[clamav-users] clamav-milter and "whitelist"

Gerard E. Seibert jerry at seibercom.net
Sun Dec 22 11:26:04 UTC 2019


clamav-milter 0.102.1
FreeBSD 11.3-p5

Either I am not understanding how the "WHITELIST" works with
clamav-milter, or it is not working as I thought it would.

# This option specifies a file which contains a list of basic POSIX regular
# expressions. Addresses (sent to or from - see below) matching these regexes
# will not be scanned.  Optionally each line can start with the string "From:"
# or "To:" (note: no whitespace after the colon) indicating if it is, 
# respectively, the sender or recipient that is to be whitelisted.
# If the field is missing, "To:" is assumed.
# Lines starting with #, : or ! are ignored.
#
# Default unset (no exclusion applied)
Whitelist /usr/local/etc/whitelisted_addresses.txt

I have this line in that file:

	From:marketing at snopes.com

However, that file is being blocked with this message in the
clamav-milter.log file:

Fri Dec 20 20:12:00 2019 -> Message from <snopescom-cdyjlit1jrhddlljg1j at cmail20.com> to <<gerard_seibert at seibercom.net>> infected by SecuriteInfo.com.Spam-50327.UNOFFICIAL

These are the two pertinent headers from that message:

Return-Path: <Snopescom-cdyjyn1jrhddlljg1j at cmail20.com>
From: "Snopes.com" <marketing at snopes.com> 

I figure I am either entering the info in the file incorrectly, or I am
entering the wrong info. I cannot reliably use the "Return-Path:",
because it is not a constant.

I would appreciate it if someone could explain to me what I am dong wrong.

Thanks!

-- 
Jerry
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 488 bytes
Desc: OpenPGP digital signature
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20191222/ecf3061e/attachment.sig>


More information about the clamav-users mailing list