Home / Alt manpages / smtpd(8postfix)

  • smtpd(8postfix)
  • Postfix admin command
  • linux

Audit Postfix smtpd Before You Change SMTP Policy

You will inspect the Postfix SMTP service, check the settings that control TLS and relay access, and make a harmless connection test before deciding whether a configuration change is needed. The examples match Postfix 3.8.6 installed on this machine. Allow about fifteen minutes, plus time to read your own policy values carefully.

You need a shell account on a host running Postfix. Reading configuration is unprivileged. Reloading the service and reading some logs may require sudo or root access. This guide does not open a relay, disable TLS, or edit a live mail system.

1. Confirm the installed smtpd version

smtpd is normally started by Postfix's master process, rather than launched directly. Each connection is handled as an SMTP transaction and the received message is passed through cleanup into the incoming queue. Check the version and the command locations first:

$ postconf -h mail_version
3.8.6
$ command -v postconf
/usr/sbin/postconf
$ command -v sendmail
/usr/sbin/sendmail

The exact version matters. For example, the installed manual documents smtpd_per_request_deadline and smtpd_min_data_rate as Postfix 3.7 features, while the newer bare-newline controls are documented for later 3.x maintenance releases. Do not copy a setting from a different host without checking its version and defaults.

2. Inspect how the SMTP service is enabled

Ask postconf for the service definition. This is read-only and shows whether the listener is provided by master.cf, along with service-specific overrides:

$ postconf -M smtp/inet
smtp       inet  n       -       y       -       -       smtpd

Your line may include -o overrides after smtpd. Those values apply to this service and can differ from main.cf. That is a common source of false conclusions: inspecting only main.cf can hide the policy actually used by the network listener.

Checkpoint: save the output of postconf -M smtp/inet in your change notes before editing anything. If the service is disabled, absent or bound to a different transport, stop here and identify the intended listener first.

3. Read the effective policy, not just the defaults

Use postconf -n for settings explicitly present in the active configuration. Then query defaults with postconf -d when you need to understand an omitted value:

$ postconf -n smtpd_banner smtpd_helo_required smtpd_tls_security_level smtpd_tls_auth_only
smtpd_banner = $myhostname ESMTP $mail_name
smtpd_helo_required = no
smtpd_tls_security_level =
smtpd_tls_auth_only = no
$ postconf -d smtpd_relay_restrictions smtpd_recipient_restrictions
smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, defer_unauth_destination
smtpd_recipient_restrictions =

Output is host-specific, so treat the values above as examples of the command's shape, not as a recommended configuration. The empty default for smtpd_tls_security_level does not mean that TLS is impossible; it means the service has not selected a TLS security level through that parameter. Certificate paths, service overrides and the SMTP greeting must be considered together.

For relay safety, start with smtpd_relay_restrictions. The documented default permits clients in mynetworks and authenticated clients, then defers unauthorised destinations. smtpd_recipient_restrictions performs recipient policy after relay control. Never test an unfamiliar server by attempting delivery to a third party: confirm the restrictions on paper first.

4. Check TLS and authentication boundaries

Read the settings that determine whether clients can authenticate and whether authentication is allowed before TLS:

$ postconf smtpd_sasl_auth_enable smtpd_sasl_type smtpd_sasl_path smtpd_tls_security_level smtpd_tls_auth_only
smtpd_sasl_auth_enable = yes
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_tls_security_level = may
smtpd_tls_auth_only = yes

The smtpd_tls_auth_only = yes boundary is worth checking explicitly: the server should not offer SMTP AUTH to a client that has not negotiated TLS. The manpage also distinguishes opportunistic TLS, selected with may, from mandatory TLS settings. Do not change a certificate path or TLS mode during an incident without a tested certificate, a maintenance window and a rollback copy of the configuration.

Review the trust list as well:

$ postconf mynetworks
mynetworks = 127.0.0.0/8 [::1]/128 ...

Every network listed there receives the privileges attached to permit_mynetworks. A broad container, VPN or cloud subnet can therefore become a relay boundary. Replace the shortened display above with the complete output when auditing your host.

5. Probe the listener without sending mail

First identify the address and port from inet_interfaces, inet_protocols and master.cf. A plain SMTP connection to port 25 can read the greeting and quit without creating a message:

$ printf 'QUIT\r\n' | nc -w 5 127.0.0.1 25
220 mail.example.test ESMTP Postfix
221 2.0.0 Bye

Use the actual local address only. The greeting should match the intended smtpd_banner policy; it may expose the hostname and mail system name. The command sends no MAIL FROM or RCPT TO, so it does not queue a message. If the connection is refused, check that the service is enabled and listening before changing SMTP policy.

For an implicit TLS service such as one configured with wrapper mode, a plain probe is the wrong test. Use the service's documented transport and port. STARTTLS is negotiated inside SMTP and should not be confused with the separate TLS wrapper mode described by smtpd_tls_wrappermode.

6. Validate before a reload

Before any edit, copy the relevant files to a root-readable backup location and record the current values. Editing main.cf or master.cf is service-affecting, so pause and confirm the exact change:

$ sudo cp --preserve=mode,ownership,timestamps /etc/postfix/main.cf /etc/postfix/main.cf.before-smtpd-change
$ sudo postfix check
$ sudo postfix reload

postfix check validates the installation and permissions; postfix reload asks the master process to reread configuration. Do not run the reload merely to make a read-only audit feel complete. If validation fails, do not reload. If the reload causes trouble, restore the backup and run the check again:

$ sudo cp --preserve=mode,ownership,timestamps /etc/postfix/main.cf.before-smtpd-change /etc/postfix/main.cf
$ sudo postfix check
$ sudo postfix reload

The backup and restore commands change system state and require elevated privileges. Keep the backup until the new SMTP greeting, TLS negotiation and relay behaviour have been checked.

7. Diagnose a surprising result

  • If the greeting is unexpected, compare postconf smtpd_banner myhostname mail_name with service-level -o overrides in postconf -M smtp/inet.
  • If AUTH is missing, check smtpd_sasl_auth_enable, smtpd_tls_auth_only, the SASL type and socket path, then inspect the Postfix and SASL logs. An empty smtpd_sasl_exceptions_networks does not by itself enable authentication.
  • If a recipient is rejected, distinguish relay policy from recipient policy. defer_unauth_destination is deliberately not the same as permitting arbitrary destinations.
  • If a client disconnects after malformed input, remember that error counters, smtpd_soft_error_limit, smtpd_hard_error_limit and command restrictions can terminate or delay a session.
  • If configuration appears correct but the service behaves differently, inspect the active listener and recent logs. The smtpd manual says protocol problems and transactions are logged through syslog or postlogd, depending on the installation.

Done means

  • The installed Postfix version and active smtp/inet service definition are recorded.
  • Effective relay, recipient, TLS, AUTH and mynetworks values were read with postconf.
  • A local SMTP greeting was checked with a connect-and-quit probe that sent no message.
  • Any configuration edit was validated with postfix check before a reload.
  • A recoverable backup exists, and the listener was tested again after a change.