Différences
Ci-dessous, les différences entre deux révisions de la page.
Les deux révisions précédentes Révision précédente Prochaine révision | Révision précédente | ||
serveur:mail [2021/04/05 14:57] – [Configuration main.cf] d2air | serveur:mail [2021/05/13 10:48] (Version actuelle) – [Création d’un serveur virtuel Apache2] d2air | ||
---|---|---|---|
Ligne 152: | Ligne 152: | ||
SSLCertificateFile | SSLCertificateFile | ||
SSLCertificateKeyFile | SSLCertificateKeyFile | ||
- | Header always | + | |
- | Header always set X-Content-Type-Options " | + | |
- | Header always set X-Frame-Options DENY | + | Header always set X-Content-Type-Options " |
- | Header always set X-XSS-Protection "1; mode=block" | + | Header always set X-Frame-Options |
+ | Header always set X-XSS-Protection "1; mode=block" | ||
+ | Header set Content-Security-Policy-Report-Only " | ||
+ | </ | ||
# | # | ||
Ligne 485: | Ligne 488: | ||
smtpd_recipient_restrictions = | smtpd_recipient_restrictions = | ||
+ | reject_rbl_client xbl.spamhaus.org, | ||
+ | reject_rbl_client pbl.spamhaus.org, | ||
+ | reject_rbl_client sbl.spamhaus.org, | ||
+ | reject_rbl_client multi.uribl.com, | ||
+ | reject_rbl_client rbl-plus.mail-abuse.org, | ||
+ | reject_rbl_client dialups.mail-abuse.org, | ||
reject_invalid_hostname, | reject_invalid_hostname, | ||
reject_non_fqdn_hostname, | reject_non_fqdn_hostname, | ||
Ligne 496: | Ligne 505: | ||
reject_unauth_destination, | reject_unauth_destination, | ||
reject_unverified_recipient, | reject_unverified_recipient, | ||
- | check_policy_service unix: | ||
permit | permit | ||
Ligne 835: | Ligne 843: | ||
<file sh main.cf> | <file sh main.cf> | ||
smtpd_recipient_restrictions = | smtpd_recipient_restrictions = | ||
- | | + | reject_rbl_client xbl.spamhaus.org, |
- | reject_non_fqdn_hostname, | + | reject_rbl_client pbl.spamhaus.org, |
- | reject_non_fqdn_sender, | + | reject_rbl_client sbl.spamhaus.org, |
- | reject_non_fqdn_recipient, | + | reject_rbl_client multi.uribl.com, |
- | reject_unknown_sender_domain, | + | reject_rbl_client rbl-plus.mail-abuse.org, |
- | reject_unknown_recipient_domain, | + | reject_rbl_client dialups.mail-abuse.org, |
- | | + | reject_invalid_hostname, |
- | reject_unverified_recipient, | + | reject_non_fqdn_hostname, |
- | | + | reject_non_fqdn_sender, |
- | permit_sasl_authenticated, | + | reject_non_fqdn_recipient, |
- | permit_auth_destination, | + | reject_unknown_sender_domain, |
- | | + | reject_unknown_recipient_domain, |
- | check_policy_service inet: | + | permit_mynetworks, |
- | permit | + | permit_sasl_authenticated, |
+ | permit_auth_destination, | ||
+ | reject_unauth_destination, | ||
+ | reject_unverified_recipient, | ||
+ | check_policy_service inet: | ||
+ | permit | ||
</ | </ | ||
Puis il faut relancer Postfix en surveillant les logs : | Puis il faut relancer Postfix en surveillant les logs : | ||
Ligne 1093: | Ligne 1106: | ||
<file sh main.cf> | <file sh main.cf> | ||
smtpd_recipient_restrictions = | smtpd_recipient_restrictions = | ||
- | [...] | + | reject_rbl_client xbl.spamhaus.org, |
- | reject_unauth_destination, | + | reject_rbl_client pbl.spamhaus.org, |
- | check_policy_service unix: | + | reject_rbl_client sbl.spamhaus.org, |
- | permit | + | reject_rbl_client multi.uribl.com, |
+ | reject_rbl_client rbl-plus.mail-abuse.org, | ||
+ | reject_rbl_client dialups.mail-abuse.org, | ||
+ | reject_invalid_hostname, | ||
+ | reject_non_fqdn_hostname, | ||
+ | reject_non_fqdn_sender, | ||
+ | reject_non_fqdn_recipient, | ||
+ | reject_unknown_sender_domain, | ||
+ | reject_unknown_recipient_domain, | ||
+ | permit_mynetworks, | ||
+ | permit_sasl_authenticated, | ||
+ | permit_auth_destination, | ||
+ | reject_unauth_destination, | ||
+ | reject_unverified_recipient, | ||
+ | check_policy_service unix: | ||
+ | check_policy_service inet: | ||
+ | permit | ||
policy-spf_time_limit = 3600s | policy-spf_time_limit = 3600s | ||
Ligne 1106: | Ligne 1135: | ||
systemctl restart postfix | systemctl restart postfix | ||
</ | </ | ||
- | Notre serveur peut maintenant vérifier les enregistrements SPF d'un autre serveur de messagerie. Pour vous assurer que cela fonctionne, envoyez vous un e-mail depuis un autre fournisseur et vous devriez voir l’en-tête | + | Notre serveur peut maintenant vérifier les enregistrements SPF d’un autre serveur de messagerie. Pour vous assurer que cela fonctionne, envoyez-vous un e-mail depuis un autre fournisseur et vous devriez voir l’en-tête |
< | < | ||
Authentication-Results: | Authentication-Results: |