stop.double-proto-html revision 1.1.1.4 1 1.1 christos 1 000 000 messages with good performance unlikely above that limit
2 1.1 christos 10 10 Mandatory configuration file edits
3 1.1 christos 11 11 To chroot or not to chroot
4 1.1 christos 12 12 Care and feeding of the Postfix system
5 1.1 christos 14 rbl_domain rbl_reason rbl_reason
6 1.1 christos 168 100 189 2 255 255 255 224
7 1.1 christos 18 rbl_domain rbl_reason rbl_reason
8 1.1 christos 1 ffff ffff ffff ffff ffff ffff ffff ffff
9 1.1 christos 2001 240 587 0 2d0 b7ff fe88 2ca7 ffff ffff ffff ffff
10 1.1 christos 31 sasldb Accounts are stored stored in a Cyrus SASL Berkeley DB
11 1.1 christos 33 ldapdb Accounts are stored stored in an LDAP database
12 1.1 christos 4 yes yes yes never 100
13 1.1 christos 5 postmaster postmaster example com
14 1.1 christos 5 root root localhost
15 1.1 christos 6 abuse abuse example com
16 1.1 christos 80821 S 0 00 24 smtpd n smtp t inet u c o stress yes
17 1.1 christos 83326 S 0 00 28 smtpd n smtp t inet u c o stress
18 1.1 christos 84345 Ss 0 00 11 usr bin perl usr libexec postfix smtpd policy pl
19 1.1 christos 8 SENDMAIL usr sbin sendmail G i NEVER NEVER NEVER use t here
20 1.1 christos address localpart as per RFC 822 so that additional or or
21 1.1 christos all all Maximum per destination delivery concurrency
22 1.1 christos and cost cost 1 times more than if the preemptive scheduler was
23 1.1 christos and sneak in the ten recipient mail Wait wait wait Could we Aren t
24 1.1 christos aNULL aNULL kEECDH kEDH RC4 eNULL EXPORT LOW STRENGTH
25 1.1 christos Arrival Date Sun 26 Nov 2006 17 01 01 0500 EST
26 1.1 christos attacks with user domain domain addresses when Postfix provides
27 1.1 christos authzTo authzTo dn regex uniqueIdentifier ou people dc example dc com
28 1.1 christos AUXLIBS AUXLIBS options for LDAP or TLS etc
29 1.1 christos blockquote blockquote
30 1.1 christos broken smtp smtp o smtp_quote_rfc821_envelope no
31 1.1 christos ccert_fingerprint C2 9D F4 87 71 73 73 D9 18 E7 C2 F3 C1 DA 6E 04
32 1.1 christos command_directory command_directory
33 1.1 christos concurrency concurrency limit
34 1.1 christos config_directory config_directory
35 1.1 christos daemon_directory daemon_directory
36 1.1 christos data_directory data_directory
37 1.1 christos Date Sun 26 Nov 2006 17 01 01 0500 EST
38 1.1 christos dd dd Alternatively check_ccert_access accepts an explicit search
39 1.1 christos dd dd check_ccert_access type table search_order cert_fingerprint
40 1.1 christos dd dd The commas are optional dd
41 1.1 christos dd dd The default algorithm is b sha256 b with Postfix ge 3 6
42 1.1 christos dd No TLS TLS will not be used unless enabled for specific
43 1.1 christos Dec 4 04 30 09 hostname postfix smtpd 58549 NOQUEUE reject
44 1.1 christos default_transport uucp uucp gateway
45 1.1 christos Documentation Documentation is available as README files start with the file
46 1.1 christos done done
47 1.1 christos done done
48 1.1 christos dt b a name check_address_map check_address_map a i a href DATABASE_RE
49 1.1 christos dt b a name check_ccert_access check_ccert_access a i a href DATABASE_
50 1.1 christos dt b a name check_client_a_access check_client_a_access a i a href DAT
51 1.1 christos dt b a name check_client_access check_client_access a i a href DATABAS
52 1.1 christos dt b a name check_client_mx_access check_client_mx_access a i a href D
53 1.1 christos dt b a name check_client_ns_access check_client_ns_access a i a href D
54 1.1 christos dt b a name check_etrn_access check_etrn_access a i a href DATABASE_RE
55 1.1 christos dt b a name check_helo_a_access check_helo_a_access a i a href DATABAS
56 1.1 christos dt b a name check_helo_access check_helo_access a i a href DATABASE_RE
57 1.1 christos dt b a name check_helo_mx_access check_helo_mx_access a i a href DATAB
58 1.1 christos dt b a name check_helo_ns_access check_helo_ns_access a i a href DATAB
59 1.1 christos dt b a name check_policy_service check_policy_service i servername i a
60 1.1 christos dt b a name check_recipient_a_access check_recipient_a_access a i a hre
61 1.1 christos dt b a name check_recipient_access check_recipient_access a i a href D
62 1.1 christos dt b a name check_recipient_mx_access check_recipient_mx_access a i a h
63 1.1 christos dt b a name check_recipient_ns_access check_recipient_ns_access a i a h
64 1.1 christos dt b a name check_sasl_access check_sasl_access a i a href DATABASE_RE
