How to restrict incoming mail in Postfix.

in linux •  11 months ago

How to restrict incoming mail in Postfix.


Scenario: We have some discussion groups (alias) and we want only a few internal people in the field to have access to them and the rest of the internet and internally are not allowed.

We are supposed to have:

  • postfix on linux ( centos or debian )
  • minimal knowledge of linux
  • I know how to use a cli editor like vim or nano
    postfix1.png

Our domain: covaci.tk
alias: all@covaci.tk and restrict@covaci.tk

1. First Step Setup list to restrict.
vim /etc/postfix/main.cf
smtpd_recipient_restrictions = check_recipient_access hash:/etc/postfix/protected_destinations
....................
..................
...the usual stuff...

Here we have defined a class for each alias.

And in these files who has the right
to send mail and the rest rejected (in /etc/postfix/main.cf ).
smtpd_restriction_classes = local_only
smtpd_restriction_classes = local_only2
local_only = check_sender_access pcre:/etc/postfix/restrict_intern
local_only2 = check_sender_access pcre:/etc/postfix/restrict_intern2

2. Second Step create files
vim /etc/postfix/protected_destinations
restrict@covaci.tk local_only
all@covaci.tk local_only2

After you exit the file you're running postmap /etc/postfix/protected_destinations

vim /etc/postfix/restrict_intern

/lucian@covaci.tk$/ OK
/user2@covaci.tk$/ OK
/.+/ REJECT

If you want a custom error message:
/.+/ REJECT "This is a custom error messages created by Admin Team at Boss request!"

The rule in this file says that only user lucian@covaci.tk and user2@covaci.tk have the right to send the rest of the mail are rejected.
vim /etc/postfix/restrict_intern2

/userlocal76@covaci.tk$/ OK
/.+/ REJECT

And finally get restart services

/etc/init.d/postfix restart ( sysV systems like Centos 6) or
systemctl restart postfix ( systemd system like Centos 7)

If you get some errors look at /var/log/maillog and test if works!
Source: http://www.postfix.net/RESTRICTION_CLASS_README.html

@luciancovaci
If you liked it
Upvote and Follow!
Created on 20170908 at 17:41 EET

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!