Discussion:
X-IronPort-AV: E=Sophos;i="4.60,386,1291590000"; d="scan'208";a="41500553"
J4K
2011-01-28 09:02:19 UTC
Permalink
Good morning everyone (almost the week-end),

Is X-IronPort-AV added by SA, or from something else (DCC Clamav ? )

I just noticed that all email from a certain company was flagged with
X-IronPort-AV, and I wonder why this is so.

I have searched on the usual engine, and saw refereces to this header, but not to the programme.


Regards, S.

-------- Original Message --------
Return-Path: <***@tele2.com>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
logout.simonloewen.info
X-Spam-Level:
X-Spam-Status: No, score=0.0 required=4.0 tests=HTML_MESSAGE
shortcircuit=no autolearn=ham version=3.3.1
X-Spam-Virus: No
Delivered-To: ***@klunky.co.uk
Received: from xxxxxxxxxx.tele2.se (xxxx.tele2.se [193.12.60.45]) by
klunky.co.uk (Postfix) with ESMTP id E4119843B7 for
<***@klunky.co.uk>; Thu, 27 Jan 2011 16:40:47 +0100 (CET)
X-IronPort-AV: E=Sophos;i="4.60,386,1291590000"; d="scan'208";a="41500553"
Received: from xxxxxx.tele2.com ([172.16.33.32]) by
xxxx.tele2.se with ESMTP; 27 Jan 2011 16:40:47 +0100
In-Reply-To:
<OFB15345B3.8FFF0406-ONC125781E.004F7DEC-***@LocalDomain>
References:
<OFB15345B3.8FFF0406-ONC125781E.004F7DEC-***@LocalDomain>
X-Disclaimed: 38106
To: xxxxxxxxxxxx
MIME-Version: 1.0
Subject: Correction 29-Jan (Re: Saturday Borrel 5-Feb-2011 in Amstelveen)
X-KeepSent: 986ACF3D:EADBDE0D-C1257825:00550505; type=4; name=$KeepSent
Message-ID:
<OF986ACF3D.EADBDE0D-ONC1257825.00550505-***@tele2.com>
From: xxxxxxxxxx
Date: Thu, 27 Jan 2011 16:40:45 +0100
Content-Type: multipart/alternative; boundary="=_alternative
0056520DC1257825_="
Giles Coochey
2011-01-28 09:11:20 UTC
Permalink
Post by J4K
Good morning everyone (almost the week-end),
Is X-IronPort-AV added by SA, or from something else (DCC Clamav ? )
I just noticed that all email from a certain company was flagged with
X-IronPort-AV, and I wonder why this is so.
I have searched on the usual engine, and saw refereces to this header, but not to the programme.
X-IronPort-AV: E=Sophos;i="4.60,386,1291590000"; d="scan'208";a="41500553"
Sophos is an anti-virus company... I would check their product list...
probably one of these
http://www.sophos.com/products/enterprise/email/security-and-control/appliances/
--
Best Regards,

Giles Coochey
NetSecSpec Ltd
NL T-Systems Mobile: +31 681 265 086
NL Mobile: +31 626 508 131
GIB Mobile: +350 5401 6693
Email/MSN/Live Messenger: ***@coochey.net
Skype: gilescoochey
Giles Coochey
2011-01-28 09:13:22 UTC
Permalink
Post by Giles Coochey
Post by J4K
Good morning everyone (almost the week-end),
Is X-IronPort-AV added by SA, or from something else (DCC Clamav ? )
I just noticed that all email from a certain company was flagged with
X-IronPort-AV, and I wonder why this is so.
I have searched on the usual engine, and saw refereces to this
header, but not to the programme.
X-IronPort-AV: E=Sophos;i="4.60,386,1291590000";
d="scan'208";a="41500553"
Sophos is an anti-virus company... I would check their product list...
probably one of these
http://www.sophos.com/products/enterprise/email/security-and-control/appliances/
Tell a lie, probably the Cisco Ironport: http://www.ironport.com/products/
I imagine it uses the Sophos engine though....
--
Best Regards,

Giles Coochey
NetSecSpec Ltd
NL T-Systems Mobile: +31 681 265 086
NL Mobile: +31 626 508 131
GIB Mobile: +350 5401 6693
Email/MSN/Live Messenger: ***@coochey.net
Skype: gilescoochey
J4K
2011-01-28 09:31:58 UTC
Permalink
Post by Giles Coochey
Post by Giles Coochey
Post by J4K
Good morning everyone (almost the week-end),
Is X-IronPort-AV added by SA, or from something else (DCC Clamav ? )
I just noticed that all email from a certain company was flagged with
X-IronPort-AV, and I wonder why this is so.
I have searched on the usual engine, and saw refereces to this
header, but not to the programme.
X-IronPort-AV: E=Sophos;i="4.60,386,1291590000";
d="scan'208";a="41500553"
Sophos is an anti-virus company... I would check their product
list... probably one of these
http://www.sophos.com/products/enterprise/email/security-and-control/appliances/
http://www.ironport.com/products/
I imagine it uses the Sophos engine though....
Cheers Giles. Then I presume its not my server adding the header. It
must be Tele2's server somewhere along the way.

S.

Loading...