1 <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN" 2 "https://www.w3.org/TR/html4/loose.dtd"> 3 <html> <head> 4 <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> 5 <link rel='stylesheet' type='text/css' href='postfix-doc.css'> 6 <title> Postfix manual - smtpd(8) </title> 7 </head> <body> <pre> 8 SMTPD(8) SMTPD(8) 9 10 <b><a name="name">NAME</a></b> 11 smtpd - Postfix SMTP server 12 13 <b><a name="synopsis">SYNOPSIS</a></b> 14 <b>smtpd</b> [generic Postfix daemon options] 15 16 <b>sendmail -bs</b> 17 18 <b><a name="description">DESCRIPTION</a></b> 19 The SMTP server accepts network connection requests and performs zero 20 or more SMTP transactions per connection. Each received message is 21 piped through the <a href="cleanup.8.html"><b>cleanup</b>(8)</a> daemon, and is placed into the <b>incoming</b> 22 queue as one single queue file. For this mode of operation, the pro- 23 gram expects to be run from the <a href="master.8.html"><b>master</b>(8)</a> process manager. 24 25 Alternatively, the SMTP server be can run in stand-alone mode; this is 26 traditionally obtained with "<b>sendmail -bs</b>". When the SMTP server runs 27 stand-alone with non $<b><a href="postconf.5.html#mail_owner">mail_owner</a></b> privileges, it receives mail even 28 while the mail system is not running, deposits messages directly into 29 the <b>maildrop</b> queue, and disables the SMTP server's access policies. As 30 of Postfix version 2.3, the SMTP server refuses to receive mail from 31 the network when it runs with non $<b><a href="postconf.5.html#mail_owner">mail_owner</a></b> privileges. 32 33 The SMTP server implements a variety of policies for connection 34 requests, and for parameters given to <b>HELO, ETRN, MAIL FROM, VRFY</b> and 35 <b>RCPT TO</b> commands. They are detailed below and in the <a href="postconf.5.html"><b>main.cf</b></a> configura- 36 tion file. 37 38 <b><a name="security">SECURITY</a></b> 39 The SMTP server is moderately security-sensitive. It talks to SMTP 40 clients and to DNS servers on the network. The SMTP server can be run 41 chrooted at fixed low privilege. 42 43 <b><a name="standards">STANDARDS</a></b> 44 <a href="https://tools.ietf.org/html/rfc821">RFC 821</a> (SMTP protocol) 45 <a href="https://tools.ietf.org/html/rfc1123">RFC 1123</a> (Host requirements) 46 <a href="https://tools.ietf.org/html/rfc1652">RFC 1652</a> (8bit-MIME transport) 47 <a href="https://tools.ietf.org/html/rfc1869">RFC 1869</a> (SMTP service extensions) 48 <a href="https://tools.ietf.org/html/rfc1870">RFC 1870</a> (Message size declaration) 49 <a href="https://tools.ietf.org/html/rfc1985">RFC 1985</a> (ETRN command) 50 <a href="https://tools.ietf.org/html/rfc2034">RFC 2034</a> (SMTP enhanced status codes) 51 <a href="https://tools.ietf.org/html/rfc2554">RFC 2554</a> (AUTH command) 52 <a href="https://tools.ietf.org/html/rfc2821">RFC 2821</a> (SMTP protocol) 53 <a href="https://tools.ietf.org/html/rfc2920">RFC 2920</a> (SMTP pipelining) 54 <a href="https://tools.ietf.org/html/rfc3030">RFC 3030</a> (CHUNKING without BINARYMIME) 55 <a href="https://tools.ietf.org/html/rfc3207">RFC 3207</a> (STARTTLS command) 56 <a href="https://tools.ietf.org/html/rfc3461">RFC 3461</a> (SMTP DSN extension) 57 <a href="https://tools.ietf.org/html/rfc3463">RFC 3463</a> (Enhanced status codes) 58 <a href="https://tools.ietf.org/html/rfc3848">RFC 3848</a> (ESMTP transmission types) 59 <a href="https://tools.ietf.org/html/rfc4409">RFC 4409</a> (Message submission) 60 <a href="https://tools.ietf.org/html/rfc4954">RFC 4954</a> (AUTH command) 61 <a href="https://tools.ietf.org/html/rfc5321">RFC 5321</a> (SMTP protocol) 62 <a href="https://tools.ietf.org/html/rfc6531">RFC 6531</a> (Internationalized SMTP) 63 <a href="https://tools.ietf.org/html/rfc6533">RFC 6533</a> (Internationalized Delivery Status Notifications) 64 <a href="https://tools.ietf.org/html/rfc7505">RFC 7505</a> ("Null MX" No Service Resource Record) 65 <a href="https://tools.ietf.org/html/rfc8689">RFC 8689</a> (SMTP REQUIRETLS extension) 66 67 <b><a name="diagnostics">DIAGNOSTICS</a></b> 68 Problems and transactions are logged to <b>syslogd</b>(8) or <a href="postlogd.8.html"><b>postlogd</b>(8)</a>. 69 70 Depending on the setting of the <b><a href="postconf.5.html#notify_classes">notify_classes</a></b> parameter, the postmas- 71 ter is notified of bounces, protocol problems, policy violations, and 72 of other trouble. 73 74 <b><a name="configuration_parameters">CONFIGURATION PARAMETERS</a></b> 75 Changes to <a href="postconf.5.html"><b>main.cf</b></a> are picked up automatically, as <a href="smtpd.8.html"><b>smtpd</b>(8)</a> processes 76 run for only a limited amount of time. Use the command "<b>postfix reload</b>" 77 to speed up a change. 78 79 The text below provides only a parameter summary. See <a href="postconf.5.html"><b>postconf</b>(5)</a> for 80 more details including examples. 81 82 <b><a name="compatibility_controls">COMPATIBILITY CONTROLS</a></b> 83 The following parameters work around implementation errors in other 84 software, and/or allow you to override standards in order to prevent 85 undesirable use. 86 87 <b><a href="postconf.5.html#broken_sasl_auth_clients">broken_sasl_auth_clients</a> (no)</b> 88 Enable interoperability with remote SMTP clients that implement 89 an obsolete version of the AUTH command (<a href="https://tools.ietf.org/html/rfc4954">RFC 4954</a>). 90 91 <b><a href="postconf.5.html#disable_vrfy_command">disable_vrfy_command</a> (no)</b> 92 Disable the SMTP VRFY command. 93 94 <b><a href="postconf.5.html#smtpd_noop_commands">smtpd_noop_commands</a> (empty)</b> 95 List of commands that the Postfix SMTP server replies to with 96 "250 Ok", without doing any syntax checks and without changing 97 state. 98 99 <b><a href="postconf.5.html#strict_rfc821_envelopes">strict_rfc821_envelopes</a> (no)</b> 100 Require that addresses received in SMTP MAIL FROM and RCPT TO 101 commands are enclosed with <>, and that those addresses do not 102 contain <a href="https://tools.ietf.org/html/rfc822">RFC 822</a> style comments or phrases. 103 104 Available in Postfix version 2.1 and later: 105 106 <b><a href="postconf.5.html#smtpd_reject_unlisted_sender">smtpd_reject_unlisted_sender</a> (no)</b> 107 Request that the Postfix SMTP server rejects mail from unknown 108 sender addresses, even when no explicit <a href="postconf.5.html#reject_unlisted_sender">reject_unlisted_sender</a> 109 access restriction is specified. 110 111 <b><a href="postconf.5.html#smtpd_sasl_exceptions_networks">smtpd_sasl_exceptions_networks</a> (empty)</b> 112 What remote SMTP clients the Postfix SMTP server will not offer 113 AUTH support to. 114 115 Available in Postfix version 2.2 and later: 116 117 <b><a href="postconf.5.html#smtpd_discard_ehlo_keyword_address_maps">smtpd_discard_ehlo_keyword_address_maps</a> (empty)</b> 118 Lookup tables, indexed by the remote SMTP client address, with 119 case insensitive lists of EHLO keywords (pipelining, starttls, 120 auth, etc.) that the Postfix SMTP server will not send in the 121 EHLO response to a remote SMTP client. 122 123 <b><a href="postconf.5.html#smtpd_discard_ehlo_keywords">smtpd_discard_ehlo_keywords</a> (empty)</b> 124 A case insensitive list of EHLO keywords (pipelining, starttls, 125 auth, etc.) that the Postfix SMTP server will not send in the 126 EHLO response to a remote SMTP client. 127 128 <b><a href="postconf.5.html#smtpd_delay_open_until_valid_rcpt">smtpd_delay_open_until_valid_rcpt</a> (yes)</b> 129 Postpone the start of an SMTP mail transaction until a valid 130 RCPT TO command is received. 131 132 Available in Postfix version 2.3 and later: 133 134 <b><a href="postconf.5.html#smtpd_tls_always_issue_session_ids">smtpd_tls_always_issue_session_ids</a> (yes)</b> 135 Force the Postfix SMTP server to issue a TLS session id, even 136 when TLS session caching is turned off (<a href="postconf.5.html#smtpd_tls_session_cache_database">smtpd_tls_ses</a>- 137 <a href="postconf.5.html#smtpd_tls_session_cache_database">sion_cache_database</a> is empty). 138 139 Available in Postfix version 2.6 and later: 140 141 <b><a href="postconf.5.html#tcp_windowsize">tcp_windowsize</a> (0)</b> 142 An optional workaround for routers that break TCP window scal- 143 ing. 144 145 Available in Postfix version 2.7 and later: 146 147 <b><a href="postconf.5.html#smtpd_command_filter">smtpd_command_filter</a> (empty)</b> 148 A mechanism to transform commands from remote SMTP clients. 149 150 Available in Postfix version 2.9 - 3.6: 151 152 <b><a href="postconf.5.html#smtpd_per_record_deadline">smtpd_per_record_deadline</a> (normal: no, <a href="STRESS_README.html">overload</a>: yes)</b> 153 Change the behavior of the <a href="postconf.5.html#smtpd_timeout">smtpd_timeout</a> and <a href="postconf.5.html#smtpd_starttls_timeout">smtpd_start</a>- 154 <a href="postconf.5.html#smtpd_starttls_timeout">tls_timeout</a> time limits, from a time limit per read or write 155 system call, to a time limit to send or receive a complete 156 record (an SMTP command line, SMTP response line, SMTP message 157 content line, or TLS protocol message). 158 159 Available in Postfix version 3.0 and later: 160 161 <b><a href="postconf.5.html#smtpd_dns_reply_filter">smtpd_dns_reply_filter</a> (empty)</b> 162 Optional filter for Postfix SMTP server DNS lookup results. 163 164 Available in Postfix 3.5 and later: 165 166 <b><a href="postconf.5.html#info_log_address_format">info_log_address_format</a> (external)</b> 167 The email address form that will be used in non-debug logging 168 (info, warning, etc.). 169 170 Available in Postfix version 3.6 and later: 171 172 <b><a href="postconf.5.html#smtpd_relay_before_recipient_restrictions">smtpd_relay_before_recipient_restrictions</a> (see 'postconf -d' output)</b> 173 Evaluate <a href="postconf.5.html#smtpd_relay_restrictions">smtpd_relay_restrictions</a> before <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipi</a>- 174 <a href="postconf.5.html#smtpd_recipient_restrictions">ent_restrictions</a>. 175 176 <b><a href="postconf.5.html#known_tcp_ports">known_tcp_ports</a> (lmtp=24, smtp=25, smtps=submissions=465, submis-</b> 177 <b>sion=587)</b> 178 Optional setting that avoids lookups in the <b>services</b>(5) data- 179 base. 180 181 Available in Postfix version 3.7 and later: 182 183 <b><a href="postconf.5.html#smtpd_per_request_deadline">smtpd_per_request_deadline</a> (normal: no, <a href="STRESS_README.html">overload</a>: yes)</b> 184 Change the behavior of the <a href="postconf.5.html#smtpd_timeout">smtpd_timeout</a> and <a href="postconf.5.html#smtpd_starttls_timeout">smtpd_start</a>- 185 <a href="postconf.5.html#smtpd_starttls_timeout">tls_timeout</a> time limits, from a time limit per plaintext or TLS 186 read or write call, to a combined time limit for receiving a 187 complete SMTP request and for sending a complete SMTP response. 188 189 <b><a href="postconf.5.html#smtpd_min_data_rate">smtpd_min_data_rate</a> (500)</b> 190 The minimum plaintext data transfer rate in bytes/second for 191 DATA and BDAT requests, when deadlines are enabled with 192 <a href="postconf.5.html#smtpd_per_request_deadline">smtpd_per_request_deadline</a>. 193 194 <b><a name="address_rewriting_controls">ADDRESS REWRITING CONTROLS</a></b> 195 See the <a href="ADDRESS_REWRITING_README.html">ADDRESS_REWRITING_README</a> document for a detailed discussion of 196 Postfix address rewriting. 197 198 <b><a href="postconf.5.html#receive_override_options">receive_override_options</a> (empty)</b> 199 Enable or disable recipient validation, built-in content filter- 200 ing, or address mapping. 201 202 Available in Postfix version 2.2 and later: 203 204 <b><a href="postconf.5.html#local_header_rewrite_clients">local_header_rewrite_clients</a> (<a href="postconf.5.html#permit_inet_interfaces">permit_inet_interfaces</a>)</b> 205 Rewrite or add message headers in mail from these clients, 206 updating incomplete addresses with the domain name in $<a href="postconf.5.html#myorigin">myorigin</a> 207 or $<a href="postconf.5.html#mydomain">mydomain</a>, and adding missing headers. 208 209 <b><a name="before-smtpd_proxy_agent">BEFORE-SMTPD PROXY AGENT</a></b> 210 Available in Postfix version 2.10 and later: 211 212 <b><a href="postconf.5.html#smtpd_upstream_proxy_protocol">smtpd_upstream_proxy_protocol</a> (empty)</b> 213 The name of the proxy protocol used by an optional before-smtpd 214 proxy agent. 215 216 <b><a href="postconf.5.html#smtpd_upstream_proxy_timeout">smtpd_upstream_proxy_timeout</a> (5s)</b> 217 The time limit for the proxy protocol specified with the 218 <a href="postconf.5.html#smtpd_upstream_proxy_protocol">smtpd_upstream_proxy_protocol</a> parameter. 219 220 <b><a name="after_queue_external_content_inspection_controls">AFTER QUEUE EXTERNAL CONTENT INSPECTION CONTROLS</a></b> 221 As of version 1.0, Postfix can be configured to send new mail to an 222 external content filter AFTER the mail is queued. This content filter 223 is expected to inject mail back into a (Postfix or other) MTA for fur- 224 ther delivery. See the <a href="FILTER_README.html">FILTER_README</a> document for details. 225 226 <b><a href="postconf.5.html#content_filter">content_filter</a> (empty)</b> 227 After the message is queued, send the entire message to the 228 specified <i>transport:destination</i>. 229 230 <b><a name="before_queue_external_content_inspection_controls">BEFORE QUEUE EXTERNAL CONTENT INSPECTION CONTROLS</a></b> 231 As of version 2.1, the Postfix SMTP server can be configured to send 232 incoming mail to a real-time SMTP-based content filter BEFORE mail is 233 queued. This content filter is expected to inject mail back into Post- 234 fix. See the <a href="SMTPD_PROXY_README.html">SMTPD_PROXY_README</a> document for details on how to config- 235 ure and operate this feature. 236 237 <b><a href="postconf.5.html#smtpd_proxy_filter">smtpd_proxy_filter</a> (empty)</b> 238 The hostname and TCP port of the mail filtering proxy server. 239 240 <b><a href="postconf.5.html#smtpd_proxy_ehlo">smtpd_proxy_ehlo</a> ($<a href="postconf.5.html#myhostname">myhostname</a>)</b> 241 How the Postfix SMTP server announces itself to the proxy fil- 242 ter. 243 244 <b><a href="postconf.5.html#smtpd_proxy_options">smtpd_proxy_options</a> (empty)</b> 245 List of options that control how the Postfix SMTP server commu- 246 nicates with a before-queue content filter. 247 248 <b><a href="postconf.5.html#smtpd_proxy_timeout">smtpd_proxy_timeout</a> (100s)</b> 249 The time limit for connecting to a proxy filter and for sending 250 or receiving information. 251 252 <b><a name="before_queue_milter_controls">BEFORE QUEUE MILTER CONTROLS</a></b> 253 As of version 2.3, Postfix supports the Sendmail version 8 Milter (mail 254 filter) protocol. These content filters run outside Postfix. They can 255 inspect the SMTP command stream and the message content, and can 256 request modifications before mail is queued. For details see the <a href="MILTER_README.html">MIL</a>- 257 <a href="MILTER_README.html">TER_README</a> document. 258 259 <b><a href="postconf.5.html#smtpd_milters">smtpd_milters</a> (empty)</b> 260 A list of Milter (mail filter) applications for new mail that 261 arrives via the Postfix <a href="smtpd.8.html"><b>smtpd</b>(8)</a> server. 262 263 <b><a href="postconf.5.html#milter_protocol">milter_protocol</a> (6)</b> 264 The mail filter protocol version and optional protocol exten- 265 sions for communication with a Milter application; prior to 266 Postfix 2.6 the default protocol is 2. 267 268 <b><a href="postconf.5.html#milter_default_action">milter_default_action</a> (Postfix</b> ><b>= 3.11: shutdown; Postfix</b> < <b>3.11: temp-</b> 269 <b>fail)</b> 270 The default action when a Milter (mail filter) response is 271 unavailable (for example, bad Postfix configuration or Milter 272 failure). 273 274 <b><a href="postconf.5.html#milter_macro_daemon_name">milter_macro_daemon_name</a> ($<a href="postconf.5.html#myhostname">myhostname</a>)</b> 275 The {daemon_name} macro value for Milter (mail filter) applica- 276 tions. 277 278 <b><a href="postconf.5.html#milter_macro_v">milter_macro_v</a> ($<a href="postconf.5.html#mail_name">mail_name</a> $<a href="postconf.5.html#mail_version">mail_version</a>)</b> 279 The {v} macro value for Milter (mail filter) applications. 280 281 <b><a href="postconf.5.html#milter_connect_timeout">milter_connect_timeout</a> (30s)</b> 282 The time limit for connecting to a Milter (mail filter) applica- 283 tion, and for negotiating protocol options. 284 285 <b><a href="postconf.5.html#milter_command_timeout">milter_command_timeout</a> (30s)</b> 286 The time limit for sending an SMTP command to a Milter (mail 287 filter) application, and for receiving the response. 288 289 <b><a href="postconf.5.html#milter_content_timeout">milter_content_timeout</a> (300s)</b> 290 The time limit for sending message content to a Milter (mail 291 filter) application, and for receiving the response. 292 293 <b><a href="postconf.5.html#milter_connect_macros">milter_connect_macros</a> (see 'postconf -d' output)</b> 294 The macros that are sent to Milter (mail filter) applications 295 after completion of an SMTP connection. 296 297 <b><a href="postconf.5.html#milter_helo_macros">milter_helo_macros</a> (see 'postconf -d' output)</b> 298 The macros that are sent to Milter (mail filter) applications 299 after the SMTP HELO or EHLO command. 300 301 <b><a href="postconf.5.html#milter_mail_macros">milter_mail_macros</a> (see 'postconf -d' output)</b> 302 The macros that are sent to Milter (mail filter) applications 303 after the SMTP MAIL FROM command. 304 305 <b><a href="postconf.5.html#milter_rcpt_macros">milter_rcpt_macros</a> (see 'postconf -d' output)</b> 306 The macros that are sent to Milter (mail filter) applications 307 after the SMTP RCPT TO command. 308 309 <b><a href="postconf.5.html#milter_data_macros">milter_data_macros</a> (see 'postconf -d' output)</b> 310 The macros that are sent to version 4 or higher Milter (mail 311 filter) applications after the SMTP DATA command. 312 313 <b><a href="postconf.5.html#milter_unknown_command_macros">milter_unknown_command_macros</a> (see 'postconf -d' output)</b> 314 The macros that are sent to version 3 or higher Milter (mail 315 filter) applications after an unknown SMTP command. 316 317 <b><a href="postconf.5.html#milter_end_of_header_macros">milter_end_of_header_macros</a> (see 'postconf -d' output)</b> 318 The macros that are sent to Milter (mail filter) applications 319 after the end of the message header. 320 321 <b><a href="postconf.5.html#milter_end_of_data_macros">milter_end_of_data_macros</a> (see 'postconf -d' output)</b> 322 The macros that are sent to Milter (mail filter) applications 323 after the message end-of-data. 324 325 Available in Postfix version 3.1 and later: 326 327 <b><a href="postconf.5.html#milter_macro_defaults">milter_macro_defaults</a> (empty)</b> 328 Optional list of <i>name=value</i> pairs that specify default values 329 for arbitrary macros that Postfix may send to Milter applica- 330 tions. 331 332 Available in Postfix version 3.2 and later: 333 334 <b><a href="postconf.5.html#smtpd_milter_maps">smtpd_milter_maps</a> (empty)</b> 335 Lookup tables with Milter settings per remote SMTP client IP 336 address. 337 338 <b><a name="general_content_inspection_controls">GENERAL CONTENT INSPECTION CONTROLS</a></b> 339 The following parameters are applicable for both built-in and external 340 content filters. 341 342 Available in Postfix version 2.1 and later: 343 344 <b><a href="postconf.5.html#receive_override_options">receive_override_options</a> (empty)</b> 345 Enable or disable recipient validation, built-in content filter- 346 ing, or address mapping. 347 348 <b><a name="external_content_inspection_controls">EXTERNAL CONTENT INSPECTION CONTROLS</a></b> 349 The following parameters are applicable for both before-queue and 350 after-queue content filtering. 351 352 Available in Postfix version 2.1 and later: 353 354 <b><a href="postconf.5.html#smtpd_authorized_xforward_hosts">smtpd_authorized_xforward_hosts</a> (empty)</b> 355 What remote SMTP clients are allowed to use the XFORWARD fea- 356 ture. 357 358 <b><a name="sasl_authentication_controls">SASL AUTHENTICATION CONTROLS</a></b> 359 Postfix SASL support (<a href="https://tools.ietf.org/html/rfc4954">RFC 4954</a>) can be used to authenticate remote SMTP 360 clients to the Postfix SMTP server, and to authenticate the Postfix 361 SMTP client to a remote SMTP server. See the <a href="SASL_README.html">SASL_README</a> document for 362 details. 363 364 <b><a href="postconf.5.html#broken_sasl_auth_clients">broken_sasl_auth_clients</a> (no)</b> 365 Enable interoperability with remote SMTP clients that implement 366 an obsolete version of the AUTH command (<a href="https://tools.ietf.org/html/rfc4954">RFC 4954</a>). 367 368 <b><a href="postconf.5.html#smtpd_sasl_auth_enable">smtpd_sasl_auth_enable</a> (no)</b> 369 Enable SASL authentication in the Postfix SMTP server. 370 371 <b><a href="postconf.5.html#smtpd_sasl_local_domain">smtpd_sasl_local_domain</a> (empty)</b> 372 The name of the Postfix SMTP server's local SASL authentication 373 realm. 374 375 <b><a href="postconf.5.html#smtpd_sasl_security_options">smtpd_sasl_security_options</a> (noanonymous)</b> 376 Postfix SMTP server SASL security options; as of Postfix 2.3 the 377 list of available features depends on the SASL server implemen- 378 tation that is selected with <b><a href="postconf.5.html#smtpd_sasl_type">smtpd_sasl_type</a></b>. 