Rejecting unknown recipients at connection level...

I have modified /etc/postfix/main.cf to reject unknown recipients combined with following additions:
/etc/postfix/virtual
[email protected] com_mydomain1_user1
[email protected] com_mydomain2_user1
[email protected] com_mydomain1_user2
[email protected] com_mydomain2_user2
/etc/postfix/virtual_domains
mydomain1.com allow
mydomain2.com allow
/etc/postfix/virtual_domains_dummy
dummy.local allow
and it works as long as the "user" part is unknown within my known domains and
I do get 550 reply for those unknown recipients.
However, if "domain" part is also unknown then I get 250 reply and
am not sure what is missing in my configuration.
Here is a copy of my main.cf:
queue_directory = /private/var/spool/postfix
command_directory = /usr/sbin
daemon_directory = /usr/libexec/postfix
mail_owner = _postfix
unknown_local_recipient_reject_code = 550
debug_peer_level = 2
debugger_command =
PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
xxgdb $daemon_directory/$process_name $process_id & sleep 5
sendmail_path = /usr/sbin/sendmail
newaliases_path = /usr/bin/newaliases
mailq_path = /usr/bin/mailq
setgid_group = _postdrop
html_directory = no
manpage_directory = /usr/share/man
sample_directory = /usr/share/doc/postfix/examples
readme_directory = /usr/share/doc/postfix
mydomain_fallback = localhost
message_size_limit = 52428800
myhostname = mail.mydomain.com
mailbox_transport = cyrus
mailbox_size_limit = 0
enable_server_options = yes
inet_interfaces = all
smtpd_client_restrictions = permit_mynetworks reject_rbl_client cbl.abuseat.org reject_rbl_client dul.dnsbl.sorbs.net permit
maps_rbl_domains =
mydomain = mydomain.com
virtual_transport = lmtp:unix:/var/imap/socket/lmtp
virtual_mailbox_domains = hash:/etc/postfix/virtual_domains_dummy
virtual_alias_domains = hash:/etc/postfix/virtual_domains
virtual_alias_maps = hash:/etc/postfix/virtual
content_filter = smtp-amavis:[127.0.0.1]:10024
owner_request_special = no
recipient_delimiter = +
alias_maps = hash:/etc/aliases
mydestination = $myhostname,localhost.$mydomain,localhost,mail.mydomain.com,mydomain.com
smtpd_use_tls = yes
smtpd_enforce_tls = no
smtpd_tls_cert_file = /etc/certificates/Default.crt
smtpd_tls_key_file = /etc/certificates/Default.key
local_recipient_maps = proxy:unix:passwd.byname $alias_maps
luser_relay =
smtpd_sasl_auth_enable = yes
smtpd_use_pw_server = yes
smtpd_recipient_restrictions = permit_sasl_authenticated,permit_mynetworks,reject_unauth_destination,permit
smtpd_pw_server_security_options = login
smtpd_reject_unlisted_recipient = yes
mynetworks = 127.0.0.0/8
I followed instruction from following link:
http://downloads.topicdesk.com/docs/Making_Virtual_Mail_Users_in_OS_X_Server.pdf
Appreciate any input to resolve this issue.
Thanks,
John

Here is some more details on what I mean by 250 and 550 replies.
$ telnet mail.mydomain.com 25
Trying 127.0.0.1...
Connected to mail.mydomain.com.
Escape character is '^]'.
220 mail.mydomain.com ESMTP Postfix
mail from: <[email protected]>
250 2.1.0 Ok
rcpt to: <[email protected]>
250 2.1.5 Ok
rcpt to: <[email protected]>
550 5.1.1 <[email protected]>: Recipient address rejected: User unknown in virtual alias table
rcpt to: <[email protected]>
250 2.1.5 Ok
Is the last 250 reply normal or should I get 550 reply if mail server is setup properly?
Is there something missing in my configuration that does not prevent an unknown user from an unknown domain from submitting?
Appreciate any comment.
John

Similar Messages

  • Rejecting unknown addresses at connection level...

    Our server currently bounces unknown addresses sent to it, but our mail appliance needs to see an immediate 550 error when an invalid RCPT TO is sent to our mail server.
    I am unsure as to how to do this with the PostFix config file. I suspect it has something to do with localrecipientmaps but I'm not sure. Can anyone help?

    Hello. Running a publicly-available mail server is a serious endeavo(u)r.
    Currently your mail-server is misconfigured:
    You _should not bounce those messages_ [!] You should be rejecting the messages instead, which
    Postfix as configured out of the box by Apple should do, and - as well, by default - it will use a 550 code when rejecting those messages.
    From the default, supplied /etc/postfix/main.cf :
    # REJECTING MAIL FOR UNKNOWN LOCAL USERS
    # The localrecipientmaps parameter specifies optional lookup tables
    # with all names or addresses of users that are local with respect
    # to $mydestination, $inet_interfaces or $proxy_interfaces.
    # If this parameter is defined, then the SMTP server will reject
    # mail for unknown local users. This parameter is defined by default.
    # The unknownlocal_recipient_rejectcode specifies the SMTP server
    # response code when a recipient domain matches $mydestination or
    # ${proxy,inet}_interfaces, while $localrecipientmaps is non-empty
    # and the recipient address or address local-part is not found.
    # The default setting is 550 (reject mail) but it is safer to start
    # with 450 (try again later) until you are certain that your
    # localrecipientmaps settings are OK.
    unknownlocal_recipient_rejectcode = 550

  • ISupplier portal - reject action at the shipment level (R11)

    Hello,
    Supplier can perform Accept, Change or Reject actions at the shipment level. The two first actions are quite straight forward to understand, but could you please advise what are the results of doing a reject? Ther is not much about it in the user guide.
    To be more precise, are there any other situations that this information is used, beside that it can be found in the iSupplier Portal? The problem is that we have a very little visibility on the line status while using the standard Purchase Orders Summary forms. And after all lines have been assigned a status by our supplier, the Acceptance Required flag is removed from the PO no matter if there are any rejects on lines or not.
    Could you also please advise which database table holds this particular iSupplier portal shipment status information?
    Thank you all in advance.
    Kamil

    Hi,
    Form the front end you can ask the user to provide a screen shot of the preferences once the buyer has logged in and it is at the bottom Notifications (Email Style), this is usually set as disabled.
    I am not sure what is the exact table, please refer to the previous post with the table name.
    Thank you,
    Ravi

  • Wi-Fi connection levels are too low

    Hi, I acquired a used notebook Pavilion g series with Atheros ar9485 Wi-Fi device but its connection levels are too low compared to my older notebooks. I updated its driver to 10.0.0.313 but to no avail.

    Hi there
    Welcome to the HP Support Forums! It is a great place to find the help you need, both from other users, HP experts and other support personnel. I understand that you are having connection issues with your wireless adapter. I am happy to assist with this.Please post the full product number for your notebook. See the following, if you need help with that information. How Do I Find My Model Number or Product Number?Are you trying to use this notebook from the same location from where you were connecting with the other device?Does the signal strength vary significantly in that area?Have you tried connecting from different  locations of to a different wireless network? Please let me know.  

  • Turn off zero-copy IO on connection level

    Hi
    Is there any possibility to turn off zero-copy IO protocol on connection level as it is with JDBC?
    JDBC Doc.: http://docs.oracle.com/cd/E11882_01/java.112/e16548/oralob.htm#CHDFEBJD
    Rationale:
    We are getting "ORA-12582: TNS:invalid operation" intermittently while reading CLOBs stored as SECUREFILEs -> Known issue: 1193913.1 - Ora-12582 using Securefile Lob
    The MOS Note suggests to set "_use_zero_copy_io=FALSE " on instance level. We would much rather prefer to disable the protocol just on the .NET client without affecting the entire environment.
    Thanks,
    Beat
    Database: Oracle 11.2.0.3
    OS: Windows 2008 R2 Server
    Client: ODP.NET 11.2.0.3

    now I have this and it still doesn't work.
    Section "ServerLayout"
    Identifier "Simple Layout"
    Screen "Screen 1" 0 0
    InputDevice "Mouse1" "CorePointer"
    InputDevice "Touchpad" "SendCoreEvents"
    InputDevice "Keyboard1" "CoreKeyboard"
    Option "OffTime" "1"
    EndSection
    Section "ServerFlags"
    Option "AutoAddDevices" "False"
    Option "DontZap" "false"
    EndSection

  • -3256 Error - Unknown error, cannot connect to remote speaker

    I recently bought time capsule and have set that up as a base station. The input to time capsule is the linksys modem + router. I have disabled the linksys router capabilities and am only using that as a modem. When i connect airport express to the time capsule network, i get a error message stating -3256. Unknown error cannot connect to the remote speaker. Before time capsule, linksys network was able to play airtunes, but time capsule is not able to. I have disabled the firewall on both time capsule and linksys.

