Configuration Postgrey
Bonjour,
J'utilise Postgrey pour filtrer les messages que je reçois sur mon
serveur Postfix mais j'ai bien l'impression qu'il est mal configuré,
je reçois des messages qui auraient dû être rejetés en permanence.
Voilà par exemple le log du filtrage d'un spam que j'ai reçu :
>> Nov 24 19:08:21 Deb postfix/smtpd[19341]: NOQUEUE: reject: RCPT
from mail11.downloadaccelerator.net[212.143.22.169]: 450
<dfdfdfdfd@ms23.hinet.net>: Sender address rejected: Greylisted for
300 seconds (see
http://isg.ee.ethz.ch/tools/postgrey/help/mondomaine.net.html);
from=<dfdfdfdfd@ms23.hinet.net> to=<admin@mondomaine.net> proto=ESMTP
helo=<lserv>
>> Nov 24 19:34:51 Deb postfix/smtpd[19403]: NOQUEUE: reject: RCPT
from unknown[212.143.22.169]: 450 <dfdfdfdfd@ms23.hinet.net>: Sender
address rejected: Greylisted for 300 seconds (see
http://isg.ee.ethz.ch/tools/postgrey/help/mondomaine.net.html);
from=<dfdfdfdfd@ms23.hinet.net> to=<admin@mondomaine.net> proto=ESMTP
helo=<lserv>
>> Nov 24 22:36:13 Deb postfix/smtpd[19827]: connect from
mail11.downloadaccelerator.net[212.143.22.169]
>> Nov 24 22:36:14 Deb postgrey[1042]: cleaning up old logs...
>> Nov 24 22:36:14 Deb postgrey[1042]: delayed 12476 seconds:
client=mail11.downloadaccelerator.net, from=dfdfdfdfd@ms23.hinet.net,
to=admin@mondomaine.net
>> Nov 24 22:36:15 Deb postfix/smtpd[19827]: F0989AE209:
client=mail11.downloadaccelerator.net[212.143.22.169]
>> Nov 24 22:36:15 Deb postfix/cleanup[19834]: F0989AE209:
message-id=<20051124213614.F0989AE209@mondomaine.net>
>> Nov 24 22:36:15 Deb postfix/qmgr[2969]: F0989AE209:
from=<dfdfdfdfd@ms23.hinet.net>, size=5220, nrcpt=1 (queue active)
>> Nov 24 22:36:16 Deb postfix/smtpd[19827]: disconnect from
mail11.downloadaccelerator.net[212.143.22.169]
>> Nov 24 22:37:42 Deb postfix/smtpd[19839]: connect from
localhost.localdomain[127.0.0.1]
>> Nov 24 22:37:46 Deb postfix/smtpd[19839]: 026E0AE20A:
client=localhost.localdomain[127.0.0.1]
>> Nov 24 22:37:46 Deb postfix/cleanup[19834]: 026E0AE20A:
message-id=<20051124213614.F0989AE209@mondomaine.net>
>> Nov 24 22:37:47 Deb postfix/smtpd[19839]: disconnect from
localhost.localdomain[127.0.0.1]
>> Nov 24 22:37:48 Deb postfix/qmgr[2969]: 026E0AE20A:
from=<dfdfdfdfd@ms23.hinet.net>, size=5825, nrcpt=1 (queue active)
>> Nov 24 22:37:50 Deb amavis[3630]: (03630-04) Passed,
<dfdfdfdfd@ms23.hinet.net> -> <admin@mondomaine.net>, Message-ID:
<20051124213614.F0989AE209@mondomaine.net>, Hits: -
>> Nov 24 22:37:51 Deb postfix/smtp[19836]: F0989AE209:
to=<admin@mondomaine.net>, relay=127.0.0.1[127.0.0.1], delay=96,
status=sent (250 2.6.0 Ok, id=03630-04, from MTA: 250 Ok: queued as
026E0AE20A)
>> Nov 24 22:37:51 Deb postfix/qmgr[2969]: F0989AE209: removed
>> Nov 24 22:37:53 Deb postfix/virtual[19845]: 026E0AE20A:
to=<admin@mondomaine.net>, relay=virtual, delay=8, status=sent
(delivered to maildir)
>> Nov 24 22:37:54 Deb postfix/qmgr[2969]: 026E0AE20A: removed
Et voilà le header de ce même message :
>> X-Kaspersky: Checked
>> Return-Path: <dfdfdfdfd@ms23.hinet.net>
>> X-Original-To: admin@mondomaine.net
>> Delivered-To: admin@mondomaine.net
>> Received: from localhost (localhost.localdomain [127.0.0.1])
>> by mondomaine.net (Postfix) with ESMTP id 026E0AE20A
>> for <admin@mondomaine.net>; Thu, 24 Nov 2005 22:37:45 +0100 (CET)
>> Received: from mondomaine.net ([127.0.0.1])
>> by localhost (Deb [127.0.0.1]) (amavisd-new, port 10024)
>> with ESMTP id 03630-04 for <admin@mondomaine.net>;
>> Thu, 24 Nov 2005 22:36:24 +0100 (CET)
>> X-Greylist: delayed 12476 seconds by postgrey-1.21 at Deb; Thu, 24
Nov 2005 22:36:14 CET
>> Received: from lserv (mail11.downloadaccelerator.net [212.143.22.169])
>> by mondomaine.net (Postfix) with ESMTP id F0989AE209
>> for <admin@mondomaine.net>; Thu, 24 Nov 2005 22:36:14 +0100 (CET)
>> Received: from okht.net (203.70.48.192) by lserv with SMTP; Thu, 24
Nov 2005 20:09:53 +0200
>> From: "»¯§´@" <"»¯§´@"@>
>> To: "admin" <admin@mondomaine.net>
>> Subject: ³o¬O¤@ÓµLªk¾a½ÕÁ~ÅýÁ~¤ôÅÜ«pªº¥@¬ö ( admin )
>> Date: Fri, 25 Nov 05 00:49:45 ¥x¥_¼Ð·Ç(r)ɶ¡
>> MIME-Version: 1.0
>> Content-Type: multipart/mixed;boundary=
"----=_NextPart_000_00E0_475540BC.E3F31B20"
>> X-Priority: 3
>> X-MSMail-Priority: Normal
>> X-Mailer: Microsoft Outlook Express 6.00.2462.0000
>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2462.0000
>> Message-Id: <20051124213614.F0989AE209@mondomaine.net>
>> X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at mondomaine.net
>> X-Amavis-Alert: BAD HEADER Non-encoded 8-bit data (char BB hex) in
message header 'From'
>> From: "\273\257\255\247\264@" <"\273\257\255\247\264@"@>\n ^
Comment se fait-il que Postgrey ou même Amavis (puisqu'il indique que
le header est mal encodé) n'ai pas bloqué ce message ?
Voilà le contenu de mon fichier de configuration Postfix main.cf :
smtpd_helo_required = yes
smtpd_sender_restrictions =
permit_mynetworks
reject_non_fqdn_sender
check_policy_service inet:127.0.0.1:60000
content_filter = smtp-amavis:[127.0.0.1]:10024
Merci d'avance !
Reply to: