Deliverability spec (inbuxa-drafts specs/deliverability.md), the server side. Every node that sends mail checks itself once a day, at its own minute in the first hour (UTC), and when an administrator asks: - its outgoing addresses (the connection strategy's, or what its EHLO name resolves to), their reverse DNS and whether it resolves back, and nine blocklists, read by each list's own codes so a refused query is never taken for a listing (DL-1 to DL-6); - for every domain: SPF for each address, each DKIM key (by signing a message that's never sent and verifying it as a receiver would), DMARC, the MTA-STS policy against the MX, TLS reporting, and the domain blocklists (DL-7 to DL-12); - whether it holds a certificate for its EHLO and MX names (DL-13). It keeps one report per node, facts only; the console grades them. - inbuxa:DeliverabilityReport: /get, and a create that asks every node to check now, broadcast as DeliverabilityCheck (DL-15). A tenant administrator gets their own domains only (DL-20). - inbuxa:DeliverabilitySettings: which built-in lists are left out, and the lists themselves (DL-6). - sysDeliverabilityGet, sysDeliverabilityUpdate, sysDeliverabilityCheck; a tenant ceiling always turns the last two off.
100 lines
2.8 KiB
Rust
100 lines
2.8 KiB
Rust
/*
|
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
|
*
|
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
|
*
|
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
|
*/
|
|
|
|
pub mod antispam;
|
|
pub mod authentication;
|
|
pub mod ai;
|
|
pub mod ai_calibration;
|
|
pub mod ai_explain;
|
|
pub mod account_lock; // inbuxa: account lock with delegation
|
|
pub mod sharing_policy; // inbuxa: MA-C, who may share mail
|
|
pub mod legal_hold; // inbuxa: legal hold
|
|
pub mod compliance; // inbuxa: the compliance roles
|
|
pub mod mail_rules; // inbuxa: DLP and mail flow rules
|
|
pub mod security_acceptances; // inbuxa: accepted security to-do items
|
|
pub mod deliverability; // inbuxa: the deliverability check
|
|
pub mod journal; // inbuxa: journaling
|
|
pub mod audit; // inbuxa: the audit log
|
|
pub mod authorization;
|
|
pub mod auto_reload; // inbuxa: registry writes apply at once
|
|
pub mod branding;
|
|
pub mod crypto;
|
|
pub mod delivery;
|
|
pub mod directory;
|
|
pub mod masked_email;
|
|
pub mod monitoring;
|
|
pub mod oidc;
|
|
pub mod purge;
|
|
pub mod quota;
|
|
pub mod reload; // inbuxa: reloads and build errors
|
|
pub mod security;
|
|
pub mod task;
|
|
pub mod tracer_reload; // inbuxa: tracers start over when their settings change
|
|
pub mod tenant;
|
|
pub mod undelete;
|
|
|
|
use crate::utils::server::TestServerBuilder;
|
|
use registry::schema::structs::{Expression, Imap, MtaStageAuth};
|
|
|
|
#[tokio::test(flavor = "multi_thread")]
|
|
pub async fn system_tests() {
|
|
let mut test = TestServerBuilder::new("system_tests")
|
|
.await
|
|
.with_default_listeners()
|
|
.await
|
|
.with_object(Imap {
|
|
allow_plain_text_auth: true,
|
|
..Default::default()
|
|
})
|
|
.await
|
|
.with_object(MtaStageAuth {
|
|
require: Expression {
|
|
else_: "false".to_string(),
|
|
..Default::default()
|
|
},
|
|
..Default::default()
|
|
})
|
|
.await
|
|
.build()
|
|
.await;
|
|
|
|
// Create admin account
|
|
let admin = test
|
|
.create_user_account(
|
|
"admin",
|
|
"[email protected]",
|
|
"these_pretzels_are_making_me_thirsty",
|
|
&[],
|
|
"Admin",
|
|
)
|
|
.await;
|
|
test.account("admin")
|
|
.assign_roles_to_account(admin.id(), &["user", "system"])
|
|
.await;
|
|
test.insert_account(admin);
|
|
|
|
directory::test(&test).await;
|
|
authentication::test(&test).await;
|
|
oidc::test(&mut test).await;
|
|
authorization::test(&mut test).await;
|
|
tenant::test(&mut test).await;
|
|
masked_email::test(&mut test).await;
|
|
security::test(&mut test).await;
|
|
quota::test(&mut test).await;
|
|
purge::test(&mut test).await;
|
|
delivery::test(&mut test).await;
|
|
crypto::test(&mut test).await;
|
|
antispam::test(&mut test).await;
|
|
undelete::test(&mut test).await;
|
|
task::test(&mut test).await;
|
|
|
|
if test.is_reset() {
|
|
test.temp_dir.delete();
|
|
}
|
|
}
|