2019-09-02 09:31:26 +02:00
|
|
|
# inter-mx with postscreen on 25/tcp
|
2017-03-02 12:23:23 +02:00
|
|
|
smtp inet n - n - 1 postscreen
|
2020-07-04 19:30:40 +02:00
|
|
|
10025 inet n - n - 1 postscreen
|
|
|
|
-o postscreen_upstream_proxy_protocol=haproxy
|
|
|
|
-o syslog_name=haproxy
|
2017-03-02 12:23:23 +02:00
|
|
|
smtpd pass - - n - - smtpd
|
|
|
|
-o smtpd_helo_restrictions=permit_mynetworks,reject_non_fqdn_helo_hostname
|
2019-02-05 11:35:32 +02:00
|
|
|
-o smtpd_sasl_auth_enable=no
|
2019-02-26 22:37:08 +02:00
|
|
|
-o smtpd_sender_restrictions=permit_mynetworks,reject_unlisted_sender,reject_unknown_sender_domain
|
2019-09-02 09:31:26 +02:00
|
|
|
|
|
|
|
# smtpd tls-wrapped (smtps) on 465/tcp
|
2019-11-24 15:18:27 +02:00
|
|
|
# TLS protocol can be modified by setting smtps_smtpd_tls_mandatory_protocols in extra.cf
|
2017-03-02 12:23:23 +02:00
|
|
|
smtps inet n - n - - smtpd
|
|
|
|
-o smtpd_tls_wrappermode=yes
|
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
|
2019-11-24 15:18:27 +02:00
|
|
|
-o smtpd_tls_mandatory_protocols=$smtps_smtpd_tls_mandatory_protocols
|
2018-10-27 13:22:29 +02:00
|
|
|
-o tls_preempt_cipherlist=yes
|
2020-10-17 09:06:38 +02:00
|
|
|
-o cleanup_service_name=smtp_sender_cleanup
|
2019-11-24 16:35:56 +02:00
|
|
|
-o syslog_name=postfix/smtps
|
2020-07-04 19:30:40 +02:00
|
|
|
10465 inet n - n - - smtpd
|
|
|
|
-o smtpd_upstream_proxy_protocol=haproxy
|
|
|
|
-o smtpd_tls_wrappermode=yes
|
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
|
|
|
|
-o smtpd_tls_mandatory_protocols=$smtps_smtpd_tls_mandatory_protocols
|
|
|
|
-o tls_preempt_cipherlist=yes
|
2020-10-17 09:06:38 +02:00
|
|
|
-o cleanup_service_name=smtp_sender_cleanup
|
2020-07-04 19:30:40 +02:00
|
|
|
-o syslog_name=postfix/smtps-haproxy
|
2019-09-02 09:31:26 +02:00
|
|
|
|
|
|
|
# smtpd with starttls on 587/tcp
|
2019-11-24 15:18:27 +02:00
|
|
|
# TLS protocol can be modified by setting submission_smtpd_tls_mandatory_protocols in extra.cf
|
2017-03-02 12:23:23 +02:00
|
|
|
submission inet n - n - - smtpd
|
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
|
|
|
|
-o smtpd_enforce_tls=yes
|
|
|
|
-o smtpd_tls_security_level=encrypt
|
2019-11-24 15:18:27 +02:00
|
|
|
-o smtpd_tls_mandatory_protocols=$submission_smtpd_tls_mandatory_protocols
|
2017-03-02 12:23:23 +02:00
|
|
|
-o tls_preempt_cipherlist=yes
|
2020-10-17 09:06:38 +02:00
|
|
|
-o cleanup_service_name=smtp_sender_cleanup
|
2019-11-24 16:35:56 +02:00
|
|
|
-o syslog_name=postfix/submission
|
2020-07-04 19:30:40 +02:00
|
|
|
10587 inet n - n - - smtpd
|
|
|
|
-o smtpd_upstream_proxy_protocol=haproxy
|
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
|
|
|
|
-o smtpd_enforce_tls=yes
|
|
|
|
