Postfix中基于发件人-收件人对精准拦截邮件的高效实现方案咨询
Postfix中基于发件人-收件人对精准拦截邮件的高效实现方案咨询
嘿,我完全懂你这种头疼的感觉——用smtpd_restriction_classes手动创建几十组规则文件和类,不仅配置麻烦,后期维护起来更是噩梦。针对你多域名Postfix环境下的精准拦截需求,我给你推荐两种更高效、易维护的方案,不用再折腾几十个独立文件:
方案一:单PCRE表搞定所有发件人-收件人拦截对(最推荐)
这种方式把所有拦截规则集中在一个文件里,不管多少组发件人-收件人对都能轻松维护:
- 确认PCRE支持:先执行
postconf -m | grep pcre,如果输出pcre就说明你的Postfix支持正则表,大部分发行版默认都带。 - 创建规则文件:新建
/etc/postfix/sender_recipient_block.pcre,把所有需要拦截的配对写在这里:# 格式:/^发件人邮箱$/ ${recipient}=目标收件人邮箱 REJECT /^a@sender.com$/ ${recipient}=b@recipient.com REJECT /^c@sender.com$/ ${recipient}=d@recipient.com REJECT # 支持批量拦截,比如拦截某发件人给整个域名发信: # /^spammer@bad-domain.com$/ ${recipient}=.*@your-domain.com REJECT - 配置Postfix主文件:修改
/etc/postfix/main.cf,添加自定义限制类并关联这个PCRE表:# 定义专门处理配对拦截的限制类 smtpd_restriction_classes = block_sender_recipient_pair block_sender_recipient_pair = check_sender_access pcre:/etc/postfix/sender_recipient_block.pcre # 在收件人限制规则中加入这个类(注意顺序,别放到permit规则前面) smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated block_sender_recipient_pair # 拦截规则放在这里 reject_unauth_destination # 保留你原有其他规则... - 生效配置:重启Postfix服务,比如
systemctl restart postfix(CentOS/Rocky)或service postfix restart(Debian/Ubuntu)。
方案二:哈希表分层配置(适合分类管理场景)
如果觉得正则不够直观,也可以用哈希表分层管理,比创建几十个限制类简洁很多:
- 创建收件人触发表:新建
/etc/postfix/recipient_block_trigger,指定哪些收件人需要触发发件人拦截:
执行b@recipient.com block_senders_for_b d@recipient.com block_senders_for_dpostmap /etc/postfix/recipient_block_trigger生成哈希库。 - 创建对应发件人拦截表:为每个收件人创建单独的发件人拦截表,比如
/etc/postfix/block_senders_for_b:
同样执行a@sender.com REJECTpostmap /etc/postfix/block_senders_for_b生成哈希库。 - 配置Postfix主文件:
smtpd_restriction_classes = block_senders_for_b, block_senders_for_d block_senders_for_b = check_sender_access hash:/etc/postfix/block_senders_for_b block_senders_for_d = check_sender_access hash:/etc/postfix/block_senders_for_d smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated check_recipient_access hash:/etc/postfix/recipient_block_trigger reject_unauth_destination # 保留你原有其他规则...
测试建议
配置完成后,可以用swaks工具模拟发件验证规则是否生效:
swaks --from a@sender.com --to b@recipient.com --server localhost
如果返回类似554 5.7.1 Access denied的错误,说明拦截规则已经正常工作。
备注:内容来源于stack exchange,提问作者dinamica
相关产品推荐
相关产品推荐

