{
    "mode": "man",
    "parameter": "smtpd",
    "section": "8postfix",
    "url": "https://www.chedong.com/phpMan.php/man/smtpd/8postfix/json",
    "generated": "2026-10-09T16:50:16Z",
    "synopsis": "smtpd [generic Postfix daemon options]",
    "sections": {
        "NAME": {
            "content": "smtpd - Postfix SMTP server\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "smtpd [generic Postfix daemon options]\n",
            "subsections": [
                {
                    "name": "sendmail -bs",
                    "content": ""
                }
            ]
        },
        "DESCRIPTION": {
            "content": "The  SMTP  server accepts network connection requests and performs zero or more SMTP transac‐\ntions per connection.  Each received message is piped through the cleanup(8) daemon,  and  is\nplaced  into  the  incoming  queue as one single queue file.  For this mode of operation, the\nprogram expects to be run from the master(8) process manager.\n\nAlternatively, the SMTP server be can run in stand-alone mode; this is traditionally obtained\nwith \"sendmail -bs\".  When the SMTP server runs stand-alone with non $mailowner  privileges,\nit  receives  mail even while the mail system is not running, deposits messages directly into\nthe maildrop queue, and disables the SMTP server's access policies.  As  of  Postfix  version\n2.3,  the  SMTP  server  refuses  to  receive  mail  from  the  network when it runs with non\n$mailowner privileges.\n\nThe SMTP server implements a variety of policies for connection requests, and for  parameters\ngiven to HELO, ETRN, MAIL FROM, VRFY and RCPT TO commands. They are detailed below and in the\nmain.cf configuration file.\n",
            "subsections": []
        },
        "SECURITY": {
            "content": "The SMTP server is moderately security-sensitive. It talks to SMTP clients and to DNS servers\non the network. The SMTP server can be run chrooted at fixed low privilege.\n",
            "subsections": []
        },
        "STANDARDS": {
            "content": "RFC 821 (SMTP protocol)\nRFC 1123 (Host requirements)\nRFC 1652 (8bit-MIME transport)\nRFC 1869 (SMTP service extensions)\nRFC 1870 (Message size declaration)\nRFC 1985 (ETRN command)\nRFC 2034 (SMTP enhanced status codes)\nRFC 2554 (AUTH command)\nRFC 2821 (SMTP protocol)\nRFC 2920 (SMTP pipelining)\nRFC 3030 (CHUNKING without BINARYMIME)\nRFC 3207 (STARTTLS command)\nRFC 3461 (SMTP DSN extension)\nRFC 3463 (Enhanced status codes)\nRFC 3848 (ESMTP transmission types)\nRFC 4409 (Message submission)\nRFC 4954 (AUTH command)\nRFC 5321 (SMTP protocol)\nRFC 6531 (Internationalized SMTP)\nRFC 6533 (Internationalized Delivery Status Notifications)\nRFC 7505 (\"Null MX\" No Service Resource Record)\n",
            "subsections": []
        },
        "DIAGNOSTICS": {
            "content": "Problems and transactions are logged to syslogd(8) or postlogd(8).\n\nDepending  on  the  setting  of  the  notifyclasses parameter, the postmaster is notified of\nbounces, protocol problems, policy violations, and of other trouble.\n",
            "subsections": []
        },
        "CONFIGURATION PARAMETERS": {
            "content": "Changes to main.cf are picked up automatically, as smtpd(8) processes run for only a  limited\namount of time. Use the command \"postfix reload\" to speed up a change.\n\nThe  text below provides only a parameter summary. See postconf(5) for more details including\nexamples.\n",
            "subsections": []
        },
        "COMPATIBILITY CONTROLS": {
            "content": "The following parameters work around implementation errors in other  software,  and/or  allow\nyou to override standards in order to prevent undesirable use.\n",
            "subsections": [
                {
                    "name": "broken_sasl_auth_clients (no)",
                    "content": "Enable interoperability with remote SMTP clients that implement an obsolete version of\nthe AUTH command (RFC 4954).\n"
                },
                {
                    "name": "disable_vrfy_command (no)",
                    "content": "Disable the SMTP VRFY command.\n"
                },
                {
                    "name": "smtpd_noop_commands (empty)",
                    "content": "List  of commands that the Postfix SMTP server replies to with \"250 Ok\", without doing\nany syntax checks and without changing state.\n"
                },
                {
                    "name": "strict_rfc821_envelopes (no)",
                    "content": "Require that addresses received in SMTP MAIL FROM and RCPT TO  commands  are  enclosed\nwith <>, and that those addresses do not contain RFC 822 style comments or phrases.\n\nAvailable in Postfix version 2.1 and later:\n"
                },
                {
                    "name": "smtpd_reject_unlisted_sender (no)",
                    "content": "Request  that the Postfix SMTP server rejects mail from unknown sender addresses, even\nwhen no explicit rejectunlistedsender access restriction is specified.\n"
                },
                {
                    "name": "smtpd_sasl_exceptions_networks (empty)",
                    "content": "What remote SMTP clients the Postfix SMTP server will not offer AUTH support to.\n\nAvailable in Postfix version 2.2 and later:\n"
                },
                {
                    "name": "smtpd_discard_ehlo_keyword_address_maps (empty)",
                    "content": "Lookup tables, indexed by the remote SMTP client address, with case insensitive  lists\nof  EHLO keywords (pipelining, starttls, auth, etc.) that the Postfix SMTP server will\nnot send in the EHLO response to a remote SMTP client.\n"
                },
                {
                    "name": "smtpd_discard_ehlo_keywords (empty)",
                    "content": "A case insensitive list of EHLO keywords (pipelining, starttls, auth, etc.)  that  the\nPostfix SMTP server will not send in the EHLO response to a remote SMTP client.\n"
                },
                {
                    "name": "smtpd_delay_open_until_valid_rcpt (yes)",
                    "content": "Postpone  the  start  of an SMTP mail transaction until a valid RCPT TO command is re‐\nceived.\n\nAvailable in Postfix version 2.3 and later:\n"
                },
                {
                    "name": "smtpd_tls_always_issue_session_ids (yes)",
                    "content": "Force the Postfix SMTP server to issue a TLS session id, even when TLS session caching\nis turned off (smtpdtlssessioncachedatabase is empty).\n\nAvailable in Postfix version 2.6 and later:\n"
                },
                {
                    "name": "tcp_windowsize (0)",
                    "content": "An optional workaround for routers that break TCP window scaling.\n\nAvailable in Postfix version 2.7 and later:\n"
                },
                {
                    "name": "smtpd_command_filter (empty)",
                    "content": "A mechanism to transform commands from remote SMTP clients.\n\nAvailable in Postfix version 2.9 - 3.6:\n"
                },
                {
                    "name": "smtpd_per_record_deadline (normal: no, overload: yes)",
                    "content": "Change the behavior of the smtpdtimeout and smtpdstarttlstimeout time limits,  from\na  time limit per read or write system call, to a time limit to send or receive a com‐\nplete record (an SMTP command line, SMTP response line, SMTP message content line,  or\nTLS protocol message).\n\nAvailable in Postfix version 3.0 and later:\n"
                },
                {
                    "name": "smtpd_dns_reply_filter (empty)",
                    "content": "Optional filter for Postfix SMTP server DNS lookup results.\n\nAvailable in Postfix 3.5 and later:\n"
                },
                {
                    "name": "info_log_address_format (external)",
                    "content": "The email address form that will be used in non-debug logging (info, warning, etc.).\n\nAvailable in Postfix version 3.6 and later:\n"
                },
                {
                    "name": "smtpd_relay_before_recipient_restrictions (see 'postconf -d' output)",
                    "content": "Evaluate smtpdrelayrestrictions before smtpdrecipientrestrictions.\n"
                },
                {
                    "name": "known_tcp_ports (lmtp=24, smtp=25, smtps=submissions=465, submission=587)",
                    "content": "Optional setting that avoids lookups in the services(5) database.\n\nAvailable in Postfix version 3.7 and later:\n"
                },
                {
                    "name": "smtpd_per_request_deadline (normal: no, overload: yes)",
                    "content": "Change  the behavior of the smtpdtimeout and smtpdstarttlstimeout time limits, from\na time limit per plaintext or TLS read or write call, to a combined time limit for re‐\nceiving a complete SMTP request and for sending a complete SMTP response.\n"
                },
                {
                    "name": "smtpd_min_data_rate (500)",
                    "content": "The minimum plaintext data transfer rate in bytes/second for DATA and  BDAT  requests,\nwhen deadlines are enabled with smtpdperrequestdeadline.\n"
                }
            ]
        },
        "ADDRESS REWRITING CONTROLS": {
            "content": "See  the  ADDRESSREWRITINGREADME  document  for  a  detailed  discussion of Postfix address\nrewriting.\n",
            "subsections": [
                {
                    "name": "receive_override_options (empty)",
                    "content": "Enable or disable recipient validation, built-in content filtering,  or  address  map‐\nping.\n\nAvailable in Postfix version 2.2 and later:\n"
                },
                {
                    "name": "local_header_rewrite_clients (permit_inet_interfaces)",
                    "content": "Rewrite  or  add  message  headers in mail from these clients, updating incomplete ad‐\ndresses with the domain name in $myorigin or $mydomain, and adding missing headers.\n"
                }
            ]
        },
        "BEFORE-SMTPD PROXY AGENT": {
            "content": "Available in Postfix version 2.10 and later:\n",