-o smtpd_tls_security_level=encrypt
|
|
|
|
-o smtpd_tls_mandatory_protocols=$submission_smtpd_tls_mandatory_protocols
|
|
|
|
-o tls_preempt_cipherlist=yes
|
2020-10-17 09:06:38 +02:00
|
|
|
-o cleanup_service_name=smtp_sender_cleanup
|
2020-07-04 19:30:40 +02:00
|
|
|
-o syslog_name=postfix/submission-haproxy
|
2019-09-02 09:31:26 +02:00
|
|
|
|
|
|
|
# used by SOGo
|
|
|
|
# smtpd_sender_restrictions should match main.cf, but with check_sasl_access prepended for login-as-mailbox-user function
|
2017-03-02 12:23:23 +02:00
|
|
|
588 inet n - n - - smtpd
|
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,permit_sasl_authenticated,reject
|
|
|
|
-o smtpd_tls_auth_only=no
|
2018-12-11 00:26:28 +02:00
|
|
|
-o smtpd_sender_restrictions=check_sasl_access,regexp:/opt/postfix/conf/allow_mailcow_local.regexp,reject_authenticated_sender_login_mismatch,permit_mynetworks,permit_sasl_authenticated,reject_unlisted_sender,reject_unknown_sender_domain
|
2020-10-17 09:06:38 +02:00
|
|
|
-o cleanup_service_name=smtp_sender_cleanup
|
2019-11-24 16:35:56 +02:00
|
|
|
-o syslog_name=postfix/sogo
|
2019-09-02 09:31:26 +02:00
|
|
|
|
|
|
|
# used to reinject quarantine mails
|
2017-12-09 10:07:06 +02:00
|
|
|
590 inet n - n - - smtpd
|
2020-02-21 09:53:23 +02:00
|
|
|
-o smtpd_helo_restrictions=
|
2017-12-09 10:07:06 +02:00
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,reject
|
|
|
|
-o smtpd_tls_auth_only=no
|
|
|
|
-o smtpd_milters=
|
|
|
|
-o non_smtpd_milters=
|
2019-11-24 16:35:56 +02:00
|
|
|
-o syslog_name=postfix/quarantine
|
2019-09-02 09:31:26 +02:00
|
|
|
|
2021-05-30 16:08:19 +02:00
|
|
|
# used to send bcc mails
|
|
|
|
591 inet n - n - - smtpd
|
|
|
|
-o smtpd_helo_restrictions=
|
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,reject
|
|
|
|
-o smtpd_tls_auth_only=no
|
|
|
|
-o smtpd_milters=
|
|
|
|
-o non_smtpd_milters=
|
|
|
|
-o syslog_name=postfix/bcc
|
|
|
|
|
2019-09-02 09:31:26 +02:00
|
|
|
# enforced smtp connector
|
2017-03-02 12:23:23 +02:00
|
|
|
smtp_enforced_tls unix - - n - - smtp
|
|
|
|
-o smtp_tls_security_level=encrypt
|
|
|
|
-o syslog_name=enforced-tls-smtp
|
|
|
|
-o smtp_delivery_status_filter=pcre:/opt/postfix/conf/smtp_dsn_filter
|
2020-10-17 09:06:38 +02:00
|
|
|
|
2019-09-02 09:31:26 +02:00
|
|
|
# smtp connector used, when a transport map matched
|
|
|
|
# this helps to have different sasl maps than we have with sender dependent transport maps
|
2018-12-19 13:16:36 +02:00
|
|
|
smtp_via_transport_maps unix - - n - - smtp
|
2018-12-19 10:39:35 +02:00
|
|
|
-o smtp_sasl_password_maps=proxy:mysql:/opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
|
2017-04-05 22:21:20 +02:00
|
|
|
|
2017-03-02 12:23:23 +02:00
|
|
|
