About "Passed CLEAN {RelayedOpenRelay}"

Benny Pedersen me at junc.eu
Fri Dec 21 00:04:24 CET 2018

Matus UHLAR - fantomas skrev den 2018-12-20 21:39:
>> Patrick Ben Koetter skrev den 2018-12-19 21:28:
>>> It usually means amavis has no idea what is inbound and what is 
>>> outbound mail.
>>> Configure @mynetworks and local_domains_maps correctly and you should 
>>> be fine.
> On 19.12.18 21:49, Benny Pedersen wrote:
>> and this does not depend on postfix config ?
> amavis does not read/understand postfix config

and maillist does not understand me, sadly

if postfix users use content-filter in main.cf of postfix then policy 
banks must in amavisd be configured as same networks as networks in 
postconf -n for the networks params, if this is not done amavisd does 
not know what is internal ip or even trusted local ip

on top of this amavisd could be fooled to belive its all originating 
emails, with will sign with dkim if amavisd is dkim signer

its depends on parts what happend

best advice is to make postfix master.cf select amavis policy banks by 
port numbers, so port 25 goes to incoming policy bank in amavisd, and 
submission to originating policy bank in amavisd, this bank is not 
default created in amavisd default config yet

i think Patrick can help more there then i can

