This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Spam from spoofed internal address not filtered

Hi,
In the recent days we are receiving a lot of spam mails with spoofed "from:" sender addresses from internal addresses. The spam filter on our Astaro 6.3 marks them with a very high spam score but does nothing more with them. Other "conventional" spams are filtered out into the proxy content filter.

I first suspected to have an infected Workstation within our network, but the smtp log seems to show that the spam really comes from outside.

I tried to workaround the problem by putting our internal domains into the blacklist but that didn´t help at all.

Appeareantly Astaro regards internal domains as "trusted" and relays everything that seems to come from internal.

Can anybody explain this behaviour to me or help me to solve the problem?


This thread was automatically locked due to age.
Parents
  • The only time I've seen this behavior was when the internal domain was in the sender whitelist.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • The only time I've seen this behavior was when the internal domain was in the sender whitelist.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Thank you for the reply! Thats seems to be the answer! I checked our long list of whitelist entrys and for some reason we had placed an entry for the local domain there (and forgot it [:(] ). 
    I will watch our mail traffic today, but I think the problem is solved now!