<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — Admin panel Mail size vs Postfix Mail size]]></title>
		<link>http://www.iredmail.org/forum/topic4340-admin-panel-mail-size-vs-postfix-mail-size.html</link>
		<atom:link href="http://www.iredmail.org/forum/feed-rss-topic4340.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in Admin panel Mail size vs Postfix Mail size.]]></description>
		<lastBuildDate>Thu, 17 Jan 2013 12:38:49 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19912.html#p19912</link>
			<description><![CDATA[<p>What&#039;s the full error message? A &quot;552 5.3.4&quot; is helpless.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Thu, 17 Jan 2013 12:38:49 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19912.html#p19912</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19901.html#p19901</link>
			<description><![CDATA[<p>Still getting error 552 5.3.4 when trying to send email larger than 15 mb</p><p>Did I miss something on<br /><a href="http://www.iredmail.org/wiki/index.php?title=IRedMail/FAQ/Enable.Throttling/Debian.Ubuntu">http://www.iredmail.org/wiki/index.php? … ian.Ubuntu</a></p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Wed, 16 Jan 2013 18:08:21 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19901.html#p19901</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19900.html#p19900</link>
			<description><![CDATA[<p>/var/log/mail.log</p><p>Jan 16 12:02:45 nm2 postfix-policyd: rcpt=20549, throttle=update(a), host=127.0.0.1, from=stacy_borkofsky@cpr.ca, to=gperri@unitedsteelandfasteners.com, size=10639/15728640, quota=21036/250000000, count=2/512(2), rcpt=2/3600(2), threshold=0%|0%|0%<br />Jan 16 12:03:00 nm2 postfix-policyd: rcpt=20550, throttle=update(a), host=10.254.10.10, from=heidi@organicdefoamergroup.com, to=obe@ppiinc.com, size=7466/15728640, quota=84324/250000000, count=7/512(17), rcpt=7/3600(17), threshold=0%|1%|0%<br />Jan 16 12:03:01 nm2 postfix-policyd: rcpt=20551, throttle=update(a), host=10.254.10.26, from=bad@host.alle-laptop-onlineshops.com, to=jsargis@unitedsteelandfasteners.com, size=17841/15728640, quota=53517/250000000, count=3/512(3), rcpt=3/3600(3), threshold=0%|0%|0%<br />Jan 16 12:03:01 nm2 postfix-policyd: rcpt=20552, throttle=update(a), host=127.0.0.1, from=heidi@organicdefoamergroup.com, to=obe@ppiinc.com, size=7669/15728640, quota=91993/250000000, count=8/512(18), rcpt=8/3600(18), threshold=0%|1%|0%<br />Jan 16 12:03:03 nm2 postfix-policyd: rcpt=20553, throttle=update(a), host=127.0.0.1, from=bad@host.alle-laptop-onlineshops.com, to=jeslinesargis@hotmail.com, size=18018/15728640, quota=71535/250000000, count=4/512(4), rcpt=4/3600(4), threshold=0%|0%|0%<br />Jan 16 12:03:03 nm2 postfix-policyd: rcpt=20554, throttle=update(a), host=127.0.0.1, from=bad@host.alle-laptop-onlineshops.com, to=jsargis@unitedsteelandfasteners.com, size=18028/15728640, quota=89563/250000000, count=5/512(5), rcpt=5/3600(5), threshold=0%|0%|0%<br />Jan 16 12:03:04 nm2 postfix-policyd: rcpt=20555, throttle=new(a), host=10.254.10.26, from=orders@potbelly.com, to=heatherh@nielsenmassey.com, size=6738/15728640, quota=6738/250000000, count=1/512(1), rcpt=1/3600(1), threshold=0%|0%|0%<br />Jan 16 12:03:04 nm2 postfix-policyd: rcpt=20556, throttle=update(a), host=127.0.0.1, from=orders@potbelly.com, to=heatherh@nielsenmassey.com, size=6941/15728640, quota=13679/250000000, count=2/512(2), rcpt=2/3600(2), threshold=0%|0%|0%</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Wed, 16 Jan 2013 18:03:52 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19900.html#p19900</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19899.html#p19899</link>
			<description><![CDATA[<p>nm2:/etc/init.d# postconf -n<br />alias_database = hash:/etc/postfix/aliases<br />alias_maps = hash:/etc/postfix/aliases<br />allow_min_user = no<br />append_dot_mydomain = no<br />biff = no<br />bounce_queue_lifetime = 1d<br />broken_sasl_auth_clients = yes<br />config_directory = /etc/postfix<br />content_filter = smtp-amavis:[127.0.0.1]:10024<br />delay_warning_time = 0h<br />disable_vrfy_command = yes<br />dovecot_destination_recipient_limit = 1<br />enable_original_recipient = no<br />home_mailbox = Maildir/<br />inet_interfaces = all<br />inet_protocols = ipv4<br />mailbox_command = /usr/lib/dovecot/deliver<br />mailbox_size_limit = 0<br />maximal_backoff_time = 4000s<br />maximal_queue_lifetime = 1d<br />message_size_limit = 15728640<br />minimal_backoff_time = 300s<br />mydestination = $myhostname, localhost, localhost.localdomain, localhost.$myhostname<br />mydomain = abgnetwork.net<br />myhostname = nm2.abgnetwork.net<br />mynetworks = 127.0.0.0/8, 10.254.10.0/24, 46.144.243.70, 72.135.198.105, 75.145.128.210, 50.193.66.177, 50.193.66.178, 192.168.222.11, 10.254.252.0/24, 10.11.109.0/24, 10.11.12.0/24<br />mynetworks_style = subnet<br />myorigin = /etc/mailname<br />proxy_read_maps = $canonical_maps $lmtp_generic_maps $local_recipient_maps $mydestination $mynetworks $smtpd_sender_login_maps $recipient_bcc_maps $recipient_canonical_maps $relay_domains $relay_recipient_maps $relocated_maps $sender_bcc_maps $sender_canonical_maps $smtp_generic_maps $transport_maps $virtual_alias_domains $virtual_alias_maps $virtual_mailbox_domains $virtual_mailbox_maps $smtpd_sender_restrictions<br />queue_run_delay = 300s<br />readme_directory = no<br />recipient_bcc_maps = proxy:mysql:/etc/postfix/mysql/recipient_bcc_maps_user.cf, proxy:mysql:/etc/postfix/mysql/recipient_bcc_maps_domain.cf<br />recipient_delimiter = +<br />relay_domains = $mydestination, proxy:mysql:/etc/postfix/mysql/relay_domains.cf<br />relayhost =<br />sender_bcc_maps = proxy:mysql:/etc/postfix/mysql/sender_bcc_maps_user.cf, proxy:mysql:/etc/postfix/mysql/sender_bcc_maps_domain.cf<br />smtp-amavis_destination_recipient_limit = 1<br />smtp_data_init_timeout = 240s<br />smtp_data_xfer_timeout = 600s<br />smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache<br />smtpd_banner = $myhostname ESMTP $mail_name (Debian/GNU)<br />smtpd_data_restrictions = reject_unauth_pipelining<br />smtpd_end_of_data_restrictions = check_policy_service inet:127.0.0.1:10032<br />smtpd_enforce_tls = no<br />smtpd_helo_required = yes<br />smtpd_helo_restrictions = permit_mynetworks,permit_sasl_authenticated, check_helo_access pcre:/etc/postfix/helo_access.pcre<br />smtpd_recipient_restrictions = reject_unknown_sender_domain, reject_unknown_recipient_domain, reject_non_fqdn_sender, reject_non_fqdn_recipient, reject_unlisted_recipient, check_policy_service inet:127.0.0.1:7777, permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination, reject_non_fqdn_helo_hostname, reject_invalid_helo_hostname, check_policy_service inet:127.0.0.1:10031<br />smtpd_reject_footer = For assistance, call Advanced Business Group 847-247-0700. Please provide the following information in your problem report: time ($localtime), client ($client_address) and server ($server_name).