OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Accept email only from local for specific addresses

From: Magnus Bäck (magnusdsek.lth.se)
Date: Sat Jul 29 2006 - 11:40:20 CDT


On Saturday, July 29, 2006 at 18:01 CEST,
     Claude Needham <gxxaxxgmail.com> wrote:

[...]

> Logically it makes more sense to put:
>
> reject_unauth_destination,
> check_recipient_access hash:/etc/postfix/internal_only
> reject_rbl_client relays.ordb.org,
> reject_rbl_client list.dsbl.org,
> reject_rbl_client sbl-xbl.spamhaus.org,
>
> But I have no clue how much overhead the check_recipient_access is.
> And since all of the blacklisted stuff will be passing through this, I
> just don't know.

check_recipient_access has a significantly lower overhead than DNSBL
lookups (at least with hash maps), so it would be a good idea to put
it first. On the other hand, there will be very few cases where
check_recipient_access results in a reject so in reality it doesn't
matter.

--
Magnus Bäck
magnusdsek.lth.se