p>
9200 1.1 tron
9201 1.1 tron <blockquote>
9202 1.1 tron <pre>
9203 1.1 tron /etc/postfix/<a href="postconf.5.html">main.cf</a>:
9204 1.1 tron <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> = hash:/etc/postfix/tls_policy
9205 1.1 tron <a href="postconf.5.html#smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a> = md5
9206 1.1 tron </pre>
9207 1.1 tron </blockquote>
9208 1.1 tron
9209 1.1 tron <blockquote>
9210 1.1 tron <pre>
9211 1.1 tron /etc/postfix/tls_policy:
9212 1.1 tron example.com fingerprint
9213 1.1 tron match=3D:95:34:51:24:66:33:B9:D2:40:99:C0:C1:17:0B:D1
9214 1.1 tron match=EC:3B:2D:B0:5B:B1:FB:6D:20:A3:9D:72:F6:8D:12:35
9215 1.1 tron </pre>
9216 1.1 tron </blockquote>
9217 1.1 tron
9218 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
9219 1.1 tron
9220 1.1 tron
9221 1.1 tron </DD>
9222 1.1 tron
9223 1.1 tron <DT><b><a name="smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a>
9224 1.1 tron (default: md5)</b></DT><DD>
9225 1.1 tron
9226 1.1 tron <p> The message digest algorithm used to construct remote SMTP server
9227 1.1 tron certificate fingerprints. At the "fingerprint" TLS security level
9228 1.1 tron (<b><a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a></b> = fingerprint), the server certificate is
9229 1.1 tron verified by directly matching its <i>fingerprint</i>. The fingerprint
9230 1.1 tron is the message digest of the server certificate using the selected
9231 1.1 tron algorithm. With a digest algorithm resistant to "second pre-image"
9232 1.1 tron attacks, it is not feasible to create a new public key and a matching
9233 1.1 tron certificate that has the same fingerprint. </p>
9234 1.1 tron
9235 1.1 tron <p> The default algorithm is <b>md5</b>; this is consistent with
9236 1.1 tron the backwards compatible setting of the digest used to verify client
9237 1.1 tron certificates in the SMTP server. </p>
9238 1.1 tron
9239 1.1 tron <p> The best practice algorithm is now <b>sha1</b>. Recent advances in hash
9240 1.1 tron function cryptanalysis have led to md5 being deprecated in favor of sha1.
9241 1.1 tron However, as long as there are no known "second pre-image" attacks
9242 1.1 tron against md5, its use in this context can still be considered safe.
9243 1.1 tron </p>
9244 1.1 tron
9245 1.1 tron <p> While additional digest algorithms are often available with OpenSSL's
9246 1.1 tron libcrypto, only those used by libssl in SSL cipher suites are available to
9247 1.1 tron Postfix. For now this means just md5 or sha1. </p>
9248 1.1 tron
9249 1.1 tron <p> To find the fingerprint of a specific certificate file, with a
9250 1.1 tron specific digest algorithm, run:
9251 1.1 tron </p>
9252 1.1 tron
9253 1.1 tron <blockquote>
9254 1.1 tron <pre>
9255 1.1 tron $ openssl x509 -noout -fingerprint -<i>digest</i> -in <i>certfile</i>.pem
9256 1.1 tron </pre>
9257 1.1 tron </blockquote>
9258 1.1 tron
9259 1.1 tron <p> The text to the right of "=" sign is the desired fingerprint.
9260 1.1 tron For example: </p>
9261 1.1 tron
9262 1.1 tron <blockquote>
9263 1.1 tron <pre>
9264 1.1 tron $ openssl x509 -noout -fingerprint -sha1 -in cert.pem
9265 1.1 tron SHA1 Fingerprint=D4:6A:AB:19:24:79:F8:32:BB:A6:CB:66:82:C0:8E:9B:EE:29:A8:1A
9266 1.1 tron </pre>
9267 1.1 tron </blockquote>
9268 1.1 tron
9269 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
9270 1.1 tron
9271 1.1 tron
9272 1.1 tron </DD>
9273 1.1 tron
9274 1.1 tron <DT><b><a name="smtp_tls_key_file">smtp_tls_key_file</a>
9275 1.1 tron (default: $<a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a>)</b></DT><DD>
9276 1.1 tron
9277 1.1 tron <p> File with the Postfix SMTP client RSA private key in PEM format.
9278 1.1 tron This file may be combined with the Postfix SMTP client RSA certificate
9279 1.1 tron file specified with $<a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a>. </p>
9280 1.1 tron
9281 1.1 tron <p> The private key must be accessible without a pass-phrase, i.e. it
9282 1.1 tron must not be encrypted. File permissions should grant read-only
9283 1.1 tron access to the system superuser account ("root"), and no access
9284 1.1 tron to anyone else. </p>
9285 1.1 tron
9286 1.1 tron <p> Example: </p>
9287 1.1 tron
9288 1.1 tron <pre>
9289 1.1 tron <a href="postconf.5.html#smtp_tls_key_file">smtp_tls_key_file</a> = $<a href="postconf.5.html#smtp_tls_cert_file">smtp_tls_cert_file</a>
9290 1.1 tron </pre>
9291 1.1 tron
9292 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9293 1.1 tron
9294 1.1 tron
9295 1.1 tron </DD>
9296 1.1 tron
9297 1.1 tron <DT><b><a name="smtp_tls_loglevel">smtp_tls_loglevel</a>
9298 1.1 tron (default: 0)</b></DT><DD>
9299 1.1 tron
9300 1.1 tron <p> Enable additional Postfix SMTP client logging of TLS activity.
9301 1.1 tron Each logging level also includes the information that is logged at
9302 1.1 tron a lower logging level. </p>
9303 1.1 tron
9304 1.1 tron <dl compact>
9305 1.1 tron
9306 1.1 tron <dt> </dt> <dd> 0 Disable logging of TLS activity. </dd>
9307 1.1 tron
9308 1.1 tron <dt> </dt> <dd> 1 Log TLS handshake and certificate information. </dd>
9309 1.1 tron
9310 1.1 tron <dt> </dt> <dd> 2 Log levels during TLS negotiation. </dd>
9311 1.1 tron
9312 1.1 tron <dt> </dt> <dd> 3 Log hexadecimal and ASCII dump of TLS negotiation
9313 1.1 tron process. </dd>
9314 1.1 tron
9315 1.1 tron <dt> </dt> <dd> 4 Log hexadecimal and ASCII dump of complete
9316 1.1 tron transmission after STARTTLS. </dd>
9317 1.1 tron
9318 1.1 tron </dl>
9319 1.1 tron
9320 1.1 tron <p> Use "<a href="postconf.5.html#smtp_tls_loglevel">smtp_tls_loglevel</a> = 3" only in case of problems. Use of
9321 1.1 tron loglevel 4 is strongly discouraged. </p>
9322 1.1 tron
9323 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9324 1.1 tron
9325 1.1 tron
9326 1.1 tron </DD>
9327 1.1 tron
9328 1.1 tron <DT><b><a name="smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a>
9329 1.1 tron (default: medium)</b></DT><DD>
9330 1.1 tron
9331 1.1 tron <p> The minimum TLS cipher grade that the Postfix SMTP client will
9332 1.1 tron use with
9333 1.1 tron mandatory TLS encryption. The default value "medium" is suitable
9334 1.1 tron for most destinations with which you may want to enforce TLS, and
9335 1.1 tron is beyond the reach of today's crypt-analytic methods. See
9336 1.1 tron <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> for information on how to configure ciphers
9337 1.1 tron on a per-destination basis. </p>
9338 1.1 tron
9339 1.1 tron <p> The following cipher grades are supported: </p>
9340 1.1 tron
9341 1.1 tron <dl>
9342 1.1 tron <dt><b>export</b></dt>
9343 1.1 tron <dd> Enable the mainstream "EXPORT" grade or better OpenSSL
9344 1.1 tron ciphers. This is always used for opportunistic encryption. It is
9345 1.1 tron not recommended for mandatory encryption unless you must enforce TLS
9346 1.1 tron with "crippled" peers. The underlying cipherlist is specified via the
9347 1.1 tron <a href="postconf.5.html#tls_export_cipherlist">tls_export_cipherlist</a> configuration parameter, which you are strongly
9348 1.1 tron encouraged to not change. The default value of <a href="postconf.5.html#tls_export_cipherlist">tls_export_cipherlist</a>
9349 1.1 tron includes anonymous ciphers, but these are automatically filtered out if
9350 1.1 tron the client is configured to verify server certificates. If you must
9351 1.1 tron exclude anonymous ciphers also at the "encrypt" security level, set
9352 1.1 tron "<a href="postconf.5.html#smtp_tls_mandatory_exclude_ciphers">smtp_tls_mandatory_exclude_ciphers</a> = aNULL". </dd>
9353 1.1 tron
9354 1.1 tron <dt><b>low</b></dt>
9355 1.1 tron <dd> Enable the mainstream "LOW" grade or better OpenSSL ciphers. This
9356 1.1 tron setting is only appropriate for internal mail servers. The underlying
9357 1.1 tron cipherlist is specified via the <a href="postconf.5.html#tls_low_cipherlist">tls_low_cipherlist</a> configuration
9358 1.1 tron parameter, which you are strongly encouraged to not change. The default
9359 1.1 tron value of <a href="postconf.5.html#tls_low_cipherlist">tls_low_cipherlist</a> includes anonymous ciphers, but these are
9360 1.1 tron automatically filtered out if the client is configured to verify server
9361 1.1 tron certificates. If you must exclude anonymous ciphers also at the "encrypt"
9362 1.1 tron security level, set "<a href="postconf.5.html#smtp_tls_mandatory_exclude_ciphers">smtp_tls_mandatory_exclude_ciphers</a> = aNULL". </dd>
9363 1.1 tron
9364 1.1 tron <dt><b>medium</b></dt>
9365 1.1 tron <dd> Enable the mainstream "MEDIUM" grade or better OpenSSL ciphers.
9366 1.1 tron The underlying cipherlist is specified via the <a href="postconf.5.html#tls_medium_cipherlist">tls_medium_cipherlist</a>
9367 1.1 tron configuration parameter, which you are strongly encouraged to not change.
9368 1.1 tron The default value of <a href="postconf.5.html#tls_medium_cipherlist">tls_medium_cipherlist</a> includes anonymous ciphers,
9369 1.1 tron but these are automatically filtered out if the client is configured to
9370 1.1 tron verify server certificates. If you must exclude anonymous ciphers also
9371 1.1 tron at the "encrypt" security level, set "<a href="postconf.5.html#smtp_tls_mandatory_exclude_ciphers">smtp_tls_mandatory_exclude_ciphers</a>
9372 1.1 tron = aNULL". </dd>
9373 1.1 tron
9374 1.1 tron <dt><b>high</b></dt>
9375 1.1 tron <dd> Enable only the mainstream "HIGH" grade OpenSSL ciphers. This
9376 1.1 tron setting is appropriate when all mandatory TLS destinations support
9377 1.1 tron some of "HIGH" grade ciphers, this is not uncommon. The underlying
9378 1.1 tron cipherlist is specified via the <a href="postconf.5.html#tls_high_cipherlist">tls_high_cipherlist</a> configuration
9379 1.1 tron parameter, which you are strongly encouraged to not change. The default
9380 1.1 tron value of <a href="postconf.5.html#tls_high_cipherlist">tls_high_cipherlist</a> includes anonymous ciphers, but these are
9381 1.1 tron automatically filtered out if the client is configured to verify server
9382 1.1 tron certificates. If you must exclude anonymous ciphers also at the "encrypt"
9383 1.1 tron security level, set "<a href="postconf.5.html#smtp_tls_mandatory_exclude_ciphers">smtp_tls_mandatory_exclude_ciphers</a> = aNULL". </dd>
9384 1.1 tron
9385 1.1 tron <dt><b>null</b></dt>
9386 1.1 tron <dd> Enable only the "NULL" OpenSSL ciphers, these provide authentication
9387 1.1 tron without encryption. This setting is only appropriate in the rare case
9388 1.1 tron that all servers are prepared to use NULL ciphers (not normally enabled
9389 1.1 tron in TLS servers). A plausible use-case is an LMTP server listening on a
9390 1.1 tron UNIX-domain socket that is configured to support "NULL" ciphers. The
9391 1.1 tron underlying cipherlist is specified via the <a href="postconf.5.html#tls_null_cipherlist">tls_null_cipherlist</a>
9392 1.1 tron configuration parameter, which you are strongly encouraged to not
9393 1.1 tron change. The default value of <a href="postconf.5.html#tls_null_cipherlist">tls_null_cipherlist</a> excludes anonymous
9394 1.1 tron ciphers (OpenSSL 0.9.8 has NULL ciphers that offer data integrity without
9395 1.1 tron encryption or authentication). </dd>
9396 1.1 tron
9397 1.1 tron </dl>
9398 1.1 tron
9399 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
9400 1.1 tron
9401 1.1 tron
9402 1.1 tron </DD>
9403 1.1 tron
9404 1.1 tron <DT><b><a name="smtp_tls_mandatory_exclude_ciphers">smtp_tls_mandatory_exclude_ciphers</a>
9405 1.1 tron (default: empty)</b></DT><DD>
9406 1.1 tron
9407 1.1 tron <p> Additional list of ciphers or cipher types to exclude from the
9408 1.1 tron SMTP client cipher list at mandatory TLS security levels. This list
9409 1.1 tron works in addition to the exclusions listed with <a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a>
9410 1.1 tron (see there for syntax details). </p>
9411 1.1 tron
9412 1.1 tron <p> Starting with Postfix 2.6, the mandatory cipher exclusions can be
9413 1.1 tron specified on a per-destination basis via the TLS policy "exclude"
9414 1.1 tron attribute. See <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> for notes and examples. </p>
9415 1.1 tron
9416 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
9417 1.1 tron
9418 1.1 tron
9419 1.1 tron </DD>
9420 1.1 tron
9421 1.1 tron <DT><b><a name="smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a>
9422 1.1 tron (default: SSLv3, TLSv1)</b></DT><DD>
9423 1.1 tron
9424 1.1 tron <p> List of SSL/TLS protocols that the Postfix SMTP client will use with
9425 1.1 tron mandatory TLS encryption. In <a href="postconf.5.html">main.cf</a> the values are separated by
9426 1.1 tron whitespace, commas or colons. In the policy table "protocols" attribute
9427 1.1 tron (see <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a>) the only valid separator is colon. An
9428 1.1 tron empty value means allow all protocols. The valid protocol names, (see
9429 1.1 tron <b>SSL_get_version(3)</b>), are "SSLv2", "SSLv3" and "TLSv1". </p>
9430 1.1 tron
9431 1.1 tron <p> With Postfix ≥ 2.5 the parameter syntax is expanded to support
9432 1.1 tron protocol exclusions. One can now explicitly exclude SSLv2 by setting
9433 1.1 tron "<a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> = !SSLv2". To exclude both SSLv2 and
9434 1.1 tron SSLv3 set "<a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> = !SSLv2, !SSLv3". Listing
9435 1.1 tron the protocols to include, rather than protocols to exclude, is still
9436 1.1 tron supported; use the form you find more intuitive. </p>
9437 1.1 tron
9438 1.1 tron <p> Since SSL version 2 has known protocol weaknesses and is now
9439 1.1 tron deprecated, the default setting excludes "SSLv2". This means that by
9440 1.1 tron default, SSL version 2 will not be used at the "encrypt" security level
9441 1.1 tron and higher. </p>
9442 1.1 tron
9443 1.1 tron <p> See the documentation of the <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> parameter and
9444 1.1 tron <a href="TLS_README.html">TLS_README</a> for more information about security levels. </p>
9445 1.1 tron
9446 1.1 tron <p> Example: </p>
9447 1.1 tron
9448 1.1 tron <pre>
9449 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> = TLSv1
9450 1.1 tron # Alternative form with Postfix ≥ 2.5:
9451 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> = !SSLv2, !SSLv3
9452 1.1 tron </pre>
9453 1.1 tron
9454 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
9455 1.1 tron
9456 1.1 tron
9457 1.1 tron </DD>
9458 1.1 tron
9459 1.1 tron <DT><b><a name="smtp_tls_note_starttls_offer">smtp_tls_note_starttls_offer</a>
9460 1.1 tron (default: no)</b></DT><DD>
9461 1.1 tron
9462 1.1 tron <p> Log the hostname of a remote SMTP server that offers STARTTLS,
9463 1.1 tron when TLS is not already enabled for that server. </p>
9464 1.1 tron
9465 1.1 tron <p> The logfile record looks like: </p>
9466 1.1 tron
9467 1.1 tron <pre>
9468 1.1 tron postfix/smtp[pid]: Host offered STARTTLS: [name.of.host]
9469 1.1 tron </pre>
9470 1.1 tron
9471 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9472 1.1 tron
9473 1.1 tron
9474 1.1 tron </DD>
9475 1.1 tron
9476 1.1 tron <DT><b><a name="smtp_tls_per_site">smtp_tls_per_site</a>
9477 1.1 tron (default: empty)</b></DT><DD>
9478 1.1 tron
9479 1.1 tron <p> Optional lookup tables with the Postfix SMTP client TLS usage
9480 1.1 tron policy by next-hop destination and by remote SMTP server hostname.
9481 1.1 tron When both lookups succeed, the more specific per-site policy (NONE,
9482 1.1 tron MUST, etc) overrides the less specific one (MAY), and the more secure
9483 1.1 tron per-site policy (MUST, etc) overrides the less secure one (NONE).
9484 1.1 tron With Postfix 2.3 and later <a href="postconf.5.html#smtp_tls_per_site">smtp_tls_per_site</a> is strongly discouraged:
9485 1.1 tron use <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> instead. </p>
9486 1.1 tron
9487 1.1 tron <p> Use of the bare hostname as the per-site table lookup key is
9488 1.1 tron discouraged. Always use the full destination nexthop (enclosed in
9489 1.1 tron [] with a possible ":port" suffix). A recipient domain or MX-enabled
9490 1.1 tron transport next-hop with no port suffix may look like a bare hostname,
9491 1.1 tron but is still a suitable <i>destination</i>. </p>
9492 1.1 tron
9493 1.1 tron <p> Specify a next-hop destination or server hostname on the left-hand
9494 1.1 tron side; no wildcards are allowed. The next-hop destination is either
9495 1.1 tron the recipient domain, or the destination specified with a <a href="transport.5.html">transport(5)</a>
9496 1.1 tron table, the <a href="postconf.5.html#relayhost">relayhost</a> parameter, or the <a href="postconf.5.html#relay_transport">relay_transport</a> parameter.
9497 1.1 tron On the right hand side specify one of the following keywords: </p>
9498 1.1 tron
9499 1.1 tron <dl>
9500 1.1 tron
9501 1.1 tron <dt> NONE </dt> <dd> Don't use TLS at all. This overrides a less
9502 1.1 tron specific <b>MAY</b> lookup result from the alternate host or next-hop
9503 1.1 tron lookup key, and overrides the global <a href="postconf.5.html#smtp_use_tls">smtp_use_tls</a>, <a href="postconf.5.html#smtp_enforce_tls">smtp_enforce_tls</a>,
9504 1.1 tron and <a href="postconf.5.html#smtp_tls_enforce_peername">smtp_tls_enforce_peername</a> settings. </dd>
9505 1.1 tron
9506 1.1 tron <dt> MAY </dt> <dd> Try to use TLS if the server announces support,
9507 1.1 tron otherwise use the unencrypted connection. This has less precedence
9508 1.1 tron than a more specific result (including <b>NONE</b>) from the alternate
9509 1.1 tron host or next-hop lookup key, and has less precedence than the more
9510 1.1 tron specific global "<a href="postconf.5.html#smtp_enforce_tls">smtp_enforce_tls</a> = yes" or "<a href="postconf.5.html#smtp_tls_enforce_peername">smtp_tls_enforce_peername</a>
9511 1.1 tron = yes". </dd>
9512 1.1 tron
9513 1.1 tron <dt> MUST_NOPEERMATCH </dt> <dd> Require TLS encryption, but do not
9514 1.1 tron require that the remote SMTP server hostname matches the information
9515 1.1 tron in the remote SMTP server certificate, or that the server certificate
9516 1.1 tron was issued by a trusted CA. This overrides a less secure <b>NONE</b>
9517 1.1 tron or a less specific <b>MAY</b> lookup result from the alternate host
9518 1.1 tron or next-hop lookup key, and overrides the global <a href="postconf.5.html#smtp_use_tls">smtp_use_tls</a>,
9519 1.1 tron <a href="postconf.5.html#smtp_enforce_tls">smtp_enforce_tls</a> and <a href="postconf.5.html#smtp_tls_enforce_peername">smtp_tls_enforce_peername</a> settings. </dd>
9520 1.1 tron
9521 1.1 tron <dt> MUST </dt> <dd> Require TLS encryption, require that the remote
9522 1.1 tron SMTP server hostname matches the information in the remote SMTP
9523 1.1 tron server certificate, and require that the remote SMTP server certificate
9524 1.1 tron was issued by a trusted CA. This overrides a less secure <b>NONE</b>
9525 1.1 tron and <b>MUST_NOPEERMATCH</b> or a less specific <b>MAY</b> lookup
9526 1.1 tron result from the alternate host or next-hop lookup key, and overrides
9527 1.1 tron the global <a href="postconf.5.html#smtp_use_tls">smtp_use_tls</a>, <a href="postconf.5.html#smtp_enforce_tls">smtp_enforce_tls</a> and <a href="postconf.5.html#smtp_tls_enforce_peername">smtp_tls_enforce_peername</a>
9528 1.1 tron settings. </dd>
9529 1.1 tron
9530 1.1 tron </dl>
9531 1.1 tron
9532 1.1 tron <p> The above keywords correspond to the "none", "may", "encrypt" and
9533 1.1 tron "verify" security levels for the new <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> parameter
9534 1.1 tron introduced in Postfix 2.3. Starting with Postfix 2.3, and independently
9535 1.1 tron of how the policy is specified, the <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> and
9536 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> parameters apply when TLS encryption
9537 1.1 tron is mandatory. Connections for which encryption is optional typically
9538 1.1 tron enable all "export" grade and better ciphers (see <a href="postconf.5.html#smtp_tls_ciphers">smtp_tls_ciphers</a>
9539 1.1 tron and <a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a>). </p>
9540 1.1 tron
9541 1.1 tron <p> As long as no secure DNS lookup mechanism is available, false
9542 1.1 tron hostnames in MX or CNAME responses can change the server hostname
9543 1.1 tron that Postfix uses for TLS policy lookup and server certificate
9544 1.1 tron verification. Even with a perfect match between the server hostname and
9545 1.1 tron the server certificate, there is no guarantee that Postfix is connected
9546 1.1 tron to the right server. See <a href="TLS_README.html">TLS_README</a> (Closing a DNS loophole with obsolete
9547 1.1 tron per-site TLS policies) for a possible work-around. </p>
9548 1.1 tron
9549 1.1 tron <p> This feature is available in Postfix 2.2 and later. With
9550 1.1 tron Postfix 2.3 and later use <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> instead. </p>
9551 1.1 tron
9552 1.1 tron
9553 1.1 tron </DD>
9554 1.1 tron
9555 1.1 tron <DT><b><a name="smtp_tls_policy_maps">smtp_tls_policy_maps</a>
9556 1.1 tron (default: empty)</b></DT><DD>
9557 1.1 tron
9558 1.1 tron <p> Optional lookup tables with the Postfix SMTP client TLS security
9559 1.1 tron policy by next-hop destination; when a non-empty value is specified,
9560 1.1 tron this overrides the obsolete <a href="postconf.5.html#smtp_tls_per_site">smtp_tls_per_site</a> parameter. See
9561 1.1 tron <a href="TLS_README.html">TLS_README</a> for a more detailed discussion of TLS security levels.
9562 1.1 tron </p>
9563 1.1 tron
9564 1.1 tron <p> The TLS policy table is indexed by the full next-hop destination,
9565 1.1 tron which is either the recipient domain, or the verbatim next-hop
9566 1.1 tron specified in the transport table, $<a href="postconf.5.html#local_transport">local_transport</a>, $<a href="postconf.5.html#virtual_transport">virtual_transport</a>,
9567 1.1 tron $<a href="postconf.5.html#relay_transport">relay_transport</a> or $<a href="postconf.5.html#default_transport">default_transport</a>. This includes any enclosing
9568 1.1 tron square brackets and any non-default destination server port suffix. The
9569 1.1 tron LMTP socket type prefix (inet: or unix:) is not included in the lookup
9570 1.1 tron key. </p>
9571 1.1 tron
9572 1.1 tron <p> Only the next-hop domain, or $<a href="postconf.5.html#myhostname">myhostname</a> with LMTP over UNIX-domain
9573 1.1 tron sockets, is used as the nexthop name for certificate verification. The
9574 1.1 tron port and any enclosing square brackets are used in the table lookup key,
9575 1.1 tron but are not used for server name verification. </p>
9576 1.1 tron
9577 1.1 tron <p> When the lookup key is a domain name without enclosing square brackets
9578 1.1 tron or any <i>:port</i> suffix (typically the recipient domain), and the full
9579 1.1 tron domain is not found in the table, just as with the <a href="transport.5.html">transport(5)</a> table,
9580 1.1 tron the parent domain starting with a leading "." is matched recursively. This
9581 1.1 tron allows one to specify a security policy for a recipient domain and all
9582 1.1 tron its sub-domains. </p>
9583 1.1 tron
9584 1.1 tron <p> The lookup result is a security level, followed by an optional list
9585 1.1 tron of whitespace and/or comma separated name=value attributes that override
9586 1.1 tron related <a href="postconf.5.html">main.cf</a> settings. The TLS security levels in order of increasing
9587 1.1 tron security are: </p>
9588 1.1 tron
9589 1.1 tron <dl>
9590 1.1 tron
9591 1.1 tron <dt><b>none</b></dt>
9592 1.1 tron <dd>No TLS. No additional attributes are supported at this level. </dd>
9593 1.1 tron
9594 1.1 tron <dt><b>may</b></dt>
9595 1.1 tron <dd>Opportunistic TLS. Since sending in the clear is acceptable,
9596 1.1 tron demanding stronger than default TLS security merely reduces
9597 1.1 tron inter-operability. The optional "ciphers", "exclude" and "protocols"
9598 1.1 tron attributes (available for opportunistic TLS with Postfix ≥ 2.6)
9599 1.1 tron override the "<a href="postconf.5.html#smtp_tls_ciphers">smtp_tls_ciphers</a>", "<a href="postconf.5.html#smtp_tls_exclude_ciphers">smtp_tls_exclude_ciphers</a>" and
9600 1.1 tron "<a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a>" configuration parameters. When opportunistic TLS
9601 1.1 tron handshakes fail, Postfix retries the connection with TLS disabled.
9602 1.1 tron This allows mail delivery to sites with non-interoperable TLS
9603 1.1 tron implementations.</dd>
9604 1.1 tron
9605 1.1 tron <dt><b>encrypt</b></dt> <dd>Mandatory TLS encryption. At this level
9606 1.1 tron and higher, the optional "protocols" attribute overrides the <a href="postconf.5.html">main.cf</a>
9607 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> parameter, the optional "ciphers" attribute
9608 1.1 tron overrides the <a href="postconf.5.html">main.cf</a> <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> parameter, and the
9609 1.1 tron optional "exclude" attribute (Postfix ≥ 2.6) overrides the <a href="postconf.5.html">main.cf</a>
9610 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_exclude_ciphers">smtp_tls_mandatory_exclude_ciphers</a> parameter. In the policy table,
9611 1.1 tron multiple protocols or excluded ciphers must be separated by colons,
9612 1.1 tron as attribute values may not contain whitespace or commas. </dd>
9613 1.1 tron
9614 1.1 tron <dt><b>fingerprint</b></dt> <dd>Certificate fingerprint
9615 1.1 tron verification. Available with Postfix 2.5 and later. At this security
9616 1.1 tron level, there are no trusted certificate authorities. The certificate
9617 1.1 tron trust chain, expiration date, ... are not checked. Instead,
9618 1.1 tron the optional <b>match</b> attribute, or else the <a href="postconf.5.html">main.cf</a>
9619 1.1 tron <b><a href="postconf.5.html#smtp_tls_fingerprint_cert_match">smtp_tls_fingerprint_cert_match</a></b> parameter, lists the
9620 1.1 tron valid "fingerprints" of the server certificate. The digest
9621 1.1 tron algorithm used to calculate the fingerprint is selected by the
9622 1.1 tron <b><a href="postconf.5.html#smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a></b> parameter. Multiple fingerprints can
9623 1.1 tron be combined with a "|" delimiter in a single match attribute, or multiple
9624 1.1 tron match attributes can be employed. The ":" character is not used as a
9625 1.1 tron delimiter as it occurs between each pair of fingerprint (hexadecimal)
9626 1.1 tron digits. </dd>
9627 1.1 tron
9628 1.1 tron <dt><b>verify</b></dt> <dd>Mandatory TLS verification. At this security
9629 1.1 tron level, DNS MX lookups are trusted to be secure enough, and the name
9630 1.1 tron verified in the server certificate is usually obtained indirectly via
9631 1.1 tron unauthenticated DNS MX lookups. The optional "match" attribute overrides
9632 1.1 tron the <a href="postconf.5.html">main.cf</a> <a href="postconf.5.html#smtp_tls_verify_cert_match">smtp_tls_verify_cert_match</a> parameter. In the policy table,
9633 1.1 tron multiple match patterns and strategies must be separated by colons.
9634 1.1 tron In practice explicit control over matching is more common with the
9635 1.1 tron "secure" policy, described below. </dd>
9636 1.1 tron
9637 1.1 tron <dt><b>secure</b></dt> <dd>Secure-channel TLS. At this security level, DNS
9638 1.1 tron MX lookups, though potentially used to determine the candidate next-hop
9639 1.1 tron gateway IP addresses, are <b>not</b> trusted to be secure enough for TLS
9640 1.1 tron peername verification. Instead, the default name verified in the server
9641 1.1 tron certificate is obtained directly from the next-hop, or is explicitly
9642 1.1 tron specified via the optional <b>match</b> attribute which overrides the
9643 1.1 tron <a href="postconf.5.html">main.cf</a> <a href="postconf.5.html#smtp_tls_secure_cert_match">smtp_tls_secure_cert_match</a> parameter. In the policy table,
9644 1.1 tron multiple match patterns and strategies must be separated by colons.
9645 1.1 tron The match attribute is most useful when multiple domains are supported by
9646 1.1 tron common server, the policy entries for additional domains specify matching
9647 1.1 tron rules for the primary domain certificate. While transport table overrides
9648 1.1 tron routing the secondary domains to the primary nexthop also allow secure
9649 1.1 tron verification, they risk delivery to the wrong destination when domains
9650 1.1 tron change hands or are re-assigned to new gateways. With the "match"
9651 1.1 tron attribute approach, routing is not perturbed, and mail is deferred if
9652 1.1 tron verification of a new MX host fails. </dd>
9653 1.1 tron
9654 1.1 tron </dl>
9655 1.1 tron
9656 1.1 tron <p>
9657 1.1 tron Example:
9658 1.1 tron </p>
9659 1.1 tron
9660 1.1 tron <pre>
9661 1.1 tron /etc/postfix/<a href="postconf.5.html">main.cf</a>:
9662 1.1 tron <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> = hash:/etc/postfix/tls_policy
9663 1.1 tron # Postfix 2.5 and later
9664 1.1 tron <a href="postconf.5.html#smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a> = md5
9665 1.1 tron </pre>
9666 1.1 tron
9667 1.1 tron <pre>
9668 1.1 tron /etc/postfix/tls_policy:
9669 1.1 tron example.edu none
9670 1.1 tron example.mil may
9671 1.1 tron example.gov encrypt protocols=TLSv1
9672 1.1 tron example.com verify ciphers=high
9673 1.1 tron example.net secure
9674 1.1 tron .example.net secure match=.example.net:example.net
9675 1.1 tron [mail.example.org]:587 secure match=nexthop
9676 1.1 tron # Postfix 2.5 and later
9677 1.1 tron [thumb.example.org] fingerprint
9678 1.1 tron match=EC:3B:2D:B0:5B:B1:FB:6D:20:A3:9D:72:F6:8D:12:35
9679 1.1 tron match=3D:95:34:51:24:66:33:B9:D2:40:99:C0:C1:17:0B:D1
9680 1.1 tron </pre>
9681 1.1 tron
9682 1.1 tron <p> <b>Note:</b> The <b>hostname</b> strategy if listed in a non-default
9683 1.1 tron setting of <a href="postconf.5.html#smtp_tls_secure_cert_match">smtp_tls_secure_cert_match</a> or in the <b>match</b> attribute
9684 1.1 tron in the policy table can render the <b>secure</b> level vulnerable to
9685 1.1 tron DNS forgery. Do not use the <b>hostname</b> strategy for secure-channel
9686 1.1 tron configurations in environments where DNS security is not assured. </p>
9687 1.1 tron
9688 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
9689 1.1 tron
9690 1.1 tron
9691 1.1 tron </DD>
9692 1.1 tron
9693 1.1 tron <DT><b><a name="smtp_tls_protocols">smtp_tls_protocols</a>
9694 1.1 tron (default: !SSLv2)</b></DT><DD>
9695 1.1 tron
9696 1.1 tron <p> List of TLS protocols that the Postfix SMTP client will exclude or
9697 1.1 tron include with opportunistic TLS encryption. Starting with Postfix 2.6,
9698 1.1 tron the Postfix SMTP client will by default not use the obsolete SSLv2
9699 1.1 tron protocol. </p>
9700 1.1 tron
9701 1.1 tron <p> In <a href="postconf.5.html">main.cf</a> the values are separated by whitespace, commas or
9702 1.1 tron colons. In the policy table (see <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a>) the only valid
9703 1.1 tron separator is colon. An empty value means allow all protocols. The valid
9704 1.1 tron protocol names, (see <b>SSL_get_version(3)</b>), are "SSLv2", "SSLv3"
9705 1.1 tron and "TLSv1". </p>
9706 1.1 tron
9707 1.1 tron <p> To include a protocol list its name, to exclude it, prefix the name
9708 1.1 tron with a "!" character. To exclude SSLv2 even for opportunistic TLS set
9709 1.1 tron "<a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a> = !SSLv2". To exclude both "SSLv2" and "SSLv3" set
9710 1.1 tron "<a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a> = !SSLv2, !SSLv3". Explicitly listing the protocols to
9711 1.1 tron include, is supported, but not recommended. OpenSSL provides no mechanisms
9712 1.1 tron for excluding protocols not known at compile-time. If Postfix is linked
9713 1.1 tron against an OpenSSL library that supports additional protocol versions,
9714 1.1 tron they cannot be excluded using either syntax. </p>
9715 1.1 tron
9716 1.1 tron <p> Example: </p>
9717 1.1 tron <pre>
9718 1.1 tron # TLSv1 only!
9719 1.1 tron <a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a> = !SSLv2, !SSLv3
9720 1.1 tron </pre>
9721 1.1 tron
9722 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
9723 1.1 tron
9724 1.1 tron
9725 1.1 tron </DD>
9726 1.1 tron
9727 1.1 tron <DT><b><a name="smtp_tls_scert_verifydepth">smtp_tls_scert_verifydepth</a>
9728 1.1 tron (default: 9)</b></DT><DD>
9729 1.1 tron
9730 1.1 tron <p> The verification depth for remote SMTP server certificates. A depth
9731 1.1 tron of 1 is sufficient if the issuing CA is listed in a local CA file. </p>
9732 1.1 tron
9733 1.1 tron <p> The default verification depth is 9 (the OpenSSL default) for
9734 1.1 tron compatibility with earlier Postfix behavior. Prior to Postfix 2.5,
9735 1.1 tron the default value was 5, but the limit was not actually enforced. If
9736 1.1 tron you have set this to a lower non-default value, certificates with longer
9737 1.1 tron trust chains may now fail to verify. Certificate chains with 1 or 2
9738 1.1 tron CAs are common, deeper chains are more rare and any number between 5
9739 1.1 tron and 9 should suffice in practice. You can choose a lower number if,
9740 1.1 tron for example, you trust certificates directly signed by an issuing CA
9741 1.1 tron but not any CAs it delegates to. </p>
9742 1.1 tron
9743 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9744 1.1 tron
9745 1.1 tron
9746 1.1 tron </DD>
9747 1.1 tron
9748 1.1 tron <DT><b><a name="smtp_tls_secure_cert_match">smtp_tls_secure_cert_match</a>
9749 1.1 tron (default: nexthop, dot-nexthop)</b></DT><DD>
9750 1.1 tron
9751 1.1 tron <p> The server certificate peername verification method for the
9752 1.1 tron "secure" TLS security level. In a "secure" TLS policy table
9753 1.1 tron ($<a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a>) entry the optional "match" attribute
9754 1.1 tron overrides this <a href="postconf.5.html">main.cf</a> setting. </p>
9755 1.1 tron
9756 1.1 tron <p> This parameter specifies one or more patterns or strategies separated
9757 1.1 tron by commas, whitespace or colons. In the policy table the only valid
9758 1.1 tron separator is the colon character. </p>
9759 1.1 tron
9760 1.1 tron <p> For a description of the pattern and strategy syntax see the
9761 1.1 tron <a href="postconf.5.html#smtp_tls_verify_cert_match">smtp_tls_verify_cert_match</a> parameter. The "hostname" strategy should
9762 1.1 tron be avoided in this context, as in the absence of a secure global DNS, using
9763 1.1 tron the results of MX lookups in certificate verification is not immune to active
9764 1.1 tron (man-in-the-middle) attacks on DNS. </p>
9765 1.1 tron
9766 1.1 tron <p>
9767 1.1 tron Sample <a href="postconf.5.html">main.cf</a> setting:
9768 1.1 tron </p>
9769 1.1 tron
9770 1.1 tron <blockquote>
9771 1.1 tron <pre>
9772 1.1 tron <a href="postconf.5.html#smtp_tls_secure_cert_match">smtp_tls_secure_cert_match</a> = nexthop
9773 1.1 tron </pre>
9774 1.1 tron </blockquote>
9775 1.1 tron
9776 1.1 tron <p>
9777 1.1 tron Sample policy table override:
9778 1.1 tron </p>
9779 1.1 tron
9780 1.1 tron <blockquote>
9781 1.1 tron <pre>
9782 1.1 tron example.net secure match=example.com:.example.com
9783 1.1 tron .example.net secure match=example.com:.example.com
9784 1.1 tron </pre>
9785 1.1 tron </blockquote>
9786 1.1 tron
9787 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
9788 1.1 tron
9789 1.1 tron
9790 1.1 tron </DD>
9791 1.1 tron
9792 1.1 tron <DT><b><a name="smtp_tls_security_level">smtp_tls_security_level</a>
9793 1.1 tron (default: empty)</b></DT><DD>
9794 1.1 tron
9795 1.1 tron <p> The default SMTP TLS security level for the Postfix SMTP client;
9796 1.1 tron when a non-empty value is specified, this overrides the obsolete
9797 1.1 tron parameters <a href="postconf.5.html#smtp_use_tls">smtp_use_tls</a>, <a href="postconf.5.html#smtp_enforce_tls">smtp_enforce_tls</a>, and <a href="postconf.5.html#smtp_tls_enforce_peername">smtp_tls_enforce_peername</a>.
9798 1.1 tron </p>
9799 1.1 tron
9800 1.1 tron <p> Specify one of the following security levels: </p>
9801 1.1 tron
9802 1.1 tron <dl>
9803 1.1 tron
9804 1.1 tron <dt><b>none</b></dt> <dd> TLS will not be used unless enabled for specific
9805 1.1 tron destinations via <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a>. </dd>
9806 1.1 tron
9807 1.1 tron <dt><b>may</b></dt>
9808 1.1 tron <dd> Opportunistic TLS. Use TLS if this is supported by the remote
9809 1.1 tron SMTP server, otherwise use plaintext. Since
9810 1.1 tron sending in the clear is acceptable, demanding stronger than default TLS
9811 1.1 tron security merely reduces inter-operability.
9812 1.1 tron The "<a href="postconf.5.html#smtp_tls_ciphers">smtp_tls_ciphers</a>" and "<a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a>" (Postfix ≥ 2.6)
9813 1.1 tron configuration parameters provide control over the protocols and
9814 1.1 tron cipher grade used with opportunistic TLS. With earlier releases the
9815 1.1 tron opportunistic TLS cipher grade is always "export" and no protocols
9816 1.1 tron are disabled.
9817 1.1 tron When TLS handshakes fail, the connection is retried with TLS disabled.
9818 1.1 tron This allows mail delivery to sites with non-interoperable TLS
9819 1.1 tron implementations. </dd>
9820 1.1 tron
9821 1.1 tron <dt><b>encrypt</b></dt> <dd>Mandatory TLS encryption. Since a minimum
9822 1.1 tron level of security is intended, it is reasonable to be specific about
9823 1.1 tron sufficiently secure protocol versions and ciphers. At this security level
9824 1.1 tron and higher, the <a href="postconf.5.html">main.cf</a> parameters <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> and
9825 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> specify the TLS protocols and minimum
9826 1.1 tron cipher grade which the administrator considers secure enough for
9827 1.1 tron mandatory encrypted sessions. This security level is not an appropriate
9828 1.1 tron default for systems delivering mail to the Internet. </dd>
9829 1.1 tron
9830 1.1 tron <dt><b>fingerprint</b></dt> <dd>Certificate fingerprint
9831 1.1 tron verification. Available with Postfix 2.5 and later. At this security
9832 1.1 tron level, there are no trusted certificate authorities. The certificate
9833 1.1 tron trust chain, expiration date, ... are not checked. Instead,
9834 1.1 tron the <b><a href="postconf.5.html#smtp_tls_fingerprint_cert_match">smtp_tls_fingerprint_cert_match</a></b> parameter lists
9835 1.1 tron the valid "fingerprints" of the server certificate. The digest
9836 1.1 tron algorithm used to calculate the fingerprint is selected by the
9837 1.1 tron <b><a href="postconf.5.html#smtp_tls_fingerprint_digest">smtp_tls_fingerprint_digest</a></b> parameter. </dd>
9838 1.1 tron
9839 1.1 tron <dt><b>verify</b></dt> <dd>Mandatory TLS verification. At this security
9840 1.1 tron level, DNS MX lookups are trusted to be secure enough, and the name
9841 1.1 tron verified in the server certificate is usually obtained indirectly
9842 1.1 tron via unauthenticated DNS MX lookups. The <a href="postconf.5.html#smtp_tls_verify_cert_match">smtp_tls_verify_cert_match</a>
9843 1.1 tron parameter controls how the server name is verified. In practice explicit
9844 1.1 tron control over matching is more common at the "secure" level, described
9845 1.1 tron below. This security level is not an appropriate default for systems
9846 1.1 tron delivering mail to the Internet. </dd>
9847 1.1 tron
9848 1.1 tron <dt><b>secure</b></dt> <dd>Secure-channel TLS. At this security level,
9849 1.1 tron DNS MX lookups, though potentially used to determine the candidate
9850 1.1 tron next-hop gateway IP addresses, are <b>not</b> trusted to be secure enough
9851 1.1 tron for TLS peername verification. Instead, the default name verified in
9852 1.1 tron the server certificate is obtained from the next-hop domain as specified
9853 1.1 tron in the <a href="postconf.5.html#smtp_tls_secure_cert_match">smtp_tls_secure_cert_match</a> configuration parameter. The default
9854 1.1 tron matching rule is that a server certificate matches when its name is equal
9855 1.1 tron to or is a sub-domain of the nexthop domain. This security level is not
9856 1.1 tron an appropriate default for systems delivering mail to the Internet. </dd>
9857 1.1 tron
9858 1.1 tron </dl>
9859 1.1 tron
9860 1.1 tron <p>
9861 1.1 tron Examples:
9862 1.1 tron </p>
9863 1.1 tron
9864 1.1 tron <pre>
9865 1.1 tron # No TLS. Formerly: <a href="postconf.5.html#smtp_use_tls">smtp_use_tls</a>=no and <a href="postconf.5.html#smtp_enforce_tls">smtp_enforce_tls</a>=no.
9866 1.1 tron <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> = none
9867 1.1 tron </pre>
9868 1.1 tron
9869 1.1 tron <pre>
9870 1.1 tron # Opportunistic TLS.
9871 1.1 tron <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> = may
9872 1.1 tron # Postfix ≥ 2.6:
9873 1.1 tron # Do not tweak opportunistic ciphers unless it is essential
9874 1.1 tron # to do so (if a security vulnerability is found in the SSL library that
9875 1.1 tron # can be mitigated by disabling a particular protocol or raising the
9876 1.1 tron # cipher grade from "export" to "low" or "medium").
9877 1.1 tron <a href="postconf.5.html#smtp_tls_ciphers">smtp_tls_ciphers</a> = export
9878 1.1 tron <a href="postconf.5.html#smtp_tls_protocols">smtp_tls_protocols</a> = !SSLv2
9879 1.1 tron </pre>
9880 1.1 tron
9881 1.1 tron <pre>
9882 1.1 tron # Mandatory (high-grade) TLS encryption.
9883 1.1 tron <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> = encrypt
9884 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> = high
9885 1.1 tron </pre>
9886 1.1 tron
9887 1.1 tron <pre>
9888 1.1 tron # Mandatory TLS verification of hostname or nexthop domain.
9889 1.1 tron <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> = verify
9890 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> = high
9891 1.1 tron <a href="postconf.5.html#smtp_tls_verify_cert_match">smtp_tls_verify_cert_match</a> = hostname, nexthop, dot-nexthop
9892 1.1 tron </pre>
9893 1.1 tron
9894 1.1 tron <pre>
9895 1.1 tron # Secure channel TLS with exact nexthop name match.
9896 1.1 tron <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> = secure
9897 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> = TLSv1
9898 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> = high
9899 1.1 tron <a href="postconf.5.html#smtp_tls_secure_cert_match">smtp_tls_secure_cert_match</a> = nexthop
9900 1.1 tron </pre>
9901 1.1 tron
9902 1.1 tron <pre>
9903 1.1 tron # Certificate fingerprint verification (Postfix ≥ 2.5).
9904 1.1 tron # The CA-less "fingerprint" security level only scales to a limited
9905 1.1 tron # number of destinations. As a global default rather than a per-site
9906 1.1 tron # setting, this is practical when mail for all recipients is sent
9907 1.1 tron # to a central mail hub.
9908 1.1 tron <a href="postconf.5.html#relayhost">relayhost</a> = [mailhub.example.com]
9909 1.1 tron <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> = fingerprint
9910 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_protocols">smtp_tls_mandatory_protocols</a> = !SSLv2, !SSLv3
9911 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> = high
9912 1.1 tron <a href="postconf.5.html#smtp_tls_fingerprint_cert_match">smtp_tls_fingerprint_cert_match</a> =
9913 1.1 tron 3D:95:34:51:24:66:33:B9:D2:40:99:C0:C1:17:0B:D1
9914 1.1 tron EC:3B:2D:B0:5B:B1:FB:6D:20:A3:9D:72:F6:8D:12:35
9915 1.1 tron </pre>
9916 1.1 tron
9917 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
9918 1.1 tron
9919 1.1 tron
9920 1.1 tron </DD>
9921 1.1 tron
9922 1.1 tron <DT><b><a name="smtp_tls_session_cache_database">smtp_tls_session_cache_database</a>
9923 1.1 tron (default: empty)</b></DT><DD>
9924 1.1 tron
9925 1.1 tron <p> Name of the file containing the optional Postfix SMTP client
9926 1.1 tron TLS session cache. Specify a database type that supports enumeration,
9927 1.1 tron such as <b>btree</b> or <b>sdbm</b>; there is no need to support
9928 1.1 tron concurrent access. The file is created if it does not exist. The <a href="smtp.8.html">smtp(8)</a>
9929 1.1 tron daemon does not use this parameter directly, rather the cache is
9930 1.1 tron implemented indirectly in the <a href="tlsmgr.8.html">tlsmgr(8)</a> daemon. This means that
9931 1.1 tron per-smtp-instance <a href="master.5.html">master.cf</a> overrides of this parameter are not effective.
9932 1.1 tron Note, that each of the cache databases supported by <a href="tlsmgr.8.html">tlsmgr(8)</a> daemon:
9933 1.1 tron $<a href="postconf.5.html#smtpd_tls_session_cache_database">smtpd_tls_session_cache_database</a>, $<a href="postconf.5.html#smtp_tls_session_cache_database">smtp_tls_session_cache_database</a>
9934 1.1 tron (and with Postfix 2.3 and later $<a href="postconf.5.html#lmtp_tls_session_cache_database">lmtp_tls_session_cache_database</a>), needs to
9935 1.1 tron be stored separately. It is not at this time possible to store multiple
9936 1.1 tron caches in a single database. </p>
9937 1.1 tron
9938 1.1 tron <p> Note: <b>dbm</b> databases are not suitable. TLS
9939 1.1 tron session objects are too large. </p>
9940 1.1 tron
9941 1.1 tron <p> As of version 2.5, Postfix no longer uses root privileges when
9942 1.1 tron opening this file. The file should now be stored under the Postfix-owned
9943 1.1 tron <a href="postconf.5.html#data_directory">data_directory</a>. As a migration aid, an attempt to open the file
9944 1.1 tron under a non-Postfix directory is redirected to the Postfix-owned
9945 1.1 tron <a href="postconf.5.html#data_directory">data_directory</a>, and a warning is logged. </p>
9946 1.1 tron
9947 1.1 tron <p> Example: </p>
9948 1.1 tron
9949 1.1 tron <pre>
9950 1.1 tron <a href="postconf.5.html#smtp_tls_session_cache_database">smtp_tls_session_cache_database</a> = btree:/var/lib/postfix/smtp_scache
9951 1.1 tron </pre>
9952 1.1 tron
9953 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9954 1.1 tron
9955 1.1 tron
9956 1.1 tron </DD>
9957 1.1 tron
9958 1.1 tron <DT><b><a name="smtp_tls_session_cache_timeout">smtp_tls_session_cache_timeout</a>
9959 1.1 tron (default: 3600s)</b></DT><DD>
9960 1.1 tron
9961 1.1 tron <p> The expiration time of Postfix SMTP client TLS session cache
9962 1.1 tron information. A cache cleanup is performed periodically
9963 1.1 tron every $<a href="postconf.5.html#smtp_tls_session_cache_timeout">smtp_tls_session_cache_timeout</a> seconds. As with
9964 1.1 tron $<a href="postconf.5.html#smtp_tls_session_cache_database">smtp_tls_session_cache_database</a>, this parameter is implemented in the
9965 1.1 tron <a href="tlsmgr.8.html">tlsmgr(8)</a> daemon and therefore per-smtp-instance <a href="master.5.html">master.cf</a> overrides
9966 1.1 tron are not possible. </p>
9967 1.1 tron
9968 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
9969 1.1 tron
9970 1.1 tron
9971 1.1 tron </DD>
9972 1.1 tron
9973 1.1 tron <DT><b><a name="smtp_tls_verify_cert_match">smtp_tls_verify_cert_match</a>
9974 1.1 tron (default: hostname)</b></DT><DD>
9975 1.1 tron
9976 1.1 tron <p> The server certificate peername verification method for the
9977 1.1 tron "verify" TLS security level. In a "verify" TLS policy table
9978 1.1 tron ($<a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a>) entry the optional "match" attribute
9979 1.1 tron overrides this <a href="postconf.5.html">main.cf</a> setting. </p>
9980 1.1 tron
9981 1.1 tron <p> This parameter specifies one or more patterns or strategies separated
9982 1.1 tron by commas, whitespace or colons. In the policy table the only valid
9983 1.1 tron separator is the colon character. </p>
9984 1.1 tron
9985 1.1 tron <p> Patterns specify domain names, or domain name suffixes: </p>
9986 1.1 tron
9987 1.1 tron <dl>
9988 1.1 tron
9989 1.1 tron <dt><i>example.com</i></dt> <dd> Match the <i>example.com</i> domain,
9990 1.1 tron i.e. one of the names the server certificate must be <i>example.com</i>,
9991 1.1 tron upper and lower case distinctions are ignored. </dd>
9992 1.1 tron
9993 1.1 tron <dt><i>.example.com</i></dt>
9994 1.1 tron <dd> Match subdomains of the <i>example.com</i> domain, i.e. match
9995 1.1 tron a name in the server certificate that consists of a non-zero number of
9996 1.1 tron labels followed by a <i>.example.com</i> suffix. Case distinctions are
9997 1.1 tron ignored.</dd>
9998 1.1 tron
9999 1.1 tron </dl>
10000 1.1 tron
10001 1.1 tron <p> Strategies specify a transformation from the next-hop domain
10002 1.1 tron to the expected name in the server certificate: </p>
10003 1.1 tron
10004 1.1 tron <dl>
10005 1.1 tron
10006 1.1 tron <dt>nexthop</dt>
10007 1.1 tron <dd> Match against the next-hop domain, which is either the recipient
10008 1.1 tron domain, or the transport next-hop configured for the domain stripped of
10009 1.1 tron any optional socket type prefix, enclosing square brackets and trailing
10010 1.1 tron port. When MX lookups are not suppressed, this is the original nexthop
10011 1.1 tron domain prior to the MX lookup, not the result of the MX lookup. For
10012 1.1 tron LMTP delivery via UNIX-domain sockets, the verified next-hop name is
10013 1.1 tron $<a href="postconf.5.html#myhostname">myhostname</a>. This strategy is suitable for use with the "secure"
10014 1.1 tron policy. Case is ignored.</dd>
10015 1.1 tron
10016 1.1 tron <dt>dot-nexthop</dt>
10017 1.1 tron <dd> As above, but match server certificate names that are subdomains
10018 1.1 tron of the next-hop domain. Case is ignored.</dd>
10019 1.1 tron
10020 1.1 tron <dt>hostname</dt> <dd> Match against the hostname of the server, often
10021 1.1 tron obtained via an unauthenticated DNS MX lookup. For LMTP delivery via
10022 1.1 tron UNIX-domain sockets, the verified name is $<a href="postconf.5.html#myhostname">myhostname</a>. This matches
10023 1.1 tron the verification strategy of the "MUST" keyword in the obsolete
10024 1.1 tron <a href="postconf.5.html#smtp_tls_per_site">smtp_tls_per_site</a> table, and is suitable for use with the "verify"
10025 1.1 tron security level. When the next-hop name is enclosed in square brackets
10026 1.1 tron to suppress MX lookups, the "hostname" strategy is the same as the
10027 1.1 tron "nexthop" strategy. Case is ignored.</dd>
10028 1.1 tron
10029 1.1 tron </dl>
10030 1.1 tron
10031 1.1 tron <p>
10032 1.1 tron Sample <a href="postconf.5.html">main.cf</a> setting:
10033 1.1 tron </p>
10034 1.1 tron
10035 1.1 tron <pre>
10036 1.1 tron <a href="postconf.5.html#smtp_tls_verify_cert_match">smtp_tls_verify_cert_match</a> = hostname, nexthop, dot-nexthop
10037 1.1 tron </pre>
10038 1.1 tron
10039 1.1 tron <p>
10040 1.1 tron Sample policy table override:
10041 1.1 tron </p>
10042 1.1 tron
10043 1.1 tron <pre>
10044 1.1 tron example.com verify match=hostname:nexthop
10045 1.1 tron .example.com verify match=example.com:.example.com:hostname
10046 1.1 tron </pre>
10047 1.1 tron
10048 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
10049 1.1 tron
10050 1.1 tron
10051 1.1 tron </DD>
10052 1.1 tron
10053 1.1 tron <DT><b><a name="smtp_use_tls">smtp_use_tls</a>
10054 1.1 tron (default: no)</b></DT><DD>
10055 1.1 tron
10056 1.1 tron <p> Opportunistic mode: use TLS when a remote SMTP server announces
10057 1.1 tron STARTTLS support, otherwise send the mail in the clear. Beware:
10058 1.1 tron some SMTP servers offer STARTTLS even if it is not configured. With
10059 1.1 tron Postfix < 2.3, if the TLS handshake fails, and no other server is
10060 1.1 tron available, delivery is deferred and mail stays in the queue. If this
10061 1.1 tron is a concern for you, use the <a href="postconf.5.html#smtp_tls_per_site">smtp_tls_per_site</a> feature instead. </p>
10062 1.1 tron
10063 1.1 tron <p> This feature is available in Postfix 2.2 and later. With
10064 1.1 tron Postfix 2.3 and later use <a href="postconf.5.html#smtp_tls_security_level">smtp_tls_security_level</a> instead. </p>
10065 1.1 tron
10066 1.1 tron
10067 1.1 tron </DD>
10068 1.1 tron
10069 1.1 tron <DT><b><a name="smtp_xforward_timeout">smtp_xforward_timeout</a>
10070 1.1 tron (default: 300s)</b></DT><DD>
10071 1.1 tron
10072 1.1 tron <p>
10073 1.1 tron The SMTP client time limit for sending the XFORWARD command, and
10074 1.1 tron for receiving the server response.
10075 1.1 tron </p>
10076 1.1 tron
10077 1.1 tron <p>
10078 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
10079 1.1 tron The default time unit is s (seconds).
10080 1.1 tron </p>
10081 1.1 tron
10082 1.1 tron <p>
10083 1.1 tron This feature is available in Postfix 2.1 and later.
10084 1.1 tron </p>
10085 1.1 tron
10086 1.1 tron
10087 1.1 tron </DD>
10088 1.1 tron
10089 1.1 tron <DT><b><a name="smtpd_authorized_verp_clients">smtpd_authorized_verp_clients</a>
10090 1.1 tron (default: $<a href="postconf.5.html#authorized_verp_clients">authorized_verp_clients</a>)</b></DT><DD>
10091 1.1 tron
10092 1.1 tron <p> What SMTP clients are allowed to specify the XVERP command.
10093 1.1 tron This command requests that mail be delivered one recipient at a
10094 1.1 tron time with a per recipient return address. </p>
10095 1.1 tron
10096 1.1 tron <p> By default, no clients are allowed to specify XVERP. </p>
10097 1.1 tron
10098 1.1 tron <p> This parameter was renamed with Postfix version 2.1. The default value
10099 1.1 tron is backwards compatible with Postfix version 2.0. </p>
10100 1.1 tron
10101 1.1 tron <p> Specify a list of network/netmask patterns, separated by commas
10102 1.1 tron and/or whitespace. The mask specifies the number of bits in the
10103 1.1 tron network part of a host address. You can also specify hostnames or
10104 1.1 tron .domain names (the initial dot causes the domain to match any name
10105 1.1 tron below it), "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns. A "/file/name"
10106 1.1 tron pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table
10107 1.1 tron is matched when a table entry matches a lookup string (the lookup
10108 1.1 tron result is ignored). Continue long lines by starting the next line
10109 1.1 tron with whitespace. Specify "!pattern" to exclude an address or network
10110 1.1 tron block from the list. The form "!/file/name" is supported only in
10111 1.1 tron Postfix version 2.4 and later. </p>
10112 1.1 tron
10113 1.1 tron <p> Note: IP version 6 address information must be specified inside
10114 1.1 tron <tt>[]</tt> in the <a href="postconf.5.html#smtpd_authorized_verp_clients">smtpd_authorized_verp_clients</a> value, and in
10115 1.1 tron files specified with "/file/name". IP version 6 addresses contain
10116 1.1 tron the ":" character, and would otherwise be confused with a "<a href="DATABASE_README.html">type:table</a>"
10117 1.1 tron pattern. </p>
10118 1.1 tron
10119 1.1 tron
10120 1.1 tron </DD>
10121 1.1 tron
10122 1.1 tron <DT><b><a name="smtpd_authorized_xclient_hosts">smtpd_authorized_xclient_hosts</a>
10123 1.1 tron (default: empty)</b></DT><DD>
10124 1.1 tron
10125 1.1 tron <p>
10126 1.1 tron What SMTP clients are allowed to use the XCLIENT feature. This
10127 1.1 tron command overrides SMTP client information that is used for access
10128 1.1 tron control. Typical use is for SMTP-based content filters, fetchmail-like
10129 1.1 tron programs, or SMTP server access rule testing. See the <a href="XCLIENT_README.html">XCLIENT_README</a>
10130 1.1 tron document for details.
10131 1.1 tron </p>
10132 1.1 tron
10133 1.1 tron <p>
10134 1.1 tron This feature is available in Postfix 2.1 and later.
10135 1.1 tron </p>
10136 1.1 tron
10137 1.1 tron <p>
10138 1.1 tron By default, no clients are allowed to specify XCLIENT.
10139 1.1 tron </p>
10140 1.1 tron
10141 1.1 tron <p>
10142 1.1 tron Specify a list of network/netmask patterns, separated by commas
10143 1.1 tron and/or whitespace. The mask specifies the number of bits in the
10144 1.1 tron network part of a host address. You can also specify hostnames or
10145 1.1 tron .domain names (the initial dot causes the domain to match any name
10146 1.1 tron below it), "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns. A "/file/name"
10147 1.1 tron pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table
10148 1.1 tron is matched when a table entry matches a lookup string (the lookup
10149 1.1 tron result is ignored). Continue long lines by starting the next line
10150 1.1 tron with whitespace. Specify "!pattern" to exclude an address or network
10151 1.1 tron block from the list. The form "!/file/name" is supported only in
10152 1.1 tron Postfix version 2.4 and later. </p>
10153 1.1 tron
10154 1.1 tron <p> Note: IP version 6 address information must be specified inside
10155 1.1 tron <tt>[]</tt> in the <a href="postconf.5.html#smtpd_authorized_xclient_hosts">smtpd_authorized_xclient_hosts</a> value, and in
10156 1.1 tron files specified with "/file/name". IP version 6 addresses contain
10157 1.1 tron the ":" character, and would otherwise be confused with a "<a href="DATABASE_README.html">type:table</a>"
10158 1.1 tron pattern. </p>
10159 1.1 tron
10160 1.1 tron
10161 1.1 tron </DD>
10162 1.1 tron
10163 1.1 tron <DT><b><a name="smtpd_authorized_xforward_hosts">smtpd_authorized_xforward_hosts</a>
10164 1.1 tron (default: empty)</b></DT><DD>
10165 1.1 tron
10166 1.1 tron <p>
10167 1.1 tron What SMTP clients are allowed to use the XFORWARD feature. This
10168 1.1 tron command forwards information that is used to improve logging after
10169 1.1 tron SMTP-based content filters. See the <a href="XFORWARD_README.html">XFORWARD_README</a> document for
10170 1.1 tron details.
10171 1.1 tron </p>
10172 1.1 tron
10173 1.1 tron <p>
10174 1.1 tron This feature is available in Postfix 2.1 and later.
10175 1.1 tron </p>
10176 1.1 tron
10177 1.1 tron <p>
10178 1.1 tron By default, no clients are allowed to specify XFORWARD.
10179 1.1 tron </p>
10180 1.1 tron
10181 1.1 tron <p>
10182 1.1 tron Specify a list of network/netmask patterns, separated by commas
10183 1.1 tron and/or whitespace. The mask specifies the number of bits in the
10184 1.1 tron network part of a host address. You can also specify hostnames or
10185 1.1 tron .domain names (the initial dot causes the domain to match any name
10186 1.1 tron below it), "/file/name" or "<a href="DATABASE_README.html">type:table</a>" patterns. A "/file/name"
10187 1.1 tron pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table
10188 1.1 tron is matched when a table entry matches a lookup string (the lookup
10189 1.1 tron result is ignored). Continue long lines by starting the next line
10190 1.1 tron with whitespace. Specify "!pattern" to exclude an address or network
10191 1.1 tron block from the list. The form "!/file/name" is supported only in
10192 1.1 tron Postfix version 2.4 and later. </p>
10193 1.1 tron
10194 1.1 tron <p> Note: IP version 6 address information must be specified inside
10195 1.1 tron <tt>[]</tt> in the <a href="postconf.5.html#smtpd_authorized_xforward_hosts">smtpd_authorized_xforward_hosts</a> value, and in
10196 1.1 tron files specified with "/file/name". IP version 6 addresses contain
10197 1.1 tron the ":" character, and would otherwise be confused with a "<a href="DATABASE_README.html">type:table</a>"
10198 1.1 tron pattern. </p>
10199 1.1 tron
10200 1.1 tron
10201 1.1 tron </DD>
10202 1.1 tron
10203 1.1 tron <DT><b><a name="smtpd_banner">smtpd_banner</a>
10204 1.1 tron (default: $<a href="postconf.5.html#myhostname">myhostname</a> ESMTP $<a href="postconf.5.html#mail_name">mail_name</a>)</b></DT><DD>
10205 1.1 tron
10206 1.1 tron <p>
10207 1.1 tron The text that follows the 220 status code in the SMTP greeting
10208 1.1 tron banner. Some people like to see the mail version advertised. By
10209 1.1 tron default, Postfix shows no version.
10210 1.1 tron </p>
10211 1.1 tron
10212 1.1 tron <p>
10213 1.1 tron You MUST specify $<a href="postconf.5.html#myhostname">myhostname</a> at the start of the text. This is
10214 1.1 tron required by the SMTP protocol.
10215 1.1 tron </p>
10216 1.1 tron
10217 1.1 tron <p>
10218 1.1 tron Example:
10219 1.1 tron </p>
10220 1.1 tron
10221 1.1 tron <pre>
10222 1.1 tron <a href="postconf.5.html#smtpd_banner">smtpd_banner</a> = $<a href="postconf.5.html#myhostname">myhostname</a> ESMTP $<a href="postconf.5.html#mail_name">mail_name</a> ($<a href="postconf.5.html#mail_version">mail_version</a>)
10223 1.1 tron </pre>
10224 1.1 tron
10225 1.1 tron
10226 1.1 tron </DD>
10227 1.1 tron
10228 1.1 tron <DT><b><a name="smtpd_client_connection_count_limit">smtpd_client_connection_count_limit</a>
10229 1.1 tron (default: 50)</b></DT><DD>
10230 1.1 tron
10231 1.1 tron <p>
10232 1.1 tron How many simultaneous connections any client is allowed to
10233 1.1 tron make to this service. By default, the limit is set to half
10234 1.1 tron the default process limit value.
10235 1.1 tron </p>
10236 1.1 tron
10237 1.1 tron <p>
10238 1.1 tron To disable this feature, specify a limit of 0.
10239 1.1 tron </p>
10240 1.1 tron
10241 1.1 tron <p>
10242 1.1 tron WARNING: The purpose of this feature is to limit abuse. It must
10243 1.1 tron not be used to regulate legitimate mail traffic.
10244 1.1 tron </p>
10245 1.1 tron
10246 1.1 tron <p>
10247 1.1 tron This feature is available in Postfix 2.2 and later.
10248 1.1 tron </p>
10249 1.1 tron
10250 1.1 tron
10251 1.1 tron </DD>
10252 1.1 tron
10253 1.1 tron <DT><b><a name="smtpd_client_connection_rate_limit">smtpd_client_connection_rate_limit</a>
10254 1.1 tron (default: 0)</b></DT><DD>
10255 1.1 tron
10256 1.1 tron <p>
10257 1.1 tron The maximal number of connection attempts any client is allowed to
10258 1.1 tron make to this service per time unit. The time unit is specified
10259 1.1 tron with the <a href="postconf.5.html#anvil_rate_time_unit">anvil_rate_time_unit</a> configuration parameter.
10260 1.1 tron </p>
10261 1.1 tron
10262 1.1 tron <p>
10263 1.1 tron By default, a client can make as many connections per time unit as
10264 1.1 tron Postfix can accept.
10265 1.1 tron </p>
10266 1.1 tron
10267 1.1 tron <p>
10268 1.1 tron To disable this feature, specify a limit of 0.
10269 1.1 tron </p>
10270 1.1 tron
10271 1.1 tron <p>
10272 1.1 tron WARNING: The purpose of this feature is to limit abuse. It must
10273 1.1 tron not be used to regulate legitimate mail traffic.
10274 1.1 tron </p>
10275 1.1 tron
10276 1.1 tron <p>
10277 1.1 tron This feature is available in Postfix 2.2 and later.
10278 1.1 tron </p>
10279 1.1 tron
10280 1.1 tron <p>
10281 1.1 tron Example:
10282 1.1 tron </p>
10283 1.1 tron
10284 1.1 tron <pre>
10285 1.1 tron <a href="postconf.5.html#smtpd_client_connection_rate_limit">smtpd_client_connection_rate_limit</a> = 1000
10286 1.1 tron </pre>
10287 1.1 tron
10288 1.1 tron
10289 1.1 tron </DD>
10290 1.1 tron
10291 1.1 tron <DT><b><a name="smtpd_client_event_limit_exceptions">smtpd_client_event_limit_exceptions</a>
10292 1.1 tron (default: $<a href="postconf.5.html#mynetworks">mynetworks</a>)</b></DT><DD>
10293 1.1 tron
10294 1.1 tron <p>
10295 1.1 tron Clients that are excluded from connection count, connection rate,
10296 1.1 tron or SMTP request rate restrictions. See the <a href="postconf.5.html#mynetworks">mynetworks</a> parameter
10297 1.1 tron description for the parameter value syntax.
10298 1.1 tron </p>
10299 1.1 tron
10300 1.1 tron <p>
10301 1.1 tron By default, clients in trusted networks are excluded. Specify a
10302 1.1 tron list of network blocks, hostnames or .domain names (the initial
10303 1.1 tron dot causes the domain to match any name below it).
10304 1.1 tron </p>
10305 1.1 tron
10306 1.1 tron <p> Note: IP version 6 address information must be specified inside
10307 1.1 tron <tt>[]</tt> in the <a href="postconf.5.html#smtpd_client_event_limit_exceptions">smtpd_client_event_limit_exceptions</a> value, and
10308 1.1 tron in files specified with "/file/name". IP version 6 addresses
10309 1.1 tron contain the ":" character, and would otherwise be confused with a
10310 1.1 tron "<a href="DATABASE_README.html">type:table</a>" pattern. </p>
10311 1.1 tron
10312 1.1 tron <p>
10313 1.1 tron This feature is available in Postfix 2.2 and later.
10314 1.1 tron </p>
10315 1.1 tron
10316 1.1 tron
10317 1.1 tron </DD>
10318 1.1 tron
10319 1.1 tron <DT><b><a name="smtpd_client_message_rate_limit">smtpd_client_message_rate_limit</a>
10320 1.1 tron (default: 0)</b></DT><DD>
10321 1.1 tron
10322 1.1 tron <p>
10323 1.1 tron The maximal number of message delivery requests that any client is
10324 1.1 tron allowed to make to this service per time unit, regardless of whether
10325 1.1 tron or not Postfix actually accepts those messages. The time unit is
10326 1.1 tron specified with the <a href="postconf.5.html#anvil_rate_time_unit">anvil_rate_time_unit</a> configuration parameter.
10327 1.1 tron </p>
10328 1.1 tron
10329 1.1 tron <p>
10330 1.1 tron By default, a client can send as many message delivery requests
10331 1.1 tron per time unit as Postfix can accept.
10332 1.1 tron </p>
10333 1.1 tron
10334 1.1 tron <p>
10335 1.1 tron To disable this feature, specify a limit of 0.
10336 1.1 tron </p>
10337 1.1 tron
10338 1.1 tron <p>
10339 1.1 tron WARNING: The purpose of this feature is to limit abuse. It must
10340 1.1 tron not be used to regulate legitimate mail traffic.
10341 1.1 tron </p>
10342 1.1 tron
10343 1.1 tron <p>
10344 1.1 tron This feature is available in Postfix 2.2 and later.
10345 1.1 tron </p>
10346 1.1 tron
10347 1.1 tron <p>
10348 1.1 tron Example:
10349 1.1 tron </p>
10350 1.1 tron
10351 1.1 tron <pre>
10352 1.1 tron <a href="postconf.5.html#smtpd_client_message_rate_limit">smtpd_client_message_rate_limit</a> = 1000
10353 1.1 tron </pre>
10354 1.1 tron
10355 1.1 tron
10356 1.1 tron </DD>
10357 1.1 tron
10358 1.1 tron <DT><b><a name="smtpd_client_new_tls_session_rate_limit">smtpd_client_new_tls_session_rate_limit</a>
10359 1.1 tron (default: 0)</b></DT><DD>
10360 1.1 tron
10361 1.1 tron <p>
10362 1.1 tron The maximal number of new (i.e., uncached) TLS sessions that a
10363 1.1 tron remote SMTP client is allowed to negotiate with this service per
10364 1.1 tron time unit. The time unit is specified with the <a href="postconf.5.html#anvil_rate_time_unit">anvil_rate_time_unit</a>
10365 1.1 tron configuration parameter.
10366 1.1 tron </p>
10367 1.1 tron
10368 1.1 tron <p>
10369 1.1 tron By default, a remote SMTP client can negotiate as many new TLS
10370 1.1 tron sessions per time unit as Postfix can accept.
10371 1.1 tron </p>
10372 1.1 tron
10373 1.1 tron <p>
10374 1.1 tron To disable this feature, specify a limit of 0. Otherwise, specify
10375 1.1 tron a limit that is at least the per-client concurrent session limit,
10376 1.1 tron or else legitimate client sessions may be rejected.
10377 1.1 tron </p>
10378 1.1 tron
10379 1.1 tron <p>
10380 1.1 tron WARNING: The purpose of this feature is to limit abuse. It must
10381 1.1 tron not be used to regulate legitimate mail traffic.
10382 1.1 tron </p>
10383 1.1 tron
10384 1.1 tron <p>
10385 1.1 tron This feature is available in Postfix 2.3 and later.
10386 1.1 tron </p>
10387 1.1 tron
10388 1.1 tron <p>
10389 1.1 tron Example:
10390 1.1 tron </p>
10391 1.1 tron
10392 1.1 tron <pre>
10393 1.1 tron <a href="postconf.5.html#smtpd_client_new_tls_session_rate_limit">smtpd_client_new_tls_session_rate_limit</a> = 100
10394 1.1 tron </pre>
10395 1.1 tron
10396 1.1 tron
10397 1.1 tron </DD>
10398 1.1 tron
10399 1.1 tron <DT><b><a name="smtpd_client_port_logging">smtpd_client_port_logging</a>
10400 1.1 tron (default: no)</b></DT><DD>
10401 1.1 tron
10402 1.1 tron <p> Enable logging of the remote SMTP client port in addition to
10403 1.1 tron the hostname and IP address. The logging format is "host[address]:port".
10404 1.1 tron </p>
10405 1.1 tron
10406 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
10407 1.1 tron
10408 1.1 tron
10409 1.1 tron </DD>
10410 1.1 tron
10411 1.1 tron <DT><b><a name="smtpd_client_recipient_rate_limit">smtpd_client_recipient_rate_limit</a>
10412 1.1 tron (default: 0)</b></DT><DD>
10413 1.1 tron
10414 1.1 tron <p>
10415 1.1 tron The maximal number of recipient addresses that any client is allowed
10416 1.1 tron to send to this service per time unit, regardless of whether or not
10417 1.1 tron Postfix actually accepts those recipients. The time unit is specified
10418 1.1 tron with the <a href="postconf.5.html#anvil_rate_time_unit">anvil_rate_time_unit</a> configuration parameter.
10419 1.1 tron </p>
10420 1.1 tron
10421 1.1 tron <p>
10422 1.1 tron By default, a client can make as many recipient addresses per time
10423 1.1 tron unit as Postfix can accept.
10424 1.1 tron </p>
10425 1.1 tron
10426 1.1 tron <p>
10427 1.1 tron To disable this feature, specify a limit of 0.
10428 1.1 tron </p>
10429 1.1 tron
10430 1.1 tron <p>
10431 1.1 tron WARNING: The purpose of this feature is to limit abuse. It must
10432 1.1 tron not be used to regulate legitimate mail traffic.
10433 1.1 tron </p>
10434 1.1 tron
10435 1.1 tron <p>
10436 1.1 tron This feature is available in Postfix 2.2 and later.
10437 1.1 tron </p>
10438 1.1 tron
10439 1.1 tron <p>
10440 1.1 tron Example:
10441 1.1 tron </p>
10442 1.1 tron
10443 1.1 tron <pre>
10444 1.1 tron <a href="postconf.5.html#smtpd_client_recipient_rate_limit">smtpd_client_recipient_rate_limit</a> = 1000
10445 1.1 tron </pre>
10446 1.1 tron
10447 1.1 tron
10448 1.1 tron </DD>
10449 1.1 tron
10450 1.1 tron <DT><b><a name="smtpd_client_restrictions">smtpd_client_restrictions</a>
10451 1.1 tron (default: empty)</b></DT><DD>
10452 1.1 tron
10453 1.1 tron <p>
10454 1.1 tron Optional SMTP server access restrictions in the context of a client
10455 1.1 tron SMTP connection request.
10456 1.1 tron See <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, section "Delayed evaluation of SMTP access
10457 1.1 tron restriction lists" for a discussion of evaluation context and time.
10458 1.1 tron </p>
10459 1.1 tron
10460 1.1 tron <p>
10461 1.1 tron The default is to allow all connection requests.
10462 1.1 tron </p>
10463 1.1 tron
10464 1.1 tron <p>
10465 1.1 tron Specify a list of restrictions, separated by commas and/or whitespace.
10466 1.1 tron Continue long lines by starting the next line with whitespace.
10467 1.1 tron Restrictions are applied in the order as specified; the first
10468 1.1 tron restriction that matches wins.
10469 1.1 tron </p>
10470 1.1 tron
10471 1.1 tron <p>
10472 1.1 tron The following restrictions are specific to client hostname or
10473 1.1 tron client network address information.