    It might actually be the firewall on your mac rather than the other hardware. I mysteriously started getting this same error when trying to use the Multiple Speakers function with AirTunes (had worked perfectly for over a year). I modified the Security/Firewall settings in System Preferences and it started working again, no error: I simply added iTunes to the "specific services" firewall list to allow incoming connections. Of course the firewall is set up quite differently in 10.4.x.
    You'd think that checking "look for remote speakers" in iTunes preferences would take care of this for you, or prompt you to make the changes yourself (I remember getting OS messages that used to say "if you want to do such-and-such, make sure you open port xxxx") but apparently not!
    I also read somewhere that checking "share my library" in iTunes prefs can help with this sometimes, but I can't verify that - I already had it checked; it was the OS firewall tweak that worked for me.

  • Webex Connect "An unknown error ocurred connecting the server" Error Message

    Hi,
    We have the latest Cisco Webex Connect Clients (7.1.1 Build 16597) in use in our company. With no obvious reason one of our employees now can't connect to Webex Connect getting the Error Message "An unknown error ocurred while connecting to the server." We tried to close and re open the client and to re-enter the password, both with no succes. Using another Jabber/XMPP capable IM Client works but not using Cisco Webex Connect.
    Can anyone help?
    Cheers,
    Patrick

    You may face this issue if your IE is working in offline mode.
    To resolve:
    Try going to google.com on internet explorer.
    Click on connect when prompted.
    Once google.com opens fine then try logging in to the WebEx Connect again.
    It should work now.

  • Voice Mail Ports Rejected in CUCM - Unity Connection

    Hi to all,
    I have a CUCM v9.1 cluster (1 Pub and 2 Subs) with two device pools (DP_Site_A and DP_Site_B), each DP has a call manager group that has the Subscriber for each site as the Primary CUCM Server in order of registration: DP_Site_A -> CMGroup_A ( 1° Sub_A and 2° Sub_B) ,
    DP_Site_B -> CMGroup_B ( 1° Sub_B and 2° Sub_A).
    The issue that I have is that when I configure the voice ports in the CUCM with either DP_Site_A or DP_Site_B I always get those ports as "Rejected" in the registration status BUT if i leave the DP for the voice ports as default they get registered and actually work fine with voice mails.
    My Unity Connection is v9.1 too.
    Any ideas about what can be causing this behavior??
    Thanks in advance for your help.

    Hi Alfonso,
    Can you check these settings in CUC for the "Secondary" CUCM (Sub) server config
    to make sure the Subs are listed as part of the SCCP registration;
    Step 32 On the Edit Servers page, do the following substeps if the Cisco Unified CM cluster has secondary servers. Otherwise, skip to Step 33.
    a. Under Cisco Unified Communications Manager Servers, click Add.
    b. Enter the following settings for the secondary Cisco Unified CM server and click Save.
    # Table 6-16     Settings for the Cisco Unified Communications Manager Servers 
    # Field
    # Setting
    # Order
    # Enter the order of priority for the Cisco Unified CM server. The  lowest  number is the primary Cisco Unified CM server, the higher  numbers are  the secondary servers.
    # IP Address or Host Name
    # Enter the IP address (or host name) of the secondary Cisco Unified CM server.
    # Port
    # Enter the TCP port of the Cisco Unified CM server that you are   integrating with Cisco Unity Connection. We recommend that you use the   default setting.
    # TLS Port
    # Enter the TLS port of the Cisco Unified CM server that you are   integrating with Cisco Unity Connection. We recommend that you use the   default setting.
    # Server Type
    # Click Cisco Unified Communications Manager.
    http://www1.cisco.com/en/US/docs/voice_ip_comm/connection/7x/integration/cucm_sccp/guide/cucintcucmskinny050.html
    Cheers!
    Rob
    "Talk about a dream
    Try to make it real" 
    - Springsteen

  • Unknown error when connecting ipod to computer.  Always worked before.  Any ideas?

