the vacation thing turn me nuts.Now it works, but only on the inside of the Mail System. If someone from inside the network—say, a coworker—sends a message, the auto-reply works; if someone from outside sends a message, there’s no out-of-office message. Since I’ve already made such a mess of things with the other one, what do I need to keep in mind to solve this problem?
inspect the log of the mail module to watch if a mail has been sent, the email is sent only once but it can be bounced by the remote smtp
I have no idea what i need as information to explain my Problem. This is a try from outside the Server to send a vacation respond, how you can see the system said, it send the message, but it doesent work, i also check spam etc.
<70e30c9bbdda11e23f37fe7fceaa2756>, rcpts: xxxxxxx@gmx.de, mime_rcpts: xxxxxxx@gmx.de
2026-08-21T08:30:02+02:00 [1:mail1:rspamd] (normal) <1AB602>; task; rspamd_protocol_http_reply: regexp statistics: 0 pcre regexps scanned, 4 regexps matched, 179 regexps total, 42 regexps cached, 0B scanned using pcre, 332B scanned total
2026-08-21T08:30:02+02:00 [1:mail1:postfix/qmgr] 1AB6022146A0: from=<>, size=889, nrcpt=2 (queue active)
2026-08-21T08:30:02+02:00 [1:mail1:rspamd] (rspamd_proxy) <9e3952>; proxy; proxy_milter_finish_handler: finished milter connection
2026-08-21T08:30:02+02:00 [1:mail1:postfix/smtpd] disconnect from localhost[127.0.0.1] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
2026-08-21T08:30:02+02:00 [1:mail1:dovecot] lmtp(xxxxx)<2069>: sieve: msgid=trinity-063caa92-ebc4-45ca-b0c0-88cb18066445-1787293744895@trinity-msg-rest-gmx-gmx-live-86cc48bb5b-s5xmx: vacation action: sent vacation response to xxxxxxx@gmx.de
2026-08-21T08:30:02+02:00 [1:mail1:dovecot] lmtp(xxxxx)<2069>: save: box=INBOX, uid=19030, msgid=<trinity-063caa92-ebc4-45ca-b0c0-88cb18066445-1787293744895@trinity-msg-rest-…, from=Kai Böhlke xxxxxxx@gmx.de, subject=et, flags=()
2026-08-21T08:30:02+02:00 [1:mail1:dovecot] lmtp(xxxxx)<2069>: sieve: msgid=trinity-063caa92-ebc4-45ca-b0c0-88cb18066445-1787293744895@trinity-msg-rest-gmx-gmx-live-86cc48bb5b-s5xmx: stored mail into mailbox ‘INBOX’
2026-08-21T08:30:02+02:00 [1:mail1:postfix/lmtp] E613A221469D: to=xxxxx@ns8.localmailserver.de.localhost, orig_to=xxxxx@localmailserver.de, relay=ns8.localmailserver.de[/var/lib/umail/lmtp], delay=0.47, delays=0.09/0.01/0.01/0.36, dsn=2.0.0, status=sent (250 2.0.0 xxxxx@ns8.localmailserver.de.localhost Xs8LA2rwh2oVCAAAnWtEFg Saved)
2026-08-21T08:30:02+02:00 [1:mail1:postfix/qmgr] E613A221469D: removed
2026-08-21T08:30:02+02:00 [1:mail1:postfix/smtp] Untrusted TLS connection established to 10.5.4.1[10.5.4.1]:20010: TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
2026-08-21T08:30:02+02:00 [1:mail1:dovecot] lmtp(2069): Disconnect from local: Logged out (state=READY)
Here, from inside the Server, from Co Worker it send the autoresponding message
4.10/22.00] [REPLY(-4.00){},MIME_GOOD(-0.10){text/plain;},ARC_NA(0.00){},DKIM_SIGNED(0.00){localmailserver.de:s=default;},FROM_NO_DN(0.00){},MID_RHS_MATCH_FROMTLD(0.00){},MIME_TRACE(0.00){0:+;},MISSING_XM_UA(0.00){},PRECEDENCE_BULK(0.00){},RCPT_COUNT_ONE(0.00){1;},RCVD_COUNT_ZERO(0.00){0;},SINGLE_SHORT_PART(0.00){},TO_DN_ALL(0.00){},TO_DOM_EQ_FROM_DOM(0.00){},TO_MATCH_ENVRCPT_ALL(0.00){}]), len: 559, time: 121.658ms, dns req: 9, digest: <9faab6634747f03b7ce8cd19861767aa>, rcpts: xxx@localmailserver.de, mime_rcpts: xxx@localmailserver.de
