Send Mail Safely with Postfix's sendmail Interface
You will finish with a safe way to submit one test message through Postfix, inspect what is waiting in the mail queue, and rebuild the local alias database when you change it. On this machine the commands come from Postfix 3.8.6-1ubuntu0.1, not from the original Sendmail implementation.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes. You need a shell account and a working Postfix installation. The submission example sends real mail, so replace every placeholder and use a destination you control. Queue inspection is read-only. Editing aliases and rebuilding their database changes local delivery and needs elevated privileges.
1. Confirm which compatibility commands are installed
Start with ordinary, read-only checks. The three names are related interfaces: sendmail submits mail, mailq lists queued mail, and newaliases rebuilds alias databases.
$ command -v sendmail mailq newaliases
/usr/sbin/sendmail
/usr/bin/mailq
/usr/bin/newaliases
$ dpkg-query -W -f='${Package} ${Version}\n' postfix
postfix 3.8.6-1ubuntu0.1
On this installation all three names resolve to the Postfix sendmail compatibility binary. That matters when you compare examples from Sendmail documentation: Postfix accepts a useful subset of the interface, and some recognised Sendmail options are deliberately ignored.
Checkpoint
If the package query or command lookup fails, stop here. Installing or repairing mail software is a separate change that should be planned for this host.
2. Inspect the queue before testing delivery
Run the read-only queue listing. mailq and sendmail -bp select the same mode.
$ mailq
-Queue ID- --Size-- ----Arrival Time---- -Sender/Recipient-------
... queue entries appear here ...
-- 5 Kbytes in 1 Request.
Your output will be host-specific. Each entry includes a queue ID, size, arrival time, sender and recipients still awaiting delivery. A trailing * marks an active item, ! marks a held item, and # marks mail forced to expire. A reason below an entry explains a failed delivery attempt.
Do not treat a non-empty queue as proof that Postfix is broken. A remote DNS failure, a refused connection or a destination server delaying mail can all leave a message queued. Record the queue ID before investigating.
Checkpoint
Verify the listing mode without changing anything:
$ sendmail -bp
$ printf 'status: %s\n' "$?"
status: 0
3. Submit one deliberately addressed test message
Prepare the message as standard headers followed by a blank line and a body. Use -- before the recipient so an address beginning with a hyphen cannot be interpreted as another sendmail option.
$ sendmail -v -- [email protected] <<'EOF'
From: [email protected]
To: [email protected]
Subject: Postfix sendmail test
This is a delivery test from the Postfix sendmail interface.
EOF
Replace both addresses with real values. The -v option requests a report about the first delivery attempt, but mail delivery still happens in the background. A successful command only means Postfix accepted the message for processing. It does not prove that the remote mailbox accepted it.
By default, sendmail reads standard input until end of file or a line containing only a full stop. The here-document above supplies end of file explicitly. The -- is also a security boundary when any recipient value is supplied by another user or program. Do not run Postfix commands as root on behalf of untrusted users without filtering their arguments.
Warning
This step creates a real queued message and may contact a remote mail server. There is no general undo for a message already delivered. If it is still queued, an administrator can identify it with mailq and use the separate Postfix queue-maintenance tools according to local policy.
4. Verify acceptance without assuming delivery
Immediately list the queue again:
$ mailq
-Queue ID- --Size-- ----Arrival Time---- -Sender/Recipient-------
... the test message may appear here ...
A message may disappear quickly if delivery succeeds, or remain while Postfix retries it. If you need a one-off routing check that does not collect or deliver a message, use -bv with a recipient:
$ sendmail -bv -- [email protected]
... a delivery verification report is sent ...
The report checks address rewriting and routing rather than delivering the message. It may itself be sent as email, so inspect the command's standard error and the local mail logs if the result is not clear. A queued message's reason is more useful than repeatedly flushing the queue.
The -q option attempts delivery of all queued mail. Treat it as an operational action, not as a harmless retry button: the manual warns that frequent flushing of undeliverable mail harms delivery performance for other messages. Use it only when you understand the backlog and the cause of the delay.
5. Change aliases with a recoverable plan
Postfix reads the alias databases named by its alias_database setting. Check the current setting before editing anything:
$ postconf -h alias_database default_database_type
hash:/etc/aliases
hash
Here the source file is /etc/aliases and the database type is hash. Save a root-owned backup before making a change:
$ sudo cp -p /etc/aliases /etc/aliases.backup
$ sudoedit /etc/aliases
Add or edit only the alias you intend to change, then rebuild the database:
$ sudo newaliases
$ printf 'status: %s\n' "$?"
status: 0
newaliases runs the Postfix alias-database update using the configured files and database type. It can take about a minute for an update to become visible; the sendmail manual recommends postfix reload when you need to eliminate that delay.
Verify the generated database exists and query the changed key through the configured map:
$ sudo ls -l /etc/aliases /etc/aliases.db
$ postmap -q ALIAS_NAME hash:/etc/aliases
TARGET_VALUE
If the edit was wrong, restore the backup and rebuild it again:
$ sudo cp -p /etc/aliases.backup /etc/aliases
$ sudo newaliases
$ sudo postfix reload
Do not use newaliases as a general queue repair command. It only updates alias databases. Likewise, editing /etc/aliases.db directly is the wrong recovery path because the source file is the durable configuration.
6. Keep the compatibility boundary clear
Common options have Postfix-specific meanings. -f or -r sets the envelope sender for delivery errors. -t adds recipients found in message headers to recipients on the command line. -B 7BIT or -B 8BITMIME describes the body type, but binary or non-ASCII content still needs suitable MIME encoding.
-I and -bi are aliases for the same alias-database initialisation mode as newaliases. -bd starts Postfix, and -bl starts it with loopback-only intent when the configuration sets inet_interfaces = loopback. These are service operations, not routine message-submission flags. Use the postfix service controls and a maintenance plan when changing daemon state.
Postfix writes problems to standard error and to the system mail logs. When a command appears to succeed but delivery does not, check the queue entry and logs before changing configuration. Avoid adding sudo reflexively: queue viewing and submission normally use the invoking user's permissions, while alias and service administration are the cases that need privilege.
Done means
- You confirmed that the installed commands belong to Postfix 3.8.6-1ubuntu0.1.
- You can distinguish message acceptance, queueing and final remote delivery.
- You used
--before a recipient boundary in scripted submission. - You inspected the queue without repeatedly flushing undeliverable mail.
- You backed up
/etc/aliasesbefore rebuilding its configured database. - You know how to restore the alias source and run
newaliasesagain.