10474 1.1 tron </p>
10475 1.1 tron
10476 1.1 tron <dl>
10477 1.1 tron
10478 1.1 tron <dt><b><a name="check_ccert_access">check_ccert_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
10479 1.1 tron
10480 1.1 tron <dd> Use the client certificate fingerprint as lookup key for the
10481 1.1 tron specified <a href="access.5.html">access(5)</a> database; with Postfix version 2.2, also require that
10482 1.1 tron the SMTP client certificate is verified successfully.
10483 1.1 tron The fingerprint digest algorithm is configurable via the
10484 1.1 tron <a href="postconf.5.html#smtpd_tls_fingerprint_digest">smtpd_tls_fingerprint_digest</a> parameter (hard-coded as md5 prior to
10485 1.1 tron Postfix version 2.5). This feature is available with Postfix version
10486 1.1 tron 2.2 and later. </dd>
10487 1.1 tron
10488 1.1 tron <dt><b><a name="check_client_access">check_client_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
10489 1.1 tron
10490 1.1 tron <dd>Search the specified access database for the client hostname,
10491 1.1 tron parent domains, client IP address, or networks obtained by stripping
10492 1.1 tron least significant octets. See the <a href="access.5.html">access(5)</a> manual page for details. </dd>
10493 1.1 tron
10494 1.1 tron <dt><b><a name="check_reverse_client_hostname_access">check_reverse_client_hostname_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
10495 1.1 tron
10496 1.1 tron <dd>Search the specified access database for the unverified reverse
10497 1.1 tron client hostname, parent domains, client IP address, or networks
10498 1.1 tron obtained by stripping least significant octets. See the <a href="access.5.html">access(5)</a>
10499 1.1 tron manual page for details. Note: a result of "OK" is not allowed for
10500 1.1 tron safety reasons. Instead, use DUNNO in order to exclude specific
10501 1.1 tron hosts from blacklists. This feature is available in Postfix 2.6
10502 1.1 tron and later.</dd>
10503 1.1 tron
10504 1.1 tron <dt><b><a name="permit_inet_interfaces">permit_inet_interfaces</a></b></dt>
10505 1.1 tron
10506 1.1 tron <dd>Permit the request when the client IP address matches
10507 1.1 tron $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>. </dd>
10508 1.1 tron
10509 1.1 tron <dt><b><a name="permit_mynetworks">permit_mynetworks</a></b></dt>
10510 1.1 tron
10511 1.1 tron <dd>Permit the request when the client IP address matches any
10512 1.1 tron network or network address listed in $<a href="postconf.5.html#mynetworks">mynetworks</a>. </dd>
10513 1.1 tron
10514 1.1 tron <dt><b><a name="permit_sasl_authenticated">permit_sasl_authenticated</a></b></dt>
10515 1.1 tron
10516 1.1 tron <dd> Permit the request when the client is successfully
10517 1.1 tron authenticated via the <a href="http://tools.ietf.org/html/rfc4954">RFC 4954</a> (AUTH) protocol. </dd>
10518 1.1 tron
10519 1.1 tron <dt><b><a name="permit_tls_all_clientcerts">permit_tls_all_clientcerts</a></b></dt>
10520 1.1 tron
10521 1.1 tron <dd> Permit the request when the remote SMTP client certificate is
10522 1.1 tron verified successfully. This option must be used only if a special
10523 1.1 tron CA issues the certificates and only this CA is listed as trusted
10524 1.1 tron CA, otherwise all clients with a recognized certificate would be
10525 1.1 tron allowed to relay. This feature is available with Postfix version 2.2.</dd>
10526 1.1 tron
10527 1.1 tron <dt><b><a name="permit_tls_clientcerts">permit_tls_clientcerts</a></b></dt>
10528 1.1 tron
10529 1.1 tron <dd>Permit the request when the remote SMTP client certificate
10530 1.1 tron fingerprint is listed in $<a href="postconf.5.html#relay_clientcerts">relay_clientcerts</a>.
10531 1.1 tron The fingerprint digest algorithm is configurable via the
10532 1.1 tron <a href="postconf.5.html#smtpd_tls_fingerprint_digest">smtpd_tls_fingerprint_digest</a> parameter (hard-coded as md5 prior to
10533 1.1 tron Postfix version 2.5). This feature is available with Postfix version
10534 1.1 tron 2.2. </dd>
10535 1.1 tron
10536 1.1 tron <dt><b><a name="reject_rbl_client">reject_rbl_client <i>rbl_domain=d.d.d.d</i></a></b></dt>
10537 1.1 tron
10538 1.1 tron <dd>Reject the request when the reversed client network address is
10539 1.1 tron listed with the A record "<i>d.d.d.d</i>" under <i>rbl_domain</i>
10540 1.1 tron (Postfix version 2.1 and later only). If no "<i>=d.d.d.d</i>" is
10541 1.1 tron specified, reject the request when the reversed client network
10542 1.1 tron address is listed with any A record under <i>rbl_domain</i>. <br>
10543 1.1 tron The <a href="postconf.5.html#maps_rbl_reject_code">maps_rbl_reject_code</a> parameter specifies the response code for
10544 1.1 tron rejected requests (default: 554), the <a href="postconf.5.html#default_rbl_reply">default_rbl_reply</a> parameter
10545 1.1 tron specifies the default server reply, and the <a href="postconf.5.html#rbl_reply_maps">rbl_reply_maps</a> parameter
10546 1.1 tron specifies tables with server replies indexed by <i>rbl_domain</i>.
10547 1.1 tron This feature is available in Postfix 2.0 and later. </dd>
10548 1.1 tron
10549 1.1 tron <dt><b><a name="reject_rhsbl_client">reject_rhsbl_client <i>rbl_domain=d.d.d.d</i></a></b></dt>
10550 1.1 tron
10551 1.1 tron <dd>Reject the request when the client hostname is listed with the
10552 1.1 tron A record "<i>d.d.d.d</i>" under <i>rbl_domain</i> (Postfix version
10553 1.1 tron 2.1 and later only). If no "<i>=d.d.d.d</i>" is specified, reject
10554 1.1 tron the request when the client hostname is listed with
10555 1.1 tron any A record under <i>rbl_domain</i>. See the <a href="postconf.5.html#reject_rbl_client">reject_rbl_client</a>
10556 1.1 tron description above for additional RBL related configuration parameters.
10557 1.1 tron This feature is available in Postfix 2.0 and later. </dd>
10558 1.1 tron
10559 1.1 tron <dt><b><a name="reject_unknown_client_hostname">reject_unknown_client_hostname</a></b> (with Postfix < 2.3: reject_unknown_client)</dt>
10560 1.1 tron
10561 1.1 tron <dd>Reject the request when 1) the client IP address->name mapping
10562 1.1 tron fails, 2) the name->address mapping fails, or 3) the name->address
10563 1.1 tron mapping does not match the client IP address. <br> This is a
10564 1.1 tron stronger restriction than the <a href="postconf.5.html#reject_unknown_reverse_client_hostname">reject_unknown_reverse_client_hostname</a>
10565 1.1 tron feature, which triggers only under condition 1) above. <br> The
10566 1.1 tron <a href="postconf.5.html#unknown_client_reject_code">unknown_client_reject_code</a> parameter specifies the response code
10567 1.1 tron for rejected requests (default: 450). The reply is always 450 in
10568 1.1 tron case the address->name or name->address lookup failed due to
10569 1.1 tron a temporary problem. </dd>
10570 1.1 tron
10571 1.1 tron <dt><b><a name="reject_unknown_reverse_client_hostname">reject_unknown_reverse_client_hostname</a></b></dt>
10572 1.1 tron
10573 1.1 tron <dd>Reject the request when the client IP address has no address->name
10574 1.1 tron mapping. <br> This is a weaker restriction than the
10575 1.1 tron <a href="postconf.5.html#reject_unknown_client_hostname">reject_unknown_client_hostname</a> feature, which requires not only
10576 1.1 tron that the address->name and name->address mappings exist, but
10577 1.1 tron also that the two mappings reproduce the client IP address. <br>
10578 1.1 tron The <a href="postconf.5.html#unknown_client_reject_code">unknown_client_reject_code</a> parameter specifies the response
10579 1.1 tron code for rejected requests (default: 450). The reply is always 450
10580 1.1 tron in case the address->name lookup failed due to a temporary
10581 1.1 tron problem. <br> This feature is available in Postfix 2.3 and
10582 1.1 tron later. </dd>
10583 1.1 tron
10584 1.1 tron </dl>
10585 1.1 tron
10586 1.1 tron <p>
10587 1.1 tron In addition, you can use any of the following <a name="generic">
10588 1.1 tron generic</a> restrictions. These restrictions are applicable in
10589 1.1 tron any SMTP command context.
10590 1.1 tron </p>
10591 1.1 tron
10592 1.1 tron <dl>
10593 1.1 tron
10594 1.1 tron <dt><b><a name="check_policy_service">check_policy_service <i>servername</i></a></b></dt>
10595 1.1 tron
10596 1.1 tron <dd>Query the specified policy server. See the <a href="SMTPD_POLICY_README.html">SMTPD_POLICY_README</a>
10597 1.1 tron document for details. This feature is available in Postfix 2.1
10598 1.1 tron and later. </dd>
10599 1.1 tron
10600 1.1 tron <dt><b><a name="defer">defer</a></b></dt>
10601 1.1 tron
10602 1.1 tron <dd>Defer the request. The client is told to try again later. This
10603 1.1 tron restriction is useful at the end of a restriction list, to make
10604 1.1 tron the default policy explicit. <br> The <a href="postconf.5.html#defer_code">defer_code</a> parameter specifies
10605 1.1 tron the SMTP server reply code (default: 450).</dd>
10606 1.1 tron
10607 1.1 tron <dt><b><a name="defer_if_permit">defer_if_permit</a></b></dt>
10608 1.1 tron
10609 1.1 tron <dd>Defer the request if some later restriction would result in an
10610 1.1 tron explicit or implicit PERMIT action. This is useful when a blacklisting
10611 1.1 tron feature fails due to a temporary problem. This feature is available
10612 1.1 tron in Postfix version 2.1 and later. </dd>
10613 1.1 tron
10614 1.1 tron <dt><b><a name="defer_if_reject">defer_if_reject</a></b></dt>
10615 1.1 tron
10616 1.1 tron <dd>Defer the request if some later restriction would result in a
10617 1.1 tron REJECT action. This is useful when a whitelisting feature fails
10618 1.1 tron due to a temporary problem. This feature is available in Postfix
10619 1.1 tron version 2.1 and later. </dd>
10620 1.1 tron
10621 1.1 tron <dt><b><a name="permit">permit</a></b></dt>
10622 1.1 tron
10623 1.1 tron <dd>Permit the request. This restriction is useful at the end of
10624 1.1 tron a restriction list, to make the default policy explicit.</dd>
10625 1.1 tron
10626 1.1 tron <dt><b><a name="reject_multi_recipient_bounce">reject_multi_recipient_bounce</a></b></dt>
10627 1.1 tron
10628 1.1 tron <dd>Reject the request when the envelope sender is the null address,
10629 1.1 tron and the message has multiple envelope recipients. This usage has
10630 1.1 tron rare but legitimate applications: under certain conditions,
10631 1.1 tron multi-recipient mail that was posted with the DSN option NOTIFY=NEVER
10632 1.1 tron may be forwarded with the null sender address.
10633 1.1 tron <br> Note: this restriction can only work reliably
10634 1.1 tron when used in <a href="postconf.5.html#smtpd_data_restrictions">smtpd_data_restrictions</a> or
10635 1.1 tron <a href="postconf.5.html#smtpd_end_of_data_restrictions">smtpd_end_of_data_restrictions</a>, because the total number of
10636 1.1 tron recipients is not known at an earlier stage of the SMTP conversation.
10637 1.1 tron Use at the RCPT stage will only reject the second etc. recipient.
10638 1.1 tron <br>
10639 1.1 tron The <a href="postconf.5.html#multi_recipient_bounce_reject_code">multi_recipient_bounce_reject_code</a> parameter specifies the
10640 1.1 tron response code for rejected requests (default: 550). This feature
10641 1.1 tron is available in Postfix 2.1 and later. </dd>
10642 1.1 tron
10643 1.1 tron <dt><b><a name="reject_plaintext_session">reject_plaintext_session</a></b></dt>
10644 1.1 tron
10645 1.1 tron <dd>Reject the request when the connection is not encrypted. This
10646 1.1 tron restriction should not be used before the client has had a chance
10647 1.1 tron to negotiate encryption with the AUTH or STARTTLS commands.
10648 1.1 tron <br>
10649 1.1 tron The <a href="postconf.5.html#plaintext_reject_code">plaintext_reject_code</a> parameter specifies the response
10650 1.1 tron code for rejected requests (default: 450). This feature is available
10651 1.1 tron in Postfix 2.3 and later. </dd>
10652 1.1 tron
10653 1.1 tron <dt><b><a name="reject_unauth_pipelining">reject_unauth_pipelining</a></b></dt>
10654 1.1 tron
10655 1.1 tron <dd>Reject the request when the client sends SMTP commands ahead
10656 1.1 tron of time where it is not allowed, or when the client sends SMTP
10657 1.1 tron commands ahead of time without knowing that Postfix actually supports
10658 1.1 tron ESMTP command pipelining. This stops mail from bulk mail software
10659 1.1 tron that improperly uses ESMTP command pipelining in order to speed up
10660 1.1.1.2 tron deliveries.
10661 1.1.1.2 tron <br> With Postfix 2.6 and later, the SMTP server sets a per-session
10662 1.1.1.2 tron flag whenever it detects illegal pipelining, including pipelined
10663 1.1.1.2 tron EHLO or HELO commands. The <a href="postconf.5.html#reject_unauth_pipelining">reject_unauth_pipelining</a> feature simply
10664 1.1.1.2 tron tests whether the flag was set at any point in time during the
10665 1.1.1.2 tron session.
10666 1.1.1.2 tron <br> With older Postfix versions, <a href="postconf.5.html#reject_unauth_pipelining">reject_unauth_pipelining</a> checks
10667 1.1.1.2 tron the current status of the input read queue, and its usage is not
10668 1.1.1.2 tron recommended in contexts other than <a href="postconf.5.html#smtpd_data_restrictions">smtpd_data_restrictions</a>. </dd>
10669 1.1 tron
10670 1.1 tron <dt><b><a name="reject">reject</a></b></dt>
10671 1.1 tron
10672 1.1 tron <dd>Reject the request. This restriction is useful at the end of
10673 1.1 tron a restriction list, to make the default policy explicit. The
10674 1.1 tron <a href="postconf.5.html#reject_code">reject_code</a> configuration parameter specifies the response code for
10675 1.1 tron rejected requests (default: 554).</dd>
10676 1.1 tron
10677 1.1 tron <dt><b><a name="sleep">sleep <i>seconds</i></a></b></dt>
10678 1.1 tron
10679 1.1 tron <dd>Pause for the specified number of seconds and proceed with
10680 1.1 tron the next restriction in the list, if any. This may stop zombie
10681 1.1 tron mail when used as:
10682 1.1 tron <pre>
10683 1.1 tron /etc/postfix/<a href="postconf.5.html">main.cf</a>:
10684 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> =
10685 1.1 tron sleep 1, <a href="postconf.5.html#reject_unauth_pipelining">reject_unauth_pipelining</a>
10686 1.1 tron <a href="postconf.5.html#smtpd_delay_reject">smtpd_delay_reject</a> = no
10687 1.1 tron </pre>
10688 1.1 tron This feature is available in Postfix 2.3. </dd>
10689 1.1 tron
10690 1.1 tron <dt><b><a name="warn_if_reject">warn_if_reject</a></b></dt>
10691 1.1 tron
10692 1.1 tron <dd>Change the meaning of the next restriction, so that it logs
10693 1.1 tron a warning instead of rejecting a request (look for logfile records
10694 1.1 tron that contain "reject_warning"). This is useful for testing new
10695 1.1 tron restrictions in a "live" environment without risking unnecessary
10696 1.1 tron loss of mail. </dd>
10697 1.1 tron
10698 1.1 tron </dl>
10699 1.1 tron
10700 1.1 tron <p>
10701 1.1 tron Other restrictions that are valid in this context:
10702 1.1 tron </p>
10703 1.1 tron
10704 1.1 tron <ul>
10705 1.1 tron
10706 1.1 tron <li> SMTP command specific restrictions that are described under
10707 1.1 tron the <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a>, <a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a> or
10708 1.1 tron <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a> parameters. When helo, sender or
10709 1.1 tron recipient restrictions are listed under <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>,
10710 1.1 tron they have effect only with "<a href="postconf.5.html#smtpd_delay_reject">smtpd_delay_reject</a> = yes", so that
10711 1.1 tron $<a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> is evaluated at the time of the RCPT TO
10712 1.1 tron command.
10713 1.1 tron
10714 1.1 tron </ul>
10715 1.1 tron
10716 1.1 tron <p>
10717 1.1 tron Example:
10718 1.1 tron </p>
10719 1.1 tron
10720 1.1 tron <pre>
10721 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> = <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, <a href="postconf.5.html#reject_unknown_client_hostname">reject_unknown_client_hostname</a>
10722 1.1 tron </pre>
10723 1.1 tron
10724 1.1 tron
10725 1.1 tron </DD>
10726 1.1 tron
10727 1.1 tron <DT><b><a name="smtpd_data_restrictions">smtpd_data_restrictions</a>
10728 1.1 tron (default: empty)</b></DT><DD>
10729 1.1 tron
10730 1.1 tron <p>
10731 1.1 tron Optional access restrictions that the Postfix SMTP server applies
10732 1.1 tron in the context of the SMTP DATA command.
10733 1.1 tron See <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, section "Delayed evaluation of SMTP access
10734 1.1 tron restriction lists" for a discussion of evaluation context and time.
10735 1.1 tron </p>
10736 1.1 tron
10737 1.1 tron <p>
10738 1.1 tron This feature is available in Postfix 2.0 and later.
10739 1.1 tron </p>
10740 1.1 tron
10741 1.1 tron <p>
10742 1.1 tron Specify a list of restrictions, separated by commas and/or whitespace.
10743 1.1 tron Continue long lines by starting the next line with whitespace.
10744 1.1 tron Restrictions are applied in the order as specified; the first
10745 1.1 tron restriction that matches wins.
10746 1.1 tron </p>
10747 1.1 tron
10748 1.1 tron <p>
10749 1.1 tron The following restrictions are valid in this context:
10750 1.1 tron </p>
10751 1.1 tron
10752 1.1 tron <ul>
10753 1.1 tron
10754 1.1 tron <li><a href="#generic">Generic</a> restrictions that can be used
10755 1.1 tron in any SMTP command context, described under <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>.
10756 1.1 tron
10757 1.1 tron <li>SMTP command specific restrictions described under
10758 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>, <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a>,
10759 1.1 tron <a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a> or <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a>.
10760 1.1 tron
10761 1.1 tron </ul>
10762 1.1 tron
10763 1.1 tron <p>
10764 1.1 tron Examples:
10765 1.1 tron </p>
10766 1.1 tron
10767 1.1 tron <pre>
10768 1.1 tron <a href="postconf.5.html#smtpd_data_restrictions">smtpd_data_restrictions</a> = <a href="postconf.5.html#reject_unauth_pipelining">reject_unauth_pipelining</a>
10769 1.1 tron <a href="postconf.5.html#smtpd_data_restrictions">smtpd_data_restrictions</a> = <a href="postconf.5.html#reject_multi_recipient_bounce">reject_multi_recipient_bounce</a>
10770 1.1 tron </pre>
10771 1.1 tron
10772 1.1 tron
10773 1.1 tron </DD>
10774 1.1 tron
10775 1.1 tron <DT><b><a name="smtpd_delay_open_until_valid_rcpt">smtpd_delay_open_until_valid_rcpt</a>
10776 1.1 tron (default: yes)</b></DT><DD>
10777 1.1 tron
10778 1.1 tron <p> Postpone the start of an SMTP mail transaction until a valid
10779 1.1 tron RCPT TO command is received. Specify "no" to create a mail transaction
10780 1.1 tron as soon as the SMTP server receives a valid MAIL FROM command. </p>
10781 1.1 tron
10782 1.1 tron <p> With sites that reject lots of mail, the default setting reduces
10783 1.1 tron the use of
10784 1.1 tron disk, CPU and memory resources. The downside is that rejected
10785 1.1 tron recipients are logged with NOQUEUE instead of a mail transaction
10786 1.1 tron ID. This complicates the logfile analysis of multi-recipient mail.
10787 1.1 tron </p>
10788 1.1 tron
10789 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
10790 1.1 tron
10791 1.1 tron
10792 1.1 tron </DD>
10793 1.1 tron
10794 1.1 tron <DT><b><a name="smtpd_delay_reject">smtpd_delay_reject</a>
10795 1.1 tron (default: yes)</b></DT><DD>
10796 1.1 tron
10797 1.1 tron <p>
10798 1.1 tron Wait until the RCPT TO command before evaluating
10799 1.1 tron $<a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>, $<a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a> and
10800 1.1 tron $<a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a>, or wait until the ETRN command before
10801 1.1 tron evaluating $<a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> and $<a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a>.
10802 1.1 tron </p>
10803 1.1 tron
10804 1.1 tron <p>
10805 1.1 tron This feature is turned on by default because some clients apparently
10806 1.1 tron mis-behave when the Postfix SMTP server rejects commands before
10807 1.1 tron RCPT TO.
10808 1.1 tron </p>
10809 1.1 tron
10810 1.1 tron <p>
10811 1.1 tron The default setting has one major benefit: it allows Postfix to log
10812 1.1 tron recipient address information when rejecting a client name/address
10813 1.1 tron or sender address, so that it is possible to find out whose mail
10814 1.1 tron is being rejected.
10815 1.1 tron </p>
10816 1.1 tron
10817 1.1 tron
10818 1.1 tron </DD>
10819 1.1 tron
10820 1.1 tron <DT><b><a name="smtpd_discard_ehlo_keyword_address_maps">smtpd_discard_ehlo_keyword_address_maps</a>
10821 1.1 tron (default: empty)</b></DT><DD>
10822 1.1 tron
10823 1.1 tron <p> Lookup tables, indexed by the remote SMTP client address, with
10824 1.1 tron case insensitive lists of EHLO keywords (pipelining, starttls, auth,
10825 1.1 tron etc.) that the SMTP server will not send in the EHLO response to a
10826 1.1 tron remote SMTP client. See <a href="postconf.5.html#smtpd_discard_ehlo_keywords">smtpd_discard_ehlo_keywords</a> for details.
10827 1.1 tron The table is not searched by hostname for robustness reasons. </p>
10828 1.1 tron
10829 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
10830 1.1 tron
10831 1.1 tron
10832 1.1 tron </DD>
10833 1.1 tron
10834 1.1 tron <DT><b><a name="smtpd_discard_ehlo_keywords">smtpd_discard_ehlo_keywords</a>
10835 1.1 tron (default: empty)</b></DT><DD>
10836 1.1 tron
10837 1.1 tron <p> A case insensitive list of EHLO keywords (pipelining, starttls,
10838 1.1 tron auth, etc.) that the SMTP server will not send in the EHLO response
10839 1.1 tron to a remote SMTP client. </p>
10840 1.1 tron
10841 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
10842 1.1 tron
10843 1.1 tron <p> Notes: </p>
10844 1.1 tron
10845 1.1 tron <ul>
10846 1.1 tron
10847 1.1 tron <li> <p> Specify the <b>silent-discard</b> pseudo keyword to prevent
10848 1.1 tron this action from being logged. </p>
10849 1.1 tron
10850 1.1 tron <li> <p> Use the <a href="postconf.5.html#smtpd_discard_ehlo_keyword_address_maps">smtpd_discard_ehlo_keyword_address_maps</a> feature
10851 1.1 tron to discard EHLO keywords selectively. </p>
10852 1.1 tron
10853 1.1 tron </ul>
10854 1.1 tron
10855 1.1 tron
10856 1.1 tron </DD>
10857 1.1 tron
10858 1.1 tron <DT><b><a name="smtpd_end_of_data_restrictions">smtpd_end_of_data_restrictions</a>
10859 1.1 tron (default: empty)</b></DT><DD>
10860 1.1 tron
10861 1.1 tron <p> Optional access restrictions that the Postfix SMTP server
10862 1.1 tron applies in the context of the SMTP END-OF-DATA command.
10863 1.1 tron See <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, section "Delayed evaluation of SMTP access
10864 1.1 tron restriction lists" for a discussion of evaluation context and time.
10865 1.1 tron </p>
10866 1.1 tron
10867 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
10868 1.1 tron
10869 1.1 tron <p> See <a href="postconf.5.html#smtpd_data_restrictions">smtpd_data_restrictions</a> for syntax details. </p>
10870 1.1 tron
10871 1.1 tron
10872 1.1 tron </DD>
10873 1.1 tron
10874 1.1 tron <DT><b><a name="smtpd_enforce_tls">smtpd_enforce_tls</a>
10875 1.1 tron (default: no)</b></DT><DD>
10876 1.1 tron
10877 1.1 tron <p> Mandatory TLS: announce STARTTLS support to SMTP clients,
10878 1.1 tron and require that clients use TLS encryption. According to <a href="http://tools.ietf.org/html/rfc2487">RFC 2487</a>
10879 1.1 tron this MUST NOT be applied in case of a publicly-referenced SMTP
10880 1.1 tron server. This option is off by default and should be used only on
10881 1.1 tron dedicated servers. </p>
10882 1.1 tron
10883 1.1 tron <p> Note 1: "<a href="postconf.5.html#smtpd_enforce_tls">smtpd_enforce_tls</a> = yes" implies "<a href="postconf.5.html#smtpd_tls_auth_only">smtpd_tls_auth_only</a> = yes". </p>
10884 1.1 tron
10885 1.1 tron <p> Note 2: when invoked via "<b>sendmail -bs</b>", Postfix will never offer
10886 1.1 tron STARTTLS due to insufficient privileges to access the server private
10887 1.1 tron key. This is intended behavior. </p>
10888 1.1 tron
10889 1.1 tron <p> This feature is available in Postfix 2.2 and later. With
10890 1.1 tron Postfix 2.3 and later use <a href="postconf.5.html#smtpd_tls_security_level">smtpd_tls_security_level</a> instead. </p>
10891 1.1 tron
10892 1.1 tron
10893 1.1 tron </DD>
10894 1.1 tron
10895 1.1 tron <DT><b><a name="smtpd_error_sleep_time">smtpd_error_sleep_time</a>
10896 1.1 tron (default: 1s)</b></DT><DD>
10897 1.1 tron
10898 1.1 tron <p>With Postfix version 2.1 and later: the SMTP server response delay after
10899 1.1 tron a client has made more than $<a href="postconf.5.html#smtpd_soft_error_limit">smtpd_soft_error_limit</a> errors, and
10900 1.1 tron fewer than $<a href="postconf.5.html#smtpd_hard_error_limit">smtpd_hard_error_limit</a> errors, without delivering mail.
10901 1.1 tron </p>
10902 1.1 tron
10903 1.1 tron <p>With Postfix version 2.0 and earlier: the SMTP server delay before
10904 1.1 tron sending a reject (4xx or 5xx) response, when the client has made
10905 1.1 tron fewer than $<a href="postconf.5.html#smtpd_soft_error_limit">smtpd_soft_error_limit</a> errors without delivering
10906 1.1 tron mail. </p>
10907 1.1 tron
10908 1.1 tron
10909 1.1 tron </DD>
10910 1.1 tron
10911 1.1 tron <DT><b><a name="smtpd_etrn_restrictions">smtpd_etrn_restrictions</a>
10912 1.1 tron (default: empty)</b></DT><DD>
10913 1.1 tron
10914 1.1 tron <p>
10915 1.1 tron Optional SMTP server access restrictions in the context of a client
10916 1.1 tron ETRN request.
10917 1.1 tron See <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, section "Delayed evaluation of SMTP access
10918 1.1 tron restriction lists" for a discussion of evaluation context and time.
10919 1.1 tron </p>
10920 1.1 tron
10921 1.1 tron <p>
10922 1.1 tron The Postfix ETRN implementation accepts only destinations that are
10923 1.1 tron eligible for the Postfix "fast flush" service. See the <a href="ETRN_README.html">ETRN_README</a>
10924 1.1 tron file for details.
10925 1.1 tron </p>
10926 1.1 tron
10927 1.1 tron <p>
10928 1.1 tron Specify a list of restrictions, separated by commas and/or whitespace.
10929 1.1 tron Continue long lines by starting the next line with whitespace.
10930 1.1 tron Restrictions are applied in the order as specified; the first
10931 1.1 tron restriction that matches wins.
10932 1.1 tron </p>
10933 1.1 tron
10934 1.1 tron <p>
10935 1.1 tron The following restrictions are specific to the domain name information
10936 1.1 tron received with the ETRN command.
10937 1.1 tron </p>
10938 1.1 tron
10939 1.1 tron <dl>
10940 1.1 tron
10941 1.1 tron <dt><b><a name="check_etrn_access">check_etrn_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
10942 1.1 tron
10943 1.1 tron <dd>Search the specified access database for the ETRN domain name
10944 1.1 tron or its parent domains. See the <a href="access.5.html">access(5)</a> manual page for details.
10945 1.1 tron </dd>
10946 1.1 tron
10947 1.1 tron </dl>
10948 1.1 tron
10949 1.1 tron <p>
10950 1.1 tron Other restrictions that are valid in this context:
10951 1.1 tron </p>
10952 1.1 tron
10953 1.1 tron <ul>
10954 1.1 tron
10955 1.1 tron <li><a href="#generic">Generic</a> restrictions that can be used
10956 1.1 tron in any SMTP command context, described under <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>.
10957 1.1 tron
10958 1.1 tron <li>SMTP command specific restrictions described under
10959 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> and <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a>.
10960 1.1 tron
10961 1.1 tron </ul>
10962 1.1 tron
10963 1.1 tron <p>
10964 1.1 tron Example:
10965 1.1 tron </p>
10966 1.1 tron
10967 1.1 tron <pre>
10968 1.1 tron <a href="postconf.5.html#smtpd_etrn_restrictions">smtpd_etrn_restrictions</a> = <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, reject
10969 1.1 tron </pre>
10970 1.1 tron
10971 1.1 tron
10972 1.1 tron </DD>
10973 1.1 tron
10974 1.1 tron <DT><b><a name="smtpd_expansion_filter">smtpd_expansion_filter</a>
10975 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
10976 1.1 tron
10977 1.1 tron <p>
10978 1.1 tron What characters are allowed in $name expansions of RBL reply
10979 1.1 tron templates. Characters not in the allowed set are replaced by "_".
10980 1.1 tron Use C like escapes to specify special characters such as whitespace.
10981 1.1 tron </p>
10982 1.1 tron
10983 1.1 tron <p>
10984 1.1 tron This parameter is not subjected to $parameter expansion.
10985 1.1 tron </p>
10986 1.1 tron
10987 1.1 tron <p>
10988 1.1 tron This feature is available in Postfix 2.0 and later.
10989 1.1 tron </p>
10990 1.1 tron
10991 1.1 tron
10992 1.1 tron </DD>
10993 1.1 tron
10994 1.1 tron <DT><b><a name="smtpd_forbidden_commands">smtpd_forbidden_commands</a>
10995 1.1 tron (default: CONNECT, GET, POST)</b></DT><DD>
10996 1.1 tron
10997 1.1 tron <p>
10998 1.1 tron List of commands that causes the Postfix SMTP server to immediately
10999 1.1 tron terminate the session with a 221 code. This can be used to disconnect
11000 1.1 tron clients that obviously attempt to abuse the system. In addition to the
11001 1.1 tron commands listed in this parameter, commands that follow the "Label:"
11002 1.1 tron format of message headers will also cause a disconnect.
11003 1.1 tron </p>
11004 1.1 tron
11005 1.1 tron <p>
11006 1.1 tron This feature is available in Postfix 2.2 and later.
11007 1.1 tron </p>
11008 1.1 tron
11009 1.1 tron
11010 1.1 tron </DD>
11011 1.1 tron
11012 1.1 tron <DT><b><a name="smtpd_hard_error_limit">smtpd_hard_error_limit</a>
11013 1.1 tron (default: normal: 20, stress: 1)</b></DT><DD>
11014 1.1 tron
11015 1.1 tron <p>
11016 1.1 tron The maximal number of errors a remote SMTP client is allowed to
11017 1.1 tron make without delivering mail. The Postfix SMTP server disconnects
11018 1.1 tron when the limit is exceeded. Normally the default limit is 20, but
11019 1.1 tron it changes under overload to just 1 with Postfix 2.6 and later.
11020 1.1 tron </p>
11021 1.1 tron
11022 1.1 tron
11023 1.1 tron </DD>
11024 1.1 tron
11025 1.1 tron <DT><b><a name="smtpd_helo_required">smtpd_helo_required</a>
11026 1.1 tron (default: no)</b></DT><DD>
11027 1.1 tron
11028 1.1 tron <p>
11029 1.1 tron Require that a remote SMTP client introduces itself at the beginning
11030 1.1 tron of an SMTP session with the HELO or EHLO command.
11031 1.1 tron </p>
11032 1.1 tron
11033 1.1 tron <p>
11034 1.1 tron Example:
11035 1.1 tron </p>
11036 1.1 tron
11037 1.1 tron <pre>
11038 1.1 tron <a href="postconf.5.html#smtpd_helo_required">smtpd_helo_required</a> = yes
11039 1.1 tron </pre>
11040 1.1 tron
11041 1.1 tron
11042 1.1 tron </DD>
11043 1.1 tron
11044 1.1 tron <DT><b><a name="smtpd_helo_restrictions">smtpd_helo_restrictions</a>
11045 1.1 tron (default: empty)</b></DT><DD>
11046 1.1 tron
11047 1.1 tron <p>
11048 1.1 tron Optional restrictions that the Postfix SMTP server applies in the
11049 1.1 tron context of the SMTP HELO command.
11050 1.1 tron See <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, section "Delayed evaluation of SMTP access
11051 1.1 tron restriction lists" for a discussion of evaluation context and time.
11052 1.1 tron </p>
11053 1.1 tron
11054 1.1 tron <p>
11055 1.1 tron The default is to permit everything.
11056 1.1 tron </p>
11057 1.1 tron
11058 1.1 tron <p>
11059 1.1 tron Specify a list of restrictions, separated by commas and/or whitespace.
11060 1.1 tron Continue long lines by starting the next line with whitespace.
11061 1.1 tron Restrictions are applied in the order as specified; the first
11062 1.1 tron restriction that matches wins.
11063 1.1 tron </p>
11064 1.1 tron
11065 1.1 tron <p>
11066 1.1 tron The following restrictions are specific to the hostname information
11067 1.1 tron received with the HELO or EHLO command.
11068 1.1 tron </p>
11069 1.1 tron
11070 1.1 tron <dl>
11071 1.1 tron
11072 1.1 tron <dt><b><a name="check_helo_access">check_helo_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
11073 1.1 tron
11074 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the HELO or EHLO
11075 1.1 tron hostname or parent domains, and execute the corresponding action.
11076 1.1 tron </dd>
11077 1.1 tron
11078 1.1 tron <dt><b><a name="check_helo_mx_access">check_helo_mx_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
11079 1.1 tron
11080 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the MX hosts for
11081 1.1 tron the HELO or EHLO hostname, and execute the corresponding action.
11082 1.1 tron Note: a result of "OK" is not allowed for safety reasons. Instead,
11083 1.1 tron use DUNNO in order to exclude specific hosts from blacklists. This
11084 1.1 tron feature is available in Postfix 2.1 and later. </dd>
11085 1.1 tron
11086 1.1 tron <dt><b><a name="check_helo_ns_access">check_helo_ns_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
11087 1.1 tron
11088 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the DNS servers
11089 1.1 tron for the HELO or EHLO hostname, and execute the corresponding action.
11090 1.1 tron Note: a result of "OK" is not allowed for safety reasons. Instead,
11091 1.1 tron use DUNNO in order to exclude specific hosts from blacklists. This
11092 1.1 tron feature is available in Postfix 2.1 and later. </dd>
11093 1.1 tron
11094 1.1 tron <dt><b><a name="reject_invalid_helo_hostname">reject_invalid_helo_hostname</a></b> (with Postfix < 2.3: reject_invalid_hostname)</dt>
11095 1.1 tron
11096 1.1 tron <dd>Reject the request when the HELO or EHLO hostname syntax is
11097 1.1 tron invalid. <br> The <a href="postconf.5.html#invalid_hostname_reject_code">invalid_hostname_reject_code</a> specifies the response
11098 1.1 tron code for rejected requests (default: 501).</dd>
11099 1.1 tron
11100 1.1 tron <dt><b><a name="reject_non_fqdn_helo_hostname">reject_non_fqdn_helo_hostname</a></b> (with Postfix < 2.3: reject_non_fqdn_hostname)</dt>
11101 1.1 tron
11102 1.1 tron <dd>Reject the request when the HELO or EHLO hostname is not in
11103 1.1 tron fully-qualified domain form, as required by the RFC. <br> The
11104 1.1 tron <a href="postconf.5.html#non_fqdn_reject_code">non_fqdn_reject_code</a> parameter specifies the response code for
11105 1.1 tron rejected requests (default: 504).</dd>
11106 1.1 tron
11107 1.1 tron <dt><b><a name="reject_rhsbl_helo">reject_rhsbl_helo <i>rbl_domain=d.d.d.d</i></a></b></dt>
11108 1.1 tron
11109 1.1 tron <dd>Reject the request when the HELO or EHLO hostname hostname is
11110 1.1 tron listed with the A record "<i>d.d.d.d</i>" under <i>rbl_domain</i>
11111 1.1 tron (Postfix version 2.1 and later only). If no "<i>=d.d.d.d</i>" is
11112 1.1 tron specified, reject the request when the HELO or EHLO hostname is
11113 1.1 tron listed with any A record under <i>rbl_domain</i>. See the
11114 1.1 tron <a href="postconf.5.html#reject_rbl_client">reject_rbl_client</a> description for additional RBL related configuration
11115 1.1 tron parameters. This feature is available in Postfix 2.0 and later.
11116 1.1 tron </dd>
11117 1.1 tron
11118 1.1 tron <dt><b><a name="reject_unknown_helo_hostname">reject_unknown_helo_hostname</a></b> (with Postfix < 2.3: reject_unknown_hostname)</dt>
11119 1.1 tron
11120 1.1 tron <dd>Reject the request when the HELO or EHLO hostname has no DNS A
11121 1.1 tron or MX record. <br> The <a href="postconf.5.html#unknown_hostname_reject_code">unknown_hostname_reject_code</a> parameter
11122 1.1 tron specifies the numerical response code for rejected requests (default:
11123 1.1 tron 450). <br> The <a href="postconf.5.html#unknown_helo_hostname_tempfail_action">unknown_helo_hostname_tempfail_action</a> parameter
11124 1.1 tron specifies the action after a temporary DNS error (default:
11125 1.1 tron <a href="postconf.5.html#defer_if_permit">defer_if_permit</a>). </dd>
11126 1.1 tron
11127 1.1 tron </dl>
11128 1.1 tron
11129 1.1 tron <p>
11130 1.1 tron Other restrictions that are valid in this context:
11131 1.1 tron </p>
11132 1.1 tron
11133 1.1 tron <ul>
11134 1.1 tron
11135 1.1 tron <li> <a href="#generic">Generic</a> restrictions that can be used
11136 1.1 tron in any SMTP command context, described under <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>.
11137 1.1 tron
11138 1.1 tron <li> Client hostname or network address specific restrictions
11139 1.1 tron described under <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>.
11140 1.1 tron
11141 1.1 tron <li> SMTP command specific restrictions described under
11142 1.1 tron <a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a> or <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a>. When
11143 1.1 tron sender or recipient restrictions are listed under <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a>,
11144 1.1 tron they have effect only with "<a href="postconf.5.html#smtpd_delay_reject">smtpd_delay_reject</a> = yes", so that
11145 1.1 tron $<a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a> is evaluated at the time of the RCPT TO
11146 1.1 tron command.
11147 1.1 tron
11148 1.1 tron </ul>
11149 1.1 tron
11150 1.1 tron <p>
11151 1.1 tron Examples:
11152 1.1 tron </p>
11153 1.1 tron
11154 1.1 tron <pre>
11155 1.1 tron <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a> = <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, <a href="postconf.5.html#reject_invalid_helo_hostname">reject_invalid_helo_hostname</a>
11156 1.1 tron <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a> = <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, <a href="postconf.5.html#reject_unknown_helo_hostname">reject_unknown_helo_hostname</a>
11157 1.1 tron </pre>
11158 1.1 tron
11159 1.1 tron
11160 1.1 tron </DD>
11161 1.1 tron
11162 1.1 tron <DT><b><a name="smtpd_history_flush_threshold">smtpd_history_flush_threshold</a>
11163 1.1 tron (default: 100)</b></DT><DD>
11164 1.1 tron
11165 1.1 tron <p>
11166 1.1 tron The maximal number of lines in the Postfix SMTP server command history
11167 1.1 tron before it is flushed upon receipt of EHLO, RSET, or end of DATA.
11168 1.1 tron </p>
11169 1.1 tron
11170 1.1 tron
11171 1.1 tron </DD>
11172 1.1 tron
11173 1.1 tron <DT><b><a name="smtpd_junk_command_limit">smtpd_junk_command_limit</a>
11174 1.1 tron (default: normal: 100, stress: 1)</b></DT><DD>
11175 1.1 tron
11176 1.1 tron <p>
11177 1.1 tron The number of junk commands (NOOP, VRFY, ETRN or RSET) that a remote
11178 1.1 tron SMTP client can send before the Postfix SMTP server starts to
11179 1.1 tron increment the error counter with each junk command. The junk
11180 1.1 tron command count is reset after mail is delivered. See also the
11181 1.1 tron <a href="postconf.5.html#smtpd_error_sleep_time">smtpd_error_sleep_time</a> and <a href="postconf.5.html#smtpd_soft_error_limit">smtpd_soft_error_limit</a> configuration
11182 1.1 tron parameters. Normally the default limit is 100, but it changes under
11183 1.1 tron overload to just 1 with Postfix 2.6 and later.
11184 1.1 tron </p>
11185 1.1 tron
11186 1.1 tron
11187 1.1 tron </DD>
11188 1.1 tron
11189 1.1 tron <DT><b><a name="smtpd_milters">smtpd_milters</a>
11190 1.1 tron (default: empty)</b></DT><DD>
11191 1.1 tron
11192 1.1 tron <p> A list of Milter (mail filter) applications for new mail that
11193 1.1 tron arrives via the Postfix <a href="smtpd.8.html">smtpd(8)</a> server. See the <a href="MILTER_README.html">MILTER_README</a>
11194 1.1 tron document for details. </p>
11195 1.1 tron
11196 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
11197 1.1 tron
11198 1.1 tron
11199 1.1 tron </DD>
11200 1.1 tron
11201 1.1 tron <DT><b><a name="smtpd_noop_commands">smtpd_noop_commands</a>
11202 1.1 tron (default: empty)</b></DT><DD>
11203 1.1 tron
11204 1.1 tron <p>
11205 1.1 tron List of commands that the Postfix SMTP server replies to with "250
11206 1.1 tron Ok", without doing any syntax checks and without changing state.
11207 1.1 tron This list overrides any commands built into the Postfix SMTP server.
11208 1.1 tron </p>
11209 1.1 tron
11210 1.1 tron
11211 1.1 tron </DD>
11212 1.1 tron
11213 1.1 tron <DT><b><a name="smtpd_null_access_lookup_key">smtpd_null_access_lookup_key</a>
11214 1.1 tron (default: <>)</b></DT><DD>
11215 1.1 tron
11216 1.1 tron <p>
11217 1.1 tron The lookup key to be used in SMTP <a href="access.5.html">access(5)</a> tables instead of the
11218 1.1 tron null sender address.
11219 1.1 tron </p>
11220 1.1 tron
11221 1.1 tron
11222 1.1 tron </DD>
11223 1.1 tron
11224 1.1 tron <DT><b><a name="smtpd_peername_lookup">smtpd_peername_lookup</a>
11225 1.1 tron (default: yes)</b></DT><DD>
11226 1.1 tron
11227 1.1 tron <p> Attempt to look up the remote SMTP client hostname, and verify that
11228 1.1 tron the name matches the client IP address. A client name is set to
11229 1.1 tron "unknown" when it cannot be looked up or verified, or when name
11230 1.1 tron lookup is disabled. Turning off name lookup reduces delays due to
11231 1.1 tron DNS lookup and increases the maximal inbound delivery rate. </p>
11232 1.1 tron
11233 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
11234 1.1 tron
11235 1.1 tron
11236 1.1 tron </DD>
11237 1.1 tron
11238 1.1 tron <DT><b><a name="smtpd_policy_service_max_idle">smtpd_policy_service_max_idle</a>
11239 1.1 tron (default: 300s)</b></DT><DD>
11240 1.1 tron
11241 1.1 tron <p>
11242 1.1 tron The time after which an idle SMTPD policy service connection is
11243 1.1 tron closed.
11244 1.1 tron </p>
11245 1.1 tron
11246 1.1 tron <p>
11247 1.1 tron This feature is available in Postfix 2.1 and later.
11248 1.1 tron </p>
11249 1.1 tron
11250 1.1 tron
11251 1.1 tron </DD>
11252 1.1 tron
11253 1.1 tron <DT><b><a name="smtpd_policy_service_max_ttl">smtpd_policy_service_max_ttl</a>
11254 1.1 tron (default: 1000s)</b></DT><DD>
11255 1.1 tron
11256 1.1 tron <p>
11257 1.1 tron The time after which an active SMTPD policy service connection is
11258 1.1 tron closed.
11259 1.1 tron </p>
11260 1.1 tron
11261 1.1 tron <p>
11262 1.1 tron This feature is available in Postfix 2.1 and later.
11263 1.1 tron </p>
11264 1.1 tron
11265 1.1 tron
11266 1.1 tron </DD>
11267 1.1 tron
11268 1.1 tron <DT><b><a name="smtpd_policy_service_timeout">smtpd_policy_service_timeout</a>
11269 1.1 tron (default: 100s)</b></DT><DD>
11270 1.1 tron
11271 1.1 tron <p>
11272 1.1 tron The time limit for connecting to, writing to or receiving from a
11273 1.1 tron delegated SMTPD policy server.
11274 1.1 tron </p>
11275 1.1 tron
11276 1.1 tron <p>
11277 1.1 tron This feature is available in Postfix 2.1 and later.
11278 1.1 tron </p>
11279 1.1 tron
11280 1.1 tron
11281 1.1 tron </DD>
11282 1.1 tron
11283 1.1 tron <DT><b><a name="smtpd_proxy_ehlo">smtpd_proxy_ehlo</a>
11284 1.1 tron (default: $<a href="postconf.5.html#myhostname">myhostname</a>)</b></DT><DD>
11285 1.1 tron
11286 1.1 tron <p>
11287 1.1 tron How the Postfix SMTP server announces itself to the proxy filter.
11288 1.1 tron By default, the Postfix hostname is used.
11289 1.1 tron </p>
11290 1.1 tron
11291 1.1 tron <p>
11292 1.1 tron This feature is available in Postfix 2.1 and later.
11293 1.1 tron </p>
11294 1.1 tron
11295 1.1 tron
11296 1.1 tron </DD>
11297 1.1 tron
11298 1.1 tron <DT><b><a name="smtpd_proxy_filter">smtpd_proxy_filter</a>
11299 1.1 tron (default: empty)</b></DT><DD>
11300 1.1 tron
11301 1.1 tron <p> The hostname and TCP port of the mail filtering proxy server.
11302 1.1 tron The proxy receives all mail from the Postfix SMTP server, and is
11303 1.1 tron supposed to give the result to another Postfix SMTP server process.
11304 1.1 tron </p>
11305 1.1 tron
11306 1.1 tron <p> Specify "host:port" or "inet:host:port" for a TCP endpoint, or
11307 1.1 tron "unix:pathname" for a UNIX-domain endpoint. The host can be specified
11308 1.1 tron as an IP address or as a symbolic name; no MX lookups are done.
11309 1.1 tron When no "host" or "host:" are specified, the local machine is
11310 1.1 tron assumed. Pathname interpretation is relative to the Postfix queue
11311 1.1 tron directory. </p>
11312 1.1 tron
11313 1.1 tron <p> This feature is available in Postfix 2.1 and later. </p>
11314 1.1 tron
11315 1.1 tron <p> The "inet:" and "unix:" prefixes are available in Postfix 2.3
11316 1.1 tron and later. </p>
11317 1.1 tron
11318 1.1 tron
11319 1.1 tron </DD>
11320 1.1 tron
11321 1.1 tron <DT><b><a name="smtpd_proxy_timeout">smtpd_proxy_timeout</a>
11322 1.1 tron (default: 100s)</b></DT><DD>
11323 1.1 tron
11324 1.1 tron <p>
11325 1.1 tron The time limit for connecting to a proxy filter and for sending or
11326 1.1 tron receiving information. When a connection fails the client gets a
11327 1.1 tron generic error message while more detailed information is logged to
11328 1.1 tron the maillog file.
11329 1.1 tron </p>
11330 1.1 tron
11331 1.1 tron <p>
11332 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
11333 1.1 tron The default time unit is s (seconds).
11334 1.1 tron </p>
11335 1.1 tron
11336 1.1 tron <p>
11337 1.1 tron This feature is available in Postfix 2.1 and later.
11338 1.1 tron </p>
11339 1.1 tron
11340 1.1 tron
11341 1.1 tron </DD>
11342 1.1 tron
11343 1.1 tron <DT><b><a name="smtpd_recipient_limit">smtpd_recipient_limit</a>
11344 1.1 tron (default: 1000)</b></DT><DD>
11345 1.1 tron
11346 1.1 tron <p>
11347 1.1 tron The maximal number of recipients that the Postfix SMTP server
11348 1.1 tron accepts per message delivery request.
11349 1.1 tron </p>
11350 1.1 tron
11351 1.1 tron
11352 1.1 tron </DD>
11353 1.1 tron
11354 1.1 tron <DT><b><a name="smtpd_recipient_overshoot_limit">smtpd_recipient_overshoot_limit</a>
11355 1.1 tron (default: 1000)</b></DT><DD>
11356 1.1 tron
11357 1.1 tron <p> The number of recipients that a remote SMTP client can send in
11358 1.1 tron excess of the limit specified with $<a href="postconf.5.html#smtpd_recipient_limit">smtpd_recipient_limit</a>, before
11359 1.1 tron the Postfix SMTP server increments the per-session error count
11360 1.1 tron for each excess recipient. </p>
11361 1.1 tron
11362 1.1 tron
11363 1.1 tron </DD>
11364 1.1 tron
11365 1.1 tron <DT><b><a name="smtpd_recipient_restrictions">smtpd_recipient_restrictions</a>
11366 1.1 tron (default: <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, <a href="postconf.5.html#reject_unauth_destination">reject_unauth_destination</a>)</b></DT><DD>
11367 1.1 tron
11368 1.1 tron <p>
11369 1.1 tron The access restrictions that the Postfix SMTP server applies in
11370 1.1 tron the context of the RCPT TO command.
11371 1.1 tron See <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, section "Delayed evaluation of SMTP access
11372 1.1 tron restriction lists" for a discussion of evaluation context and time.
11373 1.1 tron </p>
11374 1.1 tron
11375 1.1 tron <p>
11376 1.1 tron By default, the Postfix SMTP server accepts:
11377 1.1 tron </p>
11378 1.1 tron
11379 1.1 tron <ul>
11380 1.1 tron
11381 1.1 tron <li> Mail from clients whose IP address matches $<a href="postconf.5.html#mynetworks">mynetworks</a>, or:
11382 1.1 tron
11383 1.1 tron <li> Mail to remote destinations that match $<a href="postconf.5.html#relay_domains">relay_domains</a>, except
11384 1.1 tron for addresses that contain sender-specified routing
11385 1.1 tron (user@elsewhere@domain), or:
11386 1.1 tron
11387 1.1 tron <li> Mail to local destinations that match $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>
11388 1.1 tron or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>, $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>, or
11389 1.1 tron $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>.
11390 1.1 tron
11391 1.1 tron </ul>
11392 1.1 tron
11393 1.1 tron <p>
11394 1.1 tron IMPORTANT: If you change this parameter setting, you must specify
11395 1.1 tron at least one of the following restrictions. Otherwise Postfix will
11396 1.1 tron refuse to receive mail:
11397 1.1 tron </p>
11398 1.1 tron
11399 1.1 tron <blockquote>
11400 1.1 tron <pre>
11401 1.1 tron reject, defer, <a href="postconf.5.html#defer_if_permit">defer_if_permit</a>, <a href="postconf.5.html#reject_unauth_destination">reject_unauth_destination</a>
11402 1.1 tron </pre>
11403 1.1 tron </blockquote>
11404 1.1 tron
11405 1.1 tron <p>
11406 1.1 tron Specify a list of restrictions, separated by commas and/or whitespace.
11407 1.1 tron Continue long lines by starting the next line with whitespace.
11408 1.1 tron Restrictions are applied in the order as specified; the first
11409 1.1 tron restriction that matches wins.
11410 1.1 tron </p>
11411 1.1 tron
11412 1.1 tron <p>
11413 1.1 tron The following restrictions are specific to the recipient address
11414 1.1 tron that is received with the RCPT TO command.
11415 1.1 tron </p>
11416 1.1 tron
11417 1.1 tron <dl>
11418 1.1 tron
11419 1.1 tron <dt><b><a name="check_recipient_access">check_recipient_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
11420 1.1 tron
11421 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the resolved RCPT
11422 1.1 tron TO address, domain, parent domains, or localpart@, and execute the
11423 1.1 tron corresponding action. </dd>
11424 1.1 tron
11425 1.1 tron <dt><b><a name="check_recipient_mx_access">check_recipient_mx_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
11426 1.1 tron
11427 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the MX hosts for
11428 1.1 tron the RCPT TO domain, and execute the corresponding action. Note:
11429 1.1 tron a result of "OK" is not allowed for safety reasons. Instead, use
11430 1.1 tron DUNNO in order to exclude specific hosts from blacklists. This
11431 1.1 tron feature is available in Postfix 2.1 and later. </dd>
11432 1.1 tron
11433 1.1 tron <dt><b><a name="check_recipient_ns_access">check_recipient_ns_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
11434 1.1 tron
11435 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the DNS servers
11436 1.1 tron for the RCPT TO domain, and execute the corresponding action.
11437 1.1 tron Note: a result of "OK" is not allowed for safety reasons. Instead,
11438 1.1 tron use DUNNO in order to exclude specific hosts from blacklists. This
11439 1.1 tron feature is available in Postfix 2.1 and later. </dd>
11440 1.1 tron
11441 1.1 tron <dt><b><a name="permit_auth_destination">permit_auth_destination</a></b></dt>
11442 1.1 tron
11443 1.1 tron <dd>Permit the request when one of the following is true:
11444 1.1 tron
11445 1.1 tron <ul>
11446 1.1 tron
11447 1.1 tron <li> Postfix is mail forwarder: the resolved RCPT TO domain matches
11448 1.1 tron $<a href="postconf.5.html#relay_domains">relay_domains</a> or a subdomain thereof, and the address contains no
11449 1.1 tron sender-specified routing (user@elsewhere@domain),
11450 1.1 tron
11451 1.1 tron <li> Postfix is the final destination: the resolved RCPT TO domain
11452 1.1 tron matches $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>, $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>,
11453 1.1 tron $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>, or $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>, and the address
11454 1.1 tron contains no sender-specified routing (user@elsewhere@domain).
11455 1.1 tron
11456 1.1 tron </ul></dd>
11457 1.1 tron
11458 1.1 tron <dt><b><a name="permit_mx_backup">permit_mx_backup</a></b></dt>
11459 1.1 tron
11460 1.1 tron <dd>Permit the request when the local mail system is backup MX for
11461 1.1 tron the RCPT TO domain, or when the domain is an authorized destination
11462 1.1 tron (see <a href="postconf.5.html#permit_auth_destination">permit_auth_destination</a> for definition).
11463 1.1 tron
11464 1.1 tron <ul>
11465 1.1 tron
11466 1.1 tron <li> Safety: <a href="postconf.5.html#permit_mx_backup">permit_mx_backup</a> does not accept addresses that have
11467 1.1 tron sender-specified routing information (example: user@elsewhere@domain).
11468 1.1 tron
11469 1.1 tron <li> Safety: <a href="postconf.5.html#permit_mx_backup">permit_mx_backup</a> can be vulnerable to mis-use when
11470 1.1 tron access is not restricted with <a href="postconf.5.html#permit_mx_backup_networks">permit_mx_backup_networks</a>.
11471 1.1 tron
11472 1.1 tron <li> Safety: as of Postfix version 2.3, <a href="postconf.5.html#permit_mx_backup">permit_mx_backup</a> no longer
11473 1.1 tron accepts the address when the local mail system is primary MX for
11474 1.1 tron the recipient domain. Exception: <a href="postconf.5.html#permit_mx_backup">permit_mx_backup</a> accepts the address
11475 1.1 tron when it specifies an authorized destination (see <a href="postconf.5.html#permit_auth_destination">permit_auth_destination</a>
11476 1.1 tron for definition).
11477 1.1 tron
11478 1.1 tron <li> Limitation: mail may be rejected in case of a temporary DNS
11479 1.1 tron lookup problem with Postfix prior to version 2.0.
11480 1.1 tron
11481 1.1 tron </ul></dd>
11482 1.1 tron
11483 1.1 tron <dt><b><a name="reject_non_fqdn_recipient">reject_non_fqdn_recipient</a></b></dt>
11484 1.1 tron
11485 1.1 tron <dd>Reject the request when the RCPT TO address is not in
11486 1.1 tron fully-qualified domain form, as required by the RFC. <br> The
11487 1.1 tron <a href="postconf.5.html#non_fqdn_reject_code">non_fqdn_reject_code</a> parameter specifies the response code for
11488 1.1 tron rejected requests (default: 504). </dd>
11489 1.1 tron
11490 1.1 tron <dt><b><a name="reject_rhsbl_recipient">reject_rhsbl_recipient <i>rbl_domain=d.d.d.d</i></a></b></dt>
11491 1.1 tron
11492 1.1 tron <dd>Reject the request when the RCPT TO domain is listed with the
11493 1.1 tron A record "<i>d.d.d.d</i>" under <i>rbl_domain</i> (Postfix version
11494 1.1 tron 2.1 and later only). If no "<i>=d.d.d.d</i>" is specified, reject
11495 1.1 tron the request when the RCPT TO domain is listed with
11496 1.1 tron any A record under <i>rbl_domain</i>. <br> The <a href="postconf.5.html#maps_rbl_reject_code">maps_rbl_reject_code</a>
11497 1.1 tron parameter specifies the response code for rejected requests (default:
11498 1.1 tron 554); the <a href="postconf.5.html#default_rbl_reply">default_rbl_reply</a> parameter specifies the default server
11499 1.1 tron reply; and the <a href="postconf.5.html#rbl_reply_maps">rbl_reply_maps</a> parameter specifies tables with server
11500 1.1 tron replies indexed by <i>rbl_domain</i>. This feature is available
11501 1.1 tron in Postfix version 2.0 and later.</dd>
11502 1.1 tron
11503 1.1 tron <dt><b><a name="reject_unauth_destination">reject_unauth_destination</a></b></dt>
11504 1.1 tron
11505 1.1 tron <dd>Reject the request unless one of the following is true:
11506 1.1 tron
11507 1.1 tron <ul>
11508 1.1 tron
11509 1.1 tron <li> Postfix is mail forwarder: the resolved RCPT TO domain matches
11510 1.1 tron $<a href="postconf.5.html#relay_domains">relay_domains</a> or a subdomain thereof, and contains no sender-specified
11511 1.1 tron routing (user@elsewhere@domain),
11512 1.1 tron
11513 1.1 tron <li> Postfix is the final destination: the resolved RCPT TO domain
11514 1.1 tron matches $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>, $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>,
11515 1.1 tron $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>, or $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>, and contains
11516 1.1 tron no sender-specified routing (user@elsewhere@domain).
11517 1.1 tron
11518 1.1 tron </ul> The <a href="postconf.5.html#relay_domains_reject_code">relay_domains_reject_code</a> parameter specifies the response
11519 1.1 tron code for rejected requests (default: 554). </dd>
11520 1.1 tron
11521 1.1 tron <dt><b><a name="reject_unknown_recipient_domain">reject_unknown_recipient_domain</a></b></dt>
11522 1.1 tron
11523 1.1 tron <dd>Reject the request when Postfix is not final destination for
11524 1.1 tron the recipient domain, and the RCPT TO domain has no DNS A or MX
11525 1.1 tron record, or when it has a malformed MX record such as a record with
11526 1.1 tron a zero-length MX hostname (Postfix version 2.3 and later). <br> The
11527 1.1 tron <a href="postconf.5.html#unknown_address_reject_code">unknown_address_reject_code</a> parameter specifies the numerical
11528 1.1 tron response code for rejected requests (default: 450). The response
11529 1.1 tron is always 450 in case of a temporary DNS error. <br> The
11530 1.1 tron <a href="postconf.5.html#unknown_address_tempfail_action">unknown_address_tempfail_action</a> parameter specifies the action
11531 1.1 tron after a temporary DNS error (default: <a href="postconf.5.html#defer_if_permit">defer_if_permit</a>). </dd>
11532 1.1 tron
11533 1.1 tron <dt><b><a name="reject_unlisted_recipient">reject_unlisted_recipient</a></b> (with Postfix version 2.0: check_recipient_maps)</dt>
11534 1.1 tron
11535 1.1 tron <dd> Reject the request when the RCPT TO address is not listed in
11536 1.1 tron the list of valid recipients for its domain class. See the
11537 1.1 tron <a href="postconf.5.html#smtpd_reject_unlisted_recipient">smtpd_reject_unlisted_recipient</a> parameter description for details.
11538 1.1 tron This feature is available in Postfix 2.1 and later.</dd>
11539 1.1 tron
11540 1.1 tron <dt><b><a name="reject_unverified_recipient">reject_unverified_recipient</a></b></dt>
11541 1.1 tron
11542 1.1 tron <dd>Reject the request when mail to the RCPT TO address is known
11543 1.1 tron to bounce, or when the recipient address destination is not reachable.
11544 1.1 tron Address verification information is managed by the <a href="verify.8.html">verify(8)</a> server;
11545 1.1 tron see the <a href="ADDRESS_VERIFICATION_README.html">ADDRESS_VERIFICATION_README</a> file for details. <br> The
11546 1.1 tron <a href="postconf.5.html#unverified_recipient_reject_code">unverified_recipient_reject_code</a> parameter specifies the numerical
11547 1.1 tron response code when an address is known to bounce (default: 450,
11548 1.1 tron change into 550 when you are confident that it is safe to do so).
11549 1.1 tron <br>The <a href="postconf.5.html#unverified_recipient_defer_code">unverified_recipient_defer_code</a> parameter specifies the
11550 1.1 tron numerical response code when an address probe failed due to a
11551 1.1 tron temporary problem (default: 450). <br> The
11552 1.1 tron <a href="postconf.5.html#unverified_recipient_tempfail_action">unverified_recipient_tempfail_action</a> parameter specifies the action
11553 1.1 tron after addres probe failure due to a temporary problem (default:
11554 1.1 tron <a href="postconf.5.html#defer_if_permit">defer_if_permit</a>). <br> This feature is available in Postfix 2.1
11555 1.1 tron and later. </dd>
11556 1.1 tron
11557 1.1 tron </dl>
11558 1.1 tron
11559 1.1 tron <p>
11560 1.1 tron Other restrictions that are valid in this context:
11561 1.1 tron </p>
11562 1.1 tron
11563 1.1 tron <ul>
11564 1.1 tron
11565 1.1 tron <li><a href="#generic">Generic</a> restrictions that can be used
11566 1.1 tron in any SMTP command context, described under <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>.
11567 1.1 tron
11568 1.1 tron <li>SMTP command specific restrictions described under
11569 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>, <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a> and
11570 1.1 tron <a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a>.
11571 1.1 tron
11572 1.1 tron </ul>
11573 1.1 tron
11574 1.1 tron <p>
11575 1.1 tron Example:
11576 1.1 tron </p>
11577 1.1 tron
11578 1.1 tron <pre>
11579 1.1 tron <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a> = <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, <a href="postconf.5.html#reject_unauth_destination">reject_unauth_destination</a>
11580 1.1 tron </pre>
11581 1.1 tron
11582 1.1 tron
11583 1.1 tron </DD>
11584 1.1 tron
11585 1.1 tron <DT><b><a name="smtpd_reject_unlisted_recipient">smtpd_reject_unlisted_recipient</a>
11586 1.1 tron (default: yes)</b></DT><DD>
11587 1.1 tron
11588 1.1 tron <p>
11589 1.1 tron Request that the Postfix SMTP server rejects mail for unknown
11590 1.1 tron recipient addresses, even when no explicit <a href="postconf.5.html#reject_unlisted_recipient">reject_unlisted_recipient</a>
11591 1.1 tron access restriction is specified. This prevents the Postfix queue
11592 1.1 tron from filling up with undeliverable MAILER-DAEMON messages.
11593 1.1 tron </p>
11594 1.1 tron
11595 1.1 tron <ul>
11596 1.1 tron
11597 1.1 tron <li> The recipient domain matches $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>
11598 1.1 tron or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>, but the recipient is not listed in
11599 1.1 tron $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a>, and $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> is not null.
11600 1.1 tron
11601 1.1 tron <li> The recipient domain matches $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a> but the
11602 1.1 tron recipient is not listed in $<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a>.
11603 1.1 tron
11604 1.1 tron <li> The recipient domain matches $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a> but the
11605 1.1 tron recipient is not listed in $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a>, and $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a>
11606 1.1 tron is not null.
11607 1.1 tron
11608 1.1 tron <li> The recipient domain matches $<a href="postconf.5.html#relay_domains">relay_domains</a> but the recipient
11609 1.1 tron is not listed in $<a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a>, and $<a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a>
11610 1.1 tron is not null.
11611 1.1 tron
11612 1.1 tron </ul>
11613 1.1 tron
11614 1.1 tron <p>
11615 1.1 tron This feature is available in Postfix 2.1 and later.
11616 1.1 tron </p>
11617 1.1 tron
11618 1.1 tron
11619 1.1 tron </DD>
11620 1.1 tron
11621 1.1 tron <DT><b><a name="smtpd_reject_unlisted_sender">smtpd_reject_unlisted_sender</a>
11622 1.1 tron (default: no)</b></DT><DD>
11623 1.1 tron
11624 1.1 tron <p> Request that the Postfix SMTP server rejects mail from unknown
11625 1.1 tron sender addresses, even when no explicit <a href="postconf.5.html#reject_unlisted_sender">reject_unlisted_sender</a>
11626 1.1 tron access restriction is specified. This can slow down an explosion
11627 1.1 tron of forged mail from worms or viruses. </p>
11628 1.1 tron
11629 1.1 tron <ul>
11630 1.1 tron
11631 1.1 tron <li> The sender domain matches $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a> or
11632 1.1 tron $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>, but the sender is not listed in
11633 1.1 tron $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a>, and $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> is not null.
11634 1.1 tron
11635 1.1 tron <li> The sender domain matches $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a> but the sender
11636 1.1 tron is not listed in $<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a>.
11637 1.1 tron
11638 1.1 tron <li> The sender domain matches $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a> but the
11639 1.1 tron sender is not listed in $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a>, and $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a>
11640 1.1 tron is not null.
11641 1.1 tron
11642 1.1 tron <li> The sender domain matches $<a href="postconf.5.html#relay_domains">relay_domains</a> but the sender is
11643 1.1 tron not listed in $<a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a>, and $<a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a> is
11644 1.1 tron not null.
11645 1.1 tron
11646 1.1 tron </ul>
11647 1.1 tron
11648 1.1 tron <p>
11649 1.1 tron This feature is available in Postfix 2.1 and later.
11650 1.1 tron </p>
11651 1.1 tron
11652 1.1 tron
11653 1.1 tron </DD>
11654 1.1 tron
11655 1.1 tron <DT><b><a name="smtpd_restriction_classes">smtpd_restriction_classes</a>
11656 1.1 tron (default: empty)</b></DT><DD>
11657 1.1 tron
11658 1.1 tron <p>
11659 1.1 tron User-defined aliases for groups of access restrictions. The aliases
11660 1.1 tron can be specified in <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a> etc., and on the
11661 1.1 tron right-hand side of a Postfix <a href="access.5.html">access(5)</a> table.
11662 1.1 tron </p>
11663 1.1 tron
11664 1.1 tron <p>
11665 1.1 tron One major application is for implementing per-recipient UCE control.
11666 1.1 tron See the <a href="RESTRICTION_CLASS_README.html">RESTRICTION_CLASS_README</a> document for other examples.
11667 1.1 tron </p>
11668 1.1 tron
11669 1.1 tron
11670 1.1 tron </DD>
11671 1.1 tron
11672 1.1 tron <DT><b><a name="smtpd_sasl_application_name">smtpd_sasl_application_name</a>
11673 1.1 tron (default: smtpd)</b></DT><DD>
11674 1.1 tron
11675 1.1 tron <p>
11676 1.1 tron The application name that the Postfix SMTP server uses for SASL
11677 1.1 tron server initialization. This
11678 1.1 tron controls the name of the SASL configuration file. The default value
11679 1.1 tron is <b>smtpd</b>, corresponding to a SASL configuration file named
11680 1.1 tron <b>smtpd.conf</b>.
11681 1.1 tron </p>
11682 1.1 tron
11683 1.1 tron <p>
11684 1.1 tron This feature is available in Postfix 2.1 and 2.2. With Postfix 2.3
11685 1.1 tron it was renamed to <a href="postconf.5.html#smtpd_sasl_path">smtpd_sasl_path</a>.
11686 1.1 tron </p>
11687 1.1 tron
11688 1.1 tron
11689 1.1 tron </DD>
11690 1.1 tron
11691 1.1 tron <DT><b><a name="smtpd_sasl_auth_enable">smtpd_sasl_auth_enable</a>
11692 1.1 tron (default: no)</b></DT><DD>
11693 1.1 tron
11694 1.1 tron <p>
11695 1.1 tron Enable SASL authentication in the Postfix SMTP server. By default,
11696 1.1 tron the Postfix SMTP server does not use authentication.
11697 1.1 tron </p>
11698 1.1 tron
11699 1.1 tron <p>
11700 1.1 tron If a remote SMTP client is authenticated, the <a href="postconf.5.html#permit_sasl_authenticated">permit_sasl_authenticated</a>
11701 1.1 tron access restriction can be used to permit relay access, like this:
11702 1.1 tron </p>
11703 1.1 tron
11704 1.1 tron <blockquote>
11705 1.1 tron <pre>
11706 1.1 tron <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a> =
11707 1.1 tron <a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, <a href="postconf.5.html#permit_sasl_authenticated">permit_sasl_authenticated</a>, ...
11708 1.1 tron </pre>
11709 1.1 tron </blockquote>
11710 1.1 tron
11711 1.1 tron <p> To reject all SMTP connections from unauthenticated clients,
11712 1.1 tron specify "<a href="postconf.5.html#smtpd_delay_reject">smtpd_delay_reject</a> = yes" (which is the default) and use:
11713 1.1 tron </p>
11714 1.1 tron
11715 1.1 tron <blockquote>
11716 1.1 tron <pre>
11717 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> = <a href="postconf.5.html#permit_sasl_authenticated">permit_sasl_authenticated</a>, reject
11718 1.1 tron </pre>
11719 1.1 tron </blockquote>
11720 1.1 tron
11721 1.1 tron <p>
11722 1.1 tron See the <a href="SASL_README.html">SASL_README</a> file for SASL configuration and operation details.
11723 1.1 tron </p>
11724 1.1 tron
11725 1.1 tron
11726 1.1 tron </DD>
11727 1.1 tron
11728 1.1 tron <DT><b><a name="smtpd_sasl_authenticated_header">smtpd_sasl_authenticated_header</a>
11729 1.1 tron (default: no)</b></DT><DD>
11730 1.1 tron
11731 1.1 tron <p> Report the SASL authenticated user name in the <a href="smtpd.8.html">smtpd(8)</a> Received
11732 1.1 tron message header. </p>
11733 1.1 tron
11734 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
11735 1.1 tron
11736 1.1 tron
11737 1.1 tron </DD>
11738 1.1 tron
11739 1.1 tron <DT><b><a name="smtpd_sasl_exceptions_networks">smtpd_sasl_exceptions_networks</a>
11740 1.1 tron (default: empty)</b></DT><DD>
11741 1.1 tron
11742 1.1 tron <p>
11743 1.1 tron What remote SMTP clients the Postfix SMTP server will not offer
11744 1.1 tron AUTH support to.
11745 1.1 tron </p>
11746 1.1 tron
11747 1.1 tron <p>
11748 1.1 tron Some clients (Netscape 4 at least) have a bug that causes them to
11749 1.1 tron require a login and password whenever AUTH is offered, whether it's
11750 1.1 tron necessary or not. To work around this, specify, for example,
11751 1.1 tron $<a href="postconf.5.html#mynetworks">mynetworks</a> to prevent Postfix from offering AUTH to local clients.
11752 1.1 tron </p>
11753 1.1 tron
11754 1.1 tron <p>
11755 1.1 tron Specify a list of network/netmask patterns, separated by commas
11756 1.1 tron and/or whitespace. The mask specifies the number of bits in the
11757 1.1 tron network part of a host address. You can also "/file/name" or
11758 1.1 tron "<a href="DATABASE_README.html">type:table</a>" patterns. A "/file/name" pattern is replaced by its
11759 1.1 tron contents; a "<a href="DATABASE_README.html">type:table</a>" lookup table is matched when a table entry
11760 1.1 tron matches a lookup string (the lookup result is ignored). Continue
11761 1.1 tron long lines by starting the next line with whitespace. Specify
11762 1.1 tron "!pattern" to exclude an address or network block from the list.
11763 1.1 tron The form "!/file/name" is supported only in Postfix version 2.4 and
11764 1.1 tron later. </p>
11765 1.1 tron
11766 1.1 tron <p> Note: IP version 6 address information must be specified inside
11767 1.1 tron <tt>[]</tt> in the <a href="postconf.5.html#smtpd_sasl_exceptions_networks">smtpd_sasl_exceptions_networks</a> value, and in
11768 1.1 tron files specified with "/file/name". IP version 6 addresses contain
11769 1.1 tron the ":" character, and would otherwise be confused with a "<a href="DATABASE_README.html">type:table</a>"
11770 1.1 tron pattern. </p>
11771 1.1 tron
11772 1.1 tron <p>
11773 1.1 tron Example:
11774 1.1 tron </p>
11775 1.1 tron
11776 1.1 tron <pre>
11777 1.1 tron <a href="postconf.5.html#smtpd_sasl_exceptions_networks">smtpd_sasl_exceptions_networks</a> = $<a href="postconf.5.html#mynetworks">mynetworks</a>
11778 1.1 tron </pre>
11779 1.1 tron
11780 1.1 tron <p>
11781 1.1 tron This feature is available in Postfix 2.1 and later.
11782 1.1 tron </p>
11783 1.1 tron
11784 1.1 tron
11785 1.1 tron </DD>
11786 1.1 tron
11787 1.1 tron <DT><b><a name="smtpd_sasl_local_domain">smtpd_sasl_local_domain</a>
11788 1.1 tron (default: empty)</b></DT><DD>
11789 1.1 tron
11790 1.1 tron <p>
11791 1.1 tron The name of the Postfix SMTP server's local SASL authentication
11792 1.1 tron realm.
11793 1.1 tron </p>
11794 1.1 tron
11795 1.1 tron <p>
11796 1.1 tron By default, the local authentication realm name is the null string.
11797 1.1 tron </p>
11798 1.1 tron
11799 1.1 tron <p>
11800 1.1 tron Examples:
11801 1.1 tron </p>
11802 1.1 tron
11803 1.1 tron <pre>
11804 1.1 tron <a href="postconf.5.html#smtpd_sasl_local_domain">smtpd_sasl_local_domain</a> = $<a href="postconf.5.html#mydomain">mydomain</a>
11805 1.1 tron <a href="postconf.5.html#smtpd_sasl_local_domain">smtpd_sasl_local_domain</a> = $<a href="postconf.5.html#myhostname">myhostname</a>
11806 1.1 tron </pre>
11807 1.1 tron
11808 1.1 tron
11809 1.1 tron </DD>
11810 1.1 tron
11811 1.1 tron <DT><b><a name="smtpd_sasl_path">smtpd_sasl_path</a>
11812 1.1 tron (default: smtpd)</b></DT><DD>
11813 1.1 tron
11814 1.1 tron <p> Implementation-specific information that the Postfix SMTP server
11815 1.1 tron passes through to
11816 1.1 tron the SASL plug-in implementation that is selected with
11817 1.1 tron <b><a href="postconf.5.html#smtpd_sasl_type">smtpd_sasl_type</a></b>. Typically this specifies the name of a
11818 1.1 tron configuration file or rendezvous point. </p>
11819 1.1 tron
11820 1.1 tron <p> This feature is available in Postfix 2.3 and later. In earlier
11821 1.1 tron releases it was called <b>smtpd_sasl_application_name</b>. </p>
11822 1.1 tron
11823 1.1 tron
11824 1.1 tron </DD>
11825 1.1 tron
11826 1.1 tron <DT><b><a name="smtpd_sasl_security_options">smtpd_sasl_security_options</a>
11827 1.1 tron (default: noanonymous)</b></DT><DD>
11828 1.1 tron
11829 1.1 tron <p> Postfix SMTP server SASL security options; as of Postfix 2.3
11830 1.1 tron the list of available
11831 1.1 tron features depends on the SASL server implementation that is selected
11832 1.1 tron with <b><a href="postconf.5.html#smtpd_sasl_type">smtpd_sasl_type</a></b>. </p>
11833 1.1 tron
11834 1.1 tron <p> The following security features are defined for the <b>cyrus</b>
11835 1.1 tron server SASL implementation: </p>
11836 1.1 tron
11837 1.1 tron <p>
11838 1.1 tron Restrict what authentication mechanisms the Postfix SMTP server
11839 1.1 tron will offer to the client. The list of available authentication
11840 1.1 tron mechanisms is system dependent.
