Email - Postfix main.cf, relay servers
Email Solution · Config document · referenced from Relay servers
The global Postfix configuration of a relay server. It accepts mail on port 25 from the internal servers only, strips internal headers and delivers to the internet, with opportunistic TLS. The distribution's stock comment blocks in the upper part of the file are left out; the section banners, every active line and my own comments are as built.
| Item | Value |
|---|---|
| Path on the server | /etc/postfix/main.cf |
| Shown here | DC2-A-VCMSR001, the primary relay of site 2 |
| Also on | DC2-B-VCMSR001, with the differences below |
| Software | Postfix 2.10.1 from RHEL 7 |
| Activated with | systemctl start postfix in the install notes |
The file
###################################################################### # LOCAL PATHNAME INFORMATION ###################################################################### queue_directory = /var/spool/postfix command_directory = /usr/sbin daemon_directory = /usr/libexec/postfix data_directory = /var/lib/postfix ###################################################################### # QUEUE AND PROCESS OWNERSHIP ###################################################################### mail_owner = postfix ###################################################################### # INTERNET HOST AND DOMAIN NAMES ###################################################################### myhostname = mx3.ad.example.net mydomain = ad.example.net ###################################################################### # SENDING MAIL ###################################################################### myorigin = $mydomain ###################################################################### # RECEIVING MAIL ###################################################################### inet_interfaces = all inet_protocols = all mydestination = $myhostname, localhost.$mydomain, localhost ###################################################################### # REJECTING MAIL FOR UNKNOWN LOCAL USERS ###################################################################### unknown_local_recipient_reject_code = 550 ###################################################################### # ALIAS DATABASE ###################################################################### alias_maps = hash:/etc/aliases alias_database = hash:/etc/aliases ###################################################################### # DELIVERY TO MAILBOX ###################################################################### home_mailbox = Maildir/ ###################################################################### # SHOW SOFTWARE VERSION OR NOT ###################################################################### smtpd_banner = $myhostname ESMTP ###################################################################### # DEBUGGING CONTROL ###################################################################### debug_peer_level = 2 debugger_command = PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin ddd $daemon_directory/$process_name $process_id & sleep 5 ###################################################################### # INSTALL-TIME CONFIGURATION INFORMATION ###################################################################### sendmail_path = /usr/sbin/sendmail.postfix newaliases_path = /usr/bin/newaliases.postfix mailq_path = /usr/bin/mailq.postfix setgid_group = postdrop html_directory = no manpage_directory = /usr/share/man sample_directory = /usr/share/doc/postfix-2.10.1/samples readme_directory = /usr/share/doc/postfix-2.10.1/README_FILES ###################################################################### # RESTRICTIONS ###################################################################### # My networks = Internal Email Server only mynetworks = 10.12.19.33/32 10.12.19.41/32 10.12.19.42/32 # Allowed clients are only from my_networks = Internal Email Server only smtpd_recipient_restrictions = reject_non_fqdn_recipient, reject_unknown_recipient_domain, permit_mynetworks, reject_unauth_destination, reject ###################################################################### # NOTIFICATION ###################################################################### # Configure NDR (NonDeliveryReports) to by sent to specific email address #notify_classes = resource, software, bounce #bounce_notice_recipient = customerportal@example.net ###################################################################### # TRANSPORT ###################################################################### # Transport maps transport_maps = hash:/etc/postfix/transport ###################################################################### # HARDENING ###################################################################### # CFG-ON -> Disable the SMTP VRFY command. This stops some techniques used to harvest email addresses. disable_vrfy_command=yes # CFG-ON -> Require that a remote SMTP client sends HELO or EHLO before commencing a MAIL transaction. smtpd_helo_required=yes # CFG-ON -> Limit Denial of Service Attacks default_process_limit = 100 smtpd_client_connection_count_limit = 10 smtpd_client_connection_rate_limit = 30 queue_minfree = 31457280 header_size_limit = 51200 message_size_limit = 20971520 smtpd_recipient_limit = 100 # CFG-ON -> Require that addresses received in SMTP MAIL FROM and RCPT TO commands are enclosed # CFG-ON -> with <>, and that those addresses do not contain RFC 822 style comments or phrases. strict_rfc821_envelopes = yes # CFG-ON -> Reject the request when the client sends SMTP commands ahead of time where it is # CFG-ON -> not allowed, or when the client sends SMTP commands ahead of time without knowing that # CFG-ON -> Postfix actually supports ESMTP command pipelining. This stops mail from bulk mail # CFG-ON -> software that improperly uses ESMTP command pipelining in order to speed up deliveries. smtpd_data_restrictions = reject_unauth_pipelining # CFG-ON -> List of commands that cause the Postfix SMTP server to immediately terminate the # CFG-ON -> session with a 221 code. smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASS # CFG-ON -> Appending .domain is the MUA's job. append_dot_mydomain = no # CFG-ON -> Turning off SSLv2 / v3 due to the DROWN attack smtp_tls_mandatory_protocols = !SSLv2, !SSLv3 smtp_tls_protocols = !SSLv2, !SSLv3 lmtp_tls_mandatory_protocols = !SSLv2, !SSLv3 lmtp_tls_protocols = !SSLv2, !SSLv3 smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3 smtpd_tls_protocols = !SSLv2, !SSLv3 # CFG-ON -> Remove sensitive informations from email header in outgoing emails smtp_header_checks = pcre:/etc/postfix/header_checks # CFG-ON -> Enable using TLS if remote server supports it smtp_tls_security_level = may
Differences on the second relay
The result of diff between the two archived files.