2026-08-21T08:36:14+02:00 [1:mail1:rspamd] (normal) <7E0A42>; task; rspamd_protocol_http_reply: regexp statistics: 0 pcre regexps scanned, 2 regexps matched, 179 regexps total, 42 regexps cached, 0B scanned using pcre, 312B scanned total
2026-08-21T08:36:14+02:00 [1:mail1:postfix/qmgr] 7E0A422146A7: from=<>, size=760, nrcpt=2 (queue active)
2026-08-21T08:36:14+02:00 [1:mail1:rspamd] (rspamd_proxy) <497fd9>; proxy; proxy_milter_finish_handler: finished milter connection
2026-08-21T08:36:14+02:00 [1:mail1:postfix/smtpd] disconnect from localhost[127.0.0.1] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(xxxxx)<2283><x57/Hd7xh2rrCAAAnWtEFg>: sieve: msgid=2544bab3-f94c-f303-6d02-4a977bc362e5@localmailserver.de: vacation action: sent vacation response to xxx@localmailserver.de
2026-08-21T08:36:14+02:00 [1:mail1:redis-persistent] 5 changes in 60 seconds. Saving…
2026-08-21T08:36:14+02:00 [1:mail1:redis-persistent] Background saving started by pid 203
2026-08-21T08:36:14+02:00 [1:mail1:postfix/smtp] Untrusted TLS connection established to 10.5.4.1[10.5.4.1]:20010: TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(xxxxx)<2283><x57/Hd7xh2rrCAAAnWtEFg>: save: box=INBOX, uid=19031, msgid=2544bab3-f94c-f303-6d02-4a977bc362e5@localmailserver.de, from=“Uli” uli@localmailserver.de, subject=test, flags=()
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(xxxxx)<2283><x57/Hd7xh2rrCAAAnWtEFg>: sieve: msgid=2544bab3-f94c-f303-6d02-4a977bc362e5@localmailserver.de: stored mail into mailbox ‘INBOX’
2026-08-21T08:36:14+02:00 [1:mail1:postfix/lmtp] 3527E22146A6: to=xxxxx@ns8.localmailserver.de.localhost, orig_to=xxxxx@localmailserver.de, relay=ns8.localmailserver.de[/var/lib/umail/lmtp], delay=0.48, delays=0.27/0.01/0.02/0.2, dsn=2.0.0, status=sent (250 2.0.0 xxxxx@ns8.localmailserver.de.localhost x57/Hd7xh2rrCAAAnWtEFg Saved)
2026-08-21T08:36:14+02:00 [1:mail1:postfix/qmgr] 3527E22146A6: removed
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(2283): Disconnect from local: Logged out (state=READY)
2026-08-21T08:36:14+02:00 [1:mail1:postfix/smtp] 7E0A422146A7: to=archive@piler1, relay=10.5.4.1[10.5.4.1]:20010, delay=0.19, delays=0.17/0/0.01/0.01, dsn=2.0.0, status=sent (250 OK )
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(2287): Connect from local
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(uli)<2287><1WcZKt7xh2rvCAAAnWtEFg>: save: box=INBOX, uid=241111, msgid=dovecot-sieve-1787294174-506907-0@ns8.localmailserver.de, from=xxxxx@localmailserver.de, subject=Auto: test, flags=()
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(uli)<2287><1WcZKt7xh2rvCAAAnWtEFg>: sieve: msgid=dovecot-sieve-1787294174-506907-0@ns8.localmailserver.de: stored mail into mailbox ‘INBOX’
2026-08-21T08:36:14+02:00 [1:mail1:postfix/lmtp] 7E0A422146A7: to=uli@ns8.localmailserver.de.localhost, orig_to=xxx@localmailserver.de, relay=ns8.localmailserver.de[/var/lib/umail/lmtp], delay=0.21, delays=0.17/0.01/0.02/0.02, dsn=2.0.0, status=sent (250 2.0.0 uli@ns8.localmailserver.de.localhost 1WcZKt7xh2rvCAAAnWtEFg Saved)
2026-08-21T08:36:14+02:00 [1:mail1:postfix/qmgr] 7E0A422146A7: removed
2026-08-21T08:36:14+02:00 [1:mail1:dovecot] lmtp(2287): Disconnect from local: Logged out (state=READY)
2026-08-21T08:36:14+02:00 [1:mail1:redis-persistent] DB saved on disk
2026-08-21T08:36:14+02:00 [1:mail1:redis-persistent] Fork CoW for RDB: current 0 MB, peak 0 MB, average 0 MB
2026-08-21T08:36:14+02:00 [1:mail1:redis-persistent] Background saving
The vacation reply itself works correctly: the Sieve rule fires and the message is generated as expected. Internal delivery works fine.
