Print Page | Close Window

Lot of virus from deliveryexpr.com

Printed From: LogSat Software
Category: Spam Filter ISP
Forum Name: Spam Filter ISP Support
Forum Description: General support for Spam Filter ISP
URL: https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6938
Printed Date: 25 November 2024 at 9:51am


Topic: Lot of virus from deliveryexpr.com
Posted By: Shade
Subject: Lot of virus from deliveryexpr.com
Date Posted: 12 April 2011 at 4:22am
Dear Roberto,

At this time, we received lot of virus emails (W32/Malware), stopped by Norman, from same 5 or 6 domains, like, for example, deliveryexpr.com, etc.

I have add this domain to blacklistfrom domain, with rule ::NULL, but Norman's antivirus still analyse emails with ::NULL rule, even if in our log, SF detect this as spam with message "emailfrom is in local blacklist" ... and ... "will be rejected"

Is there a way to directly drop emails from, for example, *@deliveryexpr.com without norman's analyse (because of ::NULL rule) ?

It will be very good thing to decrease server load due to Norman's av activity...

Thank toy for reply,
Raphael.



Replies:
Posted By: LogSat
Date Posted: 13 April 2011 at 4:29pm
Shade,

We already replied via email, but for "Google", here's the same reply again :)

==============================
Slight correction on your syntax - you should use a :NULL suffix (with only one colon, not two), not two in that domain blacklist to obtain the effect you're looking for.

I hope this helps!



-------------
Roberto Franceschetti

http://www.logsat.com" rel="nofollow - LogSat Software

http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP


Posted By: Shade
Date Posted: 14 April 2011 at 2:19am
Thank you Roberto, that's exactly what I needed !

Best regards.



Print Page | Close Window