| Host | Line | Value |
|---|---|---|
DC2-A-VCMSR001 | myhostname | mx3.ad.example.net |
DC2-B-VCMSR001 | myhostname | mx4.ad.example.net |
DC2-A-VCMSR001 | comment above mynetworks | # My networks = Internal Email Server only |
DC2-B-VCMSR001 | comment above mynetworks | # My networks = Internal Email Server2 only |
DC2-A-VCMSR001 | mynetworks | 10.12.19.33/32 10.12.19.41/32 10.12.19.42/32, separated by spaces |
DC2-B-VCMSR001 | mynetworks | 10.12.19.33/32, 10.12.19.41/32, 10.12.19.42/32, separated by commas |
Postfix accepts both separators, so the two mynetworks lines mean the same. mydomain is ad.example.net, the mail domain of site 1, on both relays of site 2; the design gives these servers the public names mx1.ad-dc2.example.net and mx2.ad-dc2.example.net. The contradiction is described in Relay servers.
Checked against Postfix 3.11.7
| As built | Today |
|---|---|
| Postfix 2.10.1 | Stable release 3.11.7 of 2026-09-07 |
smtp_tls_security_level = may | Still valid, and the default since Postfix 3.11 |
!SSLv2, !SSLv3 in the six *_tls_protocols lines | The exclusion syntax is still accepted; the preferred form is a lower bound such as >=TLSv1.2. The as-built value still allows TLS 1.0 and 1.1 |
Relay control inside smtpd_recipient_restrictions, smtpd_relay_restrictions not set | Relay rules are preferably put into smtpd_relay_restrictions, which is evaluated first; the as-built list still works |
smtpd_data_restrictions = reject_unauth_pipelining | Still valid. Since 3.9 smtpd_forbid_unauth_pipelining = yes is the default and disconnects such clients |
| No setting against bare newlines | smtpd_forbid_bare_newline defaults to normalize since 3.9, the defence against SMTP smuggling |
smtpd_forbidden_commands = CONNECT,GET,POST,USER,PASS | Still valid; the default since 3.7 is CONNECT GET POST plus a regexp that catches lines not starting with a capital letter |
append_dot_mydomain = no | The default since Postfix 3.0 |
disable_vrfy_command, smtpd_helo_required, strict_rfc821_envelopes set to yes | Still valid; the defaults are still no |
hash:/etc/aliases, hash:/etc/postfix/transport | RHEL 10 has no Berkeley DB libraries; the tables must be converted to lmdb: (package postfix-lmdb) |
| Opportunistic TLS only, no per-destination policy | smtp_tls_policy_maps, the levels dane and dane-only, MTA-STS through a policy plugin and TLSRPT (3.10) exist for stricter outbound TLS |
A file from 2.10 has no compatibility_level. A current Postfix then runs with backwards-compatible defaults and says so in the log. What changed most since 2019 is outside this file: Gmail and Yahoo require SPF or DKIM, valid forward and reverse DNS and TLS from every sender since February 2024, and more from bulk senders. The reverse DNS requirement is exactly where the myhostname contradiction of these relays would hurt.