4 msgnested_header_checks
10 msgHotmail Problem
4 msgfeedback request: scheduled delivery of messages
1 msgpkgsrc 'postfix-stress' option (Re: PATCH versi...
10 msgHow to enforce users send email with the real f...
15 msgCatchall setup problem with Virtual domains and...
2 msgquestion

restrictions
\ D. Walsh (14 Jan 2008)
. \ Ralf Hildebrandt (14 Jan 2008)
. . \ D. Walsh (14 Jan 2008)
. . . \ D. Walsh (14 Jan 2008)
. . . \ mouss (14 Jan 2008)

5 msgproblems with virtual alias table
2 msgsome mails bounce with 'Name or service not known'
2 msgExternal recipients within same domain
2 msg~RE: stopping Spam with postfix
9 msgstopping Spam with postfix
17 msgMessages stuck in active queue
4 msgvirtual: Command as adress list
1 msgvariable quota policy ideas
2 msgHow to unistall postfix from compiling source(m...
1 msgBackup mx with local delivery and forwarding fo...
4 msgReceiving Mail with from mydomain.com from unkn...
10 msgWhich is the best soft for mailscanning?
Subject:Re: restrictions
Group:Postfix-users
From:mouss
Date:14 Jan 2008


 
D. Walsh wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hi Ralph, I didn't want to write to you directly since I know you get
> busy at times and didn't think the query was a serious issue.
>
> I removed the cbl.abuseat.org and fixed the two other entries as
> recommended.
>
> Combining the two affects the GUI and might cause confusion to the
> average user to see the client restrictions empty so leaving them as
> separate entries is probably best unless you can outline why combining
> would be a better option but I doubt my vendor would rewrite the GUI to
> incorporate the changes.
>

which average user?

DNSBL in client restrictions will be queried every time (even if mail
comes from mynetworks, even if it is a relay attempt, ...). By moving
them down enough the chain, you reduce the load on the DNSBL servers.

you can use
smtpd_client_restrictions =
check_client_access $local_black_list_map
(replace $local_bloack_list_map by the correct value)
and tell users this enables checking a local BL.


PS. the permit* in your client restrictions are useless, because the
default in client restrictions is permit.

> Also, the client restrictions can't be left out or entirely blank
> because the GUI inserts the minimum "permit_mynetworks, permit".

the GUI is stupid. This is a sign that the designer/developper is either
lazy or doesn't know his subject. A consequence is that there may be
bugs inside.


© 2004-2008 readlist.com