Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Postfix - antispam and relay package

    Scheduled Pinned Locked Moved pfSense Packages
    855 Posts 136 Posters 1.4m Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM Offline
      marcelloc
      last edited by

      As I told you last post, postfix is very judicious in header checks, so check your DNS server to see if this host announced by remote SMTP does exist or not.

      You can also try to white-list this host in your local RBL and CIDR ACL.

      I have many of these alerts too, but all of them are really spam or 'misconfigured' hosts.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • D Offline
        darklogic
        last edited by

        marcelloc,

        I am going to assume that they are misconfigured host because I know they are not spam emails.

        I did state I added the /^From:.*@someonesdomain.com OK in the ACL's Filter in the header section. Does this not whitelist the e-mail or is it just whitelisting only one of the spam checks?

        Also, if I add their domain address to the CIDR allow, wouldn't that allow their mail server to relay off ours according to the text I am reading at the bottom of that form field?

        Thanks,

        MDP

        1 Reply Last reply Reply Quote 0
        • D Offline
          darklogic
          last edited by

          Sorry, I meant relay off the pfsense box. My mail server would not act as an open relay.

          1 Reply Last reply Reply Quote 0
          • marcellocM Offline
            marcelloc
            last edited by

            @darklogic:

            I am going to assume that they are misconfigured host because I know they are not spam emails.

            Did you tested name resolution oh the remote host header info?

            @darklogic:

            Also, if I add their domain address to the CIDR allow, wouldn't that allow their mail server to relay off ours according to the text I am reading at the bottom of that form field?

            When using postscreen, the documentations says(correct me if I'm wrong) that this only prevents blocking.
            When postscreen is disabled, any ip on CIDR allows relay on your server.

            Can you test this with any other external ip?

            Treinamentos de Elite: http://sys-squad.com

            Help a community developer! ;D

            1 Reply Last reply Reply Quote 0
            • D Offline
              darklogic
              last edited by

              I have been using mxtoolbox.com for testing. One of the domains I am trying to figure out why it is getting blocked is clemansnelson.com

              When I do a test on mxtoolbox.com for mail.clemansnelson.com I get the following.

              220 CNASRV.CNA.local Microsoft ESMTP MAIL Service ready at Fri, 21 Oct 2011 12:59:31 -0400

              OK - 24.123.130.226 resolves to mail.clemansnelson.com
              Warning - Reverse DNS does not match SMTP Banner
              0 seconds - Good on Connection time
              Not an open relay.
              5.335 seconds - Warning on Transaction time

              Thanks,

              MDP

              1 Reply Last reply Reply Quote 0
              • D Offline
                darklogic
                last edited by

                How would I go about disabling postscreen just to see if the mails start to come through. I thought I did disable once by simply unselecting the after greeting checks and disabling Zombie Blocker?

                1 Reply Last reply Reply Quote 0
                • marcellocM Offline
                  marcelloc
                  last edited by

                  Can you see that there is a warning for this domain on your test?

                  I've made some tests here and  mail.clemansnelson.com has a valid dns entry and it's related as SPF for clemansnelson.com.

                  check if your dns has same info and if postfix erros say that worng hostname is mail.clemansnelson.com or something else.

                  If you disable postscreen, the error will remain as it is done in header check.

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    darklogic
                    last edited by

                    Here is the message minus user email name and our domain name.

                    postfix/smtpd[10950]: NOQUEUE: reject: RCPT from mail.clemansnelson.com[24.123.130.226]: 450 4.7.1 <cnasrv.cna.local>: Helo command rejected: Host not found; from= someone@clemansnelson.comto= someone@mydomain.comproto=ESMTP helo= <cnasrv.cna.local>When you say my DNS, our you referring to my internal DNS or external WAN DNS from the firewall?

                    Thanks,

                    MDP</cnasrv.cna.local>/someone@mydomain.com/someone@clemansnelson.com</cnasrv.cna.local>

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      darklogic
                      last edited by

                      I have spotted about 6 other domains that I know are not spam that is getting the same message above. If I disable the Postfix forwarder and then do a temporary NAT and port forward of SMTP:25 to our internal mail server. The transparent spam filters we have will allow the message through and they do a lot of the same checks. I must have something misconfigured on postfix, or these host are not configured correctly. I am not willing to say something is wrong with the package because we are still getting a lot of good e-mails coming through.

                      Up above I posted my base config, can you see anything that would be causing the issue in that config?

                      Thanks,

                      MDP

                      1 Reply Last reply Reply Quote 0
                      • marcellocM Offline
                        marcelloc
                        last edited by

                        @darklogic:

                        postfix/smtpd[10950]: NOQUEUE: reject: RCPT from mail.clemansnelson.com[24.123.130.226]: 450 4.7.1 <cnasrv.cna.local>: Helo command rejected: Host not found; from= someone@clemansnelson.comto= someone@mydomain.comproto=ESMTP helo= <cnasrv.cna.local></cnasrv.cna.local>/someone@mydomain.com/someone@clemansnelson.com</cnasrv.cna.local>

                        The problem is this : helo=<cnasrv.cna.local></cnasrv.cna.local>

                        Helo host in smtp negotiaton must exist. If you allow any host in SMTP helo, you are opening your server for a lot of spam.

                        Many STMP admins 'foget' to configure their servers, it's normal.

                        In any way I suggest you to disable spam checks.