11841 1.1 tron </p>
11842 1.1 tron
11843 1.1 tron <p>
11844 1.1 tron Specify zero or more of the following:
11845 1.1 tron </p>
11846 1.1 tron
11847 1.1 tron <dl>
11848 1.1 tron
11849 1.1 tron <dt><b>noplaintext</b></dt>
11850 1.1 tron
11851 1.1 tron <dd>Disallow methods that use plaintext passwords. </dd>
11852 1.1 tron
11853 1.1 tron <dt><b>noactive</b></dt>
11854 1.1 tron
11855 1.1 tron <dd>Disallow methods subject to active (non-dictionary) attack. </dd>
11856 1.1 tron
11857 1.1 tron <dt><b>nodictionary</b></dt>
11858 1.1 tron
11859 1.1 tron <dd>Disallow methods subject to passive (dictionary) attack. </dd>
11860 1.1 tron
11861 1.1 tron <dt><b>noanonymous</b></dt>
11862 1.1 tron
11863 1.1 tron <dd>Disallow methods that allow anonymous authentication. </dd>
11864 1.1 tron
11865 1.1 tron <dt><b>forward_secrecy</b></dt>
11866 1.1 tron
11867 1.1 tron <dd>Only allow methods that support forward secrecy (Dovecot only).
11868 1.1 tron </dd>
11869 1.1 tron
11870 1.1 tron <dt><b>mutual_auth</b></dt>
11871 1.1 tron
11872 1.1 tron <dd>Only allow methods that provide mutual authentication (not available
11873 1.1 tron with Cyrus SASL version 1). </dd>
11874 1.1 tron
11875 1.1 tron </dl>
11876 1.1 tron
11877 1.1 tron <p>
11878 1.1 tron By default, the Postfix SMTP server accepts plaintext passwords but
11879 1.1 tron not anonymous logins.
11880 1.1 tron </p>
11881 1.1 tron
11882 1.1 tron <p>
11883 1.1 tron Warning: it appears that clients try authentication methods in the
11884 1.1 tron order as advertised by the server (e.g., PLAIN ANONYMOUS CRAM-MD5)
11885 1.1 tron which means that if you disable plaintext passwords, clients will
11886 1.1 tron log in anonymously, even when they should be able to use CRAM-MD5.
11887 1.1 tron So, if you disable plaintext logins, disable anonymous logins too.
11888 1.1 tron Postfix treats anonymous login as no authentication.
11889 1.1 tron </p>
11890 1.1 tron
11891 1.1 tron <p>
11892 1.1 tron Example:
11893 1.1 tron </p>
11894 1.1 tron
11895 1.1 tron <pre>
11896 1.1 tron <a href="postconf.5.html#smtpd_sasl_security_options">smtpd_sasl_security_options</a> = noanonymous, noplaintext
11897 1.1 tron </pre>
11898 1.1 tron
11899 1.1 tron
11900 1.1 tron </DD>
11901 1.1 tron
11902 1.1 tron <DT><b><a name="smtpd_sasl_tls_security_options">smtpd_sasl_tls_security_options</a>
11903 1.1 tron (default: $<a href="postconf.5.html#smtpd_sasl_security_options">smtpd_sasl_security_options</a>)</b></DT><DD>
11904 1.1 tron
11905 1.1 tron <p> The SASL authentication security options that the Postfix SMTP
11906 1.1 tron server uses for TLS encrypted SMTP sessions. </p>
11907 1.1 tron
11908 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
11909 1.1 tron
11910 1.1 tron
11911 1.1 tron </DD>
11912 1.1 tron
11913 1.1 tron <DT><b><a name="smtpd_sasl_type">smtpd_sasl_type</a>
11914 1.1 tron (default: cyrus)</b></DT><DD>
11915 1.1 tron
11916 1.1 tron <p> The SASL plug-in type that the Postfix SMTP server should use
11917 1.1 tron for authentication. The available types are listed with the
11918 1.1 tron "<b>postconf -a</b>" command. </p>
11919 1.1 tron
11920 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
11921 1.1 tron
11922 1.1 tron
11923 1.1 tron </DD>
11924 1.1 tron
11925 1.1 tron <DT><b><a name="smtpd_sender_login_maps">smtpd_sender_login_maps</a>
11926 1.1 tron (default: empty)</b></DT><DD>
11927 1.1 tron
11928 1.1 tron <p>
11929 1.1 tron Optional lookup table with the SASL login names that own sender
11930 1.1 tron (MAIL FROM) addresses.
11931 1.1 tron </p>
11932 1.1 tron
11933 1.1 tron <p>
11934 1.1 tron Specify zero or more "<a href="DATABASE_README.html">type:table</a>" lookup tables. With lookups from
11935 1.1 tron indexed files such as DB or DBM, or from networked tables such as
11936 1.1 tron NIS, LDAP or SQL, the following search operations are done with a
11937 1.1 tron sender address of <i>user@domain</i>: </p>
11938 1.1 tron
11939 1.1 tron <dl>
11940 1.1 tron
11941 1.1 tron <dt> 1) <i>user@domain</i> </dt>
11942 1.1 tron
11943 1.1 tron <dd>This table lookup is always done and has the highest precedence. </dd>
11944 1.1 tron
11945 1.1 tron <dt> 2) <i>user</i> </dt>
11946 1.1 tron
11947 1.1 tron <dd>This table lookup is done only when the <i>domain</i> part of the
11948 1.1 tron sender address matches $<a href="postconf.5.html#myorigin">myorigin</a>, $<a href="postconf.5.html#mydestination">mydestination</a>, $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>
11949 1.1 tron or $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a>. </dd>
11950 1.1 tron
11951 1.1 tron <dt> 3) <i>@domain</i> </dt>
11952 1.1 tron
11953 1.1 tron <dd>This table lookup is done last and has the lowest precedence. </dd>
11954 1.1 tron
11955 1.1 tron </dl>
11956 1.1 tron
11957 1.1 tron <p>
11958 1.1 tron In all cases the result of table lookup must be either "not found"
11959 1.1 tron or a list of SASL login names separated by comma and/or whitespace.
11960 1.1 tron </p>
11961 1.1 tron
11962 1.1 tron
11963 1.1 tron </DD>
11964 1.1 tron
11965 1.1 tron <DT><b><a name="smtpd_sender_restrictions">smtpd_sender_restrictions</a>
11966 1.1 tron (default: empty)</b></DT><DD>
11967 1.1 tron
11968 1.1 tron <p>
11969 1.1 tron Optional restrictions that the Postfix SMTP server applies in the
11970 1.1 tron context of the MAIL FROM command.
11971 1.1 tron See <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, section "Delayed evaluation of SMTP access
11972 1.1 tron restriction lists" for a discussion of evaluation context and time.
11973 1.1 tron </p>
11974 1.1 tron
11975 1.1 tron <p>
11976 1.1 tron The default is to permit everything.
11977 1.1 tron </p>
11978 1.1 tron
11979 1.1 tron <p>
11980 1.1 tron Specify a list of restrictions, separated by commas and/or whitespace.
11981 1.1 tron Continue long lines by starting the next line with whitespace.
11982 1.1 tron Restrictions are applied in the order as specified; the first
11983 1.1 tron restriction that matches wins.
11984 1.1 tron </p>
11985 1.1 tron
11986 1.1 tron <p>
11987 1.1 tron The following restrictions are specific to the sender address
11988 1.1 tron received with the MAIL FROM command.
11989 1.1 tron </p>
11990 1.1 tron
11991 1.1 tron <dl>
11992 1.1 tron
11993 1.1 tron <dt><b><a name="check_sender_access">check_sender_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
11994 1.1 tron
11995 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the MAIL FROM
11996 1.1 tron address, domain, parent domains, or localpart@, and execute the
11997 1.1 tron corresponding action. </dd>
11998 1.1 tron
11999 1.1 tron <dt><b><a name="check_sender_mx_access">check_sender_mx_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
12000 1.1 tron
12001 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the MX hosts for
12002 1.1 tron the MAIL FROM address, and execute the corresponding action. Note:
12003 1.1 tron a result of "OK" is not allowed for safety reasons. Instead, use
12004 1.1 tron DUNNO in order to exclude specific hosts from blacklists. This
12005 1.1 tron feature is available in Postfix 2.1 and later. </dd>
12006 1.1 tron
12007 1.1 tron <dt><b><a name="check_sender_ns_access">check_sender_ns_access</a> <i><a href="DATABASE_README.html">type:table</a></i></b></dt>
12008 1.1 tron
12009 1.1 tron <dd>Search the specified <a href="access.5.html">access(5)</a> database for the DNS servers
12010 1.1 tron for the MAIL FROM address, and execute the corresponding action.
12011 1.1 tron Note: a result of "OK" is not allowed for safety reasons. Instead,
12012 1.1 tron use DUNNO in order to exclude specific hosts from blacklists. This
12013 1.1 tron feature is available in Postfix 2.1 and later. </dd>
12014 1.1 tron
12015 1.1 tron <dt><b><a name="reject_authenticated_sender_login_mismatch">reject_authenticated_sender_login_mismatch</a></b></dt>
12016 1.1 tron
12017 1.1 tron <dd>Enforces the <a href="postconf.5.html#reject_sender_login_mismatch">reject_sender_login_mismatch</a> restriction for
12018 1.1 tron authenticated clients only. This feature is available in
12019 1.1 tron Postfix version 2.1 and later. </dd>
12020 1.1 tron
12021 1.1 tron <dt><b><a name="reject_non_fqdn_sender">reject_non_fqdn_sender</a></b></dt>
12022 1.1 tron
12023 1.1 tron <dd>Reject the request when the MAIL FROM address is not in
12024 1.1 tron fully-qualified domain form, as required by the RFC. <br> The
12025 1.1 tron <a href="postconf.5.html#non_fqdn_reject_code">non_fqdn_reject_code</a> parameter specifies the response code for
12026 1.1 tron rejected requests (default: 504). </dd>
12027 1.1 tron
12028 1.1 tron <dt><b><a name="reject_rhsbl_sender">reject_rhsbl_sender <i>rbl_domain=d.d.d.d</i></a></b></dt>
12029 1.1 tron
12030 1.1 tron <dd>Reject the request when the MAIL FROM domain is listed with
12031 1.1 tron the A record "<i>d.d.d.d</i>" under <i>rbl_domain</i> (Postfix
12032 1.1 tron version 2.1 and later only). If no "<i>=d.d.d.d</i>" is specified,
12033 1.1 tron reject the request when the MAIL FROM domain is
12034 1.1 tron listed with any A record under <i>rbl_domain</i>. <br> The
12035 1.1 tron <a href="postconf.5.html#maps_rbl_reject_code">maps_rbl_reject_code</a> parameter specifies the response code for
12036 1.1 tron rejected requests (default: 554); the <a href="postconf.5.html#default_rbl_reply">default_rbl_reply</a> parameter
12037 1.1 tron specifies the default server reply; and the <a href="postconf.5.html#rbl_reply_maps">rbl_reply_maps</a> parameter
12038 1.1 tron specifies tables with server replies indexed by <i>rbl_domain</i>.
12039 1.1 tron This feature is available in Postfix 2.0 and later.</dd>
12040 1.1 tron
12041 1.1 tron <dt><b><a name="reject_sender_login_mismatch">reject_sender_login_mismatch</a></b></dt>
12042 1.1 tron
12043 1.1 tron <dd>Reject the request when $<a href="postconf.5.html#smtpd_sender_login_maps">smtpd_sender_login_maps</a> specifies an
12044 1.1 tron owner for the MAIL FROM address, but the client is not (SASL) logged
12045 1.1 tron in as that MAIL FROM address owner; or when the client is (SASL)
12046 1.1 tron logged in, but the client login name doesn't own the MAIL FROM
12047 1.1 tron address according to $<a href="postconf.5.html#smtpd_sender_login_maps">smtpd_sender_login_maps</a>.</dd>
12048 1.1 tron
12049 1.1 tron <dt><b><a name="reject_unauthenticated_sender_login_mismatch">reject_unauthenticated_sender_login_mismatch</a></b></dt>
12050 1.1 tron
12051 1.1 tron <dd>Enforces the <a href="postconf.5.html#reject_sender_login_mismatch">reject_sender_login_mismatch</a> restriction for
12052 1.1 tron unauthenticated clients only. This feature is available in
12053 1.1 tron Postfix version 2.1 and later. </dd>
12054 1.1 tron
12055 1.1 tron <dt><b><a name="reject_unknown_sender_domain">reject_unknown_sender_domain</a></b></dt>
12056 1.1 tron
12057 1.1 tron <dd>Reject the request when Postfix is not final destination for
12058 1.1 tron the sender address, and the MAIL FROM address has no DNS A or MX
12059 1.1 tron record, or when it has a malformed MX record such as a record with
12060 1.1 tron a zero-length MX hostname (Postfix version 2.3 and later). <br> The
12061 1.1 tron <a href="postconf.5.html#unknown_address_reject_code">unknown_address_reject_code</a> parameter specifies the numerical
12062 1.1 tron response code for rejected requests (default: 450). The response
12063 1.1 tron is always 450 in case of a temporary DNS error. <br> The
12064 1.1 tron <a href="postconf.5.html#unknown_address_tempfail_action">unknown_address_tempfail_action</a> parameter specifies the action
12065 1.1 tron after a temporary DNS error (default: <a href="postconf.5.html#defer_if_permit">defer_if_permit</a>). </dd>
12066 1.1 tron
12067 1.1 tron <dt><b><a name="reject_unlisted_sender">reject_unlisted_sender</a></b></dt>
12068 1.1 tron
12069 1.1 tron <dd>Reject the request when the MAIL FROM address is not listed in
12070 1.1 tron the list of valid recipients for its domain class. See the
12071 1.1 tron <a href="postconf.5.html#smtpd_reject_unlisted_sender">smtpd_reject_unlisted_sender</a> parameter description for details.
12072 1.1 tron This feature is available in Postfix 2.1 and later.</dd>
12073 1.1 tron
12074 1.1 tron <dt><b><a name="reject_unverified_sender">reject_unverified_sender</a></b></dt>
12075 1.1 tron
12076 1.1 tron <dd>Reject the request when mail to the MAIL FROM address is known to
12077 1.1 tron bounce, or when the sender address destination is not reachable.
12078 1.1 tron Address verification information is managed by the <a href="verify.8.html">verify(8)</a> server;
12079 1.1 tron see the <a href="ADDRESS_VERIFICATION_README.html">ADDRESS_VERIFICATION_README</a> file for details. <br> The
12080 1.1 tron <a href="postconf.5.html#unverified_sender_reject_code">unverified_sender_reject_code</a> parameter specifies the numerical
12081 1.1 tron response code when an address is known to bounce (default: 450,
12082 1.1 tron change into 550 when you are confident that it is safe to do so).
12083 1.1 tron <br>The <a href="postconf.5.html#unverified_sender_defer_code">unverified_sender_defer_code</a> specifies the numerical response
12084 1.1 tron code when an address address probe failed due to a temporary problem
12085 1.1 tron (default: 450). <br> The <a href="postconf.5.html#unverified_sender_tempfail_action">unverified_sender_tempfail_action</a> parameter
12086 1.1 tron specifies the action after address probe failure due to a temporary
12087 1.1 tron problem (default: <a href="postconf.5.html#defer_if_permit">defer_if_permit</a>). <br> This feature is available
12088 1.1 tron in Postfix 2.1 and later. </dd>
12089 1.1 tron
12090 1.1 tron </dl>
12091 1.1 tron
12092 1.1 tron <p>
12093 1.1 tron Other restrictions that are valid in this context:
12094 1.1 tron </p>
12095 1.1 tron
12096 1.1 tron <ul>
12097 1.1 tron
12098 1.1 tron <li> <a href="#generic">Generic</a> restrictions that can be used
12099 1.1 tron in any SMTP command context, described under <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>.
12100 1.1 tron
12101 1.1 tron <li> SMTP command specific restrictions described under
12102 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> and <a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a>.
12103 1.1 tron
12104 1.1 tron <li> SMTP command specific restrictions described under
12105 1.1 tron <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a>. When recipient restrictions are listed
12106 1.1 tron under <a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a>, they have effect only with
12107 1.1 tron "<a href="postconf.5.html#smtpd_delay_reject">smtpd_delay_reject</a> = yes", so that $<a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a> is
12108 1.1 tron evaluated at the time of the RCPT TO command.
12109 1.1 tron
12110 1.1 tron </ul>
12111 1.1 tron
12112 1.1 tron <p>
12113 1.1 tron Examples:
12114 1.1 tron </p>
12115 1.1 tron
12116 1.1 tron <pre>
12117 1.1 tron <a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a> = <a href="postconf.5.html#reject_unknown_sender_domain">reject_unknown_sender_domain</a>
12118 1.1 tron <a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a> = <a href="postconf.5.html#reject_unknown_sender_domain">reject_unknown_sender_domain</a>,
12119 1.1 tron <a href="postconf.5.html#check_sender_access">check_sender_access</a> hash:/etc/postfix/access
12120 1.1 tron </pre>
12121 1.1 tron
12122 1.1 tron
12123 1.1 tron </DD>
12124 1.1 tron
12125 1.1 tron <DT><b><a name="smtpd_soft_error_limit">smtpd_soft_error_limit</a>
12126 1.1 tron (default: 10)</b></DT><DD>
12127 1.1 tron
12128 1.1 tron <p>
12129 1.1 tron The number of errors a remote SMTP client is allowed to make without
12130 1.1 tron delivering mail before the Postfix SMTP server slows down all its
12131 1.1 tron responses.
12132 1.1 tron </p>
12133 1.1 tron
12134 1.1 tron <ul>
12135 1.1 tron
12136 1.1 tron <li><p>With Postfix version 2.1 and later, the Postfix SMTP server
12137 1.1 tron delays all responses by $<a href="postconf.5.html#smtpd_error_sleep_time">smtpd_error_sleep_time</a> seconds. </p>
12138 1.1 tron
12139 1.1 tron <li><p>With Postfix versions 2.0 and earlier, the Postfix SMTP
12140 1.1 tron server delays all responses by (number of errors) seconds. </p>
12141 1.1 tron
12142 1.1 tron </ul>
12143 1.1 tron
12144 1.1 tron
12145 1.1 tron </DD>
12146 1.1 tron
12147 1.1 tron <DT><b><a name="smtpd_starttls_timeout">smtpd_starttls_timeout</a>
12148 1.1 tron (default: 300s)</b></DT><DD>
12149 1.1 tron
12150 1.1 tron <p> The time limit for Postfix SMTP server write and read operations
12151 1.1 tron during TLS startup and shutdown handshake procedures. </p>
12152 1.1 tron
12153 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12154 1.1 tron
12155 1.1 tron
12156 1.1 tron </DD>
12157 1.1 tron
12158 1.1 tron <DT><b><a name="smtpd_timeout">smtpd_timeout</a>
12159 1.1 tron (default: normal: 300s, stress: 10s)</b></DT><DD>
12160 1.1 tron
12161 1.1 tron <p>
12162 1.1 tron The time limit for sending a Postfix SMTP server response and for
12163 1.1 tron receiving a remote SMTP client request. Normally the default limit
12164 1.1 tron is 300s, but it changes under overload to just 10s with Postfix 2.6
12165 1.1 tron and later.
12166 1.1 tron </p>
12167 1.1 tron
12168 1.1 tron <p>
12169 1.1 tron Note: if you set SMTP time limits to very large values you may have
12170 1.1 tron to update the global <a href="postconf.5.html#ipc_timeout">ipc_timeout</a> parameter.
12171 1.1 tron </p>
12172 1.1 tron
12173 1.1 tron <p>
12174 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
12175 1.1 tron The default time unit is s (seconds).
12176 1.1 tron </p>
12177 1.1 tron
12178 1.1 tron
12179 1.1 tron </DD>
12180 1.1 tron
12181 1.1 tron <DT><b><a name="smtpd_tls_CAfile">smtpd_tls_CAfile</a>
12182 1.1 tron (default: empty)</b></DT><DD>
12183 1.1 tron
12184 1.1 tron <p> A file containing (PEM format) CA certificates of root CAs trusted
12185 1.1 tron to sign either remote SMTP client certificates or intermediate CA
12186 1.1 tron certificates. These are loaded into memory before the <a href="smtpd.8.html">smtpd(8)</a> server
12187 1.1 tron enters the chroot jail. If the number of trusted roots is large, consider
12188 1.1 tron using <a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a> instead, but note that the latter directory must
12189 1.1 tron be present in the chroot jail if the <a href="smtpd.8.html">smtpd(8)</a> server is chrooted. This
12190 1.1 tron file may also be used to augment the server certificate trust chain,
12191 1.1 tron but it is best to include all the required certificates directly in the
12192 1.1 tron server certificate file. </p>
12193 1.1 tron
12194 1.1 tron <p> By default (see <a href="postconf.5.html#smtpd_tls_ask_ccert">smtpd_tls_ask_ccert</a>), client certificates are not
12195 1.1 tron requested, and <a href="postconf.5.html#smtpd_tls_CAfile">smtpd_tls_CAfile</a> should remain empty. If you do make use
12196 1.1 tron of client certificates, the distinguished names (DNs) of the certificate
12197 1.1 tron authorities listed in <a href="postconf.5.html#smtpd_tls_CAfile">smtpd_tls_CAfile</a> are sent to the remote SMTP client
12198 1.1 tron in the client certificate request message. MUAs with multiple client
12199 1.1 tron certificates may use the list of preferred certificate authorities
12200 1.1 tron to select the correct client certificate. You may want to put your
12201 1.1 tron "preferred" CA or CAs in this file, and install other trusted CAs in
12202 1.1 tron $<a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a>. </p>
12203 1.1 tron
12204 1.1 tron <p> Example: </p>
12205 1.1 tron
12206 1.1 tron <pre>
12207 1.1 tron <a href="postconf.5.html#smtpd_tls_CAfile">smtpd_tls_CAfile</a> = /etc/postfix/CAcert.pem
12208 1.1 tron </pre>
12209 1.1 tron
12210 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12211 1.1 tron
12212 1.1 tron
12213 1.1 tron </DD>
12214 1.1 tron
12215 1.1 tron <DT><b><a name="smtpd_tls_CApath">smtpd_tls_CApath</a>
12216 1.1 tron (default: empty)</b></DT><DD>
12217 1.1 tron
12218 1.1 tron <p> A directory containing (PEM format) CA certificates of root CAs
12219 1.1 tron trusted to sign either remote SMTP client certificates or intermediate CA
12220 1.1 tron certificates. Do not forget to create the necessary "hash" links with,
12221 1.1 tron for example, "$OPENSSL_HOME/bin/c_rehash /etc/postfix/certs". To use
12222 1.1 tron <a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a> in chroot mode, this directory (or a copy) must be
12223 1.1 tron inside the chroot jail. </p>
12224 1.1 tron
12225 1.1 tron <p> By default (see <a href="postconf.5.html#smtpd_tls_ask_ccert">smtpd_tls_ask_ccert</a>), client certificates are
12226 1.1 tron not requested, and <a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a> should remain empty. In contrast
12227 1.1 tron to <a href="postconf.5.html#smtp_tls_CAfile">smtp_tls_CAfile</a>, DNs of certificate authorities installed
12228 1.1 tron in $<a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a> are not included in the client certificate
12229 1.1 tron request message. MUAs with multiple client certificates may use the
12230 1.1 tron list of preferred certificate authorities to select the correct
12231 1.1 tron client certificate. You may want to put your "preferred" CA or
12232 1.1 tron CAs in $<a href="postconf.5.html#smtp_tls_CAfile">smtp_tls_CAfile</a>, and install the remaining trusted CAs in
12233 1.1 tron $<a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a>. </p>
12234 1.1 tron
12235 1.1 tron <p> Example: </p>
12236 1.1 tron
12237 1.1 tron <pre>
12238 1.1 tron <a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a> = /etc/postfix/certs
12239 1.1 tron </pre>
12240 1.1 tron
12241 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12242 1.1 tron
12243 1.1 tron
12244 1.1 tron </DD>
12245 1.1 tron
12246 1.1 tron <DT><b><a name="smtpd_tls_always_issue_session_ids">smtpd_tls_always_issue_session_ids</a>
12247 1.1 tron (default: yes)</b></DT><DD>
12248 1.1 tron
12249 1.1 tron <p> Force the Postfix SMTP server to issue a TLS session id, even
12250 1.1 tron when TLS session caching is turned off (<a href="postconf.5.html#smtpd_tls_session_cache_database">smtpd_tls_session_cache_database</a>
12251 1.1 tron is empty). This behavior is compatible with Postfix < 2.3. </p>
12252 1.1 tron
12253 1.1 tron <p> With Postfix 2.3 and later the Postfix SMTP server can disable
12254 1.1 tron session id generation when TLS session caching is turned off. This
12255 1.1 tron keeps clients from caching sessions that almost certainly cannot
12256 1.1 tron be re-used. </p>
12257 1.1 tron
12258 1.1 tron <p> By default, the Postfix SMTP server always generates TLS session
12259 1.1 tron ids. This works around a known defect in mail client applications
12260 1.1 tron such as MS Outlook, and may also prevent interoperability issues
12261 1.1 tron with other MTAs. </p>
12262 1.1 tron
12263 1.1 tron <p> Example: </p>
12264 1.1 tron
12265 1.1 tron <pre>
12266 1.1 tron <a href="postconf.5.html#smtpd_tls_always_issue_session_ids">smtpd_tls_always_issue_session_ids</a> = no
12267 1.1 tron </pre>
12268 1.1 tron
12269 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
12270 1.1 tron
12271 1.1 tron
12272 1.1 tron </DD>
12273 1.1 tron
12274 1.1 tron <DT><b><a name="smtpd_tls_ask_ccert">smtpd_tls_ask_ccert</a>
12275 1.1 tron (default: no)</b></DT><DD>
12276 1.1 tron
12277 1.1 tron <p> Ask a remote SMTP client for a client certificate. This
12278 1.1 tron information is needed for certificate based mail relaying with,
12279 1.1 tron for example, the <a href="postconf.5.html#permit_tls_clientcerts">permit_tls_clientcerts</a> feature. </p>
12280 1.1 tron
12281 1.1 tron <p> Some clients such as Netscape will either complain if no
12282 1.1 tron certificate is available (for the list of CAs in $<a href="postconf.5.html#smtpd_tls_CAfile">smtpd_tls_CAfile</a>)
12283 1.1 tron or will offer multiple client certificates to choose from. This
12284 1.1 tron may be annoying, so this option is "off" by default. </p>
12285 1.1 tron
12286 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12287 1.1 tron
12288 1.1 tron
12289 1.1 tron </DD>
12290 1.1 tron
12291 1.1 tron <DT><b><a name="smtpd_tls_auth_only">smtpd_tls_auth_only</a>
12292 1.1 tron (default: no)</b></DT><DD>
12293 1.1 tron
12294 1.1 tron <p> When TLS encryption is optional in the Postfix SMTP server, do
12295 1.1 tron not announce or accept SASL authentication over unencrypted
12296 1.1 tron connections. </p>
12297 1.1 tron
12298 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12299 1.1 tron
12300 1.1 tron
12301 1.1 tron </DD>
12302 1.1 tron
12303 1.1 tron <DT><b><a name="smtpd_tls_ccert_verifydepth">smtpd_tls_ccert_verifydepth</a>
12304 1.1 tron (default: 9)</b></DT><DD>
12305 1.1 tron
12306 1.1 tron <p> The verification depth for remote SMTP client certificates. A
12307 1.1 tron depth of 1 is sufficient if the issuing CA is listed in a local CA
12308 1.1 tron file. </p>
12309 1.1 tron
12310 1.1 tron <p> The default verification depth is 9 (the OpenSSL default) for
12311 1.1 tron compatibility with earlier Postfix behavior. Prior to Postfix 2.5,
12312 1.1 tron the default value was 5, but the limit was not actually enforced. If
12313 1.1 tron you have set this to a lower non-default value, certificates with longer
12314 1.1 tron trust chains may now fail to verify. Certificate chains with 1 or 2
12315 1.1 tron CAs are common, deeper chains are more rare and any number between 5
12316 1.1 tron and 9 should suffice in practice. You can choose a lower number if,
12317 1.1 tron for example, you trust certificates directly signed by an issuing CA
12318 1.1 tron but not any CAs it delegates to. </p>
12319 1.1 tron
12320 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12321 1.1 tron
12322 1.1 tron
12323 1.1 tron </DD>
12324 1.1 tron
12325 1.1 tron <DT><b><a name="smtpd_tls_cert_file">smtpd_tls_cert_file</a>
12326 1.1 tron (default: empty)</b></DT><DD>
12327 1.1 tron
12328 1.1 tron <p> File with the Postfix SMTP server RSA certificate in PEM format.
12329 1.1 tron This file may also contain the Postfix SMTP server private RSA key. </p>
12330 1.1 tron
12331 1.1 tron <p> Public Internet MX hosts without certificates signed by a "reputable"
12332 1.1 tron CA must generate, and be prepared to present to most clients, a
12333 1.1 tron self-signed or private-CA signed certificate. The client will not be
12334 1.1 tron able to authenticate the server, but unless it is running Postfix 2.3 or
12335 1.1 tron similar software, it will still insist on a server certificate. </p>
12336 1.1 tron
12337 1.1 tron <p> For servers that are <b>not</b> public Internet MX hosts, Postfix
12338 1.1 tron 2.3 supports configurations with no certificates. This entails the
12339 1.1 tron use of just the anonymous TLS ciphers, which are not supported by
12340 1.1 tron typical SMTP clients. Since such clients will not, as a rule, fall
12341 1.1 tron back to plain text after a TLS handshake failure, the server will
12342 1.1 tron be unable to receive email from TLS enabled clients. To avoid
12343 1.1 tron accidental configurations with no certificates, Postfix 2.3 enables
12344 1.1 tron certificate-less operation only when the administrator explicitly
12345 1.1 tron sets "<a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a> = none". This ensures that new Postfix
12346 1.1 tron configurations will not accidentally run with no certificates. </p>
12347 1.1 tron
12348 1.1 tron <p> Both RSA and DSA certificates are supported. When both types
12349 1.1 tron are present, the cipher used determines which certificate will be
12350 1.1 tron presented to the client. For Netscape and OpenSSL clients without
12351 1.1 tron special cipher choices the RSA certificate is preferred. </p>
12352 1.1 tron
12353 1.1 tron <p> To enable a remote SMTP client to verify the Postfix SMTP server
12354 1.1 tron certificate, the issuing CA certificates must be made available to the
12355 1.1 tron client. You should include the required certificates in the server
12356 1.1 tron certificate file, the server certificate first, then the issuing
12357 1.1 tron CA(s) (bottom-up order). </p>
12358 1.1 tron
12359 1.1 tron <p> Example: the certificate for "server.example.com" was issued by
12360 1.1 tron "intermediate CA" which itself has a certificate of "root CA".
12361 1.1 tron Create the server.pem file with "cat server_cert.pem intermediate_CA.pem
12362 1.1 tron root_CA.pem > server.pem". </p>
12363 1.1 tron
12364 1.1 tron <p> If you also want to verify client certificates issued by these
12365 1.1 tron CAs, you can add the CA certificates to the <a href="postconf.5.html#smtpd_tls_CAfile">smtpd_tls_CAfile</a>, in which
12366 1.1 tron case it is not necessary to have them in the <a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a> or
12367 1.1 tron <a href="postconf.5.html#smtpd_tls_dcert_file">smtpd_tls_dcert_file</a>. </p>
12368 1.1 tron
12369 1.1 tron <p> A certificate supplied here must be usable as an SSL server certificate
12370 1.1 tron and hence pass the "openssl verify -purpose sslserver ..." test. </p>
12371 1.1 tron
12372 1.1 tron <p> Example: </p>
12373 1.1 tron
12374 1.1 tron <pre>
12375 1.1 tron <a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a> = /etc/postfix/server.pem
12376 1.1 tron </pre>
12377 1.1 tron
12378 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12379 1.1 tron
12380 1.1 tron
12381 1.1 tron </DD>
12382 1.1 tron
12383 1.1 tron <DT><b><a name="smtpd_tls_cipherlist">smtpd_tls_cipherlist</a>
12384 1.1 tron (default: empty)</b></DT><DD>
12385 1.1 tron
12386 1.1 tron <p> Obsolete Postfix < 2.3 control for the Postfix SMTP server TLS
12387 1.1 tron cipher list. It is easy to create inter-operability problems by choosing
12388 1.1 tron a non-default cipher list. Do not use a non-default TLS cipherlist for
12389 1.1 tron MX hosts on the public Internet. Clients that begin the TLS handshake,
12390 1.1 tron but are unable to agree on a common cipher, may not be able to send any
12391 1.1 tron email to the SMTP server. Using a restricted cipher list may be more
12392 1.1 tron appropriate for a dedicated MSA or an internal mailhub, where one can
12393 1.1 tron exert some control over the TLS software and settings of the connecting
12394 1.1 tron clients. </p>
12395 1.1 tron
12396 1.1 tron <p> <b>Note:</b> do not use "" quotes around the parameter value. </p>
12397 1.1 tron
12398 1.1 tron <p>This feature is available with Postfix version 2.2. It is not used with
12399 1.1 tron Postfix 2.3 and later; use <a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a> instead. </p>
12400 1.1 tron
12401 1.1 tron
12402 1.1 tron </DD>
12403 1.1 tron
12404 1.1 tron <DT><b><a name="smtpd_tls_ciphers">smtpd_tls_ciphers</a>
12405 1.1 tron (default: export)</b></DT><DD>
12406 1.1 tron
12407 1.1 tron <p> The minimum TLS cipher grade that the Postfix SMTP server
12408 1.1 tron will use with opportunistic TLS encryption. Cipher types listed in
12409 1.1 tron <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> are excluded from the base definition of
12410 1.1 tron the selected cipher grade. The default value "export" ensures maximum
12411 1.1 tron inter-operability. Because encryption is optional, stronger controls
12412 1.1 tron are not appropriate, and this setting SHOULD NOT be changed unless the
12413 1.1 tron change is essential. </p>
12414 1.1 tron
12415 1.1 tron <p> When TLS is mandatory the cipher grade is chosen via the
12416 1.1 tron <a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a> configuration parameter, see there for syntax
12417 1.1 tron details. </p>
12418 1.1 tron
12419 1.1 tron <p> Example: </p>
12420 1.1 tron <pre>
12421 1.1 tron <a href="postconf.5.html#smtpd_tls_ciphers">smtpd_tls_ciphers</a> = export
12422 1.1 tron </pre>
12423 1.1 tron
12424 1.1 tron <p> This feature is available in Postfix 2.6 and later. With earlier Postfix
12425 1.1 tron releases only the <a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a> parameter is implemented,
12426 1.1 tron and opportunistic TLS always uses "export" or better (i.e. all) ciphers. </p>
12427 1.1 tron
12428 1.1 tron
12429 1.1 tron </DD>
12430 1.1 tron
12431 1.1 tron <DT><b><a name="smtpd_tls_dcert_file">smtpd_tls_dcert_file</a>
12432 1.1 tron (default: empty)</b></DT><DD>
12433 1.1 tron
12434 1.1 tron <p> File with the Postfix SMTP server DSA certificate in PEM format.
12435 1.1 tron This file may also contain the Postfix SMTP server private DSA key. </p>
12436 1.1 tron
12437 1.1 tron <p> See the discussion under <a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a> for more details.
12438 1.1 tron </p>
12439 1.1 tron
12440 1.1 tron <p> Example: </p>
12441 1.1 tron
12442 1.1 tron <pre>
12443 1.1 tron <a href="postconf.5.html#smtpd_tls_dcert_file">smtpd_tls_dcert_file</a> = /etc/postfix/server-dsa.pem
12444 1.1 tron </pre>
12445 1.1 tron
12446 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12447 1.1 tron
12448 1.1 tron
12449 1.1 tron </DD>
12450 1.1 tron
12451 1.1 tron <DT><b><a name="smtpd_tls_dh1024_param_file">smtpd_tls_dh1024_param_file</a>
12452 1.1 tron (default: empty)</b></DT><DD>
12453 1.1 tron
12454 1.1 tron <p> File with DH parameters that the Postfix SMTP server should
12455 1.1 tron use with EDH ciphers. </p>
12456 1.1 tron
12457 1.1 tron <p> Instead of using the exact same parameter sets as distributed
12458 1.1 tron with other TLS packages, it is more secure to generate your own
12459 1.1 tron set of parameters with something like the following command: </p>
12460 1.1 tron
12461 1.1 tron <blockquote>
12462 1.1 tron <pre>
12463 1.1 tron openssl gendh -out /etc/postfix/dh_1024.pem -2 1024
12464 1.1 tron </pre>
12465 1.1 tron </blockquote>
12466 1.1 tron
12467 1.1 tron <p> Your actual source for entropy may differ. Some systems have
12468 1.1 tron /dev/random; on other system you may consider using the "Entropy
12469 1.1 tron Gathering Daemon EGD", available at <a href="http://egd.sourceforge.net/">http://egd.sourceforge.net/</a>
12470 1.1 tron </p>
12471 1.1 tron
12472 1.1 tron <p> Example: </p>
12473 1.1 tron
12474 1.1 tron <pre>
12475 1.1 tron <a href="postconf.5.html#smtpd_tls_dh1024_param_file">smtpd_tls_dh1024_param_file</a> = /etc/postfix/dh_1024.pem
12476 1.1 tron </pre>
12477 1.1 tron
12478 1.1 tron <p>This feature is available with Postfix version 2.2.</p>
12479 1.1 tron
12480 1.1 tron
12481 1.1 tron </DD>
12482 1.1 tron
12483 1.1 tron <DT><b><a name="smtpd_tls_dh512_param_file">smtpd_tls_dh512_param_file</a>
12484 1.1 tron (default: empty)</b></DT><DD>
12485 1.1 tron
12486 1.1 tron <p> File with DH parameters that the Postfix SMTP server should
12487 1.1 tron use with EDH ciphers. </p>
12488 1.1 tron
12489 1.1 tron <p> See also the discussion under the <a href="postconf.5.html#smtpd_tls_dh1024_param_file">smtpd_tls_dh1024_param_file</a>
12490 1.1 tron configuration parameter. </p>
12491 1.1 tron
12492 1.1 tron <p> Example: </p>
12493 1.1 tron
12494 1.1 tron <pre>
12495 1.1 tron <a href="postconf.5.html#smtpd_tls_dh512_param_file">smtpd_tls_dh512_param_file</a> = /etc/postfix/dh_512.pem
12496 1.1 tron </pre>
12497 1.1 tron
12498 1.1 tron <p>This feature is available with Postfix version 2.2.</p>
12499 1.1 tron
12500 1.1 tron
12501 1.1 tron </DD>
12502 1.1 tron
12503 1.1 tron <DT><b><a name="smtpd_tls_dkey_file">smtpd_tls_dkey_file</a>
12504 1.1 tron (default: $<a href="postconf.5.html#smtpd_tls_dcert_file">smtpd_tls_dcert_file</a>)</b></DT><DD>
12505 1.1 tron
12506 1.1 tron <p> File with the Postfix SMTP server DSA private key in PEM format.
