I am not sure if this is the correct forum to ask this or not. So if this needs to be moved, would a moderator please move it.
What we have is a user is seeing certain email from the internet being placed into the user junk folder. The user uses the OWA not outlook. Our setup is exchange 2013 SP1 with a 2 member DAG. We do use Mcafee's Security for Exchange but when the headers of the legit email are viewed, Mcafee's Security does NOT scan it AND Mcafee Security is NOT set to deliver SPAM to the user junk folder. We have the malware option of Exchange disabled. The scanned header part of the legit email says it uses spamassassin. Here is the full header with sensitive info removed:
Received: from ourexchange.domain.com (192.168.123.12) by ourexchange.domain.com (192.168.123.12) with Microsoft SMTP Server (TLS) id 15.0.847.32 via Mailbox Transport; Mon, 8 Dec 2014 08:37:28 -0500 Received: from 2ndDAGmemeber.domain.com (192.168.123.9) by ourexchange.domain.com (192.168.123.12) with Microsoft SMTP Server (TLS) id 15.0.847.32; Mon, 8 Dec 2014 08:37:27 -0500 Received: from rock.pidgin.im (209.191.187.69) by 2ndDAGmember.domain.com (192.168.123.9) with Microsoft SMTP Server id 15.0.847.32 via Frontend Transport; Mon, 8 Dec 2014 08:37:27 -0500 Received: from localhost (localhost [127.0.0.1]) by rock.pidgin.im (Postfix) with ESMTP id 862B415E57F4; Mon, 8 Dec 2014 08:36:15 -0500 (EST) X-Virus-Scanned: Debian amavisd-new at rock.pidgin.im Received: from rock.pidgin.im ([127.0.0.1]) by localhost (rock.pidgin.im [127.0.0.1]) (amavisd-new, port 10024) with LMTP id SjgIxLi8pwK9; Mon, 8 Dec 2014 08:36:13 -0500 (EST) Received: from rock.pidgin.im (localhost [IPv6:::1]) by rock.pidgin.im (Postfix) with ESMTP id 28B0215E57ED; Mon, 8 Dec 2014 08:36:13 -0500 (EST) X-Original-To: support@pidgin.im Delivered-To: support@pidgin.im Received: from localhost (localhost [127.0.0.1]) by rock.pidgin.im (Postfix) with ESMTP id 3F39F15E572C for <support@pidgin.im>; Mon, 8 Dec 2014 08:36:11 -0500 (EST) X-Virus-Scanned: Debian amavisd-new at rock.pidgin.im Received: from rock.pidgin.im ([127.0.0.1]) by localhost (rock.pidgin.im [127.0.0.1]) (amavisd-new, port 10024) with LMTP id VWRen55-tvpC for <support@pidgin.im>; Mon, 8 Dec 2014 08:35:52 -0500 (EST) Received: from auth.a.painless.aa.net.uk (auth.a.painless.aa.net.uk [90.155.4.51]) by rock.pidgin.im (Postfix) with ESMTPS id 069D815E1ABE for <support@pidgin.im>; Mon, 8 Dec 2014 08:35:52 -0500 (EST) Received: from 219.250.187.81.in-addr.arpa ([81.187.250.219] helo=[192.168.1.37]) by a.painless.aa.net.uk with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.77) (envelope-from <forums@david-woolley.me.uk>) id 1XxyTa-0006q5-Gt; Mon, 08 Dec 2014 13:35:48 +0000 Message-ID: <5485A948.7050303@david-woolley.me.uk> Date: Mon, 8 Dec 2014 13:36:08 +0000 From: David Woolley User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Icedove/31.2.0 MIME-Version: 1.0 To: Duncan Anderson <support@pidgin.im> Subject: Re: cant access Pidgin References: <00dd01d012ea$d049d050$70dd70f0$@hiroseuk.com> In-Reply-To: <00dd01d012ea$d049d050$70dd70f0$@hiroseuk.com> X-Pidgin-SpamProbe: GOOD 0.0000010 9a9e88a5e77c0f07e773e841e70ec91b X-Pidgin-Spam-Flag: Clean X-BeenThere: support@pidgin.im X-Mailman-Version: 2.1.15 Precedence: list Reply-To: <support@pidgin.im> List-Id: "End-user support for Pidgin, Finch and libpurple" <support.pidgin.im> List-Unsubscribe: <https://pidgin.im/cgi-bin/mailman/options/support>, <mailto:support-request@pidgin.im?subject=unsubscribe> List-Archive: <https://pidgin.im/pipermail/support/> List-Post: <mailto:support@pidgin.im> List-Help: <mailto:support-request@pidgin.im?subject=help> List-Subscribe: <https://pidgin.im/cgi-bin/mailman/listinfo/support>, <mailto:support-request@pidgin.im?subject=subscribe> Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="windows-1252"; format=flowed Errors-To: support-bounces@pidgin.im Sender: Support <support-bounces@pidgin.im> Return-Path: support-bounces@pidgin.im X-MS-Exchange-Organization-Network-Message-Id: long-alphanumeric-number X-MS-Exchange-Organization-AuthSource: 2ndDAGmember.domain.com X-MS-Exchange-Organization-AuthAs: Anonymous
There aren't any rules on the exchange server. Does exchange do any form of spam scanning?
We do not have an edge server.
- Edited by forgiven Monday, December 08, 2014 4:19 PM