LINUXOR.SK ... open source notes ...

Email - Postfix main.cf, relay servers

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Relay servers

The global Postfix configuration of a relay server. It accepts mail on port 25 from the internal servers only, strips internal headers and delivers to the internet, with opportunistic TLS. The distribution's stock comment blocks in the upper part of the file are left out; the section banners, every active line and my own comments are as built.

ItemValue
Path on the server/etc/postfix/main.cf
Shown hereDC2-A-VCMSR001, the primary relay of site 2
Also onDC2-B-VCMSR001, with the differences below
SoftwarePostfix 2.10.1 from RHEL 7
Activated withsystemctl start postfix in the install notes

The file

ini
######################################################################
# LOCAL PATHNAME INFORMATION
######################################################################
queue_directory = /var/spool/postfix

command_directory = /usr/sbin

daemon_directory = /usr/libexec/postfix

data_directory = /var/lib/postfix

######################################################################
# QUEUE AND PROCESS OWNERSHIP
######################################################################
mail_owner = postfix

######################################################################
# INTERNET HOST AND DOMAIN NAMES
######################################################################
myhostname = mx3.ad.example.net

mydomain = ad.example.net

######################################################################
# SENDING MAIL
######################################################################
myorigin = $mydomain

######################################################################
# RECEIVING MAIL
######################################################################
inet_interfaces = all

inet_protocols = all

mydestination = $myhostname, localhost.$mydomain, localhost

######################################################################
# REJECTING MAIL FOR UNKNOWN LOCAL USERS
######################################################################
unknown_local_recipient_reject_code = 550

######################################################################
# ALIAS DATABASE
######################################################################
alias_maps = hash:/etc/aliases

alias_database = hash:/etc/aliases

######################################################################
# DELIVERY TO MAILBOX
######################################################################
home_mailbox = Maildir/

######################################################################
# SHOW SOFTWARE VERSION OR NOT
######################################################################
smtpd_banner = $myhostname ESMTP

######################################################################
# DEBUGGING CONTROL
######################################################################
debug_peer_level = 2

debugger_command =
         PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
         ddd $daemon_directory/$process_name $process_id & sleep 5

######################################################################
# INSTALL-TIME CONFIGURATION INFORMATION
######################################################################
sendmail_path = /usr/sbin/sendmail.postfix

newaliases_path = /usr/bin/newaliases.postfix

mailq_path = /usr/bin/mailq.postfix

setgid_group = postdrop

html_directory = no

manpage_directory = /usr/share/man

sample_directory = /usr/share/doc/postfix-2.10.1/samples

readme_directory = /usr/share/doc/postfix-2.10.1/README_FILES

######################################################################
# RESTRICTIONS
######################################################################
# My networks = Internal Email Server only
mynetworks = 10.12.19.33/32 10.12.19.41/32 10.12.19.42/32

# Allowed clients are only from my_networks = Internal Email Server only
smtpd_recipient_restrictions =
        reject_non_fqdn_recipient,
        reject_unknown_recipient_domain,
        permit_mynetworks,
        reject_unauth_destination,
        reject

######################################################################
# NOTIFICATION
######################################################################

# Configure NDR (NonDeliveryReports) to by sent to specific email address
#notify_classes = resource, software, bounce
#bounce_notice_recipient = customerportal@example.net

######################################################################
# TRANSPORT
######################################################################
# Transport maps
transport_maps = hash:/etc/postfix/transport

######################################################################
# HARDENING
######################################################################

# CFG-ON  -> Disable the SMTP VRFY command. This stops some techniques used to harvest email addresses.
disable_vrfy_command=yes

# CFG-ON  -> Require that a remote SMTP client sends HELO or EHLO before commencing a MAIL transaction.
smtpd_helo_required=yes

# CFG-ON  -> Limit Denial of Service Attacks
default_process_limit = 100
smtpd_client_connection_count_limit = 10
smtpd_client_connection_rate_limit = 30
queue_minfree = 31457280
header_size_limit = 51200
message_size_limit = 20971520
smtpd_recipient_limit = 100

# CFG-ON  -> Require that addresses received in SMTP MAIL FROM and RCPT TO commands are enclosed
# CFG-ON  -> with <>, and that those addresses do not contain RFC 822 style comments or phrases.
strict_rfc821_envelopes = yes

