You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

840 lines
33 KiB

  1. # DO NOT EDIT THIS FILE. EDIT THE MAIN.CF FILE INSTEAD. THE
  2. # TEXT HERE JUST SHOWS DEFAULT SETTINGS BUILT INTO POSTFIX.
  3. #
  4. 2bounce_notice_recipient = postmaster
  5. access_map_defer_code = 450
  6. access_map_reject_code = 554
  7. address_verify_cache_cleanup_interval = 12h
  8. address_verify_default_transport = $default_transport
  9. address_verify_local_transport = $local_transport
  10. address_verify_map = btree:$data_directory/verify_cache
  11. address_verify_negative_cache = yes
  12. address_verify_negative_expire_time = 3d
  13. address_verify_negative_refresh_time = 3h
  14. address_verify_poll_count = ${stress?{1}:{3}}
  15. address_verify_poll_delay = 3s
  16. address_verify_positive_expire_time = 31d
  17. address_verify_positive_refresh_time = 7d
  18. address_verify_relay_transport = $relay_transport
  19. address_verify_relayhost = $relayhost
  20. address_verify_sender = $double_bounce_sender
  21. address_verify_sender_dependent_default_transport_maps = $sender_dependent_default_transport_maps
  22. address_verify_sender_dependent_relayhost_maps = $sender_dependent_relayhost_maps
  23. address_verify_sender_ttl = 0s
  24. address_verify_service_name = verify
  25. address_verify_transport_maps = $transport_maps
  26. address_verify_virtual_transport = $virtual_transport
  27. allow_mail_to_commands = alias, forward
  28. allow_mail_to_files = alias, forward
  29. allow_min_user = no
  30. allow_percent_hack = yes
  31. allow_untrusted_routing = no
  32. alternate_config_directories =
  33. always_add_missing_headers = no
  34. always_bcc =
  35. anvil_rate_time_unit = 60s
  36. anvil_status_update_time = 600s
  37. append_at_myorigin = yes
  38. append_dot_mydomain = ${{$compatibility_level} < {1} ? {yes} : {no}}
  39. application_event_drain_time = 100s
  40. authorized_flush_users = static:anyone
  41. authorized_mailq_users = static:anyone
  42. authorized_submit_users = static:anyone
  43. backwards_bounce_logfile_compatibility = yes
  44. berkeley_db_create_buffer_size = 16777216
  45. berkeley_db_read_buffer_size = 131072
  46. best_mx_transport =
  47. biff = yes
  48. body_checks =
  49. body_checks_size_limit = 51200
  50. bounce_notice_recipient = postmaster
  51. bounce_queue_lifetime = 5d
  52. bounce_service_name = bounce
  53. bounce_size_limit = 50000
  54. bounce_template_file =
  55. broken_sasl_auth_clients = no
  56. canonical_classes = envelope_sender, envelope_recipient, header_sender, header_recipient
  57. canonical_maps =
  58. cleanup_service_name = cleanup
  59. command_execution_directory =
  60. command_expansion_filter = 1234567890!@%-_=+:,./abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
  61. command_time_limit = 1000s
  62. compatibility_level = 0
  63. confirm_delay_cleared = no
  64. connection_cache_protocol_timeout = 5s
  65. connection_cache_service_name = scache
  66. connection_cache_status_update_time = 600s
  67. connection_cache_ttl_limit = 2s
  68. content_filter =
  69. cyrus_sasl_config_path =
  70. daemon_table_open_error_is_fatal = no
  71. daemon_timeout = 18000s
  72. debug_peer_level = 2
  73. debug_peer_list =
  74. debugger_command =
  75. default_delivery_slot_cost = 5
  76. default_delivery_slot_discount = 50
  77. default_delivery_slot_loan = 3
  78. default_delivery_status_filter =
  79. default_destination_concurrency_failed_cohort_limit = 1
  80. default_destination_concurrency_limit = 20
  81. default_destination_concurrency_negative_feedback = 1
  82. default_destination_concurrency_positive_feedback = 1
  83. default_destination_rate_delay = 0s
  84. default_destination_recipient_limit = 50
  85. default_extra_recipient_limit = 1000
  86. default_filter_nexthop =
  87. default_minimum_delivery_slots = 3
  88. default_privs = nobody
  89. default_process_limit = 100
  90. default_rbl_reply = $rbl_code Service unavailable; $rbl_class [$rbl_what] blocked using $rbl_domain${rbl_reason?; $rbl_reason}
  91. default_recipient_limit = 20000
  92. default_recipient_refill_delay = 5s
  93. default_recipient_refill_limit = 100
  94. default_transport = smtp
  95. default_verp_delimiters = +=
  96. defer_code = 450
  97. defer_service_name = defer
  98. defer_transports =
  99. delay_logging_resolution_limit = 2
  100. delay_notice_recipient = postmaster
  101. delay_warning_time = 0h
  102. deliver_lock_attempts = 20
  103. deliver_lock_delay = 1s
  104. destination_concurrency_feedback_debug = no
  105. detect_8bit_encoding_header = yes
  106. disable_dns_lookups = no
  107. disable_mime_input_processing = no
  108. disable_mime_output_conversion = no
  109. disable_verp_bounces = no
  110. disable_vrfy_command = no
  111. dnsblog_reply_delay = 0s
  112. dnsblog_service_name = dnsblog
  113. dont_remove = 0
  114. double_bounce_sender = double-bounce