    I'm getting and "unknown error" when I connect my Ipod to my computer.  I have always used this computer and it has always worked.  Any ideas?

    Try here:
    iPhone, iPad, iPod touch: Unknown error containing '0xE' when connecting

  • Unknown PC server "connected" to the network

    I have a weird problem. I've got one iMac and one MB Pro connected to my wireless network. On the iMac I've just today started getting a PC server showing up under "shared" in the sidebar in Finder. When i try to connect, it says that the connection fails. However, on another device I've got connected to the TV that can play movies and sounds over the network, the same device appears in the "workgroup" when I log in there. When I turn off the iMac, however, that device disappears as well. Somehow, it seems my iMac is running some kind of virtual PC server that I can't connect to..?
    I'm getting really frustrated about this, because it seems to me to be a virus, but it's not possible to trace it. I'd appreciate any insights into this that the community can provide.

    Hello guys,
    More than likely you have nothing to worry about!
    There are all kinds of devices that could be showing up on the sidebar of your Finder... Your DVR or cell phone might even show up there if they are connected to your network (wired or wireless).
    There are several ways to go about finding out what the secret unknown device is...
    1. Check your network for attached devices
    Physically look at what is connected to your network by seeing what is plugged into your router or modem.
    2. Check your router for DHCP clients
    Your router will have some sort of configuration page that you can check from your computer. This will tell you what is attached and communicating with your network wired or wirelessly.
    The DHCP client list shows what devices are getting IP addresses automatically (if assigned manually, they will likely not show up here). The instructions for this are different (but not too different) from router to router. Common brands for routers include Netgear, Linksys, and Apple.
    On an Apple Airport wired and wireless DHCP "clients" are listed separately to find the wired ones go to Advanced > Logging & SNMP > Logs and Statistics > DHCP Clients and to find the wireless ones, look under AirPort > Summary > Wireless Clients. For another brand, you'll have to Google it.
    3. Run a Serious Network Scan with Nmap/Zenmap
    This is almost overkill for trying to find out what is on the sidebar of your Finder - but, nmap is an the best utility for network scanning. It can be downloaded from:
    http://nmap.org/download.html#macosx
    It comes with a graphical interface called Zenmap and a command line tool. Personally, I prefer the command line version but they both work the same. Zenmap does require X11.
    Either way, you can scan your network if you know the IP address of your own computer while it is connected.
    If you need to find your IP address - you can find this by EITHER opening a terminal and typing ifconfig OR by going to System Preferences > Network then choosing your Airport or Ethernet (whichever is connected) and looking for your IP address. It should be in the format ###.###.###.### - common IP subnets include 192.168.1.###, 192.168.0.###, and 10.0.1.### - when you've found your IP address, you can now do an nmap/Zenmap scan for all IPs within your subnet. Not only will this tell you what network devices are attached, but also it will try to detect what type of device and what operating system is being used.
    To find ALL the devices attached to your network, you will have to search the entire range of your subnet - the subnet is the first three groupings of your IP address. For my computer's IP 192.168.1.5 this would be 192.168.1 and since the minimum address for an IP is 1 and the max is 255, I will be searching in the range 192.168.1.1-255 (if my IP was 10.0.1.101 or 10.0.1.5 then I would search 10.0.1.1-255).
    If I'm using Zenmap I will make my target 192.168.1.1-255 and I will choose Quick scan from the profile - just to get an idea of what IPs are in use. 10 seconds later - Presto! A list of all the devices attached to my network.
    Feel free to upload the list here and let me take a look if you have any trouble reading it yourself.
    You can also do a scan by entering the following into the Command field of Zenmap or by running this in the Terminal (please adjust your subnet accordingly):
    nmap -O -sA 192.168.1.1-255
    This will attempt to get more information out of the attached devices, such as, what operating system they may be running.
    Start with that and post back here to let me know what you find.

  • REASON OF REJECTION AT SALES ORDER ITEM LEVEL

    In sales order item level after putting reason of rejection wether net value of sales order changed to ZERO Value?
    In Sales infromation system for that particular customer & material sales  order value reflects in report?
    Kindly send your comments on it.
    regards,
    N.M.PAWAR

    Hi
    Suppose a sales order has 2 line items say material 1  and qty is five units and each is Rs 100 and material 2  and qty is Three unitsand each is Rs 100
    Then the nett value of the sales order is Rs 800
    If you reject material 2 and qty is Three units then after that  whether order value changes to Rs 500 or remains at Rs 800 depends on your SPRO settings
    In t code OVAG against your reason of rejection if you maintain blank in the statistical column system keeps the price as Rs 800 even after rejecting it the sales order but while billing it will be billed for Rs 500 only
    If you maintain X/Y in the statistical column system changes the price as Rs 500  after assigning the reason of rejection and then enter
    The difference between X and Y is
    tomorrow if the top management wants a report that how much value loss has come thro reason of rejection such report is not available with X (if you maintain X) and with Y you can take such reports because X doesnt updates the information structures but Y does update information structures
    Regards
    Raja

  • Keep getting unknown error when connecting iPod?

    Each time I try connecting my iPod in I get an error message in iTunes. It does the same thing when I connect my iPhone in too.
    The iTunes version is the one before 9.2 came out.
    I get an error saying "iTunes could not connect to this iPod because an unknown error occurred (0xE8000001)."
    Please help I'm not sure what's wrong and can't find anything on this issue! D:

    well last I tried it did but I'm not using it now because it's at geek squad for repair so that's why I'm using the mac. I've always had this problem with this mac but never addressed it since I used my pc in the past. I think the problem may be is the mac needs updating. It's a G3 but I'm planning on taking it in and having it updated to the newest os/processor, all that good stuff.
    But I just switched usb cables and that seemed to work for the time being. Thankfully

  • How to hide Approve and reject radio buttons at item level.

    Hi All,
    On the HOME screen of EBP click Approval link ---> Under Appoval tab under Action Column click the magnifying glass icon ---> a table is displayed with Approve and Reject as two columns which contain radio buttons at item level .
    How can we hide these two columns and the radio buttons?
    Thanks & Regards,
    Anubhav

    Hi Daniel,
    As you said the template bbp sc ui its 120 is to be modified, i also located the code to be changed but when i comment the code for displaying the RBs , i get "Syntax Error in Tempate" dump in IE.
    <!--  manager view  -->
                          `if (gt_scr_itmovr_i-DEDUCT_IND[j].disabled)`
                              `if (gt_scr_itmovr_i-DEDUCT_IND[j] != "X")`
                                  `TD(align="center",valign="middle", class=tdcellclass)`
                                     <img src="`mimeURL(~service="bbpglobal",~language="", ~name="images/icon/checkedradio.gif")`"  border="0">
                                  `TD(align="center",valign="middle", class=tdcellclass)`
                                     <img src="`mimeURL(~service="bbpglobal",~language="", ~name="images/icon/uncheckedradio.gif")`" border="0">
                              `else`                
                                  `TD(align="center",valign="middle", class=tdcellclass)`
                                     <img src="`mimeURL(~service="bbpglobal",~language="", ~name="images/icon/uncheckedradio.gif")`" border="0">
                                  `TD(align="center",valign="middle", class=tdcellclass)`
                                     <img src="`mimeURL(~service="bbpglobal",~language="", ~name="images/icon/checkedradio.gif")`" border="0">
                              `end`
                          `else`
                              `TD(align="center",valign="middle", class=tdcellclass)`
                                 <input type="RADIO" name="gt_scr_itmovr_i-DEDUCT_IND[`j`]" value=""  `if (gt_scr_itmovr_i-DEDUCT_IND[j] != "X")` CHECKED `end;
                                 if ( group_hierarchy_position > -1 ); <!-- are we in a hierarchy group ? -->
                                   if ( group_hierarchy_position != j ); <!-- are we processing a subitem? -->
                                       `on click="jav asc ript:toggleSu bItemApprovalState(`j`)";`
                                     group_last_subitem_position = j;
                                   else; <!-- we are on the top of the group (the hierarchy position) -->
                                     if (GT_SCR_ITMOVR_I-HIER_EXPANDED[j] == "X");
                                       `on click="java scr ipt:setAppro valStateAllSubItems(true, `j`)";`
                                     end;
                                     group_last_subitem_position = j;
                                   end;
                                 end`>
                              `TD(align="center",valign="middle", class=tdcellclass)`
                                 <input type="RADIO" NAME="gt_scr_itmovr_i-DEDUCT_IND[`j`]"  value="X"  `if (gt_scr_itmovr_i-DEDUCT_IND[j] == "X")` CHECKED `end;
                                 if ( group_hierarchy_position > -1 ); <!-- are we in a hierarchy group ? -->
                                   if ( group_hierarchy_position != j ); <!-- are we processing a subitem? -->
                                     `on click="javas cript:tog gleSubItemApprovalState(`j`)";`
                                     group_last_subitem_position = j;
                                   else; <!-- we are on the top of the group (the hierarchy position) -->
                                     if (GT_SCR_ITMOVR_I-HIER_EXPANDED[j] == "X");
                                       `on cli ck="javas cript:setApprovalStateAllSubItems(false, `j`)";`
                                     end;
                                     group_last_subitem_position = j;
                                   end;
                                 end`>
                          `end;
                       end;
                   end`
    I guess the above mentioned code has to be modified but how?
    Thanks a lot,
    Anubhav

