This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Virus mail suspected to be sent from internal

Hello,

We have Sophos Puremessage 4.0.2 and some days (mostly in the morning) that we receive Sophos warning message saying that it has blocked virus infected messages with our domain address but we have enabled "Recipient Validation".

We have also a rule in Exchange that blocks messages out of the organisation having our domain name int the mail address and it is working we tested with telnet spoof.

To be able to troubleshoot and find the source of the those emails I added an exeption with my email on VInbound/Outbound and Internal Anti-virus rules to be able to deliver those emails to analyse it but it seems I don't receive them.

I was wonering if it was normal and what could be the best way to troubleshoot this to find the source of those email, is there a way to find this with the help of Puremessage or with third party tools?

Thank you!



This thread was automatically locked due to age.