For the external gmx.de recipient, the message is queued and handed off by our server. From the logs we can’t tell yet whether it’s delivered directly or through a relay/smarthost - that’s worth checking first, since a relay issue (auth, quota, blacklisting) could explain a silent delivery failure on our side rather than something purely external.
Could you please run this on the NS8 host and share the output:
runagent -m mail1
podman exec -ti postfix ash
postconf -n | grep -i relay
If a relayhost is configured, we’ll know where to look next. If not, delivery goes directly to gmx.de’s MX and what happens after handoff is outside our infrastructure - worth checking with the recipient for spam folder or a bounce (NDR) back to the sender.
Thanks for checking - no global relayhost, so it’s not a simple smarthost setup. But there are conditional routing tables in place (sender-based and recipient-based), so it’s worth checking if gmx.de specifically has a dedicated route.
Could you run this on the NS8 host and share the output:
runagent -m mail1
podman exec -ti postfix ash
postmap -q "gmx.de" sqlite:/etc/postfix/relaydest.cf
The first command gives the actual path to use in the second one. The second tells us whether gmx.de is routed through a specific transport/relay instead of a direct delivery to its MX.
unagent -m mail1
runagent: [INFO] starting bash -l
runagent: [INFO] working directory: /home/mail1/.config/state
[mail1@ns8 state]$ podman exec -ti postfix ash
/etc/postfix #
i figured out that a script change or take the responding adress likt xxx@xxx.de into a <> and so ionos dont accept it.
sorry I do not understand ![]()
This is my Problem:
Dovecot 2.3.21.1
sieve_vacation_send_from_recipient = yes
sieve_user_email = %u@compu-max.de
Sieve SOGO is ACTIVE
the Sieve script is syntactically correct
:from “name@correct.de” is set
.dovecot.lda-dupes has already been removed
nevertheless, Dovecot continues to generate vacation emails with
From:name@ns8.correct.de.localhost
Thanks for the detail, this makes sense now.
By default, Dovecot’s Sieve vacation replies use an empty envelope sender (from=<>), which is standard practice to avoid mail loops. With sieve_vacation_send_from_recipient = yes, that behavior changes: the reply is instead sent using the recipient’s own address, taken directly from the LMTP delivery address - and on NS8 that’s an internal address (user@ns8.<hostname>.localhost), not your real domain. That’s why you’re seeing that address in the From: header regardless of what :from is set in the Sieve script.
Could you tell us why you enabled sieve_vacation_send_from_recipient? Was it to work around the earlier delivery issue with gmx.de? That would help us understand if there’s a better fix for that specific problem instead.
Also, to see the exact set of active Dovecot overrides on your system, could you run:
runagent -m mail1
podman exec -ti dovecot ash
doveconf -n
This shows every setting that differs from Dovecot’s defaults, so we can see everything you’ve customized in one go, not just the vacation-related ones.
