Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Malformed MIME Unscannable Messages

Created: 25 Feb 2011 | 8 comments
Jvansym's picture
0 0 Votes
Login to vote

Hello Everyone,

We are currently noticing a number of emails from external sources being flagged as malformed MIME unscannable. A majority of these messages are actually spam and are flagged as unscannable spam however there are several legitimate messages that are also flagged as unscannable with the details malformed mime.

Our default policy is to strip attachments from unscannable messages and throw them in the spam quarantine so this has caused an issue for several of our users missing out on docs that have been attached to external emails and also cause issues as the messages are thrown in the spam quarantine.

Would this be something that I have configured improperly on the scanners that is causing the large number of unscannable messages ? Is there any way to allow the legitimate unscannable messages through while blocking the messages that are flagged as unscannable spam ? Or is it possible to turn off the checking for malformed MIME messages and how dangerous would this be to allow them through ?

Thanks for your help.

Discussion Filed Under:

Comments

Jvansym's picture
25
Feb
2011
0 Votes 0
Login to vote

sorry forgot to add system

sorry forgot to add system information.

We are using SBG 9.0.2 with Exchange 2007 SP1.

TSE-JDavis's picture
25
Feb
2011
1 Vote +1
Login to vote

You have not misconfigured

You have not misconfigured anything. This means that the person who sent you the message was using a client that is not RFC compliant. We do this detection as you see to prevent spammers from getting their spam by our scanners. If they make the message in haphazard way we won't be able to scan the content and it will get through to your users.

Unfortunately there is not much you can do in this situation aside from allowing the malformed messages or lowering the sensitivity to malformed messages.

Jvansym's picture
26
Feb
2011
0 Votes 0
Login to vote

Thank your for your response,

Thank your for your response, I will pass along the information to the users. One quick question, if we are having an issue with a particular sender that we know is valid would adding them to the good senders list bypass the scanning for that particular sender or will they still be subject to this check ?

akottas's picture
26
Feb
2011
0 Votes 0
Login to vote

Adding a sender to a good

Adding a sender to a good senders list only bypasses spam scanning.  Our unscannable verdict is tied to our antivirus scanning workflow, so it would not be bypassed by adding the sender to the good senders list.

akottas's picture
26
Feb
2011
1 Vote +1
Login to vote

I thnk you have also hit on

I thnk you have also hit on one of the key points about the unscannable verdict - it does not mean that the message wasn't also checked for spam and virus contents.  The unscannable verdict simply means that Symantec can not ensure the message has been fully scanned due to malformed MIME, scanning time-out, or other issue.  Some customers choose to deliver unscannable verdicts normally (Symantec will still attempt spam and virus scans on the message), and you can also choose other options such as marking up the subject as a warning.

mon_raralio's picture
03
Mar
2011
0 Votes 0
Login to vote

Quick workaround here is to

Quick workaround here is to create a policy to not scan attached files that are classified as document files. The only drawback here is that you're allowing malware using those types of file extenstions to passthrough so you better have a good AV in the endpoints. :D

“Your most unhappy customers are your greatest source of learning.”

Jvansym's picture
04
Mar
2011
0 Votes 0
Login to vote

Thanks for the responses, for

Thanks for the responses, for now we have allowed unscannable messages to be delivered with the subject line appended with a warning. The number seems a bit high ~ 300 a day but may be normal not sure yet as we have only been using brightmail for a month or so.

 

One question that did come up, is there a way to forward the message to an admin mailbox or another quarantine with with the attachments still available but deliver the message stripped of attachments to the user or their spam quarantine ? I tried configuring this by creating a forward rule to another mailbox and then stripping the attachments but it seems like it will perform the strip prior to the forwarding. The only reason we were investigating this was so we could strip the attachments but if the user needed them and they were legitimate we could retrieve them.

mon_raralio's picture
06
Mar
2011
0 Votes 0
Login to vote

Your only option is to send

Your only option is to send notifications or forward the same exact email to the admin box. And I suggest you create a separate Inbox for this as it will fill up rather quickly.

 

Cheers

“Your most unhappy customers are your greatest source of learning.”