Why is this domain spoofing.

Steve Basford steveb_clamav at sanesecurity.com
Mon Nov 9 16:23:35 GMT 2009


> Quarantine:
>     Report: Clamd:  message was infected:
> Phishing.Heuristics.Email.SpoofedDomain

It's ClamAv's Heuristics that's "caught" something, for example:

http://www.mail-archive.com/clamav-users@lists.clamav.net/msg32419.html

If it's an FP, report to (full header/body):

http://cgi.clamav.net/sendvirus.cgi

Hope it helps,

Cheers,

Steve
Sanesecurity



More information about the MailScanner mailing list