Why is this domain spoofing.

Robert Lopez rlopezcnm at gmail.com
Mon Nov 9 17:29:46 GMT 2009


On Mon, Nov 9, 2009 at 9:23 AM, Steve Basford
<steveb_clamav at sanesecurity.com> wrote:
>> Quarantine:
>>     Report: Clamd:  message was infected:
>> Phishing.Heuristics.Email.SpoofedDomain
>
> It's ClamAv's Heuristics that's "caught" something, for example:
>
> http://www.mail-archive.com/clamav-users@lists.clamav.net/msg32419.html
>
> If it's an FP, report to (full header/body):
>
> http://cgi.clamav.net/sendvirus.cgi
>
> Hope it helps,
>
> Cheers,
>
> Steve
> Sanesecurity
>
> --
> MailScanner mailing list
> mailscanner at lists.mailscanner.info
> http://lists.mailscanner.info/mailman/listinfo/mailscanner
>
> Before posting, read http://wiki.mailscanner.info/posting
>
> Support MailScanner development - buy the book off the website!
>

Steve,

Thanks for the reply.
None of those messages were quarantined so I have nothing to scan.

However, it seems if I properly white list ptk to Mailscanner, then
Mailscanner should not send the email to Clamd. Does that seem
correct?

-- 
Robert Lopez
Unix Systems Administrator
Central New Mexico Community College (CNM)
525 Buena Vista SE
Albuquerque, New Mexico 87106


More information about the MailScanner mailing list