The email is being sent from a fake user at a valid domain, to a zimbra distribution list.
what I see is postfix breaking up the DL into its seperate users for local delivery and immediately also sending the message to the user set up forward addresses.
The forwards get bounced by our relay server, due to virus infection
Local users receive an email from content filter stating that the message is infected.
received through smtp.
Last edited by jwilke; 10-14-2009 at 02:22 AM..
|