OK. Things are looking much better.
See below for the data from mail.log.
1) I am still not getting the spam scores inserted in to the header even though I have:
20-debian_defaults:$sa_tag_level_deflt = -100.0
2) I have defang_banned = 1. One of the 7 test files sends an attachment called attach.bat. It was my desire that anything banned would be removed from the message and the rest of the message delivered. Instead the entire message was delivered. Using $final_banned_destiny = D_DISCARD stops the attachment but also the entire message is killed.
I believe killing the message entirely will be fine, but I would like to understand defang_banned. I can envision use cases where valid email disappears, and without any notification, finger pointing and tension could arise.
================================================================================================
MAIL.LOG FILE **FINAL_BANNED_DESTINY / FINAL_SPAM_DESTINY** CHANGED TO D_DISCARD
================================================================================================
Blank lines added for readability
Mar 15 08:50:12 mail postfix/smtpd[13073]: connect from byteplant.com[78.47.119.33]
Mar 15 08:50:13 mail postfix/smtpd[13116]: connect from byteplant.com[78.47.119.33]
Mar 15 08:50:13 mail postfix/smtpd[13118]: connect from byteplant.com[78.47.119.33]
Mar 15 08:50:13 mail postfix/smtpd[13119]: connect from byteplant.com[78.47.119.33]
Mar 15 08:50:13 mail postfix/smtpd[13120]: connect from byteplant.com[78.47.119.33]
Mar 15 08:50:13 mail postfix/smtpd[13121]: connect from byteplant.com[78.47.119.33]
Mar 15 08:50:13 mail postfix/smtpd[13122]: connect from byteplant.com[78.47.119.33]
Mar 15 08:50:14 mail postfix/smtpd[13073]: 3D525C0700: client=byteplant.com[78.47.119.33]
Mar 15 08:50:14 mail postfix/smtpd[13118]: 98882C078B: client=byteplant.com[78.47.119.33]
Mar 15 08:50:14 mail postfix/smtpd[13116]: A1615C079F: client=byteplant.com[78.47.119.33]
Mar 15 08:50:14 mail postfix/smtpd[13120]: DB70EC07A0: client=byteplant.com[78.47.119.33]
Mar 15 08:50:14 mail postfix/smtpd[13119]: E4DE2C07A1: client=byteplant.com[78.47.119.33]
Mar 15 08:50:14 mail postfix/smtpd[13121]: EE960C07A2: client=byteplant.com[78.47.119.33]
Mar 15 08:50:15 mail postfix/smtpd[13122]: 533FAC07A3: client=byteplant.com[78.47.119.33]
Mar 15 08:50:15 mail postfix/cleanup[13126]: 3D525C0700: message-id=emailsecuritycheck.net.1.m*mYoj9OgYs1HytEMio1Gg==
Mar 15 08:50:15 mail postfix/qmgr[4235]: 3D525C0700: from=<securitycheck@emailsecuritycheck.net>, size=1421, nrcpt=1 (queue active)
Mar 15 08:50:15 mail postfix/smtpd[13158]: connect from localhost[127.0.0.1]
Mar 15 08:50:15 mail postfix/smtpd[13158]: AF12CC07A4: client=localhost[127.0.0.1]
Mar 15 08:50:15 mail postfix/cleanup[13126]: AF12CC07A4: message-id=<VArEqRUB49BvRX@mail.memorylane4us.com>
Mar 15 08:50:15 mail postfix/qmgr[4235]: AF12CC07A4: from=<postman@changed-domain.com>, size=2646, nrcpt=1 (queue active)
Mar 15 08:50:15 mail postfix/smtpd[13158]: disconnect from localhost[127.0.0.1]
Mar 15 08:50:15 mail amavis[13034]: (13034-01) Blocked BANNED (application/x-msdownload,.asc,attached.bat) {DiscardedOutbound}, LOCAL [78.47.119.33]:58035 [78.47.119.33] <securitycheck@emailsecuritycheck.net> -> <spamtest@changed-domain.com>, Queue-ID: 3D525C0700, Message-ID: <emailsecuritycheck.net.1.m*mYoj9OgYs1HytEMio1Gg==>, mail_id: rEqRUB49BvRX, Hits: -, size: 1421, 242 ms