65 1.1 christos dt b a name check_sender_a_access check_sender_a_access a i a href DAT
66 1.1 christos dt b a name check_sender_access check_sender_access a i a href DATABAS
67 1.1 christos dt b a name check_sender_mx_access check_sender_mx_access a i a href D
68 1.1 christos dt b a name check_sender_ns_access check_sender_ns_access a i a href D
69 1.1 christos dt b a name defer defer a b dt
70 1.1 christos dt b a name defer_if_permit defer_if_permit a b dt
71 1.1 christos dt b a name defer_if_reject defer_if_reject a b dt
72 1.1 christos dt b a name defer_unauth_destination defer_unauth_destination a b dt
73 1.1 christos dt b a name no_address_mappings no_address_mappings a b dt
74 1.1 christos dt b a name no_header_body_checks no_header_body_checks a b dt
75 1.1 christos dt b a name no_milters no_milters a b dt
76 1.1 christos dt b a name no_unknown_recipient_checks no_unknown_recipient_checks a b
77 1.1 christos dt b a name permit_auth_destination permit_auth_destination a b dt
78 1.1 christos dt b a name permit_dnswl_client permit_dnswl_client i dnswl_domain d d d d
79 1.1 christos dt b a name permit_inet_interfaces permit_inet_interfaces a b dt
80 1.1 christos dt b a name permit_mx_backup permit_mx_backup a b dt
81 1.1 christos dt b a name permit_mynetworks permit_mynetworks a b dt
82 1.1 christos dt b a name permit permit a b dt
83 1.1 christos dt b a name permit_rhswl_client permit_rhswl_client i rhswl_domain d d d d
84 1.1 christos dt b a name permit_sasl_authenticated permit_sasl_authenticated a b dt
85 1.1 christos dt b a name permit_tls_all_clientcerts permit_tls_all_clientcerts a b
86 1.1 christos dt b a name permit_tls_clientcerts permit_tls_clientcerts a b dt
87 1.1 christos dt b a name reject_invalid_helo_hostname reject_invalid_helo_hostname a
88 1.1 christos dt b a name reject_multi_recipient_bounce reject_multi_recipient_bounce a
89 1.1 christos dt b a name reject_non_fqdn_helo_hostname reject_non_fqdn_helo_hostname a
90 1.1 christos dt b a name reject_non_fqdn_recipient reject_non_fqdn_recipient a b dt
91 1.1 christos dt b a name reject_non_fqdn_sender reject_non_fqdn_sender a b dt
92 1.1 christos dt b a name reject_plaintext_session reject_plaintext_session a b dt
93 1.1 christos dt b a name reject_rbl_client reject_rbl_client i rbl_domain d d d d i
94 1.1 christos dt b a name reject reject a b dt
95 1.1 christos dt b a name reject_rhsbl_client reject_rhsbl_client i rbl_domain d d d d
96 1.1 christos dt b a name reject_rhsbl_helo reject_rhsbl_helo i rbl_domain d d d d i
97 1.1 christos dt b a name reject_rhsbl_recipient reject_rhsbl_recipient i rbl_domain d d
98 1.1 christos dt b a name reject_rhsbl_reverse_client reject_rhsbl_reverse_client i rbl_
99 1.1 christos dt b a name reject_rhsbl_sender reject_rhsbl_sender i rbl_domain d d d d
100 1.1 christos dt b a name reject_sender_login_mismatch reject_sender_login_mismatch a
101 1.1 christos dt b a name reject_unauth_destination reject_unauth_destination a b dt
102 1.1 christos dt b a name reject_unauth_pipelining reject_unauth_pipelining a b dt
103 1.1 christos dt b a name reject_unknown_client_hostname reject_unknown_client_hostname
104 1.1 christos dt b a name reject_unknown_helo_hostname reject_unknown_helo_hostname a
105 1.1 christos dt b a name reject_unknown_recipient_domain reject_unknown_recipient_domain
106 1.1 christos dt b a name reject_unknown_sender_domain reject_unknown_sender_domain a
107 1.1 christos dt b a name reject_unlisted_recipient reject_unlisted_recipient a b wi
108 1.1 christos dt b a name reject_unlisted_sender reject_unlisted_sender a b dt
109 1.1 christos dt b a name reject_unverified_recipient reject_unverified_recipient a b
110 1.1 christos dt b a name reject_unverified_sender reject_unverified_sender a b dt
111 1.1 christos dt b a name sleep sleep i seconds i a b dt
112 1.1 christos dt b a name warn_if_reject warn_if_reject a b dt
113 1.1 christos dt dt b i a href DATABASE_README html type table a i b dt
114 1.1 christos dt dt b i number i i number i b dt
115 1.1 christos dt dt dd 0 Disable logging of TLS activity dd
116 1.1 christos dt dt dd 1 Log only a summary message on TLS handshake completion
117 1.1 christos dt dt dd 2 Also log levels during TLS negotiation dd
118 1.1 christos dt dt dd 3 Also log hexadecimal and ASCII dump of TLS negotiation
119 1.1 christos dt dt dd 4 Also log hexadecimal and ASCII dump of complete
120 1.1 christos dude dude example com
121 1.1 christos eliminates the latency of the TCP handshake SYN SYN ACK ACK
122 1.1 christos example com uucp uucp host
123 1.1 christos example MAIL RCPT BDAT BDAT MAIL RCPT BDAT without ever having to
124 1.1 christos export MANPATH MANPATH pwd man MANPATH
125 1.1 christos fe80 1 2d0 b7ff fe88 2ca7 ffff ffff ffff ffff
126 1.1 christos fe80 5 1 ffff ffff ffff ffff
127 1.1 christos file allows for robust handling of temporary delivery errors errors
128 1.1 christos Filtered Filtered
129 1.1 christos for the file name when a pattern is a type table table specification
130 1.1 christos from host example com 192 168 0 2 TLSv1 with cipher cipher name
131 1.1 christos generic generic a restrictions These restrictions are applicable in
132 1.1 christos groups msn com 63 2 1 2 4 4 14 14 14 8 0
133 1.1 christos highvolume com 4000 160 160 320 640 1280 1440 0 0 0 0
134 1.1 christos host host port host port address or address port the form
135 1.1 christos http www umich edu dirsvcs ldap ldap html or OpenLDAP
136 1.1 christos id 84863BC0E5 Sun 26 Nov 2006 17 01 01 0500 EST
137 1.1 christos if concurrency concurrency limit
138 1.1 christos ifconfig en0 alias address netmask 255 255 255 255
139 1.1 christos inet_addr_local inet_addr_local configured 2 IPv4 addresses
140 1.1 christos inet_addr_local inet_addr_local configured 4 IPv6 addresses
141 1.1 christos insiders_only insiders_only check_sender_access hash etc postfix insiders reject
142 1.1 christos in the form of a domain name hostname hostname port hostname port
143 1.1 christos into memory such as pcre regexp or texthash texthash is similar
144 1.1 christos jane jane janes preferred machine
145 1.1 christos joe joe joes preferred machine
146 1.1 christos Line 8 NEVER NEVER NEVER use the t command line option here It
147 1.1 christos listname listname request
148 1.1 christos lists sourceforge net 2313 2313 0 0 0 0 0 0 0 0
149 1.1 christos local local 8
150 1.1 christos local_only local_only
151 1.1 christos maildrop maildrop
152 1.1 christos maildrop maildrop owner cn root dc your dc com
153 1.1 christos make make makefiles CC opt ansic bin cc Ae HP UX
154 1.1 christos make make makefiles CC purify cc
155 1.1 christos man man man5 postconf 5 less
156 1.1 christos master_service_disable foo inet inet
157 1.1 christos multi_instance_enable multi_instance_enable
158 1.1 christos multi_instance_group multi_instance_group
159 1.1 christos multi_instance_name multi_instance_name
160 1.1 christos mydestination myhostname localhost mydomain mydomain
161 1.1 christos mydomain to an incomplete address address rewriting alias
162 1.1 christos mynetworks mynetworks 127 0 0 0 8 168 100 189 0 28 1 128 fe80 10 2001 240 587
163 1.1 christos mynetworks mynetworks hash etc postfix network_table
164 1.1 christos Name lt user example com gt gt i Postfix will ignore the i User
165 1.1 christos name name port name or name port
166 1.1 christos NOTE Postfix 3 6 also introduces support for the level level
167 1.1 christos number number ranges Postfix version 2 8 and later If no
168 1.1 christos numbers or number number ranges Postfix version 2 8 and later
169 1.1 christos one or more separated numbers or number number ranges
170 1.1 christos openssl req new key key
171 1.1 christos or more separated numbers or number number ranges p
172 1.1 christos or number number ranges Postfix version 2 8 and later If no
173 1.1 christos ownership of system directories such as etc usr usr bin var
174 1.1 christos PARAM postscreen_dnsbl_max_ttl postscreen_dnsbl_ttl postscreen_dnsbl_ttl
175 1.1 christos patterns list multiple domain names as domain domain
176 1.1 christos p Note 2 address information may be enclosed inside tt tt
177 1.1 christos postfix 12345 12345 postfix no where no shell
178 1.1 christos Postfix 2 3 2 5 to hang up on clients that that match
179 1.1 christos Postfix has TWO sets of mail filters filters that are used for
180 1.1 christos Postfix Postfix can use an LDAP directory as a source for any of its lookups
181 1.1 christos Postfix Postfix passes the status back to the remote SMTP
182 1.1 christos Postfix Postfix will send the mail back to the sender address
183 1.1 christos pre pre
184 1.1 christos query_filter mailacceptinggeneralid s maildrop maildrop
185 1.1 christos queue_directory queue_directory
186 1.1 christos Received from localhost localhost 127 0 0 1
187 1.1 christos Received Received from porcupine org
188 1.1 christos rejected rejected recipients are available on request by the Milter
189 1.1 christos rewrite 8 none none
190 1.1 christos Say we have ten recipient mail followed by two two recipient mails If
191 1.1 christos separated numbers or number number ranges If no
192 1.1 christos smtpd_recipient_restrictions smtpd_recipient_restrictions
193 1.1 christos smtpd_relay_restrictions smtpd_relay_restrictions
194 1.1 christos smtpd_relay_restrictions smtpd_relay_restrictions
195 1.1 christos smtpd_tls_mandatory_protocols SSLv2 SSLv3 TLSv1 TLSv1 1
196 1.1 christos smtpd_tls_mandatory_protocols SSLv2 SSLv3 TLSv1 TLSv1 1
197 1.1 christos smtp smtp o smtp_bind_address 11 22 33 44
198 1.1 christos smtp smtp o smtp_bind_address6 1 2 3 4 5 6 7 8
199 1.1 christos smtp_tls_mandatory_protocols SSLv2 SSLv3 TLSv1 TLSv1 1
200 1.1 christos smtp_tls_mandatory_protocols SSLv2 SSLv3 TLSv1 TLSv1 1
201 1.1 christos SSLv3 TLSv1 TLSv1 1 TLSv1 2 and TLSv1 3 Starting with
202 1.1 christos T 5 10 20 40 80 160 320 640 1280 1280
203 1.1 christos T A 5 10 20 40 80 160 320 320
204 1.1 christos Therefore 301 0301 0x301 and 0x0301 are all equivalent to
205 1.1 christos The syntax of name value value name value and name value
206 1.1 christos the the backed up domain tld domain This prevents your mail queue
207 1.1 christos tls_random_source dev dev urandom
208 1.1 christos tls_random_source dev dev urandom
209 1.1 christos tls_random_source dev dev urandom
210 1.1 christos TLS TLS support in the LMTP delivery agent
211 1.1 christos TLSv1 3 with cipher TLS_AES_256_GCM_SHA384 256 256 bits
212 1.1 christos to flush flush 8 Deferred
213 1.1 christos to host example com 192 168 0 2 25 TLSv1 with cipher cipher name
214 1.1 christos to server example TLSv1 3 with cipher TLS_AES_256_GCM_SHA384 256 256 bits
215 1.1 christos TOTAL 5000 200 200 400 800 1600 1000 200 200 200 200
216 1.1 christos transport transport
217 1.1 christos tt tt in the authorized_verp_clients value and in files
218 1.1 christos tt tt in the mynetworks value and in files specified with
219 1.1 christos tt tt in the smtpd_authorized_verp_clients value and in
220 1.1 christos tt tt in the smtpd_authorized_xclient_hosts value and in
221 1.1 christos tt tt in the smtpd_authorized_xforward_hosts value and in
222 1.1 christos tt tt in the smtpd_client_event_limit_exceptions value and
223 1.1 christos tt tt in the smtpd_sasl_exceptions_networks value and in
224 1.1 christos tt tt p
225 1.1 christos two two recipient mails
226 1.1 christos uid cn cn auth
227 1.1 christos Unfiltered Unfiltered
228 1.1 christos unknown recipients in local domains domains that match mydestination
229 1.1 christos Use blockquote pre pre blockquote for examples
230 1.1 christos Use pre pre for the Examples section at the end
231 1.1 christos username username
232 1.1 christos user sourceforge net 7678 7678 0 0 0 0 0 0 0 0
233 1.1 christos using TLSv1 3 with cipher TLS_AES_256_GCM_SHA384 256 256 bits
234 1.1 christos using TLSv1 with cipher cipher name
235 1.1 christos var var spool and so on This is especially an issue if you executed
236 1.1 christos With the standard operators lt lt etc compatibility
237 1.1 christos yes yes yes never 100
238 1.1 christos zombie zombie tlsproxy 8 smtpd 8
239 1.1 christos and 1 000 000 messages with good performance unlikely above that
240 1.1 christos dt dt b name value b Postfix ge 3 0 dt
241 1.1 christos dt dt dd 3 Also log the hexadecimal and ASCII dump of the
242 1.1 christos dt dt dd 4 Also log the hexadecimal and ASCII dump of complete
243 1.1 christos parametername stress something something Other
244 1.1 christos p Note on OpenBSD systems specify dev dev arandom when dev dev urandom
245 1.1.1.2 christos user3 example net smtp smtp relay example net submission
246 1.1.1.3 christos virtual_alias_maps hash etc postfix virtual virtual aliasing
247 1.1.1.3 christos system_wide_settings system_wide_settings
248 1.1.1.3 christos ssl_library_settings ssl_library_settings
249 1.1.1.3 christos initial_ssl_settings initial_ssl_settings
250 1.1.1.3 christos postfix_settings postfix_settings
251 1.1.1.3 christos postfix_ssl_settings postfix_ssl_settings
252 1.1.1.3 christos baseline_postfix_settings baseline_postfix_settings
253 1.1.1.3 christos The and match and literally Without the the
254 1.1.1.3 christos The matches literally Without the the would
255 1.1.1.3 christos The example is simplified for educational purposes In reality my patterns list multiple domain names as domain domain
256 1.1.1.3 christos The matches literally Without the the would match any character
257 1.1.1.3 christos The and match and literally Without the the and would be grouping operators
258 1.1.1.3 christos The matches literally Without the the would match any character
259 1.1.1.3 christos pipeline all commands following EHLO for example MAIL RCPT BDAT BDAT MAIL RCPT BDAT without ever having to wait for a server response This means that with BDAT the Postfix SMTP server cannot distinguish between a well behaved client and a
260 1.1.1.3 christos NOTE Postfix 3 6 also introduces support for the level level and other operators to compare compatibility levels With the standard operators etc compatibility level 3 10 would be smaller than 3 9 which is undesirable
261 1.1.1.3 christos Otherwise the benefits of SMTP connection caching are minor it eliminates the latency of the TCP handshake SYN SYN ACK ACK plus the latency of the SMTP initial handshake 220 greeting EHLO command EHLO response With TLS encrypted
262 1.1.1.3 christos Otherwise the benefits of SMTP connection caching are minor it eliminates the latency of the TCP handshake SYN SYN ACK ACK plus the latency of the SMTP initial handshake 220 greeting EHLO command EHLO response With TLS encrypted
263 1.1.1.3 christos 3 Reject the mail by sending a suitable status code back to Postfix Postfix will send the mail back to the sender address
264 1.1.1.3 christos Line 8 NEVER NEVER NEVER use the t command line option here It will mis deliver mail like sending messages from a mailing list back to the mailing list
265 1.1.1.3 christos Line 8 NEVER NEVER NEVER use the t command line option here It will mis deliver mail like sending messages from a mailing list back to the mailing list
266 1.1.1.3 christos Documentation Documentation is available as README files start with the file README_FILES AAAREADME as HTML web pages point your browser to html index html and as UNIX style manual pages
267 1.1.1.3 christos Parameters whose defaults can be specified in this way are listed below See the postconf 5 manpage for a description command nroff man man man5 postconf 5 less
268 1.1.1.3 christos Parameters whose defaults can be specified in this way are listed below See the postconf 5 manpage for a description command nroff man man man5 postconf 5 less
269 1.1.1.3 christos mynetworks mynetworks 127 0 0 0 8 168 100 189 0 28 1 128 fe80 10 2001 240 587 64
270 1.1.1.3 christos Postfix Postfix can use an LDAP directory as a source for any of its lookups aliases 5 virtual 5 canonical 5 etc This allows you to keep information for your mail service in a replicated network database with fine grained access controls By not
271 1.1.1.3 christos If you re using the libraries from the UM distribution http www umich edu dirsvcs ldap ldap html or OpenLDAP http www openldap org something like this in the top level of your Postfix source tree should work
272 1.1.1.3 christos query_filter mailacceptinggeneralid s maildrop maildrop maildrop
273 1.1.1.3 christos query_filter mailacceptinggeneralid s maildrop maildrop maildrop
274 1.1.1.3 christos query_filter mailacceptinggeneralid s maildrop maildrop maildrop owner cn root dc your dc com
275 1.1.1.3 christos query_filter mailacceptinggeneralid s maildrop maildrop maildrop owner cn root dc your dc com
276 1.1.1.3 christos As of Postfix version 2 0 the Postfix SMTP server rejects mail for unknown recipients in local domains domains that match mydestination or the IP addresses in inet_interfaces or proxy_interfaces with User unknown in local recipient table
277 1.1.1.3 christos Postfix emulates a limited number of Sendmail macros as shown in the table Some macro values depend on whether a recipient is rejected rejected recipients are available on request by the Milter application Different macros are available at
278 1.1.1.3 christos Postfix has TWO sets of mail filters filters that are used for SMTP mail only specified with the smtpd_milters parameter and filters for non SMTP mail specified with the non_smtpd_milters parameter The non SMTP filters are primarily for
279 1.1.1.3 christos etc usr usr bin var var spool and so on This is especially an issue if you executed postfix install see above as an unprivileged user