  115. duplicate_filter_limit = 1000
  116. empty_address_default_transport_maps_lookup_key = <>
  117. empty_address_recipient = MAILER-DAEMON
  118. empty_address_relayhost_maps_lookup_key = <>
  119. enable_long_queue_ids = no
  120. enable_original_recipient = yes
  121. error_delivery_slot_cost = $default_delivery_slot_cost
  122. error_delivery_slot_discount = $default_delivery_slot_discount
  123. error_delivery_slot_loan = $default_delivery_slot_loan
  124. error_destination_concurrency_failed_cohort_limit = $default_destination_concurrency_failed_cohort_limit
  125. error_destination_concurrency_limit = $default_destination_concurrency_limit
  126. error_destination_concurrency_negative_feedback = $default_destination_concurrency_negative_feedback
  127. error_destination_concurrency_positive_feedback = $default_destination_concurrency_positive_feedback
  128. error_destination_rate_delay = $default_destination_rate_delay
  129. error_destination_recipient_limit = $default_destination_recipient_limit
  130. error_extra_recipient_limit = $default_extra_recipient_limit
  131. error_initial_destination_concurrency = $initial_destination_concurrency
  132. error_minimum_delivery_slots = $default_minimum_delivery_slots
  133. error_notice_recipient = postmaster
  134. error_recipient_limit = $default_recipient_limit
  135. error_recipient_refill_delay = $default_recipient_refill_delay
  136. error_recipient_refill_limit = $default_recipient_refill_limit
  137. error_service_name = error
  138. execution_directory_expansion_filter = 1234567890!@%-_=+:,./abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
  139. expand_owner_alias = no
  140. export_environment = TZ MAIL_CONFIG LANG
  141. fallback_transport =
  142. fallback_transport_maps =
  143. fast_flush_domains = $relay_domains
  144. fast_flush_purge_time = 7d
  145. fast_flush_refresh_time = 12h
  146. fault_injection_code = 0
  147. flush_service_name = flush
  148. fork_attempts = 5
  149. fork_delay = 1s
  150. forward_expansion_filter = 1234567890!@%-_=+:,./abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
  151. forward_path = $home/.forward${recipient_delimiter}${extension}, $home/.forward
  152. frozen_delivered_to = yes
  153. hash_queue_depth = 1
  154. hash_queue_names = deferred, defer
  155. header_address_token_limit = 10240
  156. header_checks =
  157. header_size_limit = 102400
  158. helpful_warnings = yes
  159. home_mailbox =
  160. hopcount_limit = 50
  161. ignore_mx_lookup_error = no
  162. import_environment = MAIL_CONFIG MAIL_DEBUG MAIL_LOGTAG TZ XAUTHORITY DISPLAY LANG=C
  163. in_flow_delay = 1s
  164. inet_interfaces = all
  165. inet_protocols = all
  166. initial_destination_concurrency = 5
  167. internal_mail_filter_classes =
  168. invalid_hostname_reject_code = 501
  169. ipc_idle = 5s
  170. ipc_timeout = 3600s
  171. ipc_ttl = 1000s
  172. line_length_limit = 2048
  173. lmdb_map_size = 16777216
  174. lmtp_address_preference = any
  175. lmtp_address_verify_target = rcpt
  176. lmtp_assume_final = no
  177. lmtp_bind_address =
  178. lmtp_bind_address6 =
  179. lmtp_body_checks =
  180. lmtp_cname_overrides_servername = no
  181. lmtp_connect_timeout = 0s
  182. lmtp_connection_cache_destinations =
  183. lmtp_connection_cache_on_demand = yes
  184. lmtp_connection_cache_time_limit = 2s
  185. lmtp_connection_reuse_count_limit = 0
  186. lmtp_connection_reuse_time_limit = 300s
  187. lmtp_data_done_timeout = 600s
  188. lmtp_data_init_timeout = 120s
  189. lmtp_data_xfer_timeout = 180s
  190. lmtp_defer_if_no_mx_address_found = no
  191. lmtp_delivery_slot_cost = $default_delivery_slot_cost
  192. lmtp_delivery_slot_discount = $default_delivery_slot_discount
  193. lmtp_delivery_slot_loan = $default_delivery_slot_loan
  194. lmtp_delivery_status_filter = $default_delivery_status_filter
  195. lmtp_destination_concurrency_failed_cohort_limit = $default_destination_concurrency_failed_cohort_limit
  196. lmtp_destination_concurrency_limit = $default_destination_concurrency_limit
  197. lmtp_destination_concurrency_negative_feedback = $default_destination_concurrency_negative_feedback
  198. lmtp_destination_concurrency_positive_feedback = $default_destination_concurrency_positive_feedback
  199. lmtp_destination_rate_delay = $default_destination_rate_delay
  200. lmtp_destination_recipient_limit = $default_destination_recipient_limit
  201. lmtp_discard_lhlo_keyword_address_maps =
  202. lmtp_discard_lhlo_keywords =
  203. lmtp_dns_reply_filter =
  204. lmtp_dns_resolver_options =
  205. lmtp_dns_support_level =
  206. lmtp_enforce_tls = no
  207. lmtp_extra_recipient_limit = $default_extra_recipient_limit
  208. lmtp_generic_maps =
  209. lmtp_header_checks =
  210. lmtp_host_lookup = dns
  211. lmtp_initial_destination_concurrency = $initial_destination_concurrency
  212. lmtp_lhlo_name = $myhostname
  213. lmtp_lhlo_timeout = 300s
