{CONF_sysconf_dir/helo.conf} \
{${if match_ip \
{$sender_host_address} \
- {$value}}}}}}
+ {<; $value}}}}}}
!verify = helo
set acl_c_helo_warning = true
## Reject if the client isn't allowed to relay and the recipient
## isn't in one of our known domains.
- deny message = Relaying not permitted
- !hosts = CONF_relay_clients
- !authenticated = *
- !domains = +known
+ require message = Relaying not permitted
+ acl = check_relay
## Ensure that the recipient is routable.
require message = Invalid recipient \
($recipient_verify_failure; $acl_verify_message)
verify = recipient
+SECTION(acl, misc)m4_dnl
+check_relay:
+ ## Accept either if the client is allowed to relay through us, or if
+ ## we're the correct place to send this mail.
+
+ ## Known clients and authenticated users are OK.
+ accept hosts = CONF_relay_clients
+ accept authenticated = *
+
+ ## Known domains are OK.
+ accept domains = +public
+
+ ## Finally, domains in our table are OK, unless they say they aren't.
+ accept domains = \
+ ${if exists{CONF_sysconf_dir/domains.conf} \
+ {partial0-lsearch; CONF_sysconf_dir/domains.conf}}
+ condition = DOMKV(service, {$value}{true})
+
+ ## Nope, that's not allowed.
+ deny
+
SECTION(acl, rcpt-tail)m4_dnl
## Everything checks out OK: let this one go through.
accept