Email - exceptions_encrypt_to.txt (recipients never encrypted)
Email Solution · Config document · referenced from Automatic email encryption
The list of envelope recipients (RCPT TO) whose mail the encryption filter sends on as it is. It holds one entry, the site's own mail domain: mail that stays inside, on the mailbox server, is not encrypted.
| Item | Value |
|---|---|
| Path on the server | /var/spool/postfix/bash-postfix-encrypt-filter/exceptions_encrypt_to.txt |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001, identical (diff is empty) |
| Owner and mode | bash-postfix-encrypt-filter:root, 400 |
| Read by | bash-postfix-encrypt-filter.sh, on every message; no reload needed |
| Format | one entry per line, lowercase, matched against the end of the recipient address |
| Site 1 | @ad.example.net, according to the example in the header of the script |
The file
@ad-dc2.example.net
Reading it today
- It is a suffix match. The script tests
[[ $INSPECT_EMAIL_TO == *$i ]], so@ad-dc2.example.netcovers the whole domain. A full address works too, but it also matches every longer address that ends the same way: an entryann@example.orgwould exemptjoann@example.orgas well. - The entry is a shell pattern.
$iis not quoted, so*,?and[in an entry would be read as wildcards. - Not synchronized. Like the sender list, this file is outside the two synchronized directories, and nothing synchronizes it between the nodes.