  214. lmtp_line_length_limit = 998
  215. lmtp_mail_timeout = 300s
  216. lmtp_mime_header_checks =
  217. lmtp_minimum_delivery_slots = $default_minimum_delivery_slots
  218. lmtp_mx_address_limit = 5
  219. lmtp_mx_session_limit = 2
  220. lmtp_nested_header_checks =
  221. lmtp_per_record_deadline = no
  222. lmtp_pix_workaround_delay_time = 10s
  223. lmtp_pix_workaround_maps =
  224. lmtp_pix_workaround_threshold_time = 500s
  225. lmtp_pix_workarounds = disable_esmtp,delay_dotcrlf
  226. lmtp_quit_timeout = 300s
  227. lmtp_quote_rfc821_envelope = yes
  228. lmtp_randomize_addresses = yes
  229. lmtp_rcpt_timeout = 300s
  230. lmtp_recipient_limit = $default_recipient_limit
  231. lmtp_recipient_refill_delay = $default_recipient_refill_delay
  232. lmtp_recipient_refill_limit = $default_recipient_refill_limit
  233. lmtp_reply_filter =
  234. lmtp_rset_timeout = 20s
  235. lmtp_sasl_auth_cache_name =
  236. lmtp_sasl_auth_cache_time = 90d
  237. lmtp_sasl_auth_enable = no
  238. lmtp_sasl_auth_soft_bounce = yes
  239. lmtp_sasl_mechanism_filter =
  240. lmtp_sasl_password_maps =
  241. lmtp_sasl_path =
  242. lmtp_sasl_security_options = noplaintext, noanonymous
  243. lmtp_sasl_tls_security_options = $lmtp_sasl_security_options
  244. lmtp_sasl_tls_verified_security_options = $lmtp_sasl_tls_security_options
  245. lmtp_sasl_type = cyrus
  246. lmtp_send_dummy_mail_auth = no
  247. lmtp_send_xforward_command = no
  248. lmtp_sender_dependent_authentication = no
  249. lmtp_skip_5xx_greeting = yes
  250. lmtp_skip_quit_response = no
  251. lmtp_starttls_timeout = 300s
  252. lmtp_tcp_port = 24
  253. lmtp_tls_CAfile =
  254. lmtp_tls_CApath =
  255. lmtp_tls_block_early_mail_reply = no
  256. lmtp_tls_cert_file =
  257. lmtp_tls_ciphers = export
  258. lmtp_tls_dcert_file =
  259. lmtp_tls_dkey_file = $lmtp_tls_dcert_file
  260. lmtp_tls_eccert_file =
  261. lmtp_tls_eckey_file = $lmtp_tls_eccert_file
  262. lmtp_tls_enforce_peername = yes
  263. lmtp_tls_exclude_ciphers =
  264. lmtp_tls_fingerprint_cert_match =
  265. lmtp_tls_fingerprint_digest = md5
  266. lmtp_tls_force_insecure_host_tlsa_lookup = no
  267. lmtp_tls_key_file = $lmtp_tls_cert_file
  268. lmtp_tls_loglevel = 0
  269. lmtp_tls_mandatory_ciphers = medium
  270. lmtp_tls_mandatory_exclude_ciphers =
  271. lmtp_tls_mandatory_protocols = !SSLv2
  272. lmtp_tls_note_starttls_offer = no
  273. lmtp_tls_per_site =
  274. lmtp_tls_policy_maps =
  275. lmtp_tls_protocols = !SSLv2
  276. lmtp_tls_scert_verifydepth = 9
  277. lmtp_tls_secure_cert_match = nexthop
  278. lmtp_tls_security_level =
  279. lmtp_tls_session_cache_database =
  280. lmtp_tls_session_cache_timeout = 3600s
  281. lmtp_tls_trust_anchor_file =
  282. lmtp_tls_verify_cert_match = hostname
  283. lmtp_tls_wrappermode = no
  284. lmtp_use_tls = no
  285. lmtp_xforward_timeout = 300s
  286. local_command_shell =
  287. local_delivery_slot_cost = $default_delivery_slot_cost
  288. local_delivery_slot_discount = $default_delivery_slot_discount
  289. local_delivery_slot_loan = $default_delivery_slot_loan
  290. local_delivery_status_filter = $default_delivery_status_filter
  291. local_destination_concurrency_failed_cohort_limit = $default_destination_concurrency_failed_cohort_limit
  292. local_destination_concurrency_limit = 2
  293. local_destination_concurrency_negative_feedback = $default_destination_concurrency_negative_feedback
  294. local_destination_concurrency_positive_feedback = $default_destination_concurrency_positive_feedback
  295. local_destination_rate_delay = $default_destination_rate_delay
  296. local_destination_recipient_limit = 1
  297. local_extra_recipient_limit = $default_extra_recipient_limit
  298. local_header_rewrite_clients = permit_inet_interfaces
  299. local_initial_destination_concurrency = $initial_destination_concurrency
  300. local_minimum_delivery_slots = $default_minimum_delivery_slots
  301. local_recipient_limit = $default_recipient_limit
  302. local_recipient_maps = proxy:unix:passwd.byname $alias_maps
  303. local_recipient_refill_delay = $default_recipient_refill_delay
  304. local_recipient_refill_limit = $default_recipient_refill_limit
  305. local_transport = local:$myhostname
  306. luser_relay =
  307. mail_name = Postfix
  308. mail_owner = postfix
  309. mail_release_date = 20150208
  310. mail_version = 3.0.0
  311. mailbox_command =
  312. mailbox_command_maps =
  313. mailbox_delivery_lock = fcntl, dotlock
  314. mailbox_size_limit = 51200000
  315. mailbox_transport =
  316. mailbox_transport_maps =
  317. maps_rbl_domains =
  318. maps_rbl_reject_code = 554
  319. masquerade_classes = envelope_sender, header_sender, header_recipient
  320. masquerade_domains =
  321. masquerade_exceptions =
  322. master_service_disable =
  323. max_idle = 100s
  324. max_use = 100
  325. maximal_backoff_time = 4000s
  326. maximal_queue_lifetime = 5d