            "subsections": [
                {
                    "name": "smtpd_upstream_proxy_protocol (empty)",
                    "content": "The name of the proxy protocol used by an optional before-smtpd proxy agent.\n"
                },
                {
                    "name": "smtpd_upstream_proxy_timeout (5s)",
                    "content": "The time limit for the proxy protocol specified with the smtpdupstreamproxyprotocol\nparameter.\n"
                }
            ]
        },
        "AFTER QUEUE EXTERNAL CONTENT INSPECTION CONTROLS": {
            "content": "As of version 1.0, Postfix can be configured to send new mail to an external  content  filter\nAFTER the mail is queued. This content filter is expected to inject mail back into a (Postfix\nor other) MTA for further delivery. See the FILTERREADME document for details.\n",
            "subsections": [
                {
                    "name": "content_filter (empty)",
                    "content": "After the message is queued, send the entire message to the specified transport:desti‐\nnation.\n"
                }
            ]
        },
        "BEFORE QUEUE EXTERNAL CONTENT INSPECTION CONTROLS": {
            "content": "As  of  version  2.1,  the  Postfix  SMTP server can be configured to send incoming mail to a\nreal-time SMTP-based content filter BEFORE mail is queued.  This content filter  is  expected\nto  inject mail back into Postfix.  See the SMTPDPROXYREADME document for details on how to\nconfigure and operate this feature.\n",
            "subsections": [
                {
                    "name": "smtpd_proxy_filter (empty)",
                    "content": "The hostname and TCP port of the mail filtering proxy server.\n"
                },
                {
                    "name": "smtpd_proxy_ehlo ($myhostname)",
                    "content": "How the Postfix SMTP server announces itself to the proxy filter.\n"
                },
                {
                    "name": "smtpd_proxy_options (empty)",
                    "content": "List of options that control how the Postfix  SMTP  server  communicates  with  a  be‐\nfore-queue content filter.\n"
                },
                {
                    "name": "smtpd_proxy_timeout (100s)",
                    "content": "The  time limit for connecting to a proxy filter and for sending or receiving informa‐\ntion.\n"
                }
            ]
        },
        "BEFORE QUEUE MILTER CONTROLS": {
            "content": "As of version 2.3, Postfix supports the Sendmail version 8  Milter  (mail  filter)  protocol.\nThese  content  filters run outside Postfix. They can inspect the SMTP command stream and the\nmessage content, and can request modifications before mail is queued.  For  details  see  the\nMILTERREADME document.\n",
            "subsections": [
                {
                    "name": "smtpd_milters (empty)",
                    "content": "A  list of Milter (mail filter) applications for new mail that arrives via the Postfix\nsmtpd(8) server.\n"
                },
                {
                    "name": "milter_protocol (6)",
                    "content": "The mail filter protocol version and optional protocol  extensions  for  communication\nwith a Milter application; prior to Postfix 2.6 the default protocol is 2.\n"
                },
                {
                    "name": "milter_default_action (tempfail)",
                    "content": "The  default  action when a Milter (mail filter) response is unavailable (for example,\nbad Postfix configuration or Milter failure).\n"
                },
                {
                    "name": "milter_macro_daemon_name ($myhostname)",
                    "content": "The {daemonname} macro value for Milter (mail filter) applications.\n"
                },
                {
                    "name": "milter_macro_v ($mail_name $mail_version)",
                    "content": "The {v} macro value for Milter (mail filter) applications.\n"
                },
                {
                    "name": "milter_connect_timeout (30s)",
                    "content": "The time limit for connecting to a Milter (mail filter) application, and for negotiat‐\ning protocol options.\n"
                },
                {
                    "name": "milter_command_timeout (30s)",
                    "content": "The time limit for sending an SMTP command to a Milter (mail filter) application,  and\nfor receiving the response.\n"
                },
                {
                    "name": "milter_content_timeout (300s)",
                    "content": "The  time limit for sending message content to a Milter (mail filter) application, and\nfor receiving the response.\n"
                },
                {
                    "name": "milter_connect_macros (see 'postconf -d' output)",
                    "content": "The macros that are sent to Milter (mail filter) applications after completion  of  an\nSMTP connection.\n"
                },
                {
                    "name": "milter_helo_macros (see 'postconf -d' output)",
                    "content": "The  macros  that are sent to Milter (mail filter) applications after the SMTP HELO or\nEHLO command.\n"
                },
                {
                    "name": "milter_mail_macros (see 'postconf -d' output)",
                    "content": "The macros that are sent to Milter (mail filter) applications after the SMTP MAIL FROM\ncommand.\n"
                },
                {
                    "name": "milter_rcpt_macros (see 'postconf -d' output)",
                    "content": "The macros that are sent to Milter (mail filter) applications after the SMTP  RCPT  TO\ncommand.\n"
                },
                {
                    "name": "milter_data_macros (see 'postconf -d' output)",
                    "content": "The  macros that are sent to version 4 or higher Milter (mail filter) applications af‐\nter the SMTP DATA command.\n"
                },
                {
                    "name": "milter_unknown_command_macros (see 'postconf -d' output)",
                    "content": "The macros that are sent to version 3 or higher Milter (mail filter) applications  af‐\nter an unknown SMTP command.\n"
                },
                {
                    "name": "milter_end_of_header_macros (see 'postconf -d' output)",
                    "content": "The  macros  that  are  sent to Milter (mail filter) applications after the end of the\nmessage header.\n"
                },
                {
                    "name": "milter_end_of_data_macros (see 'postconf -d' output)",
                    "content": "The macros that are sent to  Milter  (mail  filter)  applications  after  the  message\nend-of-data.\n\nAvailable in Postfix version 3.1 and later:\n"
                },
                {
                    "name": "milter_macro_defaults (empty)",
                    "content": "Optional  list  of  name=value  pairs that specify default values for arbitrary macros\nthat Postfix may send to Milter applications.\n\nAvailable in Postfix version 3.2 and later:\n"
                },
                {
                    "name": "smtpd_milter_maps (empty)",
                    "content": "Lookup tables with Milter settings per remote SMTP client IP address.\n"
                }
            ]
        },
        "GENERAL CONTENT INSPECTION CONTROLS": {
            "content": "The following parameters are applicable for both built-in and external content filters.\n\nAvailable in Postfix version 2.1 and later:\n",
            "subsections": [
                {
                    "name": "receive_override_options (empty)",
                    "content": "Enable or disable recipient validation, built-in content filtering,  or  address  map‐\nping.\n"
                }
            ]
        },
        "EXTERNAL CONTENT INSPECTION CONTROLS": {
            "content": "The following parameters are applicable for both before-queue and after-queue content filter‐\ning.\n\nAvailable in Postfix version 2.1 and later:\n",
            "subsections": [
                {
                    "name": "smtpd_authorized_xforward_hosts (empty)",
                    "content": "What remote SMTP clients are allowed to use the XFORWARD feature.\n"
                }
            ]
        },
        "SASL AUTHENTICATION CONTROLS": {
            "content": "Postfix  SASL support (RFC 4954) can be used to authenticate remote SMTP clients to the Post‐\nfix SMTP server, and to authenticate the Postfix SMTP client to a remote  SMTP  server.   See\nthe SASLREADME document for details.\n",
            "subsections": [
                {
                    "name": "broken_sasl_auth_clients (no)",
                    "content": "Enable interoperability with remote SMTP clients that implement an obsolete version of\nthe AUTH command (RFC 4954).\n"
                },
                {
                    "name": "smtpd_sasl_auth_enable (no)",
                    "content": "Enable SASL authentication in the Postfix SMTP server.\n"
                },
                {
                    "name": "smtpd_sasl_local_domain (empty)",
                    "content": "The name of the Postfix SMTP server's local SASL authentication realm.\n"
                },
                {
                    "name": "smtpd_sasl_security_options (noanonymous)",
                    "content": "Postfix  SMTP  server  SASL  security options; as of Postfix 2.3 the list of available\nfeatures  depends  on  the  SASL  server  implementation   that   is   selected   with\nsmtpdsasltype.\n"
                },
                {
                    "name": "smtpd_sender_login_maps (empty)",
                    "content": "Optional  lookup  table  with the SASL login names that own the sender (MAIL FROM) ad‐\ndresses.\n\nAvailable in Postfix version 2.1 and later:\n"
                },
                {
                    "name": "smtpd_sasl_exceptions_networks (empty)",
                    "content": "What remote SMTP clients the Postfix SMTP server will not offer AUTH support to.\n\nAvailable in Postfix version 2.1 and 2.2:\n"
                },
                {
