LINUXOR.SK ... open source notes ...

Email - Postfix main.cf, mailbox server

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Mailbox server

The Postfix configuration of the third internal server, the one that holds the mailboxes. It is the main.cf of the internal pair with the cluster and the encryption filter taken out and the routing turned around: mail for the site's own domain goes to Dovecot, everything else to the pair. In the stock blocks at the top (down to the install-time information) the distribution's comments are left out; from TRANSPORT on the file is complete.

ItemValue
Path on the server/etc/postfix/main.cf
Shown hereDC2-A-VCMSX002
CounterpartPostfix main.cf, internal servers
Lookup tablestransport, virtual_domains, restricted_senders (hash) and five ad_*.cf files (LDAP)
Activated withsystemctl start postfix and systemctl enable postfix; later changes with postfix reload
SoftwarePostfix 2.10.1 from the RHEL 7 repository

The file

ini
######################################################################
# LOCAL PATHNAME INFORMATION
######################################################################
queue_directory = /var/spool/postfix
command_directory = /usr/sbin
daemon_directory = /usr/libexec/postfix
data_directory = /var/lib/postfix

######################################################################
# QUEUE AND PROCESS OWNERSHIP
######################################################################
mail_owner = postfix

######################################################################
# INTERNET HOST AND DOMAIN NAMES
######################################################################
myhostname = dc2-a-vcmsx002.adm.example.net
mydomain = ad-dc2.example.net

######################################################################
# SENDING MAIL
######################################################################
myorigin = $mydomain

######################################################################
# RECEIVING MAIL
######################################################################
inet_interfaces = all
inet_protocols = all
mydestination = $myhostname, localhost.$mydomain, localhost

######################################################################
# REJECTING MAIL FOR UNKNOWN LOCAL USERS
######################################################################
unknown_local_recipient_reject_code = 550

######################################################################
# ALIAS DATABASE
######################################################################
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases

######################################################################
# DELIVERY TO MAILBOX
######################################################################
home_mailbox = Maildir/

######################################################################
# SHOW SOFTWARE VERSION OR NOT
######################################################################
smtpd_banner = $myhostname ESMTP

######################################################################
# DEBUGGING CONTROL
######################################################################
debug_peer_level = 2
debugger_command =
	 PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
	 ddd $daemon_directory/$process_name $process_id & sleep 5

######################################################################
# INSTALL-TIME CONFIGURATION INFORMATION
######################################################################
sendmail_path = /usr/sbin/sendmail.postfix
newaliases_path = /usr/bin/newaliases.postfix
mailq_path = /usr/bin/mailq.postfix
setgid_group = postdrop
html_directory = no
manpage_directory = /usr/share/man
sample_directory = /usr/share/doc/postfix-2.10.1/samples
readme_directory = /usr/share/doc/postfix-2.10.1/README_FILES

######################################################################
# TRANSPORT
######################################################################
# Definition of transports
transport_maps = hash:/etc/postfix/transport
dovecot_destination_recipient_limit = 1

######################################################################
# RELAYHOST (SMARTHOST)
######################################################################
# Definition of relayhost
relayhost = [10.12.19.41]

# Definition of backup relayhost
smtp_fallback_relay = [10.12.19.42]

######################################################################
# SASL
######################################################################
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous

######################################################################
# RESTRICTIONS
######################################################################
# Definition of mynetworks
mynetworks = 10.12.19.33/32, 10.12.19.34/32, 10.12.19.35/32, 10.12.19.41/32, 10.12.19.42/32

# AD users which are in the AD group "ESMTP_ACCESS" are allowed to send emails to external domains (ad_allow_external_emails.cf).
# Others AD users in domain "ad.example.net" are not allowed to send emails to external domains (restricted_senders).
# Authenticated users are allowed to send emails (permit_sasl_authenticated).
smtpd_recipient_restrictions =
	reject_non_fqdn_recipient,
	reject_unknown_recipient_domain,
	check_sender_access ldap:/etc/postfix/ad_allow_external_emails.cf,
	check_sender_access hash:/etc/postfix/restricted_senders,
	permit_sasl_authenticated,
	permit_mynetworks,
	reject_unauth_destination,
	reject

smtpd_client_restrictions=
	permit_sasl_authenticated,
	permit_mynetworks,
	reject

