Sender Verification

Questions and answers about how to do stuff
Post Reply
nicola.piazzi
Posts: 388
Joined: 23 Apr 2015 09:45

Sender Verification

Post by nicola.piazzi »

Postfix can do sender verification, and can mantain a cache table to avoid frequantly verifications of same address.
But sender verification is too aggressive, i think that is bnot a good thing to reject unverified addresses
Is there something in spamassassin so unverified can assigned a score ?
A way can be to use postfix to create a header but accept messages marking

someone know how ?
warlord
Posts: 19
Joined: 16 May 2019 21:21

Re: Sender Verification

Post by warlord »

I don't have an answer but I am migrating from a postfix+maia-mailguard to efa-based solution. I've been using sender-verify on the old system and yes, it does have many false-positives and blocks valid email, but it's also extremely important in cutting down spam. So yes, I would definitely agree that some way to get SA to process would be useful, provided there is some way to trust the header. If the header can be forged then an attacker could just create it a priori and SA would accept it.

Alternatively, you can just enable sender_verify in postfix on EFA (which I am still considering doing).
Post Reply