|
- # See /usr/share/postfix/main.cf.dist for a commented, more complete version
-
- # Debian specific: Specifying a file name will cause the first
- # line of that file to be used as the name. The Debian default
- # is /etc/mailname.
- myorigin = /etc/mailname
-
- smtpd_banner = $myhostname ESMTP $mail_name (Debian/GNU)
- biff = no
-
- # appending .domain is the MUA's job.
- append_dot_mydomain = no
-
- # Uncomment the next line to generate "delayed mail" warnings
- #delay_warning_time = 4h
-
- readme_directory = no
-
- # See http://www.postfix.org/COMPATIBILITY_README.html -- default to 2 on
- # fresh installs.
- compatibility_level = 2
-
- # TLS parameters
- smtpd_tls_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem
- smtpd_tls_key_file=/etc/ssl/private/ssl-cert-snakeoil.key
- smtpd_use_tls=yes
- smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
- smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
-
- # See /usr/share/doc/postfix/TLS_README.gz in the postfix-doc package for
- # information on enabling SSL in the smtp client.
-
- myhostname = {{mailname}}
- alias_maps = hash:/etc/aliases
- alias_database = hash:/etc/aliases
- mydestination = $myhostname, tg-infra-dev-mail-1, localhost.localdomain, , localhost
- relayhost =
- mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
- mailbox_size_limit = 0
- recipient_delimiter = +
- inet_interfaces = all
- inet_protocols = all
-
- # some rules from http://www.postfix.org/SMTPD_ACCESS_README.html
- #smtpd_client_restrictions = permit_mynetworks, reject
- #smtpd_helo_restrictions = reject_unknown_helo_hostname
- #smtpd_sender_restrictions = reject_unknown_sender_domain
- smtpd_data_restrictions = reject_unauth_pipelining
-
- smtpd_recipient_restrictions =
- permit_mynetworks,
- permit_sasl_authenticated,
- reject_rbl_client zen.spamhaus.org,
- reject_rhsbl_reverse_client dbl.spamhaus.org,
- reject_rhsbl_helo dbl.spamhaus.org,
- reject_rhsbl_sender dbl.spamhaus.org
-
- smtpd_relay_restrictions =
- permit_mynetworks,
- permit_sasl_authenticated,
- defer_unauth_destination
-
- virtual_mailbox_domains = proxy:mysql:/etc/postfix/sql/mysql_virtual_domains_maps.cf
- virtual_alias_maps =
- proxy:mysql:/etc/postfix/sql/mysql_virtual_alias_maps.cf,
- proxy:mysql:/etc/postfix/sql/mysql_virtual_alias_domain_maps.cf,
- proxy:mysql:/etc/postfix/sql/mysql_virtual_alias_domain_catchall_maps.cf
- virtual_mailbox_maps =
- proxy:mysql:/etc/postfix/sql/mysql_virtual_mailbox_maps.cf,
- proxy:mysql:/etc/postfix/sql/mysql_virtual_alias_domain_mailbox_maps.cf
-
- # use dovecot lmtp for mail transport
- virtual_transport = lmtp:unix:private/dovecot-lmtp
-
- smtpd_sasl_type = dovecot
- smtpd_sasl_path = private/auth
- smtpd_sasl_auth_enable = yes
|