我的 postfix 服务器配置为根据 spamhaus 和 spamcop 管理的几个垃圾邮件阻止列表拒绝电子邮件。
在注意到我最近收到的垃圾邮件比平时多后,我从日志中发现,上一次根据这些服务中的任何一个的积极结果拒绝电子邮件是在一周前。一段时间以来,我没有对我的后缀配置进行任何更改,因此服务器上应该没有任何更改。
我在这里运行了测试 - https://blt.spamhaus.com/并且它们都通过了,这向我证实了电子邮件没有被拒绝,因为它们应该被拒绝。另外,我已经检查了我收到的几封垃圾邮件的发送域的阻止列表并且它们存在,所以应该被拒绝。
我对如何进一步解决这个问题有点茫然。后缀日志中似乎没有任何内容显示“我没有检查此阻止列表,因为...” 我怎样才能找到这个问题的根本原因?
我的 smtp 收件人限制如下:
smtpd_recipient_restrictions =
permit_mynetworks
check_sender_access
hash:/etc/postfix/sender_access
reject_unauth_destination
reject_unauth_pipelining
reject_invalid_hostname
reject_non_fqdn_sender
reject_unknown_sender_domain
reject_non_fqdn_recipient
reject_unknown_recipient_domain
reject_rbl_client bl.spamcop.net
reject_rbl_client zen.spamhaus.org
reject_rbl_client dul.dnsbl.sorbs.net
permit
smtpd_reject_unlisted_sender = yes
postconf -n 的输出:
alias_database = hash:/etc/aliases
alias_maps = hash:/etc/aliases
biff = no
command_directory = /usr/sbin
daemon_directory = /usr/lib/postfix/sbin
disable_vrfy_command = yes
home_mailbox = Mail/
mailbox_command = /usr/lib/dovecot/deliver
mailbox_size_limit = 0
message_size_limit = 20480000
mydestination = b3.localdomain, localhost.localdomain, localhost, /etc/postfix/bubbadomains, $myhostname
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
recipient_delimiter = +
relayhost = smtp.gmail.com
sender_bcc_maps = hash:/etc/postfix/sender_bcc
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous
smtp_tls_session_cache_database = btree:${queue_directory}/smtp_scache
smtp_use_tls = yes
smtpd_banner = $myhostname ESMTP $mail_name (Debian/GNU)
smtpd_discard_ehlo_keywords = silent-discard, dsn
smtpd_helo_required = yes
smtpd_recipient_restrictions = permit_mynetworks check_sender_access hash:/etc/postfix/sender_access reject_unauth_destination reject_unauth_pipelining reject_invalid_hostname reject_non_fqdn_sender reject_unknown_sender_domain reject_non_fqdn_recipient reject_unknown_recipient_domain reject_rbl_client bl.spamcop.net reject_rbl_client zen.spamhaus.org reject_rbl_client dul.dnsbl.sorbs.net permit
smtpd_reject_unlisted_sender = yes
smtpd_relay_restrictions = permit_mynetworks check_sender_access hash:/etc/postfix/sender_access reject_unauth_destination reject_unauth_pipelining reject_invalid_hostname reject_non_fqdn_sender reject_unknown_sender_domain reject_non_fqdn_recipient reject_unknown_recipient_domain reject_rbl_client bl.spamcop.net reject_rbl_client zen.spamhaus.org reject_rbl_client dul.dnsbl.sorbs.net permit
smtpd_tls_cert_file = /etc/letsencrypt/live/mydomain.co.uk/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mydomain.co.uk/privkey.pem
smtpd_tls_session_cache_database = btree:${queue_directory}/smtpd_scache
smtpd_use_tls = yes
unknown_local_recipient_reject_code = 550
因此,尽管挖掘请求(例如
dig @localhost a 185.176.220.75.zen.spamhaus.org
)返回了预期的结果,让我假设没有网络/DNS 问题,但我确实在我的 OpenDNS 仪表板中发现了一些垃圾邮件和垃圾邮件 DNS 请求被阻止的证据。没有给出任何理由,并且在检查时没有与之关联的类别,因此这可能是/曾经是一个暂时性的问题,将自行纠正。不过,我没有把它留给机会,而是专门将这些域列入白名单。几分钟后,我再次从 spamhaus 运行电子邮件测试,而我预计会被阻止的那些测试确实如此。