{% if 'letsencrypt' in group_names %}
# TLS server parameters
-smtpd_tls_cert_file=/etc/ssl/mycerts/letsencrypt/live.crt+chain
+smtpd_tls_cert_file=/etc/ssl/mycerts/letsencrypt/live.crt
smtpd_tls_key_file=/etc/ssl/private/letsencrypt/live.key
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtpd_tls_security_level = may
postscreen_dnsbl_whitelist_threshold = -2
postscreen_dnsbl_sites =
ix.dnsbl.manitu.net*2 sbl-xbl.spamhaus.org*2
- bl.spamcop.net dnsbl.sorbs.net bl.mailspike.net
+ bl.spamcop.net bl.mailspike.net
swl.spamhaus.org*-2 list.dnswl.org=127.0.[0..255].[0..254]*-2
postscreen_greet_action = enforce
postscreen_dnsbl_action = enforce
postscreen_pipelining_enable = yes
postscreen_non_smtp_command_enable = yes
postscreen_bare_newline_enable = yes
+postscreen_access_list = permit_mynetworks,
+ cidr:$config_directory/postscreen_access.cidr
{% endif %}
# control relay access
# misc
smtpd_delay_reject = yes
disable_vrfy_command = yes
-recipient_delimiter = +
+recipient_delimiter = {{ postfix.recipient_delimiter | default("+") }}
delay_warning_time = 4h
message_size_limit = 21384000