                    "name": "smtpd_sasl_application_name (smtpd)",
                    "content": "The application name that the Postfix SMTP server uses for SASL server initialization.\n\nAvailable in Postfix version 2.3 and later:\n"
                },
                {
                    "name": "smtpd_sasl_authenticated_header (no)",
                    "content": "Report the SASL authenticated user name in the smtpd(8) Received message header.\n"
                },
                {
                    "name": "smtpd_sasl_path (smtpd)",
                    "content": "Implementation-specific information that the Postfix SMTP server passes through to the\nSASL plug-in implementation that is selected with smtpdsasltype.\n"
                },
                {
                    "name": "smtpd_sasl_type (cyrus)",
                    "content": "The SASL plug-in type that the Postfix SMTP server should use for authentication.\n\nAvailable in Postfix version 2.5 and later:\n"
                },
                {
                    "name": "cyrus_sasl_config_path (empty)",
                    "content": "Search path for Cyrus SASL application configuration files, currently used only to lo‐\ncate the $smtpdsaslpath.conf file.\n\nAvailable in Postfix version 2.11 and later:\n"
                },
                {
                    "name": "smtpd_sasl_service (smtp)",
                    "content": "The  service  name  that  is  passed  to  the  SASL  plug-in  that  is  selected  with\nsmtpdsasltype and smtpdsaslpath.\n\nAvailable in Postfix version 3.4 and later:\n"
                },
                {
                    "name": "smtpd_sasl_response_limit (12288)",
                    "content": "The maximum length of a SASL client's response to a server challenge.\n\nAvailable in Postfix 3.6 and later:\n"
                },
                {
                    "name": "smtpd_sasl_mechanism_filter (!external, static:rest)",
                    "content": "If  non-empty, a filter for the SASL mechanism names that the Postfix SMTP server will\nannounce in the EHLO response.\n"
                }
            ]
        },
        "STARTTLS SUPPORT CONTROLS": {
            "content": "Detailed information about STARTTLS configuration may be found in the TLSREADME document.\n",
            "subsections": [
                {
                    "name": "smtpd_tls_security_level (empty)",
                    "content": "The SMTP TLS security level for the Postfix SMTP server; when  a  non-empty  value  is\nspecified, this overrides the obsolete parameters smtpdusetls and smtpdenforcetls.\n"
                },
                {
                    "name": "smtpd_sasl_tls_security_options ($smtpd_sasl_security_options)",
                    "content": "The SASL authentication security options that the Postfix SMTP server uses for TLS en‐\ncrypted SMTP sessions.\n"
                },
                {
                    "name": "smtpd_starttls_timeout (see 'postconf -d' output)",
                    "content": "The  time  limit  for Postfix SMTP server write and read operations during TLS startup\nand shutdown handshake procedures.\n"
                },
                {
                    "name": "smtpd_tls_CAfile (empty)",
                    "content": "A file containing (PEM format) CA certificates of root CAs trusted to sign either  re‐\nmote SMTP client certificates or intermediate CA certificates.\n"
                },
                {
                    "name": "smtpd_tls_CApath (empty)",
                    "content": "A directory containing (PEM format) CA certificates of root CAs trusted to sign either\nremote SMTP client certificates or intermediate CA certificates.\n"
                },
                {
                    "name": "smtpd_tls_always_issue_session_ids (yes)",
                    "content": "Force the Postfix SMTP server to issue a TLS session id, even when TLS session caching\nis turned off (smtpdtlssessioncachedatabase is empty).\n"
                },
                {
                    "name": "smtpd_tls_ask_ccert (no)",
                    "content": "Ask a remote SMTP client for a client certificate.\n"
                },
                {
                    "name": "smtpd_tls_auth_only (no)",
                    "content": "When  TLS encryption is optional in the Postfix SMTP server, do not announce or accept\nSASL authentication over unencrypted connections.\n"
                },
                {
                    "name": "smtpd_tls_ccert_verifydepth (9)",
                    "content": "The verification depth for remote SMTP client certificates.\n"
                },
                {
                    "name": "smtpd_tls_cert_file (empty)",
                    "content": "File with the Postfix SMTP server RSA certificate in PEM format.\n"
                },
                {
                    "name": "smtpd_tls_exclude_ciphers (empty)",
                    "content": "List of ciphers or cipher types to exclude from the SMTP server cipher list at all TLS\nsecurity levels.\n"
                },
                {
                    "name": "smtpd_tls_dcert_file (empty)",
                    "content": "File with the Postfix SMTP server DSA certificate in PEM format.\n"
                },
                {
                    "name": "smtpd_tls_dh1024_param_file (empty)",
                    "content": "File with DH parameters that the Postfix SMTP server should use  with  non-export  EDH\nciphers.\n"
                },
                {
                    "name": "smtpd_tls_dh512_param_file (empty)",
                    "content": "File  with DH parameters that the Postfix SMTP server should use with export-grade EDH\nciphers.\n"
                },
                {
                    "name": "smtpd_tls_dkey_file ($smtpd_tls_dcert_file)",
                    "content": "File with the Postfix SMTP server DSA private key in PEM format.\n"
                },
                {
                    "name": "smtpd_tls_key_file ($smtpd_tls_cert_file)",
                    "content": "File with the Postfix SMTP server RSA private key in PEM format.\n"
                },
                {
                    "name": "smtpd_tls_loglevel (0)",
                    "content": "Enable additional Postfix SMTP server logging of TLS activity.\n"
                },
                {
                    "name": "smtpd_tls_mandatory_ciphers (medium)",
                    "content": "The minimum TLS cipher grade that the Postfix SMTP server will use with mandatory  TLS\nencryption.\n"
                },
                {
                    "name": "smtpd_tls_mandatory_exclude_ciphers (empty)",
                    "content": "Additional list of ciphers or cipher types to exclude from the Postfix SMTP server ci‐\npher list at mandatory TLS security levels.\n"
                },
                {
                    "name": "smtpd_tls_mandatory_protocols (see 'postconf -d' output)",
                    "content": "TLS protocols accepted by the Postfix SMTP server with mandatory TLS encryption.\n"
                },
                {
                    "name": "smtpd_tls_received_header (no)",
                    "content": "Request  that the Postfix SMTP server produces Received:  message headers that include\ninformation about the protocol and cipher used, as well as the remote SMTP client Com‐\nmonName and client certificate issuer CommonName.\n"
                },
                {
                    "name": "smtpd_tls_req_ccert (no)",
                    "content": "With mandatory TLS encryption, require a trusted remote SMTP client certificate in or‐\nder to allow TLS connections to proceed.\n"
                },
                {
                    "name": "smtpd_tls_wrappermode (no)",
                    "content": "Run the Postfix SMTP server in TLS \"wrapper\" mode, instead of using the STARTTLS  com‐\nmand.\n"
                },
                {
                    "name": "tls_daemon_random_bytes (32)",
                    "content": "The  number  of  pseudo-random bytes that an smtp(8) or smtpd(8) process requests from\nthe tlsmgr(8) server in order to seed its  internal  pseudo  random  number  generator\n(PRNG).\n"
                },
                {
                    "name": "tls_high_cipherlist (see 'postconf -d' output)",
                    "content": "The OpenSSL cipherlist for \"high\" grade ciphers.\n"
                },
                {
                    "name": "tls_medium_cipherlist (see 'postconf -d' output)",
                    "content": "The OpenSSL cipherlist for \"medium\" or higher grade ciphers.\n"
                },
                {
                    "name": "tls_null_cipherlist (eNULL:!aNULL)",
                    "content": "The  OpenSSL  cipherlist  for \"NULL\" grade ciphers that provide authentication without\nencryption.\n\nAvailable in Postfix version 2.3..3.7:\n"
                },
                {
                    "name": "tls_low_cipherlist (see 'postconf -d' output)",
                    "content": "The OpenSSL cipherlist for \"low\" or higher grade ciphers.\n"
                },
                {
                    "name": "tls_export_cipherlist (see 'postconf -d' output)",
                    "content": "The OpenSSL cipherlist for \"export\" or higher grade ciphers.\n\nAvailable in Postfix version 2.5 and later:\n"
                },
                {
                    "name": "smtpd_tls_fingerprint_digest (see 'postconf -d' output)",
                    "content": "The message digest algorithm to construct remote SMTP client-certificate  fingerprints\nor  public  key  fingerprints  (Postfix 2.9 and later) for checkccertaccess and per‐\nmittlsclientcerts.\n\nAvailable in Postfix version 2.6 and later:\n"
                },
                {
                    "name": "smtpd_tls_protocols (see postconf -d output)",
                    "content": "TLS protocols accepted by the Postfix SMTP server with opportunistic TLS encryption.\n"
                },
                {
                    "name": "smtpd_tls_ciphers (medium)",
                    "content": "The minimum TLS cipher grade that the Postfix SMTP server will use with  opportunistic\nTLS encryption.\n"
