email filtering with GPG



Hi list,

I have a question about a particular MTA, not FreeBSD specifically, but
since you are a bunch of service provider folk I figured I would ask.
Here is my situation. I am using Postfix as my MTA, and would like to
drastically cut the amount of email that my users see. I am already
doing blacklist filtering and lots of other stuff in
"smtpd_recipient_restrictions" in main.cf, but it isn't enough.

What I would like to do is kill any email that doesn't have a valid
PGP/GPG signature, but I am not sure that Postfix is the right place to
do this. Right now, all mail is delivered to ~/Maildir for each user by
maildrop, and they pick up their mail via IMAPS (Dovecot). At first I
was thinking about some sort of filter for Postfix that would check for
a signature and then reject the message if the signature check failed.
However, the more I think about it, the more I am inclined to use
maildrop's xfilter mechanism to do the signature checking to keep the
load off of Postfix. The reality is that I am not sure which is why I
am asking you.

Am I crazy? Can you think of better ways to do strict signature
checking in this environment, either with Postfix, maildrop, or
something else I am not currently using?

I thank you for your time and consideration.

--
Mike Oliver, KI4OFU
[see complete headers for contact information]

Attachment: pgpjtWKCqVghW.pgp
Description: PGP signature



Relevant Pages

  • Re: Linux aping M$ ?
    ... If this app runs on Slack, ... > monster like sendmail, nor M$ type cartoon-show. ... sendmail, postfix, qmail, exim, and MS Exchange. ... hairy MTA to configure even with m4, so if you need/want an MTA, I'd say ...
    (comp.os.linux.misc)
  • Re: Spam and ad/popup blockers: Recommendations please
    ... consider switching to Postfix for ease of maintenance. ... > The email situation is different (since not everybody runs the same MTA ... > and uses SpamAssassin for spam checks (SpamAssassin also supports ... MailScanner will also work with Qmail, though, and I ...
    (freebsd-questions)
  • Re: [opensuse] Virtual domain, between Postfix and Qmail
    ... If the question is "Which MTA should I use?" ... What features were the deciding factor for you to choose Qmail? ... to compare it to Postfix. ... in Sendmail. ...
    (SuSE)
  • Re: /etc/mailname and cron
    ... Cron didn't generate any mail. ... So you _probably_ want to remove your MTA. ... It may pipe it to something, but I do not have mail or mailx on my ... I do have postfix. ...
    (Ubuntu)
  • Re: [fw-wiz] FWTK and smap/smapd
    ... Postfix or qmail. ... > smap/smapd don't have a perfect security track record. ... You may run any simple mta that does mimick sendmail good enough. ...
    (Firewall-Wizards)