12507 1.1 tron This file may be combined with the Postfix SMTP server DSA certificate
12508 1.1 tron file specified with $<a href="postconf.5.html#smtpd_tls_dcert_file">smtpd_tls_dcert_file</a>. </p>
12509 1.1 tron
12510 1.1 tron <p> The private key must be accessible without a pass-phrase, i.e. it
12511 1.1 tron must not be encrypted. File permissions should grant read-only
12512 1.1 tron access to the system superuser account ("root"), and no access
12513 1.1 tron to anyone else. </p>
12514 1.1 tron
12515 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12516 1.1 tron
12517 1.1 tron
12518 1.1 tron </DD>
12519 1.1 tron
12520 1.1 tron <DT><b><a name="smtpd_tls_eccert_file">smtpd_tls_eccert_file</a>
12521 1.1 tron (default: empty)</b></DT><DD>
12522 1.1 tron
12523 1.1 tron <p> File with the Postfix SMTP server ECDSA certificate in PEM format.
12524 1.1 tron This file may also contain the Postfix SMTP server private ECDSA key. </p>
12525 1.1 tron
12526 1.1 tron <p> See the discussion under <a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a> for more details. </p>
12527 1.1 tron
12528 1.1 tron <p> Example: </p>
12529 1.1 tron
12530 1.1 tron <pre>
12531 1.1 tron <a href="postconf.5.html#smtpd_tls_eccert_file">smtpd_tls_eccert_file</a> = /etc/postfix/ecdsa-scert.pem
12532 1.1 tron </pre>
12533 1.1 tron
12534 1.1 tron <p> This feature is available in Postfix 2.6 and later, when Postfix is
12535 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
12536 1.1 tron
12537 1.1 tron
12538 1.1 tron </DD>
12539 1.1 tron
12540 1.1 tron <DT><b><a name="smtpd_tls_eckey_file">smtpd_tls_eckey_file</a>
12541 1.1 tron (default: $<a href="postconf.5.html#smtpd_tls_eccert_file">smtpd_tls_eccert_file</a>)</b></DT><DD>
12542 1.1 tron
12543 1.1 tron <p> File with the Postfix SMTP server ECDSA private key in PEM format.
12544 1.1 tron This file may be combined with the Postfix SMTP server ECDSA certificate
12545 1.1 tron file specified with $<a href="postconf.5.html#smtpd_tls_eccert_file">smtpd_tls_eccert_file</a>. </p>
12546 1.1 tron
12547 1.1 tron <p> The private key must be accessible without a pass-phrase, i.e. it
12548 1.1 tron must not be encrypted. File permissions should grant read-only
12549 1.1 tron access to the system superuser account ("root"), and no access
12550 1.1 tron to anyone else. </p>
12551 1.1 tron
12552 1.1 tron <p> This feature is available in Postfix 2.6 and later, when Postfix is
12553 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
12554 1.1 tron
12555 1.1 tron
12556 1.1 tron </DD>
12557 1.1 tron
12558 1.1 tron <DT><b><a name="smtpd_tls_eecdh_grade">smtpd_tls_eecdh_grade</a>
12559 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
12560 1.1 tron
12561 1.1 tron <p> The Postfix SMTP server security grade for ephemeral elliptic-curve
12562 1.1 tron Diffie-Hellman (EECDH) key exchange. </p>
12563 1.1 tron
12564 1.1 tron <p> The available choices are: </p>
12565 1.1 tron
12566 1.1 tron <dl>
12567 1.1 tron
12568 1.1 tron <dt><b>none</b></dt> <dd> Don't use EECDH. Ciphers based on EECDH key
12569 1.1 tron exchange will be disabled. This is the default in official Postfix
12570 1.1 tron releases (<a href="postconf.5.html#mail_version">mail_version</a> = major.minor.patchlevel). </dd>
12571 1.1 tron
12572 1.1 tron <dt><b>strong</b></dt> <dd> Use EECDH with approximately 128
12573 1.1 tron bits of security at a reasonable computational cost. This is the
12574 1.1 tron current best-practice trade-off between security and computational
12575 1.1 tron efficiency. This is the default in Postfix snapshot releases
12576 1.1 tron (<a href="postconf.5.html#mail_version">mail_version</a> = major.minor-releasedate). </dd>
12577 1.1 tron
12578 1.1 tron <dt><b>ultra</b></dt> <dd> Use EECDH with approximately 192 bits of
12579 1.1 tron security at computational cost that is approximately twice as high
12580 1.1 tron as 128 bit strength ECC. Barring significant progress in attacks on
12581 1.1 tron elliptic curve crypto-systems, the "strong" curve is sufficient for most
12582 1.1 tron users. </dd>
12583 1.1 tron
12584 1.1 tron </dl>
12585 1.1 tron
12586 1.1 tron <p> This feature is available in Postfix 2.6 and later, when it is
12587 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
12588 1.1 tron
12589 1.1 tron
12590 1.1 tron </DD>
12591 1.1 tron
12592 1.1 tron <DT><b><a name="smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a>
12593 1.1 tron (default: empty)</b></DT><DD>
12594 1.1 tron
12595 1.1 tron <p> List of ciphers or cipher types to exclude from the SMTP server
12596 1.1 tron cipher list at all TLS security levels. Excluding valid ciphers
12597 1.1 tron can create interoperability problems. DO NOT exclude ciphers unless it
12598 1.1 tron is essential to do so. This is not an OpenSSL cipherlist; it is a simple
12599 1.1 tron list separated by whitespace and/or commas. The elements are a single
12600 1.1 tron cipher, or one or more "+" separated cipher properties, in which case
12601 1.1 tron only ciphers matching <b>all</b> the properties are excluded. </p>
12602 1.1 tron
12603 1.1 tron <p> Examples (some of these will cause problems): </p>
12604 1.1 tron
12605 1.1 tron <blockquote>
12606 1.1 tron <pre>
12607 1.1 tron <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> = aNULL
12608 1.1 tron <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> = MD5, DES
12609 1.1 tron <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> = DES+MD5
12610 1.1 tron <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> = AES256-SHA, DES-CBC3-MD5
12611 1.1 tron <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> = kEDH+aRSA
12612 1.1 tron </pre>
12613 1.1 tron </blockquote>
12614 1.1 tron
12615 1.1 tron <p> The first setting disables anonymous ciphers. The next setting
12616 1.1 tron disables ciphers that use the MD5 digest algorithm or the (single) DES
12617 1.1 tron encryption algorithm. The next setting disables ciphers that use MD5 and
12618 1.1 tron DES together. The next setting disables the two ciphers "AES256-SHA"
12619 1.1 tron and "DES-CBC3-MD5". The last setting disables ciphers that use "EDH"
12620 1.1 tron key exchange with RSA authentication. </p>
12621 1.1 tron
12622 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
12623 1.1 tron
12624 1.1 tron
12625 1.1 tron </DD>
12626 1.1 tron
12627 1.1 tron <DT><b><a name="smtpd_tls_fingerprint_digest">smtpd_tls_fingerprint_digest</a>
12628 1.1 tron (default: md5)</b></DT><DD>
12629 1.1 tron
12630 1.1 tron <p> The message digest algorithm used to construct client-certificate
12631 1.1 tron fingerprints for <b><a href="postconf.5.html#check_ccert_access">check_ccert_access</a></b> and
12632 1.1 tron <b><a href="postconf.5.html#permit_tls_clientcerts">permit_tls_clientcerts</a></b>. The default algorithm is <b>md5</b>,
12633 1.1 tron for backwards compatibility with Postfix releases prior to 2.5.
12634 1.1 tron </p>
12635 1.1 tron
12636 1.1 tron <p> The best practice algorithm is now <b>sha1</b>. Recent advances in hash
12637 1.1 tron function cryptanalysis have led to md5 being deprecated in favor of sha1.
12638 1.1 tron However, as long as there are no known "second pre-image" attacks
12639 1.1 tron against md5, its use in this context can still be considered safe.
12640 1.1 tron </p>
12641 1.1 tron
12642 1.1 tron <p> While additional digest algorithms are often available with OpenSSL's
12643 1.1 tron libcrypto, only those used by libssl in SSL cipher suites are available to
12644 1.1 tron Postfix. For now this means just md5 or sha1. </p>
12645 1.1 tron
12646 1.1 tron <p> To find the fingerprint of a specific certificate file, with a
12647 1.1 tron specific digest algorithm, run: </p>
12648 1.1 tron
12649 1.1 tron <blockquote>
12650 1.1 tron <pre>
12651 1.1 tron $ openssl x509 -noout -fingerprint -<i>digest</i> -in <i>certfile</i>.pem
12652 1.1 tron </pre>
12653 1.1 tron </blockquote>
12654 1.1 tron
12655 1.1 tron <p> The text to the right of "=" sign is the desired fingerprint.
12656 1.1 tron For example: </p>
12657 1.1 tron
12658 1.1 tron <blockquote>
12659 1.1 tron <pre>
12660 1.1 tron $ openssl x509 -noout -fingerprint -sha1 -in cert.pem
12661 1.1 tron SHA1 Fingerprint=D4:6A:AB:19:24:79:F8:32:BB:A6:CB:66:82:C0:8E:9B:EE:29:A8:1A
12662 1.1 tron </pre>
12663 1.1 tron </blockquote>
12664 1.1 tron
12665 1.1 tron <p> Example: client-certificate access table, with sha1 fingerprints: </p>
12666 1.1 tron
12667 1.1 tron <blockquote>
12668 1.1 tron <pre>
12669 1.1 tron /etc/postfix/<a href="postconf.5.html">main.cf</a>:
12670 1.1 tron <a href="postconf.5.html#smtpd_tls_fingerprint_digest">smtpd_tls_fingerprint_digest</a> = sha1
12671 1.1 tron <a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> =
12672 1.1 tron <a href="postconf.5.html#check_ccert_access">check_ccert_access</a> hash:/etc/postfix/access,
12673 1.1 tron reject
12674 1.1 tron </pre>
12675 1.1 tron <pre>
12676 1.1 tron /etc/postfix/access:
12677 1.1 tron # Action folded to next line...
12678 1.1 tron AF:88:7C:AD:51:95:6F:36:96:F6:01:FB:2E:48:CD:AB:49:25:A2:3B
12679 1.1 tron OK
12680 1.1 tron 85:16:78:FD:73:6E:CE:70:E0:31:5F:0D:3C:C8:6D:C4:2C:24:59:E1
12681 1.1 tron <a href="postconf.5.html#permit_auth_destination">permit_auth_destination</a>
12682 1.1 tron </pre>
12683 1.1 tron </blockquote>
12684 1.1 tron
12685 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
12686 1.1 tron
12687 1.1 tron
12688 1.1 tron </DD>
12689 1.1 tron
12690 1.1 tron <DT><b><a name="smtpd_tls_key_file">smtpd_tls_key_file</a>
12691 1.1 tron (default: $<a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a>)</b></DT><DD>
12692 1.1 tron
12693 1.1 tron <p> File with the Postfix SMTP server RSA private key in PEM format.
12694 1.1 tron This file may be combined with the Postfix SMTP server RSA certificate
12695 1.1 tron file specified with $<a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a>. </p>
12696 1.1 tron
12697 1.1 tron <p> The private key must be accessible without a pass-phrase, i.e. it
12698 1.1 tron must not be encrypted. File permissions should grant read-only
12699 1.1 tron access to the system superuser account ("root"), and no access
12700 1.1 tron to anyone else. </p>
12701 1.1 tron
12702 1.1 tron
12703 1.1 tron </DD>
12704 1.1 tron
12705 1.1 tron <DT><b><a name="smtpd_tls_loglevel">smtpd_tls_loglevel</a>
12706 1.1 tron (default: 0)</b></DT><DD>
12707 1.1 tron
12708 1.1 tron <p> Enable additional Postfix SMTP server logging of TLS activity.
12709 1.1 tron Each logging level also includes the information that is logged at
12710 1.1 tron a lower logging level. </p>
12711 1.1 tron
12712 1.1 tron <dl compact>
12713 1.1 tron
12714 1.1 tron <dt> </dt> <dd> 0 Disable logging of TLS activity. </dd>
12715 1.1 tron
12716 1.1 tron <dt> </dt> <dd> 1 Log TLS handshake and certificate information. </dd>
12717 1.1 tron
12718 1.1 tron <dt> </dt> <dd> 2 Log levels during TLS negotiation. </dd>
12719 1.1 tron
12720 1.1 tron <dt> </dt> <dd> 3 Log hexadecimal and ASCII dump of TLS negotiation
12721 1.1 tron process. </dd>
12722 1.1 tron
12723 1.1 tron <dt> </dt> <dd> 4 Also log hexadecimal and ASCII dump of complete
12724 1.1 tron transmission after STARTTLS. </dd>
12725 1.1 tron
12726 1.1 tron </dl>
12727 1.1 tron
12728 1.1 tron <p> Use "<a href="postconf.5.html#smtpd_tls_loglevel">smtpd_tls_loglevel</a> = 3" only in case of problems. Use of
12729 1.1 tron loglevel 4 is strongly discouraged. </p>
12730 1.1 tron
12731 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12732 1.1 tron
12733 1.1 tron
12734 1.1 tron </DD>
12735 1.1 tron
12736 1.1 tron <DT><b><a name="smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a>
12737 1.1 tron (default: medium)</b></DT><DD>
12738 1.1 tron
12739 1.1 tron <p> The minimum TLS cipher grade that the Postfix SMTP server
12740 1.1 tron will use with mandatory TLS encryption. Cipher types listed in
12741 1.1 tron <a href="postconf.5.html#smtpd_tls_mandatory_exclude_ciphers">smtpd_tls_mandatory_exclude_ciphers</a> or <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> are
12742 1.1 tron excluded from the base definition of the selected cipher grade. See
12743 1.1 tron <a href="postconf.5.html#smtpd_tls_ciphers">smtpd_tls_ciphers</a> for cipher controls that apply to opportunistic
12744 1.1 tron TLS. </p>
12745 1.1 tron
12746 1.1 tron <p> The following cipher grades are supported: </p>
12747 1.1 tron
12748 1.1 tron <dl>
12749 1.1 tron <dt><b>export</b></dt>
12750 1.1 tron <dd> Enable the mainstream "EXPORT" grade or better OpenSSL ciphers.
12751 1.1 tron This is the most appropriate setting for public MX hosts, and is always
12752 1.1 tron used with opportunistic TLS encryption. The underlying cipherlist
12753 1.1 tron is specified via the <a href="postconf.5.html#tls_export_cipherlist">tls_export_cipherlist</a> configuration parameter,
12754 1.1 tron which you are strongly encouraged to not change. The default value
12755 1.1 tron of <a href="postconf.5.html#tls_export_cipherlist">tls_export_cipherlist</a> includes anonymous ciphers, but these are
12756 1.1 tron automatically filtered out if the server is configured to ask for
12757 1.1 tron client certificates. If you must always exclude anonymous ciphers,
12758 1.1 tron set "<a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> = aNULL". To exclude anonymous ciphers
12759 1.1 tron only when TLS is enforced, set "<a href="postconf.5.html#smtpd_tls_mandatory_exclude_ciphers">smtpd_tls_mandatory_exclude_ciphers</a> =
12760 1.1 tron aNULL". </dd>
12761 1.1 tron
12762 1.1 tron <dt><b>low</b></dt>
12763 1.1 tron <dd> Enable the mainstream "LOW" grade or better OpenSSL ciphers. The
12764 1.1 tron underlying cipherlist is specified via the <a href="postconf.5.html#tls_low_cipherlist">tls_low_cipherlist</a>
12765 1.1 tron configuration parameter, which you are strongly encouraged to
12766 1.1 tron not change. The default value of <a href="postconf.5.html#tls_low_cipherlist">tls_low_cipherlist</a> includes
12767 1.1 tron anonymous ciphers, but these are automatically filtered out if the
12768 1.1 tron server is configured to ask for client certificates. If you must
12769 1.1 tron always exclude anonymous ciphers, set "<a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> =
12770 1.1 tron aNULL". To exclude anonymous ciphers only when TLS is enforced, set
12771 1.1 tron "<a href="postconf.5.html#smtpd_tls_mandatory_exclude_ciphers">smtpd_tls_mandatory_exclude_ciphers</a> = aNULL". </dd>
12772 1.1 tron
12773 1.1 tron <dt><b>medium</b></dt>
12774 1.1 tron <dd> Enable the mainstream "MEDIUM" grade or better OpenSSL ciphers. These
12775 1.1 tron are essentially the 128-bit or stronger ciphers. This is the default
12776 1.1 tron minimum strength for mandatory TLS encryption. MSAs that enforce
12777 1.1 tron TLS and have clients that do not support any "MEDIUM" or "HIGH"
12778 1.1 tron grade ciphers, may need to configure a weaker ("low" or "export")
12779 1.1 tron minimum cipher grade. The underlying cipherlist is specified via the
12780 1.1 tron <a href="postconf.5.html#tls_medium_cipherlist">tls_medium_cipherlist</a> configuration parameter, which you are strongly
12781 1.1 tron encouraged to not change. The default value of <a href="postconf.5.html#tls_medium_cipherlist">tls_medium_cipherlist</a>
12782 1.1 tron includes anonymous ciphers, but these are automatically filtered out if
12783 1.1 tron the server is configured to ask for client certificates. If you must
12784 1.1 tron always exclude anonymous ciphers, set "<a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> =
12785 1.1 tron aNULL". To exclude anonymous ciphers only when TLS is enforced, set
12786 1.1 tron "<a href="postconf.5.html#smtpd_tls_mandatory_exclude_ciphers">smtpd_tls_mandatory_exclude_ciphers</a> = aNULL". </dd>
12787 1.1 tron
12788 1.1 tron <dt><b>high</b></dt>
12789 1.1 tron <dd> Enable only the mainstream "HIGH" grade OpenSSL ciphers. The
12790 1.1 tron underlying cipherlist is specified via the <a href="postconf.5.html#tls_high_cipherlist">tls_high_cipherlist</a>
12791 1.1 tron configuration parameter, which you are strongly encouraged to
12792 1.1 tron not change. The default value of <a href="postconf.5.html#tls_high_cipherlist">tls_high_cipherlist</a> includes
12793 1.1 tron anonymous ciphers, but these are automatically filtered out if the
12794 1.1 tron server is configured to ask for client certificates. If you must
12795 1.1 tron always exclude anonymous ciphers, set "<a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> =
12796 1.1 tron aNULL". To exclude anonymous ciphers only when TLS is enforced, set
12797 1.1 tron "<a href="postconf.5.html#smtpd_tls_mandatory_exclude_ciphers">smtpd_tls_mandatory_exclude_ciphers</a> = aNULL". </dd>
12798 1.1 tron
12799 1.1 tron <dt><b>null</b></dt>
12800 1.1 tron <dd> Enable only the "NULL" OpenSSL ciphers, these provide authentication
12801 1.1 tron without encryption. This setting is only appropriate in the rare
12802 1.1 tron case that all clients are prepared to use NULL ciphers (not normally
12803 1.1 tron enabled in TLS clients). The underlying cipherlist is specified via the
12804 1.1 tron <a href="postconf.5.html#tls_null_cipherlist">tls_null_cipherlist</a> configuration parameter, which you are strongly
12805 1.1 tron encouraged to not change. The default value of <a href="postconf.5.html#tls_null_cipherlist">tls_null_cipherlist</a>
12806 1.1 tron excludes anonymous ciphers (OpenSSL 0.9.8 has NULL ciphers that offer
12807 1.1 tron data integrity without encryption or authentication). </dd>
12808 1.1 tron
12809 1.1 tron </dl>
12810 1.1 tron
12811 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
12812 1.1 tron
12813 1.1 tron
12814 1.1 tron </DD>
12815 1.1 tron
12816 1.1 tron <DT><b><a name="smtpd_tls_mandatory_exclude_ciphers">smtpd_tls_mandatory_exclude_ciphers</a>
12817 1.1 tron (default: empty)</b></DT><DD>
12818 1.1 tron
12819 1.1 tron <p> Additional list of ciphers or cipher types to exclude from the
12820 1.1 tron SMTP server cipher list at mandatory TLS security levels. This list
12821 1.1 tron works in addition to the exclusions listed with <a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a>
12822 1.1 tron (see there for syntax details). </p>
12823 1.1 tron
12824 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
12825 1.1 tron
12826 1.1 tron
12827 1.1 tron </DD>
12828 1.1 tron
12829 1.1 tron <DT><b><a name="smtpd_tls_mandatory_protocols">smtpd_tls_mandatory_protocols</a>
12830 1.1 tron (default: SSLv3, TLSv1)</b></DT><DD>
12831 1.1 tron
12832 1.1 tron <p> The SSL/TLS protocols accepted by the Postfix SMTP server with
12833 1.1 tron mandatory TLS encryption. If the list is empty, the server supports all
12834 1.1 tron available SSL/TLS protocol versions. A non-empty value is a list
12835 1.1 tron of protocol
12836 1.1 tron names separated by whitespace, commas or colons. The supported protocol
12837 1.1 tron names are "SSLv2", "SSLv3" and "TLSv1", and are not case sensitive. </p>
12838 1.1 tron
12839 1.1 tron <p> With Postfix ≥ 2.5 the parameter syntax is expanded to support
12840 1.1 tron protocol exclusions. One can now explicitly exclude SSLv2 by setting
12841 1.1 tron "<a href="postconf.5.html#smtpd_tls_mandatory_protocols">smtpd_tls_mandatory_protocols</a> = !SSLv2". To exclude both SSLv2 and
12842 1.1 tron SSLv3 set "<a href="postconf.5.html#smtpd_tls_mandatory_protocols">smtpd_tls_mandatory_protocols</a> = !SSLv2, !SSLv3". Listing
12843 1.1 tron the protocols to include, rather than protocols to exclude, is still
12844 1.1 tron supported, use the form you find more intuitive. </p>
12845 1.1 tron
12846 1.1 tron <p> Since SSL version 2 has known protocol weaknesses and is now
12847 1.1 tron deprecated, the default setting excludes "SSLv2". This means that
12848 1.1 tron by default, SSL version 2 will not be used at the "encrypt" security
12849 1.1 tron level. </p>
12850 1.1 tron
12851 1.1 tron <p> Example: </p>
12852 1.1 tron
12853 1.1 tron <pre>
12854 1.1 tron <a href="postconf.5.html#smtpd_tls_mandatory_protocols">smtpd_tls_mandatory_protocols</a> = TLSv1
12855 1.1 tron # Alternative form with Postfix ≥ 2.5:
12856 1.1 tron <a href="postconf.5.html#smtpd_tls_mandatory_protocols">smtpd_tls_mandatory_protocols</a> = !SSLv2, !SSLv3
12857 1.1 tron </pre>
12858 1.1 tron
12859 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
12860 1.1 tron
12861 1.1 tron
12862 1.1 tron </DD>
12863 1.1 tron
12864 1.1 tron <DT><b><a name="smtpd_tls_protocols">smtpd_tls_protocols</a>
12865 1.1 tron (default: empty)</b></DT><DD>
12866 1.1 tron
12867 1.1 tron <p> List of TLS protocols that the Postfix SMTP server will exclude
12868 1.1 tron or include with opportunistic TLS encryption. This parameter SHOULD be
12869 1.1 tron left at its default empty value, allowing all protocols to be used with
12870 1.1 tron opportunistic TLS. </p>
12871 1.1 tron
12872 1.1 tron <p> In <a href="postconf.5.html">main.cf</a> the values are separated by whitespace, commas or
12873 1.1 tron colons. An empty value means allow all protocols. The valid protocol
12874 1.1 tron names, (see <b>SSL_get_version(3)</b>), are "SSLv2", "SSLv3" and
12875 1.1 tron "TLSv1". In <a href="postconf.5.html#smtp_tls_policy_maps">smtp_tls_policy_maps</a> table entries, "protocols" attribute
12876 1.1 tron values are separated by a colon. </p>
12877 1.1 tron
12878 1.1 tron <p> To include a protocol list its name, to exclude it, prefix the name
12879 1.1 tron with a "!" character. To exclude SSLv2 even for opportunistic TLS set
12880 1.1 tron "<a href="postconf.5.html#smtpd_tls_protocols">smtpd_tls_protocols</a> = !SSLv2". To exclude both "SSLv2" and "SSLv3" set
12881 1.1 tron "<a href="postconf.5.html#smtpd_tls_protocols">smtpd_tls_protocols</a> = !SSLv2, !SSLv3". Explicitly listing the protocols to
12882 1.1 tron include, is supported, but not recommended. OpenSSL provides no mechanisms
12883 1.1 tron for excluding protocols not known at compile-time. If Postfix is linked
12884 1.1 tron against an OpenSSL library that supports additional protocol versions,
12885 1.1 tron they cannot be excluded using either syntax. </p>
12886 1.1 tron
12887 1.1 tron <p> Example: </p>
12888 1.1 tron <pre>
12889 1.1 tron <a href="postconf.5.html#smtpd_tls_protocols">smtpd_tls_protocols</a> = !SSLv2
12890 1.1 tron </pre>
12891 1.1 tron
12892 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
12893 1.1 tron
12894 1.1 tron
12895 1.1 tron </DD>
12896 1.1 tron
12897 1.1 tron <DT><b><a name="smtpd_tls_received_header">smtpd_tls_received_header</a>
12898 1.1 tron (default: no)</b></DT><DD>
12899 1.1 tron
12900 1.1 tron <p> Request that the Postfix SMTP server produces Received: message
12901 1.1 tron headers that include information about the protocol and cipher used,
12902 1.1 tron as well as the client CommonName and client certificate issuer
12903 1.1 tron CommonName. This is disabled by default, as the information may
12904 1.1 tron be modified in transit through other mail servers. Only information
12905 1.1 tron that was recorded by the final destination can be trusted. </p>
12906 1.1 tron
12907 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12908 1.1 tron
12909 1.1 tron
12910 1.1 tron </DD>
12911 1.1 tron
12912 1.1 tron <DT><b><a name="smtpd_tls_req_ccert">smtpd_tls_req_ccert</a>
12913 1.1 tron (default: no)</b></DT><DD>
12914 1.1 tron
12915 1.1 tron <p> With mandatory TLS encryption, require a trusted remote SMTP client
12916 1.1 tron certificate in order to allow TLS connections to proceed. This
12917 1.1 tron option implies "<a href="postconf.5.html#smtpd_tls_ask_ccert">smtpd_tls_ask_ccert</a> = yes". </p>
12918 1.1 tron
12919 1.1 tron <p> When TLS encryption is optional, this setting is ignored with
12920 1.1 tron a warning written to the mail log. </p>
12921 1.1 tron
12922 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
12923 1.1 tron
12924 1.1 tron
12925 1.1 tron </DD>
12926 1.1 tron
12927 1.1 tron <DT><b><a name="smtpd_tls_security_level">smtpd_tls_security_level</a>
12928 1.1 tron (default: empty)</b></DT><DD>
12929 1.1 tron
12930 1.1 tron <p> The SMTP TLS security level for the Postfix SMTP server; when
12931 1.1 tron a non-empty value is specified, this overrides the obsolete parameters
12932 1.1 tron <a href="postconf.5.html#smtpd_use_tls">smtpd_use_tls</a> and <a href="postconf.5.html#smtpd_enforce_tls">smtpd_enforce_tls</a>. This parameter is ignored with
12933 1.1 tron "<a href="postconf.5.html#smtpd_tls_wrappermode">smtpd_tls_wrappermode</a> = yes". </p>
12934 1.1 tron
12935 1.1 tron <p> Specify one of the following security levels: </p>
12936 1.1 tron
12937 1.1 tron <dl>
12938 1.1 tron
12939 1.1 tron <dt><b>none</b></dt> <dd> TLS will not be used. </dd>
12940 1.1 tron
12941 1.1 tron <dt><b>may</b></dt> <dd> Opportunistic TLS: announce STARTTLS support
12942 1.1 tron to SMTP clients, but do not require that clients use TLS encryption.
12943 1.1 tron </dd>
12944 1.1 tron
12945 1.1 tron <dt><b>encrypt</b></dt> <dd>Mandatory TLS encryption: announce
12946 1.1 tron STARTTLS support to SMTP clients, and require that clients use TLS
12947 1.1 tron encryption. According to <a href="http://tools.ietf.org/html/rfc2487">RFC 2487</a> this MUST NOT be applied in case
12948 1.1 tron of a publicly-referenced SMTP server. Instead, this option should
12949 1.1 tron be used only on dedicated servers. </dd>
12950 1.1 tron
12951 1.1 tron </dl>
12952 1.1 tron
12953 1.1 tron <p> Note 1: the "fingerprint", "verify" and "secure" levels are not
12954 1.1 tron supported here.
12955 1.1 tron The Postfix SMTP server logs a warning and uses "encrypt" instead.
12956 1.1 tron To verify SMTP client certificates, see <a href="TLS_README.html">TLS_README</a> for a discussion
12957 1.1 tron of the <a href="postconf.5.html#smtpd_tls_ask_ccert">smtpd_tls_ask_ccert</a>, <a href="postconf.5.html#smtpd_tls_req_ccert">smtpd_tls_req_ccert</a>, and <a href="postconf.5.html#permit_tls_clientcerts">permit_tls_clientcerts</a>
12958 1.1 tron features. </p>
12959 1.1 tron
12960 1.1 tron <p> Note 2: The parameter setting "<a href="postconf.5.html#smtpd_tls_security_level">smtpd_tls_security_level</a> =
12961 1.1 tron encrypt" implies "<a href="postconf.5.html#smtpd_tls_auth_only">smtpd_tls_auth_only</a> = yes".</p>
12962 1.1 tron
12963 1.1 tron <p> Note 3: when invoked via "sendmail -bs", Postfix will never
12964 1.1 tron offer STARTTLS due to insufficient privileges to access the server
12965 1.1 tron private key. This is intended behavior.</p>
12966 1.1 tron
12967 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
12968 1.1 tron
12969 1.1 tron
12970 1.1 tron </DD>
12971 1.1 tron
12972 1.1 tron <DT><b><a name="smtpd_tls_session_cache_database">smtpd_tls_session_cache_database</a>
12973 1.1 tron (default: empty)</b></DT><DD>
12974 1.1 tron
12975 1.1 tron <p> Name of the file containing the optional Postfix SMTP server
12976 1.1 tron TLS session cache. Specify a database type that supports enumeration,
12977 1.1 tron such as <b>btree</b> or <b>sdbm</b>; there is no need to support
12978 1.1 tron concurrent access. The file is created if it does not exist. The <a href="smtpd.8.html">smtpd(8)</a>
12979 1.1 tron daemon does not use this parameter directly, rather the cache is
12980 1.1 tron implemented indirectly in the <a href="tlsmgr.8.html">tlsmgr(8)</a> daemon. This means that
12981 1.1 tron per-smtpd-instance <a href="master.5.html">master.cf</a> overrides of this parameter are not
12982 1.1 tron effective. Note, that each of the cache databases supported by <a href="tlsmgr.8.html">tlsmgr(8)</a>
12983 1.1 tron daemon: $<a href="postconf.5.html#smtpd_tls_session_cache_database">smtpd_tls_session_cache_database</a>, $<a href="postconf.5.html#smtp_tls_session_cache_database">smtp_tls_session_cache_database</a>
12984 1.1 tron (and with Postfix 2.3 and later $<a href="postconf.5.html#lmtp_tls_session_cache_database">lmtp_tls_session_cache_database</a>), needs to be
12985 1.1 tron stored separately. It is not at this time possible to store multiple
12986 1.1 tron caches in a single database. </p>
12987 1.1 tron
12988 1.1 tron <p> Note: <b>dbm</b> databases are not suitable. TLS
12989 1.1 tron session objects are too large. </p>
12990 1.1 tron
12991 1.1 tron <p> As of version 2.5, Postfix no longer uses root privileges when
12992 1.1 tron opening this file. The file should now be stored under the Postfix-owned
12993 1.1 tron <a href="postconf.5.html#data_directory">data_directory</a>. As a migration aid, an attempt to open the file
12994 1.1 tron under a non-Postfix directory is redirected to the Postfix-owned
12995 1.1 tron <a href="postconf.5.html#data_directory">data_directory</a>, and a warning is logged. </p>
12996 1.1 tron
12997 1.1 tron <p> Example: </p>
12998 1.1 tron
12999 1.1 tron <pre>
13000 1.1 tron <a href="postconf.5.html#smtpd_tls_session_cache_database">smtpd_tls_session_cache_database</a> = btree:/var/lib/postfix/smtpd_scache
13001 1.1 tron </pre>
13002 1.1 tron
13003 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13004 1.1 tron
13005 1.1 tron
13006 1.1 tron </DD>
13007 1.1 tron
13008 1.1 tron <DT><b><a name="smtpd_tls_session_cache_timeout">smtpd_tls_session_cache_timeout</a>
13009 1.1 tron (default: 3600s)</b></DT><DD>
13010 1.1 tron
13011 1.1 tron <p> The expiration time of Postfix SMTP server TLS session cache
13012 1.1 tron information. A cache cleanup is performed periodically
13013 1.1 tron every $<a href="postconf.5.html#smtpd_tls_session_cache_timeout">smtpd_tls_session_cache_timeout</a> seconds. As with
13014 1.1 tron $<a href="postconf.5.html#smtpd_tls_session_cache_database">smtpd_tls_session_cache_database</a>, this parameter is implemented in the
13015 1.1 tron <a href="tlsmgr.8.html">tlsmgr(8)</a> daemon and therefore per-smtpd-instance <a href="master.5.html">master.cf</a> overrides
13016 1.1 tron are not possible. </p>
13017 1.1 tron
13018 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13019 1.1 tron
13020 1.1 tron
13021 1.1 tron </DD>
13022 1.1 tron
13023 1.1 tron <DT><b><a name="smtpd_tls_wrappermode">smtpd_tls_wrappermode</a>
13024 1.1 tron (default: no)</b></DT><DD>
13025 1.1 tron
13026 1.1 tron <p> Run the Postfix SMTP server in the non-standard "wrapper" mode,
13027 1.1 tron instead of using the STARTTLS command. </p>
13028 1.1 tron
13029 1.1 tron <p> If you want to support this service, enable a special port in
13030 1.1 tron <a href="master.5.html">master.cf</a>, and specify "-o <a href="postconf.5.html#smtpd_tls_wrappermode">smtpd_tls_wrappermode</a>=yes" on the SMTP
13031 1.1 tron server's command line. Port 465 (smtps) was once chosen for this
13032 1.1 tron purpose. </p>
13033 1.1 tron
13034 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13035 1.1 tron
13036 1.1 tron
13037 1.1 tron </DD>
13038 1.1 tron
13039 1.1 tron <DT><b><a name="smtpd_use_tls">smtpd_use_tls</a>
13040 1.1 tron (default: no)</b></DT><DD>
13041 1.1 tron
13042 1.1 tron <p> Opportunistic TLS: announce STARTTLS support to SMTP clients,
13043 1.1 tron but do not require that clients use TLS encryption. </p>
13044 1.1 tron
13045 1.1 tron <p> Note: when invoked via "<b>sendmail -bs</b>", Postfix will never offer
13046 1.1 tron STARTTLS due to insufficient privileges to access the server private
13047 1.1 tron key. This is intended behavior. </p>
13048 1.1 tron
13049 1.1 tron <p> This feature is available in Postfix 2.2 and later. With
13050 1.1 tron Postfix 2.3 and later use <a href="postconf.5.html#smtpd_tls_security_level">smtpd_tls_security_level</a> instead. </p>
13051 1.1 tron
13052 1.1 tron
13053 1.1 tron </DD>
13054 1.1 tron
13055 1.1 tron <DT><b><a name="soft_bounce">soft_bounce</a>
13056 1.1 tron (default: no)</b></DT><DD>
13057 1.1 tron
13058 1.1 tron <p>
13059 1.1 tron Safety net to keep mail queued that would otherwise be returned to
13060 1.1 tron the sender. This parameter disables locally-generated bounces,
13061 1.1 tron and prevents the Postfix SMTP server from rejecting mail permanently,
13062 1.1 tron by changing 5xx reply codes into 4xx. However, <a href="postconf.5.html#soft_bounce">soft_bounce</a> is no
13063 1.1 tron cure for address rewriting mistakes or mail routing mistakes.
13064 1.1 tron </p>
13065 1.1 tron
13066 1.1 tron <p>
13067 1.1 tron Example:
13068 1.1 tron </p>
13069 1.1 tron
13070 1.1 tron <pre>
13071 1.1 tron <a href="postconf.5.html#soft_bounce">soft_bounce</a> = yes
13072 1.1 tron </pre>
13073 1.1 tron
13074 1.1 tron
13075 1.1 tron </DD>
13076 1.1 tron
13077 1.1 tron <DT><b><a name="stale_lock_time">stale_lock_time</a>
13078 1.1 tron (default: 500s)</b></DT><DD>
13079 1.1 tron
13080 1.1 tron <p>
13081 1.1 tron The time after which a stale exclusive mailbox lockfile is removed.
13082 1.1 tron This is used for delivery to file or mailbox.
13083 1.1 tron </p>
13084 1.1 tron
13085 1.1 tron <p>
13086 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
13087 1.1 tron The default time unit is s (seconds).
13088 1.1 tron </p>
13089 1.1 tron
13090 1.1 tron
13091 1.1 tron </DD>
13092 1.1 tron
13093 1.1 tron <DT><b><a name="stress">stress</a>
13094 1.1 tron (default: empty)</b></DT><DD>
13095 1.1 tron
13096 1.1 tron <p> This feature is documented in the <a href="STRESS_README.html">STRESS_README</a> document. </p>
13097 1.1 tron
13098 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
13099 1.1 tron
13100 1.1 tron
13101 1.1 tron </DD>
13102 1.1 tron
13103 1.1 tron <DT><b><a name="strict_7bit_headers">strict_7bit_headers</a>
13104 1.1 tron (default: no)</b></DT><DD>
13105 1.1 tron
13106 1.1 tron <p>
13107 1.1 tron Reject mail with 8-bit text in message headers. This blocks mail
13108 1.1 tron from poorly written applications.
