Postfix 06 - body_checks and header_checks
Postfix Mail Server Learning · Previous: Postfix + Cyrus + MySQL · Next: Notes on MDAs (procmail and maildrop)
The Slovak original of this document: Postfix 06 - body_checks a header_checks (slovensky).
BODY_CHECKS & HEADER_CHECKS
===============================
Checking whether body_checks and header_checks are currently in use
-------------------------------------------------------------------
# su - zimbra
# postconf | grep _checks
Required output
---------------
body_checks = regexp:/opt/zimbra/postfix/conf/body_checks
header_checks = regexp:/opt/zimbra/postfix/conf/header_checks
Change (addition) to body_checks
--------------------------------
# nano /opt/zimbra/postfix/conf/body_checks
-------------------------------------------
# the banned words and patterns will go here
#/http:\/\/.*\.info/ REJECT dotinfo
/lottery/ REJECT ban_code 555_101
/Viagra/ REJECT ban_code 555_102
/with CIALIS/ REJECT ban_code 555_103
...
-------------------------------------------EOF->/opt/zimbra/postfix/conf/body_checks
Updating the body_checks database (run as the user root)
--------------------------------------------------------
# /opt/zimbra/postfix/sbin/postmap /opt/zimbra/postfix/conf/body_checks
# su - zimbra
# postfix reload
Change (addition) to header_checks
----------------------------------
# nano /opt/zimbra/postfix/conf/header_checks
---------------------------------------------
/FAMOUS/ REJECT ban_code 111_307_pokial_sa_domnievate_ze_vasa_posta_nie_ je_spam_volajte_0902980469
/Replica/ REJECT ban_code_111_308_pokial_sa_domnievate_ze_vasa_posta_nie_ je_spam_volajte_0902980469
/Legal software/ REJECT ban_code_111_309_pokial_sa_domnievate_ze_vasa_posta_nie_ je_spam_volajte_0902980469
/PenisLonger/ REJECT ban_code_111_310_pokial_sa_domnievate_ze_vasa_posta_nie_ je_spam_volajte_0902980469
...
-------------------------------------------EOF->/opt/zimbra/postfix/conf/header_checks
Updating the header_checks database (run as the user root)
--------------------------------------------------------
# /opt/zimbra/postfix/sbin/postmap /opt/zimbra/postfix/conf/header_checks
# su - zimbra
# postfix reloadCurrent practice (checked 2026-10)
noteThe article above is kept as it was written in 2010. This section lists what has changed since and what to do instead today.
- Zimbra paths and settings: the article edits files under
/opt/zimbra/postfix/conf/. On Zimbra 8.5 and later, keep your own rules in a separate file such as/opt/zimbra/conf/custom_header_checksand register it withzmprov mcf zimbraMtaHeaderChecks, as in the command below;body_checksis not enabled by default and is switched on through thepostfix_body_checkslocal config key. postmapon a regexp table:regexp:andpcre:tables are plain text files that Postfix reads directly, so there is nothing to build withpostmap;postfix reloadis enough.postmapis useful here only for testing a pattern withpostmap -q.- Unanchored words in
body_checks: Postfix checks one line at a time and does not decode the content, so/Viagra/never matches a base64 or quoted-printable encoded body and does match any legitimate mail that contains the word. The Postfix documentation describes these checks as a tool for stopping a specific outbreak, not as a spam filter; use the content filter (Amavis with SpamAssassin, which Zimbra ships) for spam. - Unanchored
header_checks:/FAMOUS/or/Replica/is tested against every header line, includingReceived:andMessage-ID:. Anchor the pattern to the header you mean, for example/^Subject:.*Replica/. REJECTwithout a trial run: use theWARNaction first; it only logs the match, so you can see what a new pattern would have rejected before it rejects real mail.
$ zmprov mcf zimbraMtaHeaderChecks 'pcre:/opt/zimbra/conf/postfix_header_checks pcre:/opt/zimbra/conf/custom_header_checks' $ postmap -q "Subject: Replica watches" pcre:/opt/zimbra/conf/custom_header_checks
Sources: