-
Notifications
You must be signed in to change notification settings - Fork 61
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
External message warning #413
Comments
Can you post an example of a mail source code where it the warning is missing? |
I took out email addresses and phone # but thats just 1 I have several like i said it appears to be the only it injects the warning on is the one its disarming `Return-Path: --- Twst
Sent from my iPhone Helpdesk Number: Helpdesk Email: ---- Service Portal: to open new tickets, get ticket status and review FAQs. =93Going beyond merely communicatin=
g to =91connecting=92 with our clients=94
` |
@weazil Flagging this as an unconfirmed bug and will look at it asap. I'll switch to confirmed once I check the logic. In the meantime can you post your phishing settings you currently have in use for me? |
Find Phishing Fraud = yes But i've never seen a subject tagged as Fraud.. i've only ever seen Disarm and Spam |
Just to make sure you mean the correct thing: This is independent of the External Message Warning (configed via |
Yes I understand they are separate just seams odd that the only time I see the warning about external emails is in the same emails that get disarmed and display that fraud attempt |
This is the intended behavior. For the second mail the Some more examples: These would be flagged as they contain some kind of link/fqdn that doesn't match the link target These would not be flagged as the link target matches the text. |
I understand the fraud warnings Im trying to understand the random External message and it appeared to be linked to the fraud warning but i guess its more when the email has an external image its trying to load thats getting flagged as disarmed then it adds the external email header |
Ahh ok.
or
Which itself is called in
v5/common/usr/share/MailScanner/perl/MailScanner/Message.pm Lines 6438 to 6445 in 0a87daf
and v5/common/usr/share/MailScanner/perl/MailScanner/Message.pm Lines 5460 to 5467 in 0a87daf
Call that function. As with clean messages the @shawniverson Changing v5/common/usr/share/MailScanner/perl/MailScanner/Message.pm Lines 6438 to 6445 in 0a87daf
to
might work. Or evaluate the |
@Skywalker-11 thanks for the detailed analysis. I am working on this now. |
I am going to move this logic earlier in the process. It needs to perform action on all messages, not just modified ones and set the bodymodified flag. |
@Skywalker-11 @weazil Please test PR #415 and report back. |
Appears to work as expected all external now being tagged not just the ones w external images |
Need to double check my rules but atm it appears to be tagging everything |
From: southern-air.com no Return-Path: example@southern-air.com --=swift_1573821979_5ebe8f5df9a423928f41e315758ce522= Warning: This message originated from outside the organization. Test |
Can you tell me why based on my rules its tagging every thing external and internal |
See PR #419 . Let me know if that fixes it. |
Quick test appears to have worked I sent an email locally and from my gmail and only gmail got tagged |
@weazil Awesome, thanks! |
Hi All, |
External message warning only appears to append to some messages that it disarms and adds the
MailScanner has detected a possible fraud attempt from .... claiming to be ....
I would expect all messages to receive the message if not from the domains listed
The text was updated successfully, but these errors were encountered: