Koozali.org: home of the SME Server

Email slipping through without being scanned by SA

oliverm

Email slipping through without being scanned by SA
« on: March 07, 2005, 09:54:49 AM »
Having problems with a number of emails (quite a number really) getting through the SME box without being scanned by SA. We are running SME 6.01.

Below are the headers from one of todays spam that hasnt been touched by SA at all. You can see that there are no headers there whatsoever by SA. I think about 20% of emails are coming through without ever being scanned at all by SA.

Anyway I can find out why this is ? Anything I can check ?

Headers below.

Olly



Microsoft Mail Internet Headers Version 2.0
Received: from <SME_BOX> ([IP_HERE]) by exchange_server.mydomain.co.uk with Microsoft SMTPSVC(5.0.2195.6713);
    Sun, 6 Mar 2005 16:54:47 +0000
Received: (qmail 28124 invoked from network); 6 Mar 2005 17:40:48 -0000
X-Virus-Scanned: by amavis-ng-0.1.6.4-03dc on <SME_BOX>
Received: from 67.rdns.gst-oxf.uk.areti.net (HELO mx3.mail.areti.net) (193.118.189.67)
  by <SME_BOX> (192.168.100.9) with ESMTP; 06 Mar 2005 17:39:48 -0000
Received: from pool-70-19-240-25.bos.east.verizon.net (pool-70-19-240-25.bos.east.verizon.net [70.19.240.25])
   by mx3.mail.areti.net (8.13.3/8.13.3/Areti-4.1.0R) with ESMTP id j26GkHbQ016988
   for <MY_EMAIL_HERE>; Sun, 6 Mar 2005 16:46:19 GMT
Received: from amstone.net (mail.amstone.net [216.168.119.2])
   by pool-70-19-240-25.bos.east.verizon.net with esmtp
   id 9F87B37B6F for <MY_EMAIL_HERE>; Sun, 06 Mar 2005 10:46:17 -0600
Message-ID: <011101c5226c$01621b58$1b7edcb0@amstone.net>
From: "Atheistic G. Grass" <hookers@amstone.net>
To: Om <MY_EMAIL_HERE>
Subject:  Reply: Rtenott Wrohes fucekd in all hloes
Date: Sun, 06 Mar 2005 10:46:17 -0600
MIME-Version: 1.0
Content-Type: multipart/alternative;
   boundary="----=_NextPart_000_0003_68B7F63A.C012EFBD"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2479.0006
X-Virus-Scanned: by Ameriserv.net Anti-Virus E-Gateway
Return-Path: hookers@amstone.net
X-OriginalArrivalTime: 06 Mar 2005 16:54:47.0656 (UTC) FILETIME=[34717E80:01C5226D]

Offline kruhm

  • *
  • 680
  • +0/-0
Email slipping through without being scanned by SA
« Reply #1 on: March 07, 2005, 02:17:25 PM »
check your clamAV. Make sure your scan outgoing email is set to yes. There is a relationship/corelation between SA and clamAV.

/sbin/e-smith/db configuration setprop amavis-ng qmail-queue /var/qmail/bin/qmail-spamc
/sbin/e-smith/signal-event email-update

oliverm

Email slipping through without being scanned by SA
« Reply #2 on: March 07, 2005, 03:42:30 PM »
Not sure that is the issue, as we have an identical SME install working at another site (running of a clone of the original install) which is also set to not scan outgoing emails and doesnt have a problem.

Offline kruhm

  • *
  • 680
  • +0/-0
Email slipping through without being scanned by SA
« Reply #3 on: March 08, 2005, 01:32:47 PM »
set to not scan outgoing emails
doesn't matter if the other isn't having problems -this one is. In my experience, it's having problems because of clamAV updates and in my experience because of the option set to not scan outgoing emails. turn outing scanning of outgoing emails on and problem disappears (just give it a shot, it can't take more than 5 minutes to test).

check your clamAV logs and maillogs, specifically amavis-ng logs.

and make sure your SA settings are at level 5