Hello,
I’ve been receiving several CPfence notifications reporting emails as infected, but after checking I noticed most of them are actually DMARC reports.
The detections come from the cPFence_app.Foxhole.Mail_gz.UNOFFICIAL signature, and the emails are automatically moved to quarantine.
Example log:
/var/local/enhance/email/mailboxes/.../reports@domain/mail/new/1757593419...: cPFence_app.Foxh…
This content is hidden. Log in to view the full discussion.