Sign inSign up

asdaru/smtp-relay

By asdaru

•Updated almost 8 years ago

This Docker run an instance of postfix configured as SMTP relay. (repaired send with sasl auth)

Image
0

1.2K

asdaru/smtp-relay repository overview

⁠Docker SMTP Relay

Build Status

This image contains an instance of Postfix SMTP server configured as a SMTP relay. This relay is restricted to only one domain name. so it means that only mail that come from RELAY_MYDOMAIN will be relayed to the relayhost.

:warning: Take care of the changelogs⁠ because some breaking changes may happend between versions.

⁠Example of usage

This relay can take place into a information system if you want to give access to some web or other applications a way to send notification by mail.

The advantage of this configuration is that only the host in theses case are allowed to send emails through this relay :

  • The host IP's address is in the range of RELAY_MYNETWORKS
  • The host is authenticated with a valid SASL login/password

⁠Docker Informations

  • This port is available on this image
PortUsage
25SMTP for incoming relay user
  • This volume is bind on this image
VolumeUsage
/dataContains the flat database that contains all SASL user
  • This image takes theses environnements variables as parameters
EnvironmentTypeUsage
RELAY_MYHOSTNAMEStringThe hostname of the SMTP relay (because docker assign a random hostname, you can specify here a human-readable hostname)
RELAY_MYDOMAIN (mandatory)StringThe domain name that this relay will forward the mail
RELAY_MYNETWORKSList of stringsThe space separated list of network(s) which are allowed by default to relay emails
RELAY_DOMAINSList of stringsThe space separated list of external domain names for whose this relay will forward email. Useless if you use a *NODOMAIN relay mode. Default to RELAY_MYDOMAIN
RELAY_HOST (mandatory)StringThe remote host to which send the relayed emails (the relayhost)
RELAY_LOGINStringThe login name to present to the relayhost during authentication (optionnal)
RELAY_PASSWORDStringThe password to present to the relayhost during authentication (optionnal)
RELAY_USE_TLSBoolean(yes/no)Specify if you want to require a TLS connection to relayhost
RELAY_TLS_VERIFYEnumHow to verify the TLS : (none, may, encrypt, dane, dane-only, fingerprint, verify, secure)
RELAY_TLS_CAString pathThe path to the CA file use to check relayhost certificate (path in the container)
RELAY_POSTMASTERString email addressThe email address of the postmaster, in order to send error, and misconfiguration notification
RELAY_STRICT_SENDER_MYDOMAINBoolean(true/false)If set to 'true' all sender adresses must belong to the relay domains
RELAY_MODEEnumThe predefined mode of relay behaviour, theses modes has been designed by me. The availables values for this parameter are described below
RELAY_EXTRAS_SETTINGSList of stringSpace separated of extras optiosn that will be passed to postconf -e
⁠Relay Mode

Description of parameter

Relay mode valueDescriptionUsage
STRICTOnly network and sasl authenticated users can send emails through relay. All emails must have a recipient adress which belong to the relay domainsTypically you can use this mode to allow one of your application to send email to internals domain emails adresses
ALLOW_SASLAUTH_NODOMAINOnly network and sasl authenticated users can send emails through relay. All emails send by network authenticated users must have a recipient adress which belong to the relay domains. All emails send by sasl authenticated users can have any recipient adress(es).You can use this mode to allow one of your (internal) application to send email to external users. In case when some part(s) of your application will be reachable by externals users
ALLOW_NETAUTH_NODOMAINOnly network and sasl authenticated users can send emails through relay. All emails send by sasl authenticated users must have a recipient adress which belong to the relay domains. All emails send by network authenticated users can have any recipient adress(es)
ALLOW_AUTH_NODOMAINOnly network and sasl authenticated users can send emails through relay. All emails send by all authenticated users can have any recipient adress(es).In case where you want a simple relay host with a basic auth

For other examples of values, you can refer to the Dockerfile

⁠Installation

  • Manual
git clone
docker build -t turgon37/smtp-relay .
  • or Automatic
docker pull turgon37/smtp-relay

⁠Usage

docker run -p 25:25 -e "RELAY_MYDOMAIN=domain.com" -e "RELAY_HOST=relay:25" docker-smtp-relay
⁠Docker-compose Specific configuration examples
  • unauthenticated smtp relay filtered by subnet and domain name
services:
  smtp-relay:
    image: turgon37/smtp-relay:latest
    environment:
      - [email protected]
      - RELAY_MYHOSTNAME=smtp-relay.example.net
      - RELAY_MYDOMAIN=example.net
      - RELAY_MYNETWORKS=127.0.0.0/8 10.0.0.0/24
      - RELAY_HOST=[10.1.0.1]:25
    ports:
      - "10.0.0.1:3000:25"
  • authenticated smtp proxy
services:
  smtp-relay-auth:
    image: turgon37/smtp-relay:latest
    environment:
      - [email protected]
      - RELAY_MYHOSTNAME=smtp-relay.example.net
      - RELAY_MYDOMAIN=example.net
      - RELAY_MYNETWORKS=127.0.0.0/8 10.0.0.0/24
      - RELAY_HOST=[10.1.0.1]:25
      - RELAY_MODE=ALLOW_SASLAUTH_NODOMAIN
      - RELAY_LOGIN=sasl-user-login
      - RELAY_PASSWORD=xxxxxxxxxxxx
      - RELAY_USE_TLS=no
      - 'RELAY_EXTRAS_SETTINGS=compatibility_level=1'
    ports:
      - "10.0.0.1:3000:25"
    volumes:
      - data-smtp-relay-auth:/data
volumes:
  data-smtp-relay-auth:
⁠Configuration during running
  • List all SASL users :
docker exec smtp-relay /opt/postfix/listpasswd.sh
  • Add a SASL user :

If you have a host which is not in the range of addresses specified in 'mynetworks' of postfix, this host have to be sasl authenticated when it connects to the smtp relay.

To create a generic account for this host you have to run this command into the container

docker exec -it smtp-relay /opt/postfix/saslpasswd.sh -u domain.com -c username

You have to replace domain.com with your relay domain and you will be prompt for password two times. Then you will be prompted for password two times

  • Add multiple SASL users :

If you want to add multiple sasl users at the same time you can mount (-v) your credentials list to /etc/postfix/client_sasl_passwd This list must contains one credential per line and for each line use the syntax 'USERNAME PASSWORD' (the username and the password are separated with a blank space)

You can check with docker logs if all of your line has been correctly parsed

Tag summary

Content type

Image

Digest

Size

19.6 MB

Last updated

almost 8 years ago

docker pull asdaru/smtp-relay