                },
                {
                    "name": "smtpd_tls_eccert_file (empty)",
                    "content": "File with the Postfix SMTP server ECDSA certificate in PEM format.\n"
                },
                {
                    "name": "smtpd_tls_eckey_file ($smtpd_tls_eccert_file)",
                    "content": "File with the Postfix SMTP server ECDSA private key in PEM format.\n"
                },
                {
                    "name": "smtpd_tls_eecdh_grade (see 'postconf -d' output)",
                    "content": "The  Postfix  SMTP  server  security grade for ephemeral elliptic-curve Diffie-Hellman\n(EECDH) key exchange.\n"
                },
                {
                    "name": "tls_eecdh_strong_curve (prime256v1)",
                    "content": "The elliptic curve used by the Postfix SMTP server for sensibly strong ephemeral  ECDH\nkey exchange.\n"
                },
                {
                    "name": "tls_eecdh_ultra_curve (secp384r1)",
                    "content": "The elliptic curve used by the Postfix SMTP server for maximally strong ephemeral ECDH\nkey exchange.\n\nAvailable in Postfix version 2.8 and later:\n"
                },
                {
                    "name": "tls_preempt_cipherlist (no)",
                    "content": "With SSLv3 and later, use the Postfix SMTP server's cipher preference order instead of\nthe remote client's cipher preference order.\n"
                },
                {
                    "name": "tls_disable_workarounds (see 'postconf -d' output)",
                    "content": "List or bit-mask of OpenSSL bug work-arounds to disable.\n\nAvailable in Postfix version 2.11 and later:\n"
                },
                {
                    "name": "tlsmgr_service_name (tlsmgr)",
                    "content": "The name of the tlsmgr(8) service entry in master.cf.\n\nAvailable in Postfix version 3.0 and later:\n"
                },
                {
                    "name": "tls_session_ticket_cipher (Postfix >= 3.0: aes-256-cbc, Postfix < 3.0: aes-128-cbc)",
                    "content": "Algorithm used to encrypt RFC5077 TLS session tickets.\n\nAvailable in Postfix version 3.2 and later:\n"
                },
                {
                    "name": "tls_eecdh_auto_curves (see 'postconf -d' output)",
                    "content": "The  prioritized  list  of  elliptic  curves  supported by the Postfix SMTP client and\nserver.\n\nAvailable in Postfix version 3.4 and later:\n"
                },
                {
                    "name": "smtpd_tls_chain_files (empty)",
                    "content": "List of one or more PEM files, each holding one or more private keys directly followed\nby a corresponding certificate chain.\n"
                },
                {
                    "name": "tls_server_sni_maps (empty)",
                    "content": "Optional lookup tables that map names received from remote SMTP clients  via  the  TLS\nServer Name Indication (SNI) extension to the appropriate keys and certificate chains.\n\nAvailable in Postfix 3.5, 3.4.6, 3.3.5, 3.2.10, 3.1.13 and later:\n"
                },
                {
                    "name": "tls_fast_shutdown_enable (yes)",
                    "content": "A  workaround for implementations that hang Postfix while shutting down a TLS session,\nuntil Postfix times out.\n\nAvailable in Postfix version 3.8 and later:\n"
                },
                {
                    "name": "tls_ffdhe_auto_groups (see 'postconf -d' output)",
                    "content": "The prioritized list of finite-field Diffie-Hellman  ephemeral  (FFDHE)  key  exchange\ngroups supported by the Postfix SMTP client and server.\n\nAvailable in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later:\n"
                },
                {
                    "name": "tls_config_file (default)",
                    "content": "Optional configuration file with baseline OpenSSL settings.\n"
                },
                {
                    "name": "tls_config_name (empty)",
                    "content": "The application name passed by Postfix to OpenSSL library initialization functions.\n"
                }
            ]
        },
        "OBSOLETE STARTTLS CONTROLS": {
            "content": "The  following  configuration parameters exist for compatibility with Postfix versions before\n2.3. Support for these will be removed in a future release.\n",
            "subsections": [
                {
                    "name": "smtpd_use_tls (no)",
                    "content": "Opportunistic TLS: announce STARTTLS support to remote SMTP clients, but  do  not  re‐\nquire that clients use TLS encryption.\n"
                },
                {
                    "name": "smtpd_enforce_tls (no)",
                    "content": "Mandatory  TLS:  announce  STARTTLS  support  to remote SMTP clients, and require that\nclients use TLS encryption.\n"
                },
                {
                    "name": "smtpd_tls_cipherlist (empty)",
                    "content": "Obsolete Postfix < 2.3 control for the Postfix SMTP server TLS cipher list.\n"
                }
            ]
        },
        "SMTPUTF8 CONTROLS": {
            "content": "Preliminary SMTPUTF8 support is introduced with Postfix 3.0.\n",
            "subsections": [
                {
                    "name": "smtputf8_enable (yes)",
                    "content": "Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531, RFC 6532,\nand RFC 6533.\n"
                },
                {
                    "name": "strict_smtputf8 (no)",
                    "content": "Enable stricter enforcement of the SMTPUTF8 protocol.\n"
                },
                {
                    "name": "smtputf8_autodetect_classes (sendmail, verify)",
                    "content": "Detect that a message requires SMTPUTF8 support for the specified mail origin classes.\n\nAvailable in Postfix version 3.2 and later:\n"
                },
                {
                    "name": "enable_idna2003_compatibility (no)",
                    "content": "Enable 'transitional' compatibility between IDNA2003  and  IDNA2008,  when  converting\nUTF-8 domain names to/from the ASCII form that is used for DNS lookups.\n"
                }
            ]
        },
        "VERP SUPPORT CONTROLS": {
            "content": "With  VERP style delivery, each recipient of a message receives a customized copy of the mes‐\nsage with his/her own  recipient  address  encoded  in  the  envelope  sender  address.   The\nVERPREADME  file  describes configuration and operation details of Postfix support for vari‐\nable envelope return path addresses.  VERP style delivery is requested with  the  SMTP  XVERP\ncommand or with the \"sendmail -V\" command-line option and is available in Postfix version 1.1\nand later.\n",
            "subsections": [
                {
                    "name": "default_verp_delimiters (+=)",
                    "content": "The two default VERP delimiter characters.\n"
                },
                {
                    "name": "verp_delimiter_filter (-=+)",
                    "content": "The characters Postfix accepts as VERP delimiter characters on the Postfix sendmail(1)\ncommand line and in SMTP commands.\n\nAvailable in Postfix version 1.1 and 2.0:\n"
                },
                {
                    "name": "authorized_verp_clients ($mynetworks)",
                    "content": "What remote SMTP clients are allowed to specify the XVERP command.\n\nAvailable in Postfix version 2.1 and later:\n"
                },
                {
                    "name": "smtpd_authorized_verp_clients ($authorized_verp_clients)",
                    "content": "What remote SMTP clients are allowed to specify the XVERP command.\n"
                }
            ]
        },
        "TROUBLE SHOOTING CONTROLS": {
            "content": "The  DEBUGREADME document describes how to debug parts of the Postfix mail system. The meth‐\nods vary from making the software log a lot of detail, to running some daemon processes under\ncontrol of a call tracer or debugger.\n",
            "subsections": [
                {
                    "name": "debug_peer_level (2)",
                    "content": "The increment in verbose logging level when a nexthop destination,  remote  client  or\nserver  name or network address matches a pattern given with the debugpeerlist para‐\nmeter.\n"
                },
                {
                    "name": "debug_peer_list (empty)",
                    "content": "Optional list of nexthop destination, remote client or server name or network  address\npatterns  that,  if matched, cause the verbose logging level to increase by the amount\nspecified in $debugpeerlevel.\n"
                },
                {
                    "name": "error_notice_recipient (postmaster)",
                    "content": "The recipient of postmaster notifications about mail delivery problems that are caused\nby policy, resource, software or protocol errors.\n"
                },
                {
                    "name": "internal_mail_filter_classes (empty)",
                    "content": "What categories of Postfix-generated mail are subject to before-queue content  inspec‐\ntion by nonsmtpdmilters, headerchecks and bodychecks.\n"
                },
                {
                    "name": "notify_classes (resource, software)",
                    "content": "The list of error classes that are reported to the postmaster.\n"
                },
                {
                    "name": "smtpd_reject_footer (empty)",
                    "content": "Optional  information  that  is appended after each Postfix SMTP server 4XX or 5XX re‐\nsponse.\n"
                },
                {
                    "name": "soft_bounce (no)",
                    "content": "Safety net to keep mail queued that would otherwise be returned to the sender.\n\nAvailable in Postfix version 2.1 and later:\n"
                },
                {
                    "name": "smtpd_authorized_xclient_hosts (empty)",
