Skip to content

restrict trusted Postfix networks by default#387

Merged
crazy-max merged 1 commit intoanonaddy:masterfrom
crazy-max:postfix-mynetworks
May 2, 2026
Merged

restrict trusted Postfix networks by default#387
crazy-max merged 1 commit intoanonaddy:masterfrom
crazy-max:postfix-mynetworks

Conversation

@crazy-max
Copy link
Copy Markdown
Member

fixes #339
fixes #290
fixes #317
fixes #338

The default mynetworks value is now loopback-only, and POSTFIX_MYNETWORKS can be set explicitly for deployments that need trusted SMTP submitters.

Trusting all RFC1918 ranges by default can make published SMTP ports behave like an open relay when Docker or a proxy presents external clients as private bridge addresses.

@crazy-max crazy-max marked this pull request as ready for review May 2, 2026 21:45
@crazy-max crazy-max merged commit f3f26e9 into anonaddy:master May 2, 2026
5 checks passed
@crazy-max crazy-max deleted the postfix-mynetworks branch May 2, 2026 21:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant