Home | History | Annotate | Line # | Download | only in proto
CONTENT_INSPECTION_README.html revision 1.1
      1  1.1  tron <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"
      2  1.1  tron         "http://www.w3.org/TR/html4/loose.dtd">
      3  1.1  tron 
      4  1.1  tron <html>
      5  1.1  tron 
      6  1.1  tron <head>
      7  1.1  tron 
      8  1.1  tron <title>Postfix Content Inspection </title>
      9  1.1  tron 
     10  1.1  tron <meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
     11  1.1  tron 
     12  1.1  tron </head>
     13  1.1  tron 
     14  1.1  tron <body>
     15  1.1  tron 
     16  1.1  tron <h1><img src="postfix-logo.jpg" width="203" height="98" ALT="">Postfix
     17  1.1  tron Content Inspection </h1>
     18  1.1  tron 
     19  1.1  tron <hr>
     20  1.1  tron 
     21  1.1  tron <p> Postfix supports three content inspection methods, ranging from
     22  1.1  tron light-weight one-line-at-a-time scanning before mail is queued, to
     23  1.1  tron heavy duty machinery that does sophisticated content analysis after
     24  1.1  tron mail is queued. Each approach serves a different purpose.  </p>
     25  1.1  tron 
     26  1.1  tron <dl>
     27  1.1  tron 
     28  1.1  tron <dt> <b> before queue, built-in, light-weight</b> </dt>
     29  1.1  tron 
     30  1.1  tron <dd> <p> This method inspects mail BEFORE it is stored in the queue,
     31  1.1  tron and uses Postfix's built-in message header and message body
     32  1.1  tron inspection. Although the main purpose is to stop a specific flood
     33  1.1  tron of mail from worms or viruses, it is also useful to block a flood
     34  1.1  tron of bounced junk email and email notifications from virus detection
     35  1.1  tron systems.  The built-in regular expressions are not meant to implement
     36  1.1  tron general SPAM and virus detection. For that, you should use one of
     37  1.1  tron the content inspection methods described below. Details are described
     38  1.1  tron in the BUILTIN_FILTER_README and BACKSCATTER_README documents.
     39  1.1  tron </p>
     40  1.1  tron 
     41  1.1  tron <dt> <b> after queue, external, heavy-weight</b> </dt>
     42  1.1  tron 
     43  1.1  tron <dd> <p> This method inspects mail AFTER it is stored in the queue,
     44  1.1  tron and uses standard protocols such as SMTP or "pipe to command and
     45  1.1  tron wait for exit status".  After-queue inspection allows you to use
     46  1.1  tron content filters of arbitrary complexity without causing timeouts
     47  1.1  tron while receiving mail, and without running out of memory resources
     48  1.1  tron under a peak load. Details of this approach are in the FILTER_README
     49  1.1  tron document. </p>
     50  1.1  tron 
     51  1.1  tron <dt> <b> before queue, external, medium-weight</b> </dt>
     52  1.1  tron 
     53  1.1  tron <dd> <p> The following two methods inspect mail BEFORE it is stored in the
     54  1.1  tron queue.  </p>
     55  1.1  tron 
     56  1.1  tron <ul>
     57  1.1  tron 
     58  1.1  tron <li> <p> The first method uses the SMTP protocol, and is described
     59  1.1  tron in the SMTPD_PROXY_README document.  This approach is available
     60  1.1  tron with Postfix version 2.1 and later.  </p>
     61  1.1  tron 
     62  1.1  tron <li> <p> The second method uses the Sendmail 8 Milter protocol, and
     63  1.1  tron is described in the MILTER_README document.  This approach is
     64  1.1  tron available with Postfix version 2.3 and later.  </p>
     65  1.1  tron 
     66  1.1  tron </ul>
     67  1.1  tron 
     68  1.1  tron <p> Although these approaches appear to be attractive, they have
     69  1.1  tron some serious limitations that you need to be aware of.  First,
     70  1.1  tron content inspection software must finish in a limited amount of time;
     71  1.1  tron if content inspection needs too much time then incoming mail
     72  1.1  tron deliveries will time out.  Second, content inspection software must
     73  1.1  tron run in a limited amount of memory; if content inspection needs too
     74  1.1  tron much memory then software will crash under a peak load.  Before-queue
     75  1.1  tron inspection limits the peak load that your system can handle, and
     76  1.1  tron limits the sophistication of the content filter that you can use.
     77  1.1  tron </p>
     78  1.1  tron 
     79  1.1  tron </dl>
     80  1.1  tron 
     81  1.1  tron <p> The more sophisticated content filtering software is not built
     82  1.1  tron into Postfix for good reasons: writing an MTA requires different
     83  1.1  tron skills than writing a SPAM or virus killer. Postfix encourages the
     84  1.1  tron use of external filters and standard protocols because this allows
     85  1.1  tron you to choose the best MTA and the best content inspection software
     86  1.1  tron for your purpose.  Information about external content inspection
     87  1.1  tron software can be found on the Postfix website at http://www.postfix.org/,
     88  1.1  tron and on the postfix-users (a] postfix.org mailing list. </p>
     89  1.1  tron 
     90  1.1  tron </body>
     91  1.1  tron 
     92  1.1  tron </html>
     93