379 380 <b><a href="postconf.5.html#smtpd_sender_login_maps">smtpd_sender_login_maps</a> (empty)</b> 381 Optional lookup table with the SASL login names that own the 382 envelope sender (MAIL FROM) addresses. 383 384 Available in Postfix version 2.1 and later: 385 386 <b><a href="postconf.5.html#smtpd_sasl_exceptions_networks">smtpd_sasl_exceptions_networks</a> (empty)</b> 387 What remote SMTP clients the Postfix SMTP server will not offer 388 AUTH support to. 389 390 Available in Postfix version 2.1 and 2.2: 391 392 <b><a href="postconf.5.html#smtpd_sasl_application_name">smtpd_sasl_application_name</a> (smtpd)</b> 393 The application name that the Postfix SMTP server uses for SASL 394 server initialization. 395 396 Available in Postfix version 2.3 and later: 397 398 <b><a href="postconf.5.html#smtpd_sasl_authenticated_header">smtpd_sasl_authenticated_header</a> (no)</b> 399 Report the SASL authenticated user name in the <a href="smtpd.8.html"><b>smtpd</b>(8)</a> Received 400 message header. 401 402 <b><a href="postconf.5.html#smtpd_sasl_path">smtpd_sasl_path</a> (smtpd)</b> 403 Implementation-specific information that the Postfix SMTP server 404 passes through to the SASL plug-in implementation that is 405 selected with <b><a href="postconf.5.html#smtpd_sasl_type">smtpd_sasl_type</a></b>. 406 407 <b><a href="postconf.5.html#smtpd_sasl_type">smtpd_sasl_type</a> (cyrus)</b> 408 The SASL plug-in type that the Postfix SMTP server should use 409 for authentication. 410 411 Available in Postfix version 2.5 and later: 412 413 <b><a href="postconf.5.html#cyrus_sasl_config_path">cyrus_sasl_config_path</a> (empty)</b> 414 Search path for Cyrus SASL application configuration files, cur- 415 rently used only to locate the $<a href="postconf.5.html#smtpd_sasl_path">smtpd_sasl_path</a>.conf file. 416 417 Available in Postfix version 2.11 and later: 418 419 <b><a href="postconf.5.html#smtpd_sasl_service">smtpd_sasl_service</a> (smtp)</b> 420 The service name that is passed to the SASL plug-in that is 421 selected with <b><a href="postconf.5.html#smtpd_sasl_type">smtpd_sasl_type</a></b> and <b><a href="postconf.5.html#smtpd_sasl_path">smtpd_sasl_path</a></b>. 422 423 Available in Postfix version 3.4 and later: 424 425 <b><a href="postconf.5.html#smtpd_sasl_response_limit">smtpd_sasl_response_limit</a> (12288)</b> 426 The maximum length of a SASL client's response to a server chal- 427 lenge. 428 429 Available in Postfix 3.6 and later: 430 431 <b><a href="postconf.5.html#smtpd_sasl_mechanism_filter">smtpd_sasl_mechanism_filter</a> (!external, <a href="DATABASE_README.html#types">static</a>:rest)</b> 432 If non-empty, a filter for the SASL mechanism names that the 433 Postfix SMTP server will announce in the EHLO response. 434 435 <b><a name="tls_support_controls">TLS SUPPORT CONTROLS</a></b> 436 Detailed information about STARTTLS configuration may be found in the 437 <a href="TLS_README.html">TLS_README</a> document. 438 439 <b><a href="postconf.5.html#smtpd_tls_security_level">smtpd_tls_security_level</a> (empty)</b> 440 The SMTP TLS security level for the Postfix SMTP server; when a 441 non-empty value is specified, this overrides the obsolete param- 442 eters <a href="postconf.5.html#smtpd_use_tls">smtpd_use_tls</a> and <a href="postconf.5.html#smtpd_enforce_tls">smtpd_enforce_tls</a>. 443 444 <b><a href="postconf.5.html#smtpd_sasl_tls_security_options">smtpd_sasl_tls_security_options</a> ($<a href="postconf.5.html#smtpd_sasl_security_options">smtpd_sasl_security_options</a>)</b> 445 The SASL authentication security options that the Postfix SMTP 446 server uses for TLS encrypted SMTP sessions. 447 448 <b><a href="postconf.5.html#smtpd_starttls_timeout">smtpd_starttls_timeout</a> (see 'postconf -d' output)</b> 449 The time limit for Postfix SMTP server write and read operations 450 during TLS startup and shutdown handshake procedures. 451 452 <b><a href="postconf.5.html#smtpd_tls_CAfile">smtpd_tls_CAfile</a> (empty)</b> 453 A file containing (PEM format) CA certificates of root CAs 454 trusted to sign either remote SMTP client certificates or inter- 455 mediate CA certificates. 456 457 <b><a href="postconf.5.html#smtpd_tls_CApath">smtpd_tls_CApath</a> (empty)</b> 458 A directory containing (PEM format) CA certificates of root CAs 459 trusted to sign either remote SMTP client certificates or inter- 460 mediate CA certificates. 461 462 <b><a href="postconf.5.html#smtpd_tls_always_issue_session_ids">smtpd_tls_always_issue_session_ids</a> (yes)</b> 463 Force the Postfix SMTP server to issue a TLS session id, even 464 when TLS session caching is turned off (<a href="postconf.5.html#smtpd_tls_session_cache_database">smtpd_tls_ses</a>- 465 <a href="postconf.5.html#smtpd_tls_session_cache_database">sion_cache_database</a> is empty). 466 467 <b><a href="postconf.5.html#smtpd_tls_ask_ccert">smtpd_tls_ask_ccert</a> (no)</b> 468 Ask a remote SMTP client for a client certificate. 469 470 <b><a href="postconf.5.html#smtpd_tls_auth_only">smtpd_tls_auth_only</a> (no)</b> 471 When TLS encryption is optional in the Postfix SMTP server, do 472 not announce or accept SASL authentication over unencrypted con- 473 nections. 474 475 <b><a href="postconf.5.html#smtpd_tls_ccert_verifydepth">smtpd_tls_ccert_verifydepth</a> (9)</b> 476 The verification depth for remote SMTP client certificates. 477 478 <b><a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a> (empty)</b> 479 File with the Postfix SMTP server RSA certificate in PEM format. 480 481 <b><a href="postconf.5.html#smtpd_tls_exclude_ciphers">smtpd_tls_exclude_ciphers</a> (empty)</b> 482 List of ciphers or cipher types to exclude from the SMTP server 483 cipher list at all TLS security levels. 484 485 <b><a href="postconf.5.html#smtpd_tls_dcert_file">smtpd_tls_dcert_file</a> (empty)</b> 486 File with the Postfix SMTP server DSA certificate in PEM format. 487 488 <b><a href="postconf.5.html#smtpd_tls_dh1024_param_file">smtpd_tls_dh1024_param_file</a> (empty)</b> 489 File with DH parameters that the Postfix SMTP server should use 490 with non-export EDH ciphers. 491 492 <b><a href="postconf.5.html#smtpd_tls_dh512_param_file">smtpd_tls_dh512_param_file</a> (empty)</b> 493 File with DH parameters that the Postfix SMTP server should use 494 with export-grade EDH ciphers. 495 496 <b><a href="postconf.5.html#smtpd_tls_dkey_file">smtpd_tls_dkey_file</a> ($<a href="postconf.5.html#smtpd_tls_dcert_file">smtpd_tls_dcert_file</a>)</b> 497 File with the Postfix SMTP server DSA private key in PEM format. 498 499 <b><a href="postconf.5.html#smtpd_tls_key_file">smtpd_tls_key_file</a> ($<a href="postconf.5.html#smtpd_tls_cert_file">smtpd_tls_cert_file</a>)</b> 500 File with the Postfix SMTP server RSA private key in PEM format. 501 502 <b><a href="postconf.5.html#smtpd_tls_loglevel">smtpd_tls_loglevel</a> (0)</b> 503 Enable additional Postfix SMTP server logging of TLS activity. 504 505 <b><a href="postconf.5.html#smtpd_tls_mandatory_ciphers">smtpd_tls_mandatory_ciphers</a> (medium)</b> 506 The minimum TLS cipher grade that the Postfix SMTP server will 507 use with mandatory TLS encryption. 508 509 <b><a href="postconf.5.html#smtpd_tls_mandatory_exclude_ciphers">smtpd_tls_mandatory_exclude_ciphers</a> (empty)</b> 510 Additional list of ciphers or cipher types to exclude from the 511 Postfix SMTP server cipher list at mandatory TLS security lev- 512 els. 513 514 <b><a href="postconf.5.html#smtpd_tls_mandatory_protocols">smtpd_tls_mandatory_protocols</a> (see 'postconf -d' output)</b> 515 TLS protocols accepted by the Postfix SMTP server with mandatory 516 TLS encryption. 517 518 <b><a href="postconf.5.html#smtpd_tls_received_header">smtpd_tls_received_header</a> (no)</b> 519 Request that the Postfix SMTP server produces Received: message 520 headers that include information about the protocol and cipher 521 used, as well as the remote SMTP client CommonName and client 522 certificate issuer CommonName. 523 524 <b><a href="postconf.5.html#smtpd_tls_req_ccert">smtpd_tls_req_ccert</a> (no)</b> 525 With mandatory TLS encryption, require a trusted remote SMTP 526 client certificate in order to allow TLS connections to proceed. 527 528 <b><a href="postconf.5.html#smtpd_tls_wrappermode">smtpd_tls_wrappermode</a> (no)</b> 529 Run the Postfix SMTP server in TLS "wrapper" mode, instead of 530 using the STARTTLS command. 531 532 <b><a href="postconf.5.html#tls_daemon_random_bytes">tls_daemon_random_bytes</a> (32)</b> 533 The number of pseudo-random bytes that an <a href="smtp.8.html"><b>smtp</b>(8)</a> or <a href="smtpd.8.html"><b>smtpd</b>(8)</a> 534 process requests from the <a href="tlsmgr.8.html"><b>tlsmgr</b>(8)</a> server in order to seed its 535 internal pseudo random number generator (PRNG). 536 537 <b><a href="postconf.5.html#tls_high_cipherlist">tls_high_cipherlist</a> (see 'postconf -d' output)</b> 538 The OpenSSL cipherlist for "high" grade ciphers. 539 540 <b><a href="postconf.5.html#tls_medium_cipherlist">tls_medium_cipherlist</a> (see 'postconf -d' output)</b> 541 The OpenSSL cipherlist for "medium" or higher grade ciphers. 542 543 <b><a href="postconf.5.html#tls_null_cipherlist">tls_null_cipherlist</a> (eNULL:!aNULL)</b> 544 The OpenSSL cipherlist for "NULL" grade ciphers that provide 545 authentication without encryption. 546 547 Available in Postfix version 2.3..3.7: 548 549 <b><a href="postconf.5.html#tls_low_cipherlist">tls_low_cipherlist</a> (see 'postconf -d' output)</b> 550 The OpenSSL cipherlist for "low" or higher grade ciphers. 551 552 <b><a href="postconf.5.html#tls_export_cipherlist">tls_export_cipherlist</a> (see 'postconf -d' output)</b> 553 The OpenSSL cipherlist for "export" or higher grade ciphers. 554 555 Available in Postfix version 2.5 and later: 556 557 <b><a href="postconf.5.html#smtpd_tls_fingerprint_digest">smtpd_tls_fingerprint_digest</a> (see 'postconf -d' output)</b> 558 The message digest algorithm to construct remote SMTP 559 client-certificate fingerprints or public key fingerprints 560 (Postfix 2.9 and later) for <b><a href="postconf.5.html#check_ccert_access">check_ccert_access</a></b> and <b>per-</b> 561 <b>mit_tls_clientcerts</b>. 562 563 Available in Postfix version 2.6 and later: 564 565 <b><a href="postconf.5.html#smtpd_tls_protocols">smtpd_tls_protocols</a> (see 'postconf -d' output)</b> 566 TLS protocols accepted by the Postfix SMTP server with oppor- 567 tunistic TLS encryption. 568 569 <b><a href="postconf.5.html#smtpd_tls_ciphers">smtpd_tls_ciphers</a> (medium)</b> 570 The minimum TLS cipher grade that the Postfix SMTP server will 571 use with opportunistic TLS encryption. 