[ext] Komisches Verhalten

Andreas Reschke postfix_ml at rirasoft.de
Do Nov 11 09:25:36 CET 2021


Am 11.11.21 um 09:18 schrieb Ralf Hildebrandt:
> * Andreas Reschke<postfix_ml at rirasoft.de>:
>> Hallo,
>>
>> wer kann mir das hier erklären? Es kommt eine Mail an einen nicht mehr
>> existierenden User auf meinem Mailserver. Die wird gebounced. Richtig so.
> Nein. Falsch so. Mail an unbekannte User darfst Du gar nicht erst
> annehmen. Das macht jede Menge Probleme.
>
>> Allerdings schickt mein Server eine Mail genau an diesen Absender zurück.
> Ja, weil es ein Bounce ist: Wer die Mail annimmt und nicht zustellen
> kann, muss einen Bounce generieren.
>
> Deshalb mail an unbekannte User nicht annehmen.
>

Hallo Ralf,

genau das verstehe ich nicht. Das hat Server seither nicht gemacht. Wo 
habe ich hier mein Fehler?

Hier meine Konfig:

[root at linuxserver1 postfix]# postconf -n
alias_database = hash:/etc/aliases
alias_maps = hash:/etc/aliases
broken_sasl_auth_clients = yes
command_directory = /usr/sbin
compatibility_level = 2
config_directory = /etc/postfix
daemon_directory = /usr/libexec/postfix
data_directory = /var/lib/postfix
debug_peer_level = 10
debug_peer_list =
debugger_command = PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin 
xxgdb $daemon_directory/$process_name $process_id & sleep 5
home_mailbox = Maildir/
html_directory = no
inet_interfaces = all
inet_protocols = ipv4
local_recipient_maps = proxy:unix:passwd.byname $alias_maps
mail_owner = postfix
mailq_path = /usr/bin/mailq.postfix
manpage_directory = /usr/share/man
message_size_limit = 204857600
milter_mail_macros = i {mail_addr} {client_addr} {client_name} 
{auth_authen}
milter_protocol = 6
mime_header_checks = regexp:/etc/postfix/mime_header_checks.regexp
mydestination = $myhostname, localhost.$mydomain, localhost
mydomain = rirasoft.de
myhostname = mail.rirasoft.de
mynetworks = 192.168.1.0/24, 127.0.0.0/8, 192.168.2.0/24 192.168.3.0/24
mynetworks_style = subnet
myorigin = $mydomain
newaliases_path = /usr/bin/newaliases.postfix
non_smtpd_milters = inet:localhost:11332
postscreen_access_list = permit_mynetworks, 
cidr:/etc/postfix/postscreen_access.cidr
postscreen_bare_newline_action = drop
postscreen_bare_newline_enable = yes
postscreen_blacklist_action = drop
postscreen_dnsbl_action = drop
postscreen_dnsbl_sites = dul.dnsbl.sorbs.net*2, ix.dnsbl.manitu.net*2, 
zen.spamhaus.org*2
postscreen_dnsbl_threshold = 2
postscreen_greet_action = drop
postscreen_greet_banner = Famillie Reschke SMTP Service
postscreen_non_smtp_command_enable = yes
postscreen_pipelining_action = drop
postscreen_pipelining_enable = yes
queue_directory = /var/spool/postfix
readme_directory = /usr/share/doc/postfix/README_FILES
relay_domains = mysql:/etc/postfix/mysql_relay_domains_maps.cf
sample_directory = /usr/share/doc/postfix/samples
sender_canonical_maps = hash:/etc/postfix/sender_canonical_maps
sendmail_path = /usr/sbin/sendmail.postfix
setgid_group = postdrop
smtp_tls_CAfile = /etc/letsencrypt/live/www.rirasoft.de/fullchain.pem
smtp_tls_exclude_ciphers = RC4, aNULL
smtp_tls_loglevel = 1
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3
smtp_tls_note_starttls_offer = yes
smtp_tls_protocols = !SSLv2, !SSLv3
smtp_tls_security_level = may
smtp_use_tls = yes
smtpd_banner = $myhostname ESMTP
