forked from drew/smtprelay
Compare commits
102 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
813bd9ebe7 | ||
|
|
ee8a5dd989 | ||
|
|
6602836166 | ||
|
|
cdc0fe931b | ||
|
|
e5f27e02e5 | ||
|
|
dffe0bb5bb | ||
|
|
20ad1e84f9 | ||
|
|
db1238bf2d | ||
|
|
d9167eece5 | ||
|
|
e98a1c6f25 | ||
|
|
f0aefc194d | ||
|
|
bfd156e5f3 | ||
|
|
682feef610 | ||
|
|
eea3c4edaa | ||
|
|
cf25c2d0a0 | ||
|
|
774651b0f6 | ||
|
|
5cd3729b1f | ||
|
|
5b38a30349 | ||
|
|
d7585bec9b | ||
|
|
c8f62e42c8 | ||
|
|
00df491340 | ||
|
|
1bf205e7d8 | ||
|
|
c83544bd90 | ||
|
|
e3ba45ede2 | ||
|
|
f69d1f0114 | ||
|
|
e9a2b9ad5a | ||
|
|
7e3dbd515d | ||
|
|
8cc31a918b | ||
|
|
26477177fe | ||
|
|
44560c9a0c | ||
|
|
c21c13cc7a | ||
|
|
1617155f1e | ||
|
|
81ea0c7944 | ||
|
|
d9a09a20da | ||
|
|
d5d4e7a821 | ||
|
|
77ab4485b2 | ||
|
|
ce97293e33 | ||
|
|
5cd81cd7e4 | ||
|
|
62bb2becbc | ||
|
|
a2826e949e | ||
|
|
64872c0bea | ||
|
|
cdc4e572db | ||
|
|
5e78bbe643 | ||
|
|
b134e426d7 | ||
|
|
9c230182da | ||
|
|
39b8e01226 | ||
|
|
bf8c222ac1 | ||
|
|
875264837e | ||
|
|
32d0206af0 | ||
|
|
b7f3701502 | ||
|
|
cf927508dd | ||
|
|
4221919689 | ||
|
|
4f1148d77b | ||
|
|
32c43efd0c | ||
|
|
362a64dd8a | ||
|
|
bf58b2b4c8 | ||
|
|
ed13816dcd | ||
|
|
dd7905e60e | ||
|
|
5076988ddf | ||
|
|
dafbc327aa | ||
|
|
48926964bf | ||
|
|
5757db3a37 | ||
|
|
a527a147be | ||
|
|
8c0a6aab20 | ||
|
|
5be2f3aa4b | ||
|
|
2b046297ea | ||
|
|
f0d39401d4 | ||
|
|
b5fcf8e0bb | ||
|
|
016ef762fb | ||
|
|
6afc87968c | ||
|
|
b32b5690bf | ||
|
|
38aa05c9f4 | ||
|
|
03d109ff8b | ||
|
|
6c691f3cea | ||
|
|
c6b5e244eb | ||
|
|
0ee982ea31 | ||
|
|
287395ad91 | ||
|
|
3aecd3c6d6 | ||
|
|
f8960053e8 | ||
|
|
db5512d47b | ||
|
|
fd063ad879 | ||
|
|
85bdd060e3 | ||
|
|
5be6165865 | ||
|
|
b64a34becf | ||
|
|
a2ea5ab49e | ||
|
|
94957d944f | ||
|
|
a5db5e1ff5 | ||
|
|
94776b27d9 | ||
|
|
81bc7addc7 | ||
|
|
e9bfe53f18 | ||
|
|
32032c297c | ||
|
|
53e52de279 | ||
|
|
02810c0a50 | ||
|
|
6b21f52037 | ||
|
|
544bd081ff | ||
|
|
6a28f939de | ||
|
|
f0392bdf09 | ||
|
|
3f627d3281 | ||
|
|
d8860fc917 | ||
|
|
ebb53ea1b6 | ||
|
|
a5ee525825 | ||
|
|
441a53cfd9 |
8
.github/workflows/codeql-analysis.yml
vendored
8
.github/workflows/codeql-analysis.yml
vendored
@@ -25,7 +25,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v3
|
||||||
with:
|
with:
|
||||||
# We must fetch at least the immediate parents so that if this is
|
# We must fetch at least the immediate parents so that if this is
|
||||||
# a pull request then we can checkout the head.
|
# a pull request then we can checkout the head.
|
||||||
@@ -38,7 +38,7 @@ jobs:
|
|||||||
|
|
||||||
# Initializes the CodeQL tools for scanning.
|
# Initializes the CodeQL tools for scanning.
|
||||||
- name: Initialize CodeQL
|
- name: Initialize CodeQL
|
||||||
uses: github/codeql-action/init@v1
|
uses: github/codeql-action/init@v2
|
||||||
with:
|
with:
|
||||||
languages: ${{ matrix.language }}
|
languages: ${{ matrix.language }}
|
||||||
# If you wish to specify custom queries, you can do so here or in a config file.
|
# If you wish to specify custom queries, you can do so here or in a config file.
|
||||||
@@ -49,7 +49,7 @@ jobs:
|
|||||||
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
|
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
|
||||||
# If this step fails, then you should remove it and run the build manually (see below)
|
# If this step fails, then you should remove it and run the build manually (see below)
|
||||||
- name: Autobuild
|
- name: Autobuild
|
||||||
uses: github/codeql-action/autobuild@v1
|
uses: github/codeql-action/autobuild@v2
|
||||||
|
|
||||||
# ℹ️ Command-line programs to run using the OS shell.
|
# ℹ️ Command-line programs to run using the OS shell.
|
||||||
# 📚 https://git.io/JvXDl
|
# 📚 https://git.io/JvXDl
|
||||||
@@ -63,4 +63,4 @@ jobs:
|
|||||||
# make release
|
# make release
|
||||||
|
|
||||||
- name: Perform CodeQL Analysis
|
- name: Perform CodeQL Analysis
|
||||||
uses: github/codeql-action/analyze@v1
|
uses: github/codeql-action/analyze@v2
|
||||||
|
|||||||
13
.github/workflows/go.yml
vendored
13
.github/workflows/go.yml
vendored
@@ -1,5 +1,5 @@
|
|||||||
name: Go
|
name: Go
|
||||||
on: [push]
|
on: [push, pull_request]
|
||||||
jobs:
|
jobs:
|
||||||
|
|
||||||
build:
|
build:
|
||||||
@@ -7,14 +7,14 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
|
|
||||||
- name: Set up Go 1.16
|
- name: Set up Go 1.18
|
||||||
uses: actions/setup-go@v2.1.3
|
uses: actions/setup-go@v3
|
||||||
with:
|
with:
|
||||||
go-version: 1.16
|
go-version: 1.18
|
||||||
id: go
|
id: go
|
||||||
|
|
||||||
- name: Check out code into the Go module directory
|
- name: Check out code into the Go module directory
|
||||||
uses: actions/checkout@v1
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Get dependencies
|
- name: Get dependencies
|
||||||
run: |
|
run: |
|
||||||
@@ -22,3 +22,6 @@ jobs:
|
|||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
run: go build -v .
|
run: go build -v .
|
||||||
|
|
||||||
|
- name: Test
|
||||||
|
run: go test -v .
|
||||||
|
|||||||
8
.github/workflows/release.yaml
vendored
8
.github/workflows/release.yaml
vendored
@@ -11,20 +11,20 @@ jobs:
|
|||||||
strategy:
|
strategy:
|
||||||
matrix:
|
matrix:
|
||||||
goos: [freebsd, linux, windows]
|
goos: [freebsd, linux, windows]
|
||||||
goarch: ["386", amd64]
|
goarch: [amd64, arm64]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2
|
- uses: actions/checkout@v3
|
||||||
|
|
||||||
- name: Set APP_VERSION env
|
- name: Set APP_VERSION env
|
||||||
run: echo APP_VERSION=$(echo ${GITHUB_REF} | rev | cut -d'/' -f 1 | rev ) >> ${GITHUB_ENV}
|
run: echo APP_VERSION=$(echo ${GITHUB_REF} | rev | cut -d'/' -f 1 | rev ) >> ${GITHUB_ENV}
|
||||||
- name: Set BUILD_TIME env
|
- name: Set BUILD_TIME env
|
||||||
run: echo BUILD_TIME=$(date) >> ${GITHUB_ENV}
|
run: echo BUILD_TIME=$(date) >> ${GITHUB_ENV}
|
||||||
|
|
||||||
- uses: wangyoucao577/go-release-action@v1.16
|
- uses: wangyoucao577/go-release-action@v1.30
|
||||||
with:
|
with:
|
||||||
github_token: ${{ secrets.GITHUB_TOKEN }}
|
github_token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
goos: ${{ matrix.goos }}
|
goos: ${{ matrix.goos }}
|
||||||
goarch: ${{ matrix.goarch }}
|
goarch: ${{ matrix.goarch }}
|
||||||
goversion: "https://golang.org/dl/go1.16.3.linux-amd64.tar.gz"
|
goversion: 1.18
|
||||||
extra_files: LICENSE README.md smtprelay.ini
|
extra_files: LICENSE README.md smtprelay.ini
|
||||||
ldflags: -s -w -X "main.appVersion=${{ env.APP_VERSION }}" -X "main.buildTime=${{ env.BUILD_TIME }}"
|
ldflags: -s -w -X "main.appVersion=${{ env.APP_VERSION }}" -X "main.buildTime=${{ env.BUILD_TIME }}"
|
||||||
|
|||||||
@@ -16,16 +16,17 @@ configure.
