summaryrefslogtreecommitdiffstats
path: root/roles/MX/templates/etc/postfix/main.cf.j2
blob: a2cc2a8c009c2fc2c17c055da6f99fd52184b95b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
########################################################################
# Mail eXchange (MX) configuration
#
# {{ ansible_managed }}
# Do NOT edit this file directly!

smtpd_banner        = $myhostname ESMTP $mail_name (Debian/GNU)
biff                = no
readme_directory    = no
compatibility_level = 2
smtputf8_enable     = no

delay_warning_time     = 4h
maximal_queue_lifetime = 5d

myorigin            = /etc/mailname
myhostname          = mx{{ mxno | default('') }}.$mydomain
mydomain            = fripost.org
append_dot_mydomain = no

mynetworks_style = host

queue_directory       = /var/spool/postfix-{{ postfix_instance[inst].name }}
data_directory        = /var/lib/postfix-{{ postfix_instance[inst].name }}
multi_instance_group  = {{ postfix_instance[inst].group | default('') }}
multi_instance_name   = postfix-{{ postfix_instance[inst].name }}
multi_instance_enable = yes

# No local delivery
mydestination        =
local_transport      = error:5.1.1 Mailbox unavailable
alias_maps           =
alias_database       =
local_recipient_maps =

message_size_limit  = 67108864
recipient_delimiter = +

# Forward everything to our internal outgoing proxy
relayhost     = [{{ postfix_instance.out.addr | ipaddr }}]:{{ postfix_instance.out.port }}
relay_domains =


# Virtual transport
# We use a dedicated "virtual" domain to decongestion potential
# bottlenecks on trivial_rewrite(8) due to slow LDAP lookups in
# tranport_maps.
virtual_transport     = error:5.1.1 Virtual transport unavailable
virtual_alias_domains = !lmdb:$config_directory/virtual/transport
                        ldap:$config_directory/virtual/domains.cf
virtual_alias_maps    = pcre:$config_directory/virtual/reserved_alias.pcre
                        # unless there is a matching user/alias/list...
                        ldap:$config_directory/virtual/mailbox.cf
                        ldap:$config_directory/virtual/alias.cf
                        ldap:$config_directory/virtual/list.cf
                        # ...we resolve alias domains and catch alls
                        ldap:$config_directory/virtual/alias_domains.cf
                        ldap:$config_directory/virtual/catchall.cf
transport_maps        = lmdb:$config_directory/virtual/transport


# Don't rewrite remote headers
local_header_rewrite_clients               =
# Pass the client information along to the content filter
smtp_send_xforward_command                 = yes
# Avoid splitting the envelope and scanning messages multiple times
smtp_destination_recipient_limit           = 1000
reserved-alias_destination_recipient_limit = 1
# Tolerate occasional high latency
smtp_data_done_timeout           = 1200s


smtp_tls_security_level         = none
smtpd_tls_security_level        = may
smtpd_tls_ciphers               = medium
smtpd_tls_protocols             = !SSLv2, !SSLv3
smtpd_tls_cert_file             = $config_directory/ssl/mx.fripost.org.pem
smtpd_tls_key_file              = $config_directory/ssl/mx.fripost.org.key
smtpd_tls_dh1024_param_file     = /etc/ssl/dhparams.pem
smtpd_tls_CApath                = /etc/ssl/certs/
smtpd_tls_session_cache_database=
smtpd_tls_received_header       = yes


# http://en.linuxreviews.org/HOWTO_Stop_spam_using_Postfix
# http://www.howtoforge.com/block_spam_at_mta_level_postfix

strict_rfc821_envelopes = yes
smtpd_delay_reject      = yes
disable_vrfy_command    = yes

postscreen_access_list =
    permit_mynetworks
    cidr:$config_directory/access-list.cidr
postscreen_dnsbl_whitelist_threshold = -1
postscreen_cache_map = lmdb:$data_directory/postscreen_cache

postscreen_blacklist_action = drop
postscreen_dnsbl_threshold  = 8
postscreen_dnsbl_action     = enforce
postscreen_dnsbl_sites      =
    zen.spamhaus.org=127.0.0.[10;11]*8
    zen.spamhaus.org=127.0.0.[4..7]*6
    zen.spamhaus.org=127.0.0.3*4
    zen.spamhaus.org=127.0.0.2*3
    #swl.spamhaus.org*-4
    b.barracudacentral.org=127.0.0.2*7
    bl.mailspike.net=127.0.0.2*5
    bl.mailspike.net=127.0.0.[10..12]*4
    wl.mailspike.net=127.0.0.[18..20]*-2
    bl.spameatingmonkey.net=127.0.0.2*4
    bl.spamcop.net=127.0.0.2*2
    dnsbl.sorbs.net=127.0.0.10*8
    dnsbl.sorbs.net=127.0.0.5*6
    dnsbl.sorbs.net=127.0.0.7*3
    dnsbl.sorbs.net=127.0.0.8*2
    dnsbl.sorbs.net=127.0.0.6*2
    dnsbl.sorbs.net=127.0.0.9*2
    list.dnswl.org=127.0.[0..255].0*-2
    list.dnswl.org=127.0.[0..255].1*-3
    list.dnswl.org=127.0.[0..255].[2..3]*-4

postscreen_greet_action         = enforce
postscreen_whitelist_interfaces = static:all


smtpd_client_restrictions =
    permit_mynetworks

smtpd_helo_required     = yes
smtpd_helo_restrictions =
    permit_mynetworks
    reject_non_fqdn_helo_hostname
    reject_invalid_helo_hostname

smtpd_sender_restrictions =
    reject_non_fqdn_sender
    reject_unknown_sender_domain

smtpd_relay_restrictions =
    reject_non_fqdn_recipient
    permit_mynetworks
    reject_unauth_destination
    reject_unlisted_recipient

smtpd_recipient_restrictions =
    check_client_access cidr:$config_directory/access-list.cidr
    check_recipient_access ldap:$config_directory/reject-unknown-client-hostname.cf
    reject_rhsbl_reverse_client dbl.spamhaus.org=127.0.1.[2..99]
    reject_rhsbl_sender         dbl.spamhaus.org=127.0.1.[2..99]
    # defer if "abused legit": DBL return code in the 127.0.1.100+ range
    defer_if_reject
    reject_rhsbl_reverse_client dbl.spamhaus.org=127.0.1.[100..254]
    reject_rhsbl_sender         dbl.spamhaus.org=127.0.1.[100..254]

smtpd_data_restrictions =
    reject_unauth_pipelining

# vim: set filetype=pfmain :