{"_id":"haraka-plugin-relay","_rev":"4-4d23be33e748de2495510f275cd26c81","name":"haraka-plugin-relay","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"haraka-plugin-relay","version":"1.0.0","keywords":["haraka-plugin","relay"],"author":{"name":"Haraka Team","email":"haraka.team@gmail.com"},"license":"MIT","_id":"haraka-plugin-relay@1.0.0","maintainers":[{"name":"msimerson","email":"haraka.mail@gmail.com"}],"homepage":"https://github.com/haraka/haraka-plugin-relay#readme","bugs":{"url":"https://github.com/haraka/haraka-plugin-relay/issues"},"dist":{"shasum":"827b1c28daf413bc9a4c7732b6a5e7c963ecd34a","tarball":"https://registry.npmjs.org/haraka-plugin-relay/-/haraka-plugin-relay-1.0.0.tgz","fileCount":6,"integrity":"sha512-IqyedzZD0Gyame4zhCL38BR14DV3qFXxehGw/ctaqWsb/yGPjR/jFj4aickTLTmxF3bX2qvzgXd+93wtn0Df+g==","signatures":[{"sig":"MEQCICZKP/oJkbirbWuBaBBBCsDpuUVHF386II5fRODMBHNdAiBCzlr6cdwrHgihK4mY9TuQP7X0KlxxmhJ3Ektwz/xRww==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":16022},"main":"index.js","gitHead":"8fd3fc9bca16aa0f61719826a9c95d161fec2405","scripts":{"lint":"npx eslint *.js test","test":"npx mocha","format":"npm run prettier:fix && npm run lint:fix","lint:fix":"npx eslint *.js test --fix","prettier":"npx prettier . --check","versions":"npx dependency-version-checker check","prettier:fix":"npx prettier . --write --log-level=warn","versions:fix":"npx dependency-version-checker update"},"_npmUser":{"name":"msimerson","email":"haraka.mail@gmail.com"},"repository":{"url":"git+https://github.com/haraka/haraka-plugin-relay.git","type":"git"},"_npmVersion":"10.8.2","description":"Haraka plugin for managing relay permissions","directories":{},"_nodeVersion":"18.20.5","dependencies":{"ipaddr.js":"^2.2.0"},"_hasShrinkwrap":false,"devDependencies":{"mocha":"^11.1.0","haraka-test-fixtures":"^1.3.8","@haraka/eslint-config":"^2.0.2"},"_npmOperationalInternal":{"tmp":"tmp/haraka-plugin-relay_1.0.0_1736461712828_0.46840287998884356","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"haraka-plugin-relay","version":"1.0.1","keywords":["haraka-plugin","relay"],"author":{"name":"Haraka Team","email":"haraka.team@gmail.com"},"license":"MIT","_id":"haraka-plugin-relay@1.0.1","maintainers":[{"name":"msimerson","email":"haraka.mail@gmail.com"}],"homepage":"https://github.com/haraka/haraka-plugin-relay#readme","bugs":{"url":"https://github.com/haraka/haraka-plugin-relay/issues"},"dist":{"shasum":"53b6140f8854d9d537c7faeadeddf15a828e902d","tarball":"https://registry.npmjs.org/haraka-plugin-relay/-/haraka-plugin-relay-1.0.1.tgz","fileCount":6,"integrity":"sha512-PekYSpNAeTEtOY9+nz7Rw5VrDWcn0UDROZNRisDOc7xQ6oIPb9ueFUswQGFPvH7btamt+Pq8JouzWhEZnYCBFA==","signatures":[{"sig":"MEYCIQDwisVNQIt9tEwTntBfPsNF12GmNdgEwbhfWXfvEcS0AQIhAPmOjNxG/wq2BHbcv+C0lQY16YF+dMDsGh6Z6xGB7gUO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15736},"main":"index.js","gitHead":"8581d4b937f0c60310cdefc69e6ace64cf7bdb45","scripts":{"lint":"npx eslint *.js test","test":"npx mocha@^11","format":"npm run prettier:fix && npm run lint:fix","lint:fix":"npx eslint *.js test --fix","prettier":"npx prettier . --check","versions":"npx dependency-version-checker check","prettier:fix":"npx prettier . --write --log-level=warn","versions:fix":"npx dependency-version-checker update"},"_npmUser":{"name":"msimerson","email":"haraka.mail@gmail.com"},"prettier":{"semi":false,"singleQuote":true},"repository":{"url":"git+https://github.com/haraka/haraka-plugin-relay.git","type":"git"},"_npmVersion":"10.8.2","description":"Haraka plugin for