<br />smtpd_reject_unlisted_recipient = yes<br />smtpd_reject_unlisted_sender = yes<br />smtpd_sasl_auth_enable = yes<br />smtpd_sasl_authenticated_header = no<br />smtpd_sasl_local_domain =<br />smtpd_sasl_path = ./dovecot-auth<br />smtpd_sasl_security_options = noanonymous<br />smtpd_sasl_type = dovecot<br />smtpd_sender_login_maps = proxy:mysql:/etc/postfix/mysql/sender_login_maps.cf<br />smtpd_sender_restrictions = permit_mynetworks, reject_sender_login_mismatch, permit_sasl_authenticated<br />smtpd_tls_CAfile = /etc/ssl/certs/gd_bundle.crt<br />smtpd_tls_cert_file = /etc/ssl/certs/nm2.abgnetwork.net.crt<br />smtpd_tls_key_file = /etc/ssl/private/nm2.key<br />smtpd_tls_loglevel = 0<br />smtpd_tls_security_level = may<br />smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache<br />smtpd_use_tls = yes<br />tls_random_source = dev:/dev/urandom<br />transport_maps = proxy:mysql:/etc/postfix/mysql/transport_maps_user.cf, proxy:mysql:/etc/postfix/mysql/transport_maps_domain.cf<br />virtual_alias_domains =<br />virtual_alias_maps = proxy:mysql:/etc/postfix/mysql/virtual_alias_maps.cf, proxy:mysql:/etc/postfix/mysql/domain_alias_maps.cf, proxy:mysql:/etc/postfix/mysql/catchall_maps.cf, proxy:mysql:/etc/postfix/mysql/domain_alias_catchall_maps.cf<br />virtual_gid_maps = static:1001<br />virtual_mailbox_base = /var/vmail<br />virtual_mailbox_domains = proxy:mysql:/etc/postfix/mysql/virtual_mailbox_domains.cf<br />virtual_mailbox_maps = proxy:mysql:/etc/postfix/mysql/virtual_mailbox_maps.cf<br />virtual_minimum_uid = 1001<br />virtual_transport = dovecot<br />virtual_uid_maps = static:1001</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Wed, 16 Jan 2013 18:02:13 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19899.html#p19899</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19897.html#p19897</link>
			<description><![CDATA[<p>netstat -ntlp | grep -i 1003<br />tcp&nbsp; &nbsp; &nbsp; &nbsp; 0&nbsp; &nbsp; &nbsp; 0 127.0.0.1:10031&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0.0.0.0:*&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;LISTEN&nbsp; &nbsp; &nbsp; 16807/postfix-polic<br />tcp&nbsp; &nbsp; &nbsp; &nbsp; 0&nbsp; &nbsp; &nbsp; 0 127.0.0.1:10032&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0.0.0.0:*&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;LISTEN&nbsp; &nbsp; &nbsp; 16733/postfix-polic</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Wed, 16 Jan 2013 17:58:10 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19897.html#p19897</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19896.html#p19896</link>
			<description><![CDATA[<p>postfix-policyd_sender_throttle</p><p>#! /bin/sh<br />### BEGIN INIT INFO<br /># Provides:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; postfix-policyd_throttle<br /># Required-Start:&nbsp; &nbsp; $remote_fs $syslog<br /># Required-Stop:&nbsp; &nbsp; &nbsp;$remote_fs $syslog<br /># Default-Start:&nbsp; &nbsp; &nbsp;2 3 4 5<br /># Default-Stop:&nbsp; &nbsp; &nbsp; 0 1 6<br />### END INIT INFO</p><p>PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin<br />DAEMON=/usr/sbin/postfix-policyd<br />CONFIG=/etc/postfix-policyd_throttle.conf<br />PIDFILE=&#039;/var/run/policyd_throttle.pid&#039;<br />NAME=postfix-policyd_throttle<br />DESC=&quot;Postfix throttling policy daemon&quot;</p><p>test -x $DAEMON || exit 0</p><p># Include policyd defaults if available<br />#if [ -f /etc/default/postfix-policyd ] ; then<br />#&nbsp; &nbsp; &nbsp; &nbsp;. /etc/default/postfix-policyd<br />#fi</p><p>set -e</p><p>PIDFILE=`grep &quot;PIDFILE&quot; $CONFIG | awk -F &quot;=&quot; &#039;{print $2}&#039; | awk &#039;{print $1}&#039;`</p><p>case &quot;$1&quot; in<br />&nbsp; start)<br />&nbsp; &nbsp; &nbsp; &nbsp; echo -n &quot;Starting $DESC: &quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; start-stop-daemon --start --quiet --background --pidfile $PIDFILE --exec $DAEMON -- -c $CONFIG<br />&nbsp; &nbsp; &nbsp; &nbsp; echo &quot;$NAME.&quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; ;;<br />&nbsp; stop)<br />&nbsp; &nbsp; &nbsp; &nbsp; echo -n &quot;Stopping $DESC: &quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; start-stop-daemon --stop --quiet --pidfile $PIDFILE --exec $DAEMON<br />&nbsp; &nbsp; &nbsp; &nbsp; echo &quot;$NAME.&quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; ;;<br />&nbsp; reload|force-reload)<br />&nbsp; &nbsp; &nbsp; &nbsp; echo -n &quot;Reloading $DESC configuration: &quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; start-stop-daemon --stop --signal 1 --quiet --pidfile $PIDFILE --exec $DAEMON<br />&nbsp; &nbsp; &nbsp; &nbsp; echo &quot;$NAME.&quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; ;;<br />&nbsp; restart)<br />&nbsp; &nbsp; &nbsp; &nbsp; echo -n &quot;Restarting $DESC: &quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; start-stop-daemon --stop --quiet --pidfile $PIDFILE --exec $DAEMON<br />&nbsp; &nbsp; &nbsp; &nbsp; sleep 1<br />&nbsp; &nbsp; &nbsp; &nbsp; start-stop-daemon --start --quiet --background --pidfile $PIDFILE --exec $DAEMON -- -c $CONFIG<br />&nbsp; &nbsp; &nbsp; &nbsp; echo &quot;$NAME.&quot;<br />&nbsp; &nbsp; &nbsp; &nbsp; ;;<br />&nbsp; *)<br />&nbsp; &nbsp; &nbsp; &nbsp; N=/etc/init.d/$NAME<br />&nbsp; &nbsp; &nbsp; &nbsp; echo &quot;Usage: $N {start|stop|restart|reload|force-reload}&quot; &gt;&amp;2<br />&nbsp; &nbsp; &nbsp; &nbsp; exit 1<br />&nbsp; &nbsp; &nbsp; &nbsp; ;;<br />esac</p><p>exit 0</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Wed, 16 Jan 2013 17:56:32 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19896.html#p19896</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19895.html#p19895</link>
