- Shipped
- September 28, 2026 at 5:24 PM UTC
- Author
- Kamo
- Commit
- 8ad5944
kamouniverse.com, the platform's primary apex, is an alias domain of kamocrm.com: every <x>@kamouniverse.com is the <x>@kamocrm.com mailbox. It was mapped by a regexp catch-all, /^([^@]+)@kamouniverse\.com$/ -> $1@kamocrm.com, which makes EVERY local part a listed recipient: smtpd accepted mail for addresses that do not exist, Dovecot refused them over LMTP after queueing, and postfix bounced each one to its sender — usually forged, so the platform's own transactional mail IP (47.181.8.84) was set up to emit backscatter. The mapping is now a MySQL lookup **************** that answers only when <x>@kamocrm.com is a real virtual_users account or virtual_aliases source, so an unknown local part is refused at RCPT time ("User unknown in virtual alias table"). Nothing is stored: a mailbox or alias created, renamed or deleted on kamocrm.com is reflected at once, with no per-user rows to keep in step and nothing for EmailService's reconcilers to prune, and kamouniverse.com stays out of virtual_domains so no split @kamouniverse.com mailbox can be created beside the kamocrm.com one. NoReply@kamouniverse.com — the platform's transactional sender since EmailService ca1dfbd — keeps reaching postmaster through an explicit static line, which the catch-all used to cover by recursion. Verified before pushing, against the live postfix's own MySQL client with scratch copies of the new map and static table: real accounts (any case) map to their kamocrm.com mailbox, unknown local parts, @domain and bare-user probes, and other domains find nothing, SQL quoting holds, noreply@ reaches postmaster. kubectl diff of every mail-step apply target: only these two files differ from live (plus the two bootstrap Jobs, by design). kontak.kamocrm.com keeps its regexp catch-all (hand-added live 2026-09-24, purpose not recorded); the comment says how to move it onto the same map.
