You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Postfix邮件服务器465端口发件失败求助:替代25端口配置问题

Postfix通过465端口发送邮件失败(Relay access denied)问题解决

问题背景

Linux服务器因策略限制无法开放25端口,改用465端口发送邮件,已配置Postfix的TLS参数、relayhost及master.cf,但发送邮件时出现Relay access denied错误。

当前配置

TLS参数(main.cf)

# TLS parameters
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous

smtpd_use_tls = yes
smtp_tls_wrappermode = yes
smtp_tls_security_level = encrypt

smtpd_tls_cert_file = /etc/letsencrypt/live/mail.mydomain.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.mydomain.com/privkey.pem
smtpd_tls_security_level = encrypt

Relayhost配置(main.cf)

relayhost = [mail.mydomain.com]:465
mydestination = mail.$mydomain, mydomain.com, iZ0xi7acfsuw7o16lyv8e0Z, localhost.localdomain, localhost

master.cf配置

smtps     inet  n       -       n       -       -       smtpd
        -o smtpd_tls_wrappermode=yes
        -o smtpd_tls_security_level=encrypt
        -o smtpd_tls_cert_file=/etc/letsencrypt/live/mail.mydomain.com/fullchain.pem
        -o smtpd_tls_key_file=/etc/letsencrypt/live/mail.mydomain.com/privkey.pem

smtp      inet  n       -       y       -       -       smtpd
        -o smtpd_tls_security_level=encrypt
        -o smtp_tls_wrappermode=yes
        -o smtp_tls_security_level=encrypt
        -o smtpd_tls_wrappermode=yes

关键错误日志

NOQUEUE: reject: RCPT from mail.mydomain.com[xx.xxx.xx.xxx]: 454 4.7.1 <target@gmail.com>: Relay access denied; from=<root@iZ0xi7acfsuw7o16lyv8e0Z> to=<target@gmail.com> proto=ESMTP helo=<mail.mydomain.com>

2024-12-18T01:15:26.044309+08:00 iZ0xi7acfsuw7o16lyv8e0Z postfix/smtp[429557]: E379AC1D0E: to=<target@gmail.com>, relay=mail.mydomain.com[xx.xxx.xx.xxx]:465, delay=587, delays=587/0.02/0.26/0.01, dsn=4.7.1, status=deferred (host mail.mydomain.com[xx.xxx.xx.xxx] said: 454 4.7.1 <target@gmail.com>: Relay access denied (in reply to RCPT TO command))
2024-12-18T01:15:26.045320+08:00 iZ0xi7acfsuw7o16lyv8e0Z postfix/smtpd[429561]: disconnect from mail.mydomain.com[xx.xxx.xx.xxx] ehlo=1 mail=1 rcpt=0/1 data=0/1 rset=1 quit=1 commands=4/6

解决方案

1. 修正master.cf的smtp服务配置

master.cf中smtp服务的配置存在冗余错误,smtpd_tls_wrappermode=yes仅适用于465端口的smtps服务,25端口的smtp服务不需要该参数,同时客户端TLS配置应放在main.cf而非master.cf的smtp服务段。修改后的smtp服务配置如下:

smtp      inet  n       -       y       -       -       smtpd
        -o smtpd_tls_security_level=encrypt

2. 配置允许Relay的来源

在main.cf中添加/修改smtpd_relay_restrictions和mynetworks参数,确保服务器自身IP被允许作为Relay来源:

# 允许本地网络和认证用户转发邮件
smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination
# 包含服务器公网IP、localhost等可信地址
mynetworks = 127.0.0.0/8 [::1]/128 xx.xxx.xx.xxx/32

将xx.xxx.xx.xxx替换为服务器的实际公网IP。

3. 验证SASL认证配置

确保/etc/postfix/sasl_passwd文件包含正确的relayhost账号密码:

[mail.mydomain.com]:465 你的邮箱账号:你的邮箱密码

执行以下命令生成哈希映射文件:

postmap /etc/postfix/sasl_passwd

确保文件权限正确:

chmod 600 /etc/postfix/sasl_passwd /etc/postfix/sasl_passwd.db

4. 重启Postfix服务

systemctl restart postfix

5. 测试邮件发送

使用sendmail或mail命令测试发送:

echo "测试邮件内容" | mail -s "测试主题" target@gmail.com

查看日志验证是否成功:

tail -f /var/log/mail.log

内容的提问来源于stack exchange,提问作者Tony Cheng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 12:40:58