			<description><![CDATA[<p>postfix-policyd.conf</p><p>######################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; POLICY DAEMON CONFIGURATION&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;#<br />######################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; DATABASE CONFIG&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;#<br />######################################################################<br />#<br /># ip address or hostname to connect to:<br />#<br />#&nbsp; &nbsp;if you want to connect to a host/ip, enter it here.<br />#&nbsp; &nbsp;if you want to via a unix socket, set MYSQLHOST=&quot;&quot;<br />#<br />MYSQLHOST=&quot;127.0.0.1&quot;</p><p>#<br /># database name:<br />#<br />#&nbsp; &nbsp;name of database to connect to<br />#<br />MYSQLDBASE=&quot;postfixpolicyd&quot;</p><p>#<br /># database username:<br />#<br />#&nbsp; &nbsp;username to connect to database as<br />#<br />MYSQLUSER=&quot;postfix-policyd&quot;</p><p>#<br /># database password:<br />#<br />#&nbsp; &nbsp;password to for username<br />#<br />MYSQLPASS=&quot;X************************&quot;</p><p>#<br /># connection options:<br />#<br />#&nbsp; &nbsp;what client side connections policyd will use&gt;<br />#<br />#&nbsp; &nbsp; &nbsp;CLIENT_COMPRESS -&gt; compress connection from policyd -&gt; mysql<br />#&nbsp; &nbsp; &nbsp;CLIENT_SSL&nbsp; &nbsp; &nbsp; -&gt;&nbsp; encrypt connection from policyd -&gt; mysql<br />#<br />MYSQLOPT=&quot;&quot;</p><p>#<br /># failsafe/failover mode:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: on<br />#<br />#&nbsp; &nbsp;if the database or queries fail, continue accepting mail<br />#&nbsp; &nbsp;<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />FAILSAFE=1</p><p>#<br /># database keep alive:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;if you recieve very little mail, your connection to&nbsp; the<br />#&nbsp; &nbsp;mysql database will time out. enabling this option pings<br />#&nbsp; &nbsp;the database to ensure the database connection is alive.<br />#&nbsp; &nbsp;if it is not, it reconnects to the database. this option<br />#&nbsp; &nbsp;is not needed on mail servers that recieve more than one<br />#&nbsp; &nbsp;mail every 60 to 120 seconds. disabling this increases<br />#&nbsp; &nbsp;performance a little.<br />#&nbsp; &nbsp;<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />DATABASE_KEEPALIVE=0</p><br /><br /><br /><br /><p>######################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;DAEMON&nbsp; CONFIG&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;#<br />######################################################################<br />#<br /># debugging information:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 3<br />#<br />#&nbsp; &nbsp;only use debugging when there are problems<br />#<br />#&nbsp; &nbsp;0 -&gt; off (recommended)<br />#&nbsp; &nbsp;1 -&gt; standard debugging<br />#&nbsp; &nbsp;2 -&gt; 1+mysql queries+results<br />#&nbsp; &nbsp;3 -&gt; 1+2+network debugging<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0=off<br />DEBUG=0</p><p>#<br /># daemon/background mode:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: off<br />#<br />#&nbsp; &nbsp;detach policyd from terminal. enable when you&#039;re happy<br />#&nbsp; &nbsp;that things are working as they should.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />DAEMON=1</p><p>#<br /># bind to ip address:<br />#<br />#&nbsp; &nbsp;ip address which the policy daemon will listen on<br />#<br />BINDHOST=&quot;127.0.0.1&quot;</p><p>#<br /># port to bind to:<br />#<br />#&nbsp; &nbsp;port which the policy daemon will listen on<br />#<br />BINDPORT=&quot;10031&quot;</p><p>#<br /># path to pidfile:<br />#<br />#&nbsp; &nbsp;where policyd will write its current pid to<br />#<br />PIDFILE=/var/run/policyd.pid</p><p>#<br /># syslog facility<br />#<br />#&nbsp; &nbsp;what syslog facility to log to<br />#<br />SYSLOG_FACILITY=&quot;LOG_MAIL|LOG_INFO&quot;</p><br /><br /><br /><p>######################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SECURITY&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; #<br />######################################################################<br />#<br /># chroot:<br />#<br />#&nbsp; &nbsp;directory to change to before binding<br />#<br />CHROOT=/home/policyd</p><p>#<br /># uid:<br />#<br />#&nbsp; &nbsp;userid for the policy daemon to run as<br />#<br />UID=1002</p><p>#<br /># gid:<br />#<br />#&nbsp; &nbsp;groupid for the policy daemon to run as<br />#&nbsp; &nbsp;<br />GID=1002</p><p>#<br /># connection acl:<br />#<br />#&nbsp; &nbsp;this is the list of ip addresses or networks (cidr format) that<br />#&nbsp; &nbsp;will be allowed to connect to policyd. leaving this blank causes<br />#&nbsp; &nbsp;policyd to reject all connection attempts.<br />#<br />CONN_ACL=&quot;127.0.0.1&quot;</p><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; WHITELISTING&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (functional) #<br />#####################################################################<br />#<br /># whitelisting:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: on<br />#<br />#&nbsp; &nbsp;this enables whitelisting of ip/netblocks. this is needed<br />#&nbsp; &nbsp;if you want to allow any of the whitelisting features.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />WHITELISTING=1</p><p>#<br /># whitelist null sender:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;null senders are normally used for bounce messages. many<br />#&nbsp; &nbsp;viruses use null senders so its wise to leave this disabled.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />WHITELISTNULL=0</p><p>#<br /># whitelist sender address/domain<br />#<br />#&nbsp; &nbsp;this allows you to do whitelisting based on envelope sender<br />#&nbsp; &nbsp;address or envelope sender domain. a number of people have<br />#&nbsp; &nbsp;been asking for this. please AVOID using this as spammers<br />#&nbsp; &nbsp;forge senders and domains a lot.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />WHITELISTSENDER=1</p><p>#<br /># whitelist client dns name<br />#<br />#&nbsp; &nbsp;this allows you whitelist clients that have proper resolving<br />#&nbsp; &nbsp;records. for example, i could whitelist &#039;bulk.scd.yahoo.com&#039;.<br />#&nbsp; &nbsp;so any connections from n6a.bulk.scd.yahoo.com or<br />#&nbsp; &nbsp;n6b.bulk.scd.yahoo.com would be whitelisted. this type of<br />#&nbsp; &nbsp;whitelisting gives far greater power when it comes to<br />#&nbsp; &nbsp;whitelisting ISPs or big companies which you know do not<br />#&nbsp; &nbsp;house spammers. please note. this table must NOT have more<br />#&nbsp; &nbsp;than 10 000 -&gt; 15 000 entries.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />WHITELISTDNSNAME=0</p><p>#<br /># automatic whitelisting&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;this allows whitelisting of remote networks who have sent<br />#&nbsp; &nbsp;more than AUTO_WHITELIST_NUMBER of authenticated triplets.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />AUTO_WHITE_LISTING=1</p><p>#<br /># auto whitelist number:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 500<br />#<br />#&nbsp; &nbsp;how many succesfull triplets does it require before a<br />#&nbsp; &nbsp;network is automatically whitelisted<br />#<br />AUTO_WHITELIST_NUMBER=10</p><p>#<br /># whitelist netblock/24:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 0<br />#<br />#&nbsp; &nbsp;when hosts get autowhitelisted, should the host be whitelisted<br />#&nbsp; &nbsp;or should the entire netblock (class C).<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=class 0=host<br />AUTO_WHITELIST_NETBLOCK=0</p><p>#<br /># whitelist expiry&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 7 days<br />#<br />#&nbsp; &nbsp;this allows you to specify for what period of time any<br />#&nbsp; &nbsp;host will be whitelisted for when auto whitelisted.<br />#&nbsp; &nbsp;a setting of 0 sets a permanent whitelist<br />#<br />AUTO_WHITELIST_EXPIRE=7d</p><br /><br /><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; BLACKLISTING&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (functional) #<br />#####################################################################<br />#<br /># blacklisting:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: off<br />#<br />#&nbsp; &nbsp;this enables blacklisting of ip/netblocks. this is needed<br />#&nbsp; &nbsp;if you want to allow any of the blacklisting features and<br />#&nbsp; &nbsp;the spamtrapping module. if blacklisting is disabled,<br />#&nbsp; &nbsp;the other modules still run and insert blacklisting records<br />#&nbsp; &nbsp;into the table, but it doesn&#039;t take effect untill you<br />#&nbsp; &nbsp;actually turn blacklisting on. this allows people to look<br />#&nbsp; &nbsp;and what hosts get blacklisted and see if any possible<br />#&nbsp; &nbsp;problems occured. (false-positive)<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />BLACKLISTING=1</p><p>#<br /># blacklist client dns name:<br />#<br />#&nbsp; &nbsp;this allows you blacklist clients that have proper resolving<br />#&nbsp; &nbsp;records. for example, i could blacklist &#039;spamtargeting.com&#039;.<br />#&nbsp; &nbsp;so any connections from mail1.spamtargeting.com or<br />#&nbsp; &nbsp;mail2.spamtargeting.com would be blacklisted. this type of<br />#&nbsp; &nbsp;blacklisting gives far greater power when it comes to<br />#&nbsp; &nbsp;blacklisting ISPs or big companies which you know do<br />#&nbsp; &nbsp;house spammers, or e.g. ADSL home users when their ISPs<br />#&nbsp; &nbsp;give an easily identifiable reverse DNS to them like<br />#&nbsp; &nbsp;adsl-*.revip.thisisp.com. please note. this table must<br />#&nbsp; &nbsp;NOT have more than 10 000 -&gt; 15 000 entries.<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />BLACKLISTDNSNAME=0</p><p>#<br /># blacklist temp rejection:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 4xx<br />#<br />#&nbsp; &nbsp;this allows you to either temp reject (4xx) blacklisted<br />#&nbsp; &nbsp;hosts or if you&#039;re sure that blacklisted hosts are safe<br />#&nbsp; &nbsp;to reject, you can hard reject (5xx) blacklisted hosts.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=4xx&nbsp; 0=5xx<br />BLACKLIST_TEMP_REJECT=0</p><p>#<br /># blacklist netblock/24:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: host<br />#<br />#&nbsp; &nbsp;when hosts get blacklisted, should the host be blacklisted<br />#&nbsp; &nbsp;or should the entire netblock (class C). this applies to<br />#&nbsp; &nbsp;both when a host gets blacklisted via the spamtrap module<br />#&nbsp; &nbsp;or via the blacklist helo module.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=class 0=host<br />BLACKLIST_NETBLOCK=0</p><p>#<br /># blacklist rejection&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: &quot;Abuse. Go Away&quot;<br />#<br />#&nbsp; &nbsp;what error message blacklisted hosts will recieve.<br />#<br />BLACKLIST_REJECTION=&quot;Abuse. Go away.&quot;</p><p>#<br /># automatic blacklisting&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;this allows blacklisting of remote networks who have sent<br />#&nbsp; &nbsp;more than AUTO_BLACKLIST_NUMBER of unauthenticated triplets.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />AUTO_BLACK_LISTING=1</p><p>#<br /># auto blacklist number:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 500<br />#<br />#&nbsp; &nbsp;how many succesfull untriplets does it require before a<br />#&nbsp; &nbsp;network is automatically blacklisted<br />#<br />AUTO_BLACKLIST_NUMBER=500</p><p>#<br /># blacklist expiry&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 7 days<br />#<br />#&nbsp; &nbsp;this allows you to specify for what period of time any<br />#&nbsp; &nbsp;host will be blacklisted for when auto blacklisted.<br />#&nbsp; &nbsp;a setting of 0 sets a permanent blacklist<br />#<br />AUTO_BLACKLIST_EXPIRE=7d</p><br /><br /><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; BLACKLISTING HELO&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;(functional) #<br />#####################################################################<br />#<br /># blacklisting helo:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;this enables blacklisting of ip/netblocks who attempt to<br />#&nbsp; &nbsp;identify themselve as you. no legit MTA should be using<br />#&nbsp; &nbsp;your helo identity when connecting to your machines.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />BLACKLIST_HELO=0</p><p>#<br /># blacklist helo auto expire:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: permanent<br />#<br />#&nbsp; &nbsp;this allows you to specify for what period of time any<br />#&nbsp; &nbsp;host will be blacklisted for when it has been caught<br />#&nbsp; &nbsp;using your HELO to identify itself. (a setting of 0<br />#&nbsp; &nbsp;sets a permanent blacklist)<br />#<br />BLACKLIST_HELO_AUTO_EXPIRE=0</p><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; BLACKLIST SENDER&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (functional) #<br />#####################################################################<br />#<br /># blacklist sender:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: off<br />#<br />#&nbsp; &nbsp;this allows you to use policyd to block domains and/or&nbsp; &nbsp;<br />#&nbsp; &nbsp;email addresses.