572 573 <b><a href="postconf.5.html#smtpd_tls_eccert_file">smtpd_tls_eccert_file</a> (empty)</b> 574 File with the Postfix SMTP server ECDSA certificate in PEM for- 575 mat. 576 577 <b><a href="postconf.5.html#smtpd_tls_eckey_file">smtpd_tls_eckey_file</a> ($<a href="postconf.5.html#smtpd_tls_eccert_file">smtpd_tls_eccert_file</a>)</b> 578 File with the Postfix SMTP server ECDSA private key in PEM for- 579 mat. 580 581 <b><a href="postconf.5.html#smtpd_tls_eecdh_grade">smtpd_tls_eecdh_grade</a> (see 'postconf -d' output)</b> 582 The Postfix SMTP server security grade for ephemeral ellip- 583 tic-curve Diffie-Hellman (EECDH) key exchange. 584 585 <b><a href="postconf.5.html#tls_eecdh_strong_curve">tls_eecdh_strong_curve</a> (prime256v1)</b> 586 The elliptic curve used by the Postfix SMTP server for sensibly 587 strong ephemeral ECDH key exchange. 588 589 <b><a href="postconf.5.html#tls_eecdh_ultra_curve">tls_eecdh_ultra_curve</a> (secp384r1)</b> 590 The elliptic curve used by the Postfix SMTP server for maximally 591 strong ephemeral ECDH key exchange. 592 593 Available in Postfix version 2.8 and later: 594 595 <b><a href="postconf.5.html#tls_preempt_cipherlist">tls_preempt_cipherlist</a> (no)</b> 596 With SSLv3 and later, use the Postfix SMTP server's cipher pref- 597 erence order instead of the remote client's cipher preference 598 order. 599 600 <b><a href="postconf.5.html#tls_disable_workarounds">tls_disable_workarounds</a> (see 'postconf -d' output)</b> 601 List or bit-mask of OpenSSL bug work-arounds to disable. 602 603 Available in Postfix version 2.11 and later: 604 605 <b><a href="postconf.5.html#tlsmgr_service_name">tlsmgr_service_name</a> (tlsmgr)</b> 606 The name of the <a href="tlsmgr.8.html"><b>tlsmgr</b>(8)</a> service entry in <a href="master.5.html">master.cf</a>. 607 608 Available in Postfix version 3.0 and later: 609 610 <b><a href="postconf.5.html#tls_session_ticket_cipher">tls_session_ticket_cipher</a> (Postfix</b> ><b>= 3.0: aes-256-cbc, Postfix</b> < <b>3.0:</b> 611 <b>aes-128-cbc)</b> 612 Algorithm used to encrypt <a href="https://tools.ietf.org/html/rfc5077">RFC5077</a> TLS session tickets. 613 614 Available in Postfix version 3.2 and later: 615 616 <b><a href="postconf.5.html#tls_eecdh_auto_curves">tls_eecdh_auto_curves</a> (see 'postconf -d' output)</b> 617 The prioritized list of elliptic curves, that should be enabled 618 in the Postfix SMTP client and server. 619 620 Available in Postfix version 3.4 and later: 621 622 <b><a href="postconf.5.html#smtpd_tls_chain_files">smtpd_tls_chain_files</a> (empty)</b> 623 List of one or more PEM files, each holding one or more private 624 keys directly followed by a corresponding certificate chain. 625 626 <b><a href="postconf.5.html#tls_server_sni_maps">tls_server_sni_maps</a> (empty)</b> 627 Optional lookup tables that map names received from remote SMTP 628 clients via the TLS Server Name Indication (SNI) extension to 629 the appropriate keys and certificate chains. 630 631 Available in Postfix 3.5, 3.4.6, 3.3.5, 3.2.10, 3.1.13 and later: 632 633 <b><a href="postconf.5.html#tls_fast_shutdown_enable">tls_fast_shutdown_enable</a> (yes)</b> 634 A workaround for implementations that hang Postfix while shut- 635 ting down a TLS session, until Postfix times out. 636 637 Available in Postfix version 3.8 and later: 638 639 <b><a href="postconf.5.html#tls_ffdhe_auto_groups">tls_ffdhe_auto_groups</a> (see 'postconf -d' output)</b> 640 The prioritized list of finite-field Diffie-Hellman ephemeral 641 (FFDHE) key exchange groups supported by the Postfix SMTP client 642 and server. 643 644 Available in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later: 645 646 <b><a href="postconf.5.html#tls_config_file">tls_config_file</a> (default)</b> 647 Optional configuration file with baseline OpenSSL settings. 648 649 <b><a href="postconf.5.html#tls_config_name">tls_config_name</a> (empty)</b> 650 The application name passed by Postfix to OpenSSL library ini- 651 tialization functions. 652 653 Available in Postfix version 3.9 and later: 654 655 <b><a href="postconf.5.html#smtpd_tls_enable_rpk">smtpd_tls_enable_rpk</a> (no)</b> 656 Request that remote SMTP clients send an <a href="https://tools.ietf.org/html/rfc7250">RFC7250</a> raw public key 657 instead of an X.509 certificate, when asking for or requiring 658 client authentication. 659 660 Available in Postfix version 3.11 and later: 661 662 <b><a href="postconf.5.html#requiretls_enable">requiretls_enable</a> (yes)</b> 663 Enable support for the ESMTP verb "REQUIRETLS" in the "MAIL 664 FROM" command. 665 666 <b><a href="postconf.5.html#requiretls_esmtp_header">requiretls_esmtp_header</a> (yes)</b> 667 Record the ESMTP REQUIRETLS request in a "Require-TLS-ESMTP: 668 yes" message header. 669 670 <b><a name="obsolete_tls_controls">OBSOLETE TLS CONTROLS</a></b> 671 The following configuration parameters exist for compatibility with 672 Postfix versions before 2.3. Support for these will be removed in a 673 future release. 674 675 <b><a href="postconf.5.html#smtpd_use_tls">smtpd_use_tls</a> (no)</b> 676 Opportunistic TLS: announce STARTTLS support to remote SMTP 677 clients, but do not require that clients use TLS encryption. 678 679 <b><a href="postconf.5.html#smtpd_enforce_tls">smtpd_enforce_tls</a> (no)</b> 680 Mandatory TLS: announce STARTTLS support to remote SMTP clients, 681 and reject all plaintext commands except HELO, EHLO, XCLIENT, 682 STARTTLS, NOOP, QUIT, and (Postfix >= 3.9) HELP. 683 684 <b><a href="postconf.5.html#smtpd_tls_cipherlist">smtpd_tls_cipherlist</a> (empty)</b> 685 Obsolete Postfix < 2.3 control for the Postfix SMTP server TLS 686 cipher list. 687 688 <b><a name="smtputf8_controls">SMTPUTF8 CONTROLS</a></b> 689 Preliminary SMTPUTF8 support is introduced with Postfix 3.0. 690 691 <b><a href="postconf.5.html#smtputf8_enable">smtputf8_enable</a> (yes)</b> 692 Enable preliminary SMTPUTF8 support for the protocols described 693 in <a href="https://tools.ietf.org/html/rfc6531">RFC 6531</a>, <a href="https://tools.ietf.org/html/rfc6532">RFC 6532</a>, and <a href="https://tools.ietf.org/html/rfc6533">RFC 6533</a>. 694 695 <b><a href="postconf.5.html#strict_smtputf8">strict_smtputf8</a> (no)</b> 696 Enable stricter enforcement of the SMTPUTF8 protocol. 697 698 <b><a href="postconf.5.html#smtputf8_autodetect_classes">smtputf8_autodetect_classes</a> (sendmail, verify)</b> 699 Detect that a message requires SMTPUTF8 support for the speci- 700 fied mail origin classes. 701 702 Available in Postfix version 3.2 and later: 703 704 <b><a href="postconf.5.html#enable_idna2003_compatibility">enable_idna2003_compatibility</a> (no)</b> 705 Enable 'transitional' compatibility between IDNA2003 and 706 IDNA2008, when converting UTF-8 domain names to/from the ASCII 707 form that is used for DNS lookups. 708 709 <b><a name="verp_support_controls">VERP SUPPORT CONTROLS</a></b> 710 With VERP style delivery, each recipient of a message receives a cus- 711 tomized copy of the message with his/her own recipient address encoded 712 in the envelope sender address. The <a href="VERP_README.html">VERP_README</a> file describes config- 713 uration and operation details of Postfix support for variable envelope 714 return path addresses. VERP style delivery is requested with the SMTP 715 XVERP command or with the "sendmail -V" command-line option and is 716 available in Postfix version 1.1 and later. 717 718 <b><a href="postconf.5.html#default_verp_delimiters">default_verp_delimiters</a> (+=)</b> 719 The two default VERP delimiter characters. 720 721 <b><a href="postconf.5.html#verp_delimiter_filter">verp_delimiter_filter</a> (-=+)</b> 722 The characters Postfix accepts as VERP delimiter characters on 723 the Postfix <a href="sendmail.1.html"><b>sendmail</b>(1)</a> command line and in SMTP commands. 724 725 Available in Postfix version 1.1 and 2.0: 726 727 <b><a href="postconf.5.html#authorized_verp_clients">authorized_verp_clients</a> ($<a href="postconf.5.html#mynetworks">mynetworks</a>)</b> 728 What remote SMTP clients are allowed to specify the XVERP com- 729 mand. 730 731 Available in Postfix version 2.1 and later: 732 733 <b><a href="postconf.5.html#smtpd_authorized_verp_clients">smtpd_authorized_verp_clients</a> ($<a href="postconf.5.html#authorized_verp_clients">authorized_verp_clients</a>)</b> 734 What remote SMTP clients are allowed to specify the XVERP com- 735 mand. 736 737 <b><a name="trouble_shooting_controls">TROUBLE SHOOTING CONTROLS</a></b> 738 The <a href="DEBUG_README.html">DEBUG_README</a> document describes how to debug parts of the Postfix 739 mail system. The methods vary from making the software log a lot of 740 detail, to running some daemon processes under control of a call tracer 741 or debugger. 742 743 <b><a href="postconf.5.html#debug_peer_level">debug_peer_level</a> (2)</b> 744 The increment in verbose logging level when a nexthop destina- 745 tion, remote client or server name or network address matches a 746 pattern given with the <a href="postconf.5.html#debug_peer_list">debug_peer_list</a> parameter. 747 748 <b><a href="postconf.5.html#debug_peer_list">debug_peer_list</a> (empty)</b> 749 Optional list of nexthop destination, remote client or server 750 name or network address patterns that, if matched, cause the 751 verbose logging level to increase by the amount specified in 752 $<a href="postconf.5.html#debug_peer_level">debug_peer_level</a>. 753 754 <b><a href="postconf.5.html#error_notice_recipient">error_notice_recipient</a> (postmaster)</b> 755 The recipient of postmaster notifications about mail delivery 756 problems that are caused by policy, resource, software or proto- 757 col errors. 758 759 <b><a href="postconf.5.html#internal_mail_filter_classes">internal_mail_filter_classes</a> (empty)</b> 760 What categories of Postfix-generated mail are subject to 761 before-queue content inspection by <a href="postconf.5.html#non_smtpd_milters">non_smtpd_milters</a>, 762 <a href="postconf.5.html#header_checks">header_checks</a> and <a href="postconf.5.html#body_checks">body_checks</a>. 763 764 <b><a href="postconf.5.html#notify_classes">notify_classes</a> (resource, software)</b> 765 The list of error classes that are reported to the postmaster. 766 767 <b><a href="postconf.5.html#smtpd_reject_footer">smtpd_reject_footer</a> (empty)</b> 768 Optional information that is appended after each Postfix SMTP 769 server 4XX or 5XX response. 770 771 <b><a href="postconf.5.html#soft_bounce">soft_bounce</a> (no)</b> 772 Safety net to keep mail queued that would otherwise be returned 773 to the sender. 774 775 Available in Postfix version 2.1 and later: 776 777 <b><a href="postconf.5.html#smtpd_authorized_xclient_hosts">smtpd_authorized_xclient_hosts</a> (empty)</b> 778 What remote SMTP clients are allowed to use the XCLIENT feature. 779 780 Available in Postfix version 2.10 and later: 781 782 <b><a href="postconf.5.html#smtpd_log_access_permit_actions">smtpd_log_access_permit_actions</a> (empty)</b> 783 Enable logging of the named "permit" actions in SMTP server 784 access lists (by default, the SMTP server logs "reject" actions 785 but not "permit" actions). 786 787 <b><a name="known_versus_unknown_recipient_controls">KNOWN VERSUS UNKNOWN RECIPIENT CONTROLS</a></b> 788 As of Postfix version 2.0, the SMTP server rejects mail for unknown 789 recipients. This prevents the mail queue from clogging up with undeliv- 790 erable MAILER-DAEMON messages. Additional information on this topic is 791 in the <a href="LOCAL_RECIPIENT_README.html">LOCAL_RECIPIENT_README</a> and <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a> documents. 792 793 <b><a href="postconf.5.html#show_user_unknown_table_name">show_user_unknown_table_name</a> (yes)</b> 794 Display the name of the recipient table in the "User unknown" 795 responses. 796 797 <b><a href="postconf.5.html#canonical_maps">canonical_maps</a> (empty)</b> 798 Optional address mapping lookup tables for message headers and 799 envelopes. 800 801 <b><a href="postconf.5.html#recipient_canonical_maps">recipient_canonical_maps</a> (empty)</b> 802 Optional address mapping lookup tables for envelope and header 803 recipient addresses. 804 805 <b><a href="postconf.5.html#sender_canonical_maps">sender_canonical_maps</a> (empty)</b> 806 Optional address mapping lookup tables for envelope and header 807 sender addresses. 808 809 Parameters concerning known/unknown local recipients: 810 811 <b><a href="postconf.5.html#mydestination">mydestination</a> ($<a href="postconf.5.html#myhostname">myhostname</a>, localhost.$<a href="postconf.5.html#mydomain">mydomain</a>, localhost)</b> 812 The list of domains that are delivered via the $<a href="postconf.5.html#local_transport">local_transport</a> 813 mail delivery transport. 814 815 <b><a href="postconf.5.html#inet_interfaces">inet_interfaces</a> (all)</b> 816 The local network interface addresses that this mail system 817 receives mail on. 818 819 <b><a href="postconf.5.html#proxy_interfaces">proxy_interfaces</a> (empty)</b> 820 The remote network interface addresses that this mail system 821 receives mail on by way of a proxy or network address transla- 822 tion unit. 823 824 <b><a href="postconf.5.html#inet_protocols">inet_protocols</a> (see 'postconf -d' output)</b> 825 The Internet protocols Postfix will attempt to use when making 826 or accepting connections. 827 828 <b><a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> (<a href="proxymap.8.html">proxy</a>:unix:passwd.byname $<a href="postconf.5.html#alias_maps">alias_maps</a>)</b> 829 Lookup tables with all names or addresses of valid local recipi- 830 ents. 831 832 <b><a href="postconf.5.html#unknown_local_recipient_reject_code">unknown_local_recipient_reject_code</a> (550)</b> 833 The numerical Postfix SMTP server response code when a recipient 834 address is local, and $<a href="postconf.5.html#local_recipient_maps">local_recipient_maps</a> specifies a list of 835 lookup tables that does not match the recipient. 836 837 Parameters concerning known/unknown recipients of relay destinations: 838 839 <b><a href="postconf.5.html#relay_domains">relay_domains</a> (Postfix</b> ><b>= 3.0: empty, Postfix</b> < <b>3.0: $<a href="postconf.5.html#mydestination">mydestination</a>)</b> 840 What destination domains (and subdomains thereof) this system 841 will relay mail to. 842 843 <b><a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a> (empty)</b> 844 Optional lookup tables with all valid addresses in the domains 845 that match $<a href="postconf.5.html#relay_domains">relay_domains</a>. 846 847 <b><a href="postconf.5.html#unknown_relay_recipient_reject_code">unknown_relay_recipient_reject_code</a> (550)</b> 848 The numerical Postfix SMTP server reply code when a recipient 849 address matches $<a href="postconf.5.html#relay_domains">relay_domains</a>, and <a href="postconf.5.html#relay_recipient_maps">relay_recipient_maps</a> speci- 850 fies a list of lookup tables that does not match the recipient 851 address. 852 853 Parameters concerning known/unknown recipients in virtual alias 854 domains: 855 856 <b><a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a> ($<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a>)</b> 857 Postfix is the final destination for the specified list of vir- 858 tual alias domains, that is, domains for which all addresses are 859 aliased to addresses in other local or remote domains. 860 861 <b><a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a> ($<a href="postconf.5.html#virtual_maps">virtual_maps</a>)</b> 862 Optional lookup tables that are often searched with a full email 863 address (including domain) and that apply to all recipients: 864 <a href="local.8.html"><b>local</b>(8)</a>, virtual, and remote; this is unlike <a href="postconf.5.html#alias_maps">alias_maps</a> that 865 are only searched with an email address localpart (no domain) 866 and that apply only to <a href="local.8.html"><b>local</b>(8)</a> recipients. 867 868 <b><a href="postconf.5.html#unknown_virtual_alias_reject_code">unknown_virtual_alias_reject_code</a> (550)</b> 869 The Postfix SMTP server reply code when a recipient address 870 matches $<a href="postconf.5.html#virtual_alias_domains">virtual_alias_domains</a>, and $<a href="postconf.5.html#virtual_alias_maps">virtual_alias_maps</a> speci- 871 fies a list of lookup tables that does not match the recipient 872 address. 873 874 Parameters concerning known/unknown recipients in virtual mailbox 875 domains: 876 877 <b><a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a> ($<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a>)</b> 878 Postfix is the final destination for the specified list of 879 domains; mail is delivered via the $<a href="postconf.5.html#virtual_transport">virtual_transport</a> mail 880 delivery transport. 881 882 <b><a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a> (empty)</b> 883 Optional lookup tables with all valid addresses in the domains 884 that match $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>. 885 886 <b><a href="postconf.5.html#unknown_virtual_mailbox_reject_code">unknown_virtual_mailbox_reject_code</a> (550)</b> 887 The Postfix SMTP server reply code when a recipient address 888 matches $<a href="postconf.5.html#virtual_mailbox_domains">virtual_mailbox_domains</a>, and $<a href="postconf.5.html#virtual_mailbox_maps">virtual_mailbox_maps</a> 889 specifies a list of lookup tables that does not match the recip- 890 ient address. 891 892 <b><a name="resource_and_rate_controls">RESOURCE AND RATE CONTROLS</a></b> 893 The following parameters limit resource usage by the SMTP server and/or 894 control client request rates. 895 896 <b><a href="postconf.5.html#line_length_limit">line_length_limit</a> (2048)</b> 897 Upon input, long lines are chopped up into pieces of at most 898 this length; upon delivery, long lines are reconstructed. 899 900 <b><a href="postconf.5.html#queue_minfree">queue_minfree</a> (0)</b> 901 The minimal amount of free space in bytes in the queue file sys- 902 tem that is needed to receive mail. 903 904 <b><a href="postconf.5.html#message_size_limit">message_size_limit</a> (10240000)</b> 905 The maximal size in bytes of a message, including envelope 906 information. 907 908 <b><a href="postconf.5.html#smtpd_recipient_limit">smtpd_recipient_limit</a> (1000)</b> 909 The maximal number of recipients that the Postfix SMTP server 910 accepts per message delivery request. 911 912 <b><a href="postconf.5.html#smtpd_timeout">smtpd_timeout</a> (normal: 300s, <a href="STRESS_README.html">overload</a>: 10s)</b> 913 When the Postfix SMTP server wants to send an SMTP server 914 response, how long the Postfix SMTP server will wait for an 915 underlying network write operation to complete; and when the 916 Postfix SMTP server Postfix wants to receive an SMTP client 917 request, how long the Postfix SMTP server will wait for an 918 underlying network read operation to complete. 919 920 <b><a href="postconf.5.html#smtpd_history_flush_threshold">smtpd_history_flush_threshold</a> (100)</b> 921 The maximal number of lines in the Postfix SMTP server command 922 history before it is flushed upon receipt of EHLO, RSET, or end 923 of DATA. 924 925 Available in Postfix version 2.3 and later: 926 927 <b><a href="postconf.5.html#smtpd_peername_lookup">smtpd_peername_lookup</a> (yes)</b> 928 Attempt to look up the remote SMTP client hostname, and verify 929 that the name matches the client IP address. 930 931 The per SMTP client connection count and request rate limits are imple- 932 mented in co-operation with the <a href="anvil.8.html"><b>anvil</b>(8)</a> service, and are available in 933 Postfix version 2.2 and later. 934 935 <b><a href="postconf.5.html#smtpd_client_connection_count_limit">smtpd_client_connection_count_limit</a> (50)</b> 936 How many simultaneous connections any client is allowed to make 937 to this service. 938 939 <b><a href="postconf.5.html#smtpd_client_connection_rate_limit">smtpd_client_connection_rate_limit</a> (0)</b> 940 The maximal number of connection attempts any client is allowed 941 to make to this service per time unit. 942 943 <b><a href="postconf.5.html#smtpd_client_message_rate_limit">smtpd_client_message_rate_limit</a> (0)</b> 944 The maximal number of message delivery requests that any client 945 is allowed to make to this service per time unit, regardless of 946 whether or not Postfix actually accepts those messages. 947 948 <b><a href="postconf.5.html#smtpd_client_recipient_rate_limit">smtpd_client_recipient_rate_limit</a> (0)</b> 949 The maximal number of recipient addresses that any client is 950 allowed to send to this service per time unit, regardless of 951 whether or not Postfix actually accepts those recipients. 952 953 <b><a href="postconf.5.html#smtpd_client_event_limit_exceptions">smtpd_client_event_limit_exceptions</a> ($<a href="postconf.5.html#mynetworks">mynetworks</a>)</b> 954 Clients that are excluded from smtpd_client_*_count/rate_limit 955 restrictions. 956 957 Available in Postfix version 2.3 and later: 958 959 <b><a href="postconf.5.html#smtpd_client_new_tls_session_rate_limit">smtpd_client_new_tls_session_rate_limit</a> (0)</b> 960 The maximal number of new (i.e., uncached) TLS sessions that a 961 remote SMTP client is allowed to negotiate with this service per 962 time unit. 963 964 Available in Postfix version 2.9 - 3.6: 965 966 <b><a href="postconf.5.html#smtpd_per_record_deadline">smtpd_per_record_deadline</a> (normal: no, <a href="STRESS_README.html">overload</a>: yes)</b> 967 Change the behavior of the <a href="postconf.5.html#smtpd_timeout">smtpd_timeout</a> and <a href="postconf.5.html#smtpd_starttls_timeout">smtpd_start</a>- 968 <a href="postconf.5.html#smtpd_starttls_timeout">tls_timeout</a> time limits, from a time limit per read or write 969 system call, to a time limit to send or receive a complete 970 record (an SMTP command line, SMTP response line, SMTP message 971 content line, or TLS protocol message). 