  • Not rejecting unknown users on Submit channel

    I am running Java Communications Suite 6.3(2) on a single system. Currently, when one of my customers sends an email (from a thick client) through the Submit port, and one of the addresses is to an invalid address in a domain on this server, the customer receives a pop-up error on their workstation and no email is sent. If there is an invalid address to a different server domain, the message is accepted and the customer receives a return email with the error message. Customers find it confusing to deal with two different types of error processing.
    I would like to have mail sent through the submit channel (and ONLY the submit channel) handled such that the customer does not get a rejection during the SMTP dialogue, but has the email delivered to all valid recipients and receives a separate, email message with errors about the undeliverable addresses. I have a couple of questions about this configuration:
    1) Is it even possible? My fantasy is that it is just a keyword option. But it seems more likely that, if it can be done, it would have to be by routing through different channels (possibly locally written channels).
    2) Is this even a good idea? Might there be some horrible repercussions that I'm not seeing?
    Thanks

    dpalix2 wrote:
    1) Is it even possible? My fantasy is that it is just a keyword option. But it seems more likely that, if it can be done, it would have to be by routing through different channels (possibly locally written channels).You can achieve this by adding the "acceptalladdresses" keyword to the tcp_submit channel definition in imta.cnf.
    http://msg.wikidoc.info/index.php/Acceptalladdresses%2C_acceptvalidaddresses_Channel_Options
    2) Is this even a good idea? Might there be some horrible repercussions that I'm not seeing?If you only add this keyword to the tcp_submit channel it should be fine. Make sure you also add "LOG_USERNAME=1" to your option.dat file so you can track down which authenticated user is sending email -- should you need to track down emails to a given authenticated sender.
    Regards,
    Shane.

  • Can I reject other devices from connecting to my U330p?

    Hi,
    I've installed McAfee anti-virus software in my 1-mth old U330p. However, I'm getting annoyed by the frequent McAfee pop-up messages informing me that a few devices have been connected to my laptop. My issue is, I don't recognise those devices. Is there a way to reject other devices from auto-connecting to my laptop? 
    Please help. Many thanks!

    Hi MsNewbieU330p,
    Welcome to Lenovo Community Forums!
    Are you getting the Pop up telling you ip address that are trying to access?
    These possible being done by a Torrent or any file sharing Application
    As these apps will require you to share anything you have downloaded.
    These apps work on a peer to peer sharing.
    Or if Not
    Can you share the Screenshot of the pop ups?
    Thanks
    Solid Cruver
    Did someone help you today? Press the star on the left to thank them with a Kudo!
    If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"! This will help the rest of the Community with similar issues identify the verified solution and benefit from it.
    Follow @LenovoForums on Twitter!

Maybe you are looking for