IllegalMimeHeader file found sending notifications different than what is defined in "content sender (external)" notificationsWith the general option to purge illeagal mime headers, the notifications of this event seems to always go back to the external sender with a subject line of &quot;Antigen Notification: {subject line}&quot;<br/><br/>The notification definition for the content sender (external) is set as To:&quot;%ESaddress%&quot;  and Subject: &quot;%Message%&quot; with a custom text body that does not include any macros (just a generic text).<br/><br/>The idea is to notify the external sender of content that is not allowed while NOT exposing the Antigen application by name.<br/><br/>This notification definition works for other content filters (file/subject etc), but this one setting in general seems to bypass that notification rule and go out on its own and reply with a default message.<br/><br/>Is there a way to control this outbound message (reg setting) or is turning off checking of illeagal mime headers the only solutions<br/>Thanks<br/>© 2009 Microsoft Corporation. All rights reserved.Tue, 12 May 2009 17:55:31 Z07c25e17-f534-46ca-98de-3ae04768a4b8http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#07c25e17-f534-46ca-98de-3ae04768a4b8http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#07c25e17-f534-46ca-98de-3ae04768a4b8Harold007http://social.technet.microsoft.com/Profile/en-US/?user=Harold007IllegalMimeHeader file found sending notifications different than what is defined in "content sender (external)" notificationsWith the general option to purge illeagal mime headers, the notifications of this event seems to always go back to the external sender with a subject line of &quot;Antigen Notification: {subject line}&quot;<br/><br/>The notification definition for the content sender (external) is set as To:&quot;%ESaddress%&quot;  and Subject: &quot;%Message%&quot; with a custom text body that does not include any macros (just a generic text).<br/><br/>The idea is to notify the external sender of content that is not allowed while NOT exposing the Antigen application by name.<br/><br/>This notification definition works for other content filters (file/subject etc), but this one setting in general seems to bypass that notification rule and go out on its own and reply with a default message.<br/><br/>Is there a way to control this outbound message (reg setting) or is turning off checking of illeagal mime headers the only solutions<br/>Thanks<br/>Tue, 28 Apr 2009 16:15:48 Z2009-04-28T16:15:48Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#cd11e702-8e42-4dcb-aa11-e501429f2c94http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#cd11e702-8e42-4dcb-aa11-e501429f2c94Andy S. Dayhttp://social.technet.microsoft.com/Profile/en-US/?user=Andy%20S.%20DayIllegalMimeHeader file found sending notifications different than what is defined in "content sender (external)" notificationsHi Harold,<br/><br/>As with many settings that are configurable through the SETTINGS-&gt;General Options panel, the &quot;Illegal MIME Header - Internet&quot; option counts as a virus detection (not a content detection). You should therefore be able to tailor the &quot;Virus Sender (external)&quot; Notification to achieve the desired effect.<br/><br/>Cheers, AndyThu, 07 May 2009 09:26:22 Z2009-05-07T09:26:22Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#fd5a2aa0-4be9-49e1-8dd4-7ca9f99ad424http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#fd5a2aa0-4be9-49e1-8dd4-7ca9f99ad424Harold007http://social.technet.microsoft.com/Profile/en-US/?user=Harold007IllegalMimeHeader file found sending notifications different than what is defined in "content sender (external)" notifications<p>Thanks Andy,<br/>That made me look again to verify the settings for the notifications for the virus senders (external) and it IS disabled. I confirmed the server that actually caught the event (illegal mime…) and the time stamp and subject and it corresponds to the NDR we received back from the external domain (yahoo) with the reason for the NDR being a spoofed sender ID (user does not exist on the external domain). And in the NDR is the clear identifier of &quot;Subject: <strong><span style="text-decoration:underline">Antigen Notification</span></strong>:......”. Being that the only external message we have configured is “content sender (external)” that is why I thought Antigen was not complying with that custom message. Being that this is considered a “virus sender (external)” and that notification is disabled, I am not quite sure why or how this message gets generated going outbound. The ONLY NDRs we get back (as caused by antigen replying to the external sender inbound) are from the illegal mime…events, no inbound virus events ever generate an outbound message and thus we never get an NDR from inbound virus events.</p> <p>Any ideas would be appreciated.</p> <p>Thanks<br/>Harold</p>Thu, 07 May 2009 12:15:21 Z2009-05-07T12:15:21Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#cf89930b-43cc-432c-923f-a57aa06f9ef7http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#cf89930b-43cc-432c-923f-a57aa06f9ef7Andy S. Dayhttp://social.technet.microsoft.com/Profile/en-US/?user=Andy%20S.%20DayIllegalMimeHeader file found sending notifications different than what is defined in "content sender (external)" notificationsHi Harold,<br/><br/>What you are saying makes sense and normally I would need to delve deeper into your logs and settings to try to work this one out. We would need you to open a support case for that. Let me know if you wish to do this, but are not sure how.<br/><br/>One thing that may help is to turn on Additional Diagnostics-&gt;Internet from the General Options panel (for a short time only, if you are able to reproduce the issue). These diagnostics will return information about every message scanned to the programlog.txt. The diagnostics include lines about the sender determination (e.g. 'External') and some information about the notification as well (if and when sent). These may help to narrow down the cause of the issue.<br/><br/>Cheers, AndyTue, 12 May 2009 17:13:12 Z2009-05-12T17:13:12Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#8dc4fa09-a1a6-450e-a21c-ca16c50d3defhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/07c25e17-f534-46ca-98de-3ae04768a4b8#8dc4fa09-a1a6-450e-a21c-ca16c50d3defHarold007http://social.technet.microsoft.com/Profile/en-US/?user=Harold007IllegalMimeHeader file found sending notifications different than what is defined in "content sender (external)" notifications<p><br/>Thanks Andy,<br/>I'll see what I can capture with the additional logging and maybe have some insight to post. Otherwise I can try to open a case and the logs should give us a good head start. I'll see if I can capture an identical incident as what is logged right now is just minimal (found / purged).<br/>Thanks again for the help<br/>Harold</p>Tue, 12 May 2009 17:55:31 Z2009-05-12T17:55:31Z