[root@ns8 ~]# runagent -m mail1
runagent: [INFO] starting bash -l
runagent: [INFO] working directory: /home/mail1/.config/state
[mail1@ns8 state]$ podman exec -ti dovecot ash
/var/lib/vmail # doveconf -n
# 2.3.21.1 (d492236fa0): /etc/dovecot/dovecot.conf
# Pigeonhole version 0.5.21.1 (49005e73)
# OS: Linux 5.14.0-687.31.1.el9_8.x86_64 x86_64
# Hostname: ns8.xxxxx.de
auth_master_user_separator = *
auth_mechanisms = plain login
auth_username_format = %Ln
default_client_limit = 4000
default_process_limit = 400
default_vsz_limit = 1 G
disable_plaintext_auth = no
doveadm_api_key = # hidden, use -P to show it
first_valid_gid = 101
first_valid_uid = 100
last_valid_gid = 101
last_valid_uid = 100
lmtp_save_to_detail_mailbox = yes
login_trusted_networks = 10.5.4.0/24
mail_gid = vmail
mail_home = /var/lib/vmail/%Ln
mail_location = maildir:~/Maildir
mail_max_userip_connections = 20
mail_plugins = acl listescape notify mail_log fts fts_flatcurve quota
mail_shared_explicit_inbox = yes
mail_uid = vmail
managesieve_notify_capability = mailto
managesieve_sieve_capability = fileinto reject envelope encoded-character vacation subaddress comparator-i;ascii-numeric relational regex imap4flags copy include variables body enotify environment mailbox date index ihave duplicate mime foreverypart extracttext imapsieve vnd.dovecot.imapsieve
mbox_write_locks = fcntl
metric auth_success {
filter = (event=auth_request_finished AND success=yes)
}
metric imap_command {
filter = event=imap_command_finished
group_by = cmd_name tagged_reply_state
}
metric mail_delivery {
filter = event=mail_delivery_finished
group_by = duration:exponential:1:5:10
}
metric smtp_command {
filter = event=smtp_server_command_finished
group_by = cmd_name status_code duration:exponential:1:5:10
}
namespace PUBLIC {
disabled = no
list = children
location = maildir:/var/lib/vmail/vmail/Maildir:INDEXPVT=~/Maildir/public
prefix = Public/
separator = /
subscriptions = no
type = public
}
namespace SHARED_USERS {
disabled = no
list = children
location = maildir:/var/lib/vmail/%%n/Maildir:INDEXPVT=~/Maildir/shared/%%n
prefix = Shared/%%n/
separator = /
subscriptions = no
type = shared
}
namespace inbox {
inbox = yes
location =
mailbox Drafts {
special_use = \\Drafts
}
mailbox Junk {
auto = subscribe
special_use = \\Junk
}
mailbox Sent {
special_use = \\Sent
}
mailbox “Sent Messages” {
special_use = \\Sent
}
mailbox Trash {
auto = subscribe
special_use = \\Trash
}
prefix =
separator = /
}
passdb {
args = username_format=%L{username} /etc/dovecot/users
driver = passwd-file
master = yes
}
passdb {
args = /etc/dovecot/passdb.conf.ext
auth_verbose = yes
driver = ldap
master = yes
username_filter = xxxxx
}
passdb {
args = /etc/dovecot/passdb.conf.ext
auth_verbose = yes
driver = ldap
username_filter = !vmail
}
plugin {
acl = vfile
acl_shared_dict = file:/var/lib/vmail/shared-mailboxes.db
acl_user = %u
fts = flatcurve
fts_autoindex = yes
fts_decoder = decode2text
fts_filters = lowercase normalizer-icu stopwords
fts_filters_en = lowercase english-possessive stopwords
fts_flatcurve_substring_search = no
fts_languages = da de en es fi fr it nl no pt ro ru sv tr
fts_tokenizers = generic email-address
imapsieve_mailbox1_before = file:/etc/dovecot/report-spam.sieve
imapsieve_mailbox1_causes = COPY
imapsieve_mailbox1_name = Junk
imapsieve_mailbox2_before = file:/etc/dovecot/report-ham.sieve
imapsieve_mailbox2_causes = COPY
imapsieve_mailbox2_from = Junk
imapsieve_mailbox2_name = *
mail_log_events = delete undelete expunge copy mailbox_delete mailbox_rename mailbox_create flag_change append
mail_log_fields = uid box msgid from subject flags
quota = count:Quota
quota_rule = *:storage=0M
quota_vsizes = yes
sieve = file:~/sieve;active=~/.dovecot.sieve
sieve_before = /etc/dovecot/spam-actions.sieve
sieve_editheader_max_header_size = 2048
sieve_env_spam_folder = Junk
sieve_env_spam_folder_auto = subscribe
sieve_env_spam_subject_prefix =
sieve_global_extensions = +vnd.dovecot.pipe +vnd.dovecot.environment +editheader
sieve_pipe_bin_dir = /usr/local/lib/dovecot/sieve-pipe
sieve_plugins = sieve_extprograms sieve_imapsieve
sieve_user_email = %u@xxxxx.de
sieve_vacation_send_from_recipient = yes
}
protocols = imap lmtp pop3 sieve
