Postfix and Spamassassin

| No TrackBacks

I've written previously about using Postfix Enabler to set up the mail server I'm using for the site. The author, Bernard Teo, was nice enough to hook me up with a beta of version 1.1 that I've been running here for a bit over a week, and it is now available via the link above for anyone that wants to give it a shot. It now includes an optional setup for Spamassassin, as well as a handy Mail Stats generator to keep track of what your server is doing. Also included is a new field to set a RBL (Realtime block List) server, such as Spamhaus to help with spam checking.

I thought I had the Spamassassin part set up correctly, but after setting up a new account here for testing and then going out of my way to put that account where spammers would find it, I found that Spamassasin wasn't checking my mail at all. Read on for how I fixed this, and learned a bit about Postfix's main.cf configuration file.

The main think I discovered with Postfix and its config file (main.cf), was that if you give the same config line twice with two different sets of parameters, the second instance will replace the first. I suppose my work with CSS style sheets had me confused since one line could build on top of what came before, but this isn't the case with Postfix.

What was happening was that the Postfix Enabler was setting up the necessary commands for Spamassassin to filter the mail using the smtpd_recipient_restrictions control, but it turned out that I was using this for some additional filtering of my own, and Postfix Enabler was putting my custom config after its own settings, thereby overriding the settings for Spamassassin.

Once I finally realized what was going on, it was a simple matter to copy the relevant line from the config and put it into my custom settings and restart Postfix. A quick test mail then confirmed that Spamassassin was alive and well, filtering my mail.

For anyone curious, here are the custom commands that Postfix Enabler is setting, and my own custom settings below that. This sets some fairly strict filtering, so be warned.

###Start PostfixEnabler###
alias_maps=hash:/etc/postfix/aliases
alias_database=hash:/etc/postfix/aliases
inet_interfaces=all
mynetworks_style=subnet
message_size_limit=10240000
mydomain=wrightthisway.com
myhostname=wrightthisway.com
smtpd_recipient_restrictions=permit_mynetworks,check_recipient_access hash:/etc/postfix/filtered_domains

smtpd_client_restrictions=hash:/etc/postfix/access,reject_rbl_client sbl-xbl.spamhaus.org
default_rbl_reply=$rbl_code Service unavailable; $rbl_class [$rbl_what] blocked using $rbl_domain${rbl_reason?; $rbl_reason} - see http://$rbl_domain.
smtpd_helo_required=yes

unknown_local_recipient_reject_code=550
###End PostfixEnabler###

###Start Custom Config###
strict_rfc821_envelopes = yes
smtpd_helo_required = yes
smtpd_helo_restrictions =
permit_mynetworks,
check_helo_access hash:/etc/postfix/access, reject_unknown_hostname,
reject_invalid_hostname,
reject_non_fqdn_hostname

smtpd_recipient_restrictions =
permit_mynetworks,
reject_unknown_client,
reject_non_fqdn_sender,
reject_unknown_sender_domain,
reject_unknown_recipient_domain,
reject_unauth_destination,
check_recipient_access hash:/etc/postfix/access,
check_sender_access hash:/etc/postfix/access,
check_client_access hash:/etc/postfix/access,
check_recipient_access hash:/etc/postfix/filtered_domains

smtpd_data_restrictions =
reject_unauth_pipelining,
permit

unknown_address_reject_code = 550
unknown_client_reject_code = 550
unknown_hostname_reject_code = 550

No TrackBacks

TrackBack URL: http://www.wrightthisway.com/cgi-bin/mt/mt-tb.cgi/39

November 2010

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        

About this Entry

This page contains a single entry by Jim published on May 4, 2004 9:37 PM.

PocketPC Notes conversion was the previous entry in this blog.

Laser Vision is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Powered by Movable Type 5.031