OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Immediate reject without calling policy service

From: Ralf Hildebrandt (Ralf.Hildebrandtcharite.de)
Date: Sat Dec 02 2006 - 06:50:44 CST


* elaconta.com Webmaster <webmasterelaconta.com>:
> Hi
>
> I've recently deployed MARBL (http://www.orangegroove.net/code/marbl/)
> to perform selective greylisting under Postfix as a policy server, and
> it absolutely rocks, giving us all the benefits of greylisting with no
> delay for most legitimate senders and about zero false positives.
> Now i have my Postfix configuration down cold, i'm into maximum
> optimization.
> When an email is sent to a non-existent email address in a domain, the
> marbl daemon seems to be queried before rejection. Is there any way for
> me to rearrange my restrictions so that email to nonexistent addresses
> will be rejected outright without having to go through MARBL and
> therefore avoiding costly DNS lookups?

You need to use
reject_unlisted_recipient before the policy server and after
reject_unauth_destination

--
Ralf Hildebrandt (Ralf.Hildebrandtcharite.de) plonkcharite.de
Postfix - Einrichtung, Betrieb und Wartung Tel. +49 (0)30-450 570-155
http://www.postfix-buch.com
Yes, and every single administrator that's configured their virus
scanner to bounce to envelope deserves a swift kick upside the head.