MailScanner blocking ClamAV emails

Peter email at ace.net.au
Sat Mar 25 17:17:16 UTC 2017


Edit MailScanner.conf, change:

Virus Scanning = yes  to
Virus Scanning = %rules-dir%/virus.whitelist.rules

The in your rule directory create a file called virus.whitelist.rules which
uses the same syntax as spam.whitelist.rules - eg:

From: clamav at yourdomain.com and To: you at yourdomain.com   no

Don't forget to have the last line as:
FromOrTo	default	yes

The Yes/No refers to whether it is virus scanned.

Problem solved!

Cheers,

Peter


*********** REPLY SEPARATOR  ***********

On 25/03/2017 at 7:38 AM Walt Thiessen wrote:

>I have MailScanner set to check all inbound and outbound email using
>ClamAV.
>
>I have ClamAV set up to send me an email each day informing me of any 
>possible infections.
>
>For about a week or two now, this email has failed to arrive.
>
>My admins found the problem. ClamAV is apparently blocking itself via 
>MailScanner.
>
> From the maillog:
>
>[root at server ~]# grep 1cqtVW-0002rF-UX /var/log/maillog
>Mar 22 23:33:50 server MailScanner: Filename Checks: Allowing 
>1cqtVW-0002rF-UX clamav-2017-03-22.log (no rule matched)
>Mar 22 23:33:51 server MailScanner: Filetype Checks: Allowing 
>1cqtVW-0002rF-UX clamav-2017-03-22.log
>Mar 22 23:33:51 server MailScanner: Clamd::INFECTED:: 
>YARA.r57shell_php_php.UNOFFICIAL ::
>./1cqtVW-0002rF-UX/clamav-2017-03-22.log
>Mar 22 23:33:51 server MailScanner: Infected message 1cqtVW-0002rF-UX 
>came from 127.0.0.1
>Mar 22 23:33:51 server MailScanner: 1cqtVW-0002rF-UX: Received for 
>MailControl Database
>Mar 22 23:33:51 server MailScanner: 1cqtVW-0002rF-UX: MailControl cannot 
>insert row: %%C7RPN1O2FYP5LGSYVTBFOC2X10OGEDRXXIPRGRGJJJI5KDWFI8S
>
>We tried whitelisting root at server or 127.0.0.1, but it didn't help.
>
>Any ideas?
>
>Walt
>
>
>-- 
>MailScanner mailing list
>mailscanner at lists.mailscanner.info
>http://lists.mailscanner.info/mailman/listinfo/mailscanner





More information about the MailScanner mailing list