{
    "mode": "man",
    "parameter": "postscreen",
    "section": "8postfix",
    "url": "https://www.chedong.com/phpMan.php/man/postscreen/8postfix/json",
    "generated": "2026-10-08T20:36:57Z",
    "synopsis": "postscreen [generic Postfix daemon options]",
    "sections": {
        "NAME": {
            "content": "postscreen - Postfix zombie blocker\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "postscreen [generic Postfix daemon options]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "The Postfix postscreen(8) server provides additional protection against mail server overload.\nOne  postscreen(8)  process  handles  multiple  inbound  SMTP  connections, and decides which\nclients may talk to a Postfix SMTP server process.  By keeping spambots  away,  postscreen(8)\nleaves  more  SMTP server processes available for legitimate clients, and delays the onset of\nserver overload conditions.\n\nThis program should not be used on SMTP ports that receive mail from end-user clients (MUAs).\nIn a typical deployment, postscreen(8) handles the MX service on TCP port  25,  and  smtpd(8)\nreceives  mail  from  MUAs on the submission service (TCP port 587) which requires client au‐\nthentication.  Alternatively, a site could set up  a  dedicated,  non-postscreen,  \"port  25\"\nserver that provides submission service and client authentication, but no MX service.\n\npostscreen(8) maintains a temporary allowlist for clients that have passed a number of tests.\nWhen an SMTP client IP address is allowlisted, postscreen(8) hands off the connection immedi‐\nately to a Postfix SMTP server process. This minimizes the overhead for legitimate mail.\n\nBy  default,  postscreen(8)  logs  statistics and hands off each connection to a Postfix SMTP\nserver process, while excluding clients in mynetworks from all  tests  (primarily,  to  avoid\nproblems  with  non-standard  SMTP implementations in network appliances).  This default mode\nblocks no clients, and is useful for non-destructive testing.\n\nIn a typical production setting, postscreen(8) is configured to reject mail from clients that\nfail one or more tests. postscreen(8) logs rejected  mail  with  the  client  address,  helo,\nsender and recipient information.\n\npostscreen(8)  is  not  an  SMTP proxy; this is intentional.  The purpose is to keep spambots\naway from Postfix SMTP server processes, while minimizing overhead for legitimate traffic.\n",
            "subsections": []
        },
        "SECURITY": {
            "content": "The postscreen(8) server is moderately security-sensitive.  It talks to untrusted clients  on\nthe network. The process can be run chrooted at fixed low privilege.\n",
            "subsections": []
        },
        "STANDARDS": {
            "content": "RFC 821 (SMTP protocol)\nRFC 1123 (Host requirements)\nRFC 1652 (8bit-MIME transport)\nRFC 1869 (SMTP service extensions)\nRFC 1870 (Message Size Declaration)\nRFC 1985 (ETRN command)\nRFC 2034 (SMTP Enhanced Status Codes)\nRFC 2821 (SMTP protocol)\nNot: RFC 2920 (SMTP Pipelining)\nRFC 3030 (CHUNKING without BINARYMIME)\nRFC 3207 (STARTTLS command)\nRFC 3461 (SMTP DSN Extension)\nRFC 3463 (Enhanced Status Codes)\nRFC 5321 (SMTP protocol, including multi-line 220 banners)\n",
            "subsections": []
        },
        "DIAGNOSTICS": {
            "content": "Problems and transactions are logged to syslogd(8) or postlogd(8).\n",
            "subsections": []
        },
        "BUGS": {
            "content": "The postscreen(8) built-in SMTP protocol engine currently does not announce support for AUTH,\nXCLIENT  or  XFORWARD.   If you need to make these services available on port 25, then do not\nenable the optional \"after 220 server greeting\" tests.\n\nThe optional \"after 220 server greeting\" tests may result in unexpected delivery delays  from\nsenders  that  retry email delivery from a different IP address.  Reason: after passing these\ntests a new client must disconnect, and reconnect from the same IP address before it can  de‐\nliver  mail. See POSTSCREENREADME, section \"Tests after the 220 SMTP server greeting\", for a\ndiscussion.\n",
            "subsections": []
        },
        "CONFIGURATION PARAMETERS": {
            "content": "Changes to main.cf are not picked up automatically, as postscreen(8) processes  may  run  for\nseveral hours.  Use the command \"postfix reload\" after a configuration change.\n\nThe  text below provides only a parameter summary. See postconf(5) for more details including\nexamples.\n\nNOTE: Some postscreen(8) parameters implement stress-dependent behavior.  This  is  supported\nonly  when  the  default  parameter  value  is  stress-dependent  (that  is,  it  looks  like\n${stress?{X}:{Y}}, or it is the $name of an smtpd parameter with a stress-dependent default).\nOther parameters always evaluate as if the stress parameter value is the empty string.\n",
            "subsections": []
        },
        "COMPATIBILITY CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "postscreen_command_filter ($smtpd_command_filter)",
                    "content": "A mechanism to transform commands from remote SMTP clients.\n"
                },
                {
                    "name": "postscreen_discard_ehlo_keyword_address_maps ($smtpd_discard_ehlo_keyword_address_maps)",
                    "content": "Lookup tables, indexed by the remote SMTP client address, with case insensitive  lists\nof EHLO keywords (pipelining, starttls, auth, etc.) that the postscreen(8) server will\nnot send in the EHLO response to a remote SMTP client.\n"
                },
                {
                    "name": "postscreen_discard_ehlo_keywords ($smtpd_discard_ehlo_keywords)",
                    "content": "A  case  insensitive list of EHLO keywords (pipelining, starttls, auth, etc.) that the\npostscreen(8) server will not send in the EHLO response to a remote SMTP client.\n\nAvailable in Postfix version 3.1 and later:\n"
                },
                {
                    "name": "dns_ncache_ttl_fix_enable (no)",
                    "content": "Enable a workaround for future libc incompatibility.\n\nAvailable in Postfix version 3.4 and later:\n"
                },
                {
                    "name": "postscreen_reject_footer_maps ($smtpd_reject_footer_maps)",
                    "content": "Optional lookup table for information that is  appended  after  a  4XX  or  5XX  post‐\nscreen(8) server response.\n\nAvailable in Postfix 3.6 and later:\n"
                },
                {
                    "name": "respectful_logging (see 'postconf -d' output)",
                    "content": "Avoid logging that implies white is better than black.\n"
                }
            ]
        },
        "TROUBLE SHOOTING CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "postscreen_expansion_filter (see 'postconf -d' output)",
                    "content": "List  of  characters  that  are permitted in postscreenrejectfooter attribute expan‐\nsions.\n"
                },
                {
                    "name": "postscreen_reject_footer ($smtpd_reject_footer)",
                    "content": "Optional information that is appended after a 4XX  or  5XX  postscreen(8)  server  re‐\nsponse.\n"
                },
                {
                    "name": "soft_bounce (no)",
                    "content": "Safety net to keep mail queued that would otherwise be returned to the sender.\n"
                }
            ]
        },
        "BEFORE-POSTSCREEN PROXY AGENT": {
            "content": "Available in Postfix version 2.10 and later:\n",
            "subsections": [
                {
                    "name": "postscreen_upstream_proxy_protocol (empty)",
                    "content": "The name of the proxy protocol used by an optional before-postscreen proxy agent.\n"
                },
                {
                    "name": "postscreen_upstream_proxy_timeout (5s)",
                    "content": "The   time   limit   for   the   proxy  protocol  specified  with  the  postscreenup‐\nstreamproxyprotocol parameter.\n"
                }
            ]
        },
        "PERMANENT ALLOW/DENYLIST TEST": {
            "content": "This test is executed immediately after a remote SMTP client connects. If a client is  perma‐\nnently  allowlisted,  the  client  will  be  handed  off immediately to a Postfix SMTP server\nprocess.\n",
            "subsections": [
                {
                    "name": "postscreen_access_list (permit_mynetworks)",
                    "content": "Permanent allow/denylist for remote SMTP client IP addresses.\n"
                },
                {
                    "name": "postscreen_blacklist_action (ignore)",
                    "content": "Renamed to postscreendenylistaction in Postfix 3.6.\n"
                }
            ]
        },
        "MAIL EXCHANGER POLICY TESTS": {
            "content": "When postscreen(8) is configured to monitor all primary  and  backup  MX  addresses,  it  can\nrefuse  to  allowlist clients that connect to a backup MX address only. For small sites, this\nrequires configuring primary and backup MX addresses on the same MTA. Larger sites would have\nto share the postscreen(8) cache between primary and backup MTAs,  which  would  introduce  a\ncommon point of failure.\n",
            "subsections": [
                {
                    "name": "postscreen_allowlist_interfaces (static:all)",
                    "content": "A  list of local postscreen(8) server IP addresses where a non-allowlisted remote SMTP\nclient can obtain postscreen(8)'s temporary allowlist status.\n"
                }
            ]
        },
        "BEFORE 220 GREETING TESTS": {
            "content": "These tests are executed before the remote SMTP client receives the \"220  servername\"  greet‐\ning.  If  no  tests  remain after the successful completion of this phase, the client will be\nhanded off immediately to a Postfix SMTP server process.\n",
            "subsections": [
                {
                    "name": "dnsblog_service_name (dnsblog)",
                    "content": "The name of the dnsblog(8) service entry in master.cf.\n"
                },
                {
                    "name": "postscreen_dnsbl_action (ignore)",
                    "content": "The action that postscreen(8) takes when a remote SMTP client's combined  DNSBL  score\nis  equal  to  or greater than a threshold (as defined with the postscreendnsblsites\nand postscreendnsblthreshold parameters).\n"
                },
                {
                    "name": "postscreen_dnsbl_reply_map (empty)",
                    "content": "A mapping from an actual DNSBL domain name which includes a secret  password,  to  the\nDNSBL domain name that postscreen will reply with when it rejects mail.\n"
                },
                {
                    "name": "postscreen_dnsbl_sites (empty)",
                    "content": "Optional list of patterns with DNS allow/denylist domains, filters and weight factors.\n"
                },
                {
                    "name": "postscreen_dnsbl_threshold (1)",
                    "content": "The  inclusive  lower  bound  for blocking a remote SMTP client, based on its combined\nDNSBL score as defined with the postscreendnsblsites parameter.\n"
                },
                {
                    "name": "postscreen_greet_action (ignore)",
                    "content": "The action that postscreen(8) takes when a remote SMTP client speaks before  its  turn\nwithin the time specified with the postscreengreetwait parameter.\n"
                },
                {
                    "name": "postscreen_greet_banner ($smtpd_banner)",
                    "content": "The  text in the optional \"220-text...\" server response that postscreen(8) sends ahead\nof the real Postfix SMTP server's \"220 text...\" response, in an attempt to confuse bad\nSMTP clients so that they speak before their turn (pre-greet).\n"
                },
                {
                    "name": "postscreen_greet_wait (normal: 6s, overload: 2s)",
                    "content": "The amount of time that postscreen(8) will wait for an SMTP client to send  a  command\nbefore its turn, and for DNS blocklist lookup results to arrive (default: up to 2 sec‐\nonds under stress, up to 6 seconds otherwise).\n"
                },
                {
                    "name": "smtpd_service_name (smtpd)",
                    "content": "The internal service that postscreen(8) hands off allowed connections to.\n\nAvailable in Postfix version 2.11 and later:\n"
                },
                {
                    "name": "postscreen_dnsbl_whitelist_threshold (0)",
                    "content": "Renamed to postscreendnsblallowlistthreshold in Postfix 3.6.\n\nAvailable in Postfix version 3.0 and later:\n"
                },
                {
                    "name": "postscreen_dnsbl_timeout (10s)",
                    "content": "The time limit for DNSBL or DNSWL lookups.\n\nAvailable in Postfix version 3.6 and later:\n"
                },
                {
                    "name": "postscreen_denylist_action (ignore)",
                    "content": "The  action  that  postscreen(8)  takes  when  a  remote  SMTP  client  is permanently\ndenylisted with the postscreenaccesslist parameter.\n"
                },
                {
                    "name": "postscreen_allowlist_interfaces (static:all)",
                    "content": "A list of local postscreen(8) server IP addresses where a non-allowlisted remote  SMTP\nclient can obtain postscreen(8)'s temporary allowlist status.\n"
                },
                {
                    "name": "postscreen_dnsbl_allowlist_threshold (0)",
                    "content": "Allow  a  remote SMTP client to skip \"before\" and \"after 220 greeting\" protocol tests,\nbased on its combined DNSBL score as defined with the  postscreendnsblsites  parame‐\nter.\n"
                }
            ]
        },
        "AFTER 220 GREETING TESTS": {
            "content": "These tests are executed after the remote SMTP client receives the \"220 servername\" greeting.\nIf a client passes all tests during this phase, it will receive a 4XX response to all RCPT TO\ncommands.  After the client reconnects, it will be allowed to talk directly to a Postfix SMTP\nserver process.\n",
            "subsections": [
                {
                    "name": "postscreen_bare_newline_action (ignore)",
                    "content": "The action that postscreen(8) takes when a remote SMTP client  sends  a  bare  newline\ncharacter, that is, a newline not preceded by carriage return.\n"
                },
                {
                    "name": "postscreen_bare_newline_enable (no)",
                    "content": "Enable \"bare newline\" SMTP protocol tests in the postscreen(8) server.\n"
                },
                {
                    "name": "postscreen_disable_vrfy_command ($disable_vrfy_command)",
                    "content": "Disable the SMTP VRFY command in the postscreen(8) daemon.\n"
                },
                {
                    "name": "postscreen_forbidden_commands ($smtpd_forbidden_commands)",
                    "content": "List of commands that the postscreen(8) server considers in violation of the SMTP pro‐\ntocol.\n"
                },
                {
                    "name": "postscreen_helo_required ($smtpd_helo_required)",
                    "content": "Require that a remote SMTP client sends HELO or EHLO before commencing a MAIL transac‐\ntion.\n"
                },
                {
                    "name": "postscreen_non_smtp_command_action (drop)",
                    "content": "The  action that postscreen(8) takes when a remote SMTP client sends non-SMTP commands\nas specified with the postscreenforbiddencommands parameter.\n"
                },
                {
                    "name": "postscreen_non_smtp_command_enable (no)",
                    "content": "Enable \"non-SMTP command\" tests in the postscreen(8) server.\n"
                },
                {
                    "name": "postscreen_pipelining_action (enforce)",
                    "content": "The action that postscreen(8) takes when a remote SMTP client sends multiple  commands\ninstead of sending one command and waiting for the server to respond.\n"
                },
                {
                    "name": "postscreen_pipelining_enable (no)",
                    "content": "Enable \"pipelining\" SMTP protocol tests in the postscreen(8) server.\n"
                }
            ]
        },
        "CACHE CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "postscreen_cache_cleanup_interval (12h)",
                    "content": "The amount of time between postscreen(8) cache cleanup runs.\n"
                },
                {
                    "name": "postscreen_cache_map (btree:$data_directory/postscreen_cache)",
                    "content": "Persistent storage for the postscreen(8) server decisions.\n"
                },
                {
                    "name": "postscreen_cache_retention_time (7d)",
                    "content": "The  amount of time that postscreen(8) will cache an expired temporary allowlist entry\nbefore it is removed.\n"
                },
                {
                    "name": "postscreen_bare_newline_ttl (30d)",
                    "content": "The amount of time that postscreen(8) will use the result from a successful \"bare new‐\nline\" SMTP protocol test.\n"
                },