972 973 Available in Postfix version 3.1 and later: 974 975 <b><a href="postconf.5.html#smtpd_client_auth_rate_limit">smtpd_client_auth_rate_limit</a> (0)</b> 976 The maximal number of AUTH commands that any client is allowed 977 to send to this service per time unit, regardless of whether or 978 not Postfix actually accepts those commands. 979 980 Available in Postfix version 3.7 and later: 981 982 <b><a href="postconf.5.html#smtpd_per_request_deadline">smtpd_per_request_deadline</a> (normal: no, <a href="STRESS_README.html">overload</a>: yes)</b> 983 Change the behavior of the <a href="postconf.5.html#smtpd_timeout">smtpd_timeout</a> and <a href="postconf.5.html#smtpd_starttls_timeout">smtpd_start</a>- 984 <a href="postconf.5.html#smtpd_starttls_timeout">tls_timeout</a> time limits, from a time limit per plaintext or TLS 985 read or write call, to a combined time limit for receiving a 986 complete SMTP request and for sending a complete SMTP response. 987 988 <b><a href="postconf.5.html#smtpd_min_data_rate">smtpd_min_data_rate</a> (500)</b> 989 The minimum plaintext data transfer rate in bytes/second for 990 DATA and BDAT requests, when deadlines are enabled with 991 <a href="postconf.5.html#smtpd_per_request_deadline">smtpd_per_request_deadline</a>. 992 993 <b><a href="postconf.5.html#header_from_format">header_from_format</a> (standard)</b> 994 The format of the Postfix-generated <b>From:</b> header. 995 996 Available in Postfix version 3.8 and later: 997 998 <b><a href="postconf.5.html#smtpd_client_ipv4_prefix_length">smtpd_client_ipv4_prefix_length</a> (32)</b> 999 Aggregate smtpd_client_*_count and smtpd_client_*_rate statis- 1000 tics by IPv4 network blocks with the specified network prefix. 1001 1002 <b><a href="postconf.5.html#smtpd_client_ipv6_prefix_length">smtpd_client_ipv6_prefix_length</a> (84)</b> 1003 Aggregate smtpd_client_*_count and smtpd_client_*_rate statis- 1004 tics by IPv6 network blocks with the specified network prefix. 1005 1006 Available in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later: 1007 1008 <b><a href="postconf.5.html#smtpd_forbid_unauth_pipelining">smtpd_forbid_unauth_pipelining</a> (Postfix</b> ><b>= 3.9: yes)</b> 1009 Disconnect remote SMTP clients that violate <a href="https://tools.ietf.org/html/rfc2920">RFC 2920</a> (or 5321) 1010 command pipelining constraints. 1011 1012 Available in Postfix 3.9, 3.8.4, 3.7.9, 3.6.13, 3.5.23 and later: 1013 1014 <b><a href="postconf.5.html#smtpd_forbid_bare_newline">smtpd_forbid_bare_newline</a> (Postfix</b> ><b>= 3.9: normalize)</b> 1015 Reject or restrict input lines from an SMTP client that end in 1016 <LF> instead of the standard <CR><LF>. 1017 1018 <b><a href="postconf.5.html#smtpd_forbid_bare_newline_exclusions">smtpd_forbid_bare_newline_exclusions</a> ($<a href="postconf.5.html#mynetworks">mynetworks</a>)</b> 1019 Exclude the specified clients from <a href="postconf.5.html#smtpd_forbid_bare_newline">smtpd_forbid_bare_newline</a> 1020 enforcement. 1021 1022 Available in Postfix 3.9, 3.8.5, 3.7.10, 3.6.14, 3.5.24 and later: 1023 1024 <b><a href="postconf.5.html#smtpd_forbid_bare_newline_reject_code">smtpd_forbid_bare_newline_reject_code</a> (550)</b> 1025 The numerical Postfix SMTP server response code when rejecting a 1026 request with "<a href="postconf.5.html#smtpd_forbid_bare_newline">smtpd_forbid_bare_newline</a> = reject". 1027 1028 <b><a name="tarpit_controls">TARPIT CONTROLS</a></b> 1029 When a remote SMTP client makes errors, the Postfix SMTP server can 1030 insert delays before responding. This can help to slow down run-away 1031 software. The behavior is controlled by an error counter that counts 1032 the number of errors within an SMTP session that a client makes without 1033 delivering mail. 1034 1035 <b><a href="postconf.5.html#smtpd_error_sleep_time">smtpd_error_sleep_time</a> (1s)</b> 1036 With Postfix version 2.1 and later: the SMTP server response 1037 delay after a client has made more than $<a href="postconf.5.html#smtpd_soft_error_limit">smtpd_soft_error_limit</a> 1038 errors, and fewer than $<a href="postconf.5.html#smtpd_hard_error_limit">smtpd_hard_error_limit</a> errors, without 1039 delivering mail. 1040 1041 <b><a href="postconf.5.html#smtpd_soft_error_limit">smtpd_soft_error_limit</a> (10)</b> 1042 The number of errors a remote SMTP client is allowed to make 1043 without delivering mail before the Postfix SMTP server slows 1044 down all its responses. 1045 1046 <b><a href="postconf.5.html#smtpd_hard_error_limit">smtpd_hard_error_limit</a> (normal: 20, <a href="STRESS_README.html">overload</a>: 1)</b> 1047 The maximal number of errors a remote SMTP client is allowed to 1048 make without delivering mail. 1049 1050 <b><a href="postconf.5.html#smtpd_junk_command_limit">smtpd_junk_command_limit</a> (normal: 100, <a href="STRESS_README.html">overload</a>: 1)</b> 1051 The number of junk commands (NOOP, VRFY, ETRN or RSET) that a 1052 remote SMTP client can send before the Postfix SMTP server 1053 starts to increment the error counter with each junk command. 1054 1055 Available in Postfix version 2.1 and later: 1056 1057 <b><a href="postconf.5.html#smtpd_recipient_overshoot_limit">smtpd_recipient_overshoot_limit</a> (1000)</b> 1058 The number of recipients that a remote SMTP client can send in 1059 excess of the limit specified with $<a href="postconf.5.html#smtpd_recipient_limit">smtpd_recipient_limit</a>, 1060 before the Postfix SMTP server increments the per-session error 1061 count for each excess recipient. 1062 1063 <b><a name="access_policy_delegation_controls">ACCESS POLICY DELEGATION CONTROLS</a></b> 1064 As of version 2.1, Postfix can be configured to delegate access policy 1065 decisions to an external server that runs outside Postfix. See the 1066 file <a href="SMTPD_POLICY_README.html">SMTPD_POLICY_README</a> for more information. 1067 1068 <b><a href="postconf.5.html#smtpd_policy_service_max_idle">smtpd_policy_service_max_idle</a> (300s)</b> 1069 The time after which an idle SMTPD policy service connection is 1070 closed. 1071 1072 <b><a href="postconf.5.html#smtpd_policy_service_max_ttl">smtpd_policy_service_max_ttl</a> (1000s)</b> 1073 The time after which an active SMTPD policy service connection 1074 is closed. 1075 1076 <b><a href="postconf.5.html#smtpd_policy_service_timeout">smtpd_policy_service_timeout</a> (100s)</b> 1077 The time limit for connecting to, writing to, or receiving from 1078 a delegated SMTPD policy server. 1079 1080 Available in Postfix version 3.0 and later: 1081 1082 <b><a href="postconf.5.html#smtpd_policy_service_default_action">smtpd_policy_service_default_action</a> (451 4.3.5 Server configuration</b> 1083 <b>problem)</b> 1084 The default action when an SMTPD policy service request fails. 1085 1086 <b><a href="postconf.5.html#smtpd_policy_service_request_limit">smtpd_policy_service_request_limit</a> (0)</b> 1087 The maximal number of requests per SMTPD policy service connec- 1088 tion, or zero (no limit). 1089 1090 <b><a href="postconf.5.html#smtpd_policy_service_try_limit">smtpd_policy_service_try_limit</a> (2)</b> 1091 The maximal number of attempts to send an SMTPD policy service 1092 request before giving up. 1093 1094 <b><a href="postconf.5.html#smtpd_policy_service_retry_delay">smtpd_policy_service_retry_delay</a> (1s)</b> 1095 The delay between attempts to resend a failed SMTPD policy ser- 1096 vice request. 1097 1098 Available in Postfix version 3.1 and later: 1099 1100 <b><a href="postconf.5.html#smtpd_policy_service_policy_context">smtpd_policy_service_policy_context</a> (empty)</b> 1101 Optional information that the Postfix SMTP server specifies in 1102 the "policy_context" attribute of a policy service request 1103 (originally, to share the same service endpoint among multiple 1104 <a href="postconf.5.html#check_policy_service">check_policy_service</a> clients). 1105 1106 <b><a name="access_controls">ACCESS CONTROLS</a></b> 1107 The <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a> document gives an introduction to all the SMTP 1108 server access control features. 1109 1110 <b><a href="postconf.5.html#smtpd_delay_reject">smtpd_delay_reject</a> (yes)</b> 1111 Wait until the RCPT TO command before evaluating 1112 $<a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a>, $<a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a> and 1113 $<a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a>, or wait until the ETRN command 1114 before evaluating $<a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> and 1115 $<a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a>. 1116 1117 <b><a href="postconf.5.html#parent_domain_matches_subdomains">parent_domain_matches_subdomains</a> (see 'postconf -d' output)</b> 1118 A list of Postfix features where the pattern "example.com" also 1119 matches subdomains of example.com, instead of requiring an 1120 explicit ".example.com" pattern. 1121 1122 <b><a href="postconf.5.html#smtpd_client_restrictions">smtpd_client_restrictions</a> (empty)</b> 1123 Optional restrictions that the Postfix SMTP server applies in 1124 the context of a client connection request. 1125 1126 <b><a href="postconf.5.html#smtpd_helo_required">smtpd_helo_required</a> (no)</b> 1127 Require that a remote SMTP client introduces itself with the 1128 HELO or EHLO command before sending the MAIL command or other 1129 commands that require EHLO negotiation. 1130 1131 <b><a href="postconf.5.html#smtpd_helo_restrictions">smtpd_helo_restrictions</a> (empty)</b> 1132 Optional restrictions that the Postfix SMTP server applies in 1133 the context of a client HELO command. 1134 1135 <b><a href="postconf.5.html#smtpd_sender_restrictions">smtpd_sender_restrictions</a> (empty)</b> 1136 Optional restrictions that the Postfix SMTP server applies in 1137 the context of a client MAIL FROM command. 1138 1139 <b><a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a> (see 'postconf -d' output)</b> 1140 Optional restrictions that the Postfix SMTP server applies in 1141 the context of a client RCPT TO command, after 1142 <a href="postconf.5.html#smtpd_relay_restrictions">smtpd_relay_restrictions</a>. 1143 1144 <b><a href="postconf.5.html#smtpd_etrn_restrictions">smtpd_etrn_restrictions</a> (empty)</b> 1145 Optional restrictions that the Postfix SMTP server applies in 1146 the context of a client ETRN command. 1147 1148 <b><a href="postconf.5.html#allow_untrusted_routing">allow_untrusted_routing</a> (no)</b> 1149 Forward mail with sender-specified routing 1150 (user[@%!]remote[@%!]site) from untrusted clients to destina- 1151 tions matching $<a href="postconf.5.html#relay_domains">relay_domains</a>. 