I am testing the expression filter at the moment I have a word set up to force a mail into quarrantine, when I send a mail inbound it is correctly quarrantined. If I send the mail outbound it is not
The relevant part of the header is below with name info stripped
Received: from [10.0.0.1] (port=13172 helo=SERVER.company.local)
by mail.domain.co.uk with esmtps (TLSv1:AES128-SHA:128)
(Exim 4.69)
(envelope-from )
id 1LPmWV-0004SZ-2N
for gavin@domain.co.uk; Wed, 21 Jan 2009 23:30:15 +0000
Received: from SERVER.company.local ([fe80::181e:18b4:8f97:3557]) by
SERVER.company.local ([fe80::181e:18b4:8f97:3557%11]) with mapi; Wed, 21 Jan 2009
SERVER.company.local is the SBS 2008 with Exchange 2007 which is then recieved to be relayed by the Astaro and then delivered (not shown)
I'm going by the forum post that scanning outbound is possible so presumably scanning expressions is possible too (probably the most useful as you want to block any chance of a customer being sent a mail with certain words in it)
https://community.sophos.com/products/unified-threat-management/astaroorg/f/51/t/16094
Bug or no Bug?
Regards
Gavin