                {
                    "name": "postscreen_dnsbl_max_ttl (${postscreen_dnsbl_ttl?{$postscreen_dnsbl_ttl}:{1}}h)",
                    "content": "The maximum amount of time that postscreen(8) will use the result  from  a  successful\nDNS-based  reputation  test  before  a client IP address is required to pass that test\nagain.\n"
                },
                {
                    "name": "postscreen_dnsbl_min_ttl (60s)",
                    "content": "The minimum amount of time that postscreen(8) will use the result  from  a  successful\nDNS-based  reputation  test  before  a client IP address is required to pass that test\nagain.\n"
                },
                {
                    "name": "postscreen_greet_ttl (1d)",
                    "content": "The amount of time that postscreen(8) will use the result from a  successful  PREGREET\ntest.\n"
                },
                {
                    "name": "postscreen_non_smtp_command_ttl (30d)",
                    "content": "The  amount  of  time  that  postscreen(8)  will  use  the  result  from  a successful\n\"nonsmtpcommand\" SMTP protocol test.\n"
                },
                {
                    "name": "postscreen_pipelining_ttl (30d)",
                    "content": "The amount of time that postscreen(8) will use the result from a successful  \"pipelin‐\ning\" SMTP protocol test.\n"
                }
            ]
        },
        "RESOURCE CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "line_length_limit (2048)",
                    "content": "Upon  input, long lines are chopped up into pieces of at most this length; upon deliv‐\nery, long lines are reconstructed.\n"
                },
                {
                    "name": "postscreen_client_connection_count_limit ($smtpd_client_connection_count_limit)",
                    "content": "How many simultaneous connections any remote SMTP client is allowed to have  with  the\npostscreen(8) daemon.\n"
                },
                {
                    "name": "postscreen_command_count_limit (20)",
                    "content": "The  limit  on  the  total  number  of  commands  per SMTP session for postscreen(8)'s\nbuilt-in SMTP protocol engine.\n"
                },
                {
                    "name": "postscreen_command_time_limit (normal: 300s, overload: 10s)",
                    "content": "The time limit to read an entire command line with postscreen(8)'s built-in SMTP  pro‐\ntocol engine.\n"
                },
                {
                    "name": "postscreen_post_queue_limit ($default_process_limit)",
                    "content": "The  number of clients that can be waiting for service from a real Postfix SMTP server\nprocess.\n"
                },
                {
                    "name": "postscreen_pre_queue_limit ($default_process_limit)",
                    "content": "The number of non-allowlisted clients that can be waiting for a decision whether  they\nwill receive service from a real Postfix SMTP server process.\n"
                },
                {
                    "name": "postscreen_watchdog_timeout (10s)",
                    "content": "How much time a postscreen(8) process may take to respond to a remote SMTP client com‐\nmand  or  to  perform a cache operation before it is terminated by a built-in watchdog\ntimer.\n"
                }
            ]
        },
        "STARTTLS CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "postscreen_tls_security_level ($smtpd_tls_security_level)",
                    "content": "The SMTP TLS security level for the postscreen(8) server; when a  non-empty  value  is\nspecified,  this  overrides  the  obsolete  parameters  postscreenusetls  and  post‐\nscreenenforcetls.\n"
                },
                {
                    "name": "tlsproxy_service_name (tlsproxy)",
                    "content": "The name of the tlsproxy(8) service entry in master.cf.\n"
                }
            ]
        },
        "OBSOLETE STARTTLS SUPPORT CONTROLS": {
            "content": "These parameters are supported for compatibility with smtpd(8) legacy parameters.\n",
            "subsections": [
                {
                    "name": "postscreen_use_tls ($smtpd_use_tls)",
                    "content": "Opportunistic TLS: announce STARTTLS support to remote SMTP clients, but  do  not  re‐\nquire that clients use TLS encryption.\n"
                },
                {
                    "name": "postscreen_enforce_tls ($smtpd_enforce_tls)",
                    "content": "Mandatory  TLS:  announce  STARTTLS  support  to remote SMTP clients, and require that\nclients use TLS encryption.\n"
                }
            ]
        },
        "MISCELLANEOUS CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "config_directory (see 'postconf -d' output)",
                    "content": "The default location of the Postfix main.cf and master.cf configuration files.\n"
                },
                {
                    "name": "delay_logging_resolution_limit (2)",
                    "content": "The maximal number of digits after the decimal point  when  logging  sub-second  delay\nvalues.\n"
                },
                {
                    "name": "command_directory (see 'postconf -d' output)",
                    "content": "The location of all postfix administrative commands.\n"
                },
                {
                    "name": "max_idle (100s)",
                    "content": "The  maximum  amount of time that an idle Postfix daemon process waits for an incoming\nconnection before terminating voluntarily.\n"
                },
                {
                    "name": "process_id (read-only)",
                    "content": "The process ID of a Postfix command or daemon process.\n"
                },
                {
                    "name": "process_name (read-only)",
                    "content": "The process name of a Postfix command or daemon process.\n"
                },
                {
                    "name": "syslog_facility (mail)",
                    "content": "The syslog facility of Postfix logging.\n"
                },
                {
                    "name": "syslog_name (see 'postconf -d' output)",
                    "content": "A prefix that is prepended to the process name in syslog records, so that,  for  exam‐\nple, \"smtpd\" becomes \"prefix/smtpd\".\n\nAvailable in Postfix 3.3 and later:\n"
                },
                {
                    "name": "service_name (read-only)",
                    "content": "The master.cf service name of a Postfix daemon process.\n\nAvailable in Postfix 3.5 and later:\n"
                },
                {
                    "name": "info_log_address_format (external)",
                    "content": "The email address form that will be used in non-debug logging (info, warning, etc.).\n"
                }
            ]
        },
        "SEE ALSO": {
            "content": "smtpd(8), Postfix SMTP server\ntlsproxy(8), Postfix TLS proxy server\ndnsblog(8), DNS allow/denylist logger\npostlogd(8), Postfix logging\nsyslogd(8), system logging\n",
            "subsections": []
        },
        "README FILES": {
            "content": "Use \"postconf readmedirectory\" or \"postconf htmldirectory\" to locate this information.\nPOSTSCREENREADME, Postfix Postscreen Howto\n",
            "subsections": []
        },
        "LICENSE": {
            "content": "The Secure Mailer license must be distributed with this software.\n",
            "subsections": []
        },
        "HISTORY": {
            "content": "This service was introduced with Postfix version 2.8.\n\nMany  ideas  in  postscreen(8)  were  explored in earlier work by Michael Tokarev, in OpenBSD\nspamd, and in MailChannels Traffic Control.\n\nAUTHOR(S)\nWietse Venema\nIBM T.J. Watson Research\nP.O. Box 704\nYorktown Heights, NY 10598, USA\n\nWietse Venema\nGoogle, Inc.\n111 8th Avenue\nNew York, NY 10011, USA\n\nPOSTSCREEN(8postfix)",
            "subsections": []
        }
    },
    "summary": "postscreen - Postfix zombie blocker",
    "flags": [],
    "examples": [],
    "see_also": [
        {
            "name": "smtpd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/smtpd/8/json"
        },
        {
            "name": "tlsproxy",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/tlsproxy/8/json"
        },
        {
            "name": "dnsblog",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/dnsblog/8/json"
        },
        {
            "name": "postlogd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/postlogd/8/json"
        },
        {
            "name": "syslogd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/syslogd/8/json"
        }
    ]
}