{ config, ... }: { age.secrets.dmarc = { file = ../../../../secrets/falkenstein/dmarc.age; }; users.users.dmarc = { description = "DMARC Report recipient"; isNormalUser = true; }; networking.firewall.allowedTCPPorts = [ config.services.elasticsearch.tcp_port ]; services.parsedmarc = { enable = true; provision = { grafana = { dashboard = false; datasource = false; }; localMail.enable = false; elasticsearch = false; geoIp = false; }; settings = { imap = { user = "dmarc@rfive.de"; port = 993; host = "mail.rfive.de"; password = { _secret = config.age.secrets.dmarc.path; }; }; opensearch.hosts = "localhost:9200"; }; }; services.opensearch.enable = true; }