managing relay permissions","directories":{},"_nodeVersion":"20.18.2","dependencies":{"ipaddr.js":"^2.2.0"},"_hasShrinkwrap":false,"devDependencies":{"haraka-test-fixtures":"^1.3.8","@haraka/eslint-config":"^2.0.2"},"_npmOperationalInternal":{"tmp":"tmp/haraka-plugin-relay_1.0.1_1738265480740_0.6284409758153886","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"haraka-plugin-relay","version":"1.0.2","description":"Haraka plugin for managing relay permissions","main":"index.js","scripts":{"format":"npm run prettier:fix && npm run lint:fix","lint":"npx eslint *.js test","lint:fix":"npx eslint *.js test --fix","prettier":"npx prettier . --check","prettier:fix":"npx prettier . --write --log-level=warn","test":"node --test test/*.js","versions":"npx npm-dep-mgr check","versions:fix":"npx npm-dep-mgr update","test:coverage":"npx c8 --reporter=text --reporter=text-summary npm test"},"repository":{"type":"git","url":"git+https://github.com/haraka/haraka-plugin-relay.git"},"keywords":["haraka-plugin","relay"],"author":{"name":"Haraka Team","email":"haraka.team@gmail.com"},"license":"MIT","bugs":{"url":"https://github.com/haraka/haraka-plugin-relay/issues"},"homepage":"https://github.com/haraka/haraka-plugin-relay#readme","dependencies":{"ipaddr.js":"^2.4.0"},"devDependencies":{"@haraka/eslint-config":"^2.0.4","haraka-test-fixtures":"^1.5.1"},"prettier":{"singleQuote":true,"semi":false},"gitHead":"b4ff49c7e9ecf51f7b226cfab587f24fde1b016d","_id":"haraka-plugin-relay@1.0.2","_nodeVersion":"24.15.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-A7EH/ALaoylivekp+t+f0EoK5pgs6E9oAh6FfDfBQRjOS0KSRsFN8w5qduFTDoHlBCosel3scXFc2+7jxERgfQ==","shasum":"b7926e76a948815cca0585a1aac2fb11f18583fc","tarball":"https://registry.npmjs.org/haraka-plugin-relay/-/haraka-plugin-relay-1.0.2.tgz","fileCount":6,"unpackedSize":16420,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/haraka-plugin-relay@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDDDDVNzmRjZ19/8i4dYDDdxhUf9moSnzhesPHL5zmarAIgHjWWxDv6M+nzTTBWHCXwSAwJZvR/X9rz+QuWVgdhFFk="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:e108edd7-e05f-49c6-b3fa-c77ce03e2fb6"}},"directories":{},"maintainers":[{"name":"tnpi","email":"matt@tnpi.net"},{"name":"msimerson","email":"haraka.mail@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/haraka-plugin-relay_1.0.2_1778906494809_0.712514421575172"},"_hasShrinkwrap":false}},"time":{"created":"2025-01-09T22:28:32.688Z","modified":"2026-05-16T04:41:35.403Z","1.0.0":"2025-01-09T22:28:33.061Z","1.0.1":"2025-01-30T19:31:20.920Z","1.0.2":"2026-05-16T04:41:34.965Z"},"bugs":{"url":"https://github.com/haraka/haraka-plugin-relay/issues"},"author":{"name":"Haraka Team","email":"haraka.team@gmail.com"},"license":"MIT","homepage":"https://github.com/haraka/haraka-plugin-relay#readme","keywords":["haraka-plugin","relay"],"repository":{"type":"git","url":"git+https://github.com/haraka/haraka-plugin-relay.git"},"description":"Haraka plugin for managing relay permissions","maintainers":[{"name":"tnpi","email":"matt@tnpi.net"},{"name":"msimerson","email":"haraka.mail@gmail.com"}],"readme":"[![CI Test Status][ci-img]][ci-url]\n[![Code Climate][clim-img]][clim-url]\n\n# haraka-plugin-relay\n\n[MTAs](http://en.wikipedia.org/wiki/Mail_transfer_agent) generally only accept mail for _local_ domains they can deliver to. In Haraka, the `rcpt_to.*` plugins usually decide which domains and/or email addresses are deliverable. By default, everything else is rejected.