This rejection is coming from clamav, not spamassassin. They're entirely
separate.
Please follow Aleksander's post.
Thanks Aleksander!
--
-Eric 'shubes'
On 04/21/2014 10:59 PM, Linux wrote:
Eric,
I used to bypass my Gmail ID as,
1. put my gmaul id in whitelist_senders
2. in ~/.spamassassin/user_prefs.cf
whitelist_from [email protected]
But is not receiving mails got same (Heuristics.Phishing.Email.SpoofedDomain
virus) bounce mail in Gmail.
-----Original Message-----
From: Eric Shubert [mailto:[email protected]]
Sent: Monday, April 21, 2014 9:46 PM
To: [email protected]
Subject: [qmailtoaster] Re: failure when forward mails from Gmail
On 04/21/2014 12:11 AM, Linux wrote:
Hi team,
I am getting bounce back when I forward mails from my Gmail account to
my qmail.
I am forwarding mails that received from hdfcbank.net.
How I can allow mails from particular Email ID.
---------- Forwarded message ----------
From: *Mail Delivery Subsystem* <[email protected]
<mailto:[email protected]>>
Date: Fri, Apr 18, 2014 at 11:42 AM
Subject: Delivery Status Notification (Failure)
To: [email protected] <mailto:[email protected]>
Delivery to the following recipient failed permanently:
[email protected] <mailto:[email protected]>
Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the server
for the recipient domain example.com <http://ikf.co.in> by
webmail.example.cm <http://webmail.ikf.co.in>. [X.X.X.X].
The error that the other server returned was:
554 Your email was rejected because it contains the
Heuristics.Phishing.Email.SpoofedDomain virus
This bounce is happening as a result of a clamav scan.
Which version(s) of QMT are you using?
Are you using sanesecurity signatures (you ran
qtp-install-sanesecurity)? They occasionally get a false positive.
Presuming you're using sanesecurity, you can find the rule somewhere in
/usr/share/clamav/unofficial-dbs and comment it out.
A more drastic measure would be to turn off scanning for certain
senders, but I would only do that for trusted senders such as financial
institutions, certainly not gmail. Are you certain that this is a
legitimate email from hdfcbank.net? These are precisely the type of
phishing attempts that sanesecurity is intending to block.
If you're forwarding everything from gmail to QMT, you might instead set
up fetchmail to pull the messages from gmail for this account. You could
then turn off virus scanning just for fetchmail, which would be simpler
and more secure than turning off scanning for all of gmail.
I think the best solution would be to use the QMT email address with the
hdfcbank account, and bypass scanning messages from hdfcbank servers.
That's what I do.
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]