|
|||||||
|
|
||||||
My use case is simple. I need to send automatically generated mails from
|
My use case is simple. I need to send automatically generated mails from
|
||||||
cron via msmtp/sSMTP/dma, mails from various services and network printers
|
cron via msmtp/sSMTP/dma, mails from various services and network printers
|
||||||
to GMail without giving away my GMail credentials to each device which
|
via a remote SMTP server without giving away my mail credentials to each
|
||||||
produces mail.
|
device which produces mail.
|
||||||
|
|
||||||
|
|
||||||
## Main features
|
## Main features
|
||||||
|
|
||||||
|
* Simple configuration with ini file .env file or environment variables
|
||||||
* Supports SMTPS/TLS (465), STARTTLS (587) and unencrypted SMTP (25)
|
* Supports SMTPS/TLS (465), STARTTLS (587) and unencrypted SMTP (25)
|
||||||
* Checks for sender, receiver, client IP
|
* Checks for sender, receiver, client IP
|
||||||
* Authentication support with file (LOGIN, PLAIN)
|
* Authentication support with file (LOGIN, PLAIN)
|
||||||
* Enforce encryption for authentication
|
* Enforce encryption for authentication
|
||||||
* Forwards all mail to a smarthost (GMail, MailGun or any other SMTP server)
|
* Forwards all mail to a smarthost (any SMTP server)
|
||||||
* Small codebase
|
* Small codebase
|
||||||
* IPv6 support
|
* IPv6 support
|
||||||
|
|||||||
239
config.go
239
config.go
@@ -1,13 +1,17 @@
|
|||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bufio"
|
||||||
"flag"
|
"flag"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
"net"
|
"net"
|
||||||
"net/smtp"
|
"os"
|
||||||
"regexp"
|
"regexp"
|
||||||
"strings"
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
"github.com/vharitonsky/iniflags"
|
"github.com/peterbourgon/ff/v3"
|
||||||
"github.com/sirupsen/logrus"
|
"github.com/sirupsen/logrus"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -17,37 +21,50 @@ var (
|
|||||||
)
|
)
|
||||||
|
|
||||||
var (
|
var (
|
||||||
logFile = flag.String("logfile", "", "Path to logfile")
|
flagset = flag.NewFlagSet("smtprelay", flag.ContinueOnError)
|
||||||
logFormat = flag.String("log_format", "default", "Log output format")
|
|
||||||
logLevel = flag.String("log_level", "info", "Minimum log level to output")
|
// config flags
|
||||||
hostName = flag.String("hostname", "localhost.localdomain", "Server hostname")
|
logFile = flagset.String("logfile", "", "Path to logfile")
|
||||||
welcomeMsg = flag.String("welcome_msg", "", "Welcome message for SMTP session")
|
logFormat = flagset.String("log_format", "default", "Log output format")
|
||||||
listenStr = flag.String("listen", "127.0.0.1:25 [::1]:25", "Address and port to listen for incoming SMTP")
|
logLevel = flagset.String("log_level", "info", "Minimum log level to output")
|
||||||
|
hostName = flagset.String("hostname", "localhost.localdomain", "Server hostname")
|
||||||
|
welcomeMsg = flagset.String("welcome_msg", "", "Welcome message for SMTP session")
|
||||||
|
listenStr = flagset.String("listen", "127.0.0.1:25 [::1]:25", "Address and port to listen for incoming SMTP")
|
||||||
|
localCert = flagset.String("local_cert", "", "SSL certificate for STARTTLS/TLS")
|
||||||
|
localKey = flagset.String("local_key", "", "SSL private key for STARTTLS/TLS")
|
||||||
|
localForceTLS = flagset.Bool("local_forcetls", false, "Force STARTTLS (needs local_cert and local_key)")
|
||||||
|
readTimeoutStr = flagset.String("read_timeout", "60s", "Socket timeout for read operations")
|
||||||
|
writeTimeoutStr = flagset.String("write_timeout", "60s", "Socket timeout for write operations")
|
||||||
|
dataTimeoutStr = flagset.String("data_timeout", "5m", "Socket timeout for DATA command")
|
||||||
|
maxConnections = flagset.Int("max_connections", 100, "Max concurrent connections, use -1 to disable")
|
||||||
|
maxMessageSize = flagset.Int("max_message_size", 10240000, "Max message size in bytes")
|
||||||
|
maxRecipients = flagset.Int("max_recipients", 100, "Max RCPT TO calls for each envelope")
|
||||||
|
allowedNetsStr = flagset.String("allowed_nets", "127.0.0.0/8 ::1/128", "Networks allowed to send mails")
|
||||||
|
allowedSenderStr = flagset.String("allowed_sender", "", "Regular expression for valid FROM EMail addresses")
|
||||||
|
allowedRecipStr = flagset.String("allowed_recipients", "", "Regular expression for valid TO EMail addresses")
|
||||||
|
allowedUsers = flagset.String("allowed_users", "", "Path to file with valid users/passwords")
|
||||||
|
command = flagset.String("command", "", "Path to pipe command")
|
||||||
|
remotesStr = flagset.String("remotes", "", "Outgoing SMTP servers")
|
||||||
|
|
||||||
|
// additional flags
|
||||||
|
_ = flagset.String("config", "", "Path to config file (ini format)")
|
||||||
|
versionInfo = flagset.Bool("version", false, "Show version information")
|
||||||
|
|
||||||
|
// internal
|
||||||
listenAddrs = []protoAddr{}
|
listenAddrs = []protoAddr{}
|
||||||
localCert = flag.String("local_cert", "", "SSL certificate for STARTTLS/TLS")
|
readTimeout time.Duration
|
||||||
localKey = flag.String("local_key", "", "SSL private key for STARTTLS/TLS")
|
writeTimeout time.Duration
|
||||||
localForceTLS = flag.Bool("local_forcetls", false, "Force STARTTLS (needs local_cert and local_key)")
|
dataTimeout time.Duration
|
||||||
allowedNetsStr = flag.String("allowed_nets", "127.0.0.0/8 ::1/128", "Networks allowed to send mails")
|
|
||||||
allowedNets = []*net.IPNet{}
|
allowedNets = []*net.IPNet{}
|
||||||
allowedSenderStr = flag.String("allowed_sender", "", "Regular expression for valid FROM EMail addresses")
|
|
||||||
allowedSender *regexp.Regexp
|
allowedSender *regexp.Regexp
|
||||||
allowedRecipStr = flag.String("allowed_recipients", "", "Regular expression for valid TO EMail addresses")
|
|
||||||
allowedRecipients *regexp.Regexp
|
allowedRecipients *regexp.Regexp
|
||||||
allowedUsers = flag.String("allowed_users", "", "Path to file with valid users/passwords")
|
remotes = []*Remote{}
|
||||||
remoteHost = flag.String("remote_host", "", "Outgoing SMTP server")
|
|
||||||
remoteUser = flag.String("remote_user", "", "Username for authentication on outgoing SMTP server")
|
|
||||||
remotePass = flag.String("remote_pass", "", "Password for authentication on outgoing SMTP server")
|
|
||||||
remoteAuthStr = flag.String("remote_auth", "none", "Auth method on outgoing SMTP server (none, plain, login)")
|
|
||||||
remoteAuth smtp.Auth
|
|
||||||
remoteSender = flag.String("remote_sender", "", "Sender e-mail address on outgoing SMTP server")
|
|
||||||
versionInfo = flag.Bool("version", false, "Show version information")
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func localAuthRequired() bool {
|
func localAuthRequired() bool {
|
||||||
return *allowedUsers != ""
|
return *allowedUsers != ""
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
func setupAllowedNetworks() {
|
func setupAllowedNetworks() {
|
||||||
for _, netstr := range splitstr(*allowedNetsStr, ' ') {
|
for _, netstr := range splitstr(*allowedNetsStr, ' ') {
|
||||||
baseIP, allowedNet, err := net.ParseCIDR(netstr)
|
baseIP, allowedNet, err := net.ParseCIDR(netstr)
|
||||||
@@ -61,7 +78,7 @@ func setupAllowedNetworks() {
|
|||||||
// meaning the address refers to a host and not a network.