13109 1.1 tron </p>
13110 1.1 tron
13111 1.1 tron <p>
13112 1.1 tron This feature should not be enabled on a general purpose mail server,
13113 1.1 tron because it is likely to reject legitimate email.
13114 1.1 tron </p>
13115 1.1 tron
13116 1.1 tron <p>
13117 1.1 tron This feature is available in Postfix 2.0 and later.
13118 1.1 tron </p>
13119 1.1 tron
13120 1.1 tron
13121 1.1 tron </DD>
13122 1.1 tron
13123 1.1 tron <DT><b><a name="strict_8bitmime">strict_8bitmime</a>
13124 1.1 tron (default: no)</b></DT><DD>
13125 1.1 tron
13126 1.1 tron <p>
13127 1.1 tron Enable both <a href="postconf.5.html#strict_7bit_headers">strict_7bit_headers</a> and <a href="postconf.5.html#strict_8bitmime_body">strict_8bitmime_body</a>.
13128 1.1 tron </p>
13129 1.1 tron
13130 1.1 tron <p>
13131 1.1 tron This feature should not be enabled on a general purpose mail server,
13132 1.1 tron because it is likely to reject legitimate email.
13133 1.1 tron </p>
13134 1.1 tron
13135 1.1 tron <p>
13136 1.1 tron This feature is available in Postfix 2.0 and later.
13137 1.1 tron </p>
13138 1.1 tron
13139 1.1 tron
13140 1.1 tron </DD>
13141 1.1 tron
13142 1.1 tron <DT><b><a name="strict_8bitmime_body">strict_8bitmime_body</a>
13143 1.1 tron (default: no)</b></DT><DD>
13144 1.1 tron
13145 1.1 tron <p>
13146 1.1 tron Reject 8-bit message body text without 8-bit MIME content encoding
13147 1.1 tron information. This blocks mail from poorly written applications.
13148 1.1 tron </p>
13149 1.1 tron
13150 1.1 tron <p>
13151 1.1 tron Unfortunately, this also rejects majordomo approval requests when
13152 1.1 tron the included request contains valid 8-bit MIME mail, and it rejects
13153 1.1 tron bounces from mailers that do not MIME encapsulate 8-bit content
13154 1.1 tron (for example, bounces from qmail or from old versions of Postfix).
13155 1.1 tron </p>
13156 1.1 tron
13157 1.1 tron <p>
13158 1.1 tron This feature should not be enabled on a general purpose mail server,
13159 1.1 tron because it is likely to reject legitimate email.
13160 1.1 tron </p>
13161 1.1 tron
13162 1.1 tron <p>
13163 1.1 tron This feature is available in Postfix 2.0 and later.
13164 1.1 tron </p>
13165 1.1 tron
13166 1.1 tron
13167 1.1 tron </DD>
13168 1.1 tron
13169 1.1 tron <DT><b><a name="strict_mailbox_ownership">strict_mailbox_ownership</a>
13170 1.1 tron (default: yes)</b></DT><DD>
13171 1.1 tron
13172 1.1 tron <p> Defer delivery when a mailbox file is not owned by its recipient.
13173 1.1 tron The default setting is not backwards compatible. </p>
13174 1.1 tron
13175 1.1 tron <p> This feature is available in Postfix 2.5.3 and later. </p>
13176 1.1 tron
13177 1.1 tron
13178 1.1 tron </DD>
13179 1.1 tron
13180 1.1 tron <DT><b><a name="strict_mime_encoding_domain">strict_mime_encoding_domain</a>
13181 1.1 tron (default: no)</b></DT><DD>
13182 1.1 tron
13183 1.1 tron <p>
13184 1.1 tron Reject mail with invalid Content-Transfer-Encoding: information
13185 1.1 tron for the message/* or multipart/* MIME content types. This blocks
13186 1.1 tron mail from poorly written software.
13187 1.1 tron </p>
13188 1.1 tron
13189 1.1 tron <p>
13190 1.1 tron This feature should not be enabled on a general purpose mail server,
13191 1.1 tron because it will reject mail after a single violation.
13192 1.1 tron </p>
13193 1.1 tron
13194 1.1 tron <p>
13195 1.1 tron This feature is available in Postfix 2.0 and later.
13196 1.1 tron </p>
13197 1.1 tron
13198 1.1 tron
13199 1.1 tron </DD>
13200 1.1 tron
13201 1.1 tron <DT><b><a name="strict_rfc821_envelopes">strict_rfc821_envelopes</a>
13202 1.1 tron (default: no)</b></DT><DD>
13203 1.1 tron
13204 1.1 tron <p>
13205 1.1 tron Require that addresses received in SMTP MAIL FROM and RCPT TO
13206 1.1 tron commands are enclosed with <>, and that those addresses do
13207 1.1 tron not contain <a href="http://tools.ietf.org/html/rfc822">RFC 822</a> style comments or phrases. This stops mail
13208 1.1 tron from poorly written software.
13209 1.1 tron </p>
13210 1.1 tron
13211 1.1 tron <p>
13212 1.1 tron By default, the Postfix SMTP server accepts <a href="http://tools.ietf.org/html/rfc822">RFC 822</a> syntax in MAIL
13213 1.1 tron FROM and RCPT TO addresses.
13214 1.1 tron </p>
13215 1.1 tron
13216 1.1 tron
13217 1.1 tron </DD>
13218 1.1 tron
13219 1.1 tron <DT><b><a name="sun_mailtool_compatibility">sun_mailtool_compatibility</a>
13220 1.1 tron (default: no)</b></DT><DD>
13221 1.1 tron
13222 1.1 tron <p>
13223 1.1 tron Obsolete SUN mailtool compatibility feature. Instead, use
13224 1.1 tron "<a href="postconf.5.html#mailbox_delivery_lock">mailbox_delivery_lock</a> = dotlock".
13225 1.1 tron </p>
13226 1.1 tron
13227 1.1 tron
13228 1.1 tron </DD>
13229 1.1 tron
13230 1.1 tron <DT><b><a name="swap_bangpath">swap_bangpath</a>
13231 1.1 tron (default: yes)</b></DT><DD>
13232 1.1 tron
13233 1.1 tron <p>
13234 1.1 tron Enable the rewriting of "site!user" into "user@site". This is
13235 1.1 tron necessary if your machine is connected to UUCP networks. It is
13236 1.1 tron enabled by default.
13237 1.1 tron </p>
13238 1.1 tron
13239 1.1 tron <p> Note: with Postfix version 2.2, message header address rewriting
13240 1.1 tron happens only when one of the following conditions is true: </p>
13241 1.1 tron
13242 1.1 tron <ul>
13243 1.1 tron
13244 1.1 tron <li> The message is received with the Postfix <a href="sendmail.1.html">sendmail(1)</a> command,
13245 1.1 tron
13246 1.1 tron <li> The message is received from a network client that matches
13247 1.1 tron $<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a>,
13248 1.1 tron
13249 1.1 tron <li> The message is received from the network, and the
13250 1.1 tron <a href="postconf.5.html#remote_header_rewrite_domain">remote_header_rewrite_domain</a> parameter specifies a non-empty value.
13251 1.1 tron
13252 1.1 tron </ul>
13253 1.1 tron
13254 1.1 tron <p> To get the behavior before Postfix version 2.2, specify
13255 1.1 tron "<a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> = static:all". </p>
13256 1.1 tron
13257 1.1 tron <p>
13258 1.1 tron Example:
13259 1.1 tron </p>
13260 1.1 tron
13261 1.1 tron <pre>
13262 1.1 tron <a href="postconf.5.html#swap_bangpath">swap_bangpath</a> = no
13263 1.1 tron </pre>
13264 1.1 tron
13265 1.1 tron
13266 1.1 tron </DD>
13267 1.1 tron
13268 1.1 tron <DT><b><a name="syslog_facility">syslog_facility</a>
13269 1.1 tron (default: mail)</b></DT><DD>
13270 1.1 tron
13271 1.1 tron <p>
13272 1.1 tron The syslog facility of Postfix logging. Specify a facility as
13273 1.1 tron defined in syslog.conf(5). The default facility is "mail".
13274 1.1 tron </p>
13275 1.1 tron
13276 1.1 tron <p>
13277 1.1 tron Warning: a non-default <a href="postconf.5.html#syslog_facility">syslog_facility</a> setting takes effect only
13278 1.1 tron after a Postfix process has completed initialization. Errors during
13279 1.1 tron process initialization will be logged with the default facility.
13280 1.1 tron Examples are errors while parsing the command line arguments, and
13281 1.1 tron errors while accessing the Postfix <a href="postconf.5.html">main.cf</a> configuration file.
13282 1.1 tron </p>
13283 1.1 tron
13284 1.1 tron
13285 1.1 tron </DD>
13286 1.1 tron
13287 1.1 tron <DT><b><a name="syslog_name">syslog_name</a>
13288 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
13289 1.1 tron
13290 1.1 tron <p>
13291 1.1 tron The mail system name that is prepended to the process name in syslog
13292 1.1 tron records, so that "smtpd" becomes, for example, "postfix/smtpd".
13293 1.1 tron </p>
13294 1.1 tron
13295 1.1 tron <p>
13296 1.1 tron Warning: a non-default <a href="postconf.5.html#syslog_name">syslog_name</a> setting takes effect only after
13297 1.1 tron a Postfix process has completed initialization. Errors during
13298 1.1 tron process initialization will be logged with the default name. Examples
13299 1.1 tron are errors while parsing the command line arguments, and errors
13300 1.1 tron while accessing the Postfix <a href="postconf.5.html">main.cf</a> configuration file.
13301 1.1 tron </p>
13302 1.1 tron
13303 1.1 tron
13304 1.1 tron </DD>
13305 1.1 tron
13306 1.1 tron <DT><b><a name="tcp_windowsize">tcp_windowsize</a>
13307 1.1 tron (default: 0)</b></DT><DD>
13308 1.1 tron
13309 1.1 tron <p> An optional workaround for routers that break TCP window scaling.
13310 1.1 tron Specify a value > 0 and < 65536 to enable this feature. With
13311 1.1 tron Postfix TCP servers (<a href="smtpd.8.html">smtpd(8)</a>, <a href="qmqpd.8.html">qmqpd(8)</a>), this feature is implemented
13312 1.1 tron by the Postfix <a href="master.8.html">master(8)</a> daemon. </p>
13313 1.1 tron
13314 1.1 tron <p> To change this parameter without stopping Postfix, you need to
13315 1.1 tron first terminate all Postfix TCP servers: </p>
13316 1.1 tron
13317 1.1 tron <blockquote>
13318 1.1 tron <pre>
13319 1.1 tron # postconf -e <a href="postconf.5.html#master_service_disable">master_service_disable</a>=inet
13320 1.1 tron # postfix reload
13321 1.1 tron </pre>
13322 1.1 tron </blockquote>
13323 1.1 tron
13324 1.1 tron <p> This immediately terminates all processes that accept network
13325 1.1 tron connections. Next, you enable Postfix TCP servers with the updated
13326 1.1 tron <a href="postconf.5.html#tcp_windowsize">tcp_windowsize</a> setting: </p>
13327 1.1 tron
13328 1.1 tron <blockquote>
13329 1.1 tron <pre>
13330 1.1 tron # postconf -e <a href="postconf.5.html#tcp_windowsize">tcp_windowsize</a>=65535 <a href="postconf.5.html#master_service_disable">master_service_disable</a>=
13331 1.1 tron # postfix reload
13332 1.1 tron </pre>
13333 1.1 tron </blockquote>
13334 1.1 tron
13335 1.1 tron <p> If you skip these steps with a running Postfix system, then the
13336 1.1 tron <a href="postconf.5.html#tcp_windowsize">tcp_windowsize</a> change will work only for Postfix TCP clients (<a href="smtp.8.html">smtp(8)</a>,
13337 1.1 tron <a href="lmtp.8.html">lmtp(8)</a>). </p>
13338 1.1 tron
13339 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
13340 1.1 tron
13341 1.1 tron
13342 1.1 tron </DD>
13343 1.1 tron
13344 1.1 tron <DT><b><a name="tls_daemon_random_bytes">tls_daemon_random_bytes</a>
13345 1.1 tron (default: 32)</b></DT><DD>
13346 1.1 tron
13347 1.1 tron <p> The number of pseudo-random bytes that an <a href="smtp.8.html">smtp(8)</a> or <a href="smtpd.8.html">smtpd(8)</a>
13348 1.1 tron process requests from the <a href="tlsmgr.8.html">tlsmgr(8)</a> server in order to seed its
13349 1.1 tron internal pseudo random number generator (PRNG). The default of 32
13350 1.1 tron bytes (equivalent to 256 bits) is sufficient to generate a 128bit
13351 1.1 tron (or 168bit) session key. </p>
13352 1.1 tron
13353 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13354 1.1 tron
13355 1.1 tron
13356 1.1 tron </DD>
13357 1.1 tron
13358 1.1 tron <DT><b><a name="tls_eecdh_strong_curve">tls_eecdh_strong_curve</a>
13359 1.1 tron (default: prime256v1)</b></DT><DD>
13360 1.1 tron
13361 1.1 tron <p> The elliptic curve used by the SMTP server for sensibly strong
13362 1.1 tron ephemeral ECDH key exchange. This curve is used by the Postfix SMTP
13363 1.1 tron server when "<a href="postconf.5.html#smtpd_tls_eecdh_grade">smtpd_tls_eecdh_grade</a> = strong". The phrase "sensibly
13364 1.1 tron strong" means approximately 128-bit security based on best known
13365 1.1 tron attacks. The selected curve must be implemented by OpenSSL (as
13366 1.1 tron reported by ecparam(1) with the "-list_curves" option) and be one
13367 1.1 tron of the curves listed in Section 5.1.1 of <a href="http://tools.ietf.org/html/rfc4492">RFC 4492</a>. You should not
13368 1.1 tron generally change this setting. </p>
13369 1.1 tron
13370 1.1 tron <p> This default curve is specified in NSA "Suite B" Cryptography
13371 1.1 tron (see <a href="http://www.nsa.gov/ia/industry/crypto_suite_b.cfm">http://www.nsa.gov/ia/industry/crypto_suite_b.cfm</a>) for
13372 1.1 tron information classified as SECRET. </p>
13373 1.1 tron
13374 1.1 tron <p> Note: elliptic curve names are poorly standardized; different
13375 1.1 tron standards groups are assigning different names to the same underlying
13376 1.1 tron curves. The curve with the X9.62 name "prime256v1" is also known
13377 1.1 tron under the SECG name "secp256r1", but OpenSSL does not recognize the
13378 1.1 tron latter name. </p>
13379 1.1 tron
13380 1.1 tron <p> This feature is available in Postfix 2.6 and later, when it is
13381 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
13382 1.1 tron
13383 1.1 tron
13384 1.1 tron </DD>
13385 1.1 tron
13386 1.1 tron <DT><b><a name="tls_eecdh_ultra_curve">tls_eecdh_ultra_curve</a>
13387 1.1 tron (default: secp384r1)</b></DT><DD>
13388 1.1 tron
13389 1.1 tron <p> The elliptic curve used by the SMTP server for maximally strong
13390 1.1 tron ephemeral ECDH key exchange. This curve is used by the Postfix SMTP
13391 1.1 tron server when "<a href="postconf.5.html#smtpd_tls_eecdh_grade">smtpd_tls_eecdh_grade</a> = ultra". The phrase "maximally
13392 1.1 tron strong" means approximately 192-bit security based on best known attacks.
13393 1.1 tron This additional strength comes at a significant computational cost, most
13394 1.1 tron users should instead set "<a href="postconf.5.html#smtpd_tls_eecdh_grade">smtpd_tls_eecdh_grade</a> = strong". The selected
13395 1.1 tron curve must be implemented by OpenSSL (as reported by ecparam(1) with the
13396 1.1 tron "-list_curves" option) and be one of the curves listed in Section 5.1.1
13397 1.1 tron of <a href="http://tools.ietf.org/html/rfc4492">RFC 4492</a>. You should not generally change this setting. </p>
13398 1.1 tron
13399 1.1 tron <p> This default "ultra" curve is specified in NSA "Suite B" Cryptography
13400 1.1 tron (see <a href="http://www.nsa.gov/ia/industry/crypto_suite_b.cfm">http://www.nsa.gov/ia/industry/crypto_suite_b.cfm</a>) for information
13401 1.1 tron classified as TOP SECRET. </p>
13402 1.1 tron
13403 1.1 tron <p> This feature is available in Postfix 2.6 and later, when it is
13404 1.1 tron compiled and linked with OpenSSL 0.9.9 or later. </p>
13405 1.1 tron
13406 1.1 tron
13407 1.1 tron </DD>
13408 1.1 tron
13409 1.1 tron <DT><b><a name="tls_export_cipherlist">tls_export_cipherlist</a>
13410 1.1 tron (default: ALL:+RC4:@STRENGTH)</b></DT><DD>
13411 1.1 tron
13412 1.1 tron <p> The OpenSSL cipherlist for "EXPORT" or higher grade ciphers. This
13413 1.1 tron defines the meaning of the "export" setting in <a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a>,
13414 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> and <a href="postconf.5.html#lmtp_tls_mandatory_ciphers">lmtp_tls_mandatory_ciphers</a>. This is
13415 1.1 tron the cipherlist for the opportunistic ("may") TLS client security
13416 1.1 tron level and is the default cipherlist for the SMTP server. You are
13417 1.1 tron strongly encouraged to not change this setting. </p>
13418 1.1 tron
13419 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
13420 1.1 tron
13421 1.1 tron
13422 1.1 tron </DD>
13423 1.1 tron
13424 1.1 tron <DT><b><a name="tls_high_cipherlist">tls_high_cipherlist</a>
13425 1.1 tron (default: ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@STRENGTH)</b></DT><DD>
13426 1.1 tron
13427 1.1 tron <p> The OpenSSL cipherlist for "HIGH" grade ciphers. This defines
13428 1.1 tron the meaning of the "high" setting in <a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a>,
13429 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> and <a href="postconf.5.html#lmtp_tls_mandatory_ciphers">lmtp_tls_mandatory_ciphers</a>. You are
13430 1.1 tron strongly encouraged to not change this setting. </p>
13431 1.1 tron
13432 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
13433 1.1 tron
13434 1.1 tron
13435 1.1 tron </DD>
13436 1.1 tron
13437 1.1 tron <DT><b><a name="tls_low_cipherlist">tls_low_cipherlist</a>
13438 1.1 tron (default: ALL:!EXPORT:+RC4:@STRENGTH)</b></DT><DD>
13439 1.1 tron
13440 1.1 tron <p> The OpenSSL cipherlist for "LOW" or higher grade ciphers. This defines
13441 1.1 tron the meaning of the "low" setting in <a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a>,
13442 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> and <a href="postconf.5.html#lmtp_tls_mandatory_ciphers">lmtp_tls_mandatory_ciphers</a>. You are
13443 1.1 tron strongly encouraged to not change this setting. </p>
13444 1.1 tron
13445 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
13446 1.1 tron
13447 1.1 tron
13448 1.1 tron </DD>
13449 1.1 tron
13450 1.1 tron <DT><b><a name="tls_medium_cipherlist">tls_medium_cipherlist</a>
13451 1.1 tron (default: ALL:!EXPORT:!LOW:+RC4:@STRENGTH)</b></DT><DD>
13452 1.1 tron
13453 1.1 tron <p> The OpenSSL cipherlist for "MEDIUM" or higher grade ciphers. This
13454 1.1 tron defines the meaning of the "medium" setting in <a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a>,
13455 1.1 tron <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> and <a href="postconf.5.html#lmtp_tls_mandatory_ciphers">lmtp_tls_mandatory_ciphers</a>. This is
13456 1.1 tron the default cipherlist for mandatory TLS encryption in the TLS
13457 1.1 tron client (with anonymous ciphers disabled when verifying server
13458 1.1 tron certificates). You are strongly encouraged to not change this
13459 1.1 tron setting. </p>
13460 1.1 tron
13461 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
13462 1.1 tron
13463 1.1 tron
13464 1.1 tron </DD>
13465 1.1 tron
13466 1.1 tron <DT><b><a name="tls_null_cipherlist">tls_null_cipherlist</a>
13467 1.1 tron (default: eNULL:!aNULL)</b></DT><DD>
13468 1.1 tron
13469 1.1 tron <p> The OpenSSL cipherlist for "NULL" grade ciphers that provide
13470 1.1 tron authentication without encryption. This defines the meaning of the "null"
13471 1.1 tron setting in smtpd_mandatory_tls_ciphers, <a href="postconf.5.html#smtp_tls_mandatory_ciphers">smtp_tls_mandatory_ciphers</a> and
13472 1.1 tron <a href="postconf.5.html#lmtp_tls_mandatory_ciphers">lmtp_tls_mandatory_ciphers</a>. You are strongly encouraged to not
13473 1.1 tron change this setting. </p>
13474 1.1 tron
13475 1.1 tron <p> This feature is available in Postfix 2.3 and later. </p>
13476 1.1 tron
13477 1.1 tron
13478 1.1 tron </DD>
13479 1.1 tron
13480 1.1 tron <DT><b><a name="tls_random_bytes">tls_random_bytes</a>
13481 1.1 tron (default: 32)</b></DT><DD>
13482 1.1 tron
13483 1.1 tron <p> The number of bytes that <a href="tlsmgr.8.html">tlsmgr(8)</a> reads from $<a href="postconf.5.html#tls_random_source">tls_random_source</a>
13484 1.1 tron when (re)seeding the in-memory pseudo random number generator (PRNG)
13485 1.1 tron pool. The default of 32 bytes (256 bits) is good enough for 128bit
13486 1.1 tron symmetric keys. If using EGD or a device file, a maximum of 255
13487 1.1 tron bytes is read. </p>
13488 1.1 tron
13489 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13490 1.1 tron
13491 1.1 tron
13492 1.1 tron </DD>
13493 1.1 tron
13494 1.1 tron <DT><b><a name="tls_random_exchange_name">tls_random_exchange_name</a>
13495 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
13496 1.1 tron
13497 1.1 tron <p> Name of the pseudo random number generator (PRNG) state file
13498 1.1 tron that is maintained by <a href="tlsmgr.8.html">tlsmgr(8)</a>. The file is created when it does
13499 1.1 tron not exist, and its length is fixed at 1024 bytes. </p>
13500 1.1 tron
13501 1.1 tron <p> As of version 2.5, Postfix no longer uses root privileges when
13502 1.1 tron opening this file, and the default file location was changed from
13503 1.1 tron ${<a href="postconf.5.html#config_directory">config_directory</a>}/prng_exch to ${<a href="postconf.5.html#data_directory">data_directory</a>}/prng_exch. As
13504 1.1 tron a migration aid, an attempt to open the file under a non-Postfix
13505 1.1 tron directory is redirected to the Postfix-owned <a href="postconf.5.html#data_directory">data_directory</a>, and a
13506 1.1 tron warning is logged. </p>
13507 1.1 tron
13508 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13509 1.1 tron
13510 1.1 tron
13511 1.1 tron </DD>
13512 1.1 tron
13513 1.1 tron <DT><b><a name="tls_random_prng_update_period">tls_random_prng_update_period</a>
13514 1.1 tron (default: 3600s)</b></DT><DD>
13515 1.1 tron
13516 1.1 tron <p> The time between attempts by <a href="tlsmgr.8.html">tlsmgr(8)</a> to save the state of
13517 1.1 tron the pseudo random number generator (PRNG) to the file specified
13518 1.1 tron with $<a href="postconf.5.html#tls_random_exchange_name">tls_random_exchange_name</a>. </p>
13519 1.1 tron
13520 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13521 1.1 tron
13522 1.1 tron
13523 1.1 tron </DD>
13524 1.1 tron
13525 1.1 tron <DT><b><a name="tls_random_reseed_period">tls_random_reseed_period</a>
13526 1.1 tron (default: 3600s)</b></DT><DD>
13527 1.1 tron
13528 1.1 tron <p> The maximal time between attempts by <a href="tlsmgr.8.html">tlsmgr(8)</a> to re-seed the
13529 1.1 tron in-memory pseudo random number generator (PRNG) pool from external
13530 1.1 tron sources. The actual time between re-seeding attempts is calculated
13531 1.1 tron using the PRNG, and is between 0 and the time specified. </p>
13532 1.1 tron
13533 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13534 1.1 tron
13535 1.1 tron
13536 1.1 tron </DD>
13537 1.1 tron
13538 1.1 tron <DT><b><a name="tls_random_source">tls_random_source</a>
13539 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
13540 1.1 tron
13541 1.1 tron <p> The external entropy source for the in-memory <a href="tlsmgr.8.html">tlsmgr(8)</a> pseudo
13542 1.1 tron random number generator (PRNG) pool. Be sure to specify a non-blocking
13543 1.1 tron source. If this source is not a regular file, the entropy source
13544 1.1 tron type must be prepended: egd:/path/to/egd_socket for a source with
13545 1.1 tron EGD compatible socket interface, or dev:/path/to/device for a
13546 1.1 tron device file. </p>
13547 1.1 tron
13548 1.1 tron <p> Note: on OpenBSD systems specify /dev/arandom when /dev/urandom
13549 1.1 tron gives timeout errors. </p>
13550 1.1 tron
13551 1.1 tron <p> This feature is available in Postfix 2.2 and later. </p>
13552 1.1 tron
13553 1.1 tron
13554 1.1 tron </DD>
13555 1.1 tron
13556 1.1 tron <DT><b><a name="trace_service_name">trace_service_name</a>
13557 1.1 tron (default: trace)</b></DT><DD>
13558 1.1 tron
13559 1.1 tron <p>
13560 1.1 tron The name of the trace service. This service is implemented by the
13561 1.1 tron <a href="bounce.8.html">bounce(8)</a> daemon and maintains a record
13562 1.1 tron of mail deliveries and produces a mail delivery report when verbose
13563 1.1 tron delivery is requested with "<b>sendmail -v</b>".
13564 1.1 tron </p>
13565 1.1 tron
13566 1.1 tron <p>
13567 1.1 tron This feature is available in Postfix 2.1 and later.
13568 1.1 tron </p>
13569 1.1 tron
13570 1.1 tron
13571 1.1 tron </DD>
13572 1.1 tron
13573 1.1 tron <DT><b><a name="transport_delivery_slot_cost">transport_delivery_slot_cost</a>
13574 1.1 tron (default: $<a href="postconf.5.html#default_delivery_slot_cost">default_delivery_slot_cost</a>)</b></DT><DD>
13575 1.1 tron
13576 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_delivery_slot_cost">default_delivery_slot_cost</a>
13577 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13578 1.1 tron the message delivery transport. </p>
13579 1.1 tron
13580 1.1 tron
13581 1.1 tron </DD>
13582 1.1 tron
13583 1.1 tron <DT><b><a name="transport_delivery_slot_discount">transport_delivery_slot_discount</a>
13584 1.1 tron (default: $<a href="postconf.5.html#default_delivery_slot_discount">default_delivery_slot_discount</a>)</b></DT><DD>
13585 1.1 tron
13586 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_delivery_slot_discount">default_delivery_slot_discount</a>
13587 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13588 1.1 tron the message delivery transport. </p>
13589 1.1 tron
13590 1.1 tron
13591 1.1 tron </DD>
13592 1.1 tron
13593 1.1 tron <DT><b><a name="transport_delivery_slot_loan">transport_delivery_slot_loan</a>
13594 1.1 tron (default: $<a href="postconf.5.html#default_delivery_slot_loan">default_delivery_slot_loan</a>)</b></DT><DD>
13595 1.1 tron
13596 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_delivery_slot_loan">default_delivery_slot_loan</a>
13597 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13598 1.1 tron the message delivery transport. </p>
13599 1.1 tron
13600 1.1 tron
13601 1.1 tron </DD>
13602 1.1 tron
13603 1.1 tron <DT><b><a name="transport_destination_concurrency_failed_cohort_limit">transport_destination_concurrency_failed_cohort_limit</a>
13604 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_failed_cohort_limit">default_destination_concurrency_failed_cohort_limit</a>)</b></DT><DD>
13605 1.1 tron
13606 1.1 tron <p> A transport-specific override for the
13607 1.1 tron <a href="postconf.5.html#default_destination_concurrency_failed_cohort_limit">default_destination_concurrency_failed_cohort_limit</a> parameter value,
13608 1.1 tron where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of the message delivery
13609 1.1 tron transport. </p>
13610 1.1 tron
13611 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
13612 1.1 tron
13613 1.1 tron
13614 1.1 tron </DD>
13615 1.1 tron
13616 1.1 tron <DT><b><a name="transport_destination_concurrency_limit">transport_destination_concurrency_limit</a>
13617 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_limit">default_destination_concurrency_limit</a>)</b></DT><DD>
13618 1.1 tron
13619 1.1 tron <p> A transport-specific override for the
13620 1.1 tron <a href="postconf.5.html#default_destination_concurrency_limit">default_destination_concurrency_limit</a> parameter value, where
13621 1.1 tron <i>transport</i> is the <a href="master.5.html">master.cf</a> name of the message delivery
13622 1.1 tron transport. </p>
13623 1.1 tron
13624 1.1 tron
13625 1.1 tron </DD>
13626 1.1 tron
13627 1.1 tron <DT><b><a name="transport_destination_concurrency_negative_feedback">transport_destination_concurrency_negative_feedback</a>
13628 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_negative_feedback">default_destination_concurrency_negative_feedback</a>)</b></DT><DD>
13629 1.1 tron
13630 1.1 tron <p> A transport-specific override for the
13631 1.1 tron <a href="postconf.5.html#default_destination_concurrency_negative_feedback">default_destination_concurrency_negative_feedback</a> parameter value,
13632 1.1 tron where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of the message delivery
13633 1.1 tron transport. </p>
13634 1.1 tron
13635 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
13636 1.1 tron
13637 1.1 tron
13638 1.1 tron </DD>
13639 1.1 tron
13640 1.1 tron <DT><b><a name="transport_destination_concurrency_positive_feedback">transport_destination_concurrency_positive_feedback</a>
13641 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_positive_feedback">default_destination_concurrency_positive_feedback</a>)</b></DT><DD>
13642 1.1 tron
13643 1.1 tron <p> A transport-specific override for the
13644 1.1 tron <a href="postconf.5.html#default_destination_concurrency_positive_feedback">default_destination_concurrency_positive_feedback</a> parameter value,
13645 1.1 tron where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of the message delivery
13646 1.1 tron transport. </p>
13647 1.1 tron
13648 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
13649 1.1 tron
13650 1.1 tron
13651 1.1 tron </DD>
13652 1.1 tron
13653 1.1 tron <DT><b><a name="transport_destination_rate_delay">transport_destination_rate_delay</a>
13654 1.1 tron (default: $<a href="postconf.5.html#default_destination_rate_delay">default_destination_rate_delay</a>)</b></DT><DD>
13655 1.1 tron
13656 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_destination_rate_delay">default_destination_rate_delay</a>
13657 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13658 1.1 tron the message delivery transport. </p>
13659 1.1 tron
13660 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
13661 1.1 tron
13662 1.1 tron
13663 1.1 tron </DD>
13664 1.1 tron
13665 1.1 tron <DT><b><a name="transport_destination_recipient_limit">transport_destination_recipient_limit</a>
13666 1.1 tron (default: $<a href="postconf.5.html#default_destination_recipient_limit">default_destination_recipient_limit</a>)</b></DT><DD>
13667 1.1 tron
13668 1.1 tron <p> A transport-specific override for the
13669 1.1 tron <a href="postconf.5.html#default_destination_recipient_limit">default_destination_recipient_limit</a> parameter value, where
13670 1.1 tron <i>transport</i> is the <a href="master.5.html">master.cf</a> name of the message delivery
13671 1.1 tron transport. </p>
13672 1.1 tron
13673 1.1 tron
13674 1.1 tron </DD>
13675 1.1 tron
13676 1.1 tron <DT><b><a name="transport_extra_recipient_limit">transport_extra_recipient_limit</a>
13677 1.1 tron (default: $<a href="postconf.5.html#default_extra_recipient_limit">default_extra_recipient_limit</a>)</b></DT><DD>
13678 1.1 tron
13679 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_extra_recipient_limit">default_extra_recipient_limit</a>
13680 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13681 1.1 tron the message delivery transport. </p>
13682 1.1 tron
13683 1.1 tron
13684 1.1 tron </DD>
13685 1.1 tron
13686 1.1 tron <DT><b><a name="transport_initial_destination_concurrency">transport_initial_destination_concurrency</a>
13687 1.1 tron (default: $<a href="postconf.5.html#initial_destination_concurrency">initial_destination_concurrency</a>)</b></DT><DD>
13688 1.1 tron
13689 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#initial_destination_concurrency">initial_destination_concurrency</a>
13690 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13691 1.1 tron the message delivery transport. </p>
13692 1.1 tron
13693 1.1 tron <p> This feature is available in Postfix 2.5 and later. </p>
13694 1.1 tron
13695 1.1 tron
13696 1.1 tron </DD>
13697 1.1 tron
13698 1.1 tron <DT><b><a name="transport_maps">transport_maps</a>
13699 1.1 tron (default: empty)</b></DT><DD>
13700 1.1 tron
13701 1.1 tron <p>
13702 1.1 tron Optional lookup tables with mappings from recipient address to
13703 1.1 tron (message delivery transport, next-hop destination). See <a href="transport.5.html">transport(5)</a>
13704 1.1 tron for details.
13705 1.1 tron </p>
13706 1.1 tron
13707 1.1 tron <p>
13708 1.1 tron Specify zero or more "<a href="DATABASE_README.html">type:table</a>" lookup tables. If you use this
13709 1.1 tron feature with local files, run "<b>postmap /etc/postfix/transport</b>"
13710 1.1 tron after making a change. </p>
13711 1.1 tron
13712 1.1 tron <p> For safety reasons, as of Postfix 2.3 this feature does not
13713 1.1 tron allow $number substitutions in regular expression maps. </p>
13714 1.1 tron
13715 1.1 tron <p>
13716 1.1 tron Examples:
13717 1.1 tron </p>
13718 1.1 tron
13719 1.1 tron <pre>
13720 1.1 tron <a href="postconf.5.html#transport_maps">transport_maps</a> = dbm:/etc/postfix/transport
13721 1.1 tron <a href="postconf.5.html#transport_maps">transport_maps</a> = hash:/etc/postfix/transport
13722 1.1 tron </pre>
13723 1.1 tron
13724 1.1 tron
13725 1.1 tron </DD>
13726 1.1 tron
13727 1.1 tron <DT><b><a name="transport_minimum_delivery_slots">transport_minimum_delivery_slots</a>
13728 1.1 tron (default: $<a href="postconf.5.html#default_minimum_delivery_slots">default_minimum_delivery_slots</a>)</b></DT><DD>
13729 1.1 tron
13730 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_minimum_delivery_slots">default_minimum_delivery_slots</a>
13731 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13732 1.1 tron the message delivery transport. </p>
13733 1.1 tron
13734 1.1 tron
13735 1.1 tron </DD>
13736 1.1 tron
13737 1.1 tron <DT><b><a name="transport_recipient_limit">transport_recipient_limit</a>
13738 1.1 tron (default: $<a href="postconf.5.html#default_recipient_limit">default_recipient_limit</a>)</b></DT><DD>
13739 1.1 tron
13740 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_recipient_limit">default_recipient_limit</a>
13741 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13742 1.1 tron the message delivery transport. </p>
13743 1.1 tron
13744 1.1 tron
13745 1.1 tron </DD>
13746 1.1 tron
13747 1.1 tron <DT><b><a name="transport_recipient_refill_delay">transport_recipient_refill_delay</a>
13748 1.1 tron (default: $<a href="postconf.5.html#default_recipient_refill_delay">default_recipient_refill_delay</a>)</b></DT><DD>
13749 1.1 tron
13750 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_recipient_refill_delay">default_recipient_refill_delay</a>
13751 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13752 1.1 tron the message delivery transport. </p>
13753 1.1 tron
13754 1.1 tron <p> This feature is available in Postfix 2.4 and later. </p>
13755 1.1 tron
13756 1.1 tron
13757 1.1 tron </DD>
13758 1.1 tron
13759 1.1 tron <DT><b><a name="transport_recipient_refill_limit">transport_recipient_refill_limit</a>
13760 1.1 tron (default: $<a href="postconf.5.html#default_recipient_refill_limit">default_recipient_refill_limit</a>)</b></DT><DD>
13761 1.1 tron
13762 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#default_recipient_refill_limit">default_recipient_refill_limit</a>
13763 1.1 tron parameter value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of
13764 1.1 tron the message delivery transport. </p>
13765 1.1 tron
13766 1.1 tron <p> This feature is available in Postfix 2.4 and later. </p>
13767 1.1 tron
13768 1.1 tron
13769 1.1 tron </DD>
13770 1.1 tron
13771 1.1 tron <DT><b><a name="transport_retry_time">transport_retry_time</a>
13772 1.1 tron (default: 60s)</b></DT><DD>
13773 1.1 tron
13774 1.1 tron <p>
13775 1.1 tron The time between attempts by the Postfix queue manager to contact
13776 1.1 tron a malfunctioning message delivery transport.
13777 1.1 tron </p>
13778 1.1 tron
13779 1.1 tron <p>
13780 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
13781 1.1 tron The default time unit is s (seconds).
13782 1.1 tron </p>
13783 1.1 tron
13784 1.1 tron
13785 1.1 tron </DD>
13786 1.1 tron
13787 1.1 tron <DT><b><a name="transport_time_limit">transport_time_limit</a>
13788 1.1 tron (default: $<a href="postconf.5.html#command_time_limit">command_time_limit</a>)</b></DT><DD>
13789 1.1 tron
13790 1.1 tron <p> A transport-specific override for the <a href="postconf.5.html#command_time_limit">command_time_limit</a> parameter
13791 1.1 tron value, where <i>transport</i> is the <a href="master.5.html">master.cf</a> name of the message
13792 1.1 tron delivery transport. </p>
13793 1.1 tron
13794 1.1 tron
13795 1.1 tron </DD>
13796 1.1 tron
13797 1.1 tron <DT><b><a name="trigger_timeout">trigger_timeout</a>
13798 1.1 tron (default: 10s)</b></DT><DD>
13799 1.1 tron
13800 1.1 tron <p>
13801 1.1 tron The time limit for sending a trigger to a Postfix daemon (for
13802 1.1 tron example, the <a href="pickup.8.html">pickup(8)</a> or <a href="qmgr.8.html">qmgr(8)</a> daemon). This time limit prevents
13803 1.1 tron programs from getting stuck when the mail system is under heavy
13804 1.1 tron load.
13805 1.1 tron </p>
13806 1.1 tron
13807 1.1 tron <p>
13808 1.1 tron Time units: s (seconds), m (minutes), h (hours), d (days), w (weeks).
13809 1.1 tron The default time unit is s (seconds).
13810 1.1 tron </p>
13811 1.1 tron
13812 1.1 tron
13813 1.1 tron </DD>
13814 1.1 tron
13815 1.1 tron <DT><b><a name="undisclosed_recipients_header">undisclosed_recipients_header</a>
13816 1.1 tron (default: To: undisclosed-recipients:;)</b></DT><DD>
13817 1.1 tron
13818 1.1 tron <p>
13819 1.1 tron Message header that the Postfix <a href="cleanup.8.html">cleanup(8)</a> server inserts when a
13820 1.1 tron message contains no To: or Cc: message header. With Postfix 2.4
13821 1.1 tron and later, specify an empty value to disable this feature. </p>
13822 1.1 tron
13823 1.1 tron
13824 1.1 tron </DD>
13825 1.1 tron
13826 1.1 tron <DT><b><a name="unknown_address_reject_code">unknown_address_reject_code</a>
13827 1.1 tron (default: 450)</b></DT><DD>
13828 1.1 tron
13829 1.1 tron <p>
13830 1.1 tron The numerical Postfix SMTP server response code when a sender or
13831 1.1 tron recipient address is rejected by the <a href="postconf.5.html#reject_unknown_sender_domain">reject_unknown_sender_domain</a>
13832 1.1 tron or <a href="postconf.5.html#reject_unknown_recipient_domain">reject_unknown_recipient_domain</a> restriction. The response is
13833 1.1 tron always 450 in case of a temporary DNS error.
13834 1.1 tron </p>
13835 1.1 tron
13836 1.1 tron <p>
13837 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
13838 1.1 tron </p>
13839 1.1 tron
13840 1.1 tron
13841 1.1 tron </DD>
13842 1.1 tron
13843 1.1 tron <DT><b><a name="unknown_address_tempfail_action">unknown_address_tempfail_action</a>
13844 1.1 tron (default: $<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b></DT><DD>
13845 1.1 tron
13846 1.1 tron <p> The Postfix SMTP server's action when <a href="postconf.5.html#reject_unknown_sender_domain">reject_unknown_sender_domain</a>
13847 1.1 tron or <a href="postconf.5.html#reject_unknown_recipient_domain">reject_unknown_recipient_domain</a> fail due to a temporary error
13848 1.1 tron condition. Specify "defer" to defer the remote SMTP client request
13849 1.1 tron immediately. With the default "<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>" action, the Postfix
13850 1.1 tron SMTP server continues to look for opportunities to reject mail, and
13851 1.1 tron defers the client request only if it would otherwise be accepted.
13852 1.1 tron </p>
13853 1.1 tron
13854 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
13855 1.1 tron
13856 1.1 tron
13857 1.1 tron </DD>
13858 1.1 tron
13859 1.1 tron <DT><b><a name="unknown_client_reject_code">unknown_client_reject_code</a>
13860 1.1 tron (default: 450)</b></DT><DD>
13861 1.1 tron
13862 1.1 tron <p>
13863 1.1 tron The numerical Postfix SMTP server response code when a client
13864 1.1 tron without valid address <=> name mapping is rejected by the
13865 1.1 tron <a href="postconf.5.html#reject_unknown_client_hostname">reject_unknown_client_hostname</a> restriction. The SMTP server always replies
13866 1.1 tron with 450 when the mapping failed due to a temporary error condition.
13867 1.1 tron </p>
13868 1.1 tron
13869 1.1 tron <p>
13870 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
13871 1.1 tron </p>
13872 1.1 tron
13873 1.1 tron
13874 1.1 tron </DD>
13875 1.1 tron
13876 1.1 tron <DT><b><a name="unknown_helo_hostname_tempfail_action">unknown_helo_hostname_tempfail_action</a>
13877 1.1 tron (default: $<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b></DT><DD>
13878 1.1 tron
13879 1.1 tron <p> The Postfix SMTP server's action when <a href="postconf.5.html#reject_unknown_helo_hostname">reject_unknown_helo_hostname</a>
13880 1.1 tron fails due to an temporary error condition. Specify "defer" to defer
13881 1.1 tron the remote SMTP client request immediately. With the default
13882 1.1 tron "<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>" action, the Postfix SMTP server continues to look
13883 1.1 tron for opportunities to reject mail, and defers the client request
13884 1.1 tron only if it would otherwise be accepted. </p>
13885 1.1 tron
13886 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
13887 1.1 tron
13888 1.1 tron
13889 1.1 tron </DD>
13890 1.1 tron
13891 1.1 tron <DT><b><a name="unknown_hostname_reject_code">unknown_hostname_reject_code</a>
13892 1.1 tron (default: 450)</b></DT><DD>
13893 1.1 tron
13894 1.1 tron <p>
13895 1.1 tron The numerical Postfix SMTP server response code when the hostname
13896 1.1 tron specified with the HELO or EHLO command is rejected by the
13897 1.1 tron <a href="postconf.5.html#reject_unknown_helo_hostname">reject_unknown_helo_hostname</a> restriction.
13898 1.1 tron </p>
13899 1.1 tron
13900 1.1 tron <p>
13901 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
13902 1.1 tron </p>
13903 1.1 tron
13904 1.1 tron
13905 1.1 tron </DD>
13906 1.1 tron
13907 1.1 tron <DT><b><a name="unknown_local_recipient_reject_code">unknown_local_recipient_reject_code</a>
13908 1.1 tron (default: 550)</b></DT><DD>
13909 1.1 tron
13910 1.1 tron <p>
13911 1.1 tron The numerical Postfix SMTP server response code when a recipient
13912 1.1 tron address is local, and $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> specifies a list of
13913 1.1 tron lookup tables that does not match the recipient. A recipient
13914 1.1 tron address is local when its domain matches $<a href="postconf.5.html#mydestination">mydestination</a>,
13915 1.1 tron $<a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a> or $<a href="postconf.5.html#inet_interfaces">inet_interfaces</a>.
13916 1.1 tron </p>
13917 1.1 tron
13918 1.1 tron <p>
13919 1.1 tron The default setting is 550 (reject mail) but it is safer to initially
13920 1.1 tron use 450 (try again later) so you have time to find out if your
13921 1.1 tron <a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> settings are OK.
13922 1.1 tron </p>
13923 1.1 tron
13924 1.1 tron <p>
13925 1.1 tron Example:
13926 1.1 tron </p>
13927 1.1 tron
13928 1.1 tron <pre>
13929 1.1 tron <a href="postconf.5.html#unknown_local_recipient_reject_code">unknown_local_recipient_reject_code</a> = 450
13930 1.1 tron </pre>
13931 1.1 tron
13932 1.1 tron <p>
13933 1.1 tron This feature is available in Postfix 2.0 and later.
13934 1.1 tron </p>
13935 1.1 tron
13936 1.1 tron
13937 1.1 tron </DD>
13938 1.1 tron
13939 1.1 tron <DT><b><a name="unknown_relay_recipient_reject_code">unknown_relay_recipient_reject_code</a>
13940 1.1 tron (default: 550)</b></DT><DD>
13941 1.1 tron
13942 1.1 tron <p>
13943 1.1 tron The numerical Postfix SMTP server reply code when a recipient
13944 1.1 tron address matches $<a href="postconf.5.html#relay_domains">relay_domains</a>, and <a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a> specifies
13945 1.1 tron a list of lookup tables that does not match the recipient address.
13946 1.1 tron </p>
13947 1.1 tron
13948 1.1 tron <p>
13949 1.1 tron This feature is available in Postfix 2.0 and later.
13950 1.1 tron </p>
13951 1.1 tron
13952 1.1 tron
13953 1.1 tron </DD>
13954 1.1 tron
13955 1.1 tron <DT><b><a name="unknown_virtual_alias_reject_code">unknown_virtual_alias_reject_code</a>
13956 1.1 tron (default: 550)</b></DT><DD>
13957 1.1 tron
13958 1.1 tron <p>
13959 1.1 tron The SMTP server reply code when a recipient address matches
13960 1.1 tron $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>, and $<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a> specifies a list
13961 1.1 tron of lookup tables that does not match the recipient address.
13962 1.1 tron </p>
13963 1.1 tron
13964 1.1 tron <p>
13965 1.1 tron This feature is available in Postfix 2.0 and later.
13966 1.1 tron </p>
13967 1.1 tron
13968 1.1 tron
13969 1.1 tron </DD>
13970 1.1 tron
13971 1.1 tron <DT><b><a name="unknown_virtual_mailbox_reject_code">unknown_virtual_mailbox_reject_code</a>
13972 1.1 tron (default: 550)</b></DT><DD>
13973 1.1 tron
13974 1.1 tron <p>
13975 1.1 tron The SMTP server reply code when a recipient address matches
13976 1.1 tron $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>, and $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a> specifies a list
13977 1.1 tron of lookup tables that does not match the recipient address.
13978 1.1 tron </p>
13979 1.1 tron
13980 1.1 tron <p>
13981 1.1 tron This feature is available in Postfix 2.0 and later.
13982 1.1 tron </p>
13983 1.1 tron
13984 1.1 tron
13985 1.1 tron </DD>
13986 1.1 tron
13987 1.1 tron <DT><b><a name="unverified_recipient_defer_code">unverified_recipient_defer_code</a>
13988 1.1 tron (default: 450)</b></DT><DD>
13989 1.1 tron
13990 1.1 tron <p>
13991 1.1 tron The numerical Postfix SMTP server response when a recipient address
13992 1.1 tron probe fails due to a temporary error condition.
13993 1.1 tron </p>
13994 1.1 tron
13995 1.1 tron <p>
13996 1.1 tron Unlike elsewhere in Postfix, you can specify 250 in order to
13997 1.1 tron accept the address anyway.
13998 1.1 tron </p>
13999 1.1 tron
14000 1.1 tron <p>
14001 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
14002 1.1 tron </p>
14003 1.1 tron
14004 1.1 tron <p>
14005 1.1 tron This feature is available in Postfix 2.6 and later.
14006 1.1 tron </p>
14007 1.1 tron
14008 1.1 tron
14009 1.1 tron </DD>
14010 1.1 tron
14011 1.1 tron <DT><b><a name="unverified_recipient_reject_code">unverified_recipient_reject_code</a>
14012 1.1 tron (default: 450)</b></DT><DD>
14013 1.1 tron
14014 1.1 tron <p>
14015 1.1 tron The numerical Postfix SMTP server response when a recipient address
14016 1.1 tron is rejected by the <a href="postconf.5.html#reject_unverified_recipient">reject_unverified_recipient</a> restriction.
14017 1.1 tron </p>
14018 1.1 tron
14019 1.1 tron <p>
14020 1.1 tron Unlike elsewhere in Postfix, you can specify 250 in order to
14021 1.1 tron accept the address anyway.
14022 1.1 tron </p>
14023 1.1 tron
14024 1.1 tron <p>
14025 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
14026 1.1 tron </p>
14027 1.1 tron
14028 1.1 tron <p>
14029 1.1 tron This feature is available in Postfix 2.1 and later.
14030 1.1 tron </p>
14031 1.1 tron
14032 1.1 tron
14033 1.1 tron </DD>
14034 1.1 tron
14035 1.1 tron <DT><b><a name="unverified_recipient_reject_reason">unverified_recipient_reject_reason</a>
14036 1.1 tron (default: empty)</b></DT><DD>
14037 1.1 tron
14038 1.1 tron <p> The Postfix SMTP server's reply when rejecting mail with
14039 1.1 tron <a href="postconf.5.html#reject_unverified_recipient">reject_unverified_recipient</a>. Do not include the numeric SMTP reply
14040 1.1 tron code or the enhanced status code. By default, the response includes
14041 1.1 tron actual address verification details.
14042 1.1 tron
14043 1.1 tron <p> Example: </p>
14044 1.1 tron
14045 1.1 tron <pre>
14046 1.1 tron <a href="postconf.5.html#unverified_recipient_reject_reason">unverified_recipient_reject_reason</a> = Recipient address lookup failed
14047 1.1 tron </pre>
14048 1.1 tron
14049 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
14050 1.1 tron
14051 1.1 tron
14052 1.1 tron </DD>
14053 1.1 tron
14054 1.1 tron <DT><b><a name="unverified_recipient_tempfail_action">unverified_recipient_tempfail_action</a>
14055 1.1 tron (default: $<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b></DT><DD>
14056 1.1 tron
14057 1.1 tron <p> The Postfix SMTP server's action when <a href="postconf.5.html#reject_unverified_recipient">reject_unverified_recipient</a>
14058 1.1 tron fails due to a temporary error condition. Specify "defer" to defer
14059 1.1 tron the remote SMTP client request immediately. With the default
14060 1.1 tron "<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>" action, the Postfix SMTP server continues to look
14061 1.1 tron for opportunities to reject mail, and defers the client request
14062 1.1 tron only if it would otherwise be accepted. </p>
14063 1.1 tron
14064 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
14065 1.1 tron
14066 1.1 tron
14067 1.1 tron </DD>
14068 1.1 tron
14069 1.1 tron <DT><b><a name="unverified_sender_defer_code">unverified_sender_defer_code</a>
14070 1.1 tron (default: 450)</b></DT><DD>
14071 1.1 tron
14072 1.1 tron <p>
14073 1.1 tron The numerical Postfix SMTP server response code when a sender address
14074 1.1 tron probe fails due to a temporary error condition.
14075 1.1 tron </p>
14076 1.1 tron
14077 1.1 tron <p>
14078 1.1 tron Unlike elsewhere in Postfix, you can specify 250 in order to
14079 1.1 tron accept the address anyway.
14080 1.1 tron </p>
14081 1.1 tron
14082 1.1 tron <p>
14083 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
14084 1.1 tron </p>
14085 1.1 tron
14086 1.1 tron <p>
14087 1.1 tron This feature is available in Postfix 2.6 and later.
14088 1.1 tron </p>
14089 1.1 tron
14090 1.1 tron
14091 1.1 tron </DD>
14092 1.1 tron
14093 1.1 tron <DT><b><a name="unverified_sender_reject_code">unverified_sender_reject_code</a>
14094 1.1 tron (default: 450)</b></DT><DD>
14095 1.1 tron
14096 1.1 tron <p>
14097 1.1 tron The numerical Postfix SMTP server response code when a recipient
14098 1.1 tron address is rejected by the <a href="postconf.5.html#reject_unverified_sender">reject_unverified_sender</a> restriction.
14099 1.1 tron </p>
14100 1.1 tron
14101 1.1 tron <p>
14102 1.1 tron Unlike elsewhere in Postfix, you can specify 250 in order to
14103 1.1 tron accept the address anyway.
14104 1.1 tron </p>
14105 1.1 tron
14106 1.1 tron <p>
14107 1.1 tron Do not change this unless you have a complete understanding of <a href="http://tools.ietf.org/html/rfc2821">RFC 2821</a>.
14108 1.1 tron </p>
14109 1.1 tron
14110 1.1 tron <p>
14111 1.1 tron This feature is available in Postfix 2.1 and later.
14112 1.1 tron </p>
14113 1.1 tron
14114 1.1 tron
14115 1.1 tron </DD>
14116 1.1 tron
14117 1.1 tron <DT><b><a name="unverified_sender_reject_reason">unverified_sender_reject_reason</a>
14118 1.1 tron (default: empty)</b></DT><DD>
14119 1.1 tron
14120 1.1 tron <p> The Postfix SMTP server's reply when rejecting mail with
14121 1.1 tron <a href="postconf.5.html#reject_unverified_sender">reject_unverified_sender</a>. Do not include the numeric SMTP reply
14122 1.1 tron code or the enhanced status code. By default, the response includes
14123 1.1 tron actual address verification details.
14124 1.1 tron
14125 1.1 tron <p> Example: </p>
14126 1.1 tron
14127 1.1 tron <pre>
14128 1.1 tron <a href="postconf.5.html#unverified_sender_reject_reason">unverified_sender_reject_reason</a> = Sender address lookup failed
14129 1.1 tron </pre>
14130 1.1 tron
14131 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
14132 1.1 tron
14133 1.1 tron
14134 1.1 tron </DD>
14135 1.1 tron
14136 1.1 tron <DT><b><a name="unverified_sender_tempfail_action">unverified_sender_tempfail_action</a>
14137 1.1 tron (default: $<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b></DT><DD>
14138 1.1 tron
14139 1.1 tron <p> The Postfix SMTP server's action when <a href="postconf.5.html#reject_unverified_sender">reject_unverified_sender</a>
14140 1.1 tron fails due to a temporary error condition. Specify "defer" to defer
14141 1.1 tron the remote SMTP client request immediately. With the default
14142 1.1 tron "<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>" action, the Postfix SMTP server continues to look
14143 1.1 tron for opportunities to reject mail, and defers the client request
14144 1.1 tron only if it would otherwise be accepted. </p>
14145 1.1 tron
14146 1.1 tron <p> This feature is available in Postfix 2.6 and later. </p>
14147 1.1 tron
14148 1.1 tron
14149 1.1 tron </DD>
14150 1.1 tron
14151 1.1 tron <DT><b><a name="verp_delimiter_filter">verp_delimiter_filter</a>
14152 1.1 tron (default: -=+)</b></DT><DD>
14153 1.1 tron
14154 1.1 tron <p>
14155 1.1 tron The characters Postfix accepts as VERP delimiter characters on the
14156 1.1 tron Postfix <a href="sendmail.1.html">sendmail(1)</a> command line and in SMTP commands.
14157 1.1 tron </p>
14158 1.1 tron
14159 1.1 tron <p>
14160 1.1 tron This feature is available in Postfix 1.1 and later.
14161 1.1 tron </p>
14162 1.1 tron
14163 1.1 tron
14164 1.1 tron </DD>
14165 1.1 tron
14166 1.1 tron <DT><b><a name="virtual_alias_domains">virtual_alias_domains</a>
14167 1.1 tron (default: $<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a>)</b></DT><DD>
14168 1.1 tron
14169 1.1 tron <p> Postfix is final destination for the specified list of virtual
14170 1.1 tron alias domains, that is, domains for which all addresses are aliased
14171 1.1 tron to addresses in other local or remote domains. The SMTP server
14172 1.1 tron validates recipient addresses with $<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a> and rejects
14173 1.1 tron non-existent recipients. See also the <a href="ADDRESS_CLASS_README.html#virtual_alias_class">virtual alias domain</a> class
14174 1.1 tron in the <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a> file </p>
14175 1.1 tron
14176 1.1 tron <p>
14177 1.1 tron This feature is available in Postfix 2.0 and later. The default
14178 1.1 tron value is backwards compatible with Postfix version 1.1.
14179 1.1 tron </p>
14180 1.1 tron
14181 1.1 tron <p>
14182 1.1 tron The default value is $<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a> so that you can keep all
14183 1.1 tron information about <a href="ADDRESS_CLASS_README.html#virtual_alias_class">virtual alias domains</a> in one place. If you have
14184 1.1 tron many users, it is better to separate information that changes more
14185 1.1 tron frequently (virtual address -> local or remote address mapping)
14186 1.1 tron from information that changes less frequently (the list of virtual
14187 1.1 tron domain names).
14188 1.1 tron </p>
14189 1.1 tron
14190 1.1 tron <p> Specify a list of host or domain names, "/file/name" or
14191 1.1 tron "<a href="DATABASE_README.html">type:table</a>" patterns, separated by commas and/or whitespace. A
14192 1.1 tron "/file/name" pattern is replaced by its contents; a "<a href="DATABASE_README.html">type:table</a>"
14193 1.1 tron lookup table is matched when a table entry matches a lookup string
14194 1.1 tron (the lookup result is ignored). Continue long lines by starting
14195 1.1 tron the next line with whitespace. Specify "!pattern" to exclude a host
14196 1.1 tron or domain name from the list. The form "!/file/name" is supported
14197 1.1 tron only in Postfix version 2.4 and later. </p>
14198 1.1 tron
14199 1.1 tron <p>
14200 1.1 tron See also the <a href="VIRTUAL_README.html">VIRTUAL_README</a> and <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a> documents
14201 1.1 tron for further information.
14202 1.1 tron </p>
14203 1.1 tron
14204 1.1 tron <p>
14205 1.1 tron Example:
14206 1.1 tron </p>
14207 1.1 tron
14208 1.1 tron <pre>
14209 1.1 tron <a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a> = virtual1.tld virtual2.tld
14210 1.1 tron </pre>
14211 1.1 tron
14212 1.1 tron
14213 1.1 tron </DD>
14214 1.1 tron
14215 1.1 tron <DT><b><a name="virtual_alias_expansion_limit">virtual_alias_expansion_limit</a>
14216 1.1 tron (default: 1000)</b></DT><DD>
14217 1.1 tron
14218 1.1 tron <p>
14219 1.1 tron The maximal number of addresses that virtual alias expansion produces
14220 1.1 tron from each original recipient.
14221 1.1 tron </p>
14222 1.1 tron
14223 1.1 tron <p>
14224 1.1 tron This feature is available in Postfix 2.1 and later.
14225 1.1 tron </p>
14226 1.1 tron
14227 1.1 tron
14228 1.1 tron </DD>
14229 1.1 tron
14230 1.1 tron <DT><b><a name="virtual_alias_maps">virtual_alias_maps</a>
14231 1.1 tron (default: $<a href="postconf.5.html#virtual_maps">virtual_maps</a>)</b></DT><DD>
14232 1.1 tron
14233 1.1 tron <p>
14234 1.1 tron Optional lookup tables that alias specific mail addresses or domains
14235 1.1 tron to other local or remote address. The table format and lookups
14236 1.1 tron are documented in <a href="virtual.5.html">virtual(5)</a>. For an overview of Postfix address
14237 1.1 tron manipulations see the <a href="ADDRESS_REWRITING_README.html">ADDRESS_REWRITING_README</a> document.
14238 1.1 tron </p>
14239 1.1 tron
14240 1.1 tron <p>
14241 1.1 tron This feature is available in Postfix 2.0 and later. The default
14242 1.1 tron value is backwards compatible with Postfix version 1.1.
14243 1.1 tron </p>
14244 1.1 tron
14245 1.1 tron <p>
14246 1.1 tron If you use this feature with indexed files, run "<b>postmap
14247 1.1 tron /etc/postfix/virtual</b>" after changing the file.
14248 1.1 tron </p>
14249 1.1 tron
14250 1.1 tron <p>
14251 1.1 tron Examples:
14252 1.1 tron </p>
14253 1.1 tron
14254 1.1 tron <pre>
14255 1.1 tron <a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a> = dbm:/etc/postfix/virtual
14256 1.1 tron <a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a> = hash:/etc/postfix/virtual
14257 1.1 tron </pre>
14258 1.1 tron
14259 1.1 tron
14260 1.1 tron </DD>
14261 1.1 tron
14262 1.1 tron <DT><b><a name="virtual_alias_recursion_limit">virtual_alias_recursion_limit</a>
14263 1.1 tron (default: 1000)</b></DT><DD>
14264 1.1 tron
14265 1.1 tron <p>
14266 1.1 tron The maximal nesting depth of virtual alias expansion. Currently
14267 1.1 tron the recursion limit is applied only to the left branch of the
14268 1.1 tron expansion graph, so the depth of the tree can in the worst case
14269 1.1 tron reach the sum of the expansion and recursion limits. This may
14270 1.1 tron change in the future.
14271 1.1 tron </p>
14272 1.1 tron
14273 1.1 tron <p>
14274 1.1 tron This feature is available in Postfix 2.1 and later.
14275 1.1 tron </p>
14276 1.1 tron
14277 1.1 tron
14278 1.1 tron </DD>
14279 1.1 tron
14280 1.1 tron <DT><b><a name="virtual_destination_concurrency_limit">virtual_destination_concurrency_limit</a>
14281 1.1 tron (default: $<a href="postconf.5.html#default_destination_concurrency_limit">default_destination_concurrency_limit</a>)</b></DT><DD>
14282 1.1 tron
14283 1.1 tron <p> The maximal number of parallel deliveries to the same destination
14284 1.1 tron via the virtual message delivery transport. This limit is enforced
14285 1.1 tron by the queue manager. The message delivery transport name is the
14286 1.1 tron first field in the entry in the <a href="master.5.html">master.cf</a> file. </p>
14287 1.1 tron
14288 1.1 tron
14289 1.1 tron </DD>
14290 1.1 tron
14291 1.1 tron <DT><b><a name="virtual_destination_recipient_limit">virtual_destination_recipient_limit</a>
14292 1.1 tron (default: $<a href="postconf.5.html#default_destination_recipient_limit">default_destination_recipient_limit</a>)</b></DT><DD>
14293 1.1 tron
14294 1.1 tron <p> The maximal number of recipients per message for the virtual
14295 1.1 tron message delivery transport. This limit is enforced by the queue
14296 1.1 tron manager. The message delivery transport name is the first field in
14297 1.1 tron the entry in the <a href="master.5.html">master.cf</a> file. </p>
14298 1.1 tron
14299 1.1 tron <p> Setting this parameter to a value of 1 changes the meaning of
14300 1.1 tron <a href="postconf.5.html#virtual_destination_concurrency_limit">virtual_destination_concurrency_limit</a> from concurrency per domain
14301 1.1 tron into concurrency per recipient. </p>
14302 1.1 tron
14303 1.1 tron
14304 1.1 tron </DD>
14305 1.1 tron
14306 1.1 tron <DT><b><a name="virtual_gid_maps">virtual_gid_maps</a>
14307 1.1 tron (default: empty)</b></DT><DD>
14308 1.1 tron
14309 1.1 tron <p>
14310 1.1 tron Lookup tables with the per-recipient group ID for <a href="virtual.8.html">virtual(8)</a> mailbox
14311 1.1 tron delivery.
14312 1.1 tron </p>
14313 1.1 tron
14314 1.1 tron <p>
14315 1.1 tron In a lookup table, specify a left-hand side of "@domain.tld" to
14316 1.1 tron match any user in the specified domain that does not have a specific
14317 1.1 tron "user (a] domain.tld" entry.
14318 1.1 tron </p>
14319 1.1 tron
14320 1.1 tron <p>
14321 1.1 tron When a recipient address has an optional address extension
14322 1.1 tron (user+foo (a] domain.tld), the <a href="virtual.8.html">virtual(8)</a> delivery agent looks up
14323 1.1 tron the full address first, and when the lookup fails, it looks up the
14324 1.1 tron unextended address (user (a] domain.tld).
14325 1.1 tron </p>
14326 1.1 tron
14327 1.1 tron <p>
14328 1.1 tron Note 1: for security reasons, the <a href="virtual.8.html">virtual(8)</a> delivery agent disallows
14329 1.1 tron regular expression substitution of $1 etc. in regular expression
14330 1.1 tron lookup tables, because that would open a security hole.
14331 1.1 tron </p>
14332 1.1 tron
14333 1.1 tron <p>
14334 1.1 tron Note 2: for security reasons, the <a href="virtual.8.html">virtual(8)</a> delivery agent will
14335 1.1 tron silently ignore requests to use the <a href="proxymap.8.html">proxymap(8)</a> server. Instead
14336 1.1 tron it will open the table directly. Before Postfix version 2.2, the
14337 1.1 tron <a href="virtual.8.html">virtual(8)</a> delivery agent will terminate with a fatal error.
14338 1.1 tron </p>
14339 1.1 tron
14340 1.1 tron
14341 1.1 tron </DD>
14342 1.1 tron
14343 1.1 tron <DT><b><a name="virtual_mailbox_base">virtual_mailbox_base</a>
14344 1.1 tron (default: empty)</b></DT><DD>
14345 1.1 tron
14346 1.1 tron <p>
14347 1.1 tron A prefix that the <a href="virtual.8.html">virtual(8)</a> delivery agent prepends to all pathname
14348 1.1 tron results from $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a> table lookups. This is a safety
14349 1.1 tron measure to ensure that an out of control map doesn't litter the
14350 1.1 tron file system with mailboxes. While <a href="postconf.5.html#virtual_mailbox_base">virtual_mailbox_base</a> could be
14351 1.1 tron set to "/", this setting isn't recommended.
14352 1.1 tron </p>
14353 1.1 tron
14354 1.1 tron <p>
14355 1.1 tron Example:
14356 1.1 tron </p>
14357 1.1 tron
14358 1.1 tron <pre>
14359 1.1 tron <a href="postconf.5.html#virtual_mailbox_base">virtual_mailbox_base</a> = /var/mail
14360 1.1 tron </pre>
14361 1.1 tron
14362 1.1 tron
14363 1.1 tron </DD>
14364 1.1 tron
14365 1.1 tron <DT><b><a name="virtual_mailbox_domains">virtual_mailbox_domains</a>
14366 1.1 tron (default: $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a>)</b></DT><DD>
14367 1.1 tron
14368 1.1 tron <p> Postfix is final destination for the specified list of domains;
14369 1.1 tron mail is delivered via the $<a href="postconf.5.html#virtual_transport">virtual_transport</a> mail delivery transport.
14370 1.1 tron By default this is the Postfix <a href="virtual.8.html">virtual(8)</a> delivery agent. The SMTP
14371 1.1 tron server validates recipient addresses with $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a>
14372 1.1 tron and rejects mail for non-existent recipients. See also the virtual
14373 1.1 tron mailbox domain class in the <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a> file. </p>
14374 1.1 tron
14375 1.1 tron <p> This parameter expects the same syntax as the <a href="postconf.5.html#mydestination">mydestination</a>
14376 1.1 tron configuration parameter. </p>
14377 1.1 tron
14378 1.1 tron <p>
14379 1.1 tron This feature is available in Postfix 2.0 and later. The default
14380 1.1 tron value is backwards compatible with Postfix version 1.1.
14381 1.1 tron </p>
14382 1.1 tron
14383 1.1 tron
14384 1.1 tron </DD>
14385 1.1 tron
14386 1.1 tron <DT><b><a name="virtual_mailbox_limit">virtual_mailbox_limit</a>
14387 1.1 tron (default: 51200000)</b></DT><DD>
14388 1.1 tron
14389 1.1 tron <p>
14390 1.1 tron The maximal size in bytes of an individual mailbox or maildir file,
14391 1.1 tron or zero (no limit).
14392 1.1 tron </p>
14393 1.1 tron
14394 1.1 tron
14395 1.1 tron </DD>
14396 1.1 tron
14397 1.1 tron <DT><b><a name="virtual_mailbox_lock">virtual_mailbox_lock</a>
14398 1.1 tron (default: see "postconf -d" output)</b></DT><DD>
14399 1.1 tron
14400 1.1 tron <p>
14401 1.1 tron How to lock a UNIX-style <a href="virtual.8.html">virtual(8)</a> mailbox before attempting
14402 1.1 tron delivery. For a list of available file locking methods, use the
14403 1.1 tron "<b>postconf -l</b>" command.
14404 1.1 tron </p>
14405 1.1 tron
14406 1.1 tron <p>
14407 1.1 tron This setting is ignored with <b>maildir</b> style delivery, because
14408 1.1 tron such deliveries are safe without application-level locks.
14409 1.1 tron </p>
14410 1.1 tron
14411 1.1 tron <p>
14412 1.1 tron Note 1: the <b>dotlock</b> method requires that the recipient UID
14413 1.1 tron or GID has write access to the parent directory of the recipient's
14414 1.1 tron mailbox file.
14415 1.1 tron </p>
14416 1.1 tron
14417 1.1 tron <p>
14418 1.1 tron Note 2: the default setting of this parameter is system dependent.
14419 1.1 tron </p>
14420 1.1 tron
14421 1.1 tron
14422 1.1 tron </DD>
14423 1.1 tron
14424 1.1 tron <DT><b><a name="virtual_mailbox_maps">virtual_mailbox_maps</a>
14425 1.1 tron (default: empty)</b></DT><DD>
14426 1.1 tron
14427 1.1 tron <p>
14428 1.1 tron Optional lookup tables with all valid addresses in the domains that
14429 1.1 tron match $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>.
14430 1.1 tron </p>
14431 1.1 tron
14432 1.1 tron <p>
14433 1.1 tron In a lookup table, specify a left-hand side of "@domain.tld" to
14434 1.1 tron match any user in the specified domain that does not have a specific
14435 1.1 tron "user (a] domain.tld" entry.
14436 1.1 tron </p>
14437 1.1 tron
14438 1.1 tron <p>
14439 1.1 tron The <a href="virtual.8.html">virtual(8)</a> delivery agent uses this table to look up the
14440 1.1 tron per-recipient mailbox or maildir pathname. If the lookup result
14441 1.1 tron ends in a slash ("/"), maildir-style delivery is carried out,
14442 1.1 tron otherwise the path is assumed to specify a UNIX-style mailbox file.
14443 1.1 tron Note that $<a href="postconf.5.html#virtual_mailbox_base">virtual_mailbox_base</a> is unconditionally prepended to
14444 1.1 tron this path.
14445 1.1 tron </p>
14446 1.1 tron
14447 1.1 tron <p>
14448 1.1 tron When a recipient address has an optional address extension
14449 1.1 tron (user+foo (a] domain.tld), the <a href="virtual.8.html">virtual(8)</a> delivery agent looks up
14450 1.1 tron the full address first, and when the lookup fails, it looks up the
14451 1.1 tron unextended address (user (a] domain.tld).
14452 1.1 tron </p>
14453 1.1 tron
14454 1.1 tron <p>
14455 1.1 tron Note 1: for security reasons, the <a href="virtual.8.html">virtual(8)</a> delivery agent disallows
14456 1.1 tron regular expression substitution of $1 etc. in regular expression
14457 1.1 tron lookup tables, because that would open a security hole.
14458 1.1 tron </p>
14459 1.1 tron
14460 1.1 tron <p>
14461 1.1 tron Note 2: for security reasons, the <a href="virtual.8.html">virtual(8)</a> delivery agent will
14462 1.1 tron silently ignore requests to use the <a href="proxymap.8.html">proxymap(8)</a> server. Instead
14463 1.1 tron it will open the table directly. Before Postfix version 2.2, the
14464 1.1 tron <a href="virtual.8.html">virtual(8)</a> delivery agent will terminate with a fatal error.
14465 1.1 tron </p>
14466 1.1 tron
14467 1.1 tron
14468 1.1 tron </DD>
14469 1.1 tron
14470 1.1 tron <DT><b><a name="virtual_maps">virtual_maps</a>
14471 1.1 tron (default: empty)</b></DT><DD>
14472 1.1 tron
14473 1.1 tron <p> Optional lookup tables with a) names of domains for which all
14474 1.1 tron addresses are aliased to addresses in other local or remote domains,
14475 1.1 tron and b) addresses that are aliased to addresses in other local or
14476 1.1 tron remote domains. Available before Postfix version 2.0. With Postfix
14477 1.1 tron version 2.0 and later, this is replaced by separate controls: <a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>
14478 1.1 tron and <a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a>. </p>
14479 1.1 tron
14480 1.1 tron
14481 1.1 tron </DD>
14482 1.1 tron
14483 1.1 tron <DT><b><a name="virtual_minimum_uid">virtual_minimum_uid</a>
14484 1.1 tron (default: 100)</b></DT><DD>
14485 1.1 tron
14486 1.1 tron <p>
14487 1.1 tron The minimum user ID value that the <a href="virtual.8.html">virtual(8)</a> delivery agent accepts
14488 1.1 tron as a result from $<a href="postconf.5.html#virtual_uid_maps">virtual_uid_maps</a> table lookup. Returned
14489 1.1 tron values less than this will be rejected, and the message will be
14490 1.1 tron deferred.
14491 1.1 tron </p>
14492 1.1 tron
14493 1.1 tron
14494 1.1 tron </DD>
14495 1.1 tron
14496 1.1 tron <DT><b><a name="virtual_transport">virtual_transport</a>
14497 1.1 tron (default: virtual)</b></DT><DD>
14498 1.1 tron
14499 1.1 tron <p>
14500 1.1 tron The default mail delivery transport and next-hop destination for
14501 1.1 tron final delivery to domains listed with $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>.
14502 1.1 tron This information can be overruled with the <a href="transport.5.html">transport(5)</a> table.
14503 1.1 tron </p>
14504 1.1 tron
14505 1.1 tron <p>
14506 1.1 tron Specify a string of the form <i>transport:nexthop</i>, where <i>transport</i>
14507 1.1 tron is the name of a mail delivery transport defined in <a href="master.5.html">master.cf</a>.
14508 1.1 tron The <i>:nexthop</i> part is optional. For more details see the
14509 1.1 tron <a href="transport.5.html">transport(5)</a> manual page.
14510 1.1 tron </p>
14511 1.1 tron
14512 1.1 tron <p>
14513 1.1 tron This feature is available in Postfix 2.0 and later.
14514 1.1 tron </p>
14515 1.1 tron
14516 1.1 tron
14517 1.1 tron </DD>
14518 1.1 tron
14519 1.1 tron <DT><b><a name="virtual_uid_maps">virtual_uid_maps</a>
14520 1.1 tron (default: empty)</b></DT><DD>
14521 1.1 tron
14522 1.1 tron <p>
14523 1.1 tron Lookup tables with the per-recipient user ID that the <a href="virtual.8.html">virtual(8)</a>
14524 1.1 tron delivery agent uses while writing to the recipient's mailbox.
14525 1.1 tron </p>
14526 1.1 tron
14527 1.1 tron <p>
14528 1.1 tron In a lookup table, specify a left-hand side of "@domain.tld"
14529 1.1 tron to match any user in the specified domain that does not have a
14530 1.1 tron specific "user (a] domain.tld" entry.
14531 1.1 tron </p>
14532 1.1 tron
14533 1.1 tron <p>
14534 1.1 tron When a recipient address has an optional address extension
14535 1.1 tron (user+foo (a] domain.tld), the <a href="virtual.8.html">virtual(8)</a> delivery agent looks up
14536 1.1 tron the full address first, and when the lookup fails, it looks up the
14537 1.1 tron unextended address (user (a] domain.tld).
14538 1.1 tron </p>
14539 1.1 tron
14540 1.1 tron <p>
14541 1.1 tron Note 1: for security reasons, the <a href="virtual.8.html">virtual(8)</a> delivery agent disallows
14542 1.1 tron regular expression substitution of $1 etc. in regular expression
14543 1.1 tron lookup tables, because that would open a security hole.
14544 1.1 tron </p>
14545 1.1 tron
14546 1.1 tron <p>
14547 1.1 tron Note 2: for security reasons, the <a href="virtual.8.html">virtual(8)</a> delivery agent will
14548 1.1 tron silently ignore requests to use the <a href="proxymap.8.html">proxymap(8)</a> server. Instead
14549 1.1 tron it will open the table directly. Before Postfix version 2.2, the
14550 1.1 tron <a href="virtual.8.html">virtual(8)</a> delivery agent will terminate with a fatal error.
14551 1.1 tron </p>
14552 1.1 tron
14553 1.1 tron
14554 1.1 tron </DD>
14555 1.1 tron
14556 1.1 tron </dl>
14557 1.1 tron
14558 1.1 tron </body>
14559 1.1 tron
14560 1.1 tron </html>
14561