Email - Postfix main.cf, mailbox server
Email Solution · Config document · referenced from Mailbox server
The Postfix configuration of the third internal server, the one that holds the mailboxes. It is the main.cf of the internal pair with the cluster and the encryption filter taken out and the routing turned around: mail for the site's own domain goes to Dovecot, everything else to the pair. In the stock blocks at the top (down to the install-time information) the distribution's comments are left out; from TRANSPORT on the file is complete.
| Item | Value |
|---|---|
| Path on the server | /etc/postfix/main.cf |
| Shown here | DC2-A-VCMSX002 |
| Counterpart | Postfix main.cf, internal servers |
| Lookup tables | transport, virtual_domains, restricted_senders (hash) and five ad_*.cf files (LDAP) |
| Activated with | systemctl start postfix and systemctl enable postfix; later changes with postfix reload |
| Software | Postfix 2.10.1 from the RHEL 7 repository |
The file
###################################################################### # LOCAL PATHNAME INFORMATION ###################################################################### queue_directory = /var/spool/postfix command_directory = /usr/sbin daemon_directory = /usr/libexec/postfix data_directory = /var/lib/postfix ###################################################################### # QUEUE AND PROCESS OWNERSHIP ###################################################################### mail_owner = postfix ###################################################################### # INTERNET HOST AND DOMAIN NAMES ###################################################################### myhostname = dc2-a-vcmsx002.adm.example.net mydomain = ad-dc2.example.net ###################################################################### # SENDING MAIL ###################################################################### myorigin = $mydomain ###################################################################### # RECEIVING MAIL ###################################################################### inet_interfaces = all inet_protocols = all mydestination = $myhostname, localhost.$mydomain, localhost ###################################################################### # REJECTING MAIL FOR UNKNOWN LOCAL USERS ###################################################################### unknown_local_recipient_reject_code = 550 ###################################################################### # ALIAS DATABASE ###################################################################### alias_maps = hash:/etc/aliases alias_database = hash:/etc/aliases ###################################################################### # DELIVERY TO MAILBOX ###################################################################### home_mailbox = Maildir/ ###################################################################### # SHOW SOFTWARE VERSION OR NOT ###################################################################### smtpd_banner = $myhostname ESMTP ###################################################################### # DEBUGGING CONTROL ###################################################################### debug_peer_level = 2 debugger_command = PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin ddd $daemon_directory/$process_name $process_id & sleep 5 ###################################################################### # INSTALL-TIME CONFIGURATION INFORMATION ###################################################################### sendmail_path = /usr/sbin/sendmail.postfix newaliases_path = /usr/bin/newaliases.postfix mailq_path = /usr/bin/mailq.postfix setgid_group = postdrop html_directory = no manpage_directory = /usr/share/man sample_directory = /usr/share/doc/postfix-2.10.1/samples readme_directory = /usr/share/doc/postfix-2.10.1/README_FILES ###################################################################### # TRANSPORT ###################################################################### # Definition of transports transport_maps = hash:/etc/postfix/transport dovecot_destination_recipient_limit = 1 ###################################################################### # RELAYHOST (SMARTHOST) ###################################################################### # Definition of relayhost relayhost = [10.12.19.41] # Definition of backup relayhost smtp_fallback_relay = [10.12.19.42] ###################################################################### # SASL ###################################################################### smtpd_sasl_type = dovecot smtpd_sasl_path = private/auth smtpd_sasl_auth_enable = yes smtpd_sasl_security_options = noanonymous ###################################################################### # RESTRICTIONS ###################################################################### # Definition of mynetworks mynetworks = 10.12.19.33/32, 10.12.19.34/32, 10.12.19.35/32, 10.12.19.41/32, 10.12.19.42/32 # AD users which are in the AD group "ESMTP_ACCESS" are allowed to send emails to external domains (ad_allow_external_emails.cf). # Others AD users in domain "ad.example.net" are not allowed to send emails to external domains (restricted_senders). # Authenticated users are allowed to send emails (permit_sasl_authenticated). smtpd_recipient_restrictions = reject_non_fqdn_recipient, reject_unknown_recipient_domain, check_sender_access ldap:/etc/postfix/ad_allow_external_emails.cf, check_sender_access hash:/etc/postfix/restricted_senders, permit_sasl_authenticated, permit_mynetworks, reject_unauth_destination, reject smtpd_client_restrictions= permit_sasl_authenticated, permit_mynetworks, reject # AD users which are in the AD group "SMTP_ACCESS" are allowed to send emails to internal domains (ad_allow_internal_emails.cf). # Using email address (MAIL FROM) which is different from login credentials (user@domain) is not allowed (reject_sender_login_mismatch). smtpd_sender_restrictions= check_sender_access ldap:/etc/postfix/ad_allow_internal_emails.cf, permit_mynetworks, reject_sender_login_mismatch, reject # RESTRICTION CLASSES smtpd_restriction_classes = local_only local_only = check_recipient_access hash:/etc/postfix/virtual_domains, reject ###################################################################### # NOTIFICATION ###################################################################### # Configure NDR (NonDeliveryReports) to by sent to specific email address #notify_classes = resource, software, bounce #bounce_notice_recipient = customerportal@example.net ###################################################################### # VIRTUAL DOMAINS, USERS, MAILBOXES, GROUPS ###################################################################### # Valid virtual domains virtual_mailbox_domains = hash:/etc/postfix/virtual_domains # LDAP (Active Directory) users/senders smtpd_sender_login_maps = proxy:ldap:/etc/postfix/ad_sender_login_maps.cf # LDAP (Active Directory) mailboxes virtual_mailbox_maps = proxy:ldap:/etc/postfix/ad_virtual_mailbox_maps.cf # LDAP (Active Directory) lists/groups virtual_alias_maps = proxy:ldap:/etc/postfix/ad_virtual_group_maps.cf ###################################################################### # TLS ###################################################################### # Enable TLS (required to encrypt the plaintext SASL authentication) smtpd_tls_security_level = encrypt # Only offer SASL in a TLS session smtpd_tls_auth_only = yes # Certification Authority # smtpd_tls_CAfile = /etc/postfix/ssl/ca.cer # Public Certificate smtpd_tls_cert_file = /etc/pki/tls/certs/dc2-a-vcmsx002.adm.example.net.crt # Private Key (without passphrase) smtpd_tls_key_file = /etc/pki/tls/private/dc2-a-vcmsx002.adm.example.net.key # Randomizer for key creation tls_random_source = dev:/dev/urandom # TLS related logging (set to 2 for debugging) smtpd_tls_loglevel = 0 # Avoid Denial-Of-Service-Attacks smtpd_client_new_tls_session_rate_limit = 10 # Activate TLS Session Cache smtpd_tls_session_cache_database = btree:/etc/postfix/smtpd_session_cache # Deny some TLS-Ciphers smtpd_tls_exclude_ciphers = EXP EDH-RSA-DES-CBC-SHA ADH-DES-CBC-SHA DES-CBC-SHA SEED-SHA # Diffie-Hellman Parameters for Perfect Forward Secrecy # Can be created with: # openssl dhparam -2 -out dh_512.pem 512 # openssl dhparam -2 -out dh_1024.pem 1024 # openssl dhparam -2 -out dh_2048.pem 2048 smtpd_tls_dh512_param_file = /etc/pki/tls/certs/dh_512.pem smtpd_tls_dh1024_param_file = /etc/pki/tls/certs/dh_1024.pem ###################################################################### # HARDENING ###################################################################### # CFG-ON -> Disable the SMTP VRFY command. This stops some techniques used to harvest email addresses. disable_vrfy_command=yes # CFG-ON -> Require that a remote SMTP client sends HELO or EHLO before commencing a MAIL transaction. smtpd_helo_required=yes # CFG-ON -> Limit Denial of Service Attacks default_process_limit = 100 smtpd_client_connection_count_limit = 10 smtpd_client_connection_rate_limit = 30 queue_minfree = 31457280 header_size_limit = 51200 message_size_limit = 20971520 smtpd_recipient_limit = 100 # CFG-ON -> Require that addresses received in SMTP MAIL FROM and RCPT TO commands are enclosed # CFG-ON -> with <>, and that those addresses do not contain RFC 822 style comments or phrases. strict_rfc821_envelopes = yes # CFG-ON -> Reject the request when the client sends SMTP commands ahead of time where it is # CFG-ON -> not allowed, or when the client sends SMTP commands ahead of time without knowing that # CFG-ON -> Postfix actually supports ESMTP command pipelining. This stops mail from bulk mail # CFG-ON -> software that improperly uses ESMTP command pipelining in order to speed up deliveries. smtpd_data_restrictions = reject_unauth_pipelining # CFG-ON -> List of commands that cause the Postfix SMTP server to immediately terminate the # CFG-ON -> session with a 221 code. smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASS # CFG-ON -> Appending .domain is the MUA's job. append_dot_mydomain = no # CFG-ON -> Turning off SSLv2 / v3 due to the DROWN attack smtp_tls_mandatory_protocols = !SSLv2, !SSLv3 smtp_tls_protocols = !SSLv2, !SSLv3 lmtp_tls_mandatory_protocols = !SSLv2, !SSLv3 lmtp_tls_protocols = !SSLv2, !SSLv3 smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3 smtpd_tls_protocols = !SSLv2, !SSLv3 # CFG-ON -> Enable using TLS if remote server supports it smtp_tls_security_level = may
Differences from the internal pair
| Line | DC2-A-VCMSX001 | DC2-A-VCMSX002 |
|---|---|---|
myhostname | dc2-a-vcmsx001.adm.example.net | dc2-a-vcmsx002.adm.example.net |
smtp_bind_address, smtp_bind_address6 | the VIP, 10.12.19.33 and 2001:db8:a2:b6f::f:1 | not set |
relayhost | [10.12.19.34], the first relay | [10.12.19.41], node A of the pair |
smtp_fallback_relay | [10.12.19.35], the second relay | [10.12.19.42], node B of the pair |
mynetworks | the two relays and the mailbox server | the VIP, the two relays and the two nodes of the pair |
smtpd_tls_cert_file, smtpd_tls_key_file | files named after dc2-a-vcmsx001 | files named after dc2-a-vcmsx002 |
bash-postfix-encrypt-filter_destination_recipient_limit | 1 | not set, there is no filter here |
The rest of what diff prints is white space. One comment differs as well: the pair says "AD users in domain ad-dc2.example.net", this file still says ad.example.net, the domain of site 1 from which the file was copied. The /etc/postfix/transport behind transport_maps is where the two servers really part: transport, mailbox server.
Checked against Postfix 3.11.7
| As built | Today |
|---|---|
hash: tables, btree: session cache | RHEL 10 has no Berkeley DB; the tables must become lmdb:, and Postfix 3.11 ships a migration guide (NON_BERKELEYDB_README) |
smtpd_tls_dh512_param_file | silently ignored since 3.6 |
smtpd_tls_dh1024_param_file | deprecated since 3.9: leave at default |
!SSLv2, !SSLv3 protocol lists | still accepted; the preferred form is a lower bound such as >=TLSv1.2. The as-built value allows TLS 1.0 and 1.1 |
smtpd_tls_cert_file, smtpd_tls_key_file | still valid; smtpd_tls_chain_files is preferred since 3.4 |
smtpd_tls_exclude_ciphers | still valid; upstream advises not to exclude ciphers unless it is essential |
relay rules inside smtpd_recipient_restrictions | still work; smtpd_relay_restrictions is the preferred place and is evaluated first |
smtpd_data_restrictions = reject_unauth_pipelining | still valid; since 3.9 smtpd_forbid_unauth_pipelining = yes is the default as well |
smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASS | still valid; the default since 3.7 adds a pattern for non-command input that this value drops |
append_dot_mydomain = no, smtp_tls_security_level = may | both are now defaults (3.0 and 3.11) |
no compatibility_level | introduced in 3.0; without it Postfix runs with backwards-compatible defaults and logs that it does |
Postfix 3.11.7 was announced on 2026-09-07. Nothing in the file stops a current Postfix from starting except the Berkeley DB tables on a system without that library. Postfix 3.9 added defences against SMTP smuggling that are on by default (smtpd_forbid_bare_newline = normalize). dovecot_destination_recipient_limit = 1 is still required for the D and O flags of the pipe transport.