1152 1153 <b><a href="postconf.5.html#smtpd_restriction_classes">smtpd_restriction_classes</a> (empty)</b> 1154 User-defined aliases for groups of access restrictions. 1155 1156 <b><a href="postconf.5.html#smtpd_null_access_lookup_key">smtpd_null_access_lookup_key</a> (</b><><b>)</b> 1157 The lookup key to be used in SMTP <a href="access.5.html"><b>access</b>(5)</a> tables instead of 1158 the null sender address. 1159 1160 <b><a href="postconf.5.html#permit_mx_backup_networks">permit_mx_backup_networks</a> (empty)</b> 1161 Restrict the use of the <a href="postconf.5.html#permit_mx_backup">permit_mx_backup</a> SMTP access feature to 1162 only domains whose primary MX hosts match the listed networks. 1163 1164 Available in Postfix version 2.0 and later: 1165 1166 <b><a href="postconf.5.html#smtpd_data_restrictions">smtpd_data_restrictions</a> (empty)</b> 1167 Optional access restrictions that the Postfix SMTP server 1168 applies in the context of the SMTP DATA command. 1169 1170 <b><a href="postconf.5.html#smtpd_expansion_filter">smtpd_expansion_filter</a> (see 'postconf -d' output)</b> 1171 What characters are allowed in $name expansions of RBL reply 1172 templates. 1173 1174 Available in Postfix version 2.1 and later: 1175 1176 <b><a href="postconf.5.html#smtpd_reject_unlisted_sender">smtpd_reject_unlisted_sender</a> (no)</b> 1177 Request that the Postfix SMTP server rejects mail from unknown 1178 sender addresses, even when no explicit <a href="postconf.5.html#reject_unlisted_sender">reject_unlisted_sender</a> 1179 access restriction is specified. 1180 1181 <b><a href="postconf.5.html#smtpd_reject_unlisted_recipient">smtpd_reject_unlisted_recipient</a> (yes)</b> 1182 Request that the Postfix SMTP server rejects mail for unknown 1183 recipient addresses, even when no explicit 1184 <a href="postconf.5.html#reject_unlisted_recipient">reject_unlisted_recipient</a> access restriction is specified. 1185 1186 Available in Postfix version 2.2 and later: 1187 1188 <b><a href="postconf.5.html#smtpd_end_of_data_restrictions">smtpd_end_of_data_restrictions</a> (empty)</b> 1189 Optional access restrictions that the Postfix SMTP server 1190 applies in the context of the SMTP END-OF-DATA command. 1191 1192 Available in Postfix version 2.10 and later: 1193 1194 <b><a href="postconf.5.html#smtpd_relay_restrictions">smtpd_relay_restrictions</a> (<a href="postconf.5.html#permit_mynetworks">permit_mynetworks</a>, <a href="postconf.5.html#permit_sasl_authenticated">permit_sasl_authenticated</a>,</b> 1195 <b><a href="postconf.5.html#defer_unauth_destination">defer_unauth_destination</a>)</b> 1196 Access restrictions for mail relay control that the Postfix SMTP 1197 server applies in the context of the RCPT TO command, before 1198 <a href="postconf.5.html#smtpd_recipient_restrictions">smtpd_recipient_restrictions</a>. 1199 1200 <b><a name="sender_and_recipient_address_verification_controls">SENDER AND RECIPIENT ADDRESS VERIFICATION CONTROLS</a></b> 1201 Postfix version 2.1 introduces sender and recipient address verifica- 1202 tion. This feature is implemented by sending probe email messages that 1203 are not actually delivered. This feature is requested via the 1204 <a href="postconf.5.html#reject_unverified_sender">reject_unverified_sender</a> and <a href="postconf.5.html#reject_unverified_recipient">reject_unverified_recipient</a> access 1205 restrictions. The status of verification probes is maintained by the 1206 <a href="verify.8.html"><b>verify</b>(8)</a> server. See the file <a href="ADDRESS_VERIFICATION_README.html">ADDRESS_VERIFICATION_README</a> for infor- 1207 mation about how to configure and operate the Postfix sender/recipient 1208 address verification service. 1209 1210 <b><a href="postconf.5.html#address_verify_poll_count">address_verify_poll_count</a> (normal: 3, <a href="STRESS_README.html">overload</a>: 1)</b> 1211 How many times to query the <a href="verify.8.html"><b>verify</b>(8)</a> service for the completion 1212 of an address verification request in progress. 1213 1214 <b><a href="postconf.5.html#address_verify_poll_delay">address_verify_poll_delay</a> (3s)</b> 1215 The delay between queries for the completion of an address veri- 1216 fication request in progress. 1217 1218 <b><a href="postconf.5.html#address_verify_sender">address_verify_sender</a> ($<a href="postconf.5.html#double_bounce_sender">double_bounce_sender</a>)</b> 1219 The sender address to use in address verification probes; prior 1220 to Postfix 2.5 the default was "postmaster". 1221 1222 <b><a href="postconf.5.html#unverified_sender_reject_code">unverified_sender_reject_code</a> (450)</b> 1223 The numerical Postfix SMTP server response code when a recipient 1224 address is rejected by the <a href="postconf.5.html#reject_unverified_sender">reject_unverified_sender</a> restriction. 1225 1226 <b><a href="postconf.5.html#unverified_recipient_reject_code">unverified_recipient_reject_code</a> (450)</b> 1227 The numerical Postfix SMTP server response when a recipient 1228 address is rejected by the <a href="postconf.5.html#reject_unverified_recipient">reject_unverified_recipient</a> restric- 1229 tion. 1230 1231 Available in Postfix version 2.6 and later: 1232 1233 <b><a href="postconf.5.html#unverified_sender_defer_code">unverified_sender_defer_code</a> (450)</b> 1234 The numerical Postfix SMTP server response code when a sender 1235 address probe fails due to a temporary error condition. 1236 1237 <b><a href="postconf.5.html#unverified_recipient_defer_code">unverified_recipient_defer_code</a> (450)</b> 1238 The numerical Postfix SMTP server response when a recipient 1239 address probe fails due to a temporary error condition. 1240 1241 <b><a href="postconf.5.html#unverified_sender_reject_reason">unverified_sender_reject_reason</a> (empty)</b> 1242 The Postfix SMTP server's reply when rejecting mail with 1243 <a href="postconf.5.html#reject_unverified_sender">reject_unverified_sender</a>. 1244 1245 <b><a href="postconf.5.html#unverified_recipient_reject_reason">unverified_recipient_reject_reason</a> (empty)</b> 1246 The Postfix SMTP server's reply when rejecting mail with 1247 <a href="postconf.5.html#reject_unverified_recipient">reject_unverified_recipient</a>. 1248 1249 <b><a href="postconf.5.html#unverified_sender_tempfail_action">unverified_sender_tempfail_action</a> ($<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b> 1250 The Postfix SMTP server's action when <a href="postconf.5.html#reject_unverified_sender">reject_unverified_sender</a> 1251 fails due to a temporary error condition. 1252 1253 <b><a href="postconf.5.html#unverified_recipient_tempfail_action">unverified_recipient_tempfail_action</a> ($<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b> 1254 The Postfix SMTP server's action when <a href="postconf.5.html#reject_unverified_recipient">reject_unverified_recipi</a>- 1255 <a href="postconf.5.html#reject_unverified_recipient">ent</a> fails due to a temporary error condition. 1256 1257 Available with Postfix 2.9 and later: 1258 1259 <b><a href="postconf.5.html#address_verify_sender_ttl">address_verify_sender_ttl</a> (0s)</b> 1260 The time between changes in the time-dependent portion of 1261 address verification probe sender addresses. 1262 1263 <b><a name="access_control_responses">ACCESS CONTROL RESPONSES</a></b> 1264 The following parameters control numerical SMTP reply codes and/or text 1265 responses. 1266 1267 <b><a href="postconf.5.html#access_map_reject_code">access_map_reject_code</a> (554)</b> 1268 The numerical Postfix SMTP server response code for an <a href="access.5.html"><b>access</b>(5)</a> 1269 map "reject" action. 1270 1271 <b><a href="postconf.5.html#defer_code">defer_code</a> (450)</b> 1272 The numerical Postfix SMTP server response code when a remote 1273 SMTP client request is rejected by the "defer" restriction. 1274 1275 <b><a href="postconf.5.html#invalid_hostname_reject_code">invalid_hostname_reject_code</a> (501)</b> 1276 The numerical Postfix SMTP server response code when the client 1277 HELO or EHLO command parameter is rejected by the 1278 <a href="postconf.5.html#reject_invalid_helo_hostname">reject_invalid_helo_hostname</a> restriction. 1279 1280 <b><a href="postconf.5.html#maps_rbl_reject_code">maps_rbl_reject_code</a> (554)</b> 1281 The numerical Postfix SMTP server response code when a remote 1282 SMTP client request is blocked by the <a href="postconf.5.html#reject_rbl_client">reject_rbl_client</a>, 1283 <a href="postconf.5.html#reject_rhsbl_client">reject_rhsbl_client</a>, <a href="postconf.5.html#reject_rhsbl_reverse_client">reject_rhsbl_reverse_client</a>, 1284 <a href="postconf.5.html#reject_rhsbl_sender">reject_rhsbl_sender</a> or <a href="postconf.5.html#reject_rhsbl_recipient">reject_rhsbl_recipient</a> restriction. 1285 1286 <b><a href="postconf.5.html#non_fqdn_reject_code">non_fqdn_reject_code</a> (504)</b> 1287 The numerical Postfix SMTP server reply code when a client 1288 request is rejected by the <a href="postconf.5.html#reject_non_fqdn_helo_hostname">reject_non_fqdn_helo_hostname</a>, 1289 <a href="postconf.5.html#reject_non_fqdn_sender">reject_non_fqdn_sender</a> or <a href="postconf.5.html#reject_non_fqdn_recipient">reject_non_fqdn_recipient</a> restriction. 1290 1291 <b><a href="postconf.5.html#plaintext_reject_code">plaintext_reject_code</a> (450)</b> 1292 The numerical Postfix SMTP server response code when a request 1293 is rejected by the <b><a href="postconf.5.html#reject_plaintext_session">reject_plaintext_session</a></b> restriction. 1294 1295 <b><a href="postconf.5.html#reject_code">reject_code</a> (554)</b> 1296 The numerical Postfix SMTP server response code when a remote 1297 SMTP client request is rejected by the "reject" restriction. 1298 1299 <b><a href="postconf.5.html#relay_domains_reject_code">relay_domains_reject_code</a> (554)</b> 1300 The numerical Postfix SMTP server response code when a client 1301 request is rejected by the <a href="postconf.5.html#reject_unauth_destination">reject_unauth_destination</a> recipient 1302 restriction. 1303 1304 <b><a href="postconf.5.html#unknown_address_reject_code">unknown_address_reject_code</a> (450)</b> 1305 The numerical response code when the Postfix SMTP server rejects 1306 a sender or recipient address because its domain is unknown. 1307 1308 <b><a href="postconf.5.html#unknown_client_reject_code">unknown_client_reject_code</a> (450)</b> 1309 The numerical Postfix SMTP server response code when a client 1310 without valid address <=> name mapping is rejected by the 1311 <a href="postconf.5.html#reject_unknown_client_hostname">reject_unknown_client_hostname</a> restriction. 1312 1313 <b><a href="postconf.5.html#unknown_hostname_reject_code">unknown_hostname_reject_code</a> (450)</b> 1314 The numerical Postfix SMTP server response code when the host- 1315 name specified with the HELO or EHLO command is rejected by the 1316 <a href="postconf.5.html#reject_unknown_helo_hostname">reject_unknown_helo_hostname</a> restriction. 1317 1318 Available in Postfix version 2.0 and later: 1319 1320 <b><a href="postconf.5.html#default_rbl_reply">default_rbl_reply</a> (see 'postconf -d' output)</b> 1321 The default Postfix SMTP server response template for a request 1322 that is rejected by an RBL-based restriction. 1323 1324 <b><a href="postconf.5.html#multi_recipient_bounce_reject_code">multi_recipient_bounce_reject_code</a> (550)</b> 1325 The numerical Postfix SMTP server response code when a remote 1326 SMTP client request is blocked by the <a href="postconf.5.html#reject_multi_recipient_bounce">reject_multi_recipi</a>- 1327 <a href="postconf.5.html#reject_multi_recipient_bounce">ent_bounce</a> restriction. 1328 1329 <b><a href="postconf.5.html#rbl_reply_maps">rbl_reply_maps</a> (empty)</b> 1330 Optional lookup tables with RBL or RHSBL response templates. 1331 1332 Available in Postfix version 2.6 and later: 1333 1334 <b><a href="postconf.5.html#access_map_defer_code">access_map_defer_code</a> (450)</b> 1335 The numerical Postfix SMTP server response code for an <a href="access.5.html"><b>access</b>(5)</a> 1336 map "defer" action, including "<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>" or 1337 "<a href="postconf.5.html#defer_if_reject">defer_if_reject</a>". 1338 1339 <b><a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a> (<a href="postconf.5.html#defer_if_permit">defer_if_permit</a>)</b> 1340 The Postfix SMTP server's action when a reject-type restriction 1341 fails due to a temporary error condition. 1342 1343 <b><a href="postconf.5.html#unknown_helo_hostname_tempfail_action">unknown_helo_hostname_tempfail_action</a> ($<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b> 1344 The Postfix SMTP server's action when <a href="postconf.5.html#reject_unknown_helo_hostname">reject_unknown_helo_host</a>- 1345 <a href="postconf.5.html#reject_unknown_helo_hostname">name</a> fails due to a temporary error condition. 1346 1347 <b><a href="postconf.5.html#unknown_address_tempfail_action">unknown_address_tempfail_action</a> ($<a href="postconf.5.html#reject_tempfail_action">reject_tempfail_action</a>)</b> 1348 The Postfix SMTP server's action when 1349 <a href="postconf.5.html#reject_unknown_sender_domain">reject_unknown_sender_domain</a> or <a href="postconf.5.html#reject_unknown_recipient_domain">reject_unknown_recipient_domain</a> 1350 fail due to a temporary error condition. 1351 1352 <b><a name="miscellaneous_controls">MISCELLANEOUS CONTROLS</a></b> 1353 <b><a href="postconf.5.html#config_directory">config_directory</a> (see 'postconf -d' output)</b> 1354 The default location of the Postfix <a href="postconf.5.html">main.cf</a> and <a href="master.5.html">master.cf</a> con- 1355 figuration files. 1356 1357 <b><a href="postconf.5.html#daemon_timeout">daemon_timeout</a> (18000s)</b> 1358 How much time a Postfix daemon process may take to handle a 1359 request before it is terminated by a built-in watchdog timer. 1360 1361 <b><a href="postconf.5.html#command_directory">command_directory</a> (see 'postconf -d' output)</b> 1362 The location of all postfix administrative commands. 1363 1364 <b><a href="postconf.5.html#double_bounce_sender">double_bounce_sender</a> (double-bounce)</b> 1365 The sender address of postmaster notifications that are gener- 1366 ated by the mail system. 1367 1368 <b><a href="postconf.5.html#ipc_timeout">ipc_timeout</a> (3600s)</b> 1369 The time limit for sending or receiving information over an 1370 internal communication channel. 1371 1372 <b><a href="postconf.5.html#mail_name">mail_name</a> (Postfix)</b> 1373 The mail system name that is displayed in Received: headers, in 1374 the SMTP greeting banner, and in bounced mail. 1375 1376 <b><a href="postconf.5.html#mail_owner">mail_owner</a> (postfix)</b> 1377 The UNIX system account that owns the Postfix queue and most 1378 Postfix daemon processes. 1379 1380 <b><a href="postconf.5.html#max_idle">max_idle</a> (100s)</b> 1381 The maximum amount of time that an idle Postfix daemon process 1382 waits for an incoming connection before terminating voluntarily. 1383 1384 <b><a href="postconf.5.html#max_use">max_use</a> (100)</b> 1385 The maximal number of incoming connections that a Postfix daemon 1386 process will service before terminating voluntarily. 1387 1388 <b><a href="postconf.5.html#myhostname">myhostname</a> (see 'postconf -d' output)</b> 1389 The internet hostname of this mail system. 1390 1391 <b><a href="postconf.5.html#mynetworks">mynetworks</a> (see 'postconf -d' output)</b> 1392 The list of "trusted" remote SMTP clients that have more privi- 1393 leges than "strangers". 1394 1395 <b><a href="postconf.5.html#myorigin">myorigin</a> ($<a href="postconf.5.html#myhostname">myhostname</a>)</b> 1396 The domain name that locally-posted mail appears to come from, 1397 and that locally posted mail is delivered to. 1398 1399 <b><a href="postconf.5.html#process_id">process_id</a> (read-only)</b> 1400 The process ID of a Postfix command or daemon process. 1401 1402 <b><a href="postconf.5.html#process_name">process_name</a> (read-only)</b> 1403 The process name of a Postfix command or daemon process. 1404 1405 <b><a href="postconf.5.html#queue_directory">queue_directory</a> (see 'postconf -d' output)</b> 1406 The location of the Postfix top-level queue directory. 1407 1408 <b><a href="postconf.5.html#recipient_delimiter">recipient_delimiter</a> (empty)</b> 1409 The set of characters that can separate an email address local- 1410 part, user name, or a .forward file name from its extension. 1411 1412 <b><a href="postconf.5.html#smtpd_banner">smtpd_banner</a> ($<a href="postconf.5.html#myhostname">myhostname</a> ESMTP $<a href="postconf.5.html#mail_name">mail_name</a>)</b> 1413 The text that follows the 220 status code in the SMTP greeting 1414 banner. 1415 1416 <b><a href="postconf.5.html#syslog_facility">syslog_facility</a> (mail)</b> 1417 The syslog facility of Postfix logging. 1418 1419 <b><a href="postconf.5.html#syslog_name">syslog_name</a> (see 'postconf -d' output)</b> 1420 A prefix that is prepended to the process name in syslog 1421 records, so that, for example, "smtpd" becomes "prefix/smtpd". 1422 1423 Available in Postfix version 2.2 and later: 1424 1425 <b><a href="postconf.5.html#smtpd_forbidden_commands">smtpd_forbidden_commands</a> (CONNECT GET POST <a href="regexp_table.5.html">regexp</a>:{{/^[^A-Z]/ Bogus}})</b> 1426 List of commands that cause the Postfix SMTP server to immedi- 1427 ately terminate the session with a 221 code. 1428 1429 Available in Postfix version 2.5 and later: 1430 1431 <b><a href="postconf.5.html#smtpd_client_port_logging">smtpd_client_port_logging</a> (no)</b> 1432 Enable logging of the remote SMTP client port in addition to the 1433 hostname and IP address. 1434 1435 Available in Postfix 3.3 and later: 1436 1437 <b><a href="postconf.5.html#service_name">service_name</a> (read-only)</b> 1438 The <a href="master.5.html">master.cf</a> service name of a Postfix daemon process. 1439 1440 Available in Postfix 3.4 and later: 1441 1442 <b><a href="postconf.5.html#smtpd_reject_footer_maps">smtpd_reject_footer_maps</a> (empty)</b> 1443 Lookup tables, indexed by the complete Postfix SMTP server 4xx 1444 or 5xx response, with reject footer templates. 1445 1446 Available in Postfix 3.10 and later: 1447 1448 <b><a href="postconf.5.html#smtpd_hide_client_session">smtpd_hide_client_session</a> (no)</b> 1449 Do not include SMTP client session information in the Postfix 1450 SMTP server's Received: message header. 1451 1452 Available in Postfix version 3.11 and later: 1453 1454 <b><a href="postconf.5.html#smtpd_reject_filter_maps">smtpd_reject_filter_maps</a> (empty)</b> 1455 An optional filter that can replace a reject response from the 1456 Postfix SMTP server itself, or from a program that replies 1457 through the Postfix SMTP server. 1458 1459 <b><a name="see_also">SEE ALSO</a></b> 1460 <a href="anvil.8.html">anvil(8)</a>, connection/rate limiting 1461 <a href="cleanup.8.html">cleanup(8)</a>, message canonicalization 1462 <a href="tlsmgr.8.html">tlsmgr(8)</a>, TLS session and PRNG management 1463 <a href="trivial-rewrite.8.html">trivial-rewrite(8)</a>, address resolver 1464 <a href="verify.8.html">verify(8)</a>, address verification service 1465 <a href="postconf.5.html">postconf(5)</a>, configuration parameters 1466 <a href="master.5.html">master(5)</a>, generic daemon options 1467 <a href="master.8.html">master(8)</a>, process manager 1468 <a href="postlogd.8.html">postlogd(8)</a>, Postfix logging 1469 syslogd(8), system logging 1470 1471 <b><a name="readme_files">README FILES</a></b> 1472 <a href="ADDRESS_CLASS_README.html">ADDRESS_CLASS_README</a>, blocking unknown hosted or relay recipients 1473 <a href="ADDRESS_REWRITING_README.html">ADDRESS_REWRITING_README</a>, Postfix address manipulation 1474 <a href="BDAT_README.html">BDAT_README</a>, Postfix CHUNKING support 1475 <a href="FILTER_README.html">FILTER_README</a>, external after-queue content filter 1476 <a href="LOCAL_RECIPIENT_README.html">LOCAL_RECIPIENT_README</a>, blocking unknown local recipients 1477 <a href="MILTER_README.html">MILTER_README</a>, before-queue mail filter applications 1478 <a href="SMTPD_ACCESS_README.html">SMTPD_ACCESS_README</a>, built-in access policies 1479 <a href="SMTPD_POLICY_README.html">SMTPD_POLICY_README</a>, external policy server 1480 <a href="SMTPD_PROXY_README.html">SMTPD_PROXY_README</a>, external before-queue content filter 1481 <a href="SASL_README.html">SASL_README</a>, Postfix SASL howto 1482 <a href="TLS_README.html">TLS_README</a>, Postfix STARTTLS howto 1483 <a href="VERP_README.html">VERP_README</a>, Postfix XVERP extension 1484 <a href="XCLIENT_README.html">XCLIENT_README</a>, Postfix XCLIENT extension 1485 <a href="XFORWARD_README.html">XFORWARD_README</a>, Postfix XFORWARD extension 1486 1487 <b><a name="license">LICENSE</a></b> 1488 The Secure Mailer license must be distributed with this software. 1489 1490 <b>AUTHOR(S)</b> 1491 Wietse Venema 1492 IBM T.J. Watson Research 1493 P.O. Box 704 1494 Yorktown Heights, NY 10598, USA 1495 1496 Wietse Venema 1497 Google, Inc. 1498 111 8th Avenue 1499 New York, NY 10011, USA 1500 1501 Wietse Venema 1502 porcupine.org 1503 1504 SASL support originally by: 1505 Till Franke 1506 SuSE Rhein/Main AG 1507 65760 Eschborn, Germany 1508 1509 TLS support originally by: 1510 Lutz Jaenicke 1511 BTU Cottbus 1512 Allgemeine Elektrotechnik 1513 Universitaetsplatz 3-4 1514 D-03044 Cottbus, Germany 1515 1516 Revised TLS support by: 1517 Victor Duchovni 1518 Morgan Stanley 1519 1520 SMTPD(8) 1521 </pre> </body> </html> 1522