  327. message_drop_headers = bcc, content-length, resent-bcc, return-path
  328. message_reject_characters =
  329. message_size_limit = 10240000
  330. message_strip_characters =
  331. milter_command_timeout = 30s
  332. milter_connect_macros = j {daemon_name} v
  333. milter_connect_timeout = 30s
  334. milter_content_timeout = 300s
  335. milter_data_macros = i
  336. milter_default_action = tempfail
  337. milter_end_of_data_macros = i
  338. milter_end_of_header_macros = i
  339. milter_header_checks =
  340. milter_helo_macros = {tls_version} {cipher} {cipher_bits} {cert_subject} {cert_issuer}
  341. milter_macro_daemon_name = $myhostname
  342. milter_macro_v = $mail_name $mail_version
  343. milter_mail_macros = i {auth_type} {auth_authen} {auth_author} {mail_addr} {mail_host} {mail_mailer}
  344. milter_protocol = 6
  345. milter_rcpt_macros = i {rcpt_addr} {rcpt_host} {rcpt_mailer}
  346. milter_unknown_command_macros =
  347. mime_boundary_length_limit = 2048
  348. mime_header_checks = $header_checks
  349. mime_nesting_limit = 100
  350. minimal_backoff_time = 300s
  351. multi_instance_directories =
  352. multi_instance_enable = no
  353. multi_instance_group =
  354. multi_instance_name =
  355. multi_instance_wrapper =
  356. multi_recipient_bounce_reject_code = 550
  357. mydestination = $myhostname, localhost.$mydomain, localhost
  358. myorigin = $myhostname
  359. nested_header_checks = $header_checks
  360. non_fqdn_reject_code = 504
  361. non_smtpd_milters =
  362. notify_classes = resource, software
  363. owner_request_special = yes
  364. parent_domain_matches_subdomains = debug_peer_list,fast_flush_domains,mynetworks,permit_mx_backup_networks,qmqpd_authorized_clients,relay_domains,smtpd_access_maps
  365. permit_mx_backup_networks =
  366. pickup_service_name = pickup
  367. pipe_delivery_status_filter = $default_delivery_status_filter
  368. plaintext_reject_code = 450
  369. postmulti_control_commands = reload flush
  370. postmulti_start_commands = start
  371. postmulti_stop_commands = stop abort drain quick-stop
  372. postscreen_access_list = permit_mynetworks
  373. postscreen_bare_newline_action = ignore
  374. postscreen_bare_newline_enable = no
  375. postscreen_bare_newline_ttl = 30d
  376. postscreen_blacklist_action = ignore
  377. postscreen_cache_cleanup_interval = 12h
  378. postscreen_cache_map = btree:$data_directory/postscreen_cache
  379. postscreen_cache_retention_time = 7d
  380. postscreen_client_connection_count_limit = $smtpd_client_connection_count_limit
  381. postscreen_command_count_limit = 20
  382. postscreen_command_filter =
  383. postscreen_command_time_limit = ${stress?{10}:{300}}s
  384. postscreen_disable_vrfy_command = $disable_vrfy_command
  385. postscreen_discard_ehlo_keyword_address_maps = $smtpd_discard_ehlo_keyword_address_maps
  386. postscreen_discard_ehlo_keywords = $smtpd_discard_ehlo_keywords
  387. postscreen_dnsbl_action = ignore
  388. postscreen_dnsbl_reply_map =
  389. postscreen_dnsbl_sites =
  390. postscreen_dnsbl_threshold = 1
  391. postscreen_dnsbl_timeout = 10s
  392. postscreen_dnsbl_ttl = 1h
  393. postscreen_dnsbl_whitelist_threshold = 0
  394. postscreen_enforce_tls = $smtpd_enforce_tls
  395. postscreen_expansion_filter = $smtpd_expansion_filter
  396. postscreen_forbidden_commands = $smtpd_forbidden_commands
  397. postscreen_greet_action = ignore
  398. postscreen_greet_banner = $smtpd_banner
  399. postscreen_greet_ttl = 1d
  400. postscreen_greet_wait = ${stress?{2}:{6}}s
  401. postscreen_helo_required = $smtpd_helo_required
  402. postscreen_non_smtp_command_action = drop
  403. postscreen_non_smtp_command_enable = no
  404. postscreen_non_smtp_command_ttl = 30d
  405. postscreen_pipelining_action = enforce
  406. postscreen_pipelining_enable = no
  407. postscreen_pipelining_ttl = 30d
  408. postscreen_post_queue_limit = $default_process_limit
  409. postscreen_pre_queue_limit = $default_process_limit
  410. postscreen_reject_footer = $smtpd_reject_footer
  411. postscreen_tls_security_level = $smtpd_tls_security_level
  412. postscreen_upstream_proxy_protocol =
  413. postscreen_upstream_proxy_timeout = 5s
  414. postscreen_use_tls = $smtpd_use_tls
  415. postscreen_watchdog_timeout = 10s
  416. postscreen_whitelist_interfaces = static:all
  417. prepend_delivered_header = command, file, forward
  418. process_id = 25939
  419. process_id_directory = pid
  420. process_name = postconf
  421. propagate_unmatched_extensions = canonical, virtual
  422. proxy_interfaces =
  423. proxy_read_maps = $local_recipient_maps $mydestination $virtual_alias_maps $virtual_alias_domains $virtual_mailbox_maps $virtual_mailbox_domains $relay_recipient_maps $relay_domains $canonical_maps $sender_canonical_maps $recipient_canonical_maps $relocated_maps $transport_maps $mynetworks $smtpd_sender_login_maps $sender_bcc_maps $recipient_bcc_maps $smtp_generic_maps $lmtp_generic_maps $alias_maps $smtpd_client_restrictions $smtpd_helo_restrictions $smtpd_sender_restrictions $smtpd_relay_restrictions $smtpd_recipient_restrictions
