Skip to content

Instantly share code, notes, and snippets.

@sibok
Created March 28, 2014 19:32
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save sibok/f6f3fc9dfa074868e10e to your computer and use it in GitHub Desktop.
Save sibok/f6f3fc9dfa074868e10e to your computer and use it in GitHub Desktop.
postfix/smtpd[15455]: connect from mail-wi0-x22f.google.com[2a00:1450:400c:c05::22f]
postfix/smtpd[15455]: Anonymous TLS connection established from mail-wi0-x22f.google.com[2a00:1450:400c:c05::22f]: TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)
postfix/smtpd[15455]: warning: restriction `reject_authenticated_sender_login_mismatch' ignored: no SASL support
$ postconf -n
2bounce_notice_recipient = $delay_notice_recipient
alias_database = hash:/etc/postfix/aliases
alias_maps = hash:/etc/postfix/aliases
biff = no
broken_sasl_auth_clients = no
command_directory = /usr/sbin
config_directory = /etc/postfix
content_filter = amavis:[127.0.0.1]:10024
daemon_directory = /usr/lib/postfix
data_directory = /var/lib/postfix
debug_peer_level = 2
debugger_command = PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin ddd $daemon_directory/$process_name $process_id & sleep 5
delay_notice_recipient = admin
delay_warning_time = 30m
disable_vrfy_command = yes
header_checks = regexp:/etc/postfix/header_checks
html_directory = no
inet_interfaces = all
inet_protocols = all
lmtp_tls_session_cache_database = btree:/var/lib/postfix/lmtp_scache
local_recipient_maps =
mail_owner = postfix
mailbox_size_limit = 512000000
mailq_path = /usr/bin/mailq.postfix
manpage_directory = /usr/share/man
masquerade_domains = mail.webeloping.es mail.webeloping.com we.webeloping.es we.webeloping.com www.webeloping.es www.webeloping.com
maximal_backoff_time = 8000s
maximal_queue_lifetime = 5d
message_size_limit = 36700160
milter_default_action = accept
milter_protocol = 2
mime_header_checks = regexp:/etc/postfix/mime_header_checks
minimal_backoff_time = 1000s
mydestination =
mydomain = webeloping.es
myhostname = we.webeloping.es
mynetworks_style = host
myorigin = webeloping.es
newaliases_path = /usr/bin/newaliases.postfix
non_smtpd_milters = inet:localhost:8891
notify_classes = bounce, delay, policy, protocol, resource, software
policy-spf_time_limit = 3600s
queue_directory = /var/spool/postfix
readme_directory = /usr/share/doc/postfix-2.6.6/README_FILES
receive_override_options = no_address_mappings
relayhost =
relocated_maps = mysql:/etc/postfix/mysql_relocated.cf
sample_directory = /usr/share/doc/postfix-2.6.6/samples
sender_canonical_maps = hash:/etc/postfix/generic
sendmail_path = /usr/sbin/sendmail.postfix
setgid_group = postdrop
show_user_unknown_table_name = no
smtp_generic_maps = hash:/etc/postfix/generic
smtp_helo_timeout = 60s
smtp_tls_CAfile = $smtpd_tls_CAfile
smtp_tls_CApath = $smtpd_tls_CApath
smtp_tls_cert_file = $smtpd_tls_cert_file
smtp_tls_key_file = $smtpd_tls_key_file
smtp_tls_note_starttls_offer = yes
smtp_tls_security_level = may
smtp_tls_session_cache_database = btree:/var/lib/postfix/smtp_scache
smtpd_banner = $myhostname ESMTP $mail_name
smtpd_client_restrictions = reject_rbl_client blackholes.easynet.nl, reject_rbl_client zen.spamhaus.org, reject_rbl_client bl.spamcop.net, permit_sasl_authenticated, permit_dnswl_client list.dnswl.org, ,check_client_access regexp:/etc/postfix/client_restrictions
smtpd_data_restrictions = reject_unauth_pipelining
smtpd_delay_reject = yes
smtpd_error_sleep_time = 5
smtpd_hard_error_limit = 12
smtpd_helo_required = yes
smtpd_helo_restrictions = permit_sasl_authenticated, reject_non_fqdn_hostname, reject_invalid_hostname, reject_unknown_helo_hostname, permit
smtpd_junk_command_limit = 5
smtpd_milters = inet:localhost:8891, inet:localhost:8893
smtpd_recipient_limit = 16
