Message too big for spam checks but Attachment stripped without explanation

Dave Jenkins davejenx at googlemail.com
Thu Jul 17 12:10:14 IST 2008


Hi,

I'm trying to work out why a message had its attachment stripped. The
attachment was replaced with the following mime-attachment.txt:

----8<----
[Attachment stripped: Original attachment type: "application/msword",
name: "calendar as at 16 July 2008.doc"]
----8<----

The text of this message doesn't correspond to anything I can see in
rules/en and I don't recall seeing it before. Usually when an
attachment is blocked, it is replaced with a more informative message
specifying why it was blocked and saying it has been quarantined or
explaining that it couldn't be. Here there is no indication in the
message or logs of why the attachment was stripped. It was not
qarantined. Here are the maillog entries:

----8<----
Jul 17 09:09:27 myhost postfix/smtpd[21892]: 6B20DFE0A1:
client=localhost.localdomain[127.0.0.1]
Jul 17 09:09:27 myhost postfix/cleanup[22942]: 6B20DFE0A1: hold:
header Received: from localhost (localhost.localdomain
[127.0.0.1])??by myhost.my.domain (Postfix) with ESMTP id
6B20DFE0A1??for <linda at some.domain>; Thu, 17 Jul 2008 09:09:27 +0100
(BST from localhost.localdomain[127.0.0.1]; from=<clair at some.domain>
to=<linda at some.domain> proto=ESMTP helo=<localhost>
Jul 17 09:09:27 myhost postfix/cleanup[22942]: 6B20DFE0A1:
message-id=<20080717090927.vhm5vhj94w4wos48 at mailserver.domain>
Jul 17 09:09:27 myhost postfix/smtpd[21892]: disconnect from
localhost.localdomain[127.0.0.1]
Jul 17 09:09:31 myhost MailScanner[13663]: New Batch: Scanning 1
messages, 706602 bytes
Jul 17 09:09:31 myhost MailScanner[13663]: Message 6B20DFE0A1.81B5B
from 127.0.0.1 (clair at some.domain) to some.domain is too big for spam
checks (706602 > 200000 bytes)
Jul 17 09:09:31 myhost MailScanner[13663]: Virus and Content Scanning: Starting
Jul 17 09:09:36 myhost MailScanner[13663]: Requeue: 6B20DFE0A1.81B5B
to 41596FE0A4
Jul 17 09:09:36 myhost postfix/qmgr[19910]: 41596FE0A4:
from=<clair at some.domain>, size=711200, nrcpt=1 (queue active)
Jul 17 09:09:36 myhost MailScanner[13663]: Uninfected: Delivered 1 messages
Jul 17 09:09:36 myhost postfix/local[22968]: 41596FE0A4:
to=<webNN_linda at myhost.my.domain>, orig_to=<linda at some.domain>,
relay=local, delay=9.4, delays=9.2/0/0/0.25, dsn=2.0.0, status=sent
(delivered to command: /usr/bin/procmail -f-)
Jul 17 09:09:36 myhost postfix/qmgr[19910]: 41596FE0A4: removed
----8<----

We do not block msword docs and have not previously seen this problem
with word or any other attachments.

The message was sent via Horde/IMP webmail running on the mail server,
with sender & recipient being in the same domain, which is hosted on
the mailserver.

Any help would be appreciated.

Thanks,

Dave


More information about the MailScanner mailing list