service auth {
inet_listener {
port = 4367
}
unix_listener /var/lib/umail/auth {
group = vmail
mode = 0660
}
unix_listener auth-userdb {
group = vmail
mode = 0660
}
}
service decode2text {
executable = script /usr/libexec/dovecot/decode2text.sh
unix_listener decode2text {
mode = 0666
}
user = vmail
}
service doveadm {
inet_listener http {
port = 9288
}
}
service imap-postlogin {
executable = script-login /usr/local/bin/dovecot-postlogin
user = $default_internal_user
}
service imap {
executable = imap imap-postlogin
}
service lmtp {
unix_listener /var/lib/umail/lmtp {
group = vmail
mode = 0660
user = vmail
}
}
service managesieve-login {
inet_listener sieve_deprecated {
port = 2000
}
}
service stats {
inet_listener http {
port = 9289
}
}
ssl = required
ssl_cert = </etc/ssl/dovecot/server.pem
ssl_dh = # hidden, use -P to show it
ssl_key = # hidden, use -P to show it
ssl_prefer_server_ciphers = yes
submission_host = postfix:25
userdb {
args = username_format=%L{username} /etc/dovecot/users
driver = passwd-file
}
userdb {
args = /etc/dovecot/uquota.conf.ext
driver = dict
result_success = continue
}
userdb {
driver = prefetch
}
userdb {
args = /etc/dovecot/userdb.conf.ext
driver = ldap
}
protocol lmtp {
mail_plugins = acl listescape notify mail_log fts fts_flatcurve quota sieve
}
protocol !indexer-worker {
mail_vsize_bg_after_count = 100
}
protocol imap {
mail_plugins = acl listescape notify mail_log fts fts_flatcurve quota imap_acl imap_sieve imap_filter_sieve imap_quota
}
remote 10.5.4.0/24 {
mail_max_userip_connections = 100
}
/var/lib/vmail #
the problem is, that from the script for vacation the email adress is routed to the internal adress. and then the relay server dont allow to send it.
Found it — thanks for the doveconf output, it confirms the full chain.
sieve_vacation_send_from_recipient = yes is set in your config. This setting makes Dovecot use the LMTP delivery address as the vacation’s sender/from address instead of your sieve_user_email (%u@xxxxx.de) or the script’s own :from. On NS8, that delivery address is an internal address (the *.localhost domain you’re seeing), not your real domain - and that’s exactly why the relay then refuses to send it out: it’s not a valid outbound sender.
sieve_user_email is already correctly set to your real address, so the fix should be to remove sieve_vacation_send_from_recipient = yes from your Dovecot custom config. Once removed, the vacation reply should use your real address again instead of the internal one.
Could you let us know which file you added that setting in, so we can confirm exactly what to change? After removing it, please test again from outside and let us know if the vacation reply reaches gmx.de correctly.
i did not get it done, i tried everything but the vacation respond is always with an empty sender mail and so the relay server denied it. u see it down in the first row from=<> it is empty
in Rspamd it looks like:
| [unknown] correct@adress.de |
|---|
2026-08-23T13:25:08+02:00 [1:mail1:postfix/qmgr] 08AD222146BA: from=<>, size=788, nrcpt=2 (queue active) … 2026-08-23T13:25:08+02:00 [1:mail1:postfix/smtp] Untrusted TLS connection established to smtp.xxxxx.de[213.165.67.113]:587: TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256 2026-08-23T13:25:08+02:00 [1:mail1:postfix/smtp] 08AD222146BA: to=xx@xxxxxx.de, relay=smtp.ionos.de[213.165.67.113]:587, delay=0.89, delays=0.48/0.01/0.37/0.02, dsn=5.0.0, status=bounced (host smtp.xxxx.de[213.165.67.113] said: 550-Requested action not taken: mailbox unavailable 550-Sender address is not allowed. 550 1McY4R-1wNw9z0kij-00nigR (in reply to MAIL FROM command))
I am a bit lost and I am sorry for that, I cannot help here
Ugh, that’s really, really too bad. I tried so much things but nothing succeed ![]()
Maybe @mrmarkuz have an idea? and maybe you can reactivate the thread? because it is signed as fixed with a solution
Maybe it helps to set sieve_vacation_send_from_recipient = yes and rewrite the address as explained here:
Honestly, I didn’t make that clear, but there were actually two separate concerns. The first one has been solved. The second one should have had its own thread, rather than continuing this one.