smtpd_hard_error_limit = 1
smtpd_milters = inet:localhost:11332
smtpd_recipient_restrictions = check_recipient_access 
hash:/etc/postfix/recipient-rfc, reject_non_fqdn_sender, 
reject_non_fqdn_recipient, reject_unknown_recipient_domain, 
permit_mynetworks, reject_sender_login_mismatch, permit_sasl_auth
enticated, reject_unknown_sender_domain, reject_unauth_destination, 
reject_multi_recipient_bounce, reject_unlisted_recipient, 
reject_invalid_helo_hostname, reject_unknown_client_hostname, 
reject_unknown_reverse_client_hostname, reject_u
nauth_pipelining, reject_non_fqdn_hostname, reject_unlisted_sender, 
permit_tls_clientcerts, check_sender_mx_access 
cidr:/etc/postfix/bogon_networks.cidr, check_sender_ns_access 
hash:/etc/postfix/bogus_dns, reject_rbl_client zen.spamhaus
.org=127.0.0.[2..11], reject_rbl_client ix.dnsbl.manitu.net, permit
smtpd_relay_restrictions = permit_sasl_authenticated, permit_mynetworks, 
reject_unauth_destination
smtpd_sasl_auth_enable = yes
smtpd_sasl_authenticated_header = no
smtpd_sasl_local_domain = rirasoft.de
smtpd_sasl_path = private/auth
smtpd_sasl_security_options = noanonymous, noplaintext
smtpd_sasl_tls_security_options = noanonymous
smtpd_sasl_type = dovecot
smtpd_sender_login_maps = mysql:/etc/postfix/mysql_virtual_alias_maps.cf
smtpd_sender_restrictions = regexp:/etc/postfix/sender_access.regexp, 
check_sender_access hash:/etc/postfix/sender_access
smtpd_tls_ask_ccert = yes
smtpd_tls_auth_only = yes
smtpd_tls_cert_file = /etc/letsencrypt/live/www.rirasoft.de/fullchain.pem
smtpd_tls_dh1024_param_file = /etc/postfix/dh_1024.pem
smtpd_tls_dh512_param_file = /etc/postfix/dh_512.pem
smtpd_tls_eecdh_grade = strong
smtpd_tls_exclude_ciphers = RC4, aNULL
smtpd_tls_key_file = /etc/letsencrypt/live/www.rirasoft.de/privkey.pem
smtpd_tls_loglevel = 1
smtpd_tls_mandatory_ciphers = medium
smtpd_tls_mandatory_exclude_ciphers = aNULL, eNULL, EXPORT, DES, RC4, 
MD5, PSK, aECDH, EDH-DSS-DES-CBC3-SHA, EDH-RSA-DES-CDC3-SHA, KRB5-DE5, 
CBC3-SHA
smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
smtpd_tls_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
smtpd_tls_received_header = yes
smtpd_tls_security_level = may
smtpd_tls_session_cache_timeout = 3600s
smtpd_use_tls = yes
tls_medium_cipherlist = 
ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES2
56-GCM-SHA384
tls_preempt_cipherlist = no
tls_random_source = dev:/dev/urandom
unknown_address_reject_code = 550
unknown_client_reject_code = 550
unknown_hostname_reject_code = 550
unknown_local_recipient_reject_code = 550
unverified_recipient_reject_code = 577
unverified_sender_reject_code = 554
virtual_alias_maps = mysql:/etc/postfix/mysql_virtual_alias_maps.cf
virtual_gid_maps = static:901
virtual_mailbox_base = /vmail
virtual_mailbox_domains = mysql:/etc/postfix/mysql_virtual_domains_maps.cf
virtual_mailbox_limit = 2048576000
virtual_mailbox_maps = mysql:/etc/postfix/mysql_virtual_mailbox_maps.cf
virtual_minimum_uid = 901
virtual_uid_maps = static:901
[root at linuxserver1 postfix]#


Gruß

Andreas
-------------- nächster Teil --------------
Ein Dateianhang mit HTML-Daten wurde abgetrennt...
URL: <https://listi.jpberlin.de/pipermail/postfixbuch-users/attachments/20211111/29577296/attachment-0001.htm>


Mehr Informationen über die Mailingliste Postfixbuch-users