smtpd_banner = $myhostname ESMTP $mail_name (Debian/GNU)
biff = no

append_dot_mydomain = no

readme_directory = no

myhostname = mail
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
myorigin = /etc/mailname
mydestination = {{ inventory_hostname }}, {{ inventory_hostname_short }}, localhost.localdomain, localhost
relayhost = 
mynetworks = [::ffff:]/104 [::1]/128{% for network in smtp_allow_relay_from  %} {{ network }}{% endfor %}

mailbox_command = procmail -a "$EXTENSION"
mailbox_size_limit = 0
recipient_delimiter = +
inet_interfaces = all

# LDAP directory look-ups for domains, mailboxes and aliases.
virtual_mailbox_domains = ldap:/etc/postfix/
virtual_mailbox_maps = ldap:/etc/postfix/
virtual_alias_maps = ldap:/etc/postfix/

# Delivery of mails via Dovecot for virtual domains.
virtual_transport = dovecot
dovecot_destination_recipient_limit = 1

# SMTP authentication.
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_auth_enable = yes

# TLS configuration.
smtpd_tls_security_level = may
smtpd_tls_auth_only = yes
smtpd_tls_cert_file = /etc/ssl/certs/{{ smtp_tls_certificate | basename }}
smtpd_tls_key_file = /etc/ssl/private/{{ smtp_tls_key | basename }}
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache

# Recipients restricting.
smtpd_recipient_restrictions = permit_mynetworks
  {% for rbl in smtp_rbl -%}
  reject_rbl {{ rbl }}
  {% endfor -%}
smtpd_milters = unix:/var/run/clamav/clamav-milter.ctl
non_smtpd_milters = unix:/var/run/clamav/clamav-milter.ctl