为macOS上运行的Postfix设置访问密码,强制端口25身份验证
在Mac上为Postfix端口25启用强制身份验证
完全可以实现,以下是具体配置步骤:
1. 修改Postfix主配置文件
编辑/etc/postfix/main.cf,添加或更新以下配置项:
- 启用SASL身份验证模块:
smtpd_sasl_auth_enable = yes smtpd_sasl_security_options = noanonymous smtpd_sasl_local_domain = $myhostname - 强制仅允许已认证客户端通过端口25中继邮件:
这条规则会优先放行已完成身份验证的客户端,直接拒绝未认证客户端的中继请求,完全契合你的需求。smtpd_recipient_restrictions = permit_sasl_authenticated, reject_unauth_destination
2. 配置并启动SASL认证服务(saslauthd)
Mac系统自带saslauthd,默认通过PAM验证系统用户账号:
- 若不存在
/etc/saslauthd.conf则创建该文件,添加:pwcheck_method: saslauthd mech_list: plain login - 启动
saslauthd服务:sudo launchctl load -w /System/Library/LaunchDaemons/org.postfix.saslauthd.plist
3. 重启Postfix使配置生效
sudo postfix reload
验证配置效果
可以用swaks或telnet工具测试:
- 未执行认证步骤直接尝试发送邮件,Postfix会返回
554 5.7.1 Relay access denied的拒绝信息 - 执行
AUTH PLAIN或AUTH LOGIN并提供正确的系统账号密码后,即可正常完成邮件中继
内容的提问来源于stack exchange,提问作者mihirg
相关产品推荐
相关产品推荐

