File: //proc/624551/root/etc/postfix/master.cf.bak.2025-10-31-0747
smtp inet n - y - - smtpd
# Submission (587) TLS + AUTH (Dovecot)
# SMTPS (465) TLS + AUTH
submission inet n - n - - smtpd
-o chroot=n
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_sasl_type=dovecot
-o smtpd_sasl_path=private/auth
-o milter_macro_daemon_name=ORIGINATING
-o smtpd_tls_cert_file=/etc/letsencrypt/live/mail-smtp.dakarash.co.id/fullchain.pem
-o smtpd_tls_key_file=/etc/letsencrypt/live/mail-smtp.dakarash.co.id/privkey.pem
smtps inet n - y - - smtpd
-o syslog_name=postfix/smtps
-o smtpd_tls_wrapper_mode=yes
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
-o milter_macro_daemon_name=ORIGINATING
-o smtpd_sasl_type=dovecot
-o smtpd_sasl_path=private/auth
-o smtpd_tls_security_level=encrypt
-o chroot=n
-o smtpd_tls_cert_file=/etc/letsencrypt/live/mail.dakarash.co.id/fullchain.pem
-o smtpd_tls_key_file=/etc/letsencrypt/live/mail-smtp.dakarash.co.id/privkey.pem
pickup fifo n - y 60 1 pickup
cleanup unix n - y - 0 cleanup
qmgr fifo n - n 300 1 qmgr
tlsmgr unix - - y - 1 tlsmgr
rewrite unix - - y - - trivial-rewrite
bounce unix - - y - 0 bounce
defer unix - - y - 0 bounce
trace unix - - y - 0 bounce
verify unix - - y - 1 verify
flush unix n - y 1000? 0 flush
proxymap unix - - n - - proxymap
proxywrite unix - - n - 1 proxymap
anvil unix - - y - 1 anvil
scache unix - - y - 1 scache
local unix - n n - - local
virtual unix - n n - - virtual
lmtp unix - - n - - lmtp
smtp unix - - y - - smtp
relay unix - - y - - smtp
# --- FIXED smtps (465) wrapper mode di dalam blok service ---
smtps inet n - y - - smtpd
-o syslog_name=postfix/smtps
-o smtpd_tls_wrapper_mode=yes
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
# --- FIXED submission (587) STARTTLS ---
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
# -- FIXED smtps (465) wrapper mode --
smtps inet n - y - - smtpd
-o syslog_name=postfix/smtps
-o smtpd_tls_wrapper_mode=yes
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
# -- FIXED submission (587) STARTTLS --
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
# === SMTP (port 25) ===
smtp inet n - y - - smtpd
# === SMTPS (port 465, wrapper TLS) ===
smtps inet n - y - - smtpd
-o syslog_name=postfix/smtps
-o smtpd_tls_wrapper_mode=yes
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
# === SUBMISSION (port 587, STARTTLS wajib) ===
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
# === SMTPS (465) wrapper TLS ===
smtps inet n - y - - smtpd
-o syslog_name=postfix/smtps
-o smtpd_tls_wrapper_mode=yes
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
# === Submission (587) STARTTLS ===
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_client_restrictions=permit_sasl_authenticated,reject