Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Postfix - antispam and relay package

    Scheduled Pinned Locked Moved pfSense Packages
    855 Posts 136 Posters 1.4m Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      ics
      last edited by

      Hi,

      In Postfix, is it possible to forward emails to specific servers depending on the recipient email address (not only on the domain) ?

      Thank you

      1 Reply Last reply Reply Quote 0
      • marcellocM Offline
        marcelloc
        last edited by

        not yet.  :(

        Treinamentos de Elite: http://sys-squad.com

        Help a community developer! ;D

        1 Reply Last reply Reply Quote 0
        • Z Offline
          zlyzwy
          last edited by

          Hi Marcelloc,

          Can I add the NOQUEUE email address to Whitelist?
          Some of mail server can't pass 'Helo Hostname' check….

          As my understanding, the "access lists" will only work with QUEUE email address.

          Thanks in advance~

          Zlyzwy

          1 Reply Last reply Reply Quote 0
          • marcellocM Offline
            marcelloc
            last edited by

            The noqueue info in log file are for messages that failed during header check.

            to workaround it,you can:

            • unselect the helo check on config gui

            • add the host hello info to /etc/hosts (check if pfsense boot process does not clean this file)

            • if you really trust the remote domain, add it to mynetworks.

            But the best way is to ask remote site admin to fix his smtp configuration.

            Treinamentos de Elite: http://sys-squad.com

            Help a community developer! ;D

            1 Reply Last reply Reply Quote 0
            • I Offline
              ics
              last edited by

              Hi,

              In Search Mail some emails have status "sent" even if it's detected as spam (maillog).
              And for some other emails status "spam" is obviously correct. :)

              Any explanation ?

              Another question :
              the subject displayed is the original subject of the email. Is it possible to view the modified subject also ?

              Thanks

              1 Reply Last reply Reply Quote 0
              • marcellocM Offline
                marcelloc
                last edited by

                @ics:

                Any explanation ?

                Are you using mailscanner too? if so, there are som actions that sends the spam message just changing the subject, so the last action of this message_id is sent as postfix sent it to user.

                @ics:

                the subject displayed is the original subject of the email. Is it possible to view the modified subject also ?

                Not yet, the databased is filled by maillog file, the subject is logged only when messages arrives.

                Treinamentos de Elite: http://sys-squad.com

                Help a community developer! ;D

                1 Reply Last reply Reply Quote 0
                • B Offline
                  biggsy
                  last edited by

                  Hi Marcello,

                  I have an IronPort box that's been trying to bounce the same mail to my mail server, on the hour for nearly three days.

                  The sender address is being rejected for obvious reasons:

                  NOQUEUE: reject: RCPT from ironport2-out.teksavvy.com[206.248.154.182]: 450 4.1.8 mailman-bounces@localhost.localdomain: Sender address rejected: Domain not found; from= mailman-bounces@localhost.localdomain…

                  I tried to whitelist the server, blacklist it and a bunch of other things but the reject_unknown_sender_domain still kicks in and, becasue it's only a 450 response, they try again an hour later.

                  I thought I'd try "soft_bounce=no" but the GUI won't allow me to set that.

                  I can get soft_bounce=yes by setting soft bounce to "enabled" in the GUI but selecting either "Only in PostScreen" or "Disabled" just clears soft_bounce from main.cf.

                  I thought Disabled should set soft_bounce=no but wanted to ask what you think?/mailman-bounces@localhost.localdomain/mailman-bounces@localhost.localdomain

                  1 Reply Last reply Reply Quote 0
                  • marcellocM Offline
                    marcelloc
                    last edited by

                    The best way to receive this bounce is to send an email to remote site sysadmin explaining his server misconfiguration.
                    To workaround for this misconfigured server, enable dns forwarder service and add missing domain/host as a Host Override.

                    I thought Disabled should set soft_bounce=no but wanted to ask what you think?

                    postfix documentation says that soft_bounce default value is no, so if it's not declared, then soft_bounce=no.

                    soft_bounce (default: no)
                    Safety net to keep mail queued that would otherwise be returned to the sender. This parameter disables locally-generated bounces, and prevents the Postfix SMTP server from rejecting mail permanently, by changing 5xx reply codes into 4xx. However, soft_bounce is no cure for address rewriting mistakes or mail routing mistakes.

                    Example:

                    soft_bounce = yes

                    att,
                    Marcello Coutinho

                    Treinamentos de Elite: http://sys-squad.com

                    Help a community developer! ;D

                    1 Reply Last reply Reply Quote 0
                    • I Offline
                      ics
                      last edited by

                      Hi,

                      My Postfix rejects emails from a server with the error : "Client host rejected: cannot find your hostname"
                      However, the IP address is perfectly resolvable.
                      And in maillog :
                      "warning: ...: hostname domain.net verification failed: hostname nor servname provided, or not known"

                      I tried to add the IP address in MyNetworks, no change.

                      Do you know what is misconfigured ?

                      Thanks

                      1 Reply Last reply Reply Quote 0
                      • marcellocM Offline
                        marcelloc
                        last edited by

                        The ip address is resolvable, but hostname that server sent on smtp header is?

                        Sometimes this wrong hostname is sent on servername or helo info.

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • I Offline
                          ics
                          last edited by

                          postfix says :
                          RCPT from unknown[IP_Address]: 450 4.7.1 Client host rejected: cannot find your hostname
                          The helo is correct and correspond to the IP address when resolved.

                          The hostname in smtp header is the HELO ?
                          If not where can I find it in the log ?

                          Anyway, why is it still rejected while the IP is in MyNetworks ?

                          1 Reply Last reply Reply Quote 0
                          • marcellocM Offline
                            marcelloc
                            last edited by

                            @ics:

                            Anyway, why is it still rejected while the IP is in MyNetworks ?

                            even on MyNetworks, the email must be correct.
                            The mynetworks will allow this ip to relay to any domain.

                            Add this ipname on dns forwarder host override list and check if it pass the resolv test.

                            att,
                            Marcello Coutinho

                            Treinamentos de Elite: http://sys-squad.com

                            Help a community developer! ;D

                            1 Reply Last reply Reply Quote 0
                            • I Offline
                              ics
                              last edited by

                              @marcelloc:

                              Add this ipname on dns forwarder host override list and check if it pass the resolv test.

                              It works.

                              Thank you

                              1 Reply Last reply Reply Quote 0
                              • A Offline
                                arosenau
                                last edited by

                                Has anyone been able to get this to work using Gmail as a relay? I get the following errors when I try and relay through gmail using this package

                                Jul 12 23:50:51
                                postfix/smtp[17005]: unable to dlopen /usr/local/lib/sasl2/libgssapiv2.so.2: Shared object "libgssapi.so.10" not found, required by "libgssapiv2.so.2"

                                Jul 12 23:50:51
                                postfix/smtp[17005]: unable to dlopen /usr/local/lib/sasl2/libgssapiv2.so.2: Shared object "libgssapi.so.10" not found, required by "libgssapiv2.so.2"

                                Jul 12 23:50:51
                                postfix/smtp[17005]: cannot load Certificate Authority data: disabling TLS support

                                Jul 12 23:50:51
                                postfix/smtp[17005]: warning: TLS library problem: 17005:error:02001002:system library:fopen:No such file or directory:/usr/src/secure/lib/libcrypto/../../../crypto/openssl/crypto/bio/bss_file.c:126:fopen('/etc/pki/tls/certs/ca-bundle.crt','r'):

                                Jul 12 23:50:51
                                postfix/smtp[17005]: warning: TLS library problem: 17005:error:2006D080:BIO routines:BIO_new_file:no such file:/usr/src/secure/lib/libcrypto/../../../crypto/openssl/crypto/bio/bss_file.c:129:

                                Jul 12 23:50:51
                                postfix/smtp[17005]: warning: TLS library problem: 17005:error:0B084002:x509 certificate routines:X509_load_cert_crl_file:system lib:/usr/src/secure/lib/libcrypto/../../../crypto/openssl/crypto/x509/by_file.c:274:

                                I think the most important error is this one
                                postfix/smtp[17005]: cannot load Certificate Authority data: disabling TLS support

                                and I would assume that is because it can't find the smtp_tls_CAfile which I also can't find anywhere on the pfsense box, so I can't specify the correct path in my main.cf file.

                                Any ideas? I'm sure its something simple i missed.  :P

                                1 Reply Last reply Reply Quote 0
                                • marcellocM Offline
                                  marcelloc
                                  last edited by

                                  @arosenau:

                                  Any ideas? I'm sure its something simple i missed.  :P

                                  you will need some libs from freebsd to get it working.

                                  take a look on my repo.
                                  i386
                                  http://e-sac.siteseguro.ws/pfsense/8/All/ldd/

                                  amd64
                                  http://e-sac.siteseguro.ws/pfsense/8/amd64/All/ldd/

                                  Treinamentos de Elite: http://sys-squad.com

                                  Help a community developer! ;D

                                  1 Reply Last reply Reply Quote 0
                                  • A Offline
                                    arosenau
                                    last edited by

                                    @marcelloc:

                                    @arosenau:

                                    Any ideas? I'm sure its something simple i missed.  :P

                                    you will need some libs from freebsd to get it working.

                                    take a look on my repo.
                                    i386
                                    http://e-sac.siteseguro.ws/pfsense/8/All/ldd/

                                    amd64
                                    http://e-sac.siteseguro.ws/pfsense/8/amd64/All/ldd/

                                    Can you point me in the right direction on how to get these installed? I am familiar with apt and yum in the Linux world, but I don't know how package management works in the freebsd/pfsense world.

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM Offline
                                      marcelloc
                                      last edited by

                                      @arosenau:

                                      Can you point me in the right direction on how to get these installed?