smtpd_recipient_restrictions = reject_unauth_pipelining, reject_non_fqdn_recipient, reject_unknown_recipient_domain, reject_rhsbl_helo dbl.spamhaus.org, reject_rhsbl_sender dbl.spamhaus.org, check_policy_service unix:private/policy-spf, permit_mynetworks, permit_sasl_authenticated, permit_dnswl_client list.dnswl.org, check_policy_service inet:127.0.0.1:10023, reject_unauth_destination, permit
smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination
smtpd_sasl_auth_enable = no
smtpd_sasl_local_domain =
smtpd_sasl_security_options = noanonymous
smtpd_sender_login_maps = proxy:mysql:/etc/postfix/mysql_sender_login_maps.cf
smtpd_sender_restrictions = reject_non_fqdn_sender, reject_unknown_sender_domain, reject_unlisted_sender, reject_authenticated_sender_login_mismatch, permit_mynetworks, permit_sasl_authenticated, reject_unauth_pipelining, permit
smtpd_soft_error_limit = 3
smtpd_tls_CAfile = /etc/ssl/certs/startssl_ca-bundle.pem.pem
smtpd_tls_CApath = /etc/ssl/certs
smtpd_tls_cert_file = /etc/ssl/certs/class2.webeloping_es.pem
smtpd_tls_key_file = /etc/ssl/private/class2.webeloping_es.key
smtpd_tls_loglevel = 1
smtpd_tls_received_header = yes
smtpd_tls_security_level = may
smtpd_tls_session_cache_database = btree:/var/lib/postfix/smtpd_scache
smtpd_tls_session_cache_timeout = 3600s
strict_rfc821_envelopes = no
tls_random_source = dev:/dev/urandom
transport_maps = mysql:/etc/postfix/mysql_transport.cf
transport_retry_time = 30s
unknown_local_recipient_reject_code = 450
virtual_alias_maps = mysql:/etc/postfix/mysql_alias.cf, mysql:/etc/postfix/mysql_email2email.cf
virtual_gid_maps = static:5000
virtual_mailbox_base = /var/spool/mail/virtual
virtual_mailbox_domains = mysql:/etc/postfix/mysql_domains.cf
virtual_mailbox_maps = mysql:/etc/postfix/mysql_mailbox.cf
virtual_uid_maps = static:5000
$ postconf -P
pickup/fifo/content_filter =
pickup/fifo/receive_override_options = no_header_body_checks
relay/unix/smtp_fallback_relay =
amavis/unix/disable_dns_lookups = yes
amavis/unix/max_use = 20
amavis/unix/smtp_data_done_timeout = 1200
amavis/unix/smtp_send_xforward_command = yes
127.0.0.1:10025/inet/content_filter =
127.0.0.1:10025/inet/local_header_rewrite_clients =
127.0.0.1:10025/inet/local_recipient_maps =
127.0.0.1:10025/inet/mynetworks = 127.0.0.0/8
127.0.0.1:10025/inet/receive_override_options = no_header_body_checks,no_unknown_recipient_checks,no_milters
127.0.0.1:10025/inet/relay_recipient_maps =
127.0.0.1:10025/inet/smtpd_client_connection_count_limit = 0
127.0.0.1:10025/inet/smtpd_client_connection_rate_limit = 0
127.0.0.1:10025/inet/smtpd_client_restrictions = permit_mynetworks,reject
127.0.0.1:10025/inet/smtpd_data_restrictions = reject_unauth_pipelining
127.0.0.1:10025/inet/smtpd_delay_reject = no
127.0.0.1:10025/inet/smtpd_end_of_data_restrictions =
127.0.0.1:10025/inet/smtpd_error_sleep_time = 0
127.0.0.1:10025/inet/smtpd_hard_error_limit = 1000
127.0.0.1:10025/inet/smtpd_helo_restrictions =
127.0.0.1:10025/inet/smtpd_milters =
127.0.0.1:10025/inet/smtpd_recipient_restrictions = permit_mynetworks,reject
127.0.0.1:10025/inet/smtpd_restriction_classes =
127.0.0.1:10025/inet/smtpd_sender_restrictions =
127.0.0.1:10025/inet/smtpd_soft_error_limit = 1001
submission/inet/smtpd_client_restrictions = permit_sasl_authenticated,reject_unauth_destination,reject
submission/inet/smtpd_sasl_auth_enable = yes
submission/inet/smtpd_sasl_security_options = noanonymous,noplaintext
submission/inet/smtpd_sasl_tls_security_options = noanonymous
submission/inet/smtpd_tls_auth_only = yes
submission/inet/smtpd_tls_security_level = encrypt
smtps/inet/smtpd_client_restrictions = permit_sasl_authenticated,reject
smtps/inet/smtpd_sasl_auth_enable = yes
smtps/inet/smtpd_sasl_security_options = noanonymous,noplaintext
smtps/inet/smtpd_sasl_tls_security_options = noanonymous
smtps/inet/smtpd_tls_auth_only = yes
smtps/inet/smtpd_tls_wrappermode = yes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment