exim и relay

EXIM, sendmail, postfix, Dovecot и прочие. Решение проблем связанных с работой электронной почты

Модератор: xM

Правила форума
Убедительная просьба юзать теги [code] при оформлении листингов.
Сообщения не оформленные должным образом имеют все шансы быть незамеченными.
Аватара пользователя
Cheshirski
рядовой
Сообщения: 18
Зарегистрирован: 2009-09-02 10:13:41
Откуда: Ленинск-Кузнецкий
Контактная информация:

exim и relay

Непрочитанное сообщение Cheshirski » 2010-08-02 12:15:41

Подскажите пожалуйся что не так сделано, стоит в офисе почтарь, на нем висит куча замороженных сообщений, при это в конфиге прописано:

Код: Выделить всё

hostlist   relay_from_hosts = localhost:10.2.2.0/24
при просмотре тела замороженного письма вижу:

Код: Выделить всё

mail# exim -Mvb 1Ofr2W-0003CQ-R1
1Ofr2W-0003CQ-R1-D
This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  41270000dc568c47@router.acoustics.ru
    retry time not reached for any host after a long failure period
  574200008751ef46@router.acoustics.ru
    retry time not reached for any host after a long failure period

------ This is a copy of the message, including all the headers. ------

Return-path: <sasalmvteb@big-d.com>
Received: from [10.50.10.176] (helo=ххх)
	by mail.lenkuz.ru with esmtp (Exim 4.72 (FreeBSD))
	(envelope-from <sasalmvteb@big-d.com>)
	id 1OeN29-000483-Mn; Thu, 29 Jul 2010 13:56:01 +0700
Date: Thu, 29 Jul 2010 14:58:20 +0700
Message-ID: <000901cb2eeb$6dbc2470$00426d68@verdfxfufi>
From: =?windows-1251?B?wf7w7iDv8/Ll+OXx8uLo6Q==?= <sasalmvteb@big-d.com>
To: <574200008751ef46@router.acoustics.ru>
Subject: =?windows-1251?B?zvLk+/Xg5ewg4iDv7uTs7vHq7uLt7ukg2OLl6fbg8OjoIA==?=
MIME-Version: 1.0
Content-Type: text/plain; charset="windows-1251"
Content-Transfer-Encoding: quoted-printable
Откуда Received: from [10.50.10.176] вот это вот чудо?

Хостинговая компания Host-Food.ru
Хостинг HostFood.ru
 

Услуги хостинговой компании Host-Food.ru

Хостинг HostFood.ru

Тарифы на хостинг в России, от 12 рублей: https://www.host-food.ru/tariffs/hosting/
Тарифы на виртуальные сервера (VPS/VDS/KVM) в РФ, от 189 руб.: https://www.host-food.ru/tariffs/virtualny-server-vps/
Выделенные сервера, Россия, Москва, от 2520 рублей (8 CPU, 8Gb RAM, 2x500Gb HDD, RAID 3ware 9750):
https://www.host-food.ru/tariffs/vydelennyi-server-ds/
Недорогие домены в популярных зонах: https://www.host-food.ru/domains/

Аватара пользователя
hizel
дядя поня
Сообщения: 9031
Зарегистрирован: 2007-06-29 10:05:02
Откуда: Выборг

Re: exim и relay

Непрочитанное сообщение hizel » 2010-08-02 12:51:41

relay_from_hosts это просто переменная и нужна вся конфигурация
В дурацкие игры он не играет. Он просто жуткий, чу-чу, паровозик, и зовут его Блейн. Блейн --- это Боль.

Аватара пользователя
Cheshirski
рядовой
Сообщения: 18
Зарегистрирован: 2009-09-02 10:13:41
Откуда: Ленинск-Кузнецкий
Контактная информация:

Re: exim и relay

Непрочитанное сообщение Cheshirski » 2010-08-03 8:24:50

Код: Выделить всё

mail# less configure.xxx 
 primary_hostname =     mail.lenkuz.ru

hide mysql_servers = localhost/dbmail/dbmail/dbmail

domainlist local_domains = ${lookup mysql{SELECT `domainname` \
                                FROM `domains` WHERE \
                                `domainname`='${domain}' AND \
                                (`type`='LOCAL' OR `type`='VIRTUAL')}}
domainlist relay_to_domains = ${lookup mysql{SELECT `domainname` \
                                FROM `domains` WHERE \
                                `domainname`='${domain}' \
                                 AND `type`='RELAY'}}

hostlist   relay_from_hosts = localhost:10.2.2.0/24

acl_smtp_rcpt = acl_check_rcpt
acl_smtp_data = acl_check_data

 av_scanner = clamd:/var/run/clamav/clamd.sock


# spamd_address = 127.0.0.1 783

 qualify_domain = lenkuz.ru


 qualify_recipient = mail.lenkuz.ru

exim_user = mailnull
exim_group = mail
never_users = root

host_lookup = *

rfc1413_hosts = *
rfc1413_query_timeout = 5s
 sender_unqualified_hosts = +relay_from_hosts
 
 recipient_unqualified_hosts = +relay_from_hosts
 
ignore_bounce_errors_after = 45m

timeout_frozen_after = 7d


begin acl

acl_check_rcpt:

  accept  hosts = :
          control = dkim_disable_verify

  deny    message       = Restricted characters in address
          domains       = +local_domains
          local_parts   = ^[.] : ^.*[@%!/|]


  deny    message       = Restricted characters in address
          domains       = !+local_domains
          local_parts   = ^[./|] : ^.*[@%!] : ^.*/\\.\\./

  accept  local_parts   = postmaster
          domains       = +local_domains


  require verify        = sender

  accept  hosts         = +relay_from_hosts
          control       = submission
          control       = dkim_disable_verify

  accept  authenticated = *
          control       = submission
          control       = dkim_disable_verify

  require message = relay not permitted
          domains = +local_domains : +relay_to_domains

  require verify = recipient

  
  drop    message       = Go Away
          condition     = ${if match{$sender_host_name} \
                      {bezeqint\\.net|net\\.il|dialup|dsl|pool|peer|dhcp} \
                      {yes}{no}}
 drop    message       = message from \
  $sender_host_address rejected - see http://njabl.org/
          log_message   = found in $dnslist_domain
          dnslists      = dnsbl.njabl.org
  drop    message       = rejected because \
  $sender_host_address for bad WHOIS info, see http://www.rfc-ignorant.org/
          log_message   = found in $dnslist_domain
          dnslists      = ipwhois.rfc-ignorant.org
  drop    message       = rejected because $sender_host_address \
  is in a black list at $dnslist_domain\n$dnslist_text
          log_message   = found in $dnslist_domain
          dnslists      = dialups.mail-abuse.org
  drop    message       = rejected because $sender_host_address \
  is in a black list at $dnslist_domain\n$dnslist_text
          log_message   = found in $dnslist_domain
          dnslists      = list.dsbl.org
  drop    message       = Spam blocked see: \
  http://www.spamcop.net/w3m?action=checkblock&ip=$sender_host_address
          log_message   = found in $dnslist_domain
          dnslists      = bl.spamcop.net
  drop    message       = rejected, $sender_host_address \
  Open Proxy, see: $dnslist_domain\n$dnslist_text
          log_message   = found in $dnslist_domain
          dnslists      = dnsbl.void.ru


  accept



acl_check_data:

   deny    malware    = *
           message    = This message contains a virus ($malware_name).

   warn    spam       = nobody
           add_header = X-Spam_score: $spam_score\n\
                        X-Spam_score_int: $spam_score_int\n\
                        X-Spam_bar: $spam_bar\n\
                        X-Spam_report: $spam_report

  # Accept the message.

  accept



begin routers


dnslookup:
  driver = dnslookup
  domains = ! +local_domains
  transport = remote_smtp
  ignore_target_hosts = 0.0.0.0 : 127.0.0.0/8
  no_more



dbmailuser:
    driver = accept
    condition = ${lookup mysql{SELECT `alias_idnr` FROM \
    `dbmail_aliases` WHERE \
    `alias`='${quote_mysql:$local_part@$domain}' OR \
    `alias`='${quote_mysql:@$domain}'}{yes}{no}}
    transport = dbmail_delivery

dspam_router:
   no_verify
   check_local_user
   # When to scan a message :
   # - it isn't already flagged as spam from Spamassassin
   # - it isn't already flagged as spam from DSPAM
   # - it isn't already scanned
   # - it isn't local
   # - it isn't from one internal domain user to another
   # - it is less than 512k in size
   condition   = "${if and { \
                           {!def:h_X-Spam-Flag:} \
                           {!def:h_X-FILTER-DSPAM:} \
                           {!eq {$received_protocol}{local}} \
                           { <= {$message_size}{512k}} \
                           }\
                           {1}{0}}"
   headers_add  = "X-FILTER-DSPAM: by $primary_hostname on $tod_full"
   driver       = accept
   transport    = dspam_spamcheck
   # Which users to run dspam for.
   #local_parts = /usr/local/etc/exim/dspam-testers
dspam_addspam_router:
 driver            = accept
 local_part_prefix = spam-
 transport         = dspam_addspam
dspam_falsepositive_router:
 driver            = accept
 local_part_prefix = nospam-
 transport         = dspam_falsepositive
    
    
begin transports



remote_smtp:
  driver = smtp
  interface = 81.1.202.154


dbmail_delivery:
    driver = pipe
    check_string =
    command = /usr/local/sbin/dbmail-smtp -d ${pipe_addresses}
    group = mail
    message_prefix = ""
    message_suffix = ""
    path="/bin:/sbin:/usr/local/bin:/usr/local/sbin"
address_pipe:
  driver = pipe
  return_output


