A user complained that he wasn't receiving an email message he knew had been sent multiple times; I looked in the spam blocker report and found it was being blocked due to Scan Failure; further I saw dozens of other messages marked "Block Message (scan failure)[F]"... alot were spam, alot weren't.
I expanded out the report time to the whole month, and filtered for (scan failure):

That's almost 40% of messages blocked due to scan failure. I've unchecked "Close Connection on Scan Failure" to stop blocking/delaying legit email, but now of course there will be a spam flood.
There's no indication of high CPU usage when the scanner fails; it's almost always less than 2. Everything looks ok.
Any suggestions on where to look?
I expanded out the report time to the whole month, and filtered for (scan failure):
That's almost 40% of messages blocked due to scan failure. I've unchecked "Close Connection on Scan Failure" to stop blocking/delaying legit email, but now of course there will be a spam flood.
There's no indication of high CPU usage when the scanner fails; it's almost always less than 2. Everything looks ok.
Any suggestions on where to look?
Comment