                                      Just download the missing libs to /usr/local/lib using fetch cmd on console/ssh and try again.

                                      att,
                                      Marcello Coutinho

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • A Offline
                                        arosenau
                                        last edited by

                                        @marcelloc:

                                        Just download the missing libs to /usr/local/lib using fetch cmd on console/ssh and try again.

                                        att,
                                        Marcello Coutinho

                                        So I got those packages downloaded and stopped and started post fix but I'm still having the same errors. Also I didn't mention in my first post that I also get an error that says " Must issue a STARTTLS command first. y5sm20759670igb.11 (in reply to MAIL FROM command))" I would assume I"m getting this error because it can't load the Certificate Authority data and it disabled TLS support.

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM Offline
                                          marcelloc
                                          last edited by

                                          @arosenau:

                                          Jul 12 23:50:51
                                          postfix/smtp[17005]: unable to dlopen /usr/local/lib/sasl2/libgssapiv2.so.2: Shared object "libgssapi.so.10" not found, required by "libgssapiv2.so.2"

                                          The postfix message looks for libs on /usr/local/lib/sasl2/ instead of  /usr/local/lib like I've posted.

                                          can you try to copy these libs to /usr/local/lib/sasl2/ and teste again?

                                          att,
                                          Marcello Coutinho

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • A Offline
                                            arosenau
                                            last edited by

                                            @marcelloc:

                                            The postfix message looks for libs on /usr/local/lib/sasl2/ instead of  /usr/local/lib like I've posted.

                                            can you try to copy these libs to /usr/local/lib/sasl2/ and teste again?

                                            att,
                                            Marcello Coutinho

                                            Still doesn't work, although the error now looks slightly different "unsupported file layout"

                                            Jul 16 22:12:40 postfix/smtp[9495]: unable to dlopen /usr/local/lib/sasl2/libgssapiv2.so.2: /usr/local/lib/libgssapi.so.10: unsupported file layout 
                                            Jul 16 22:12:40 postfix/smtp[9495]: unable to dlopen /usr/local/lib/sasl2/libgssapiv2.so.2: /usr/local/lib/libgssapi.so.10: unsupported file layout 
                                            Jul 16 22:12:40 postfix/smtp[9495]: cannot load Certificate Authority data: disabling TLS support 
                                            Jul 16 22:12:40 postfix/smtp[9495]: warning: TLS library problem: 9495:error:02001002:system library:fopen:No such file or directory:/usr/src/secure/lib/libcrypto/../../../crypto/openssl/crypto/bio/bss_file.c:126:fopen('/etc/pki/tls/certs/ca-bundle.crt','r'): 
                                            Jul 16 22:12:40 postfix/smtp[9495]: warning: TLS library problem: 9495:error:2006D080:BIO routines:BIO_new_file:no such file:/usr/src/secure/lib/libcrypto/../../../crypto/openssl/crypto/bio/bss_file.c:129: 
                                            Jul 16 22:12:40 postfix/smtp[9495]: warning: TLS library problem: 9495:error:0B084002:x509 certificate routines:X509_load_cert_crl_file:system lib:/usr/src/secure/lib/libcrypto/../../../crypto/openssl/crypto/x509/by_file.c:274: 
                                            Jul 16 22:12:40 postfix/smtp[9495]: 0EE7440B28F: to=<armyreciepent@gmail.com>, relay=smtp.gmail.com[209.85.225.108]:587, delay=0.64, delays=0.37/0.02/0.21/0.04, dsn=5.7.0, status=bounced (host smtp.gmail.com[209.85.225.108] said: 530 5.7.0 Must issue a STARTTLS command first. ud8sm20864816igb.4 (in reply to MAIL FROM command)) 
                                            Jul 16 22:12:40 postfix/cleanup[9348]: A5BBD40B298: message-id=<20120716221240.A5BBD40B298@relay> 
                                            Jul 16 22:12:40 postfix/bounce[9782]: 0EE7440B28F: sender non-delivery notification: A5BBD40B298 
                                            Jul 16 22:12:40 postfix/qmgr[53688]: A5BBD40B298: from=<>, size=2493, nrcpt=1 (queue active) 
                                            Jul 16 22:12:40 postfix/qmgr[53688]: 0EE7440B28F: removed 
                                            Jul 16 22:12:40 postfix/smtp[9495]: A5BBD40B298: to=<xxx@mydomain.com>, relay=smtp.gmail.com[209.85.225.109]:587, delay=0.16, delays=0.01/0/0.12/0.04, dsn=5.7.0, status=bounced (host smtp.gmail.com[209.85.225.109] said: 530 5.7.0 Must issue a STARTTLS command first. k5sm9875094igq.12 (in reply to MAIL FROM command)) 
                                            Jul 16 22:12:40 postfix/qmgr[53688]: A5BBD40B298: removed</xxx@mydomain.com></armyreciepent@gmail.com> 
                                            
                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.