280 1.1.1.3 christos etc usr usr bin var var spool and so on This is especially an issue if you executed postfix install see above as an unprivileged user
281 1.1.1.3 christos parametername stress something stress something or parametername stress something something Other parameters always evaluate as if the stress value is the empty string
282 1.1.1.3 christos parametername stress something stress something or parametername stress something something Other parameters always evaluate as if the stress value is the empty string
283 1.1.1.3 christos more CPU faster disks and more network bandwidth can deal with larger deferred queues but as a rule of thumb the deferred queue scales to somewhere between 100 000 and 1 000 000 messages with good performance unlikely above that limit
284 1.1.1.3 christos 31 sasldb Accounts are stored stored in a Cyrus SASL Berkeley DB database
285 1.1.1.3 christos assigned to the delivery slots might look like this 12131415 Hmm fine for sneaking in the single recipient mail but how do we sneak in the mail with more than one recipient Say if we have one four recipient mail followed by two two recipient
286 1.1.1.3 christos we see the hundred recipient job can accumulate ten free delivery slots and then we could preempt it and sneak in the ten recipient mail Wait wait wait Could we Aren t we overinflating the original one thousand recipient mail
287 1.1.1.3 christos The truth is that it turns out that it is not really necessary to wait until the jobs counter accumulates all the delivery slots in advance Say we have ten recipient mail followed by two two recipient mails If the preemption happened when enough
288 1.1.1.3 christos Disallowing RFC 822 address syntax example MAIL FROM the dude dude example com
289 1.1.1.3 christos 3 Reject the mail by sending a suitable SMTP status code back to Postfix Postfix passes the status back to the remote SMTP client This way Postfix does not have to send a bounce message
290 1.1.1.3 christos Lines 14 18 Define the list of valid addresses in the the backed up domain tld domain This prevents your mail queue from filling up with undeliverable MAILER DAEMON messages If you can t maintain a list of valid recipients then you must
291 1.1.1.3 christos The syntax of name value value name value and name value is explained at the beginning of the postconf 5 manual page
292 1.1.1.3 christos Use 521 SMTP reply codes Postfix 2 6 and later or 421 Postfix 2 3 2 5 to hang up on clients that that match botnet related RBLs see next bullet or that match selected non RBL restrictions such as SMTP access maps The Postfix SMTP
293 1.1.1.3 christos the next hop destination can have the Postfix specific form name name port name or name port
294 1.1.1.3 christos dt b a name no_unknown_recipient_checks no_unknown_recipient_checks a b dt
295 1.1.1.3 christos dt b a name check_ccert_access check_ccert_access a i a href DATABASE_README html type table a i b dt
296 1.1.1.3 christos dt b a name check_client_access check_client_access a i a href DATABASE_README html type table a i b dt
297 1.1.1.3 christos dt b a name check_client_a_access check_client_a_access a i a href DATABASE_README html type table a i b dt
298 1.1.1.3 christos dt b a name check_client_mx_access check_client_mx_access a i a href DATABASE_README html type table a i b dt
299 1.1.1.3 christos dt b a name check_client_ns_access check_client_ns_access a i a href DATABASE_README html type table a i b dt
300 1.1.1.3 christos dt b a name check_reverse_client_hostname_access check_reverse_client_hostname_access a i a href DATABASE_README html type table a i b dt
301 1.1.1.3 christos dt b a name check_reverse_client_hostname_a_access check_reverse_client_hostname_a_access a i a href DATABASE_README html type table a i b dt
302 1.1.1.3 christos dt b a name check_reverse_client_hostname_mx_access check_reverse_client_hostname_mx_access a i a href DATABASE_README html type table a i b dt
303 1.1.1.3 christos dt b a name check_reverse_client_hostname_ns_access check_reverse_client_hostname_ns_access a i a href DATABASE_README html type table a i b dt
304 1.1.1.3 christos dt b a name check_sasl_access check_sasl_access a i a href DATABASE_README html type table a i b dt
305 1.1.1.3 christos dt b a name permit_sasl_authenticated permit_sasl_authenticated a b dt
306 1.1.1.3 christos dt b a name permit_tls_all_clientcerts permit_tls_all_clientcerts a b dt
