PostFix Sender-based Routing with the same SMTP host but different credentials

Viewed 219

I have a postfix based mail server that I need to configure to send mail for different domains using the same SMTP server but with different AUTH settings.

Example:

  • mail from domain1.com should go out via smtp.gmail.com with username1@domain.com:PASSWORD1
  • mail from domain2.com should go out via smtp.gmail.com with username2@domain.com:PASSWORD2 ... and so on.

I have this so far in my main.cf file:

sender_dependent_relayhost_maps = hash:/etc/postfix/relay_maps
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous
smtp_tls_security_level = encrypt
smtp_tls_note_starttls_offer = yes

And /etc/postfix/relay_maps:

@domain1.com [smtp.gmail.com]:587
@domain2.com [smtp.gmail.com]:587

And /etc/postfix/sasl_passwd:

[smtp.gmail.com]:587    user1@domain.com:PASSWORD1
[smtp.gmail.com]:587    user2@domain.com:PASSWORD2

But it does not work as expected and everything goes out using the first line of credentials from sasl_passwd

Basically what I can't figure out is how to make postfix differentiate which credentials set it should use for which domain.

Please help. THanks

1 Answers

I found something that worked for me at https://gist.github.com/zmwangx/2c56aa32be68daf48c2f

This is the short version of what is described.

Create 2 files.

/etc/postfix/sasl_passwd:

# per-sender authentication
account1@gmail.com account1@gmail.com:passwd1
account2@gmail.com account2@gmail.com:passwd2

# default relayhost
[smtp.gmail.com]:587 default_account@gmail.com:default_passwd

/etc/postfix/sender_relay:

account1@gmail.com [smtp.gmail.com]:587
account2@gmail.com [smtp.gmail.com]:587

Process the files

chmod 600 /etc/postfix/sasl_passwd
postmap sasl_passwd sender_relay

add to main.cf

# sender-dependent sasl authentication
smtp_sender_dependent_authentication = yes
sender_dependent_relayhost_maps = hash:/etc/postfix/sender_relay

# smtp authentication settings
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous
smtp_sasl_mechanism_filter = plain
smtp_tls_CAfile = /etc/pki/tls/certs/ca-bundle.crt
smtp_use_tls = yes
smtp_tls_security_level = encrypt
Related