<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />BLACKLISTSENDER=1</p><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;HELO_CHECK&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;(functional) #<br />#####################################################################<br />#<br /># helo unique checking&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;(legit) hosts that connect to your mail servers 99% of<br />#&nbsp; &nbsp;the time use static HELO information. spammers randomize<br />#&nbsp; &nbsp;their helo. enabling this will cut down the amount of<br />#&nbsp; &nbsp;spam entering your network.<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />HELO_CHECK=1</p><p>#<br /># helo max number count:<br />#<br />#&nbsp; &nbsp;this allows you to specify how many unique/different<br />#&nbsp; &nbsp;helo names a connecting host/ip is allowed to send.<br />#&nbsp; &nbsp;spammers randomize their helo information in big<br />#&nbsp; &nbsp;numbers. legit MTAs with floating ips also do this,<br />#&nbsp; &nbsp;but the number of them is fairly small.<br />#<br />#<br />HELO_MAX_COUNT=10</p><p>#<br /># helo blacklist auto expire:<br />#<br />#&nbsp; &nbsp;this allows you to specify for what period of time any<br />#&nbsp; &nbsp;host will be blacklisted for when it has been caught<br />#&nbsp; &nbsp;randomizing their helo information. (a setting of 0<br />#&nbsp; &nbsp;sets a permanent blacklist)<br />#<br />HELO_BLACKLIST_AUTO_EXPIRE=14d</p><p>#<br /># helo auto expire:<br />#<br />#&nbsp; &nbsp;this allows you to specify for what period of time any<br />#&nbsp; &nbsp;HELO identity will remain in the database for before it<br />#&nbsp; &nbsp;gets expired. (a setting of 0 ensures that all HELO<br />#&nbsp; &nbsp;information stays stored and is never expired).<br />#<br />HELO_AUTO_EXPIRE=7d</p><br /><br /><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;SPAMTRAP&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;(functional) #<br />#####################################################################<br />#<br /># enable spamtrap&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: off<br />#<br />#&nbsp; &nbsp;the idea of this module is to allow you to capture<br />#&nbsp; &nbsp;hosts that mail to your spamtraps without having to<br />#&nbsp; &nbsp;resort to parsing the mails to identify senders. you<br />#&nbsp; &nbsp;now have the ability to blacklist the host/netblock<br />#&nbsp; &nbsp;for a period of time (definable in SPAMTRAP_AUTO_EXPIRE).<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />SPAMTRAPPING=1</p><p>#<br /># spamtrap rejection:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: &quot;Abuse. Go Away.&quot;<br />#<br />#&nbsp; &nbsp;what error message the connecting host will recieve<br />#&nbsp; &nbsp;when a message is directly sent to your spamtraps<br />#<br />SPAMTRAP_REJECTION=&quot;Abuse. Go away.&quot;</p><p>#<br /># spamtrap auto expire:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 7 days<br />#<br />#&nbsp; &nbsp;this allows you to specify for what period of time any<br />#&nbsp; &nbsp;host will be blacklisted for when it has been caught<br />#&nbsp; &nbsp;mailing to your spamtrap addresses. (a setting of 0<br />#&nbsp; &nbsp;sets a permanent blacklist)<br />#<br />SPAMTRAP_AUTO_EXPIRE=7d</p><br /><br /><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GREYLISTING&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;(functional) #<br />#####################################################################<br />#<br /># enable greylisting&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: on<br />#<br />#&nbsp; &nbsp;whether greylisting should be enabled or disabled.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />GREYLISTING=0</p><p>#<br /># greylist rejection:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: &quot;Please try later&quot;<br />#<br />#&nbsp; &nbsp;what error message the connecting host will recieve<br />#&nbsp; &nbsp;when a new triplet has been created.<br />#<br />GREYLIST_REJECTION=&quot;Please try later.&quot;</p><p>#<br /># greylist x-header:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;you now have the functionality of tagging all mail<br />#&nbsp; &nbsp;that has passed greylisting.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />GREYLIST_X_HEADER=0</p><p>#<br /># greylist host address:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;by default policyd will only use 3 octets when dealing<br />#&nbsp; &nbsp;with greylisting information. this allows policyd to<br />#&nbsp; &nbsp;work around roaming MTAs which are known to move mail<br />#&nbsp; &nbsp;between different queues after a 450/temp rejection.<br />#&nbsp; &nbsp;<br />#&nbsp; &nbsp;some dont want this functionality and wish to be more<br />#&nbsp; &nbsp;aggressive when receiving mail. example of the format<br />#&nbsp; &nbsp;of the ips stored:<br />#<br />#&nbsp; &nbsp;1=192<br />#&nbsp; &nbsp;2=192.168<br />#&nbsp; &nbsp;3=192.168.0&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;- default/recommended<br />#&nbsp; &nbsp;4=192.168.0.1<br />#<br />GREYLIST_HOSTADDR=3</p><p>#<br /># train database:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: off<br />#<br />#&nbsp; &nbsp;this is very usefull for people would want to build<br />#&nbsp; &nbsp;up a collection of triplets before they start rejecting<br />#&nbsp; &nbsp;mail. training mode allows the collection of triplets<br />#&nbsp; &nbsp;to mature to a stage that when greylisting is actually<br />#&nbsp; &nbsp;enabled, they impact caused is far far less.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />TRAINING_MODE=0</p><p>#<br /># training policy duration/timeout&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 0d<br />#<br />#&nbsp; &nbsp;when you have run TRAINING_MODE for your all your domains<br />#&nbsp; &nbsp;and are running greylisting across the board, adding new<br />#&nbsp; &nbsp;domains and subjecting them to greylisting without a <br />#&nbsp; &nbsp;training period can bring unnessasary hassles. this feature<br />#&nbsp; &nbsp;allows you to specify for how long &#039;new domains&#039; are to be<br />#&nbsp; &nbsp;trained for before being subjected to greylisting.<br />#<br />#&nbsp; &nbsp;a value of 0 disables this feature.