Blacklisting is provided by Policyd, and it's placed after 'permit_sasl_authenticated' in Postfix parameter 'smtpd_recipient_restrictions':
smtpd_recipient_restrictions = .., permit_sasl_authenticated, ..., check_policy_service inet:127.0.0.1:10031
So mail sent by authenticated user will be passed before applying blacklist provided by Policyd.
posa68 wrote:
- Then I suspend whole domain
From Dashboard: List all domain -> select the domain wich spammer account belong to -> Action: disable
Could you please show me file content of /etc/postfix/mysql/sender_login_maps.cf? Please remove/hide password before posting.