Some servers do not support this parameter

I've developed a patch providing additional checkbox on HTMLMail settings page. Please review it

Comments

id.tarzanych created an issue. See original summary.

id.tarzanych’s picture

salvis’s picture

Thank you for your report and patch!

For the sake of completeness, please mention a concrete case where this is an issue and how it manifests itself.

Has anyone seen this issue before?

Any testers/reviewers?

id.tarzanych’s picture

I'm pretty sure that almost all mail servers support this additional parameter.

But I've got errors on particular corporate mail server. Messages simply were not sent if custom Return-Path parameter had been set.

That's why I decided to provide additional config for HTML Mail module. Maybe that can help somebody else with the same problem

salvis’s picture

Assigned: id.tarzanych » Unassigned
Status: Needs review » Closed (won't fix)

I've looked at https://tools.ietf.org/html/rfc2821 and found that adding a Return-Path header would always be an error.

If a client module tries to set that header, then it violates the standard and needs to be fixed.

id.tarzanych’s picture

Status: Closed (won't fix) » Needs review

Sorry for being stubborn. Return-Path is not sent in headers, but in additional parameters.

Let's look at Drupal Core code

  $default_from = variable_get('site_mail', ini_get('sendmail_from'));

...

  if ($default_from) {
    // To prevent e-mail from looking like spam, the addresses in the Sender and
    // Return-Path headers should have a domain authorized to use the originating
    // SMTP server.
    $headers['From'] = $headers['Sender'] = $headers['Return-Path'] = $default_from;
  }

So the Return-Path header is set.
Later in DefaultMailSystem class (and in HTMLMailSystem too) Return-Path is moved from headers to additional parameters

    // If 'Return-Path' isn't already set in php.ini, we pass it separately
    // as an additional parameter instead of in the header.
    // However, if PHP's 'safe_mode' is on, this is not allowed.
    if (isset($message['headers']['Return-Path']) && !ini_get('safe_mode')) {
      $return_path_set = strpos(ini_get('sendmail_path'), ' -f');
      if (!$return_path_set) {
        $message['Return-Path'] = $message['headers']['Return-Path'];
        unset($message['headers']['Return-Path']);
      }
    }
      if (isset($message['Return-Path']) && !ini_get('safe_mode')) {
        // On most non-Windows systems, the "-f" option to the sendmail command
        // is used to set the Return-Path. There is no space between -f and
        // the value of the return path.
        $mail_result = @mail(
          $message['to'],
          $mail_subject,
          $mail_body,
          $mail_headers,
          '-f' . $message['Return-Path']
        );
      }

In htmlmail.mail.inc we have similar code

Of course to set that parameter, mail sending user needs to be a trusted user for mail system
I tried to contact system administrator to do that, but unsuccessfully
And I had to fix that problem ASAP.
So I decided to provide possibility not to add additional Return-Path
This situation happens rather hardly, but I think that additional option is helpful sometimes

salvis’s picture

I see, we're not adding a header (although it feels that way), but we're setting the envelope from address.

But why is your site configured to try to set the envelope from address if your mailer chokes on it?

Every additional configuration option is a burden on everyone involved, users, support, and maintainers, and I'm very conservative about adding new options, especially if they serve only very few sites and their benefit could be implemented outside of the module with reasonable effort.

I see two possible approaches outside of HTML Mail:

1. Find out what module is trying to set the envelope from address and why. Reconfigure or fix that module to make that optional.

2. Implement hook_mail_alter() to remove the Return-Path 'header'.

P.S. As system administrator I would be reluctant to allow an application to set the envelope from address, too, especially if you don't don't have a valid reason but just try to satisfy some inconsiderate piece of software.

id.tarzanych’s picture

Return-Path is set by Drupal Core, not a custom module
Look at includes/mail.inc, drupal_mail()

  if ($default_from) {
    // To prevent e-mail from looking like spam, the addresses in the Sender and
    // Return-Path headers should have a domain authorized to use the originating
    // SMTP server.
    $headers['From'] = $headers['Sender'] = $headers['Return-Path'] = $default_from;
  }

Well, I can cut down this param with a hook of course. As you wish.

salvis’s picture

Status: Needs review » Closed (won't fix)

I see. Having the Return-Path be the same as the From address is probably the default and should be OK if it's a legal sender. That's probably why most mailers accept it.

I understand your reasoning, but I haven't found any similar issue in the queue, so this must be an isolated issue on your site and it doesn't make sense to add features/options for isolated cases.