[Rspamd-Users] Rspamd clamav integration - Am I overlooking something?

Steve Siirila sfs at umn.edu
Tue Jul 21 13:34:16 UTC 2026


We are running Red Hat Enterprise Linux 9 and the following ClamAV / Rspamd
packages on our MTA servers:

clamav-1.4.3-3.el9.x86_64
clamav-filesystem-1.4.3-3.el9.noarch
clamav-freshclam-1.4.3-3.el9.x86_64
clamav-lib-1.4.3-3.el9.x86_64
clamd-1.4.3-3.el9.x86_64
rspamd-4.1.0-1.el8.x86_64

I do not see "*no category symbols defined for clamav*" in our rspamd logs.

On Tue, Jul 21, 2026 at 8:12 AM Steve <sjh_rspamd at shic.co.uk> wrote:

> Hi (another) Steve,
>
> My /etc/rspamd/local.d/antivirus.conf is almost identical.  You have:
>
>   servers = "/run/clamd.scan/clamd.sock";
>
> whereas I have:
>
>   servers = "/var/run/clamav/clamd.ctl";
>
> I expect this difference is because you're using a different Linux distro
> and your clamav-daemon is configured by it to use a different default Unix
> socket.  I'm using the rspamd package specifically for Debian Trixie - from
> the rspamd.com repo - not one that has been packaged by Debian
> themselves.  (I presumed this would be best as this package seemed to be
> recommended on the Rspamd website over the default Debian one.)
>
> I suspect my problems may be version dependent...  I'm using:
>
> *$ cat /etc/os-release*
> PRETTY_NAME="Debian GNU/Linux 13 (trixie)"
> NAME="Debian GNU/Linux"
> VERSION_ID="13"
> VERSION="13 (trixie)"
> VERSION_CODENAME=trixie
> DEBIAN_VERSION_FULL=13.6
> ID=debian
> HOME_URL="https://www.debian.org/" <https://www.debian.org/>
> SUPPORT_URL="https://www.debian.org/support"
> <https://www.debian.org/support>
> BUG_REPORT_URL="https://bugs.debian.org/" <https://bugs.debian.org/>
>
>
> *$ cat /etc/apt/sources.list.d/rspamd.list *deb
> [signed-by=/usr/share/keyrings/rspamd.gpg] https://rspamd.com/apt-stable/
> trixie main
>
> *$ apt list --installed clamav-daemon rspamd*
> clamav-daemon/stable,now 1.4.3+dfsg-1 amd64 [installed]
> rspamd/unknown,now 4.1.1-1~0f29274~trixie amd64 [installed]
>
> Are you (or is anyone else) using the same distro/packages as me?
>
> If not, do you also see the same "*no category symbols defined for clamav*"
> in your rspamd log (when "antivirus" is in the debug_modules list in
> /etc/rspamd/local.d/logging.inc)? If rspamd/clamav integration works for
> you - and you also see that log line, it probably shows that I'm barking up
> the wrong tree. If integration works for you - and you don't see that log
> line - then I might be on the right track to work out why the integration
> seems to be failing for me. (I see no evidence in the logs, or in rspamd
> inserted email headers, to suggest that email is actually being scanned by
> clamav... I assume it is 'obviously working properly' for others.)
>
> Steve
>
> On 20/07/2026 18:59, Steve Siirila via Users wrote:
>
> Hi Steve,
>
> We recently switched from
> Amavis/Spamassassin/ClamAV/OpenDKIM/OpenDMARC/Postgrey to Rspamd/ClamAV and
> it has proven a worthwhile effort and resulted in less maintenance. Not to
> mention it got us away from:
>
>    1. building and managing our own OpenDMARC instance (because EPEL did
>    not compile it w/SPF support properly),
>    2. file descriptor leaks in OpenDKIM requiring twice daily restarts,
>    3. occasional data corruption in Postgrey requiring detection and
>    automatic restarts
>
> Here is our antivirus.conf file:
>
> # /etc/rspamd/local.d/antivirus.conf
>
> # Configure the clamav scanner
> clamav {
>
>   # Type of scanner: "clamav", "fprot", "sophos" or "savapi"
>   type = "clamav";
>
>   # Servers to query or a path to the unix socket
>   servers = "/run/clamd.scan/clamd.sock";
>
>   # Symbol to add (add it to metric if you want a non-zero weight)
>   symbol = "CLAMAV";
>
>   # Maximum file size to scan (25MB)
>   max_size = 10485760;
>
>   # Log when messages are clean (default: false to reduce noise)
>   log_clean = true;
>
>   # Transfer the complete email message (not just attachments) to the AV
> scanner
>   scan_mime_parts = false;
>
>   # Scan messages originating from local networks? (default is false)
>   scan_local = true;
>
>   # Scan messages from authenticated users? (default is false)
>   scan_authenticated = true;
>
>   # Scan messages that are classified as non-spam (ham)? (default is false)
>   scan_ham = true;
>
>   # Add this line to force rejection immediately
>   action = "discard";
>
>   # Optional: Customize the bounce message the sender sees
>   message = "Virus found: ${VIRUS}";
> }
>
>
>
>
>


More information about the Users mailing list