|
// meaning the address refers to a host and not a network.
|
||||||
if !allowedNet.IP.Equal(baseIP) {
|
if !allowedNet.IP.Equal(baseIP) {
|
||||||
log.WithFields(logrus.Fields{
|
log.WithFields(logrus.Fields{
|
||||||
"given_net": netstr,
|
"given_net": netstr,
|
||||||
"proper_net": allowedNet,
|
"proper_net": allowedNet,
|
||||||
}).Fatal("Invalid network in allowed_nets (host bits set)")
|
}).Fatal("Invalid network in allowed_nets (host bits set)")
|
||||||
}
|
}
|
||||||
@@ -73,7 +90,7 @@ func setupAllowedNetworks() {
|
|||||||
func setupAllowedPatterns() {
|
func setupAllowedPatterns() {
|
||||||
var err error
|
var err error
|
||||||
|
|
||||||
if (*allowedSenderStr != "") {
|
if *allowedSenderStr != "" {
|
||||||
allowedSender, err = regexp.Compile(*allowedSenderStr)
|
allowedSender, err = regexp.Compile(*allowedSenderStr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.WithField("allowed_sender", *allowedSenderStr).
|
log.WithField("allowed_sender", *allowedSenderStr).
|
||||||
@@ -82,7 +99,7 @@ func setupAllowedPatterns() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (*allowedRecipStr != "") {
|
if *allowedRecipStr != "" {
|
||||||
allowedRecipients, err = regexp.Compile(*allowedRecipStr)
|
allowedRecipients, err = regexp.Compile(*allowedRecipStr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.WithField("allowed_recipients", *allowedRecipStr).
|
log.WithField("allowed_recipients", *allowedRecipStr).
|
||||||
@@ -92,47 +109,18 @@ func setupAllowedPatterns() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func setupRemotes() {
|
||||||
|
logger := log.WithField("remotes", *remotesStr)
|
||||||
|
|
||||||
func setupRemoteAuth() {
|
if *remotesStr != "" {
|
||||||
logger := log.WithField("remote_auth", *remoteAuthStr)
|
for _, remoteURL := range strings.Split(*remotesStr, " ") {
|
||||||
|
r, err := ParseRemote(remoteURL)
|
||||||
|
if err != nil {
|
||||||
|
logger.Fatal(fmt.Sprintf("error parsing url: '%s': %v", remoteURL, err))
|
||||||
|
}
|
||||||
|
|
||||||
// Remote auth disabled?
|
remotes = append(remotes, r)
|
||||||
if *remoteAuthStr == "" || *remoteAuthStr == "none" {
|
|
||||||
if *remoteUser != "" {
|
|
||||||
logger.Fatal("remote_user given but not used")
|
|
||||||
}
|
}
|
||||||
if *remotePass != "" {
|
|
||||||
logger.Fatal("remote_pass given but not used")
|
|
||||||
}
|
|
||||||
|
|
||||||
// No auth; use empty default
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// We need a username, password, and remote host
|
|
||||||
if *remoteUser == "" {
|
|
||||||
logger.Fatal("remote_user required but empty")
|
|
||||||
}
|
|
||||||
if *remotePass == "" {
|
|
||||||
logger.Fatal("remote_pass required but empty")
|
|
||||||
}
|
|
||||||
if *remoteHost == "" {
|
|
||||||
logger.Fatal("remote_auth without remote_host is pointless")
|
|
||||||
}
|
|
||||||
|
|
||||||
host, _, err := net.SplitHostPort(*remoteHost)
|
|
||||||
if err != nil {
|
|
||||||
logger.WithField("remote_host", *remoteHost).
|
|
||||||
Fatal("Invalid remote_host")
|
|
||||||
}
|
|
||||||
|
|
||||||
switch *remoteAuthStr {
|
|
||||||
case "plain":
|
|
||||||
remoteAuth = smtp.PlainAuth("", *remoteUser, *remotePass, host)
|
|
||||||
case "login":
|
|
||||||
remoteAuth = LoginAuth(*remoteUser, *remotePass)
|
|
||||||
default:
|
|
||||||
logger.Fatal("Invalid remote_auth type")
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -144,13 +132,13 @@ type protoAddr struct {
|
|||||||
func splitProto(s string) protoAddr {
|
func splitProto(s string) protoAddr {
|
||||||
idx := strings.Index(s, "://")
|
idx := strings.Index(s, "://")
|
||||||
if idx == -1 {
|
if idx == -1 {
|
||||||
return protoAddr {
|
return protoAddr{
|
||||||
address: s,
|
address: s,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return protoAddr {
|
return protoAddr{
|
||||||
protocol: s[0 : idx],
|
protocol: s[0:idx],
|
||||||
address: s[idx+3 : len(s)],
|
address: s[idx+3:],
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -161,26 +149,127 @@ func setupListeners() {
|
|||||||
if localAuthRequired() && pa.protocol == "" {
|
if localAuthRequired() && pa.protocol == "" {
|
||||||
log.WithField("address", pa.address).
|
log.WithField("address", pa.address).
|
||||||
Fatal("Local authentication (via allowed_users file) " +
|
Fatal("Local authentication (via allowed_users file) " +
|
||||||
"not allowed with non-TLS listener")
|
"not allowed with non-TLS listener")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
listenAddrs = append(listenAddrs, pa)
|
listenAddrs = append(listenAddrs, pa)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func setupTimeouts() {
|
||||||
|
var err error
|
||||||
|
|
||||||
|
readTimeout, err = time.ParseDuration(*readTimeoutStr)
|
||||||
|
if err != nil {
|
||||||
|
log.WithField("read_timeout", *readTimeoutStr).
|
||||||
|
WithError(err).
|
||||||
|
Fatal("read_timeout duration string invalid")
|
||||||
|
}
|
||||||
|
if readTimeout.Seconds() < 1 {
|
||||||
|
log.WithField("read_timeout", *readTimeoutStr).
|
||||||
|
Fatal("read_timeout less than one second")
|
||||||
|
}
|
||||||
|
|
||||||
|
writeTimeout, err = time.ParseDuration(*writeTimeoutStr)
|
||||||
|
if err != nil {
|
||||||
|
log.WithField("write_timeout", *writeTimeoutStr).
|
||||||
|
WithError(err).
|
||||||
|
Fatal("write_timeout duration string invalid")
|
||||||
|
}
|
||||||
|
if writeTimeout.Seconds() < 1 {
|
||||||
|
log.WithField("write_timeout", *writeTimeoutStr).
|
||||||
|
Fatal("write_timeout less than one second")
|
||||||
|
}
|
||||||
|
|
||||||
|
dataTimeout, err = time.ParseDuration(*dataTimeoutStr)
|
||||||
|
if err != nil {
|
||||||
|
log.WithField("data_timeout", *dataTimeoutStr).
|
||||||
|
WithError(err).
|
||||||
|
Fatal("data_timeout duration string invalid")
|
||||||
|
}
|
||||||
|
if dataTimeout.Seconds() < 1 {
|
||||||
|
log.WithField("data_timeout", *dataTimeoutStr).