                        EDIT:

                        Note that any client behind a misconfigured server will receive this erros for many domains, so they can forward it to SMTP 'admins'

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • D Offline
                          darklogic
                          last edited by

                          Well, as much as I hated to, I disabled the spam checks and saved, then disabled and saved and then renabled postfix and saved.

                          I am still getting the same messages?

                          Thanks,

                          MDP

                          1 Reply Last reply Reply Quote 0
                          • marcellocM Offline
                            marcelloc
                            last edited by

                            And about your config, I suggest you to change RBL threshold to 2.

                            As I told you, this host error is got by header check, not postscreen.
                            See configuration files options in gui.

                            in main.cf

                            #Don't talk to mail systems that don't know their own hostname.
                            smtpd_helo_required = yes
                            smtpd_helo_restrictions = reject_unknown_helo_hostname
                            
                            

                            This is a feature, not a bug or false positive.

                            Don't think the problem is with your setup.

                            Treinamentos de Elite: http://sys-squad.com

                            Help a community developer! ;D

                            1 Reply Last reply Reply Quote 0
                            • D Offline
                              darklogic
                              last edited by

                              Ok, I am starting to see now what you are saying. On the main config code you pointed out, Should I change smtpd_helo_required = yes to = no or change smtpd_helo_restrictions = reject_unknown_helo_hostname

                              Like you said, I am afraid I will open the gates for flooding of spam. We have transparent backend filters, but I was hoping to kill most of it at the gateway level.

                              So what would you suggest at this point. I changed my RBL from 1 to 2.

                              Thanks for all your help,

                              MDP

                              1 Reply Last reply Reply Quote 0
                              • marcellocM Offline
                                marcelloc
                                last edited by

                                Send a email to postmaster@ domains you identify that misconfiguration.

                                Or try CIDR with remote SMTPS While using postscreen

                                Treinamentos de Elite: http://sys-squad.com

                                Help a community developer! ;D

                                1 Reply Last reply Reply Quote 0
                                • I Offline
                                  invaluement
                                  last edited by

                                  @darklogic:

                                  RBL with = dnsbl.sorbs.net, bl.spamcop.net2, dnslb.local-5, cbl.abuseat.org, b.barracudacentral.org

                                  MDP,

                                  Hi. I'm the owner/manager of invaluement.com and the host name you listed above for using invaluement.com as an RBL is WRONG!!!! (I deleted it in my quote of your post.. see post for what I'm talking about)

                                  Anyone using that host name as an RBL will ONLY get rejected queries. This a waste of other's resources–since anyone adding a bogus RBL only adds wasted time to the processing of each message. Therefore, please edit your post above to remove that reference to invaluement.

                                  Even if you had the correct host name, it would STILL get blocked because access to invaluement is ONLY available to paying subscribers via RSYNC to rbldnsd files, which are then hosted locally.

                                  An invaluement subscription is VERY INEXPENSIVE... and locally hosted RBLs on an rbldnsd server are extremely FAST--which helps your filtering to go FASTER and become more scalable--could even save you $$ on hardware upgrades in the future! Subscription information can be found here:

                                  http://dnsbl.invaluement.com/subscribe/

                                  Thanks and please let me know if you have any questions.

                                  1 Reply Last reply Reply Quote 0
                                  • D Offline
                                    darklogic
                                    last edited by

                                    marcelloc,

                                    Can you confirm if that last post from invaluement is true? I noticed they are a new user with that being their first post. Looks a little shady.

                                    Also I e-mail postmaster at those domains with nothing yet. Also, I am not sure what you were meaning with "Or try CIDR with remote SMTPS While using postscreen"?

                                    Thanks,

                                    MDP

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM Offline
                                      marcelloc
                                      last edited by

                                      The Rbl list in package example is just an example for how to configure Rbl list.

                                      You MUST take care on what list you choose. There is also a link in the package for a lot of Rbl lists, free and paid.

                                      And about the emails you sent, just be patient. You can also look for other emails on domains web page.

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • D Offline
                                        darklogic
                                        last edited by

                                        I clicked the link, but I am not sure what list are free and which ones are paid?

                                        1 Reply Last reply Reply Quote 0
                                        • D Offline
                                          darklogic
                                          last edited by

                                          marcelloc,

                                          I have some new info for you as requested. I have compared the past 3 weeks of SPAM data on our backend SPAM filter reports, and they have been very close from week-to-week of around 650 to 700 SPAM e-mails per week. This past weeks reports since the postfix forwarder package has been installed, has litterally cut that report down to around 190 to 200 SPAM e-mails. This is without any mail scanner or Spamassin added to the postfix forwarder.

                                          So right now we are seeing about a 300% decrease in SPAM on just the first layer of filtering at the gateway level. Very Nice…

                                          Any idea on when that mailscanner feature will be added?

                                          1 Reply Last reply Reply Quote 0
                                          • marcellocM Offline
                                            marcelloc
                                            last edited by

                                            Great news,

                                            Looking my logs what I see is that nasty emails like fake domains, virus, phishing, etc are almost 100% blocked with postfix. Comercial mail that has real smtp info can be easly blocked using ACLS.

                                            Any idea on when that mailscanner feature will be added?

                                            I think i will release a mailscanner-dev version with freebsd 8.1-release packages to get it working until pfsense packages are done.

                                            Thanks for your feedback

                                            Treinamentos de Elite: http://sys-squad.com

                                            Help a community developer! ;D

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.