RSpamD rejects mail with 0.xx score

Hi there,

our customer get’s mails with attached HTML- containers. This Messages all get rejected, but the score of this mails is at 0.xx. I can’t identify, why this mails are being rejected. If I leave out the HTML container, the email goes through.

The action / score is: reject 0.89 / 7

Here is a filter output:

GENERIC_REPUTATION (0.588967) [0.58896705825681]
PDF_ENCRYPTED (0.3) [SecuredPdf.pdf]
MIME_GOOD (-0.1) [multipart/mixed,multipart/alternative,text/plain]
MIME_BASE64_TEXT (0.1)
RCVD_COUNT_THREE (0) [4]
MIME_TRACE (0) [0:+,1:+,2:+,3:~,4:~,5:~]
TO_DN_NONE (0)
RCVD_VIA_SMTP_AUTH (0)
CLAM_VIRUS (0) [TwinWave.EvilHTML.QakyDoRight.20220909.UNOFFICIAL]
HAS_ATTACHMENT (0)
RCPT_COUNT_ONE (0) [1]
FROM_EQ_ENVFROM (0)
MID_RHS_MATCH_FROM (0)
HAS_DATA_URI (0)
FREEMAIL_ENVFROM (0) [gmx.de]
FREEMAIL_FROM (0) [gmx.de]
FROM_HAS_DN (0)
RCVD_TLS_ALL (0)
PREVIOUSLY_DELIVERED (0) [hidden@hidden.de] (I made the mail adress unrecognizable)

I tried also “Scan/Learn”, but the results are the same. Does anyone have a suggestion?

It appears that the antivirus scan found something suspicious.
That’s probably why the email gets blocked anyway.

1 Like

I just tried it: That’s it! How did you come to the conclusion that if Clam_Virus reports 0 (zero) that the virus scanner is the cause?

A lot of experience! :wink:

1 Like

Great!

yes because when we find a match of clamav we stop to analyse and we reject

1 Like

good shot mate