3 msgRe: Virtual domain aliases
4 msgaddress verify vs. virtual_alias_maps
20 msgPostfix/ClamAV Config Error
4 msgsmtp /dev/poll problem

Addresses filtering for only one supported domain
\ Laurent Neiger (28 Nov 2007)
. \ mouss (28 Nov 2007)
. . \ Laurent Neiger (29 Nov 2007)
. . . \ Laurent Neiger (30 Nov 2007)
. . . . \ mouss (30 Nov 2007)
. . . . . \ Laurent Neiger (3 Dec 2007)

14 msgGreylist question
1 msgOne transport with AUTH and other transport wit...
7 msgIs this expected reject behavior for foreign IP...
3 msgrelay_domains and virtual_mailbox_domains not w...
2 msgNeed help debugging a possible content filter p...
11 msgspam emails with | in front of the email addresses
9 msgunexpected domain rewrite (by postfix?)
5 msgError receiving email
20 msgPostfix 2.5-20071111, smtp.gmail.com, bouncing ...
1 msgBounce notification configure
45 msgRe: Recipient validation
2 msgUse of MySQL for lookups
8 msgproposal: change behavior with respect to recip...
11 msgOT: Any bad DKIM experiences?
8 msghashed spool directories
Subject:Addresses filtering for only one supported domain
Group:Postfix-users
From:Laurent Neiger
Date:28 Nov 2007


 


Hello all,

I'd like to make some tuning in my postfix config but I cannot
find out if it's possible...

I have a postfix 2.3.8-2 which stands onto a server and support
several domains : a main one, for our users, and other ones, for
conferences, external projects, etc.

This mail server is not our MX, as we have a frontal SMTP gateway
running qpsmtpd which, in association with spam-assassin, reject
spams on-the-fly (before the end of the smtp transaction, before
accepting the mail) and forward hams to the postfix server for
local delivery.

But this gateway only acts for our main domain, mail addressed
to our other domains arrive directly to the postfix machine.
So the postfix machine is accepting TCP/25 connections from
anywhere (as a normal MX)...

One trick we encounter is we occasionnaly receive spam for our
main domain because it is directly addresses to the postfix server.
Some spammer seem to have found out they can skip our gateway
by not asking the DNS for the MX but send directly to the postfix
server.

Thus (thanks guys for having kept reading, my question is here !)
I'd like to configure postfix for accepting connections only from
our local domain (for local mail) or our gateway (for mails coming
from outside) but ONLY for our main domain.

In effect, I can't put an ACL on the postfix server as for delivery
for other domains, external emails must arrive directly.

And in postfix docs, I see configs for allow/reject mail depending
on sender parameter (e.g. check_client_address, check_sender_address,
...) but this seem to apply to whole configuration, all the supported
domains or destinations, so I can't here reject all external connections...

Is there a way to tell postfix to apply a policy for one (or some) of
its supported domains (destinations), and another policy to the
other ones ?

Thanks a lot in advance for your help,

I hope to read from you soon and of course can sharpen the description
of my problem or config if you need.

Best regards,

Laurent.




begin:vcard
fn:Laurent Neiger
n:Neiger;Laurent
org;quoted-printable:CNRS Grenoble;Centre R=C3=A9seau & Informatique Commun
adr:B.P. 166;;25, avenue des Martyrs;Grenoble;;38042;France
email;internet:Laurent.Neiger
title;quoted-printable:Administrateur Syst=C3=A8mes & R=C3=A9seaux
tel;work:(0033) (0)4 76 88 79 91
tel;fax:(0033) (0)4 76 88 12 95
note:Certificats : http://igc.services.cnrs.fr/Doc/General/trust.html
x-mozilla-html:TRUE
url:http://cric.grenoble.cnrs.fr
version:2.1
end:vcard





© 2004-2008 readlist.com