Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SPAM (confirmed) - Problems with Cyren Database or bad pattern?

Are there any problems with the cyren spam database at the moment or any bad pattern?

UTM 9.506 - Pattern 138738

 

I've got a customer and regular mails from @siemens.com, @samsung.com, @dyson.com are rejected as Spam (confirmed)!? Also the customer self is not able to send mails to me -> customer domain is also classified as Spam (confirmed) at our UTM.

I checked blacklists and cyren but no entry! A lot of false positives?!?

I had a similar problems last week with an other customer. A lot of trouble at the moment...

 

Anybody else can confirm?

 

regards



This thread was automatically locked due to age.
  • Do you wonder if this is a problem for you?

    Here's a quick way to get a list of all email senders to you (user@domain.com) that were blocked as confirmed spam this year:

    zgrep 'reason="as" extra="confirmed"' /var/log/smtp/2018/*/*|grep 'to="user@domain.com"'|grep -oP 'from=".*?"'|sort -n|uniq -c|sort -n

    Or, just the ones this month:

    zgrep 'reason="as" extra="confirmed"' /var/log/smtp/2018/05/*|grep 'to="user@domain.com"'|grep -oP 'from=".*?"'|sort -n|uniq -c|sort -n

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I can also confirm strange issues with spam confirmed at customer sites in the last days.

    Glad to hear that Sophos now really tries to fix/analyse this issue instead of just telling "false positives"! Of course there can be "false positives" but not in this way...

     

    regards

  • I've captured four so far. Still need others to open a ticket and submit or to submit via me.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I quarantine everything that is marked as Spam.   Today, I flagged several using "release and report as false positives"   Is that sufficient?

  • I received an email 3.5 hours ago from Sophos Support (the people that interface for the developers and Sophos Labs):

    I have received an update on my submission. Labs has confirmed that they have found the cause for the misclassification and have corrected our data accordingly.
    Please let me know if you have any more of these false positives.

    Please post here if you don't perceive that the problem has been fixed.

    Thanks to SWeissflog for opening this thread!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA