[Service] Type=simple User=opendmarc ExecStart= ExecStart=/usr/sbin/opendmarc -f -p fd:3 StandardOutput=journal SyslogFacility=mail RuntimeDirectory=opendmarc # Hardening NoNewPrivileges=yes PrivateDevices=yes ProtectHome=yes ProtectSystem=strict ProtectControlGroups=yes ProtectKernelModules=yes ProtectKernelTunables=yes