307 1.1.1.3 christos dt b a name reject_rbl_client reject_rbl_client i rbl_domain d d d d i a b dt
308 1.1.1.3 christos dt b a name permit_dnswl_client permit_dnswl_client i dnswl_domain d d d d i a b dt
309 1.1.1.3 christos dt b a name reject_rhsbl_client reject_rhsbl_client i rbl_domain d d d d i a b dt
310 1.1.1.3 christos dt b a name permit_rhswl_client permit_rhswl_client i rhswl_domain d d d d i a b dt
311 1.1.1.3 christos dt b a name reject_rhsbl_reverse_client reject_rhsbl_reverse_client i rbl_domain d d d d i a b dt
312 1.1.1.3 christos dt b a name reject_unknown_client_hostname reject_unknown_client_hostname a b with Postfix lt 2 3 reject_unknown_client dt
313 1.1.1.3 christos dt b a name reject_unknown_reverse_client_hostname reject_unknown_reverse_client_hostname a b dt
314 1.1.1.3 christos dt b a name reject_unknown_forward_client_hostname reject_unknown_forward_client_hostname a b dt
315 1.1.1.3 christos dt b a name check_policy_service check_policy_service i servername i a b dt
316 1.1.1.3 christos dt b a name reject_multi_recipient_bounce reject_multi_recipient_bounce a b dt
317 1.1.1.3 christos dt b a name check_etrn_access check_etrn_access a i a href DATABASE_README html type table a i b dt
318 1.1.1.3 christos dt b a name check_helo_access check_helo_access a i a href DATABASE_README html type table a i b dt
319 1.1.1.3 christos dt b a name check_helo_a_access check_helo_a_access a i a href DATABASE_README html type table a i b dt
320 1.1.1.3 christos dt b a name check_helo_mx_access check_helo_mx_access a i a href DATABASE_README html type table a i b dt
321 1.1.1.3 christos dt b a name check_helo_ns_access check_helo_ns_access a i a href DATABASE_README html type table a i b dt
322 1.1.1.3 christos dt b a name reject_invalid_helo_hostname reject_invalid_helo_hostname a b with Postfix lt 2 3 reject_invalid_hostname dt
323 1.1.1.3 christos dt b a name reject_non_fqdn_helo_hostname reject_non_fqdn_helo_hostname a b with Postfix lt 2 3 reject_non_fqdn_hostname dt
324 1.1.1.3 christos dt b a name reject_rhsbl_helo reject_rhsbl_helo i rbl_domain d d d d i a b dt
325 1.1.1.3 christos dt b a name reject_unknown_helo_hostname reject_unknown_helo_hostname a b with Postfix lt 2 3 reject_unknown_hostname dt
326 1.1.1.3 christos dt b a name check_recipient_access check_recipient_access a i a href DATABASE_README html type table a i b dt
327 1.1.1.3 christos dt b a name check_recipient_a_access check_recipient_a_access a i a href DATABASE_README html type table a i b dt
328 1.1.1.3 christos dt b a name check_recipient_mx_access check_recipient_mx_access a i a href DATABASE_README html type table a i b dt
329 1.1.1.3 christos dt b a name check_recipient_ns_access check_recipient_ns_access a i a href DATABASE_README html type table a i b dt
330 1.1.1.3 christos dt b a name reject_non_fqdn_recipient reject_non_fqdn_recipient a b dt
331 1.1.1.3 christos dt b a name reject_rhsbl_recipient reject_rhsbl_recipient i rbl_domain d d d d i a b dt
332 1.1.1.3 christos dt b a name reject_unauth_destination reject_unauth_destination a b dt
333 1.1.1.3 christos dt b a name reject_unknown_recipient_domain reject_unknown_recipient_domain a b dt
334 1.1.1.3 christos dt b a name reject_unlisted_recipient reject_unlisted_recipient a b with Postfix version 2 0 check_recipient_maps dt
335 1.1.1.3 christos dt b a name reject_unverified_recipient reject_unverified_recipient a b dt
336 1.1.1.3 christos dt b a name check_sender_access check_sender_access a i a href DATABASE_README html type table a i b dt
337 1.1.1.3 christos dt b a name check_sender_a_access check_sender_a_access a i a href DATABASE_README html type table a i b dt
338 1.1.1.3 christos dt b a name check_sender_mx_access check_sender_mx_access a i a href DATABASE_README html type table a i b dt
339 1.1.1.3 christos dt b a name check_sender_ns_access check_sender_ns_access a i a href DATABASE_README html type table a i b dt
340 1.1.1.3 christos dt b a name reject_authenticated_sender_login_mismatch reject_authenticated_sender_login_mismatch a b dt
341 1.1.1.3 christos dt b a name reject_known_sender_login_mismatch reject_known_sender_login_mismatch a b dt
342 1.1.1.3 christos dt b a name reject_rhsbl_sender reject_rhsbl_sender i rbl_domain d d d d i a b dt
343 1.1.1.3 christos dt b a name reject_sender_login_mismatch reject_sender_login_mismatch a b dt
