Server Alerts reports "Virus Detected in inbound email" for spam

I receive hundreds of email every day that a Virus was detected in inbound email.  When checking the contents of /Library/Server/Mail/Data/scanner/quarantine these messages are only spam message, not viruses.  Virus infected messages seem to get placed in /Library/Server/Mail/Data/scanner/virusmails
I am running on Mavericks Server 3.1.2 (1354517)
serveradmin -v = Version 10.8 ($revision: 1.13 $ -- May 13 2014)
Does anyone know how to tune the Server Alerting to properly handle the files in /Library/Server/Mail/Data/scanner so that virusmails are reported as virus's but quarantine is not reported?
I have searched high and low, and cannot find where this is controlled.  With Mavericks, I no longer see Virus Alerts under the alerts management menu of Server.app
I checked amavisd configs, as well as many other files under /Library/Server for any references to "quarantine" text, to no avail.
I dumped all of serveradmin settings, and do not see anything that references quarantine except for the quarantine recipient addresses for spam and viruses.
Is anyone else experiencing this, or does anyone know how to solve this?
Thanks in advance.

I received over 200 spam messages yesterday that got reported as viruses to me, and out of frustration, I discovered a work around.  I don't know if this is the result of a past update, or the steps I used trying to reset the server, but I performed the following and was able to suppress the email alerts.  At the time of my original posting, the Alerts section of the Server.app did not offer any option for disabling the alerts for virus..
1) Launch Server.app
2) Select Mail in left pane
3) Turn off Virus filtering
4) stop/start Mail server
5) Turn on Virus filtering
6) stop/start Mail server
7) Turn off Spam filtering
8) stop/start Mail server
9) Turn on Spam filtering
10) stop/start Mail server
11) Select Alerts in left pane
12) clear all active alert
13) Under notifications tab, I now saw "Mail" as an option
13.1) Turn off the alerts for Mail
Now I don't get spammed with Virus alerts for spam messages.  This is not a fix for the configuration error in the alerting service, but it does stop the admin mailboxes from being flooded with virus alerts for all spam messages.  I cannot confirm if it was the enable/disable of the filtering that added the Mail entry under alert notifications or if it was an update, as I did not check the alerts notifications at the time.  I was frustrated, and desperate for a fix, so I did the first thing that came to mind.  But now my Mail system alerts can be enabled/disabled through server.app so I am happy.  Lets just hope for a classification fix in the Yosemite update coming this fall.

Similar Messages

  • Virus detected in inbound email

    We have just upgraded to OSX Server 3.0.3 and am now getting alerts saying "Virus detected in inbound email".
    Go to /Library/Server/Mail/Data/scanner/quarantine 
    When I go to the folder, I don't have permission to get into it even though I am logged into the server as the administrator?
    I need to see if these are coming from customer or not.
    Any ideas on how to inspect them much appreciated.
    Thanks
    Carl

    I found this post on Google, sorry to dig up an old thread but I'd just like to say you can inspect them this way:
    sudo su
    cd /Library/Server/Mail/Data/scanner/quarantine
    ls
    If the files are gz format like they are on my server you can:
    zless <bad file name here>.gz
    Then use your up and down keys to see the HTML content or anything else. In my case it was actually a legitimate message being marked as spam, not a virus at all!

  • Virus Detected in inbound e-mail

    I have been getting alerts on mac os server pertaining to the mail:
    Virus detected in inbound email
    A virus was detected in an inbound email. The message containing the virus was not delivered to the intended recipient and has been moved to:
    /Library/Server/Mail/Data/scanner/quarantine
    It is recommended that you delete all messages in this directory. Messages left in the above location for longer than 72 hours will be automatically deleted.
    However when I go look in that folder it is empty (I know it deletes in 72 hours but I look immediately).  I get no info on who it was intended for, what was really done with it, if it was a mistake or anything.  Am i missing something?
    Thanks

    I found this post on Google, sorry to dig up an old thread but I'd just like to say you can inspect them this way:
    sudo su
    cd /Library/Server/Mail/Data/scanner/quarantine
    ls
    If the files are gz format like they are on my server you can:
    zless <bad file name here>.gz
    Then use your up and down keys to see the HTML content or anything else. In my case it was actually a legitimate message being marked as spam, not a virus at all!