# CFG-ON  -> Reject the request when the client sends SMTP commands ahead of time where it is
# CFG-ON  -> not allowed, or when the client sends SMTP commands ahead of time without knowing that
# CFG-ON  -> Postfix actually supports ESMTP command pipelining. This stops mail from bulk mail
# CFG-ON  -> software that improperly uses ESMTP command pipelining in order to speed up deliveries.
smtpd_data_restrictions = reject_unauth_pipelining

# CFG-ON  -> List of commands that cause the Postfix SMTP server to immediately terminate the
# CFG-ON  -> session with a 221 code.
smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASS

# CFG-ON  -> Appending .domain is the MUA's job.
append_dot_mydomain = no

# CFG-ON  -> Turning off SSLv2 / v3 due to the DROWN attack
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3
smtp_tls_protocols = !SSLv2, !SSLv3

lmtp_tls_mandatory_protocols = !SSLv2, !SSLv3
lmtp_tls_protocols = !SSLv2, !SSLv3

smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3
smtpd_tls_protocols = !SSLv2, !SSLv3

# CFG-ON  -> Remove sensitive informations from email header in outgoing emails
smtp_header_checks = pcre:/etc/postfix/header_checks

# CFG-ON  -> Enable using TLS if remote server supports it
smtp_tls_security_level = may

Differences on the second relay

The result of diff between the two archived files.

HostLineValue
DC2-A-VCMSR001myhostnamemx3.ad.example.net
DC2-B-VCMSR001myhostnamemx4.ad.example.net
DC2-A-VCMSR001comment above mynetworks# My networks = Internal Email Server only
DC2-B-VCMSR001comment above mynetworks# My networks = Internal Email Server2 only
DC2-A-VCMSR001mynetworks10.12.19.33/32 10.12.19.41/32 10.12.19.42/32, separated by spaces
DC2-B-VCMSR001mynetworks10.12.19.33/32, 10.12.19.41/32, 10.12.19.42/32, separated by commas

Postfix accepts both separators, so the two mynetworks lines mean the same. mydomain is ad.example.net, the mail domain of site 1, on both relays of site 2; the design gives these servers the public names mx1.ad-dc2.example.net and mx2.ad-dc2.example.net. The contradiction is described in Relay servers.

Checked against Postfix 3.11.7

As builtToday
Postfix 2.10.1Stable release 3.11.7 of 2026-09-07
smtp_tls_security_level = mayStill valid, and the default since Postfix 3.11
!SSLv2, !SSLv3 in the six *_tls_protocols linesThe exclusion syntax is still accepted; the preferred form is a lower bound such as >=TLSv1.2. The as-built value still allows TLS 1.0 and 1.1
Relay control inside smtpd_recipient_restrictions, smtpd_relay_restrictions not setRelay rules are preferably put into smtpd_relay_restrictions, which is evaluated first; the as-built list still works
smtpd_data_restrictions = reject_unauth_pipeliningStill valid. Since 3.9 smtpd_forbid_unauth_pipelining = yes is the default and disconnects such clients
No setting against bare newlinessmtpd_forbid_bare_newline defaults to normalize since 3.9, the defence against SMTP smuggling
smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASSStill valid; the default since 3.7 is CONNECT GET POST plus a regexp that catches lines not starting with a capital letter
append_dot_mydomain = noThe default since Postfix 3.0
disable_vrfy_command, smtpd_helo_required, strict_rfc821_envelopes set to yesStill valid; the defaults are still no
hash:/etc/aliases, hash:/etc/postfix/transportRHEL 10 has no Berkeley DB libraries; the tables must be converted to lmdb: (package postfix-lmdb)
Opportunistic TLS only, no per-destination policysmtp_tls_policy_maps, the levels dane and dane-only, MTA-STS through a policy plugin and TLSRPT (3.10) exist for stricter outbound TLS

A file from 2.10 has no compatibility_level. A current Postfix then runs with backwards-compatible defaults and says so in the log. What changed most since 2019 is outside this file: Gmail and Yahoo require SPF or DKIM, valid forward and reverse DNS and TLS from every sender since February 2024, and more from bulk senders. The reverse DNS requirement is exactly where the myhostname contradiction of these relays would hurt.

← solutionz