# This transport is used for handling deliveries directly to files that are
# generated by aliasing or forwarding.

address_file:
  driver = appendfile
  delivery_date_add
  envelope_to_add
  return_path_add


# This transport is used for handling autoreplies generated by the filtering
# option of the userforward router.

address_reply:
  driver = autoreply


dspam_spamcheck:
 driver = pipe
 command = "/usr/local/bin/dspam --deliver=innocent --user ${lc:$local_part} -f \
           '$sender_address' -- %u"
 home_directory = "/tmp"
 current_directory = "/tmp"
 user = mailnull
 group = mail
 log_output = true
 return_fail_output = true
 return_path_add = false
 message_prefix =
 message_suffix =
dspam_addspam:
 driver = pipe
 command = "/usr/local/bin/dspam --class=spam --source=error --user \
            ${lc:$local_part} -f '$sender_address' -- %u"
 home_directory = "/tmp"
 current_directory = "/tmp"
 user = mailnull
 group = mail
 log_output = true
 return_fail_output = true
 return_path_add = false
 message_prefix =
 message_suffix =

dspam_falsepositive:
 driver = pipe
 command = "/usr/local/bin/dspam --class=innocent --source=error \
           --deliver=innocent,spam --user ${lc:$local_part}\
           -f '$sender_address' -- %u"
 home_directory = "/tmp"
 current_directory = "/tmp"
 user = mailnull
 group = mail
 log_output = true
 return_fail_output = true
 return_path_add = false
 message_prefix =
 message_suffix =


begin retry
# retry rule unless you really don't want any retries.

# Address or Domain    Error       Retries
# -----------------    -----       -------

*                      *           F,2h,15m; G,16h,1h,1.5; F,4d,6h



begin rewrite




begin authenticators


auth_plain:
    driver = plaintext
    public_name = PLAIN
    server_condition = ${lookup mysql{SELECT `user_idnr` FROM \
    `dbmail_users` WHERE `userid` = \
    '${quote_mysql:$1}' AND `passwd` = \
    '${quote_mysql:$2}'}{yes}{no}}
    
server_prompts = :
server_set_id = $2

auth_login:
    driver = plaintext
    public_name = LOGIN
    server_condition = ${lookup mysql{SELECT `user_idnr` FROM \
    `dbmail_users` WHERE `userid` = \
    '${quote_mysql:$1}' AND `passwd` = \
    '${quote_mysql:$2}'}{yes}{no}}
    
server_prompts = Username:: : Password::
server_set_id = $1

auth_cram_md5:
    driver = cram_md5
    public_name = CRAM-MD5
    server_secret = ${lookup mysql{SELECT `passwd` FROM \
    `dbmail_users` WHERE `userid` \
    = '${quote_mysql:$1}'}{$value}fail}
server_set_id = $1


# begin local_scan


# End of Exim configuration file

Аватара пользователя
hizel
дядя поня
Сообщения: 9031
Зарегистрирован: 2007-06-29 10:05:02
Откуда: Выборг

Re: exim и relay

Непрочитанное сообщение hizel » 2010-08-03 8:45:49

Код: Выделить всё

  require message = relay not permitted
          domains = +local_domains : +relay_to_domains
отправитель в +local_domains : +relay_to_domains?
В дурацкие игры он не играет. Он просто жуткий, чу-чу, паровозик, и зовут его Блейн. Блейн --- это Боль.

Аватара пользователя
Cheshirski
рядовой
Сообщения: 18
Зарегистрирован: 2009-09-02 10:13:41
Откуда: Ленинск-Кузнецкий
Контактная информация:

Re: exim и relay

Непрочитанное сообщение Cheshirski » 2010-08-03 9:04:02

hizel писал(а):

Код: Выделить всё

  require message = relay not permitted
          domains = +local_domains : +relay_to_domains
отправитель в +local_domains : +relay_to_domains?
Запросы которые идут в бд по данным переменным, прописаны в них только домены и все как тип LOCAL, RELAY нету и нет там ипов, с которых можно отправлять сообщения, таблица domain содержит поля id, domain,type и все.

Аватара пользователя
hizel
дядя поня
Сообщения: 9031
Зарегистрирован: 2007-06-29 10:05:02
Откуда: Выборг

Re: exim и relay

Непрочитанное сообщение hizel » 2010-08-03 9:44:18

а причем тут ip, тут проверка по домену отправителя
В дурацкие игры он не играет. Он просто жуткий, чу-чу, паровозик, и зовут его Блейн. Блейн --- это Боль.