  • Inbound Email for Upload attachment

    HI Guys,
    What is the procedure to Upload CSV File attachment by inbound email in SNC via File Transfer Functionality.
    -$andeep

    Hi Nikkil
    We are facing the same issue on upload File Transfer through Inbound Email functionality
    It Would be great if you throw some light on this issue
    We are processing ASN through an Email for Due List of purchasing Documents
    When we send  a E-mail with CSV file as an attachment to the defined Reciepent Mail addresss
    It reaches SNC and also visible in SOIN TA,  but there is no further update on this transaction, ASN is not getting posted for this attachment
    We had made the following Setting for Inbound Email for File Upload
    Make Settings for Global Constants-  qRFC destination, Sender e-mail
    Number Ranges for File Transfer-Define Number Ranges for Upload Profile Number
    Determine Accepted E-Mail Addresses for File Upload- we had mapped the Interace(ASNDLPD) to Email Pattern
    Determine Error Control of the File Upload - for Interface (ASNDLPD)
    And we are also maintanied the exit rules for Inbound processing In SO50 - we had entry for /SCA/CL_FTR_MAIL_INBOUND for Internet Mail(Communication Type)
    Is there any other setting that we missed out?
    Regards
    Satish

  • FSE Marking ALL Inbound Email as Spam due to Content

    New installation. All inbound mails are marked as Spam by Cloudmark for Content. From anyone:  Yahoo, Gmail, Hotmail, O365... all mail(even when testing from the Edge server itself to itself by telnet 127.0.0.1 25).
    New, greenfield installation:
    Windows Server 2012 DC's, Windows Server 2012 functional level
    Exchange 2013 All roles (CAS/Mailbox) on Windows Server 2012
    Exchange 2010 Edge Server with Forefront Protection for Exchange 2010 on Windows 2008R2
    Cloudmark engine is updating successfully and shows today's date as the version.
    ALL emails inbound
    Logs show: 
    When I set Forefront to stamp and continue processing (it goes into junk mail):  "FSE Content Filter Agent,OnEndOfData,AcceptMessage,,SCL,9"
    When I reject:  "FSE Content Filter Agent,OnEndOfData,RejectMessage,550 5.7.1 Message rejected due to content restrictions,SclAtOrAboveRejectThreshold,9,v=2.1 cv=M6V0dUAs c=0 sm=1 tr=0 p=PdbawN1DAAAA:8 a=mFs5E60Zd2Jof9JknIyuNg==:117 a=dOjwkhujJHM2b/QMFULrXQ==:17
    a=nDghuxUhq_wA:10 a=UzMy6eNlxVsA:10 a=pGLkceISAAAA:8 a=1XWaLZrsAAAA:8"
    When I quarantine: "FSE Content Filter Agent,OnEndOfData,QuarantineMessage,550 5.2.1 Content Filter agent quarantined this message,SclAtOrAboveQuarantineThreshold,9,v=2.1 cv=ep3mkOZX c=0 sm=1 tr=0 p=PdbawN1DAAAA:8 a=WkljmVdYkabdwxfqvArNOQ==:117 a=8rjiAUXplIkA:10
    a=YaFYD9Hhv54A:10 a=uBmvdUkjAAAA:8"
    Messages are simply "This is a test" messages.
    Product appears to be activated.

    Hi
    I think you have encountered a problem that all of incoming mails were treated as SPAM. The information that you provided indicates that these mails were marked as SCL rating 9 which will be deleted, rejected or
    quarantine . However, normal mails should be mark as SCL-1 and these mails usually  can be forwarded.
    Please check the configuration with following steps:
    What are the allow words or block words you defined before ?
    How did you dispatch SCL rating  for different mails ?
    How were the mails treated in each SCL rating
    You are able to get more information about  “SPAM content filter” by the link below:
    Understanding Anti-Spam and Antivirus Mail Flow
    http://technet.microsoft.com/en-us/library/aa997242.aspx
    Configuring spam filtering
    http://technet.microsoft.com/en-us/library/dd441022.aspx#contentf
    Microsoft Forefront Protection 2010 for Exchange Server
    http://technet.microsoft.com/en-us/library/cc482977.aspx

  • Accepting inbound emails for other Organization

    Hi There,
    We have an Organization (it is a ODC) which wants to route their emails through our gateway servers. Mailboxes will be hosted on their servers. We don't have any contacts for their organization users'. How can we route their outbound and inbound through
    our systems??
    Can we create a send connector and route their email smart host? Please provide few steps. Thank you!

