1 |
On Dec 6, 2011 7:19 AM, "Grant" <emailgrant@×××××.com> wrote: |
2 |
> |
3 |
> > Here's the entirety of my main.cf postscreen section for reference. I've |
4 |
> > deemed these safe, but you shouldn't enable them without reading what |
5 |
they |
6 |
> > do! |
7 |
> > |
8 |
> > |
9 |
> > # |
10 |
> > # Postscreen settings |
11 |
> > # |
12 |
> > |
13 |
> > postscreen_greet_action = enforce |
14 |
> > |
15 |
> > postscreen_dnsbl_sites = |
16 |
> > psbl.surriel.com, |
17 |
> > bl.spamcop.net, |
18 |
> > zen.spamhaus.org, |
19 |
> > b.barracudacentral.org |
20 |
> > |
21 |
> > postscreen_dnsbl_threshold = 1 |
22 |
> > postscreen_dnsbl_action = enforce |
23 |
> > |
24 |
> > |
25 |
> > ## |
26 |
> > ## Deep protocol tests |
27 |
> > ## |
28 |
> > |
29 |
> > postscreen_pipelining_enable = yes |
30 |
> > postscreen_pipelining_action = enforce |
31 |
> > |
32 |
> > postscreen_non_smtp_command_enable = yes |
33 |
> > postscreen_non_smtp_command_action = enforce |
34 |
> > |
35 |
> > postscreen_bare_newline_enable = yes |
36 |
> > postscreen_bare_newline_action = enforce |
37 |
> |
38 |
> I've looked up each of those parameters and they sound fine to me. |
39 |
> How long have you been running them? Have you been notified of any |
40 |
> mistakenly rejected mail? It's very important my server doesn't miss |
41 |
> any mail, even if it means dealing with more spam. |
42 |
> |
43 |
|
44 |
Similar situation with me. Because my company is in the financial sector, |
45 |
false negatives are much more preferred than false positives. |
46 |
|
47 |
(Although I can always weasel my way out of any problems caused by slight |
48 |
configuration mistakes, I prefer not having to put myself into a situation |
49 |
where weasel-ing is needed :-) |
50 |
|
51 |
Rgds, |