After looking a little deeper, a percentage of these false positives are
Virus: (Heuristics.Phishing.Email.SpoofedDomain)
Example A record
welcome.xxxxxxxxxxx.com = 0.0.0.0
IP does not match MX or SPF, and the email goes to Quarantine.
You could turn off Scan Messages Without Attachments, but it is unclear if this would allow Virus/Ransomware links through your scanners.
Question for Smartermail Admin, can a whitelist be added to Defender, ClamAV, and/or Cyren?
J. Sebastian Lee Service2Client LLC 6333 E Mockingbird Ste 147 Dallas, TX 75214 - 877.251.3273