                    "content": "What remote SMTP clients are allowed to use the XCLIENT feature.\n\nAvailable in Postfix version 2.10 and later:\n"
                },
                {
                    "name": "smtpd_log_access_permit_actions (empty)",
                    "content": "Enable logging of the named \"permit\" actions in SMTP server access lists (by  default,\nthe SMTP server logs \"reject\" actions but not \"permit\" actions).\n"
                }
            ]
        },
        "KNOWN VERSUS UNKNOWN RECIPIENT CONTROLS": {
            "content": "As of Postfix version 2.0, the SMTP server rejects mail for unknown recipients. This prevents\nthe  mail queue from clogging up with undeliverable MAILER-DAEMON messages. Additional infor‐\nmation on this topic is in the LOCALRECIPIENTREADME and ADDRESSCLASSREADME documents.\n",
            "subsections": [
                {
                    "name": "show_user_unknown_table_name (yes)",
                    "content": "Display the name of the recipient table in the \"User unknown\" responses.\n"
                },
                {
                    "name": "canonical_maps (empty)",
                    "content": "Optional address mapping lookup tables for message headers and envelopes.\n"
                },
                {
                    "name": "recipient_canonical_maps (empty)",
                    "content": "Optional address mapping lookup tables for envelope and header recipient addresses.\n"
                },
                {
                    "name": "sender_canonical_maps (empty)",
                    "content": "Optional address mapping lookup tables for envelope and header sender addresses.\n\nParameters concerning known/unknown local recipients:\n"
                },
                {
                    "name": "mydestination ($myhostname, localhost.$mydomain, localhost)",
                    "content": "The list of domains that are delivered via the $localtransport mail  delivery  trans‐\nport.\n"
                },
                {
                    "name": "inet_interfaces (all)",
                    "content": "The local network interface addresses that this mail system receives mail on.\n"
                },
                {
                    "name": "proxy_interfaces (empty)",
                    "content": "The  remote  network interface addresses that this mail system receives mail on by way\nof a proxy or network address translation unit.\n"
                },
                {
                    "name": "inet_protocols (see 'postconf -d output')",
                    "content": "The Internet protocols Postfix will attempt to use when making  or  accepting  connec‐\ntions.\n"
                },
                {
                    "name": "local_recipient_maps (proxy:unix:passwd.byname $alias_maps)",
                    "content": "Lookup  tables with all names or addresses of local recipients: a recipient address is\nlocal when its domain matches $mydestination, $inetinterfaces or $proxyinterfaces.\n"
                },
                {
                    "name": "unknown_local_recipient_reject_code (550)",
                    "content": "The numerical Postfix SMTP server response code when a recipient address is local, and\n$localrecipientmaps specifies a list of lookup tables that does not match the recip‐\nient.\n\nParameters concerning known/unknown recipients of relay destinations:\n"
                },
                {
                    "name": "relay_domains (Postfix >= 3.0: empty, Postfix < 3.0: $mydestination)",
                    "content": "What destination domains (and subdomains thereof) this system will relay mail to.\n"
                },
                {
                    "name": "relay_recipient_maps (empty)",
                    "content": "Optional lookup tables with all valid addresses in the domains that  match  $relaydo‐\nmains.\n"
                },
                {
                    "name": "unknown_relay_recipient_reject_code (550)",
                    "content": "The  numerical  Postfix  SMTP  server reply code when a recipient address matches $re‐\nlaydomains, and relayrecipientmaps specifies a list of lookup tables that does  not\nmatch the recipient address.\n\nParameters concerning known/unknown recipients in virtual alias domains:\n"
                },
                {
                    "name": "virtual_alias_domains ($virtual_alias_maps)",
                    "content": "Postfix is the final destination for the specified list of virtual alias domains, that\nis,  domains for which all addresses are aliased to addresses in other local or remote\ndomains.\n"
                },
                {
                    "name": "virtual_alias_maps ($virtual_maps)",
                    "content": "Optional lookup tables that alias specific mail addresses or domains to other local or\nremote addresses.\n"
                },
                {
                    "name": "unknown_virtual_alias_reject_code (550)",
                    "content": "The Postfix SMTP server reply code when a recipient address matches $virtualaliasdo‐\nmains, and $virtualaliasmaps specifies a list of lookup tables that does  not  match\nthe recipient address.\n\nParameters concerning known/unknown recipients in virtual mailbox domains:\n"
                },
                {
                    "name": "virtual_mailbox_domains ($virtual_mailbox_maps)",
                    "content": "Postfix  is the final destination for the specified list of domains; mail is delivered\nvia the $virtualtransport mail delivery transport.\n"
                },
                {
                    "name": "virtual_mailbox_maps (empty)",
                    "content": "Optional lookup tables with all valid  addresses  in  the  domains  that  match  $vir‐\ntualmailboxdomains.\n"
                },
                {
                    "name": "unknown_virtual_mailbox_reject_code (550)",
                    "content": "The  Postfix  SMTP  server  reply code when a recipient address matches $virtualmail‐\nboxdomains, and $virtualmailboxmaps specifies a list of lookup tables that does not\nmatch the recipient address.\n"
                }
            ]
        },
        "RESOURCE AND RATE CONTROLS": {
            "content": "The following parameters limit resource usage by the SMTP server and/or  control  client  re‐\nquest rates.\n",
            "subsections": [
                {
                    "name": "line_length_limit (2048)",
                    "content": "Upon  input, long lines are chopped up into pieces of at most this length; upon deliv‐\nery, long lines are reconstructed.\n"
                },
                {
                    "name": "queue_minfree (0)",
                    "content": "The minimal amount of free space in bytes in the queue file system that is  needed  to\nreceive mail.\n"
                },
                {
                    "name": "message_size_limit (10240000)",
                    "content": "The maximal size in bytes of a message, including envelope information.\n"
                },
                {
                    "name": "smtpd_recipient_limit (1000)",
                    "content": "The  maximal number of recipients that the Postfix SMTP server accepts per message de‐\nlivery request.\n"
                },
                {
                    "name": "smtpd_timeout (normal: 300s, overload: 10s)",
                    "content": "When the Postfix SMTP server wants to send an SMTP server response, how long the Post‐\nfix SMTP server will wait for an underlying network write operation to  complete;  and\nwhen the Postfix SMTP server Postfix wants to receive an SMTP client request, how long\nthe  Postfix  SMTP  server  will wait for an underlying network read operation to com‐\nplete.\n"
                },
                {
                    "name": "smtpd_history_flush_threshold (100)",
                    "content": "The maximal number of lines in the Postfix SMTP server command history  before  it  is\nflushed upon receipt of EHLO, RSET, or end of DATA.\n\nAvailable in Postfix version 2.3 and later:\n"
                },
                {
                    "name": "smtpd_peername_lookup (yes)",
                    "content": "Attempt  to  look up the remote SMTP client hostname, and verify that the name matches\nthe client IP address.\n\nThe per SMTP client connection count and request rate limits are implemented in  co-operation\nwith the anvil(8) service, and are available in Postfix version 2.2 and later.\n"
                },
                {
                    "name": "smtpd_client_connection_count_limit (50)",
                    "content": "How many simultaneous connections any client is allowed to make to this service.\n"
                },
                {
                    "name": "smtpd_client_connection_rate_limit (0)",
                    "content": "The  maximal  number of connection attempts any client is allowed to make to this ser‐\nvice per time unit.\n"
                },
                {
                    "name": "smtpd_client_message_rate_limit (0)",
                    "content": "The maximal number of message delivery requests that any client is allowed to make  to\nthis  service  per  time  unit,  regardless of whether or not Postfix actually accepts\nthose messages.\n"
                },
                {
                    "name": "smtpd_client_recipient_rate_limit (0)",
                    "content": "The maximal number of recipient addresses that any client is allowed to send  to  this\nservice per time unit, regardless of whether or not Postfix actually accepts those re‐\ncipients.\n"
                },
                {
                    "name": "smtpd_client_event_limit_exceptions ($mynetworks)",
                    "content": "Clients that are excluded from smtpdclient*count/ratelimit restrictions.\n\nAvailable in Postfix version 2.3 and later:\n"
                },
                {
                    "name": "smtpd_client_new_tls_session_rate_limit (0)",
                    "content": "The  maximal  number of new (i.e., uncached) TLS sessions that a remote SMTP client is\nallowed to negotiate with this service per time unit.\n\nAvailable in Postfix version 2.9 - 3.6:\n"
                },