  424. proxy_write_maps = $smtp_sasl_auth_cache_name $lmtp_sasl_auth_cache_name $address_verify_map $postscreen_cache_map
  425. proxymap_service_name = proxymap
  426. proxywrite_service_name = proxywrite
  427. qmgr_clog_warn_time = 300s
  428. qmgr_daemon_timeout = 1000s
  429. qmgr_fudge_factor = 100
  430. qmgr_ipc_timeout = 60s
  431. qmgr_message_active_limit = 20000
  432. qmgr_message_recipient_limit = 20000
  433. qmgr_message_recipient_minimum = 10
  434. qmqpd_authorized_clients =
  435. qmqpd_client_port_logging = no
  436. qmqpd_error_delay = 1s
  437. qmqpd_timeout = 300s
  438. queue_file_attribute_count_limit = 100
  439. queue_minfree = 0
  440. queue_run_delay = 300s
  441. queue_service_name = qmgr
  442. rbl_reply_maps =
  443. receive_override_options =
  444. recipient_bcc_maps =
  445. recipient_canonical_classes = envelope_recipient, header_recipient
  446. recipient_canonical_maps =
  447. recipient_delimiter =
  448. reject_code = 554
  449. reject_tempfail_action = defer_if_permit
  450. relay_clientcerts =
  451. relay_delivery_slot_cost = $default_delivery_slot_cost
  452. relay_delivery_slot_discount = $default_delivery_slot_discount
  453. relay_delivery_slot_loan = $default_delivery_slot_loan
  454. relay_destination_concurrency_failed_cohort_limit = $default_destination_concurrency_failed_cohort_limit
  455. relay_destination_concurrency_limit = $default_destination_concurrency_limit
  456. relay_destination_concurrency_negative_feedback = $default_destination_concurrency_negative_feedback
  457. relay_destination_concurrency_positive_feedback = $default_destination_concurrency_positive_feedback
  458. relay_destination_rate_delay = $default_destination_rate_delay
  459. relay_destination_recipient_limit = $default_destination_recipient_limit
  460. relay_domains = ${{$compatibility_level} < {2} ? {$mydestination} : {}}
  461. relay_domains_reject_code = 554
  462. relay_extra_recipient_limit = $default_extra_recipient_limit
  463. relay_initial_destination_concurrency = $initial_destination_concurrency
  464. relay_minimum_delivery_slots = $default_minimum_delivery_slots
  465. relay_recipient_limit = $default_recipient_limit
  466. relay_recipient_maps =
  467. relay_recipient_refill_delay = $default_recipient_refill_delay
  468. relay_recipient_refill_limit = $default_recipient_refill_limit
  469. relay_transport = relay
  470. relayhost =
  471. relocated_maps =
  472. remote_header_rewrite_domain =
  473. require_home_directory = no
  474. reset_owner_alias = no
  475. resolve_dequoted_address = yes
  476. resolve_null_domain = no
  477. resolve_numeric_domain = no
  478. retry_delivery_slot_cost = $default_delivery_slot_cost
  479. retry_delivery_slot_discount = $default_delivery_slot_discount
  480. retry_delivery_slot_loan = $default_delivery_slot_loan
  481. retry_destination_concurrency_failed_cohort_limit = $default_destination_concurrency_failed_cohort_limit
  482. retry_destination_concurrency_limit = $default_destination_concurrency_limit
  483. retry_destination_concurrency_negative_feedback = $default_destination_concurrency_negative_feedback
  484. retry_destination_concurrency_positive_feedback = $default_destination_concurrency_positive_feedback
  485. retry_destination_rate_delay = $default_destination_rate_delay
  486. retry_destination_recipient_limit = $default_destination_recipient_limit
  487. retry_extra_recipient_limit = $default_extra_recipient_limit
  488. retry_initial_destination_concurrency = $initial_destination_concurrency
  489. retry_minimum_delivery_slots = $default_minimum_delivery_slots
  490. retry_recipient_limit = $default_recipient_limit
  491. retry_recipient_refill_delay = $default_recipient_refill_delay
  492. retry_recipient_refill_limit = $default_recipient_refill_limit
  493. rewrite_service_name = rewrite
  494. send_cyrus_sasl_authzid = no
  495. sender_bcc_maps =
  496. sender_canonical_classes = envelope_sender, header_sender
  497. sender_canonical_maps =
  498. sender_dependent_default_transport_maps =
  499. sender_dependent_relayhost_maps =
  500. sendmail_fix_line_endings = always
  501. service_throttle_time = 60s
  502. setgid_group = postdrop
  503. show_user_unknown_table_name = yes
  504. showq_service_name = showq
  505. smtp_address_preference = any
  506. smtp_address_verify_target = rcpt
  507. smtp_always_send_ehlo = yes
  508. smtp_bind_address =
  509. smtp_bind_address6 =
  510. smtp_body_checks =
  511. smtp_cname_overrides_servername = no
  512. smtp_connect_timeout = 30s
  513. smtp_connection_cache_destinations =
  514. smtp_connection_cache_on_demand = yes
  515. smtp_connection_cache_time_limit = 2s
  516. smtp_connection_reuse_count_limit = 0
  517. smtp_connection_reuse_time_limit = 300s
