CONTENT_INSPECTION_README.html revision 1.1.1.3 1 1.1 tron <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"
2 1.1 tron "http://www.w3.org/TR/html4/loose.dtd">
3 1.1 tron
4 1.1 tron <html>
5 1.1 tron
6 1.1 tron <head>
7 1.1 tron
8 1.1 tron <title>Postfix Content Inspection </title>
9 1.1 tron
10 1.1.1.2 christos <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
11 1.1.1.3 christos <link rel='stylesheet' type='text/css' href='postfix-doc.css'>
12 1.1 tron
13 1.1 tron </head>
14 1.1 tron
15 1.1 tron <body>
16 1.1 tron
17 1.1 tron <h1><img src="postfix-logo.jpg" width="203" height="98" ALT="">Postfix
18 1.1 tron Content Inspection </h1>
19 1.1 tron
20 1.1 tron <hr>
21 1.1 tron
22 1.1 tron <p> Postfix supports three content inspection methods, ranging from
23 1.1 tron light-weight one-line-at-a-time scanning before mail is queued, to
24 1.1 tron heavy duty machinery that does sophisticated content analysis after
25 1.1 tron mail is queued. Each approach serves a different purpose. </p>
26 1.1 tron
27 1.1 tron <dl>
28 1.1 tron
29 1.1 tron <dt> <b> before queue, built-in, light-weight</b> </dt>
30 1.1 tron
31 1.1 tron <dd> <p> This method inspects mail BEFORE it is stored in the queue,
32 1.1 tron and uses Postfix's built-in message header and message body
33 1.1 tron inspection. Although the main purpose is to stop a specific flood
34 1.1 tron of mail from worms or viruses, it is also useful to block a flood
35 1.1 tron of bounced junk email and email notifications from virus detection
36 1.1 tron systems. The built-in regular expressions are not meant to implement
37 1.1 tron general SPAM and virus detection. For that, you should use one of
38 1.1 tron the content inspection methods described below. Details are described
39 1.1 tron in the BUILTIN_FILTER_README and BACKSCATTER_README documents.
40 1.1 tron </p>
41 1.1 tron
42 1.1 tron <dt> <b> after queue, external, heavy-weight</b> </dt>
43 1.1 tron
44 1.1 tron <dd> <p> This method inspects mail AFTER it is stored in the queue,
45 1.1 tron and uses standard protocols such as SMTP or "pipe to command and
46 1.1 tron wait for exit status". After-queue inspection allows you to use
47 1.1 tron content filters of arbitrary complexity without causing timeouts
48 1.1 tron while receiving mail, and without running out of memory resources
49 1.1 tron under a peak load. Details of this approach are in the FILTER_README
50 1.1 tron document. </p>
51 1.1 tron
52 1.1 tron <dt> <b> before queue, external, medium-weight</b> </dt>
53 1.1 tron
54 1.1 tron <dd> <p> The following two methods inspect mail BEFORE it is stored in the
55 1.1 tron queue. </p>
56 1.1 tron
57 1.1 tron <ul>
58 1.1 tron
59 1.1 tron <li> <p> The first method uses the SMTP protocol, and is described
60 1.1 tron in the SMTPD_PROXY_README document. This approach is available
61 1.1 tron with Postfix version 2.1 and later. </p>
62 1.1 tron
63 1.1 tron <li> <p> The second method uses the Sendmail 8 Milter protocol, and
64 1.1 tron is described in the MILTER_README document. This approach is
65 1.1 tron available with Postfix version 2.3 and later. </p>
66 1.1 tron
67 1.1 tron </ul>
68 1.1 tron
69 1.1 tron <p> Although these approaches appear to be attractive, they have
70 1.1 tron some serious limitations that you need to be aware of. First,
71 1.1 tron content inspection software must finish in a limited amount of time;
72 1.1 tron if content inspection needs too much time then incoming mail
73 1.1 tron deliveries will time out. Second, content inspection software must
74 1.1 tron run in a limited amount of memory; if content inspection needs too
75 1.1 tron much memory then software will crash under a peak load. Before-queue
76 1.1 tron inspection limits the peak load that your system can handle, and
77 1.1 tron limits the sophistication of the content filter that you can use.
78 1.1 tron </p>
79 1.1 tron
80 1.1 tron </dl>
81 1.1 tron
82 1.1 tron <p> The more sophisticated content filtering software is not built
83 1.1 tron into Postfix for good reasons: writing an MTA requires different
84 1.1 tron skills than writing a SPAM or virus killer. Postfix encourages the
85 1.1 tron use of external filters and standard protocols because this allows
86 1.1 tron you to choose the best MTA and the best content inspection software
87 1.1 tron for your purpose. Information about external content inspection
88 1.1 tron software can be found on the Postfix website at http://www.postfix.org/,
89 1.1 tron and on the postfix-users (a] postfix.org mailing list. </p>
90 1.1 tron
91 1.1 tron </body>
92 1.1 tron
93 1.1 tron </html>
94