tlsproxy unix - - n - 0 tlsproxy
|
|
|
|
dnsblog unix - - n - 0 dnsblog
|
|
|
|
pickup fifo n - n 60 1 pickup
|
|
|
|
cleanup unix n - n - 0 cleanup
|
|
|
|
qmgr fifo n - n 300 1 qmgr
|
|
|
|
tlsmgr unix - - n 1000? 1 tlsmgr
|
|
|
|
rewrite unix - - n - - trivial-rewrite
|
|
|
|
bounce unix - - n - 0 bounce
|
|
|
|
defer unix - - n - 0 bounce
|
|
|
|
trace unix - - n - 0 bounce
|
|
|
|
verify unix - - n - 1 verify
|
|
|
|
flush unix n - n 1000? 0 flush
|
|
|
|
proxymap unix - - n - - proxymap
|
|
|
|
proxywrite unix - - n - 1 proxymap
|
|
|
|
smtp unix - - n - - smtp
|
|
|
|
relay unix - - n - - smtp
|
|
|
|
showq unix n - n - - showq
|
|
|
|
error unix - - n - - error
|
|
|
|
retry unix - - n - - error
|
|
|
|
discard unix - - n - - discard
|
|
|
|
local unix - n n - - local
|
|
|
|
virtual unix - n n - - virtual
|
|
|
|
lmtp unix - - n - - lmtp
|
|
|
|
anvil unix - - n - 1 anvil
|
|
|
|
scache unix - - n - 1 scache
|
|
|
|
maildrop unix - n n - - pipe flags=DRhu
|
|
|
|
user=vmail argv=/usr/bin/maildrop -d ${recipient}
|
2017-09-21 19:25:43 +02:00
|
|
|
|
2020-10-17 09:06:38 +02:00
|
|
|
# used to anonymize sender IP
|
|
|
|
smtp_sender_cleanup unix n - y - 0 cleanup
|
|
|
|
-o header_checks=$smtp_header_checks
|
|
|
|
|
2017-09-21 19:25:43 +02:00
|
|
|
# start whitelist_fwd
|
2017-04-23 19:38:27 +02:00
|
|
|
127.0.0.1:10027 inet n n n - 0 spawn user=nobody argv=/usr/local/bin/whitelist_forwardinghosts.sh
|
2017-09-21 19:25:43 +02:00
|
|
|
# end whitelist_fwd
|
|
|
|
|
|
|
|
# start watchdog-specific
|
2019-09-02 09:31:26 +02:00
|
|
|
# logs to local7 (hidden)
|
2017-09-21 19:25:43 +02:00
|
|
|
589 inet n - n - - smtpd
|
|
|
|
-o smtpd_client_restrictions=permit_mynetworks,reject
|
|
|
|
-o syslog_name=watchdog
|
2017-10-11 11:21:41 +02:00
|
|
|
-o syslog_facility=local7
|
2017-09-21 19:25:43 +02:00
|
|
|
-o smtpd_milters=
|
2017-10-11 11:21:41 +02:00
|
|
|
-o cleanup_service_name=watchdog_cleanup
|
2017-09-21 19:25:43 +02:00
|
|
|
-o non_smtpd_milters=
|
2017-10-11 11:21:41 +02:00
|
|
|
watchdog_cleanup unix n - n - 0 cleanup
|
|
|
|
-o syslog_name=watchdog
|
|
|
|
-o syslog_facility=local7
|
2017-09-21 19:25:43 +02:00
|
|
|
-o queue_service_name=watchdog_qmgr
|
|
|
|
watchdog_qmgr fifo n - n 300 1 qmgr
|
2017-10-11 11:21:41 +02:00
|
|
|
-o syslog_facility=local7
|
|
|
|
-o syslog_name=watchdog
|
|
|
|
-o rewrite_service_name=watchdog_rewrite
|
|
|
|
watchdog_rewrite unix - - n - - trivial-rewrite
|
|
|
|
-o syslog_facility=local7
|
|
|
|
-o syslog_name=watchdog
|
|
|
|
-o local_transport=watchdog_discard
|
|
|
|
watchdog_discard unix - - n - - discard
|
|
|
|
-o syslog_facility=local7
|
|
|
|
-o syslog_name=watchdog
|
2017-09-21 19:25:43 +02:00
|
|
|
# end watchdog-specific
|