Mar 15 08:50:15 mail postfix/smtp[13154]: 3D525C0700: to=<spamtest@changed-domain.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=1.8, delays=1.5/0.01/0.01/0.3, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=13034-01 - BANNED: application/x-msdownload,.asc,attached.bat)
Mar 15 08:50:15 mail postfix/qmgr[4235]: 3D525C0700: removed
Mar 15 08:50:15 mail postfix/smtpd[13073]: disconnect from byteplant.com[78.47.119.33]
Mar 15 08:50:15 mail postfix/cleanup[13137]: 98882C078B: message-id=emailsecuritycheck.net.3.m*mYoj9OgYs1HytEMio1Gg==
Mar 15 08:50:16 mail postfix/cleanup[13138]: A1615C079F: message-id=emailsecuritycheck.net.2.m*mYoj9OgYs1HytEMio1Gg==
Mar 15 08:50:16 mail postfix/qmgr[4235]: 98882C078B: from=<securitycheck@emailsecuritycheck.net>, size=1138, nrcpt=1 (queue active)
Mar 15 08:50:16 mail postfix/qmgr[4235]: A1615C079F: from=<securitycheck@emailsecuritycheck.net>, size=1600, nrcpt=1 (queue active)
Mar 15 08:50:16 mail postfix/cleanup[13143]: DB70EC07A0: message-id=emailsecuritycheck.net.5.m*mYoj9OgYs1HytEMio1Gg==
Mar 15 08:50:16 mail postfix/qmgr[4235]: DB70EC07A0: from=<securitycheck@emailsecuritycheck.net>, size=1425, nrcpt=1 (queue active)
Mar 15 08:50:16 mail postfix/cleanup[13151]: EE960C07A2: message-id=emailsecuritycheck.net.6.m*mYoj9OgYs1HytEMio1Gg==
Mar 15 08:50:16 mail postfix/cleanup[13144]: E4DE2C07A1: message-id=emailsecuritycheck.net.4.m*mYoj9OgYs1HytEMio1Gg==
Mar 15 08:50:16 mail postfix/qmgr[4235]: EE960C07A2: from=<securitycheck@emailsecuritycheck.net>, size=1426, nrcpt=1 (queue active)
Mar 15 08:50:16 mail postfix/qmgr[4235]: E4DE2C07A1: from=<securitycheck@emailsecuritycheck.net>, size=1501, nrcpt=1 (queue active)
Mar 15 08:50:16 mail postfix/pipe[13159]: AF12CC07A4: to=<postman@changed-domain.com>, relay=dovecot, delay=0.62, delays=0.04/0.01/0/0.57, dsn=2.0.0, status=sent (delivered via dovecot service)
Mar 15 08:50:16 mail postfix/qmgr[4235]: AF12CC07A4: removed
Mar 15 08:50:16 mail postfix/smtpd[13158]: connect from localhost[127.0.0.1]
Mar 15 08:50:16 mail postfix/smtpd[13158]: 68070C0700: client=localhost[127.0.0.1]
Mar 15 08:50:16 mail postfix/cleanup[13126]: 68070C0700: message-id=<VAOw1SLz7sH7Tq@mail.memorylane4us.com>
Mar 15 08:50:16 mail postfix/smtpd[13118]: disconnect from byteplant.com[78.47.119.33]
Mar 15 08:50:16 mail postfix/qmgr[4235]: 68070C0700: from=<postman@changed-domain.com>, size=2727, nrcpt=1 (queue active)
Mar 15 08:50:16 mail amavis[13034]: (13034-02) Blocked INFECTED (Eicar-Test-Signature) {DiscardedOutbound,Quarantined}, LOCAL [78.47.119.33]:42885 [78.47.119.33] <securitycheck@emailsecuritycheck.net> -> <spamtest@changed-domain.com>, quarantine: O/virus-Ow1SLz7sH7Tq, Queue-ID: A1615C079F, Message-ID: <emailsecuritycheck.net.2.m*mYoj9OgYs1HytEMio1Gg==>, mail_id: Ow1SLz7sH7Tq, Hits: -, size: 1600, 387 ms
Mar 15 08:50:16 mail postfix/smtpd[13121]: disconnect from byteplant.com[78.47.119.33]
Mar 15 08:50:16 mail postfix/smtpd[13120]: disconnect from byteplant.com[78.47.119.33]
Mar 15 08:50:16 mail postfix/smtpd[13116]: disconnect from byteplant.com[78.47.119.33]
Mar 15 08:50:16 mail postfix/smtpd[13119]: disconnect from byteplant.com[78.47.119.33]
Mar 15 08:50:16 mail postfix/smtp[13164]: A1615C079F: to=<spamtest@changed-domain.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=2.2, delays=1.7/0.02/0/0.46, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=13034-02 - INFECTED: Eicar-Test-Signature)