\n\n**Relaying** is when a MTA accepts mail that is destined elsewhere. Back in the day (1980s), most MTAs permitted open relaying. Soon spammers abused our open relays (1990s) and left us with soiled mail queues. Now nearly all MTAs have relaying disabled and [MUAs](http://en.wikipedia.org/wiki/Mail_user_agent) are required to use a [MSA](http://en.wikipedia.org/wiki/Message_submission_agent) to relay. Most MTAs (including Haraka) have MSA features and can serve both purposes.\n\nThis **relay** plugin provides Haraka with options for managing relay permissions.\n\n## Authentication\n\nOne way to enable relaying is authentication via the [auth plugins](http://haraka.github.io/plugins). Successful authentication enables relaying during _that_ SMTP connection. To securely offer SMTP AUTH, the [tls](http://haraka.github.io/plugins/tls) plugin and at least one auth plugin must be enabled and properly configured. When that requirement is met, the AUTH SMTP extension will be advertised to SMTP clients.\n\n    % nc mail.example.com 587\n    220 mail.example.com ESMTP Haraka 2.4.0 ready\n    ehlo client.example.com\n    250-mail.example.com Hello client.example.com [192.168.0.1], Haraka is at your service.\n    250-PIPELINING\n    250-8BITMIME\n    250-SIZE 10000000\n    250 STARTTLS\n    quit\n    221 mail.example.com closing connection. Have a jolly good day.\n\nNotice that there's no AUTH advertised. We only permit authentication when the\nconnection is secured with TLS:\n\n    % openssl s_client -connect mail.example.com:587 -starttls smtp\n    CONNECTED(00000003)\n    <snip long SSL certificate details>\n    ---\n    250 STARTTLS\n    ehlo client.example.com\n    250-mail.example.com Hello client.example.com [192.168.1.1], Haraka is at your service.\n    250-PIPELINING\n    250-8BITMIME\n    250-SIZE 10000000\n    250 AUTH PLAIN LOGIN\n    quit\n    221 mail.example.com closing connection. Have a jolly good day.\n    closed\n\nTo avoid port 25 restrictions, in 1998 we developed [SMTP submission](http://tools.ietf.org/html/rfc2476) on port 587. As of January 2018, [RFC 8314](https://tools.ietf.org/html/rfc8314) resurrects [SMTPS](https://en.wikipedia.org/wiki/SMTPS) on port 465 in favor of port 587 with STARTTLS. For optimal security and reliability, [MUAs](http://en.wikipedia.org/wiki/Mail_user_agent) should be configured to send mail to port 465 with TLS.\n\n## ACL (Access Control List)\n\nACL processing is enabled by setting acl=true in the [relay] section of\nrelay.ini:\n\n    [relay]\n    acl=true\n\nWith the Access Control List feature, relaying can be enabled for IPv4 and\nIPv6 networks. IP ranges listed in the ACL file are allowed to send mails\nwithout furthur checks.\n\n- `config/relay_acl_allow`\n\n  Allowed IP ranges in CIDR notation, one per line.\n\nBack in the day, ISPs enabled all of their IP space to relay. That proved\nproblematic for users who took their laptops and mobile phones elsewhere and\nthen couldn't send mail. For end users therefore, use SMTP AUTH described\nabove. If you reside somewhere technology evolves more slowly, you can still\nadd IP allocations to `relay_acl_allow` like so:\n\n    echo 'N.N.N.N/24' >> /path/to/haraka/config/relay_acl_allow\n\nA common use case for IP based relaying is to relay messages on behalf of\nanother mail server. If your organization has an Exchange server, using Haraka\nto filter inbound messages is a great choice. You might also want to relay\noutbound messages via Haraka as well, so they can be DKIM signed on their way\nto the internet. For such a use case, you would set 'acl=true' (the default)\nin the [relay] section