                {
                    "name": "smtpd_per_record_deadline (normal: no, overload: yes)",
                    "content": "Change the behavior of the smtpdtimeout and smtpdstarttlstimeout time limits,  from\na  time limit per read or write system call, to a time limit to send or receive a com‐\nplete record (an SMTP command line, SMTP response line, SMTP message content line,  or\nTLS protocol message).\n\nAvailable in Postfix version 3.1 and later:\n"
                },
                {
                    "name": "smtpd_client_auth_rate_limit (0)",
                    "content": "The maximal number of AUTH commands that any client is allowed to send to this service\nper time unit, regardless of whether or not Postfix actually accepts those commands.\n\nAvailable in Postfix version 3.7 and later:\n"
                },
                {
                    "name": "smtpd_per_request_deadline (normal: no, overload: yes)",
                    "content": "Change  the behavior of the smtpdtimeout and smtpdstarttlstimeout time limits, from\na time limit per plaintext or TLS read or write call, to a combined time limit for re‐\nceiving a complete SMTP request and for sending a complete SMTP response.\n"
                },
                {
                    "name": "smtpd_min_data_rate (500)",
                    "content": "The minimum plaintext data transfer rate in bytes/second for DATA and  BDAT  requests,\nwhen deadlines are enabled with smtpdperrequestdeadline.\n"
                },
                {
                    "name": "header_from_format (standard)",
                    "content": "The format of the Postfix-generated From: header.\n\nAvailable in Postfix version 3.8 and later:\n"
                },
                {
                    "name": "smtpd_client_ipv4_prefix_length (32)",
                    "content": "Aggregate  smtpdclient*count  and  smtpdclient*rate  statistics  by IPv4 network\nblocks with the specified network prefix.\n"
                },
                {
                    "name": "smtpd_client_ipv6_prefix_length (84)",
                    "content": "Aggregate smtpdclient*count and  smtpdclient*rate  statistics  by  IPv6  network\nblocks with the specified network prefix.\n\nAvailable in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later:\n"
                },
                {
                    "name": "smtpd_forbid_unauth_pipelining (Postfix >= 3.9: yes)",
                    "content": "Disconnect remote SMTP clients that violate RFC 2920 (or 5321) command pipelining con‐\nstraints.\n\nAvailable in Postfix 3.9, 3.8.4, 3.7.9, 3.6.13, 3.5.23 and later:\n"
                },
                {
                    "name": "smtpd_forbid_bare_newline (Postfix < 3.9: no)",
                    "content": "Reject  or  restrict  input  lines from an SMTP client that end in <LF> instead of the\nstandard <CR><LF>.\n"
                },
                {
                    "name": "smtpd_forbid_bare_newline_exclusions ($mynetworks)",
                    "content": "Exclude the specified clients from smtpdforbidbarenewline enforcement.\n\nAvailable in Postfix 3.9, 3.8.5, 3.7.10, 3.6.14, 3.5.24 and later:\n"
                },
                {
                    "name": "smtpd_forbid_bare_newline_reject_code (550)",
                    "content": "The numerical Postfix  SMTP  server  response  code  when  rejecting  a  request  with\n\"smtpdforbidbarenewline = reject\".\n"
                }
            ]
        },
        "TARPIT CONTROLS": {
            "content": "When  a remote SMTP client makes errors, the Postfix SMTP server can insert delays before re‐\nsponding. This can help to slow down run-away software.  The behavior is controlled by an er‐\nror counter that counts the number of errors within an SMTP session that a client makes with‐\nout delivering mail.\n",
            "subsections": [
                {
                    "name": "smtpd_error_sleep_time (1s)",
                    "content": "With Postfix version 2.1 and later: the SMTP server response delay after a client  has\nmade  more than $smtpdsofterrorlimit errors, and fewer than $smtpdharderrorlimit\nerrors, without delivering mail.\n"
                },
                {
                    "name": "smtpd_soft_error_limit (10)",
                    "content": "The number of errors a remote SMTP client is allowed to make without  delivering  mail\nbefore the Postfix SMTP server slows down all its responses.\n"
                },
                {
                    "name": "smtpd_hard_error_limit (normal: 20, overload: 1)",
                    "content": "The  maximal number of errors a remote SMTP client is allowed to make without deliver‐\ning mail.\n"
                },
                {
                    "name": "smtpd_junk_command_limit (normal: 100, overload: 1)",
                    "content": "The number of junk commands (NOOP, VRFY, ETRN or RSET) that a remote SMTP  client  can\nsend  before  the  Postfix SMTP server starts to increment the error counter with each\njunk command.\n\nAvailable in Postfix version 2.1 and later:\n"
                },
                {
                    "name": "smtpd_recipient_overshoot_limit (1000)",
                    "content": "The number of recipients that a remote SMTP client can send in  excess  of  the  limit\nspecified  with  $smtpdrecipientlimit, before the Postfix SMTP server increments the\nper-session error count for each excess recipient.\n"
                }
            ]
        },
        "ACCESS POLICY DELEGATION CONTROLS": {
            "content": "As of version 2.1, Postfix can be configured to delegate access policy decisions to an exter‐\nnal server that runs outside Postfix.  See the file SMTPDPOLICYREADME for more information.\n",
            "subsections": [
                {
                    "name": "smtpd_policy_service_max_idle (300s)",
                    "content": "The time after which an idle SMTPD policy service connection is closed.\n"
                },
                {
                    "name": "smtpd_policy_service_max_ttl (1000s)",
                    "content": "The time after which an active SMTPD policy service connection is closed.\n"
                },
                {
                    "name": "smtpd_policy_service_timeout (100s)",
                    "content": "The time limit for connecting to, writing to, or receiving from a delegated SMTPD pol‐\nicy server.\n\nAvailable in Postfix version 3.0 and later:\n"
                },
                {
                    "name": "smtpd_policy_service_default_action (451 4.3.5 Server configuration problem)",
                    "content": "The default action when an SMTPD policy service request fails.\n"
                },
                {
                    "name": "smtpd_policy_service_request_limit (0)",
                    "content": "The maximal number of requests per  SMTPD  policy  service  connection,  or  zero  (no\nlimit).\n"
                },
                {
                    "name": "smtpd_policy_service_try_limit (2)",
                    "content": "The  maximal  number of attempts to send an SMTPD policy service request before giving\nup.\n"
                },
                {
                    "name": "smtpd_policy_service_retry_delay (1s)",
                    "content": "The delay between attempts to resend a failed SMTPD policy service request.\n\nAvailable in Postfix version 3.1 and later:\n"
                },
                {
                    "name": "smtpd_policy_service_policy_context (empty)",
                    "content": "Optional information that the Postfix SMTP server specifies  in  the  \"policycontext\"\nattribute  of a policy service request (originally, to share the same service endpoint\namong multiple checkpolicyservice clients).\n"
                }
            ]
        },
        "ACCESS CONTROLS": {
            "content": "The SMTPDACCESSREADME document gives an introduction to all the SMTP server access  control\nfeatures.\n",
            "subsections": [
                {
                    "name": "smtpd_delay_reject (yes)",
                    "content": "Wait   until   the  RCPT  TO  command  before  evaluating  $smtpdclientrestrictions,\n$smtpdhelorestrictions and $smtpdsenderrestrictions, or wait until the  ETRN  com‐\nmand before evaluating $smtpdclientrestrictions and $smtpdhelorestrictions.\n"
                },
                {
                    "name": "parent_domain_matches_subdomains (see 'postconf -d' output)",
                    "content": "A  list of Postfix features where the pattern \"example.com\" also matches subdomains of\nexample.com, instead of requiring an explicit \".example.com\" pattern.\n"
                },
                {
                    "name": "smtpd_client_restrictions (empty)",
                    "content": "Optional restrictions that the Postfix SMTP server applies in the context of a  client\nconnection request.\n"
                },
                {
                    "name": "smtpd_helo_required (no)",
                    "content": "Require  that a remote SMTP client introduces itself with the HELO or EHLO command be‐\nfore sending the MAIL command or other commands that require EHLO negotiation.\n"
                },
                {
                    "name": "smtpd_helo_restrictions (empty)",
                    "content": "Optional restrictions that the Postfix SMTP server applies in the context of a  client\nHELO command.\n"
                },
                {
                    "name": "smtpd_sender_restrictions (empty)",
                    "content": "Optional  restrictions that the Postfix SMTP server applies in the context of a client\nMAIL FROM command.\n"
                },
                {
                    "name": "smtpd_recipient_restrictions (see 'postconf -d' output)",
                    "content": "Optional restrictions that the Postfix SMTP server applies in the context of a  client\nRCPT TO command, after smtpdrelayrestrictions.\n"
                },
                {
                    "name": "smtpd_etrn_restrictions (empty)",
                    "content": "Optional  restrictions that the Postfix SMTP server applies in the context of a client\nETRN command.\n"
