20 Runbooks

Postfix Troubleshooting

Structured diagnostics and recovery guidance for common production incidents.

SMTP Connection Refused

Check listener bindings, firewall policy, service health and network path.

Relay Access Denied

Validate recipient classification, relay restrictions, authentication and transport routing.

SASL Authentication Failed

Inspect mechanism availability, socket paths, credentials, TLS policy and Dovecot/Cyrus logs.

TLS Handshake Failed

Check certificate chain, protocol compatibility, SNI, permissions and policy maps.

Mail Forwarding Loop

Trace Received headers, aliases, transports, virtual maps and relay routes.

Queue Growing Rapidly

Identify affected destinations, SMTP responses, disk latency, DNS failures and policy changes.

Deferred Due to DNS

Verify resolver health, MX/A/AAAA records, DNSSEC failures and timeout behavior.

Sender Address Rejected

Review restriction order, access maps, sender verification and local domain classification.

Recipient Address Rejected

Review destination classes, virtual maps, mailbox existence checks and relay policy.

OpenDKIM Not Signing

Validate milter reachability, table matches, trusted hosts, permissions and DNS selector records.

Dovecot Auth Socket Missing

Check socket path, chroot namespace, service ownership and Dovecot startup errors.

postfix check Errors

Resolve ownership, mode, map, directory and syntax findings before reload.

Mail Stuck in Active Queue

Inspect qmgr limits, transport process health, destination concurrency and filesystem latency.

TLS Private Key Permission Error

Set secure readable ownership for Postfix while avoiding world-readable private keys.

Submission Port Not Listening

Check master.cf syntax, service enablement, firewall rules and process startup logs.

Wrong Outbound Source IP

Inspect smtp_bind_address, transport overrides, multi-instance routing and OS route selection.

HELO or Hostname Mismatch

Align myhostname, smtp_helo_name, PTR and forward DNS for each outbound identity.

Map Changes Not Applied

Rebuild hash/db maps, verify lookup type/path and reload the correct instance.

High Memory Usage

Inspect process limits, active queue size, content filters, concurrency and abnormal clients.

Duplicate Delivery

Trace queue IDs, retries, downstream acknowledgments, application injection and alias expansion.

Search Trushilla Documentation