344 1.1.1.3 christos dt b a name reject_unauthenticated_sender_login_mismatch reject_unauthenticated_sender_login_mismatch a b dt
345 1.1.1.3 christos dt b a name reject_unknown_sender_domain reject_unknown_sender_domain a b dt
346 1.1.1.3 christos dt b a name check_address_map check_address_map a i a href DATABASE_README html type table a i b dt
347 1.1.1.3 christos PARAM postscreen_dnsbl_max_ttl postscreen_dnsbl_ttl postscreen_dnsbl_ttl 1 h
348 1.1.1.3 christos standard lt CR gt lt LF gt br br This maintains compatibility
349 1.1.1.3 christos lt CR gt lt LF gt lt CR gt lt LF gt br br Such clients
350 1.1.1.3 christos smtpd_forbid_bare_newline_reject_code br br This will reject
351 1.1.1.3 christos br br This will also reject some email from Microsoft services
352 1.1.1.3 christos 2045 Sections 2 7 and 2 8 br br Such clients can be excluded
353 1.1.1.3 christos br br This will also reject email from services that use BDAT
354 1.1.1.3 christos RFC 2045 Sections 2 7 and 2 8 br br Such clients can be
355 1.1.1.3 christos to become a list of comma separated names br br This feature
356 1.1.1.3 christos the form of a domain name hostname hostname service hostname service
357 1.1.1.3 christos expected to become a list of comma separated names br br This
358 1.1.1.3 christos Postfix Postfix can use MongoDB as a source for any of its lookups aliases 5 virtual 5 canonical 5 etc This allows you to keep information for your mail service in a replicated noSQL database with fine grained access controls By not storing it
359 1.1.1.3 christos CCARGS CCARGS DHAS_MONGODB I usr include libmongoc 1 0
360 1.1.1.3 christos dt dt dd 2 Also enable verbose logging in the Postfix TLS
361 1.1.1.3 christos Postfix Postfix legacy TLS Support
362 1.1.1.3 christos var run tlsrpt tlsrpt sock Relative names will work with and without Postfix chroot support Do not specify a location under a directory such as private or public that is already used by Postfix programs Only Postfix programs should create
363 1.1.1.3 christos Note the recommended socket location is still to be determined A good socket location would be under the Postfix queue directory for example smtp_tlsrpt_socket_name run tlsrpt tlsrpt sock The advantage of using a relative name is that
364 1.1.1.3 christos with cipher ECDHE RSA AES256 GCM SHA384 256 256 bits
365 1.1.1.3 christos TLSv1 2 with cipher ECDHE RSA AES256 GCM SHA384 256 256 bits
366 1.1.1.3 christos The recommended socket location is still to be determined A good socket location would be under the Postfix queue directory for example smtp_tlsrpt_socket_name run tlsrpt tlsrpt sock The advantage of using a relative name is that it
367 1.1.1.4 christos enhanced status code and text format 45 number number text
368 1.1.1.4 christos opportunistic opportunistic starttls
369 1.1.1.4 christos li The general format is tls feature feature
370 1.1.1.4 christos li p The general format is tt tls feature feature tt
371 1.1.1.4 christos li p When a feature is enclosed in tt tt and tt tt
372 1.1.1.4 christos li p When tt tt is prepended to a feature the policy
373 1.1.1.4 christos tt none tt tt may tt tt encrypt tt etc Other
374 1.1.1.4 christos tt tls i level i requiretls tt where tt tt
375 1.1.1.4 christos where tt tt indicates the kind of policy violation described
376 1.1.1.4 christos tt tt tls i level i requiretls noencryption tt or
377 1.1.1.4 christos xn mumble mumble Punycode A label form that Postfix needs
378 1.1.1.4 christos xn mumble mumble Punycode A label form that Postfix needs Note if you specify the domain list outside main cf then the automatic name expansions and Punycode conversions will not happen you will need to enter real domain names and will
379 1.1.1.4 christos pre pre
380 1.1.1.4 christos contains the xn mumble mumble Punycode A label form that Postfix needs
381 1.1.1.4 christos domain_to_ascii returns the xn mumble mumble Punycode A label form that Postfix needs This works around a limitation that may be eliminated in a future Postfix version
382 1.1.1.4 christos smtp_requiretls_policy smtp_requiretls_policy inline
383 1.1.1.4 christos xn mumble mumble Punycode A label form that Postfix needs This works around a limitation that may be eliminated in a future Postfix version
384 1.1.1.4 christos in tt tt p
385 1.1.1.4 christos mynetworks mynetworks lmdb etc postfix network_table
386 1.1.1.4 christos 44 enable redirect redirect hash to lmdb or cdb
387