在 Ubuntu 上搭建或运维邮件服务器时,防垃圾邮件通常需要“多层防御”。下面按实用、可落地的方式给你一套方案,适合 Postfix / Exim / Sendmail 等常见场景。
垃圾邮件过滤首先看“你是谁”。
v=spf1 mx ip4:你的IP -all
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com
✅ 没有这三项,基本必进垃圾箱。
smtpd_relay_restrictions =
permit_mynetworks,
permit_sasl_authenticated,
reject_unauth_destination
smtpd_sender_restrictions =
reject_unknown_sender_domain
reject_unauthenticated_sender_login_mismatch
anvil_rate_time_unit = 60s
anvil_rate_limit = 20
sudo apt install spamassassin spamc
Postfix 中调用:
content_filter = spamassassin
常用规则:
postscreen_greet_action = enforce
postscreen_dnsbl_action = enforce
postscreen_dnsbl_sites =
zen.spamhaus.org,
bl.spamcop.net
✅ 可挡掉大量僵尸网络
smtpd_recipient_restrictions =
reject_rbl_client zen.spamhaus.org
reject_rbl_client bl.spamcop.net
smtpd_sasl_auth_enable = yes
smtpd_tls_security_level = may
避免明文密码被抓。
防止账号被盗群发:
tail -f /var/log/mail.log
sa-update
mailq
最简组合:
✅ SPF + DKIM + DMARC
✅ Postscreen + SpamAssassin
如果你愿意,可以告诉我:
我可以直接给你一份可复制的配置文件。