# AD users which are in the AD group "SMTP_ACCESS" are allowed to send emails to internal domains (ad_allow_internal_emails.cf).
# Using email address (MAIL FROM) which is different from login credentials (user@domain) is not allowed (reject_sender_login_mismatch).
smtpd_sender_restrictions=
	check_sender_access ldap:/etc/postfix/ad_allow_internal_emails.cf,
	permit_mynetworks,
	reject_sender_login_mismatch,
	reject

# RESTRICTION CLASSES
smtpd_restriction_classes = local_only
local_only = check_recipient_access hash:/etc/postfix/virtual_domains, reject

######################################################################
# NOTIFICATION
######################################################################

# Configure NDR (NonDeliveryReports) to by sent to specific email address
#notify_classes = resource, software, bounce
#bounce_notice_recipient = customerportal@example.net

######################################################################
# VIRTUAL DOMAINS, USERS, MAILBOXES, GROUPS
######################################################################

# Valid virtual domains
virtual_mailbox_domains = hash:/etc/postfix/virtual_domains

# LDAP (Active Directory) users/senders
smtpd_sender_login_maps = proxy:ldap:/etc/postfix/ad_sender_login_maps.cf

# LDAP (Active Directory) mailboxes
virtual_mailbox_maps = proxy:ldap:/etc/postfix/ad_virtual_mailbox_maps.cf

# LDAP (Active Directory) lists/groups
virtual_alias_maps = proxy:ldap:/etc/postfix/ad_virtual_group_maps.cf

######################################################################
# TLS
######################################################################

# Enable TLS (required to encrypt the plaintext SASL authentication)
smtpd_tls_security_level = encrypt

# Only offer SASL in a TLS session
smtpd_tls_auth_only = yes

# Certification Authority
# smtpd_tls_CAfile = /etc/postfix/ssl/ca.cer

# Public Certificate
smtpd_tls_cert_file = /etc/pki/tls/certs/dc2-a-vcmsx002.adm.example.net.crt

# Private Key (without passphrase)
smtpd_tls_key_file = /etc/pki/tls/private/dc2-a-vcmsx002.adm.example.net.key

# Randomizer for key creation
tls_random_source = dev:/dev/urandom

# TLS related logging (set to 2 for debugging)
smtpd_tls_loglevel = 0

# Avoid Denial-Of-Service-Attacks
smtpd_client_new_tls_session_rate_limit = 10

# Activate TLS Session Cache
smtpd_tls_session_cache_database = btree:/etc/postfix/smtpd_session_cache

# Deny some TLS-Ciphers
smtpd_tls_exclude_ciphers =
        EXP
        EDH-RSA-DES-CBC-SHA
        ADH-DES-CBC-SHA
        DES-CBC-SHA
        SEED-SHA

# Diffie-Hellman Parameters for Perfect Forward Secrecy
# Can be created with:
# openssl dhparam -2 -out dh_512.pem 512
# openssl dhparam -2 -out dh_1024.pem 1024
# openssl dhparam -2 -out dh_2048.pem 2048
smtpd_tls_dh512_param_file = /etc/pki/tls/certs/dh_512.pem
smtpd_tls_dh1024_param_file = /etc/pki/tls/certs/dh_1024.pem

######################################################################
# HARDENING
######################################################################

# CFG-ON  -> Disable the SMTP VRFY command. This stops some techniques used to harvest email addresses.
disable_vrfy_command=yes

# CFG-ON  -> Require that a remote SMTP client sends HELO or EHLO before commencing a MAIL transaction.
smtpd_helo_required=yes

# CFG-ON  -> Limit Denial of Service Attacks
default_process_limit = 100
smtpd_client_connection_count_limit = 10
smtpd_client_connection_rate_limit = 30
queue_minfree = 31457280
header_size_limit = 51200
message_size_limit = 20971520
smtpd_recipient_limit = 100

# CFG-ON  -> Require that addresses received in SMTP MAIL FROM and RCPT TO commands are enclosed
# CFG-ON  -> with <>, and that those addresses do not contain RFC 822 style comments or phrases.
strict_rfc821_envelopes = yes