                },
                {
                    "name": "allow_untrusted_routing (no)",
                    "content": "Forward mail with sender-specified routing (user[@%!]remote[@%!]site)  from  untrusted\nclients to destinations matching $relaydomains.\n"
                },
                {
                    "name": "smtpd_restriction_classes (empty)",
                    "content": "User-defined aliases for groups of access restrictions.\n"
                },
                {
                    "name": "smtpd_null_access_lookup_key (<>)",
                    "content": "The lookup key to be used in SMTP access(5) tables instead of the null sender address.\n"
                },
                {
                    "name": "permit_mx_backup_networks (empty)",
                    "content": "Restrict  the  use  of  the permitmxbackup SMTP access feature to only domains whose\nprimary MX hosts match the listed networks.\n\nAvailable in Postfix version 2.0 and later:\n"
                },
                {
                    "name": "smtpd_data_restrictions (empty)",
                    "content": "Optional access restrictions that the Postfix SMTP server applies in  the  context  of\nthe SMTP DATA command.\n"
                },
                {
                    "name": "smtpd_expansion_filter (see 'postconf -d' output)",
                    "content": "What characters are allowed in $name expansions of RBL reply templates.\n\nAvailable in Postfix version 2.1 and later:\n"
                },
                {
                    "name": "smtpd_reject_unlisted_sender (no)",
                    "content": "Request  that the Postfix SMTP server rejects mail from unknown sender addresses, even\nwhen no explicit rejectunlistedsender access restriction is specified.\n"
                },
                {
                    "name": "smtpd_reject_unlisted_recipient (yes)",
                    "content": "Request that the Postfix SMTP server rejects mail  for  unknown  recipient  addresses,\neven when no explicit rejectunlistedrecipient access restriction is specified.\n\nAvailable in Postfix version 2.2 and later:\n"
                },
                {
                    "name": "smtpd_end_of_data_restrictions (empty)",
                    "content": "Optional  access  restrictions  that the Postfix SMTP server applies in the context of\nthe SMTP END-OF-DATA command.\n\nAvailable in Postfix version 2.10 and later:\n"
                },
                {
                    "name": "smtpd_relay_restrictions (permit_mynetworks, permit_sasl_authenticated, defer_unauth_destina‐",
                    "content": ""
                },
                {
                    "name": "tion)",
                    "content": "Access restrictions for mail relay control that the Postfix SMTP server applies in the\ncontext of the RCPT TO command, before smtpdrecipientrestrictions.\n"
                }
            ]
        },
        "SENDER AND RECIPIENT ADDRESS VERIFICATION CONTROLS": {
            "content": "Postfix version 2.1 introduces sender and recipient address verification.   This  feature  is\nimplemented by sending probe email messages that are not actually delivered.  This feature is\nrequested  via  the  rejectunverifiedsender and rejectunverifiedrecipient access restric‐\ntions.  The status of verification probes is maintained by the  verify(8)  server.   See  the\nfile ADDRESSVERIFICATIONREADME for information about how to configure and operate the Post‐\nfix sender/recipient address verification service.\n",
            "subsections": [
                {
                    "name": "address_verify_poll_count (normal: 3, overload: 1)",
                    "content": "How many times to query the verify(8) service for the completion of an address verifi‐\ncation request in progress.\n"
                },
                {
                    "name": "address_verify_poll_delay (3s)",
                    "content": "The  delay  between  queries  for the completion of an address verification request in\nprogress.\n"
                },
                {
                    "name": "address_verify_sender ($double_bounce_sender)",
                    "content": "The sender address to use in address verification probes; prior to Postfix 2.5 the de‐\nfault was \"postmaster\".\n"
                },
                {
                    "name": "unverified_sender_reject_code (450)",
                    "content": "The numerical Postfix SMTP server response code when a recipient address  is  rejected\nby the rejectunverifiedsender restriction.\n"
                },
                {
                    "name": "unverified_recipient_reject_code (450)",
                    "content": "The numerical Postfix SMTP server response when a recipient address is rejected by the\nrejectunverifiedrecipient restriction.\n\nAvailable in Postfix version 2.6 and later:\n"
                },
                {
                    "name": "unverified_sender_defer_code (450)",
                    "content": "The  numerical Postfix SMTP server response code when a sender address probe fails due\nto a temporary error condition.\n"
                },
                {
                    "name": "unverified_recipient_defer_code (450)",
                    "content": "The numerical Postfix SMTP server response when a recipient address probe fails due to\na temporary error condition.\n"
                },
                {
                    "name": "unverified_sender_reject_reason (empty)",
                    "content": "The Postfix SMTP server's reply when rejecting mail with rejectunverifiedsender.\n"
                },
                {
                    "name": "unverified_recipient_reject_reason (empty)",
                    "content": "The Postfix SMTP server's reply when rejecting mail with rejectunverifiedrecipient.\n"
                },
                {
                    "name": "unverified_sender_tempfail_action ($reject_tempfail_action)",
                    "content": "The Postfix SMTP server's action when rejectunverifiedsender fails due to  a  tempo‐\nrary error condition.\n"
                },
                {
                    "name": "unverified_recipient_tempfail_action ($reject_tempfail_action)",
                    "content": "The  Postfix SMTP server's action when rejectunverifiedrecipient fails due to a tem‐\nporary error condition.\n\nAvailable with Postfix 2.9 and later:\n"
                },
                {
                    "name": "address_verify_sender_ttl (0s)",
                    "content": "The time between changes in the time-dependent portion of address  verification  probe\nsender addresses.\n"
                }
            ]
        },
        "ACCESS CONTROL RESPONSES": {
            "content": "The following parameters control numerical SMTP reply codes and/or text responses.\n",
            "subsections": [
                {
                    "name": "access_map_reject_code (554)",
                    "content": "The numerical Postfix SMTP server response code for an access(5) map \"reject\" action.\n"
                },
                {
                    "name": "defer_code (450)",
                    "content": "The  numerical  Postfix SMTP server response code when a remote SMTP client request is\nrejected by the \"defer\" restriction.\n"
                },
                {
                    "name": "invalid_hostname_reject_code (501)",
                    "content": "The numerical Postfix SMTP server response code when the client HELO or  EHLO  command\nparameter is rejected by the rejectinvalidhelohostname restriction.\n"
                },
                {
                    "name": "maps_rbl_reject_code (554)",
                    "content": "The  numerical  Postfix SMTP server response code when a remote SMTP client request is\nblocked by the  rejectrblclient,  rejectrhsblclient,  rejectrhsblreverseclient,\nrejectrhsblsender or rejectrhsblrecipient restriction.\n"
                },
                {
                    "name": "non_fqdn_reject_code (504)",
                    "content": "The  numerical Postfix SMTP server reply code when a client request is rejected by the\nrejectnonfqdnhelohostname, rejectnonfqdnsender or rejectnonfqdnrecipient re‐\nstriction.\n"
                },
                {
                    "name": "plaintext_reject_code (450)",
                    "content": "The numerical Postfix SMTP server response code when a request is rejected by the  re‐\njectplaintextsession restriction.\n"
                },
                {
                    "name": "reject_code (554)",
                    "content": "The  numerical  Postfix SMTP server response code when a remote SMTP client request is\nrejected by the \"reject\" restriction.\n"
                },
                {
                    "name": "relay_domains_reject_code (554)",
                    "content": "The numerical Postfix SMTP server response code when a client request is  rejected  by\nthe rejectunauthdestination recipient restriction.\n"
                },
                {
                    "name": "unknown_address_reject_code (450)",
                    "content": "The numerical response code when the Postfix SMTP server rejects a sender or recipient\naddress because its domain is unknown.\n"
                },
                {
                    "name": "unknown_client_reject_code (450)",
                    "content": "The  numerical  Postfix  SMTP server response code when a client without valid address\n<=> name mapping is rejected by the rejectunknownclienthostname restriction.\n"
                },
                {
                    "name": "unknown_hostname_reject_code (450)",
                    "content": "The numerical Postfix SMTP server response code when the hostname specified  with  the\nHELO or EHLO command is rejected by the rejectunknownhelohostname restriction.\n\nAvailable in Postfix version 2.0 and later:\n"
                },
                {
                    "name": "default_rbl_reply (see 'postconf -d' output)",
                    "content": "The default Postfix SMTP server response template for a request that is rejected by an\nRBL-based restriction.\n"
