Scott Kopel wrote: > I'm noticing a bunch of obviously spam that is getting thru because it > is "whitelisted" > where is this whitelist? it's not something I created. > it's not the auto_whitelist is it? wouldn't that say AWL Yes, that would say AWL. And SA's whitelist_from* would sa USER_IN_WHITELIST. > is it the phishing whitelist? when I start MailScanner I see "Read 755 > hostnames from the phishing whitelist" No, that merely exempts certian sites from the phishing net that tries to detect phishing attempts like: <a href= foo.com>signin.ebay.com</a> > thanks for any help This message was whitelisted at the Mailscanner by the file pointed to by your "Is Definitely Not Spam" setting in your MailScanner.conf.
Words of advice: My guess is that you whitelisted all mail to one or more recipients, and that this message was actually sent to several people at once, including one whitelisted user. Since there's only one message to act on, MailScanner honored the recipient whitelist. There's a whole lot of people in the Cc: line.. are any of them listed in your whitelist for "To"? It's also possible there were more recipients that were Bcc'ed in (typical for spam). To find these, try grepping your maillog for the SMTP id: grep kAUJvfwn002997 /var/log/maillog