|
||||||
|
Fatal("data_timeout less than one second")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func ConfigLoad() {
|
func ConfigLoad() {
|
||||||
iniflags.Parse()
|
// use .env file if it exists
|
||||||
|
if _, err := os.Stat(".env"); err == nil {
|
||||||
|
if err := ff.Parse(flagset, os.Args[1:],
|
||||||
|
ff.WithEnvVarPrefix("smtprelay"),
|
||||||
|
ff.WithConfigFile(".env"),
|
||||||
|
ff.WithConfigFileParser(ff.EnvParser),
|
||||||
|
); err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "error: %v\n", err)
|
||||||
|
os.Exit(1)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
// use env variables and smtprelay.ini file
|
||||||
|
if err := ff.Parse(flagset, os.Args[1:],
|
||||||
|
ff.WithEnvVarPrefix("smtprelay"),
|
||||||
|
ff.WithConfigFileFlag("config"),
|
||||||
|
ff.WithConfigFileParser(IniParser),
|
||||||
|
); err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "error: %v\n", err)
|
||||||
|
os.Exit(1)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Set up logging as soon as possible
|
// Set up logging as soon as possible
|
||||||
setupLogger()
|
setupLogger()
|
||||||
|
|
||||||
if (*remoteHost == "") {
|
if *versionInfo {
|
||||||
log.Warn("remote_host not set; mail will not be forwarded!")
|
fmt.Printf("smtprelay/%s (%s)\n", appVersion, buildTime)
|
||||||
|
os.Exit(0)
|
||||||
|
}
|
||||||
|
|
||||||
|
if *remotesStr == "" && *command == "" {
|
||||||
|
log.Warn("no remotes or command set; mail will not be forwarded!")
|
||||||
}
|
}
|
||||||
|
|
||||||
setupAllowedNetworks()
|
setupAllowedNetworks()
|
||||||
setupAllowedPatterns()
|
setupAllowedPatterns()
|
||||||
setupRemoteAuth()
|
setupRemotes()
|
||||||
setupListeners()
|
setupListeners()
|
||||||
|
setupTimeouts()
|
||||||
|
}
|
||||||
|
|
||||||
|
// IniParser is a parser for config files in classic key/value style format. Each
|
||||||
|
// line is tokenized as a single key/value pair. The first "=" delimited
|
||||||
|
// token in the line is interpreted as the flag name, and all remaining tokens
|
||||||
|
// are interpreted as the value. Any leading hyphens on the flag name are
|
||||||
|
// ignored.
|
||||||
|
func IniParser(r io.Reader, set func(name, value string) error) error {
|
||||||
|
s := bufio.NewScanner(r)
|
||||||
|
for s.Scan() {
|
||||||
|
line := strings.TrimSpace(s.Text())
|
||||||
|
if line == "" {
|
||||||
|
continue // skip empties
|
||||||
|
}
|
||||||
|
|
||||||
|
if line[0] == '#' || line[0] == ';' {
|
||||||
|
continue // skip comments
|
||||||
|
}
|
||||||
|
|
||||||
|
var (
|
||||||
|
name string
|
||||||
|
value string
|
||||||
|
index = strings.IndexRune(line, '=')
|
||||||
|
)
|
||||||
|
if index < 0 {
|
||||||
|
name, value = line, "true" // boolean option
|
||||||
|
} else {
|
||||||
|
name, value = strings.TrimSpace(line[:index]), strings.Trim(strings.TrimSpace(line[index+1:]), "\"")
|
||||||
|
}
|
||||||
|
|
||||||
|
if i := strings.Index(value, " #"); i >= 0 {
|
||||||
|
value = strings.TrimSpace(value[:i])
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := set(name, value); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -6,24 +6,24 @@ import (
|
|||||||
|
|
||||||
func TestSplitProto(t *testing.T) {
|
func TestSplitProto(t *testing.T) {
|
||||||
var tests = []struct {
|
var tests = []struct {
|
||||||
input string
|
input string
|
||||||
proto string
|
proto string
|
||||||
addr string
|
addr string
|
||||||
}{
|
}{
|
||||||
{
|
{
|
||||||
input: "localhost",
|
input: "localhost",
|
||||||
proto: "",
|
proto: "",
|
||||||
addr: "localhost",
|
addr: "localhost",
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
input: "tls://my.local.domain",
|
input: "tls://my.local.domain",
|
||||||
proto: "tls",
|
proto: "tls",
|
||||||
addr: "my.local.domain",
|
addr: "my.local.domain",
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
input: "starttls://my.local.domain",
|
input: "starttls://my.local.domain",
|
||||||
proto: "starttls",
|
proto: "starttls",
|
||||||
addr: "my.local.domain",
|
addr: "my.local.domain",
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
20
go.mod
20
go.mod
@@ -1,11 +1,19 @@
|
|||||||
module github.com/decke/smtprelay
|
module github.com/decke/smtprelay
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/chrj/smtpd v0.3.0
|
github.com/chrj/smtpd v0.3.1
|
||||||
github.com/google/uuid v1.2.0
|
github.com/google/uuid v1.3.0
|
||||||
github.com/sirupsen/logrus v1.8.1
|
github.com/peterbourgon/ff/v3 v3.3.0
|
||||||
github.com/vharitonsky/iniflags v0.0.0-20180513140207-a33cd0b5f3de
|
github.com/sirupsen/logrus v1.9.0
|
||||||
golang.org/x/crypto v0.0.0-20201221181555-eec23a3978ad
|
github.com/stretchr/testify v1.8.0
|
||||||
|
golang.org/x/crypto v0.0.0-20220411220226-7b82a4e95df4
|
||||||
)
|
)
|
||||||
|
|
||||||
go 1.13
|
require (
|
||||||
|
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||||
|
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||||
|
golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8 // indirect
|
||||||
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||||
|
)
|
||||||
|
|
||||||
|
go 1.18
|
||||||
|
|||||||
44
go.sum
44
go.sum
@@ -1,24 +1,28 @@
|
|||||||
github.com/chrj/smtpd v0.3.0 h1:cw1LSHDOz7N3XbkcZSF/bue9dh7ATKk5ZksfBztV6b0=
|
github.com/chrj/smtpd v0.3.1 h1:kogHFkbFdKaoH3bgZkqNC9uVtKYOFfM3uV3rroBdooE=
|
||||||
github.com/chrj/smtpd v0.3.0/go.mod h1:1hmG9KbrE10JG1SmvG79Krh4F6713oUrw2+gRp1oSYk=
|
github.com/chrj/smtpd v0.3.1/go.mod h1:JtABvV/LzvLmEIzy0NyDnrfMGOMd8wy5frAokwf6J9Q=
|
||||||
|
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
||||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
github.com/eaigner/dkim v0.0.0-20150301120808-6fe4a7ee9cfb/go.mod h1:FSCIHbrqk7D01Mj8y/jW+NS1uoCerr+ad+IckTHTFf4=
|
github.com/google/uuid v1.3.0 h1:t6JiXgmwXMjEs8VusXIJk2BXHsn+wx8BZdTaoZ5fu7I=
|
||||||
github.com/google/uuid v1.2.0 h1:qJYtXnJRWmpe7m/3XlyhrsLrEURqHRM2kxzoxXqyUDs=
|
github.com/google/uuid v1.3.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
|
||||||
github.com/google/uuid v1.2.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
|
github.com/peterbourgon/ff/v3 v3.3.0 h1:PaKe7GW8orVFh8Unb5jNHS+JZBwWUMa2se0HM6/BI24=
|
||||||
|
github.com/peterbourgon/ff/v3 v3.3.0/go.mod h1:zjJVUhx+twciwfDl0zBcFzl4dW8axCRyXE/eKY9RztQ=
|
||||||
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
|
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
|
||||||
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||||
github.com/sirupsen/logrus v1.8.1 h1:dJKuHgqk1NNQlqoA6BTlM1Wf9DOH3NBjQyu0h9+AZZE=
|
github.com/sirupsen/logrus v1.9.0 h1:trlNQbNUG3OdDrDil03MCb1H2o9nJ1x4/5LYw7byDE0=
|
||||||
github.com/sirupsen/logrus v1.8.1/go.mod h1:yWOB1SBYBC5VeMP7gHvWumXLIWorT60ONWic61uBYv0=
|
github.com/sirupsen/logrus v1.9.0/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ=
|
||||||
github.com/stretchr/testify v1.2.2 h1:bSDNvY7ZPG5RlJ8otE/7V6gMiyenm9RtJ7IUVIAoJ1w=
|
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
||||||
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
|
github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw=
|
||||||
github.com/vharitonsky/iniflags v0.0.0-20180513140207-a33cd0b5f3de h1:fkw+7JkxF3U1GzQoX9h69Wvtvxajo5Rbzy6+YMMzPIg=
|
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
||||||
github.com/vharitonsky/iniflags v0.0.0-20180513140207-a33cd0b5f3de/go.mod h1:irMhzlTz8+fVFj6CH2AN2i+WI5S6wWFtK3MBCIxIpyI=
|
github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
||||||
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
github.com/stretchr/testify v1.8.0 h1:pSgiaMZlXftHpm5L7V1+rVB+AZJydKsMxsQBIJw4PKk=
|
||||||
golang.org/x/crypto v0.0.0-20201221181555-eec23a3978ad h1:DN0cp81fZ3njFcrLCytUHRSUkqBjfTo4Tx9RJTWs0EY=
|
github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU=
|
||||||
golang.org/x/crypto v0.0.0-20201221181555-eec23a3978ad/go.mod h1:jdWPYTVW3xRLrWPugEBEK3UY2ZEsg3UU495nc5E+M+I=
|
golang.org/x/crypto v0.0.0-20220411220226-7b82a4e95df4 h1:kUhD7nTDoI3fVd9G4ORWrbV5NY0liEs/Jg2pv5f+bBA=
|
||||||
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
golang.org/x/crypto v0.0.0-20220411220226-7b82a4e95df4/go.mod h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4=
|
||||||
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8 h1:0A+M6Uqn+Eje4kHMK80dtF3JCXC4ykBgQG4Fe06QRhQ=
|
||||||
golang.org/x/sys v0.0.0-20191026070338-33540a1f6037 h1:YyJpGZS1sBuBCzLAR1VEpK193GlqGZbnPFnPV/5Rsb4=
|
golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
golang.org/x/sys v0.0.0-20191026070338-33540a1f6037/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM=
|
||||||
golang.org/x/term v0.0.0-20201117132131-f5c789dd3221/go.mod h1:Nr5EML6q2oocZ2LXRh80K7BxOlk5/8JxuGnuhpl+muw=
|
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||||
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||||
|
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
|
||||||
|
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ func setupLogger() {
|
|||||||
log = logrus.New()
|
log = logrus.New()
|
||||||
|
|
||||||
// Handle logfile
|
// Handle logfile
|
||||||
if (*logFile == "") {
|
if *logFile == "" {
|
||||||
log.SetOutput(os.Stderr)
|
log.SetOutput(os.Stderr)
|
||||||
} else {
|
} else {
|
||||||
writer, err := os.OpenFile(*logFile, os.O_CREATE|os.O_RDWR|os.O_APPEND, 0600)
|
writer, err := os.OpenFile(*logFile, os.O_CREATE|os.O_RDWR|os.O_APPEND, 0600)
|
||||||
|
|||||||
115
main.go
115
main.go
@@ -1,11 +1,12 @@
|
|||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bytes"
|
||||||
"crypto/tls"
|
"crypto/tls"
|
||||||
"fmt"
|
|
||||||
"net"
|
"net"
|
||||||
"net/textproto"
|
"net/textproto"
|
||||||
"os"
|
"os"
|
||||||
|
"os/exec"
|
||||||
"os/signal"
|
"os/signal"
|
||||||
"strings"
|
"strings"
|
||||||
"syscall"
|
"syscall"
|
||||||
@@ -86,7 +87,7 @@ func senderChecker(peer smtpd.Peer, addr string) error {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
// Shouldn't happen: authChecker already validated username+password
|
// Shouldn't happen: authChecker already validated username+password
|
||||||
log.WithFields(logrus.Fields{
|
log.WithFields(logrus.Fields{
|
||||||
"peer": peer.Addr,
|
"peer": peer.Addr,
|
||||||
"username": peer.Username,
|
"username": peer.Username,
|
||||||
}).WithError(err).Warn("could not fetch auth user")
|
}).WithError(err).Warn("could not fetch auth user")
|
||||||
return smtpd.Error{Code: 451, Message: "Bad sender address"}
|
return smtpd.Error{Code: 451, Message: "Bad sender address"}
|
||||||
@@ -94,8 +95,8 @@ func senderChecker(peer smtpd.Peer, addr string) error {
|
|||||||
|
|
||||||
if !addrAllowed(addr, user.allowedAddresses) {
|
if !addrAllowed(addr, user.allowedAddresses) {
|
||||||
log.WithFields(logrus.Fields{
|
log.WithFields(logrus.Fields{
|
||||||
"peer": peer.Addr,
|
"peer": peer.Addr,
|
||||||
"username": peer.Username,
|
"username": peer.Username,
|
||||||
"sender_address": addr,
|
"sender_address": addr,
|
||||||
}).Warn("sender address not allowed for authenticated user")
|
}).Warn("sender address not allowed for authenticated user")
|
||||||
return smtpd.Error{Code: 451, Message: "Bad sender address"}
|
return smtpd.Error{Code: 451, Message: "Bad sender address"}
|
||||||
@@ -114,7 +115,7 @@ func senderChecker(peer smtpd.Peer, addr string) error {
|
|||||||
|
|
||||||
log.WithFields(logrus.Fields{
|
log.WithFields(logrus.Fields{
|
||||||
"sender_address": addr,
|
"sender_address": addr,
|
||||||
"peer": peer.Addr,
|
"peer": peer.Addr,
|
||||||
}).Warn("sender address not allowed by allowed_sender pattern")
|
}).Warn("sender address not allowed by allowed_sender pattern")
|
||||||
return smtpd.Error{Code: 451, Message: "Bad sender address"}
|
return smtpd.Error{Code: 451, Message: "Bad sender address"}
|
||||||
}
|
}
|
||||||
@@ -131,7 +132,7 @@ func recipientChecker(peer smtpd.Peer, addr string) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
log.WithFields(logrus.Fields{
|
log.WithFields(logrus.Fields{
|
||||||
"peer": peer.Addr,
|
"peer": peer.Addr,
|
||||||
"recipient_address": addr,
|
"recipient_address": addr,
|
||||||
}).Warn("recipient address not allowed by allowed_recipients pattern")
|
}).Warn("recipient address not allowed by allowed_recipients pattern")
|
||||||
return smtpd.Error{Code: 451, Message: "Bad recipient address"}
|
return smtpd.Error{Code: 451, Message: "Bad recipient address"}
|
||||||
@@ -141,7 +142,7 @@ func authChecker(peer smtpd.Peer, username string, password string) error {
|
|||||||
err := AuthCheckPassword(username, password)
|
err := AuthCheckPassword(username, password)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.WithFields(logrus.Fields{
|
log.WithFields(logrus.Fields{
|
||||||
"peer": peer.Addr,
|
"peer": peer.Addr,
|
||||||
"username": username,
|
"username": username,
|
||||||
}).WithError(err).Warn("auth error")
|
}).WithError(err).Warn("auth error")
|
||||||
return smtpd.Error{Code: 535, Message: "Authentication credentials invalid"}
|
return smtpd.Error{Code: 535, Message: "Authentication credentials invalid"}
|
||||||
@@ -157,59 +158,72 @@ func mailHandler(peer smtpd.Peer, env smtpd.Envelope) error {
|
|||||||
|
|
||||||
logger := log.WithFields(logrus.Fields{
|
logger := log.WithFields(logrus.Fields{
|
||||||
"from": env.Sender,
|
"from": env.Sender,
|
||||||
"to": env.Recipients,
|
"to": env.Recipients,
|
||||||
"peer": peerIP,
|
"peer": peerIP,
|
||||||
"host": *remoteHost,
|
|
||||||
"uuid": generateUUID(),
|
"uuid": generateUUID(),
|
||||||
})
|
})
|
||||||
|
|
||||||
if (*remoteHost == "") {
|
if *remotesStr == "" && *command == "" {
|
||||||
logger.Warning("remote_host not set; discarding mail")
|
logger.Warning("no remote_host or command set; discarding mail")
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
logger.Info("delivering mail from peer using smarthost")
|
|
||||||
|
|
||||||
env.AddReceivedLine(peer)
|
env.AddReceivedLine(peer)
|
||||||
|
|
||||||
var sender string
|
if *command != "" {
|
||||||
|
cmdLogger := logger.WithField("command", *command)
|
||||||
|
|
||||||
if *remoteSender == "" {
|
var stdout bytes.Buffer
|
||||||
sender = env.Sender
|
var stderr bytes.Buffer
|
||||||
} else {
|
|
||||||
sender = *remoteSender
|
|
||||||
}
|
|
||||||
|
|
||||||
err := SendMail(
|
cmd := exec.Command(*command)
|
||||||
*remoteHost,
|
cmd.Stdin = bytes.NewReader(env.Data)
|
||||||
remoteAuth,
|
cmd.Stdout = &stdout
|
||||||
sender,
|
cmd.Stderr = &stderr
|
||||||
env.Recipients,
|
|
||||||
env.Data,
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
var smtpError smtpd.Error
|
|
||||||
|
|
||||||
switch err.(type) {
|
err := cmd.Run()
|
||||||
case *textproto.Error:
|
if err != nil {
|
||||||
err := err.(*textproto.Error)
|
cmdLogger.WithError(err).Error(stderr.String())
|
||||||
smtpError = smtpd.Error{Code: err.Code, Message: err.Msg}
|
return smtpd.Error{Code: 554, Message: "External command failed"}
|
||||||
|
|
||||||
logger.WithFields(logrus.Fields{
|
|
||||||
"err_code": err.Code,
|
|
||||||
"err_msg": err.Msg,
|
|
||||||
}).Error("delivery failed")
|
|
||||||
default:
|
|
||||||
smtpError = smtpd.Error{Code: 554, Message: "Forwarding failed"}
|
|
||||||
|
|
||||||
logger.WithError(err).
|
|
||||||
Error("delivery failed")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return smtpError
|
cmdLogger.Info("pipe command successful: " + stdout.String())
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, remote := range remotes {
|
||||||
|
logger = logger.WithField("host", remote.Addr)
|
||||||
|
logger.Info("delivering mail from peer using smarthost")
|
||||||
|
|
||||||
|
err := SendMail(
|
||||||
|
remote,
|
||||||
|
env.Sender,
|
||||||
|
env.Recipients,
|
||||||
|
env.Data,
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
var smtpError smtpd.Error
|
||||||
|
|
||||||
|
switch err := err.(type) {
|
||||||
|
case *textproto.Error:
|
||||||
|
smtpError = smtpd.Error{Code: err.Code, Message: err.Msg}
|
||||||
|
|
||||||
|
logger.WithFields(logrus.Fields{
|
||||||
|
"err_code": err.Code,
|
||||||
|
"err_msg": err.Msg,
|
||||||
|
}).Error("delivery failed")
|
||||||
|
default:
|
||||||
|
smtpError = smtpd.Error{Code: 554, Message: "Forwarding failed"}
|
||||||
|
|
||||||
|
logger.WithError(err).
|
||||||
|
Error("delivery failed")
|
||||||
|
}
|
||||||
|
|
||||||
|
return smtpError
|
||||||
|
}
|
||||||
|
|
||||||
|
logger.Debug("delivery successful")
|
||||||
}
|
}
|
||||||
|
|
||||||
logger.Debug("delivery successful")
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -246,7 +260,7 @@ func getTLSConfig() *tls.Config {
|
|||||||
if *localCert == "" || *localKey == "" {
|
if *localCert == "" || *localKey == "" {
|
||||||
log.WithFields(logrus.Fields{
|
log.WithFields(logrus.Fields{
|
||||||
"cert_file": *localCert,
|
"cert_file": *localCert,
|
||||||
"key_file": *localKey,
|
"key_file": *localKey,
|
||||||
}).Fatal("TLS certificate/key file not defined in config")
|
}).Fatal("TLS certificate/key file not defined in config")
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -267,11 +281,6 @@ func getTLSConfig() *tls.Config {
|
|||||||
func main() {
|
func main() {
|
||||||
ConfigLoad()
|
ConfigLoad()
|
||||||
|
|
||||||
if *versionInfo {
|
|
||||||
fmt.Printf("smtprelay/%s (%s)\n", appVersion, buildTime)
|
|
||||||
os.Exit(0)
|
|
||||||
}
|
|
||||||
|
|
||||||
log.WithField("version", appVersion).
|
log.WithField("version", appVersion).
|
||||||
Debug("starting smtprelay")
|
Debug("starting smtprelay")
|
||||||
|
|
||||||
@@ -294,6 +303,12 @@ func main() {
|
|||||||
server := &smtpd.Server{
|
server := &smtpd.Server{
|
||||||
Hostname: *hostName,
|
Hostname: *hostName,
|
||||||
WelcomeMessage: *welcomeMsg,
|
WelcomeMessage: *welcomeMsg,
|
||||||
|
ReadTimeout: readTimeout,
|
||||||
|
WriteTimeout: writeTimeout,
|
||||||
|
DataTimeout: dataTimeout,
|
||||||
|
MaxConnections: *maxConnections,
|
||||||
|
MaxMessageSize: *maxMessageSize,
|
||||||
|
MaxRecipients: *maxRecipients,
|
||||||
ConnectionChecker: connectionChecker,
|
ConnectionChecker: connectionChecker,
|
||||||
SenderChecker: senderChecker,
|
SenderChecker: senderChecker,
|
||||||
RecipientChecker: recipientChecker,
|
RecipientChecker: recipientChecker,
|
||||||
|
|||||||
83
remotes.go
Normal file
83
remotes.go
Normal file
@@ -0,0 +1,83 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"net/smtp"
|
||||||
|
"net/url"
|
||||||
|
)
|
||||||
|
|
||||||
|
type Remote struct {
|
||||||
|
SkipVerify bool
|
||||||
|
Auth smtp.Auth
|
||||||
|
Scheme string
|
||||||
|
Hostname string
|
||||||
|
Port string
|
||||||
|
Addr string
|
||||||
|
Sender string
|
||||||
|
}
|
||||||
|
|
||||||
|
// ParseRemote creates a remote from a given url in the following format:
|
||||||
|
//
|
||||||
|
// smtp://[user[:password]@][netloc][:port][/remote_sender][?param1=value1&...]
|
||||||
|
// smtps://[user[:password]@][netloc][:port][/remote_sender][?param1=value1&...]
|
||||||
|
// starttls://[user[:password]@][netloc][:port][/remote_sender][?param1=value1&...]
|
||||||
|
//
|
||||||
|
// Supported Params:
|
||||||
|
// - skipVerify: can be "true" or empty to prevent ssl verification of remote server's certificate.
|
||||||
|
// - auth: can be "login" to trigger "LOGIN" auth instead of "PLAIN" auth
|
||||||
|
func ParseRemote(remoteURL string) (*Remote, error) {
|
||||||
|
u, err := url.Parse(remoteURL)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
if u.Scheme != "smtp" && u.Scheme != "smtps" && u.Scheme != "starttls" {
|
||||||
|
return nil, fmt.Errorf("'%s' is not a supported relay scheme", u.Scheme)
|
||||||
|
}
|
||||||
|
|
||||||
|
hostname, port := u.Hostname(), u.Port()
|
||||||
|
|
||||||
|
if port == "" {
|
||||||
|
switch u.Scheme {
|
||||||
|
case "smtp":
|
||||||
|
port = "25"
|
||||||
|
case "smtps":
|
||||||
|
port = "465"
|
||||||
|
case "starttls":
|
||||||
|
port = "587"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
q := u.Query()
|
||||||
|
r := &Remote{
|
||||||
|
Scheme: u.Scheme,
|
||||||
|
Hostname: hostname,
|
||||||
|
Port: port,
|
||||||
|
Addr: fmt.Sprintf("%s:%s", hostname, port),
|
||||||
|
}
|
||||||
|
|
||||||
|
if u.User != nil {
|
||||||
|
pass, _ := u.User.Password()
|
||||||
|
user := u.User.Username()
|
||||||
|
|
||||||
|
if hasAuth, authVal := q.Has("auth"), q.Get("auth"); hasAuth {
|
||||||
|
if authVal != "login" {
|
||||||
|
return nil, fmt.Errorf("Auth must be login or not present, received '%s'", authVal)
|
||||||
|
}
|
||||||
|
|
||||||
|
r.Auth = LoginAuth(user, pass)
|
||||||
|
} else {
|
||||||
|
r.Auth = smtp.PlainAuth("", user, pass, u.Hostname())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if hasVal, skipVerify := q.Has("skipVerify"), q.Get("skipVerify"); hasVal && skipVerify != "false" {
|
||||||
|
r.SkipVerify = true
|
||||||
|
}
|
||||||
|
|
||||||
|
if u.Path != "" {
|
||||||
|
r.Sender = u.Path[1:]
|
||||||
|
}
|
||||||
|
|
||||||
|
return r, nil
|
||||||
|
}
|
||||||
114
remotes_test.go
Normal file
114
remotes_test.go
Normal file
@@ -0,0 +1,114 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/smtp"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/assert"
|
||||||
|
)
|
||||||
|
|
||||||
|
func AssertRemoteUrlEquals(t *testing.T, expected *Remote, remotUrl string) {
|
||||||
|
actual, err := ParseRemote(remotUrl)
|
||||||
|
assert.Nil(t, err)
|
||||||
|
assert.NotNil(t, actual)
|
||||||
|
assert.Equal(t, expected.Scheme, actual.Scheme, "Scheme %s", remotUrl)
|
||||||
|
assert.Equal(t, expected.Addr, actual.Addr, "Addr %s", remotUrl)
|
||||||
|
assert.Equal(t, expected.Hostname, actual.Hostname, "Hostname %s", remotUrl)
|
||||||
|
assert.Equal(t, expected.Port, actual.Port, "Port %s", remotUrl)
|
||||||
|
assert.Equal(t, expected.Sender, actual.Sender, "Sender %s", remotUrl)
|
||||||
|
assert.Equal(t, expected.SkipVerify, actual.SkipVerify, "SkipVerify %s", remotUrl)
|
||||||
|
|
||||||
|
if expected.Auth != nil || actual.Auth != nil {
|
||||||
|
assert.NotNil(t, expected, "Auth %s", remotUrl)
|
||||||
|
assert.NotNil(t, actual, "Auth %s", remotUrl)
|
||||||
|
assert.IsType(t, expected.Auth, actual.Auth)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestValidRemoteUrls(t *testing.T) {
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "smtp",
|
||||||
|
SkipVerify: false,
|
||||||
|
Auth: nil,
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "25",
|
||||||
|
Addr: "email.com:25",
|
||||||
|
Sender: "",
|
||||||
|
}, "smtp://email.com")
|
||||||
|
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "smtp",
|
||||||
|
SkipVerify: true,
|
||||||
|
Auth: nil,
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "25",
|
||||||
|
Addr: "email.com:25",
|
||||||
|
Sender: "",
|
||||||
|
}, "smtp://email.com?skipVerify")
|
||||||
|
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "smtp",
|
||||||
|
SkipVerify: false,
|
||||||
|
Auth: smtp.PlainAuth("", "user", "pass", ""),
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "25",
|
||||||
|
Addr: "email.com:25",
|
||||||
|
Sender: "",
|
||||||
|
}, "smtp://user:pass@email.com")
|
||||||
|
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "smtp",
|
||||||
|
SkipVerify: false,
|
||||||
|
Auth: LoginAuth("user", "pass"),
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "25",
|
||||||
|
Addr: "email.com:25",
|
||||||
|
Sender: "",
|
||||||
|
}, "smtp://user:pass@email.com?auth=login")
|
||||||
|
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "smtp",
|
||||||
|
SkipVerify: false,
|
||||||
|
Auth: LoginAuth("user", "pass"),
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "25",
|
||||||
|
Addr: "email.com:25",
|
||||||
|
Sender: "sender@website.com",
|
||||||
|
}, "smtp://user:pass@email.com/sender@website.com?auth=login")
|
||||||
|
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "smtps",
|
||||||
|
SkipVerify: false,
|
||||||
|
Auth: LoginAuth("user", "pass"),
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "465",
|
||||||
|
Addr: "email.com:465",
|
||||||
|
Sender: "sender@website.com",
|
||||||
|
}, "smtps://user:pass@email.com/sender@website.com?auth=login")
|
||||||
|
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "smtps",
|
||||||
|
SkipVerify: true,
|
||||||
|
Auth: LoginAuth("user", "pass"),
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "8425",
|
||||||
|
Addr: "email.com:8425",
|
||||||
|
Sender: "sender@website.com",
|
||||||
|
}, "smtps://user:pass@email.com:8425/sender@website.com?auth=login&skipVerify")
|
||||||
|
|
||||||
|
AssertRemoteUrlEquals(t, &Remote{
|
||||||
|
Scheme: "starttls",
|
||||||
|
SkipVerify: true,
|
||||||
|
Auth: LoginAuth("user", "pass"),
|
||||||
|
Hostname: "email.com",
|
||||||
|
Port: "8425",
|
||||||
|
Addr: "email.com:8425",
|
||||||
|
Sender: "sender@website.com",
|
||||||
|
}, "starttls://user:pass@email.com:8425/sender@website.com?auth=login&skipVerify")
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMissingScheme(t *testing.T) {
|
||||||
|
_, err := ParseRemote("http://user:pass@email.com:8425/sender@website.com")
|
||||||
|
assert.NotNil(t, err, "Err must be present")
|
||||||
|
assert.Equal(t, err.Error(), "'http' is not a supported relay scheme")
|
||||||
|
}
|
||||||
49
smtp.go
49
smtp.go
@@ -4,15 +4,17 @@
|
|||||||
|
|
||||||
// Package smtp implements the Simple Mail Transfer Protocol as defined in RFC 5321.
|
// Package smtp implements the Simple Mail Transfer Protocol as defined in RFC 5321.
|
||||||
// It also implements the following extensions:
|
// It also implements the following extensions:
|
||||||
|
//
|
||||||
// 8BITMIME RFC 1652
|
// 8BITMIME RFC 1652
|
||||||
// AUTH RFC 2554
|
// AUTH RFC 2554
|
||||||
// STARTTLS RFC 3207
|
// STARTTLS RFC 3207
|
||||||
|
//
|
||||||
// Additional extensions may be handled by clients.
|
// Additional extensions may be handled by clients.
|
||||||
//
|
//
|
||||||
// The smtp package is frozen and is not accepting new features.
|
// The smtp package is frozen and is not accepting new features.
|
||||||
// Some external packages provide more functionality. See:
|
// Some external packages provide more functionality. See:
|
||||||
//
|
//
|
||||||
// https://godoc.org/?q=smtp
|
// https://godoc.org/?q=smtp
|
||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
@@ -106,7 +108,7 @@ func (c *Client) Hello(localName string) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// cmd is a convenience function that sends a command and returns the response
|
// cmd is a convenience function that sends a command and returns the response
|
||||||
func (c *Client) cmd(expectCode int, format string, args ...interface{}) (int, string, error) {
|
func (c *Client) cmd(expectCode int, format string, args ...any) (int, string, error) {
|
||||||
id, err := c.Text.Cmd(format, args...)
|
id, err := c.Text.Cmd(format, args...)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return 0, "", err
|
return 0, "", err
|
||||||
@@ -137,12 +139,8 @@ func (c *Client) ehlo() error {
|
|||||||
if len(extList) > 1 {
|
if len(extList) > 1 {
|
||||||
extList = extList[1:]
|
extList = extList[1:]
|
||||||
for _, line := range extList {
|
for _, line := range extList {
|
||||||
args := strings.SplitN(line, " ", 2)
|
k, v, _ := strings.Cut(line, " ")
|
||||||
if len(args) > 1 {
|
ext[k] = v
|
||||||
ext[args[0]] = args[1]
|
|
||||||
} else {
|
|
||||||
ext[args[0]] = ""
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if mechs, ok := ext["AUTH"]; ok {
|
if mechs, ok := ext["AUTH"]; ok {
|
||||||
@@ -322,7 +320,11 @@ var testHookStartTLS func(*tls.Config) // nil, except for tests
|
|||||||
// attachments (see the mime/multipart package), or other mail
|
// attachments (see the mime/multipart package), or other mail
|
||||||
// functionality. Higher-level packages exist outside of the standard
|
// functionality. Higher-level packages exist outside of the standard
|
||||||
// library.
|
// library.
