Saw something interesting in yesterdays stats from one of my mail servers...
Exim Error Stat Collector
========================================================================
Obtaining Records for 2003-09-19...
BLACKLIST Hostname 661
BLACKLIST Sender 0
BOUNCE Attachment 0
BROKEN HELO-EHLO 2,554
DISCARD VIRUS 0
DISCARD ATTACHMENT 7,244
DISCARD MAXSPAM 2
DISCARD TZDATE 569
DROP RBL-ALWAYS 2,273
HELO MISMATCH 4,682
HELO OUR SYSTEM 1
HELO OUR IP 1,919
MARKED AS SPAM 450
MIME ERROR 0
BLACKLIST EXPRESSION 25
RELAYING NOT ALLOWED 56
SPAM BLOCK RBL-LOCAL 1,526
SPAM BLOCK rDNS ERROR 3,311
SPAM BLOCK RBL-ANTISPAM 2,987
SPAM BLOCK RBL-COUNTRY 82
SPAM BLOCK OPEN PROXY 23
SPAM BLOCK RBL-OPENRELAY 1,666
UNKNOWN USER 1,501
INVALID HOSTNAME-HELO 3,786
All of those virus/worm messages (over 7,000) not one was caught by ClamAV
because it never got that far. Exiscan-ACL caught them all with .exe .com
attachment content scanning and discarded them.
--
Kevin W. Reed - TNET Services, Inc.
Mailing List Account
URL:
http://www.tnet.com