The Sophos Community will be offline for scheduled maintenance this Saturday, May 27th, at 13:00 UTC for approximately 1 hour. Apologies for any inconvenience caused.
"Wanna" ransomware outbreak. Please see this Sophos article sophos.com/kb/126733 for advice on how to protect your organization. Immediate action recommended.
Issue If you are using a POP3 Connector for Microsoft Exchange, you may see inbound mail scanned as internal.
Sophos product and version PureMessage for Microsoft Exchange 3.0.0 Operating system Windows 2003 SBS SP2 Exchange 2003 SP2
Open the PureMessage Administration Console
Inbound mail should now be treated correctly
Technical Information When using a POP3 Connector in Exchange it effectively acts as a relay for the mail.
The POP3 mail is pulled from the ISP and then 'converted' to smtp, it is then relayed onto the Exchange mailboxes via PureMessage. This action counts as the first 'hop' for the mail. PureMessage checks the first 'hop' to see if it is an internal IP address, if it is then the internal policies are applied to it. If the IP address is an external one, then the inbound policies are applied.
By adding the IP address of the server to the list of trust relays, the first hop is ignored.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. If you need technical support please post a question to our community. Alternatively for licensed products open a support ticket.