  518. smtp_data_done_timeout = 600s
  519. smtp_data_init_timeout = 120s
  520. smtp_data_xfer_timeout = 180s
  521. smtp_defer_if_no_mx_address_found = no
  522. smtp_delivery_slot_cost = $default_delivery_slot_cost
  523. smtp_delivery_slot_discount = $default_delivery_slot_discount
  524. smtp_delivery_slot_loan = $default_delivery_slot_loan
  525. smtp_delivery_status_filter = $default_delivery_status_filter
  526. smtp_destination_concurrency_failed_cohort_limit = $default_destination_concurrency_failed_cohort_limit
  527. smtp_destination_concurrency_limit = $default_destination_concurrency_limit
  528. smtp_destination_concurrency_negative_feedback = $default_destination_concurrency_negative_feedback
  529. smtp_destination_concurrency_positive_feedback = $default_destination_concurrency_positive_feedback
  530. smtp_destination_rate_delay = $default_destination_rate_delay
  531. smtp_destination_recipient_limit = $default_destination_recipient_limit
  532. smtp_discard_ehlo_keyword_address_maps =
  533. smtp_discard_ehlo_keywords =
  534. smtp_dns_reply_filter =
  535. smtp_dns_resolver_options =
  536. smtp_dns_support_level =
  537. smtp_enforce_tls = no
  538. smtp_extra_recipient_limit = $default_extra_recipient_limit
  539. smtp_fallback_relay = $fallback_relay
  540. smtp_generic_maps =
  541. smtp_header_checks =
  542. smtp_helo_name = $myhostname
  543. smtp_helo_timeout = 300s
  544. smtp_host_lookup = dns
  545. smtp_initial_destination_concurrency = $initial_destination_concurrency
  546. smtp_line_length_limit = 998
  547. smtp_mail_timeout = 300s
  548. smtp_mime_header_checks =
  549. smtp_minimum_delivery_slots = $default_minimum_delivery_slots
  550. smtp_mx_address_limit = 5
  551. smtp_mx_session_limit = 2
  552. smtp_nested_header_checks =
  553. smtp_never_send_ehlo = no
  554. smtp_per_record_deadline = no
  555. smtp_pix_workaround_delay_time = 10s
  556. smtp_pix_workaround_maps =
  557. smtp_pix_workaround_threshold_time = 500s
  558. smtp_pix_workarounds = disable_esmtp,delay_dotcrlf
  559. smtp_quit_timeout = 300s
  560. smtp_quote_rfc821_envelope = yes
  561. smtp_randomize_addresses = yes
  562. smtp_rcpt_timeout = 300s
  563. smtp_recipient_limit = $default_recipient_limit
  564. smtp_recipient_refill_delay = $default_recipient_refill_delay
  565. smtp_recipient_refill_limit = $default_recipient_refill_limit
  566. smtp_reply_filter =
  567. smtp_rset_timeout = 20s
  568. smtp_sasl_auth_cache_name =
  569. smtp_sasl_auth_cache_time = 90d
  570. smtp_sasl_auth_enable = no
  571. smtp_sasl_auth_soft_bounce = yes
  572. smtp_sasl_mechanism_filter =
  573. smtp_sasl_password_maps =
  574. smtp_sasl_path =
  575. smtp_sasl_security_options = noplaintext, noanonymous
  576. smtp_sasl_tls_security_options = $smtp_sasl_security_options
  577. smtp_sasl_tls_verified_security_options = $smtp_sasl_tls_security_options
  578. smtp_sasl_type = cyrus
  579. smtp_send_dummy_mail_auth = no
  580. smtp_send_xforward_command = no
  581. smtp_sender_dependent_authentication = no
  582. smtp_skip_5xx_greeting = yes
  583. smtp_skip_quit_response = yes
  584. smtp_starttls_timeout = 300s
  585. smtp_tls_CAfile =
  586. smtp_tls_CApath =
  587. smtp_tls_block_early_mail_reply = no
  588. smtp_tls_cert_file =
  589. smtp_tls_ciphers = export
  590. smtp_tls_dcert_file =
  591. smtp_tls_dkey_file = $smtp_tls_dcert_file
  592. smtp_tls_eccert_file =
  593. smtp_tls_eckey_file = $smtp_tls_eccert_file
  594. smtp_tls_enforce_peername = yes
  595. smtp_tls_exclude_ciphers =
  596. smtp_tls_fingerprint_cert_match =
  597. smtp_tls_fingerprint_digest = md5
  598. smtp_tls_force_insecure_host_tlsa_lookup = no
  599. smtp_tls_key_file = $smtp_tls_cert_file
  600. smtp_tls_loglevel = 0
  601. smtp_tls_mandatory_ciphers = medium
  602. smtp_tls_mandatory_exclude_ciphers =
  603. smtp_tls_mandatory_protocols = !SSLv2
  604. smtp_tls_note_starttls_offer = no
  605. smtp_tls_per_site =
  606. smtp_tls_policy_maps =
  607. smtp_tls_protocols = !SSLv2
  608. smtp_tls_scert_verifydepth = 9
  609. smtp_tls_secure_cert_match = nexthop, dot-nexthop
  610. smtp_tls_security_level =
  611. smtp_tls_session_cache_database =
  612. smtp_tls_session_cache_timeout = 3600s
  613. smtp_tls_trust_anchor_file =
  614. smtp_tls_verify_cert_match = hostname
  615. smtp_tls_wrappermode = no
  616. smtp_use_tls = no
  617. smtp_xforward_timeout = 300s
  618. smtpd_authorized_verp_clients = $authorized_verp_clients
  619. smtpd_authorized_xclient_hosts =
  620. smtpd_authorized_xforward_hosts =
  621. smtpd_banner = $myhostname ESMTP $mail_name
  622. smtpd_client_connection_count_limit = 50
  623. smtpd_client_connection_rate_limit = 0
  624. smtpd_client_event_limit_exceptions = ${smtpd_client_connection_limit_exceptions:$mynetworks}
  625. smtpd_client_message_rate_limit = 0
  626. smtpd_client_new_tls_session_rate_limit = 0
  627. smtpd_client_port_logging = no