|
||||||
func SendMail(addr string, a smtp.Auth, from string, to []string, msg []byte) error {
|
func SendMail(r *Remote, from string, to []string, msg []byte) error {
|
||||||
|
if r.Sender != "" {
|
||||||
|
from = r.Sender
|
||||||
|
}
|
||||||
|
|
||||||
if err := validateLine(from); err != nil {
|
if err := validateLine(from); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -331,19 +333,19 @@ func SendMail(addr string, a smtp.Auth, from string, to []string, msg []byte) er
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
host, port, err := net.SplitHostPort(addr)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
var c *Client
|
var c *Client
|
||||||
if port == "465" || port == "smtps" {
|
var err error
|
||||||
config := &tls.Config{ServerName: host}
|
if r.Scheme == "smtps" {
|
||||||
conn, err := tls.Dial("tcp", addr, config)
|
config := &tls.Config{
|
||||||
|
ServerName: r.Hostname,
|
||||||
|
InsecureSkipVerify: r.SkipVerify,
|
||||||
|
}
|
||||||
|
conn, err := tls.Dial("tcp", r.Addr, config)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
defer conn.Close()
|
defer conn.Close()
|
||||||
c, err = NewClient(conn, host)
|
c, err = NewClient(conn, r.Hostname)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -351,7 +353,7 @@ func SendMail(addr string, a smtp.Auth, from string, to []string, msg []byte) er
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
c, err = Dial(addr)
|
c, err = Dial(r.Addr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -360,20 +362,25 @@ func SendMail(addr string, a smtp.Auth, from string, to []string, msg []byte) er
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if ok, _ := c.Extension("STARTTLS"); ok {
|
if ok, _ := c.Extension("STARTTLS"); ok {
|
||||||
config := &tls.Config{ServerName: c.serverName}
|
config := &tls.Config{
|
||||||
|
ServerName: c.serverName,
|
||||||
|
InsecureSkipVerify: r.SkipVerify,
|
||||||
|
}
|
||||||
if testHookStartTLS != nil {
|
if testHookStartTLS != nil {
|
||||||
testHookStartTLS(config)
|
testHookStartTLS(config)
|
||||||
}
|
}
|
||||||
if err = c.StartTLS(config); err != nil {
|
if err = c.StartTLS(config); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
} else if r.Scheme == "starttls" {
|
||||||
|
return errors.New("starttls: server does not support extension, check remote scheme")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if a != nil && c.ext != nil {
|
if r.Auth != nil && c.ext != nil {
|
||||||
if _, ok := c.ext["AUTH"]; !ok {
|
if _, ok := c.ext["AUTH"]; !ok {
|
||||||
return errors.New("smtp: server doesn't support AUTH")
|
return errors.New("smtp: server doesn't support AUTH")
|
||||||
}
|
}
|
||||||
if err = c.Auth(a); err != nil {
|
if err = c.Auth(r.Auth); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,19 +1,23 @@
|
|||||||
; smtprelay configuration
|
; smtprelay configuration
|
||||||
|
;
|
||||||
|
; All config parameters can also be provided as environment
|
||||||
|
; variables in uppercase and the prefix "SMTPRELAY_".
|
||||||
|
; (eg. SMTPRELAY_LOGFILE, SMTPRELAY_LOG_FORMAT)
|
||||||
|
|
||||||
; Logfile (blank/default is stderr)
|
; Logfile (blank/default is stderr)
|
||||||
;logfile =
|
;logfile =
|
||||||
|
|
||||||
; Log format: default, plain (no timestamp), json
|
; Log format: default, plain (no timestamp), json
|
||||||
;log_format = "default"
|
;log_format = default
|
||||||
|
|
||||||
; Log level: panic, fatal, error, warn, info, debug, trace
|
; Log level: panic, fatal, error, warn, info, debug, trace
|
||||||
;log_level = "info"
|
;log_level = info
|
||||||
|
|
||||||
; Hostname for this SMTP server
|
; Hostname for this SMTP server
|
||||||
;hostname = "localhost.localdomain"
|
;hostname = localhost.localdomain
|
||||||
|
|
||||||
; Welcome message for clients
|
; Welcome message for clients
|
||||||
;welcome_msg = "<hostname> ESMTP ready."
|
;welcome_msg = <hostname> ESMTP ready.
|
||||||
|
|
||||||
; Listen on the following addresses for incoming
|
; Listen on the following addresses for incoming
|
||||||
; unencrypted connections.
|
; unencrypted connections.
|
||||||
@@ -30,6 +34,33 @@
|
|||||||
; accepting mails from client.
|
; accepting mails from client.
|
||||||
;local_forcetls = false
|
;local_forcetls = false
|
||||||
|
|
||||||
|
; Socket timeout for read operations
|
||||||
|
; Duration string as sequence of decimal numbers,
|
||||||
|
; each with optional fraction and a unit suffix.
|
||||||
|
; Valid time units are "ns", "us", "ms", "s", "m", "h".
|
||||||
|
;read_timeout = 60s
|
||||||
|
|
||||||
|
; Socket timeout for write operations
|
||||||
|
; Duration string as sequence of decimal numbers,
|
||||||
|
; each with optional fraction and a unit suffix.
|
||||||
|
; Valid time units are "ns", "us", "ms", "s", "m", "h".
|
||||||
|
;write_timeout = 60s
|
||||||
|
|
||||||
|
; Socket timeout for DATA command
|
||||||
|
; Duration string as sequence of decimal numbers,
|
||||||
|
; each with optional fraction and a unit suffix.
|
||||||
|
; Valid time units are "ns", "us", "ms", "s", "m", "h".
|
||||||
|
;data_timeout = 5m
|
||||||
|
|
||||||
|
; Max concurrent connections, use -1 to disable
|
||||||
|
;max_connections = 100
|
||||||
|
|
||||||
|
; Max message size in bytes
|
||||||
|
;max_message_size = 10240000
|
||||||
|
|
||||||
|
; Max RCPT TO calls for each envelope
|
||||||
|
;max_recipients = 100
|
||||||
|
|
||||||
; Networks that are allowed to send mails to us
|
; Networks that are allowed to send mails to us
|
||||||
; Defaults to localhost. If set to "", then any address is allowed.
|
; Defaults to localhost. If set to "", then any address is allowed.
|
||||||
;allowed_nets = 127.0.0.0/8 ::1/128
|
;allowed_nets = 127.0.0.0/8 ::1/128
|
||||||
@@ -56,25 +87,40 @@
|
|||||||
; E.g. "app@example.com,@appsrv.example.com"
|
; E.g. "app@example.com,@appsrv.example.com"
|
||||||
;allowed_users =
|
;allowed_users =
|
||||||
|
|
||||||
; Relay all mails to this SMTP server.
|
; Relay all mails to this SMTP servers.
|
||||||
; If not set, mails are discarded.
|
; If not set, mails are discarded.
|
||||||
|
;
|
||||||
|
; Format:
|
||||||
|
; protocol://[user[:password]@][netloc][:port][/remote_sender][?param1=value1&...]
|
||||||
|
;
|
||||||
|
; protocol: smtp (unencrypted), smtps (TLS), starttls (STARTTLS)
|
||||||
|
; user: Username for authentication
|
||||||
|
; password: Password for authentication
|
||||||
|
; remote_sender: Email address to use as FROM
|
||||||
|
; params:
|
||||||
|
; skipVerify: "true" or empty to prevent ssl verification of remote server's certificate
|
||||||
|
; auth: "login" to use LOGIN authentication
|
||||||
|
|
||||||
; GMail
|
; GMail
|
||||||
;remote_host = smtp.gmail.com:587
|
;remotes = starttls://user:pass@smtp.gmail.com:587
|
||||||
|
|
||||||
; Mailgun.org
|
; Mailgun.org
|
||||||
;remote_host = smtp.mailgun.org:587
|
;remotes = starttls://user:pass@smtp.mailgun.org:587
|
||||||
|
|
||||||
; Mailjet.com
|
; Mailjet.com
|
||||||
;remote_host = in-v3.mailjet.com:587
|
;remotes = starttls://user:pass@in-v3.mailjet.com:587
|
||||||
|
|
||||||
; Authentication credentials on outgoing SMTP server
|
; Ignore remote host certificates
|
||||||
;remote_user =
|
;remotes = starttls://user:pass@server:587?skipVerify
|
||||||
;remote_pass =
|
|
||||||
|
|
||||||
; Authentication method on outgoing SMTP server
|
; Login Authentication method on outgoing SMTP server
|
||||||
; (none, plain, login)
|
;remotes = smtp://user:pass@server:2525?auth=login
|
||||||
;remote_auth = none
|
|
||||||
|
|
||||||
; Sender e-mail address on outgoing SMTP server
|
; Sender e-mail address on outgoing SMTP server
|
||||||
;remote_sender =
|
;remotes = smtp://user:pass@server:2525/overridden@email.com?auth=login
|
||||||
|
|
||||||
|
; Multiple remotes, space delimited
|
||||||
|
;remotes = smtp://127.0.0.1:1025 starttls://user:pass@smtp.mailgun.org:587
|
||||||
|
|
||||||
|
; Pipe messages to external command
|
||||||
|
;command = /usr/local/bin/script
|
||||||
|
|||||||
Reference in New Issue
Block a user