Mar 15 08:50:16 mail postfix/qmgr[4235]: A1615C079F: removed
Mar 15 08:50:16 mail postfix/cleanup[13153]: 533FAC07A3: message-id=emailsecuritycheck.net.7.m*mYoj9OgYs1HytEMio1Gg==
Mar 15 08:50:16 mail postfix/smtpd[13158]: CF79CC07A7: client=localhost[127.0.0.1]
Mar 15 08:50:16 mail postfix/cleanup[13151]: CF79CC07A7: message-id=<VAyu-17k9aBraj@mail.memorylane4us.com>
Mar 15 08:50:16 mail postfix/qmgr[4235]: CF79CC07A7: from=<postman@changed-domain.com>, size=2607, nrcpt=1 (queue active)
Mar 15 08:50:16 mail postfix/qmgr[4235]: 533FAC07A3: from=<securitycheck@emailsecuritycheck.net>, size=1427, nrcpt=1 (queue active)
Mar 15 08:50:17 mail amavis[13034]: (13034-03) Blocked BANNED (application/x-msdownload,.asc) {DiscardedOutbound}, LOCAL [78.47.119.33]:47666 [78.47.119.33] <securitycheck@emailsecuritycheck.net> -> <spamtest@changed-domain.com>, Queue-ID: DB70EC07A0, Message-ID: <emailsecuritycheck.net.5.m*mYoj9OgYs1HytEMio1Gg==>, mail_id: yu-17k9aBraj, Hits: -, size: 1425, 445 ms
Mar 15 08:50:17 mail postfix/pipe[13159]: 68070C0700: to=<postman@changed-domain.com>, relay=dovecot, delay=0.65, delays=0.1/0/0/0.54, dsn=2.0.0, status=sent (delivered via dovecot service)
Mar 15 08:50:17 mail postfix/qmgr[4235]: 68070C0700: removed
Mar 15 08:50:17 mail postfix/smtp[13164]: DB70EC07A0: to=<spamtest@changed-domain.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=2.5, delays=1.6/0.4/0.01/0.54, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=13034-03 - BANNED: application/x-msdownload,.asc)
Mar 15 08:50:17 mail postfix/qmgr[4235]: DB70EC07A0: removed
Mar 15 08:50:17 mail postfix/smtpd[13122]: disconnect from byteplant.com[78.47.119.33]
Mar 15 08:50:17 mail postfix/pipe[13171]: CF79CC07A7: to=<postman@changed-domain.com>, relay=dovecot, delay=0.39, delays=0.02/0.01/0/0.35, dsn=2.0.0, status=sent (delivered via dovecot service)
Mar 15 08:50:17 mail postfix/qmgr[4235]: CF79CC07A7: removed
Mar 15 08:50:17 mail postfix/smtpd[13158]: 592C4C0700: client=localhost[127.0.0.1]
Mar 15 08:50:17 mail postfix/cleanup[13126]: 592C4C0700: message-id=<VAJP65vUVMxddl@mail.memorylane4us.com>
Mar 15 08:50:17 mail postfix/qmgr[4235]: 592C4C0700: from=<postman@changed-domain.com>, size=2656, nrcpt=1 (queue active)
Mar 15 08:50:17 mail amavis[13034]: (13034-03-2) Blocked BANNED (application/x-msdownload,.asc,attached.()bat) {DiscardedOutbound}, LOCAL [78.47.119.33]:44213 [78.47.119.33] <securitycheck@emailsecuritycheck.net> -> <spamtest@changed-domain.com>, Queue-ID: EE960C07A2, Message-ID: <emailsecuritycheck.net.6.m*mYoj9OgYs1HytEMio1Gg==>, mail_id: JP65vUVMxddl, Hits: -, size: 1426, 240 ms
Mar 15 08:50:17 mail postfix/smtp[13164]: EE960C07A2: to=<spamtest@changed-domain.com>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=2, delay=2.6, delays=1.4/0.91/0/0.28, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=13034-03-2 - BANNED: application/x-msdownload,.asc,attached.()bat)
Mar 15 08:50:17 mail postfix/qmgr[4235]: EE960C07A2: removed
Mar 15 08:50:17 mail postfix/smtpd[13158]: 92A26C07A0: client=localhost[127.0.0.1]
Mar 15 08:50:17 mail postfix/cleanup[13153]: 92A26C07A0: message-id=<VAdfrZzy-umkBN@mail.memorylane4us.com>
Mar 15 08:50:17 mail postfix/pipe[13159]: 592C4C0700: to=<postman@changed-domain.com>, relay=dovecot, delay=0.25, delays=0.03/0/0/0.22, dsn=2.0.0, status=sent (delivered via dovecot service)
Mar 15 08:50:17 mail postfix/qmgr[4235]: 592C4C0700: removed
Mar 15 08:50:17 mail postfix/qmgr[4235]: 92A26C07A0: from=<postman@changed-domain.com>, size=2712, nrcpt=1 (queue active)
Mar 15 08:50:17 mail amavis[13034]: (13034-03-3) Blocked BANNED (application/x-msdownload,.asc,attached.bat,=??Q?attached.bat?=) {DiscardedOutbound}, LOCAL [78.47.119.33]:49290 [78.47.119.33] <securitycheck@emailsecuritycheck.net> -> <spamtest@changed-domain.com>, Queue-ID: E4DE2C07A1, Message-ID: <emailsecuritycheck.net.4.m*mYoj9OgYs1HytEMio1Gg==>, mail_id: dfrZzy-umkBN, Hits: -, size: 1501, 218 ms
Mar 15 08:50:17 mail postfix/smtp[13164]: E4DE2C07A1: to=<spamtest@changed-domain.com>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=3, delay=3, delays=1.6/1.2/0/0.27, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=13034-03-3 - BANNED: application/x-msdownload,.asc,attached.bat,=??Q?attached.bat?=)
Mar 15 08:50:17 mail postfix/qmgr[4235]: E4DE2C07A1: removed
Mar 15 08:50:17 mail postfix/pipe[13171]: 92A26C07A0: to=<postman@changed-domain.com>, relay=dovecot, delay=0.28, delays=0.06/0/0/0.22, dsn=2.0.0, status=sent (delivered via dovecot service)
Mar 15 08:50:17 mail postfix/qmgr[4235]: 92A26C07A0: removed
Mar 15 08:50:17 mail postfix/smtpd[13158]: E0EBAC07A0: client=localhost[127.0.0.1]
Mar 15 08:50:17 mail postfix/cleanup[13138]: E0EBAC07A0: message-id=<VAmbg9MnVu9YZm@mail.memorylane4us.com>
Mar 15 08:50:17 mail postfix/qmgr[4235]: E0EBAC07A0: from=<postman@changed-domain.com>, size=2748, nrcpt=1 (queue active)
Mar 15 08:50:17 mail amavis[13034]: (13034-03-4) Blocked BANNED (application/x-msdownload,.asc,attached\\) {DiscardedOutbound}, LOCAL [78.47.119.33]:49339 [78.47.119.33] <securitycheck@emailsecuritycheck.net> -> <spamtest@changed-domain.com>, Queue-ID: 533FAC07A3, Message-ID: <emailsecuritycheck.net.7.m*mYoj9OgYs1HytEMio1Gg==>, mail_id: mbg9MnVu9YZm, Hits: -, size: 1429, 243 ms
Mar 15 08:50:18 mail postfix/smtp[13164]: 533FAC07A3: to=<spamtest@changed-domain.com>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=4, delay=2.8, delays=1.7/0.85/0/0.28, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=13034-03-4 - BANNED: application/x-msdownload,.asc,attached\\\\)
Mar 15 08:50:18 mail postfix/qmgr[4235]: 533FAC07A3: removed
Mar 15 08:50:18 mail postfix/pipe[13159]: E0EBAC07A0: to=<postman@changed-domain.com>, relay=dovecot, delay=0.29, delays=0.04/0/0/0.25, dsn=2.0.0, status=sent (delivered via dovecot service)
Mar 15 08:50:18 mail postfix/qmgr[4235]: E0EBAC07A0: removed
Mar 15 08:50:20 mail amavis[13033]: (13033-02) Blocked SPAM {DiscardedOutbound}, LOCAL [78.47.119.33]:46024 [78.47.119.33] <securitycheck@emailsecuritycheck.net> -> <spamtest@changed-domain.com>, Queue-ID: 98882C078B, Message-ID: <emailsecuritycheck.net.3.m*mYoj9OgYs1HytEMio1Gg==>, mail_id: VE2HziYTEM0F, Hits: 997.967, size: 1138, 4052 ms
Mar 15 08:50:20 mail postfix/smtp[13154]: 98882C078B: to=<spamtest@changed-domain.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=5.9, delays=1.7/0.01/0/4.1, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=13033-02 - spam)
Mar 15 08:50:20 mail postfix/qmgr[4235]: 98882C078B: removed
Mar 15 08:52:03 mail postfix/scache[13169]: statistics: start interval Mar 15 08:50:16
Mar 15 08:52:03 mail postfix/scache[13169]: statistics: domain lookup hits=3 miss=1 success=75%
Mar 15 08:52:03 mail postfix/scache[13169]: statistics: address lookup hits=0 miss=1 success=0%
Mar 15 08:52:03 mail postfix/scache[13169]: statistics: max simultaneous domains=1 addresses=1 connection=1