- Server operating system version
- Ubuntu 26.04.1
- Plesk version and microupdate number
- 18.0.81 #2
Hello,
I discovered that incoming mail is NOT being virus-scanned on this server, even though ClamAV (clamav-daemon) is running correctly and clamdscan detects the EICAR test file without issue when run directly.
Root cause: Amavis (the content filter between Postfix and ClamAV) has the following in the Plesk-generated config /etc/amavis/conf.d/99-email-security:
@bypass_virus_checks_maps = (1);
This unconditionally skips virus checking for all mail. Simply commenting out this line does not fix the problem - with debug logging enabled ($log_level = 5), Amavis tries to read the bypass_virus_checks value from Plesk's own SQL database (the emailsecurity database, policy table) instead, but that column does not exist there ("no such fields: bypass_virus_checks"). When the lookup fails, Amavis falls back to a hardcoded value of "1" (= bypass active), silently disabling virus scanning for the whole server.
So the actual issue is a mismatch between what Amavis's Plesk-generated config expects to find in the emailsecurity.policy table and what that table's schema actually contains on this installation.
Impact: Virus scanning is completely inactive for incoming mail, with no error or warning visible anywhere in the Plesk panel - everything looks "enabled" and ClamAV itself reports healthy. This could easily go unnoticed on any server affected by the same schema mismatch.
Happy to provide the full Amavis debug log or the emailsecurity.policy table schema if that helps track this down.
I discovered that incoming mail is NOT being virus-scanned on this server, even though ClamAV (clamav-daemon) is running correctly and clamdscan detects the EICAR test file without issue when run directly.
Root cause: Amavis (the content filter between Postfix and ClamAV) has the following in the Plesk-generated config /etc/amavis/conf.d/99-email-security:
@bypass_virus_checks_maps = (1);
This unconditionally skips virus checking for all mail. Simply commenting out this line does not fix the problem - with debug logging enabled ($log_level = 5), Amavis tries to read the bypass_virus_checks value from Plesk's own SQL database (the emailsecurity database, policy table) instead, but that column does not exist there ("no such fields: bypass_virus_checks"). When the lookup fails, Amavis falls back to a hardcoded value of "1" (= bypass active), silently disabling virus scanning for the whole server.
So the actual issue is a mismatch between what Amavis's Plesk-generated config expects to find in the emailsecurity.policy table and what that table's schema actually contains on this installation.
Impact: Virus scanning is completely inactive for incoming mail, with no error or warning visible anywhere in the Plesk panel - everything looks "enabled" and ClamAV itself reports healthy. This could easily go unnoticed on any server affected by the same schema mismatch.
Happy to provide the full Amavis debug log or the emailsecurity.policy table schema if that helps track this down.