<br />#<br />TRAINING_POLICY_TIMEOUT=0</p><p>#<br />#<br /># triplet timeout:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 4 minutes<br />#<br />#&nbsp; &nbsp;when a triplet is created from the first mail delivery<br />#&nbsp; &nbsp;attempt, what period of time should go by before we<br />#&nbsp; &nbsp;allow the &#039;final delivery&#039;. a study shows that there<br />#&nbsp; &nbsp;is no difference between 1 minute and 1 hour for spam<br />#&nbsp; &nbsp;at this point in time. a sane limit would be 5 minutes.<br />#&nbsp; &nbsp;<br />TRIPLET_TIME=5m</p><p>#<br /># opt in and opt out:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: off<br />#<br />#&nbsp; &nbsp;some people are fairly irate when it comes to mail and<br />#&nbsp; &nbsp;refuse wanting to have any type of delay. this feature<br />#&nbsp; &nbsp;enables each and every person the ability to not subject<br />#&nbsp; &nbsp;themselves to greylisting. this feature is also VERY<br />#&nbsp; &nbsp;usefull when you dont want to subject EVERY person to<br />#&nbsp; &nbsp;greylisting at once but instead allows you to enable<br />#&nbsp; &nbsp;it in batches/groups of users so you get a feel on the<br />#&nbsp; &nbsp;type of complaints or praise from your users.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />OPTINOUT=0</p><p>#<br /># optinoutall:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;this allows you to either opt everyone in, or opt every<br />#&nbsp; &nbsp;one out and only has any effect if OPTINOUT is enabled.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />OPTINOUTALL=0</p><p>#<br /># triplet authenticated cleanup&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 30d<br />#<br />#&nbsp; &nbsp;if a triplet has been successfully updated (retried and<br />#&nbsp; &nbsp;delivered), this is what is considered an &#039;authenticated&#039;<br />#&nbsp; &nbsp;triplet. this options allows some sanity so you do not<br />#&nbsp; &nbsp;keep these triplets forever. specify the amount of days<br />#&nbsp; &nbsp;that we keep authenticated triplets since it was last updated.<br />#<br />TRIPLET_AUTH_TIMEOUT=7d</p><p>#<br /># triplet unauthenticated cleanup&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 2d<br />#<br />#&nbsp; &nbsp;if a triplet has NOT been successfully updated (no retry<br />#&nbsp; &nbsp;attempt), this is what is considered as an &#039;unathenticated&#039;<br />#&nbsp; &nbsp;triplet. this option allows some sanity so you do not<br />#&nbsp; &nbsp;keep these triplets forever. specify the amount of days<br />#&nbsp; &nbsp;that we keep unauthenticated triplets since being inserted<br />#&nbsp; &nbsp;into the database<br />#<br />TRIPLET_UNAUTH_TIMEOUT=2d</p><br /><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SENDER THROTTLE&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;(functional) #<br />#####################################################################<br />#<br /># throttle senders&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: off<br />#<br />#&nbsp; &nbsp;sender throttling allows per-user limits of all<br />#&nbsp; &nbsp;mail that passes the policy daemon. any envelope<br />#&nbsp; &nbsp;sender that is not found in the database will<br />#&nbsp; &nbsp;fall back to the config defaults listed below.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />SENDERTHROTTLE=0</p><p>#<br /># throttle SASL users&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default=on<br />#<br />#&nbsp; &nbsp;throttling based upon envelope sender addresses does<br />#&nbsp; &nbsp;not work very well as it can of course be easily forged.<br />#&nbsp; &nbsp;if your users are forced to authenticate via SASL, enable<br />#&nbsp; &nbsp;this option so that quotas stick like glue regardless of<br />#&nbsp; &nbsp;what they try.<br />#<br />#&nbsp; &nbsp;if this option is enabled, and a remote client connects<br />#&nbsp; &nbsp;WITHOUT sasl, it will then use the clients sending/FROM<br />#&nbsp; &nbsp;address.<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />SENDER_THROTTLE_SASL=0</p><p>#<br /># throttle IP addresses&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default=on<br />#<br />#&nbsp; &nbsp;throttling based upon the ip address of the sender<br />#&nbsp; &nbsp;will ensure that the host does not send more than<br />#&nbsp; &nbsp;their allowed quota. you may only enable <br />#&nbsp; &nbsp;SENDER_THROTTLE_SASL or SENDER_THROTTLE_HOST but<br />#&nbsp; &nbsp;*NOT* both.<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />SENDER_THROTTLE_HOST=0</p><p>#<br /># quota exceeded temp rejection:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 5xx<br />#<br />#&nbsp; &nbsp;select temp reject (4xx) or hard reject (5xx) on quota exceeded<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=4xx&nbsp; 0=5xx<br />QUOTA_EXCEEDED_TEMP_REJECT=1</p><p>#<br /># throttle rejection:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: &quot;Quota Exceeded&quot;<br />#<br />#&nbsp; &nbsp;what error message the connecting host will recieve<br />#&nbsp; &nbsp;when they have exceeded any of their quotas.<br />#<br />SENDER_QUOTA_REJECTION=&quot;Quota Exceeded.&quot;</p><p>#<br /># throttle max message size reject message&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: Message size too big<br />#<br />#&nbsp; &nbsp;<br />#<br />SENDER_SIZE_REJECTION=&quot;Message size too big.&quot;</p><p>#<br /># maximum mail sent per time period&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 5000<br />#<br />#&nbsp; &nbsp;how many messages a user is allowed to send out<br />#&nbsp; &nbsp;before the time limit has expired.<br />#<br />SENDERMSGLIMIT=512</p><p>#<br /># maximum mail recipients per time period&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 5000<br />#<br />#&nbsp; &nbsp;how many recipients a user is allowed to send out<br />#&nbsp; &nbsp;before the time limit has expired.<br />#<br />SENDERRCPTLIMIT=3600</p><p>#<br /># maximum mail quota/size per time period&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 250 meg<br />#<br />#&nbsp; &nbsp;how much mail will be allowed from a user (in megs)<br />#&nbsp; &nbsp;which will be accepted before the timelimit has expired.<br />#&nbsp; &nbsp;note: the maximum supported size is 2gig<br />#<br />SENDERQUOTALIMIT=250000000</p><p>#<br /># sender time limit:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 24 hours<br />#<br />#&nbsp; &nbsp;after how long does all quota last before counters<br />#&nbsp; &nbsp;are reset back to to zero.