of `relay.ini` and then add the external IP address\nof the corporate firewall to `config/relay_acl_allow`:\n\n    echo 'N.N.N.N/32' >> /path/to/haraka/config/relay_acl_allow\n\n## Force Route / Dest[ination] Domains\n\nForce routes and Destination Domains are enabled by setting in the [relay]\nsection of relay.ini:\n\n    [relay]\n    force_routing=false  (default: false)\n    dest_domains=false   (default: false)\n\nThese two features share another common config file:\n\n- `config/relay_dest_domains.ini`\n\nThe format is ini and entries are within the [domains] section. The key for each entry is the domain and the value is a JSON string. Within the JSON string, the currently supported keys are:\n\n    * action  (Dest Domains)\n    * nexthop (Force Route)\n\n### Force Route\n\nThink of force route as the equivalent of the transport map in Postfix or the smtproutes file in Qmail. Rather than looking up the MX for a host, the _nexthop_ value from the entry in the config file is used.\n\nThe value of \"nexthop\": can be a hostname or an IP, optionally follow by :port.\n\nExample:\n\n    [domains]\n    test.com = { \"action\": \"continue\", \"nexthop\": \"127.0.0.1:2525\" }\n\n### Destination Domains\n\nAllowed destination/recipient domains. The field within the JSON value used\nby Dest Domains is \"action\": and the possible values are accept, continue, or\ndeny.\n\n    * accept   (accept the mail without further checks)\n\nExample:\n\n    [domains]\n    test.com = { \"action\": \"accept\" }\n\nThink of _accept_ as the equivalent of qmail's _rcpthosts_, or a misplaced Haraka `rcpt_to.*` plugin. The _accept_ mechanism is another way to tell Haraka that a particular domain is one we accept mail for. The difference between this and the [rcpt_to.in_host_list](http://haraka.github.io/plugins/rcpt_to.in_host_list) plugin is that this one also enables relaying.\n\n    * continue (mails are subject to further checks)\n\nExample:\n\n    [domains]\n    test.com = { \"action\": \"continue\" }\n\nBecause the default behavior of Dest Routes is to deny, the _continue_ option provides an escape, permitting another Haraka plugin to validate the recipient. Like the _accept_ option, it too enables relaying.\n\n    * deny    (mails are rejected)\n\nThis deny option baffles me. The default behavior of Haraka is to reject emails for\nwhich a recipient validation plugin hasn't vouched. Adding it here prevents\nany subsequent recipient validation plugin from getting a chance. It also\nnecessitates the continue option.\n\n## all\n\nRelay all is enabled by setting all=true in the [relay] section of\nrelay.ini:\n\n    [relay]\n    all=true     (default: false)\n\nRelay all is useful for spamtraps to accept all mail.\n\nDo NOT use this on a real mail server, unless you really know what you are\ndoing. If you use the all feature with anything that relays mail (such\nas forwarding to a real mail server, or the `deliver` plugin), your mail\nserver is now an open relay.\n\nThis is BAD. Hence the big letters. In short: DO NOT USE THIS FEATURE.\n\nIt is useful for testing and spamtraps, hence its presence.\n\n<!-- leave these buried at the bottom of the document -->\n\n[ci-img]: https://github.com/haraka/haraka-plugin-relay/actions/workflows/ci.yml/badge.svg\n[ci-url]: https://github.com/haraka/haraka-plugin-relay/actions/workflows/ci.yml\n[clim-img]: https://codeclimate.com/github/haraka/haraka-plugin-relay/badges/gpa.svg\n[clim-url]: https://codeclimate.com/github/haraka/haraka-plugin-relay\n","readmeFilename":"README.md"}