Print Page | Close Window

Lot of virus from

Printed From: LogSat Software
Category: Spam Filter ISP
Forum Name: Spam Filter ISP Support
Forum Description: General support for Spam Filter ISP
Printed Date: 15 February 2025 at 9:31pm

Topic: Lot of virus from
Posted By: Shade
Subject: Lot of virus from
Date Posted: 12 April 2011 at 4:22am
Dear Roberto,

At this time, we received lot of virus emails (W32/Malware), stopped by Norman, from same 5 or 6 domains, like, for example,, etc.

I have add this domain to blacklistfrom domain, with rule ::NULL, but Norman's antivirus still analyse emails with ::NULL rule, even if in our log, SF detect this as spam with message "emailfrom is in local blacklist" ... and ... "will be rejected"

Is there a way to directly drop emails from, for example, * without norman's analyse (because of ::NULL rule) ?

It will be very good thing to decrease server load due to Norman's av activity...

Thank toy for reply,

Posted By: LogSat
Date Posted: 13 April 2011 at 4:29pm

We already replied via email, but for "Google", here's the same reply again :)

Slight correction on your syntax - you should use a :NULL suffix (with only one colon, not two), not two in that domain blacklist to obtain the effect you're looking for.

I hope this helps!

Roberto Franceschetti" rel="nofollow - LogSat Software" rel="nofollow - Spam Filter ISP

Posted By: Shade
Date Posted: 14 April 2011 at 2:19am
Thank you Roberto, that's exactly what I needed !

Best regards.

Print Page | Close Window