Hello,
I’ve been receiving several CPfence notifications reporting emails as infected, but after checking I noticed most of them are actually DMARC reports.
The detections come from the cPFence_app.Foxhole.Mail_gz.UNOFFICIAL signature, and the emails are automatically moved to quarantine.
Example log:
/var/local/enhance/email/mailboxes/.../reports@domain/mail/new/1757593419...: cPFence_app.Foxhole.Mail_gz.UNOFFICIAL FOUND
moved to '/opt/cpfence/quarantined/...
In reality, these are legitimate .gz attachments with aggregated DMARC reports, but they are being flagged as malware. From what I understand, this looks like a false positive caused by the Foxhole signature.
Is anyone else experiencing the same situation?
What’s the recommended way to whitelist DMARC reports so they are not lost, while still keeping Foxhole protection active for the rest of the traffic?
Thanks in advance for your feedback!