Hi guys, i have a Problem with Mailfiltering...
I want to move specific types of attachments from external users to quarantine (in this case .doc files).
I thought the Rules are working, but today i noticed that in at least one case they are getting ignored.
Working sender:
Non working sender:
There is no whitelist or something in the second case.
Any suggestions?
EDIT: The mailservers are both connecting to the same external port.
I want to move specific types of attachments from external users to quarantine (in this case .doc files).
I thought the Rules are working, but today i noticed that in at least one case they are getting ignored.
Working sender:
Code:
Nov 12 09:53:46 mail postfix/smtpd[114951]: connect from mail.example.org[x.x.x.x]
Nov 12 09:53:46 mail postfix/smtpd[114951]: 5969810825FF: client=mail.example.org[x.x.x.x]
Nov 12 09:53:46 mail postfix/cleanup[114934]: 5969810825FF: message-id=<9c1c4cbf-eaa8-8dcd-c624-4e1c5e6f3d2f@example.org>
Nov 12 09:53:46 mail postfix/qmgr[93153]: 5969810825FF: from=<user@example.org>, size=44262, nrcpt=1 (queue active)
Nov 12 09:53:46 mail postfix/smtpd[114951]: disconnect from mail.example.org[x.x.x.x] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7
Nov 12 09:53:46 mail pmg-smtp-filter[114718]: 108260D5FACF81A6FB79: new mail message-id=<9c1c4cbf-eaa8-8dcd-c624-4e1c5e6f3d2f@example.org>#012
Nov 12 09:53:47 mail pmg-smtp-filter[114718]: 108260D5FACF81A6FB79: SA score=0/5 time=0.583 bayes=undefined autolearn=ham autolearn_force=no hits=AWL(-0.000),DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),DKIM_VALID_EF(-0.1),SPF_HELO_NONE(0.001),SPF_PASS(-0.001),URIBL_BLOCKED(0.001)
Nov 12 09:53:47 mail pmg-smtp-filter[114718]: 108260D5FACF81A6FB79: notify <user@example.org> (rule: Benachrichtigung, 1A3541082613)
Nov 12 09:53:47 mail pmg-smtp-filter[114718]: 108260D5FACF81A6FB79: moved mail for <recipient@destination.org> to attachment quarantine - 10826145FACF81B1BA9C (rule: Quarantine Office)
Nov 12 09:53:47 mail pmg-smtp-filter[114718]: 108260D5FACF81A6FB79: removed attachment 3 ('Auftrag.doc', rule: Quarantine Office)
Nov 12 09:53:47 mail pmg-smtp-filter[114718]: 108260D5FACF81A6FB79: block mail to <recipient@destination.org> (rule: Quarantine Office)
Nov 12 09:53:47 mail pmg-smtp-filter[114718]: 108260D5FACF81A6FB79: processing time: 0.661 seconds (0.583, 0.054, 0)
Nov 12 09:53:47 mail postfix/lmtp[114935]: 5969810825FF: to=<recipient@destination.org>, relay=127.0.0.1[127.0.0.1]:10024, delay=0.79, delays=0.13/0/0/0.66, dsn=2.7.0, status=sent (250 2.7.0 BLOCKED (108260D5FACF81A6FB79))
Nov 12 09:53:47 mail postfix/qmgr[93153]: 5969810825FF: removed
Non working sender:
Code:
Nov 12 09:52:43 mail postfix/smtpd[114715]: connect from mout.example1.org[x.x.x.x]
Nov 12 09:52:44 mail postfix/smtpd[114715]: 08DFA10825FF: client=mout.example1.org[x.x.x.x]
Nov 12 09:52:44 mail postfix/cleanup[114934]: 08DFA10825FF: message-id=<ac629a9927ec45b68b4ce30cb15350fa@user-domain.de>
Nov 12 09:52:44 mail postfix/qmgr[93153]: 08DFA10825FF: from=<user1@user-domain.de>, size=59889, nrcpt=1 (queue active)
Nov 12 09:52:44 mail postfix/smtpd[114715]: disconnect from mout.example1.org[x.x.x.x] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Nov 12 09:52:44 mail pmg-smtp-filter[114827]: 108260D5FACF7DC1DBD5: new mail message-id=<ac629a9927ec45b68b4ce30cb15350fa@user-domain.de>#012
Nov 12 09:52:44 mail pmg-smtp-filter[114827]: 108260D5FACF7DC1DBD5: SA score=1/5 time=0.625 bayes=undefined autolearn=no autolearn_force=no hits=AWL(0.158),KAM_DMARC_STATUS(0.01),KAM_LAZY_DOMAIN_SECURITY(1),RCVD_IN_DNSWL_NONE(-0.0001),RCVD_IN_MSPIKE_H2(-0.001),SPF_HELO_NONE(0.001),SPF_NONE(0.001)
Nov 12 09:52:44 mail postfix/smtpd[114940]: connect from localhost.localdomain[127.0.0.1]
Nov 12 09:52:44 mail postfix/smtpd[114940]: C72491082613: client=localhost.localdomain[127.0.0.1], orig_client=mout.example1.org[x.x.x.x]
Nov 12 09:52:44 mail postfix/cleanup[114934]: C72491082613: message-id=<ac629a9927ec45b68b4ce30cb15350fa@user-domain.de>
Nov 12 09:52:44 mail postfix/qmgr[93153]: C72491082613: from=<user1@user-domain.de>, size=60702, nrcpt=1 (queue active)
Nov 12 09:52:44 mail postfix/smtpd[114940]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Nov 12 09:52:44 mail pmg-smtp-filter[114827]: 108260D5FACF7DC1DBD5: accept mail to <recipient@destination.org> (C72491082613) (rule: default-accept)
Nov 12 09:52:44 mail pmg-smtp-filter[114827]: 108260D5FACF7DC1DBD5: processing time: 0.7 seconds (0.625, 0.049, 0)
Nov 12 09:52:44 mail postfix/lmtp[114935]: 08DFA10825FF: to=<recipient@destination.org>, relay=127.0.0.1[127.0.0.1]:10024, delay=0.83, delays=0.1/0.01/0.01/0.71, dsn=2.5.0, status=sent (250 2.5.0 OK (108260D5FACF7DC1DBD5))
Nov 12 09:52:44 mail postfix/qmgr[93153]: 08DFA10825FF: removed
Nov 12 09:52:44 mail postfix/smtp[114941]: C72491082613: to=<recipient@destination.org>, relay=x.x.x.x[x.x.x.x]:25, delay=0.15, delays=0.01/0.01/0.02/0.11, dsn=2.6.0, status=sent (250 2.6.0 <ac629a9927ec45b68b4ce30cb15350fa@user-domain.de> [InternalId=45518063403451, Hostname=mailserver.destination.org] 62103 bytes in 0.104, 579,370 KB/sec Queued mail for delivery)
Nov 12 09:52:44 mail postfix/qmgr[93153]: C72491082613: removed
There is no whitelist or something in the second case.
Any suggestions?
EDIT: The mailservers are both connecting to the same external port.
Last edited: