Solved

Exchange 2010 ScanMail Fail

Posted on 2013-06-11
3
1,676 Views
Last Modified: 2013-07-18
I have a user who sent an internal email using outlook 2007 which was processed by our exchange 2010 server.   She did not receive an error message when sending but when opening the sent item she gets the following message. " A policy violated content was detected and removed from the original mail header, subject, boty or attachment. You can safely save or delete this replacement attachment. "

I've traced the message using powershell and found the following information but I'm not sure where to go from here as I didn't find the message listed in the Agent Logs for  that time period .....  
++++++++++++++++++++++++++
PSComputerName          : exchange1.desertortho.local
RunspaceId              : 61def46d-dfa4-479d-81ee-299869729dc3
Timestamp               : 6/7/2013 11:16:54 AM
ClientIp                :
ClientHostname          : EXCHANGE1
ServerIp                :
ServerHostname          :
SourceContext           : ScanMail Routing Agent
ConnectorId             :
Source                  : AGENT
EventId                 : FAIL
InternalMessageId       : 366903
MessageId               : <EF54B011491F8341A6201379C871891606AE7FE4@EXCHANGE1.DesertOrtho.local>
Recipients              : {debi@dbjortho.com}
RecipientStatus         : {}
TotalBytes              : 16033
RecipientCount          : 1
RelatedRecipientAddress :
Reference               :
MessageSubject          : W/C charges...
Sender                  : jodic@dbjortho.com
ReturnPath              : jodic@dbjortho.com
MessageInfo             :
MessageLatency          :
MessageLatencyType      : None
EventData               :

+++++++++++++++++++++++++++++++++++++++++

We We have anti-spam turned on in exchange as well as our Trendmicro is filtering messages .......

Thanks so much for any help you can provide. ...

Joel Brown
0
Comment
Question by:jtbrown1111
  • 2
3 Comments
 
LVL 8

Accepted Solution

by:
vSolutionsIT earned 500 total points
ID: 39239547
Confirm the contents of the emails and attachments from the user and verify if any of the custom words or attachments are configured in the scanmail to quarantine emails.
if the attachment was excel sheet then verify if it has any macro's in that case you will have to configure scanmail to allow excel sheets with macros.
0
 

Author Comment

by:jtbrown1111
ID: 39239579
@vSolutionsIT,   will do .... are you saying that scanmail belongs to exchange or trendmicro ?   thougths ..?
0
 
LVL 8

Expert Comment

by:vSolutionsIT
ID: 39335863
Scanmail belongs to Trendmicro.
0

Featured Post

Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now