<br />#<br />SENDERTIMELIMIT=1h</p><p>#<br /># sender message size:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default: 10 meg<br />#<br />#&nbsp; &nbsp;this is the maximum sender mail size<br />#<br />SENDERMSGSIZE=10240000</p><p>#<br /># sender &quot;warning&quot; threshold<br />#<br />#&nbsp; &nbsp;this is the threshold (in percentage) that will trigger a<br />#&nbsp; &nbsp;a warning to syslog. valid percentages are 1 -&gt; 99<br />#<br />SENDERMSGSIZE_WARN=50</p><p>#<br /># sender &quot;panic&quot; threshold<br />#<br />#&nbsp; &nbsp;this is the threshold (in percentage) that will trigger a<br />#&nbsp; &nbsp;a warning to syslog. valid percentages are 1 -&gt; 99<br />#<br />SENDERMSGSIZE_PANIC=90</p><p>#<br /># inactive sender database record cleanup&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 31 days<br />#<br />#&nbsp; &nbsp;this allows you to specify how long the throttling<br />#&nbsp; &nbsp;records of inactive senders kept in the database.<br />#&nbsp; &nbsp;this allows to keep the database small. a setting<br />#&nbsp; &nbsp;of 0 keeps all entries.<br />#<br />SENDER_INACTIVE_EXPIRE=31d</p><br /><br /><br /><p>#####################################################################<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; RECIPIENT THROTTLE&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (functional) #<br />#####################################################################<br />#<br /># throttle recipients&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: off<br />#<br />#&nbsp; &nbsp;recipient throttling allows per-user limits of all<br />#&nbsp; &nbsp;mail that passes the policy daemon. any envelope<br />#&nbsp; &nbsp;recipient that is not found in the database will<br />#&nbsp; &nbsp;fall back to the config defaults listed below.<br />#<br />#&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1=on&nbsp; 0=off<br />RECIPIENTTHROTTLE=0</p><p>#<br /># maximum mail sent per time period&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 5000<br />#<br />#&nbsp; &nbsp;how many messages a user is allowed to send out<br />#&nbsp; &nbsp;before the time limit has expired.<br />#<br />RECIPIENTMSGLIMIT=64</p><p>#<br /># recipient time limit:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: 24 hours<br />#<br />#&nbsp; &nbsp;after how long does all quota last before counters<br />#&nbsp; &nbsp;are reset back to to zero.<br />#<br />RECIPIENTTIMELIMIT=1h</p><p># throttle recipient rejection:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;default: &quot;Quota Exceeded&quot;<br />#<br />#&nbsp; &nbsp;what error message the connecting host will recieve<br />#&nbsp; &nbsp;when they have exceeded any of their quotas.<br />#<br />RECIPIENT_QUOTA_REJECTION=&quot;Quota Exceeded.&quot;</p><p>#<br /># inactive recipients database record cleanup&nbsp; &nbsp; &nbsp; &nbsp;default: 31 days<br />#<br />#&nbsp; &nbsp;this allows you to specify how long the throttling<br />#&nbsp; &nbsp;records of inactive recipients are kept in the database.<br />#&nbsp; &nbsp;this allows to keep the database small. a setting<br />#&nbsp; &nbsp;of 0 keeps all entries.<br />#<br />RECIPIENT_INACTIVE_EXPIRE=31d</p><br /><br /><p>#######<br /># EOF #<br />#######</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Wed, 16 Jan 2013 17:50:05 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19895.html#p19895</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19881.html#p19881</link>
			<description><![CDATA[<p>Policyd stores per-user/per-domain settings in SQL database. The one in postfix-policyd_throttle.conf is a global setting, it will override the one in Postfix (main.cf) if you have Policyd enabled.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Wed, 16 Jan 2013 11:46:27 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19881.html#p19881</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19861.html#p19861</link>
			<description><![CDATA[<div class="quotebox"><cite>ZhangHuangbin wrote:</cite><blockquote><p>The problem is you didn&#039;t enable sender throttling in Postfix and Policyd. Please follow this tutorial:<br /><a href="http://www.iredmail.org/wiki/index.php?title=IRedMail/FAQ/Enable.Throttling/Debian.Ubuntu">http://www.iredmail.org/wiki/index.php? … ian.Ubuntu</a></p></blockquote></div><br /><p>Enabled as per document</p><p>Problem:&nbsp; &nbsp;The admin panel is still not overriding the settings in the main.cf &amp; postfix-policyd_throttle.conf</p><p>postfix-policyd_throttle.conf<br />SENDERMSGSIZE=15728640</p><p>main.cf <br />message_size_limit = 15728640</p><p>How does the iredadmin-pro mysql admin panel override this setting?<br />So far it is still limited to 15 mb, I set 30 mb</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Tue, 15 Jan 2013 15:19:41 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19861.html#p19861</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19853.html#p19853</link>
			<description><![CDATA[<p>The problem is you didn&#039;t enable sender throttling in Postfix and Policyd. Please follow this tutorial:<br /><a href="http://www.iredmail.org/wiki/index.php?title=IRedMail/FAQ/Enable.Throttling/Debian.Ubuntu">http://www.iredmail.org/wiki/index.php? … ian.Ubuntu</a></p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 15 Jan 2013 03:28:38 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19853.html#p19853</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19849.html#p19849</link>
			<description><![CDATA[<p>Any Ideas?</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Mon, 14 Jan 2013 19:43:24 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19849.html#p19849</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19805.html#p19805</link>
