LINUXOR.SK ... open source notes ...

Email - Postfix header_checks, relay servers

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Relay servers

The PCRE table that the Postfix SMTP client of a relay server applies to the headers of every message it delivers (smtp_header_checks in main.cf). It removes the headers that describe the inside of the network.

ItemValue
Path on the server/etc/postfix/header_checks
Shown hereDC2-A-VCMSR001
Also onDC2-B-VCMSR001, the same rules; the files differ only in tabs against spaces
Referenced bysmtp_header_checks = pcre:/etc/postfix/header_checks
SoftwarePostfix 2.10.1 from RHEL 7
Activated withnothing to compile: a pcre: table is read as text when Postfix starts or reloads

The file

ini
###################################################################################################
# Pattern  	                Action
###################################################################################################
# CFG-ON  -> Remove sensitive information from email header
/^Received:/			IGNORE
/^\s*Mime-Version: 1.0.*/	REPLACE Mime-Version: 1.0
/^\s*User-Agent/		IGNORE
/^\s*X-Enigmail/		IGNORE
/^\s*X-Mailer/			IGNORE
/^\s*X-Originating-IP/		IGNORE

What each rule does

PatternActionEffect
/^Received:/IGNOREDrops every Received: header, the relay's own included
/^\sMime-Version: 1.0./REPLACERewrites the header to the bare Mime-Version: 1.0, cutting off anything a mail client appended after the version
/^\s*User-Agent/IGNOREDrops the name and version of the mail client
/^\s*X-Enigmail/IGNOREDrops the headers of the Enigmail add-on
/^\s*X-Mailer/IGNOREDrops the name and version of the sending program
/^\s*X-Originating-IP/IGNOREDrops the address of the client, where a webmail or a gateway added it

The design document of the first concept and the final design both call the file /etc/postfix/header.checks; the servers and main.cf have header_checks.

Checked against Postfix 3.11.7

As builtToday
smtp_header_checks with a pcre: tableStill valid
IGNOREStill valid; STRIP, available since 3.2, does the same and logs it
REPLACE Mime-Version: 1.0Still valid; the replacement has to start with a valid header label, which it does
Deleting every Received: lineRFC 5321, section 4.4: "An Internet mail program MUST NOT change or delete a Received: line that was previously added to the message header section."

The first rule was against the standard in 2019 as it is today. Postfix has a narrower tool for the same wish, smtpd_hide_client_session, meant for the submission services on 587 and 465; its documentation says the default must stay on the port 25 service because the information is required by that same section of RFC 5321.

← solutionz