When UTM9.x recieves a smtp e-mail and the sender adres is from the "internal" domain.
UTM 9.x doesnt scan for virusses. even when it is send from outside the network it is passed to the mail server without checking.
Just change in your email client (from home for example ) your sender adress to for example "info@yourcompany.com"
and send a email to yourname@yourcompany.com
Tested it with eicar.txt and it passes to the internal mail server. (not checked because of internal domain)
Change the sender to info@sophos.com and spf will block the email
Change the sender to yourname@hotmail.com and it is rejected containing malware ( as it should )
when using a blacklisted extention it will block the email
when using a blacklisted recipient it will block the email
How can check incoming email for all domains and not pass malware
This thread was automatically locked due to age.