A widely used transfer agent.
WHAT IT IS
A modular transfer agent, designed for security and configured through a small number of files.
WHAT ITS ARCHITECTURE PROVIDES
Separate processes for separate functions, with limited privilege.
WHAT THE MAIN CONFIGURATION CONTROLS
Which networks may relay How recipients are looked up Where mail is delivered Restrictions applied at each stage
WHAT RESTRICTIONS TO APPLY
Reject unknown recipients, at the transaction Require authentication for submission Reject invalid or forged identification Apply reputation checks
WHY REJECTING UNKNOWN RECIPIENTS MATTERS
Accepting then bouncing generates backscatter and harms your reputation.
WHAT LOOKUP TABLES PROVIDE
Mapping addresses to destinations, aliases, and policy.
WHAT TO KEEP THEM IN
Files, or a database, depending on scale.
WHAT TO SEPARATE
Submission and transfer, with different restrictions on each.
WHAT TO CONFIGURE FOR SUBMISSION
Authentication required Encryption required Sender restricted to addresses the user owns
WHY THAT LAST POINT
It prevents an authenticated user sending as anyone.
WHAT TO MONITOR
The queue, deferred mail, and rejection rates.