You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2 Ubuntu实例部署Postfix SMTP服务器遇Relay access denied错误求助

问题:EC2 Ubuntu Postfix SMTP服务器发送邮件时出现Relay access denied错误

我在EC2的Ubuntu实例上搭建了Postfix SMTP服务器,配置了端口和EC2入站规则,但运行Node.js代码发送邮件时遇到以下错误:

Error: Can't send mail - all recipients were rejected: 454 4.7.1 <recipient@yopmail.com>: Relay access denied
    at SMTPConnection._formatError (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:790:19)
    at SMTPConnection._actionRCPT (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1654:28)
    at SMTPConnection.<anonymous> (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1607:30)
    at SMTPConnection._processResponse (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:969:20)
    at SMTPConnection._onData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:755:14)
    at SMTPConnection._onSocketData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:193:44)
    at TLSSocket.emit (node:events:514:28)
    at addChunk (node:internal/streams/readable:324:12)
    at readableAddChunk (node:internal/streams/readable:297:9)
    at Readable.push (node:internal/streams/readable:234:10) {
  code: 'EENVELOPE',
  response: '454 4.7.1 <recipient@yopmail.com>: Relay access denied',
  responseCode: 454,
  command: 'RCPT TO',
  rejected: [ '<recipient@yopmail.com>' ],
  rejectedErrors: [
    Error: Recipient command failed: 454 4.7.1 <recipient@yopmail.com>: Relay access denied
        at SMTPConnection._formatError (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:790:19)
        at SMTPConnection._actionRCPT (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1640:24)
        at SMTPConnection.<anonymous> (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:1607:30)
        at SMTPConnection._processResponse (C:\path\burra\node_modules\nodemailer\lib\smtp-connection\index.js:969:20)
        at SMTPConnection._onData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:755:14)
        at SMTPConnection._onSocketData (C:\Users\path\node_modules\nodemailer\lib\smtp-connection\index.js:193:44)
        at TLSSocket.emit (node:events:514:28)
        at addChunk (node:internal/streams/readable:324:12)
        at readableAddChunk (node:internal/streams/readable:297:9)
        at Readable.push (node:internal/streams/readable:234:10) {
      code: 'EENVELOPE',
      response: '454 4.7.1 <recipient@yopmail.com>: Relay access denied',
      responseCode: 454,
      command: 'RCPT TO',
      recipient: '<recipient@yopmail.com>'
    }
  ]
}

使用的Node.js代码如下:

const nodemailer = require('nodemailer');

const transporter = nodemailer.createTransport({
    host: 'EC2_IP', // Replace with your EC2 instance public IP or domain
    port: 25,
    secure: false,
    tls: {
        rejectUnauthorized: false
    },
    auth: {
        user: 'EC2_UBUNTU_LOGIN_USERNAME', // Use the system user associated with Postfix
        pass: 'EC2_UBUNTU_LOGIN_PASSWORD' // Use the system user's password
    }
});

const mailOptions = {
    from: 'sender@gmail.com',
    to: 'recipient@yopmail.com',
    subject: 'Test Email',
    text: 'This is a test email from your Node.js script.'
};

transporter.sendMail(mailOptions, (error, info) => {
    if (error) {
        return console.error('Error:', error);
    }
    console.log('Email sent:', info.response);
});

解决方案

这个错误的核心是Postfix拒绝了中继请求——Postfix默认只允许本地发送或特定可信来源的邮件中继到外部地址。以下是具体修复步骤:

1. 调整Postfix中继配置

编辑Postfix主配置文件:

sudo nano /etc/postfix/main.cf

修改以下关键参数:

  • mynetworks:添加运行Node.js代码的客户端公网IP,或者EC2实例的私有IP段,允许这些地址发起中继请求。示例:
    mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 你的客户端公网IP/32
    
  • smtpd_relay_restrictions:确保配置允许可信网络和认证用户的中继请求,修改为:
    smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination
    

2. 启用Postfix SASL认证

Postfix默认未开启账号密码认证,需要配置让Node.js的登录信息通过验证:

  1. 安装依赖包:
    sudo apt install postfix sasl2-bin
    
  2. 编辑/etc/postfix/sasl/smtpd.conf,添加:
    pwcheck_method: saslauthd
    mech_list: plain login
    
  3. 修改/etc/default/saslauthd,设置:
    START=yes
    OPTIONS="-c -m /var/spool/postfix/var/run/saslauthd"
    
  4. 重启相关服务:
    sudo systemctl restart saslauthd
    sudo systemctl restart postfix
    

3. 验证认证有效性

在EC2实例上测试SASL认证是否正常:

testsaslauthd -u EC2_UBUNTU_LOGIN_USERNAME -p EC2_UBUNTU_LOGIN_PASSWORD

返回0: OK "Success."则说明认证配置正确。

4. 优化Node.js代码配置

  • 发件人地址:建议使用Postfix服务器上的有效本地地址(如username@你的EC2域名),避免被目标邮箱系统判定为垃圾邮件,同时Postfix可能拒绝非本地的发件人地址。
  • 端口替换:部分云服务商默认限制25端口,可改用587端口,修改后的transporter配置:
    const transporter = nodemailer.createTransport({
        host: 'EC2_IP',
        port: 587,
        secure: false,
        tls: {
            rejectUnauthorized: false
        },
        auth: {
            user: 'EC2_UBUNTU_LOGIN_USERNAME',
            pass: 'EC2_UBUNTU_LOGIN_PASSWORD'
        }
    });
    

5. 检查防火墙规则

确保EC2安全组允许入站的25或587端口,同时开放Ubuntu本地防火墙端口:

sudo ufw allow 587/tcp
sudo ufw reload

内容的提问来源于stack exchange,提问作者Meghana Burra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 03:49:56