LINUXOR.SK ... open source notes ...

Email - Postfix restricted_senders table

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Internal servers: Postfix

An access table keyed by sender. It sends every sender address of the site's own domain into the restriction class local_only, which permits recipients of the own domain and rejects the rest. Senders in the AD group ESMTP_ACCESS never get here, because the LDAP lookup in front of it has already permitted them.

ItemValue
Path on the server/etc/postfix/restricted_senders
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002, identical
Referenced bycheck_sender_access hash:/etc/postfix/restricted_senders in smtpd_recipient_restrictions
Needssmtpd_restriction_classes = local_only in main.cf
Activated withpostmap /etc/postfix/restricted_senders; the install notes do not record the command

The file

ini
###################################################################################################
# Domain/mail_address	Restriction class
###################################################################################################
ad-dc2.example.net		local_only

Differences on the other hosts

diff shows none between the three internal servers of site 2. For site 1 the first design shows the same file with ad.example.net.

The table matches the sender domain only. A sender address of any other domain is not restricted by it and falls through to the rest of smtpd_recipient_restrictions.

Checked against Postfix 3.11

As builtToday
hash: table, built with postmap into a Berkeley DB fileRHEL 10 no longer provides the Berkeley DB libraries; the default table type of its Postfix is lmdb: and existing tables have to be converted. Postfix 3.11 describes the migration in NON_BERKELEYDB_README
smtpd_restriction_classes = local_onlystill valid
relay control only in smtpd_recipient_restrictionssmtpd_relay_restrictions is the preferred place for relay permission rules; the list as built still works

The content needs no change; the table type does.

← solutionz