    Hi There,
    We have an Organization (it is a ODC) which wants to route their emails through our gateway servers. Mailboxes will be hosted on their servers. We don't have any contacts for their organization users'. How can we route their outbound and inbound through
    our systems??
    Can we create a send connector and route their email smart host? Please provide few steps. Thank you!
    What are you using for gateway servers? 
    Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • Not able to run adhoc report (2008) and send by email

    Hello All,
    I am trying to set up subscription on adhoc  reports. I have already configured SMTP.
    Whenever I create a subscription, it is getting saved but the status remains "New Subscription" for all the reports. and also not sending email for any error.
    Can you please suggest for same?
    Thanks in Advance
    Regards
    Kumud

    Sometimes, in special cases, the developers or other functional consultants do not understand the security concept, or they don't have one to use, or they have no faith in the one which they do have, anymore... at which point they create "check tables" in which the user ID's names of those authorized to run the report can be maintained via a view or other less sophisticated approaches. This is sometimes also the reason why they claim that they cannot perform their work in production systems without SAP_ALL.
    This is less primitive than hard coding the user names into the report itself... which was the era before the check table approach, before they realized that they had to maintain the report code itself all the time. This is sometimes also the reason why they claim that they cannot perform their work in production systems without developer keys for them.
    If my above rant is the explanation for this strange behaviour, then you will most likely find it by scanning the report code for use of the system field "SY-UNAME".
    (Use the binoculars or report RPT_SCAN_SOURCE - not sure of the exact spelling though).
    Cheers,
    Julius

  • Cannot configure email for an Office365 Sharepoint list

    Hi,
    We are using an Office365 deployment of Project Online and SharePoint sites. There is a lot of information available on how to configure SharePoint lists to receive emails however the only option I have under List Settings | Communications is for RSS Feeds.
    Can anyone tell me if this feature available in Office365 SharePoint? 
    Regards,
    Conrad 

    Hi Conrad,
    Please refer to the threads below for the email settings in Office 365 SharePoint sites:
    http://community.office365.com/en-us/f/154/t/809.aspx
    QUOTE:
    Email alerts and workflow notifications can be sent to SharePoint users when documents or other items have been changed or added to a site. SharePoint Online does not at this time support to inbound email for document libraries, discussion boards, calendars,
    and lists.
    If you would like to make SharePoint sites to receive emails, I'd suggest you conside sitemailbox in SharePoint site:
    http://office.microsoft.com/en-in/office365-suite-help/prepare-for-using-site-mailboxes-in-office-365-HA103834109.aspx
    Regards,
    Rebecca Tu
    TechNet Community Support

  • Exchange server 2013 content filter rejecting all incoming messages as spam.

    Hello All,
    Today out of the blue our Exchange server 2013 install started rejecting any inbound message as spam. It first started with only one user not being able to receive any mail because of this anomaly and
    then after 12 or so hours all users were getting their mail rejected.
    I currently had the threshold set to 5 on external messages only. Internal is disabled.
    I have tried setting the threshold to 8 and 9, and rebooted the server after restarting
    all services just to make sure everything reset. Even dished out a IISRESET just in case. Whatever I tried still does not work.
    The install is a stand alone server facing the outside world (no edge server) living
    in a 2 domain controller environment with a share point farm thrown in (ESXI5.5 environment)
    Everything works just fine and dandy if I disable the content filter all together. Not seeing anything in the application logs out of the ordinary. Everything was working great and the same settings I used on this server worked well for a totally different
    server that runs just fine.
    Any ideas?
    fr0stsp1re

    RunspaceId                            : 87157b62-a061-436b-8fb9-dab446be3473
    Name                                  : ContentFilterConfig
    RejectionResponse                     : Message rejected as spam by Content Filtering.
    OutlookEmailPostmarkValidationEnabled : True
    BypassedRecipients                    : {}
    QuarantineMailbox                     :
    SCLRejectThreshold                    : 6
    SCLRejectEnabled                      : False
    SCLDeleteThreshold                    : 9
    SCLDeleteEnabled                      : False
    SCLQuarantineThreshold                : 9
    SCLQuarantineEnabled                  : False
    BypassedSenders                       : {}
    BypassedSenderDomains                 : {}
    Enabled                               : False
    ExternalMailEnabled                   : True
    InternalMailEnabled                   : False
    AdminDisplayName                      :
    ExchangeVersion                       : 0.1 (8.0.535.0)
    DistinguishedName                     : CN=ContentFilterConfig,CN=Message Hygiene,CN=Transport Settings,CN=Smith And
                                            Smith,CN=Microsoft
                                            Exchange,CN=Services,CN=Configuration,DC=XXXXXXXXXXX,DC=com
    Identity                              : ContentFilterConfig
    Guid                                  : 8f86e0b6-da37-42d3-b7cd-b9635b7db271
    ObjectCategory                        : XXXXXXXXXXXXXXXXXXX/Configuration/Schema/ms-Exch-Message-Hygiene-Conten
                                            t-Filter-Config
    ObjectClass                           : {top, msExchAgent, msExchMessageHygieneContentFilterConfig}
    WhenChanged                           : 5/28/2014 12:15:21 PM
    WhenCreated                           : 5/1/2014 4:17:55 PM
    WhenChangedUTC                        : 5/28/2014 7:15:21 PM
    WhenCreatedUTC                        : 5/1/2014 11:17:55 PM
    OrganizationId                        :
    OriginatingServer                     : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
    IsValid                               : True
    ObjectState                           : Unchanged
     This is what it is set at now. Completely disabled. It worked fine for quite some time filtering out spam pretty nicely then one day everyone's mail was being rejected as spam by the content filtering agent. I know of someone else who also had this
    issue except their box was running 2008R2 with EX2007. They too disabled the content filter as it was giving them too many problems with mail being rejected.
    fr0stsp1re

  • Inbound SOAP for IDoc : Register Service

    Hi ,
    We have a requirement where we need to post an Inbound IDoc in the R3 from a Web Service that is called from a 3rd party application, I found something in the Transaction
    SALE->Basic Settings-> Inbound SOAP for IDoc : Register Service in R3 , the documentation says "You execute the report SRT_REGISTER_SERVICE to activate Inbound SOAP for IDocs." But I'm confused what needs to be done after that.
    Can anyone throw some more light on the following issues :
    a) where does the WSDL get stored for the IDoc,
    b) how to register a particular IDoc as a web service such that it can be called from third party system.
    Thanking all the experts in advance for their valuable time and help.
    Regards,
    Advait.

    Hi Advait,
    Did you get any further with this problem. I have the same issue and I don't know how to go further on this
    Ron

  • Verizon filtering OUTGOING email as spam now

    My sister sent me an email with a home listing of a house she wants to buy.
    I tried to forward it onto other people that I know.
    However, I get this from Verizon's mail server:
    9:58:43 PM S:550 5.7.1 The message you attempted to send was determined to be spam. Please visit http://www.verizon.net/spamfaq for more information.
    Seems all of a sudden Verizon has determined that they'll filter their outbound email for spam, you get NO recourse if they falsely identify something as spam, you cannot call, contact anybody about it and all verdicts are final.
    This is the last straw.  In 6 months when my contract is up, I'm switching back to Road Runner.

    So I'm guessing you're using verizon.net email?
    You're going to switch to RoadRunner and use their email now?
    You'll have to service, sign up for new service, and equipment/etc..etc just to switch email accounts just to fix a "spam" issue, 
    Why not just use a better email provider?
    Use gmail or something, then your email itself isn't tied on your ISP.

  • Alert Report through email

    Hello Dear Sir/Madam
    I want to configure our ISA server 2006 to send alert reports to my Gmail account. in the Alert action settings ISA server just ask about the email account but how can I configure the password for that account so ISA can have access to that?
    appreciate your help.

    Hi Arsh,
    You will not have options to enter Password. You need to use internal Exchange or any mail server with Anonymous access to the email address.
    Or if you want to use Gmail address - You may have to configure an SMTP realy on your network and then use SMTP relay to send Email to Gmail and from tr it will deliver other mailbox.
    https://support.google.com/a/answer/2956491?hl=en

  • How to configure notification emails for reports output or alerts for all users in r12

    Hi,
    I need to configure notification emails. I have provided settings in OAM-> Workflow and SMTP IP address in settings and only Outbound. I am able to test for my user ID.
    I want to know how to redirect emails or alerts for users like when a user runs a report he should get notification email in his outlook about the report output and details. In settings it only points for one replyto field. How do I mention all user ID's?
    Regards,
    Mohammed

    Hi Mohammed,
    You may check on XML bursting for XML based reports.
    In addition, also see links:
    http://oracle.anilpassi.com/email-output-of-concurrent-program-request.html
    Anil: Oracle Apps Concurrent program Output as Email
    Oracle ERP World: Email the output of a concurrent program as Attachment
    Also see:
    How to Redirect Output from Printer to Mail Message after Running Report (Doc ID 1036586.6)
    Thanks &
    Best Regards,

  • Inbound Email configuration - SAP CRM with MS Exchange Server

    Dear Pundits,
    We are implementing SAP CRM and one of the requirement is to configure the Inbound email functionality.
    As of now, we have successfully configured the outbound mail functionality.
    The inbound email functionality to a Single client:
    Our MS Exchange Server Domain is ITAstute.com.
    Where as, on the CRM system, under SCOT transaction --> Settings --> Default Domain, we have entered the Domain name as
    crm-dev.itastute.com
    We are planning to receive emails for different email id's like service, complaints, and so on into our SAP system.
    How will the exchange server can direct the mails from above external emails from domail itastute.com to onto CRM server domain crm-dev.itastute.com????
    Thank you,
    Nikee

    Then you need to define the routing rule in the exchange server.
    Exchange server config is outside the SAP scope and you should contact your exchange admin to get it done.
    Also they might force you to use the port 25 if you have any policy such in your company.
    We used the routing rule from exchange to BIGIP and BIGIP to our SAP server, that way we could use different port.
    You could search in google for the steps and i come accross the link given below.
    See if its useful.
    Link: [exchange rule|http://www.petri.co.il/forums/showthread.php?t=13120]
    Additional input related to the rule.
    you need to define the virtual host if you have more than one client that need to be configured for inbound routing.
    *@crm-dev.itastutecom => * applies to any user in your system and crm-dev.itastutecom should be your virtual host.
    janus.itastute.com => is your hostname and define port number for each client that need to configured.

  • Error in workflow mailer configuration - Inbound Email Server

    Hi
    I have Windows 2000 SP4.
    I have installed Oracle Workflow 2.6.3 Standalone as below
    I have installed Oracle Database 10gR1 and Oracle Workflow Server 2.6.3 in same oracle home.
    I have installed Apache HTTP Server 9.0.4 and Workflow Middle Tier in the same oracle home.
    I have finished installation and configuration successfully.
    Now I want to configure mailer parameters.
    I have started Workflow Component Container and Workflow Management Container.
    When I try to enter paramters for mailer I get error in Inbound EMail Account Server Name.
    The error says: Unable to make a network connection.
    I do not want to configure Inbound Mail Server but I need to enter these parameters as they are mandatory.
    I set Inbound Thread Count = 0 so that configuration does not consider parameters for IMAP server.
    My mail server is SMTP server.
    Any idea how to overcome this error and continue with notification mailer configuration?
    Thanks

    You would need to modify all the parameters listed in this script. This script updates each of the mailer and agent listener parameter. You may edit the script to remove all API calls OTHER THAN those for "Workflow Notification Mailer".
    Then update ALL the parameters for "Workflow Notification Mailer" with appropriate values with Inbound Thread Count to 0 and Outbound Thread Count to 1. Inbound Server Name, Account, Inbox, Discard and Processed values can be ignored. Make sure Outbound Server Name is valid SMTP Server name.
    Values like From, HTML Agent should point appropriately as per your env.
    Hope this helps
    Vijay

Maybe you are looking for

  • Incorrect oracle query in perl

    I the the following perl script, however it does not return anything. Did i form my syantax wrongly? $sth=$dbh->prepare("select a.rowid,a.* from Table1 a                   where a.field1 = \'$Indicator1\'                   and a.schedule = \'$Indicat

  • I need help to reinstall photoelement 12

    I got a message saying to update to photoelement 12.1 but is unable to do so when I try.  It says's contact customer service.

  • Runtime Excetpion

    Hi dudes I am new to this forum. I am using iText pdf converter in my office. When i tried to create a dynamic pdf file, generates some runtime exceptions. It is compiling with out any problem I had run the same code in another system at my home with

  • Error -100000 when downloading gifted songs

    So for Christmas, my uncle gifted me a bunch of songs (three albums and four songs). In one of the albums, the Dick Figures Season 1 Soundtrack, I cannot download four songs. iTunes keeps giving me error -100000. It says the file is corrupt and I sho

  • Connection pooling - looking for some advice

    Hi all, I wish to implement a JDBC connection pool. I have read through previous posts and have also read the tutorial on connection pooling. Some things are just still not quite clear. I am only actually asking for advice as my deadline is approachi