Thank you @D4niel ,
I see clearer now. Just the ipv6nat-mailcow content was not merged.
Since I am seeing myself being an open relay, although I have disabled ipv6 as the docs say,
I need to investigate further.
In german, see the other Thread: https://community.mailcow.email/d/5013-massenhaft-bounces-durch-spam/6
But it seems to me at the moment:
- As soon as I disable IPv6 as the docs say, the docker stack still creates docker-proxy with IPv6, forwarding/natting everything from IPv6 to the postfix, which identifies the request coming from 172.11.1.1 thus automatically accepting mails that are forged to be from my server. -> Open relay 👿