OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: ANTI-SPAM: Adding more envelope information to Received: header generation

From: Len Conrad (LConradGo2France.com)
Date: Thu May 01 2003 - 15:24:05 CDT


> > If you compile postfix with -DRECEIVED_ENVELOPE_FROM in you CCARGS you
> > will get something like this.
> >
> > Received: from camomile.cloud9.net (camomile.cloud9.net [168.100.1.3])
> > by kaneda.oav.net (Postfix) with ESMTP id A244A15736 for
> > <kiwioav.net>; Thu, 1 May 2003 18:15:16 +0200 (CEST) (envelope-from
> > owner-postfix-userspostfix.org)

For more verbose Received headers ok, but is there any compile trick to get
more info into a single maillog line?

It's easy to report on qmgr lines to see what the postfix queue ID +
envelope sender was for a msg that was accepted ("ah, that's a spammer
sender.domain to block, but what MTA sent it?"). It's very expensive to
go back through the maillog file, 100's or 1000's of iterations, grepping
for a queue ID to find the log lines with SMTPD/MTA and SMTP/envelope
recipient. man pages

Len

_____________________________________________________________________
http://MenAndMice.com/DNS-training: Denver; New York; Seattle
IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free