summaryrefslogtreecommitdiffstats
path: root/roles/MX/templates/etc/postfix/main.cf.j2
blob: b9f7c09eb2929c8bea56b2ba9f732130174a3726 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
########################################################################
# MX configuration
#
# {{ ansible_managed }}
# Do NOT edit this file directly!

smtpd_banner     = $myhostname ESMTP $mail_name (Debian/GNU)
biff             = no
readme_directory = no
mail_owner       = postfix

delay_warning_time     = 4h
maximal_queue_lifetime = 5d

myorigin            = /etc/mailname
myhostname          = mx{{ mxno | default('') }}.$mydomain
mydomain            = fripost.org
append_dot_mydomain = no

# Turn off all TCP/IP listener ports except that necessary for the mail
# exchange.
master_service_disable = !smtp.inet inet

queue_directory       = /var/spool/postfix-{{ postfix_instance[inst].name }}
data_directory        = /var/lib/postfix-{{ postfix_instance[inst].name }}
multi_instance_group  = {{ postfix_instance[inst].group | default('') }}
multi_instance_name   = postfix-{{ postfix_instance[inst].name }}
multi_instance_enable = yes

# This server is a Mail eXchange
mynetworks_style = host
inet_interfaces  = all

# No local delivery
mydestination        =
local_transport      = error:5.1.1 Mailbox unavailable
alias_maps           =
alias_database       =
local_recipient_maps =

message_size_limit  = 67108864
recipient_delimiter = +

# Forward everything to our internal outgoing proxy
{% if 'out' in group_names %}
relayhost     = [127.0.0.1]:{{ postfix_instance.out.port }}
{% else %}
relayhost     = [outgoing.fripost.org]:{{ postfix_instance.out.port }}
{% endif %}
relay_domains =


# Virtual transport
# We use a dedicated "virtual" domain to decongestion potential
# bottlenecks on trivial_rewrite(8) due to slow LDAP lookups in
# tranport_maps.
virtual_transport     = error:5.1.1 Virtual transport unavailable
virtual_alias_domains = !cdb:$config_directory/virtual/transport
                        ldap:$config_directory/virtual/domains.cf
virtual_alias_maps    = pcre:$config_directory/virtual/reserved_alias.pcre
                        # unless there is a matching user/alias/list...
                        ldap:$config_directory/virtual/mailbox.cf
                        ldap:$config_directory/virtual/alias.cf
                        ldap:$config_directory/virtual/list.cf
                        # ...we resolve alias domains and catch alls
                        ldap:$config_directory/virtual/alias_domains.cf
                        ldap:$config_directory/virtual/catchall.cf
transport_maps        = cdb:$config_directory/virtual/transport


# Don't rewrite remote headers
local_header_rewrite_clients               =
# Pass the client information along to the content filter
smtp_send_xforward_command                 = yes
# Avoid splitting the envelope and scanning messages multiple times
smtp_destination_recipient_limit           = 1000
reserved-alias_destination_recipient_limit = 1
# Tolerate occasional high latency
smtp_data_done_timeout           = 1200s


{% if 'out' in group_names %}
smtp_tls_security_level         = none
smtp_bind_address               = 127.0.0.1
{% else %}
smtp_tls_security_level         = encrypt
smtp_tls_cert_file              = /etc/postfix/ssl/{{ ansible_fqdn }}.pem
smtp_tls_key_file               = /etc/postfix/ssl/{{ ansible_fqdn }}.key
smtp_tls_session_cache_database = btree:$data_directory/smtp_tls_session_cache
smtp_tls_policy_maps            = cdb:/etc/postfix/tls_policy
smtp_tls_fingerprint_digest     = sha256
{% endif %}

smtpd_tls_security_level        = may
smtpd_tls_exclude_ciphers       = EXPORT, LOW, MEDIUM, aNULL, eNULL, DES, RC4, MD5
smtpd_tls_cert_file             = /etc/ssl/certs/ssl-cert-snakeoil.pem
smtpd_tls_key_file              = /etc/ssl/private/ssl-cert-snakeoil.key
smtpd_tls_dh1024_param_file     = /etc/ssl/private/dhparams.pem
smtpd_tls_CApath                = /etc/ssl/certs/
smtpd_tls_session_cache_database= btree:$data_directory/smtpd_tls_session_cache
smtpd_tls_received_header       = yes
smtpd_tls_ask_ccert             = yes


# http://en.linuxreviews.org/HOWTO_Stop_spam_using_Postfix
# http://www.howtoforge.com/block_spam_at_mta_level_postfix

strict_rfc821_envelopes = yes
smtpd_delay_reject      = yes
disable_vrfy_command    = yes

# UCE control
invalid_hostname_reject_code        = 554
multi_recipient_bounce_reject_code  = 554
non_fqdn_reject_code                = 554
relay_domains_reject_code           = 554
unknown_address_reject_code         = 554
unknown_client_reject_code          = 554
unknown_hostname_reject_code        = 554
unknown_local_recipient_reject_code = 554
unknown_relay_recipient_reject_code = 554
unknown_virtual_alias_reject_code   = 554
unknown_virtual_mailbox_reject_code = 554

postscreen_blacklist_action = drop
postscreen_dnsbl_threshold  = 3
postscreen_dnsbl_action     = enforce
postscreen_dnsbl_sites      =
    zen.spamhaus.org*3
    swl.spamhaus.org*-4
    b.barracudacentral.org*2
    bl.spameatingmonkey.net*2
    bl.spamcop.net
    dnsbl.sorbs.net
    list.dnswl.org=127.[0..255].[0..255].0*-2
    list.dnswl.org=127.[0..255].[0..255].1*-3
    list.dnswl.org=127.[0..255].[0..255].[2..255]*-4

postscreen_greet_action          = enforce
postscreen_whitelist_interfaces = !88.80.11.28 ![2a00:16b0:242:13::de30] static:all

smtpd_client_restrictions =
    permit_mynetworks

smtpd_helo_required     = yes
smtpd_helo_restrictions =
    permit_mynetworks
    reject_non_fqdn_helo_hostname
    reject_invalid_helo_hostname

smtpd_sender_restrictions =
    reject_non_fqdn_sender

smtpd_relay_restrictions =
    reject_non_fqdn_recipient
    permit_mynetworks
    reject_unauth_destination
    reject_unlisted_recipient

smtpd_data_restrictions =
    reject_unauth_pipelining

# vim: set filetype=pfmain :