activeguard/mta/startup_cfg/postfix_custom/.
Next hop syntax
The following syntax can be used to set the next hop in routing-related configuration, for example intransport maps or in the relayhost parameter.
Sender-based routing
In sender-based routing, the next hop (referred to as<next-hop>) for the email is chosen based on the sender’s address (MAIL FROM). This configuration is usually only used in conjunction with recipient-based routing to address special cases.
First, we need to enable the sender-dependent transport in the main.cf file:
sender_dependent_transport file does not exist, you have to create it.
Routing precedencePlease be aware that recipient-based routing has precedence over sender-based routing. If a recipient address matches an entry in
transport, it will overrule any next-hop configurations from a match in sender_dependent_transport.sender_dependent_transport file. You can specify sender email addresses as well as sender domains:
Subdomain matching
Subdomains in transport maps
When configuring email routing intransport, subdomains are not matched by default. This means that if you want to route emails for both a domain (e.g., xorlab.com) and its subdomains (e.g., sub.xorlab.com), you must either specify them explicitly or use the dot-prefix (.) syntax to apply a wildcard rule.
main.cf:
Subdomains in client access
In contrast, subdomain matching behaves differently forclient_access and relay_domains configurations. For these settings, subdomains are automatically matched without requiring explicit entries. This is because Postfix performs a reverse DNS lookup on the EHLO IP address, which allows it to match both the domain and its subdomains seamlessly.
For example:
- In
client_access, you only need to list the top-level domain (xorlab.com), and subdomains will be matched automatically. - Similarly, listing the main domains as
relay_domainsinmain.cfis sufficient for subdomain matching.
Sender and recipient restrictions
This section explains how to impose generic restrictions on either a sending MTA or on a recipient address or domain.SMTP restrictionsThe restrictions described in this section refer to the SMTP connection only. Emails rejected during the SMTP connection will not appear in the XCC web interface.
Reject clients
To reject emails from certain sender IPs or hostnames during the SMTP connection, list them in theclient_access file with reject:
Reject recipients
To reject all emails to certain recipients, add these recipients to the filerecipient_access:
TLS configuration
TLS policies can be defined for xorlab Security Platform when acting as a client as well as when acting as a server. The policies are set inmain.cf:
none: Disable TLS.may(default): Opportunistic TLS. Use TLS if the client, respectively the server, supports TLS.encrypt: Enforce TLS. Do not send or receive emails without TLS. No valid certificate required.verify: Enforce TLS and successful certificate verification. Only supported forsmtp_tls_security_level.
smtp_tls_security_level as well as smtpd_tls_security_level.
After changing the TLS policy, click Publish. The new Postfix settings become active within about one minute.
SMTP auth for specific email addresses
If you want emails sent from specific addresses to be routed through an SMTP server requiring authentication, you can follow this configuration. For example, you can authenticate xorlab Security Platform when sending reported email feedback from thethreatanalyst@example.com address:
-
Set the desired sender address for feedback emails as described in Feedback emails. We will use
threatanalyst@example.comhere. For any other email addresses, just skip this step. -
Configure sender-dependent transport in the
main.cffile by enabling (uncommenting) this line: -
If the
sender_dependent_transportfile does not exist, create it and add this entry: -
In the same folder, create two files:
sasl_passwd.lmdband ansasl_passwdfile. Leave the former empty, while in the latter add this line: -
Finally, go back to the
main.cffile and add the following block under the line you enabled in step #2: - Click Publish. The new Postfix settings become active within about one minute.
Message size limit
The maximum message size that xorlab Security Platform will accept during an SMTP connection can be defined inmain.cf and postfix_custom/master.cf:
main.cf
master.cf
- Many major email providers don’t accept message sizes over 35 MB.
- The xorlab Security Platform file size limit for attachments sent to the Sandbox is 50 MB.
- Aggressively increasing the message size limit can slow down email processing times.
Additional configuration
xorlab Security Platform exposes the internal Postfix configuration files and thereby allows you to use the entire SMTP configuration that Postfix offers. This includes, for example:- Address rewrites
- Header rewrites
- SMTP connection configuration (limit, rate, delay, etc.)
Postfix lookup tablesxorlab supports Postmap lookup tables in
lmdb: format (Lookup tables).The following files are automatically postmapped: client_access,client_access_tenant,recipient_access,sender_access,transport,sender_dependent_transport and postmap_*.If you use a different file name, you need to either:a) Prefix your file postmap_.b) Create an empty file with the same name and .lmbd suffix. E.g., for custom_transport, you need to create an empty file called custom_transport.lmdb in the same folder.Reserved configuration
The following Postfix features are reserved for internal use and must not be configured:mynetworks: Use theclient_accessfile instead to allow certain IPs to relay emails through xorlab Security Platformcontent_filter
Multi-Tenancy
In a multi-tenant deployment, routing is configured with the same Postfix files described on this page, but they have to line up with the tenants declared inshared/guarded_tenants.yml:
transportneeds a next hop per guarded domain.client_accessneeds to permit the SMTP clients of every tenant.client_access_tenantprepends the header that xorlab uses to identify the tenant, matching thetenantSelectorof that tenant.