EC2 Ubuntu实例部署Postfix SMTP服务器遇Relay access denied错误求助
问题:EC2 Ubuntu Postfix SMTP服务器发送邮件时出现Relay access denied错误
我在EC2的Ubuntu实例上搭建了Postfix SMTP服务器,配置了端口和EC2入站规则,但运行Node.js代码发送邮件时遇到以下错误:
Error: Can't send mail - all recipients were rejected: 454 4.7.1 <recipient@yopmail.com>: Relay access denied at SMTPConnection._formatError (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:790:19) at SMTPConnection._actionRCPT (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1654:28) at SMTPConnection.<anonymous> (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1607:30) at SMTPConnection._processResponse (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:969:20) at SMTPConnection._onData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:755:14) at SMTPConnection._onSocketData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:193:44) at TLSSocket.emit (node:events:514:28) at addChunk (node:internal/streams/readable:324:12) at readableAddChunk (node:internal/streams/readable:297:9) at Readable.push (node:internal/streams/readable:234:10) { code: 'EENVELOPE', response: '454 4.7.1 <recipient@yopmail.com>: Relay access denied', responseCode: 454, command: 'RCPT TO', rejected: [ '<recipient@yopmail.com>' ], rejectedErrors: [ Error: Recipient command failed: 454 4.7.1 <recipient@yopmail.com>: Relay access denied at SMTPConnection._formatError (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:790:19) at SMTPConnection._actionRCPT (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1640:24) at SMTPConnection.<anonymous> (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1607:30) at SMTPConnection._processResponse (C:\path\burra\node_modules\nodemailer\lib\smtp-connection\index.js:969:20) at SMTPConnection._onData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:755:14) at SMTPConnection._onSocketData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:193:44) at TLSSocket.emit (node:events:514:28) at addChunk (node:internal/streams/readable:324:12) at readableAddChunk (node:internal/streams/readable:297:9) at Readable.push (node:internal/streams/readable:234:10) { code: 'EENVELOPE', response: '454 4.7.1 <recipient@yopmail.com>: Relay access denied', responseCode: 454, command: 'RCPT TO', recipient: '<recipient@yopmail.com>' } ] }
使用的Node.js代码如下:
const nodemailer = require('nodemailer'); const transporter = nodemailer.createTransport({ host: 'EC2_IP', // Replace with your EC2 instance public IP or domain port: 25, secure: false, tls: { rejectUnauthorized: false }, auth: { user: 'EC2_UBUNTU_LOGIN_USERNAME', // Use the system user associated with Postfix pass: 'EC2_UBUNTU_LOGIN_PASSWORD' // Use the system user's password } }); const mailOptions = { from: 'sender@gmail.com', to: 'recipient@yopmail.com', subject: 'Test Email', text: 'This is a test email from your Node.js script.' }; transporter.sendMail(mailOptions, (error, info) => { if (error) { return console.error('Error:', error); } console.log('Email sent:', info.response); });
解决方案
这个错误的核心是Postfix拒绝了中继请求——Postfix默认只允许本地发送或特定可信来源的邮件中继到外部地址。以下是具体修复步骤:
1. 调整Postfix中继配置
编辑Postfix主配置文件:
sudo nano /etc/postfix/main.cf
修改以下关键参数:
- mynetworks:添加运行Node.js代码的客户端公网IP,或者EC2实例的私有IP段,允许这些地址发起中继请求。示例:
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 你的客户端公网IP/32 - smtpd_relay_restrictions:确保配置允许可信网络和认证用户的中继请求,修改为:
smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination
2. 启用Postfix SASL认证
Postfix默认未开启账号密码认证,需要配置让Node.js的登录信息通过验证:
- 安装依赖包:
sudo apt install postfix sasl2-bin - 编辑
/etc/postfix/sasl/smtpd.conf,添加:pwcheck_method: saslauthd mech_list: plain login - 修改
/etc/default/saslauthd,设置:START=yes OPTIONS="-c -m /var/spool/postfix/var/run/saslauthd" - 重启相关服务:
sudo systemctl restart saslauthd sudo systemctl restart postfix
3. 验证认证有效性
在EC2实例上测试SASL认证是否正常:
testsaslauthd -u EC2_UBUNTU_LOGIN_USERNAME -p EC2_UBUNTU_LOGIN_PASSWORD
返回0: OK "Success."则说明认证配置正确。
4. 优化Node.js代码配置
- 发件人地址:建议使用Postfix服务器上的有效本地地址(如
username@你的EC2域名),避免被目标邮箱系统判定为垃圾邮件,同时Postfix可能拒绝非本地的发件人地址。 - 端口替换:部分云服务商默认限制25端口,可改用587端口,修改后的transporter配置:
const transporter = nodemailer.createTransport({ host: 'EC2_IP', port: 587, secure: false, tls: { rejectUnauthorized: false }, auth: { user: 'EC2_UBUNTU_LOGIN_USERNAME', pass: 'EC2_UBUNTU_LOGIN_PASSWORD' } });
5. 检查防火墙规则
确保EC2安全组允许入站的25或587端口,同时开放Ubuntu本地防火墙端口:
sudo ufw allow 587/tcp sudo ufw reload
内容的提问来源于stack exchange,提问作者Meghana Burra
相关产品推荐
相关产品推荐