			<description><![CDATA[<p>postconf -n<br />alias_database = hash:/etc/postfix/aliases<br />alias_maps = hash:/etc/postfix/aliases<br />allow_min_user = no<br />append_dot_mydomain = no<br />biff = no<br />bounce_queue_lifetime = 1d<br />broken_sasl_auth_clients = yes<br />config_directory = /etc/postfix<br />content_filter = smtp-amavis:[127.0.0.1]:10024<br />delay_warning_time = 0h<br />disable_vrfy_command = yes<br />dovecot_destination_recipient_limit = 1<br />enable_original_recipient = no<br />home_mailbox = Maildir/<br />inet_interfaces = all<br />inet_protocols = ipv4<br />mailbox_command = /usr/lib/dovecot/deliver<br />mailbox_size_limit = 0<br />maximal_backoff_time = 4000s<br />maximal_queue_lifetime = 1d<br />message_size_limit = 15728640<br />minimal_backoff_time = 300s<br />mydestination = $myhostname, localhost, localhost.localdomain, localhost.$myhost&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; name<br />mydomain = abgnetwork.net<br />myhostname = nm2.abgnetwork.net<br />mynetworks = 127.0.0.0/8, 10.254.10.0/24<br />mynetworks_style = subnet<br />myorigin = /etc/mailname<br />proxy_read_maps = $canonical_maps $lmtp_generic_maps $local_recipient_maps $myde&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; stination $mynetworks $smtpd_sender_login_maps $recipient_bcc_maps $recipient_ca&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; nonical_maps $relay_domains $relay_recipient_maps $relocated_maps $sender_bcc_ma&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ps $sender_canonical_maps $smtp_generic_maps $transport_maps $virtual_alias_doma&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ins $virtual_alias_maps $virtual_mailbox_domains $virtual_mailbox_maps $smtpd_se&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; nder_restrictions<br />queue_run_delay = 300s<br />readme_directory = no<br />recipient_bcc_maps = proxy:mysql:/etc/postfix/mysql/recipient_bcc_maps_user.cf,&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;proxy:mysql:/etc/postfix/mysql/recipient_bcc_maps_domain.cf<br />recipient_delimiter = +<br />relay_domains = $mydestination, proxy:mysql:/etc/postfix/mysql/relay_domains.cf<br />relayhost =<br />sender_bcc_maps = proxy:mysql:/etc/postfix/mysql/sender_bcc_maps_user.cf, proxy:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; mysql:/etc/postfix/mysql/sender_bcc_maps_domain.cf<br />smtp-amavis_destination_recipient_limit = 1<br />smtp_data_init_timeout = 240s<br />smtp_data_xfer_timeout = 600s<br />smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache<br />smtpd_banner = $myhostname ESMTP $mail_name (Debian/GNU)<br />smtpd_data_restrictions = reject_unauth_pipelining<br />smtpd_enforce_tls = no<br />smtpd_helo_required = yes<br />smtpd_helo_restrictions = permit_mynetworks,permit_sasl_authenticated, check_hel&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; o_access pcre:/etc/postfix/helo_access.pcre<br />smtpd_recipient_restrictions = reject_unknown_sender_domain, reject_unknown_reci&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; pient_domain, reject_non_fqdn_sender, reject_non_fqdn_recipient, reject_unlisted&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; _recipient, check_policy_service inet:127.0.0.1:7777, permit_mynetworks, permit_&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; sasl_authenticated, reject_unauth_destination, reject_non_fqdn_helo_hostname, re&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ject_invalid_helo_hostname, check_policy_service inet:127.0.0.1:10031<br />smtpd_reject_footer = For assistance, call Advanced Business Group 847-247-0700.&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Please provide the following information in your problem report: time ($localti&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; me), client ($client_address) and server ($server_name).<br />smtpd_reject_unlisted_recipient = yes<br />smtpd_reject_unlisted_sender = yes<br />smtpd_sasl_auth_enable = yes<br />smtpd_sasl_authenticated_header = no<br />smtpd_sasl_local_domain =<br />smtpd_sasl_path = ./dovecot-auth<br />smtpd_sasl_security_options = noanonymous<br />smtpd_sasl_type = dovecot<br />smtpd_sender_login_maps = proxy:mysql:/etc/postfix/mysql/sender_login_maps.cf<br />smtpd_sender_restrictions = permit_mynetworks, reject_sender_login_mismatch, per&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; mit_sasl_authenticated<br />smtpd_tls_CAfile = /etc/ssl/certs/gd_bundle.crt<br />smtpd_tls_cert_file = /etc/ssl/certs/nm2.abgnetwork.net.crt<br />smtpd_tls_key_file = /etc/ssl/private/nm2.key<br />smtpd_tls_loglevel = 0<br />smtpd_tls_security_level = may<br />smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache<br />smtpd_use_tls = yes<br />tls_random_source = dev:/dev/urandom<br />transport_maps = proxy:mysql:/etc/postfix/mysql/transport_maps_user.cf, proxy:my&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; sql:/etc/postfix/mysql/transport_maps_domain.cf<br />virtual_alias_domains =<br />virtual_alias_maps = proxy:mysql:/etc/postfix/mysql/virtual_alias_maps.cf, proxy&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; :mysql:/etc/postfix/mysql/domain_alias_maps.cf, proxy:mysql:/etc/postfix/mysql/c&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; atchall_maps.cf, proxy:mysql:/etc/postfix/mysql/domain_alias_catchall_maps.cf<br />virtual_gid_maps = static:1001<br />virtual_mailbox_base = /var/vmail<br />virtual_mailbox_domains = proxy:mysql:/etc/postfix/mysql/virtual_mailbox_domains&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; .cf<br />virtual_mailbox_maps = proxy:mysql:/etc/postfix/mysql/virtual_mailbox_maps.cf<br />virtual_minimum_uid = 1001<br />virtual_transport = dovecot<br />virtual_uid_maps = static:1001</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Thu, 10 Jan 2013 14:41:07 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19805.html#p19805</guid>
		</item>
		<item>
			<title><![CDATA[Re: Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19794.html#p19794</link>
			<description><![CDATA[<p>Could you please paste output of command &quot;postconf -n&quot; to help troubleshoot?</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Wed, 09 Jan 2013 10:24:41 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19794.html#p19794</guid>
		</item>
		<item>
			<title><![CDATA[Admin panel Mail size vs Postfix Mail size]]></title>
			<link>http://www.iredmail.org/forum/post19790.html#p19790</link>
			<description><![CDATA[<p>==== Required information ====<br />- iRedMail version:&nbsp; &nbsp;0.82<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): mysql (iRedAdmin-Pro-MySQL-1.5.0.tar.bz2 )<br />- Linux/BSD distribution name and version: Debian<br />- Related log if you&#039;re reporting an issue: <br />==== </p><p>Postfix specifies 15 mb</p><p>MYSQL admin panel, under domain, I have enabled sender throttling<br />max size of single outgoing email is 30mb</p><p>Problem:&nbsp; The system is using the setting set in Postfix</p><p>the quota size of all outgoing emails is 0, is this my mistake, should this be 30 mb?</p><p>If some is over the quota, where is it logged?&nbsp; &nbsp;/var/log/mail&nbsp; ???</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Tue, 08 Jan 2013 23:38:43 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post19790.html#p19790</guid>
		</item>
	</channel>
</rss>