# CFG-ON  -> Reject the request when the client sends SMTP commands ahead of time where it is
# CFG-ON  -> not allowed, or when the client sends SMTP commands ahead of time without knowing that
# CFG-ON  -> Postfix actually supports ESMTP command pipelining. This stops mail from bulk mail
# CFG-ON  -> software that improperly uses ESMTP command pipelining in order to speed up deliveries.
smtpd_data_restrictions = reject_unauth_pipelining

# CFG-ON  -> List of commands that cause the Postfix SMTP server to immediately terminate the
# CFG-ON  -> session with a 221 code.
smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASS

# CFG-ON  -> Appending .domain is the MUA's job.
append_dot_mydomain = no

# CFG-ON  -> Turning off SSLv2 / v3 due to the DROWN attack
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3
smtp_tls_protocols = !SSLv2, !SSLv3

lmtp_tls_mandatory_protocols = !SSLv2, !SSLv3
lmtp_tls_protocols = !SSLv2, !SSLv3

smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3
smtpd_tls_protocols = !SSLv2, !SSLv3

# CFG-ON  -> Enable using TLS if remote server supports it
smtp_tls_security_level = may

Differences from the internal pair

LineDC2-A-VCMSX001DC2-A-VCMSX002
myhostnamedc2-a-vcmsx001.adm.example.netdc2-a-vcmsx002.adm.example.net
smtp_bind_address, smtp_bind_address6the VIP, 10.12.19.33 and 2001:db8:a2:b6f::f:1not set
relayhost[10.12.19.34], the first relay[10.12.19.41], node A of the pair
smtp_fallback_relay[10.12.19.35], the second relay[10.12.19.42], node B of the pair
mynetworksthe two relays and the mailbox serverthe VIP, the two relays and the two nodes of the pair
smtpd_tls_cert_file, smtpd_tls_key_filefiles named after dc2-a-vcmsx001files named after dc2-a-vcmsx002
bash-postfix-encrypt-filter_destination_recipient_limit1not set, there is no filter here

The rest of what diff prints is white space. One comment differs as well: the pair says "AD users in domain ad-dc2.example.net", this file still says ad.example.net, the domain of site 1 from which the file was copied. The /etc/postfix/transport behind transport_maps is where the two servers really part: transport, mailbox server.

Checked against Postfix 3.11.7

As builtToday
hash: tables, btree: session cacheRHEL 10 has no Berkeley DB; the tables must become lmdb:, and Postfix 3.11 ships a migration guide (NON_BERKELEYDB_README)
smtpd_tls_dh512_param_filesilently ignored since 3.6
smtpd_tls_dh1024_param_filedeprecated since 3.9: leave at default
!SSLv2, !SSLv3 protocol listsstill accepted; the preferred form is a lower bound such as >=TLSv1.2. The as-built value allows TLS 1.0 and 1.1
smtpd_tls_cert_file, smtpd_tls_key_filestill valid; smtpd_tls_chain_files is preferred since 3.4
smtpd_tls_exclude_ciphersstill valid; upstream advises not to exclude ciphers unless it is essential
relay rules inside smtpd_recipient_restrictionsstill work; smtpd_relay_restrictions is the preferred place and is evaluated first
smtpd_data_restrictions = reject_unauth_pipeliningstill valid; since 3.9 smtpd_forbid_unauth_pipelining = yes is the default as well
smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASSstill valid; the default since 3.7 adds a pattern for non-command input that this value drops
append_dot_mydomain = no, smtp_tls_security_level = mayboth are now defaults (3.0 and 3.11)
no compatibility_levelintroduced in 3.0; without it Postfix runs with backwards-compatible defaults and logs that it does

Postfix 3.11.7 was announced on 2026-09-07. Nothing in the file stops a current Postfix from starting except the Berkeley DB tables on a system without that library. Postfix 3.9 added defences against SMTP smuggling that are on by default (smtpd_forbid_bare_newline = normalize). dovecot_destination_recipient_limit = 1 is still required for the D and O flags of the pipe transport.

← solutionz