Unfortunately it is hard to tell what signature Avast or Norton are seeing that is triggering this response. Because the message is arriving via an API call, it does just arrive as a json so I can see the plain text or html code having something that could trigger these AV programs.
Considering you know this is your own server, I would suggest excluding it from these scans. After all, you can have antispam and antivirus run on your spool. If you want to have Avast or Norton perform these checks, you can enable the proc folder and let these AV's run on that folder as SmarterMail processes the mail through the spool.
Jereming Chen
System/Network Administrator
SmarterTools Inc.
www.smartertools.com