  628. smtpd_client_recipient_rate_limit = 0
  629. smtpd_client_restrictions =
  630. smtpd_command_filter =
  631. smtpd_data_restrictions =
  632. smtpd_delay_open_until_valid_rcpt = yes
  633. smtpd_delay_reject = yes
  634. smtpd_discard_ehlo_keyword_address_maps =
  635. smtpd_discard_ehlo_keywords =
  636. smtpd_dns_reply_filter =
  637. smtpd_end_of_data_restrictions =
  638. smtpd_enforce_tls = no
  639. smtpd_error_sleep_time = 1s
  640. smtpd_etrn_restrictions =
  641. smtpd_expansion_filter = \t\40!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~
  642. smtpd_forbidden_commands = CONNECT GET POST
  643. smtpd_hard_error_limit = ${stress?{1}:{20}}
  644. smtpd_helo_required = no
  645. smtpd_helo_restrictions =
  646. smtpd_history_flush_threshold = 100
  647. smtpd_junk_command_limit = ${stress?{1}:{100}}
  648. smtpd_log_access_permit_actions =
  649. smtpd_milters =
  650. smtpd_noop_commands =
  651. smtpd_null_access_lookup_key = <>
  652. smtpd_peername_lookup = yes
  653. smtpd_per_record_deadline = ${stress?{yes}:{no}}
  654. smtpd_policy_service_default_action = 451 4.3.5 Server configuration problem
  655. smtpd_policy_service_max_idle = 300s
  656. smtpd_policy_service_max_ttl = 1000s
  657. smtpd_policy_service_request_limit = 0
  658. smtpd_policy_service_retry_delay = 1s
  659. smtpd_policy_service_timeout = 100s
  660. smtpd_policy_service_try_limit = 2
  661. smtpd_proxy_ehlo = $myhostname
  662. smtpd_proxy_filter =
  663. smtpd_proxy_options =
  664. smtpd_proxy_timeout = 100s
  665. smtpd_recipient_limit = 1000
  666. smtpd_recipient_overshoot_limit = 1000
  667. smtpd_recipient_restrictions =
  668. smtpd_reject_footer =
  669. smtpd_reject_unlisted_recipient = yes
  670. smtpd_reject_unlisted_sender = no
  671. smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, defer_unauth_destination
  672. smtpd_restriction_classes =
  673. smtpd_sasl_auth_enable = no
  674. smtpd_sasl_authenticated_header = no
  675. smtpd_sasl_exceptions_networks =
  676. smtpd_sasl_local_domain =
  677. smtpd_sasl_path = smtpd
  678. smtpd_sasl_security_options = noanonymous
  679. smtpd_sasl_service = smtp
  680. smtpd_sasl_tls_security_options = $smtpd_sasl_security_options
  681. smtpd_sasl_type = cyrus
  682. smtpd_sender_login_maps =
  683. smtpd_sender_restrictions =
  684. smtpd_service_name = smtpd
  685. smtpd_soft_error_limit = 10
  686. smtpd_starttls_timeout = ${stress?{10}:{300}}s
  687. smtpd_timeout = ${stress?{10}:{300}}s
  688. smtpd_tls_CAfile =
  689. smtpd_tls_CApath =
  690. smtpd_tls_always_issue_session_ids = yes
  691. smtpd_tls_ask_ccert = no
  692. smtpd_tls_auth_only = no
  693. smtpd_tls_ccert_verifydepth = 9
  694. smtpd_tls_cert_file =
  695. smtpd_tls_ciphers = export
  696. smtpd_tls_dcert_file =
  697. smtpd_tls_dh1024_param_file =
  698. smtpd_tls_dh512_param_file =
  699. smtpd_tls_dkey_file = $smtpd_tls_dcert_file
  700. smtpd_tls_eccert_file =
  701. smtpd_tls_eckey_file = $smtpd_tls_eccert_file
  702. smtpd_tls_eecdh_grade = strong
  703. smtpd_tls_exclude_ciphers =
  704. smtpd_tls_fingerprint_digest = md5
  705. smtpd_tls_key_file = $smtpd_tls_cert_file
  706. smtpd_tls_loglevel = 0
  707. smtpd_tls_mandatory_ciphers = medium
  708. smtpd_tls_mandatory_exclude_ciphers =
  709. smtpd_tls_mandatory_protocols = !SSLv2
  710. smtpd_tls_protocols =
  711. smtpd_tls_received_header = no
  712. smtpd_tls_req_ccert = no
  713. smtpd_tls_security_level =
  714. smtpd_tls_session_cache_database =
  715. smtpd_tls_session_cache_timeout = 3600s
  716. smtpd_tls_wrappermode = no
  717. smtpd_upstream_proxy_protocol =
  718. smtpd_upstream_proxy_timeout = 5s
  719. smtpd_use_tls = no
  720. smtputf8_autodetect_classes = sendmail, verify
  721. soft_bounce = no
  722. stale_lock_time = 500s
  723. stress =
  724. strict_7bit_headers = no
  725. strict_8bitmime = no
  726. strict_8bitmime_body = no
  727. strict_mailbox_ownership = yes
  728. strict_mime_encoding_domain = no
  729. strict_rfc821_envelopes = no
  730. strict_smtputf8 = no
  731. sun_mailtool_compatibility = no
  732. swap_bangpath = yes
  733. syslog_facility = mail
  734. syslog_name = ${multi_instance_name?{$multi_instance_name}:{postfix}}
  735. tcp_windowsize = 0
  736. tls_append_default_CA = no
  737. tls_daemon_random_bytes = 32
  738. tls_dane_digest_agility = on
  739. tls_dane_digests = sha512 sha256
  740. tls_dane_trust_anchor_digest_enable = yes
  741. tls_disable_workarounds =
  742. tls_eecdh_strong_curve = prime256v1
  743. tls_eecdh_ultra_curve = secp384r1
  744. tls_export_cipherlist = aNULL:-aNULL:ALL:+RC4:@STRENGTH
  745. tls_high_cipherlist = aNULL:-aNULL:ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@STRENGTH
  746. tls_legacy_public_key_fingerprints = no
  747. tls_low_cipherlist = aNULL:-aNULL:ALL:!EXPORT:+RC4:@STRENGTH
  748. tls_medium_cipherlist = aNULL:-aNULL:ALL:!EXPORT:!LOW:+RC4:@STRENGTH
  749. tls_null_cipherlist = eNULL:!aNULL
  750. tls_preempt_cipherlist = no
  751. tls_random_bytes = 32
  752. tls_random_exchange_name = ${data_directory}/prng_exch
  753. tls_random_prng_update_period = 3600s
  754. tls_random_reseed_period = 3600s
  755. tls_random_source = dev:/dev/urandom
  756. tls_session_ticket_cipher = aes-128-cbc
  757. tls_ssl_options =
  758. tls_wildcard_matches_multiple_labels = yes
  759. tlsmgr_service_name = tlsmgr
  760. tlsproxy_enforce_tls = $smtpd_enforce_tls
  761. tlsproxy_service_name = tlsproxy
  762. tlsproxy_tls_CAfile = $smtpd_tls_CAfile
  763. tlsproxy_tls_CApath = $smtpd_tls_CApath
  764. tlsproxy_tls_always_issue_session_ids = $smtpd_tls_always_issue_session_ids
  765. tlsproxy_tls_ask_ccert = $smtpd_tls_ask_ccert
  766. tlsproxy_tls_ccert_verifydepth = $smtpd_tls_ccert_verifydepth
  767. tlsproxy_tls_cert_file = $smtpd_tls_cert_file
  768. tlsproxy_tls_ciphers = $smtpd_tls_ciphers
  769. tlsproxy_tls_dcert_file = $smtpd_tls_dcert_file
  770. tlsproxy_tls_dh1024_param_file = $smtpd_tls_dh1024_param_file
  771. tlsproxy_tls_dh512_param_file = $smtpd_tls_dh512_param_file
  772. tlsproxy_tls_dkey_file = $smtpd_tls_dkey_file
  773. tlsproxy_tls_eccert_file = $smtpd_tls_eccert_file
  774. tlsproxy_tls_eckey_file = $smtpd_tls_eckey_file
  775. tlsproxy_tls_eecdh_grade = $smtpd_tls_eecdh_grade
  776. tlsproxy_tls_exclude_ciphers = $smtpd_tls_exclude_ciphers
  777. tlsproxy_tls_fingerprint_digest = $smtpd_tls_fingerprint_digest
  778. tlsproxy_tls_key_file = $smtpd_tls_key_file
  779. tlsproxy_tls_loglevel = $smtpd_tls_loglevel
  780. tlsproxy_tls_mandatory_ciphers = $smtpd_tls_mandatory_ciphers
  781. tlsproxy_tls_mandatory_exclude_ciphers = $smtpd_tls_mandatory_exclude_ciphers
  782. tlsproxy_tls_mandatory_protocols = $smtpd_tls_mandatory_protocols
  783. tlsproxy_tls_protocols = $smtpd_tls_protocols
  784. tlsproxy_tls_req_ccert = $smtpd_tls_req_ccert
  785. tlsproxy_tls_security_level = $smtpd_tls_security_level
  786. tlsproxy_use_tls = $smtpd_use_tls
  787. tlsproxy_watchdog_timeout = 10s
  788. trace_service_name = trace
  789. transport_maps =
  790. transport_retry_time = 60s
  791. trigger_timeout = 10s
  792. undisclosed_recipients_header =
  793. unknown_address_reject_code = 450
  794. unknown_address_tempfail_action = $reject_tempfail_action
  795. unknown_client_reject_code = 450
  796. unknown_helo_hostname_tempfail_action = $reject_tempfail_action
  797. unknown_hostname_reject_code = 450
  798. unknown_local_recipient_reject_code = 550
  799. unknown_relay_recipient_reject_code = 550
  800. unknown_virtual_alias_reject_code = 550
  801. unknown_virtual_mailbox_reject_code = 550
  802. unverified_recipient_defer_code = 450
  803. unverified_recipient_reject_code = 450
  804. unverified_recipient_reject_reason =
  805. unverified_recipient_tempfail_action = $reject_tempfail_action
  806. unverified_sender_defer_code = 450
  807. unverified_sender_reject_code = 450
  808. unverified_sender_reject_reason =
  809. unverified_sender_tempfail_action = $reject_tempfail_action
  810. verp_delimiter_filter = -=+
  811. virtual_alias_address_length_limit = 1000
  812. virtual_alias_domains = $virtual_alias_maps
  813. virtual_alias_expansion_limit = 1000
  814. virtual_alias_maps = $virtual_maps
  815. virtual_alias_recursion_limit = 1000
  816. virtual_delivery_slot_cost = $default_delivery_slot_cost
  817. virtual_delivery_slot_discount = $default_delivery_slot_discount
  818. virtual_delivery_slot_loan = $default_delivery_slot_loan
  819. virtual_delivery_status_filter = $default_delivery_status_filter
  820. virtual_destination_concurrency_failed_cohort_limit = $default_destination_concurrency_failed_cohort_limit
  821. virtual_destination_concurrency_limit = $default_destination_concurrency_limit
  822. virtual_destination_concurrency_negative_feedback = $default_destination_concurrency_negative_feedback
  823. virtual_destination_concurrency_positive_feedback = $default_destination_concurrency_positive_feedback
  824. virtual_destination_rate_delay = $default_destination_rate_delay
  825. virtual_destination_recipient_limit = $default_destination_recipient_limit
  826. virtual_extra_recipient_limit = $default_extra_recipient_limit
  827. virtual_gid_maps =
  828. virtual_initial_destination_concurrency = $initial_destination_concurrency
  829. virtual_mailbox_base =
  830. virtual_mailbox_domains = $virtual_mailbox_maps
  831. virtual_mailbox_limit = 51200000
  832. virtual_mailbox_lock = fcntl, dotlock
  833. virtual_mailbox_maps =
  834. virtual_minimum_delivery_slots = $default_minimum_delivery_slots
  835. virtual_minimum_uid = 100
  836. virtual_recipient_limit = $default_recipient_limit
  837. virtual_recipient_refill_delay = $default_recipient_refill_delay
  838. virtual_recipient_refill_limit = $default_recipient_refill_limit
  839. virtual_transport = virtual
  840. virtual_uid_maps =