                },
                {
                    "name": "multi_recipient_bounce_reject_code (550)",
                    "content": "The  numerical  Postfix SMTP server response code when a remote SMTP client request is\nblocked by the rejectmultirecipientbounce restriction.\n"
                },
                {
                    "name": "rbl_reply_maps (empty)",
                    "content": "Optional lookup tables with RBL response templates.\n\nAvailable in Postfix version 2.6 and later:\n"
                },
                {
                    "name": "access_map_defer_code (450)",
                    "content": "The numerical Postfix SMTP server response code for an access(5) map  \"defer\"  action,\nincluding \"deferifpermit\" or \"deferifreject\".\n"
                },
                {
                    "name": "reject_tempfail_action (defer_if_permit)",
                    "content": "The  Postfix SMTP server's action when a reject-type restriction fails due to a tempo‐\nrary error condition.\n"
                },
                {
                    "name": "unknown_helo_hostname_tempfail_action ($reject_tempfail_action)",
                    "content": "The Postfix SMTP server's action when rejectunknownhelohostname fails due to a tem‐\nporary error condition.\n"
                },
                {
                    "name": "unknown_address_tempfail_action ($reject_tempfail_action)",
                    "content": "The Postfix SMTP  server's  action  when  rejectunknownsenderdomain  or  rejectun‐\nknownrecipientdomain fail due to a temporary error condition.\n"
                }
            ]
        },
        "MISCELLANEOUS CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "config_directory (see 'postconf -d' output)",
                    "content": "The default location of the Postfix main.cf and master.cf configuration files.\n"
                },
                {
                    "name": "daemon_timeout (18000s)",
                    "content": "How  much time a Postfix daemon process may take to handle a request before it is ter‐\nminated by a built-in watchdog timer.\n"
                },
                {
                    "name": "command_directory (see 'postconf -d' output)",
                    "content": "The location of all postfix administrative commands.\n"
                },
                {
                    "name": "double_bounce_sender (double-bounce)",
                    "content": "The sender address of postmaster notifications that are generated by the mail system.\n"
                },
                {
                    "name": "ipc_timeout (3600s)",
                    "content": "The time limit for sending or receiving information  over  an  internal  communication\nchannel.\n"
                },
                {
                    "name": "mail_name (Postfix)",
                    "content": "The mail system name that is displayed in Received: headers, in the SMTP greeting ban‐\nner, and in bounced mail.\n"
                },
                {
                    "name": "mail_owner (postfix)",
                    "content": "The UNIX system account that owns the Postfix queue and most Postfix daemon processes.\n"
                },
                {
                    "name": "max_idle (100s)",
                    "content": "The  maximum  amount of time that an idle Postfix daemon process waits for an incoming\nconnection before terminating voluntarily.\n"
                },
                {
                    "name": "max_use (100)",
                    "content": "The maximal number of incoming connections that a Postfix daemon process will  service\nbefore terminating voluntarily.\n"
                },
                {
                    "name": "myhostname (see 'postconf -d' output)",
                    "content": "The internet hostname of this mail system.\n"
                },
                {
                    "name": "mynetworks (see 'postconf -d' output)",
                    "content": "The list of \"trusted\" remote SMTP clients that have more privileges than \"strangers\".\n"
                },
                {
                    "name": "myorigin ($myhostname)",
                    "content": "The domain name that locally-posted mail appears to come from, and that locally posted\nmail is delivered to.\n"
                },
                {
                    "name": "process_id (read-only)",
                    "content": "The process ID of a Postfix command or daemon process.\n"
                },
                {
                    "name": "process_name (read-only)",
                    "content": "The process name of a Postfix command or daemon process.\n"
                },
                {
                    "name": "queue_directory (see 'postconf -d' output)",
                    "content": "The location of the Postfix top-level queue directory.\n"
                },
                {
                    "name": "recipient_delimiter (empty)",
                    "content": "The  set  of  characters that can separate an email address localpart, user name, or a\n.forward file name from its extension.\n"
                },
                {
                    "name": "smtpd_banner ($myhostname ESMTP $mail_name)",
                    "content": "The text that follows the 220 status code in the SMTP greeting banner.\n"
                },
                {
                    "name": "syslog_facility (mail)",
                    "content": "The syslog facility of Postfix logging.\n"
                },
                {
                    "name": "syslog_name (see 'postconf -d' output)",
                    "content": "A prefix that is prepended to the process name in syslog records, so that,  for  exam‐\nple, \"smtpd\" becomes \"prefix/smtpd\".\n\nAvailable in Postfix version 2.2 and later:\n"
                },
                {
                    "name": "smtpd_forbidden_commands (CONNECT GET POST regexp:{{/^[^A-Z]/ Bogus}})",
                    "content": "List  of commands that cause the Postfix SMTP server to immediately terminate the ses‐\nsion with a 221 code.\n\nAvailable in Postfix version 2.5 and later:\n"
                },
                {
                    "name": "smtpd_client_port_logging (no)",
                    "content": "Enable logging of the remote SMTP client port in addition to the hostname and  IP  ad‐\ndress.\n\nAvailable in Postfix 3.3 and later:\n"
                },
                {
                    "name": "service_name (read-only)",
                    "content": "The master.cf service name of a Postfix daemon process.\n\nAvailable in Postfix 3.4 and later:\n"
                },
                {
                    "name": "smtpd_reject_footer_maps (empty)",
                    "content": "Lookup  tables,  indexed by the complete Postfix SMTP server 4xx or 5xx response, with\nreject footer templates.\n"
                }
            ]
        },
        "SEE ALSO": {
            "content": "anvil(8), connection/rate limiting\ncleanup(8), message canonicalization\ntlsmgr(8), TLS session and PRNG management\ntrivial-rewrite(8), address resolver\nverify(8), address verification service\npostconf(5), configuration parameters\nmaster(5), generic daemon options\nmaster(8), process manager\npostlogd(8), Postfix logging\nsyslogd(8), system logging\n",
            "subsections": []
        },
        "README FILES": {
            "content": "Use \"postconf readmedirectory\" or \"postconf htmldirectory\" to locate this information.\nADDRESSCLASSREADME, blocking unknown hosted or relay recipients\nADDRESSREWRITINGREADME, Postfix address manipulation\nBDATREADME, Postfix CHUNKING support\nFILTERREADME, external after-queue content filter\nLOCALRECIPIENTREADME, blocking unknown local recipients\nMILTERREADME, before-queue mail filter applications\nSMTPDACCESSREADME, built-in access policies\nSMTPDPOLICYREADME, external policy server\nSMTPDPROXYREADME, external before-queue content filter\nSASLREADME, Postfix SASL howto\nTLSREADME, Postfix STARTTLS howto\nVERPREADME, Postfix XVERP extension\nXCLIENTREADME, Postfix XCLIENT extension\nXFORWARDREADME, Postfix XFORWARD extension\n",
            "subsections": []
        },
        "LICENSE": {
            "content": "The Secure Mailer license must be distributed with this software.\n\nAUTHOR(S)\nWietse Venema\nIBM T.J. Watson Research\nP.O. Box 704\nYorktown Heights, NY 10598, USA\n\nWietse Venema\nGoogle, Inc.\n111 8th Avenue\nNew York, NY 10011, USA\n\nSASL support originally by:\nTill Franke\nSuSE Rhein/Main AG\n65760 Eschborn, Germany\n\nTLS support originally by:\nLutz Jaenicke\nBTU Cottbus\nAllgemeine Elektrotechnik\nUniversitaetsplatz 3-4\nD-03044 Cottbus, Germany\n\nRevised TLS support by:\nVictor Duchovni\nMorgan Stanley\n\nSMTPD(8postfix)",
            "subsections": []
        }
    },
    "summary": "smtpd - Postfix SMTP server",
    "flags": [],
    "examples": [],
    "see_also": [
        {
            "name": "anvil",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/anvil/8/json"
        },
        {
            "name": "cleanup",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/cleanup/8/json"
        },
        {
            "name": "tlsmgr",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/tlsmgr/8/json"
        },
        {
            "name": "trivial-rewrite",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/trivial-rewrite/8/json"
        },
        {
            "name": "verify",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/verify/8/json"
        },
        {
            "name": "postconf",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/postconf/5/json"
        },
        {
            "name": "master",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/master/5/json"
        },
        {
            "name": "master",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/master/8/json"
        },
        {
            "name": "postlogd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/postlogd/8/json"
        },
        {
            "name": "syslogd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/syslogd/8/json"
        }
    ]
}