Hi everyone,
While migrating our SmarterMail server to a new Windows Server 2025 VM, we spent some time testing the antivirus integrations. I’m sharing what we found because some of it isn’t documented and might save others a few hours.
Environment
- SmarterMail 100.0.9756.27316, Windows Server 2025
- Sophos Intercept X as the primary endpoint AV
- Microsoft Defender real-time protection disabled by policy, so Defender stays in “Normal” mode with real-time, behavior monitoring, IOAV and on-access all off, to avoid running two real-time AVs side by side
- ClamAV enabled in SmarterMail
1. The Microsoft Defender engine requires Defender real-time protection
On our old server, where Defender real-time protection is on, the Defender engine works: Defender’s threat history shows detections as amsi:_...\MailService.exe, so SmarterMail passes content to Defender through AMSI.
On the new server, with real-time protection off, an EICAR test sent via SMTP with ClamAV disabled is delivered without any detection. No error appears anywhere, and the engine just reports the message as clean. Enabling Sophos “AMSI Protection” does not help, since it targets script-based threats.
This isn’t mentioned in the documentation, and the admin UI shows no warning. If you run a third-party AV and disabled Defender real-time protection, your Defender engine is probably doing nothing.
2. Command-Line Antivirus: the script location in the documentation is wrong
The help page says the script must be in:
C:\Program Files (x86)\SmarterTools\SmarterMail\Service\Assets
SmarterMail actually launches it from:
C:\Program Files (x86)\SmarterTools\SmarterMail\Service\Settings\Assets
From the delivery log:
Launching 'C:/Program Files (x86)/SmarterTools/SmarterMail/Service/Settings/Assets/antiVirus.bat' command line exe.
Command line exe finished.
If the file is missing, it still logs “Command line exe finished” and raises no error, so it’s very easy to believe the scanner is running when it isn’t.
3. %FILEPATH is passed with forward slashes
The argument arrives as D:/SmarterMail/Spool/SubSpool2/235409001001.eml. MpCmdRun.exe does not accept that: it stops right after “Scan starting...” and returns exit code 2, which is also the code it uses for “threat found”. In a batch file you can convert it with:
set "SRC=%~1"
set "SRC=%SRC:/=\%"
4. File-based scanners don’t decode MIME, so the command-line approach can’t catch attachments
Even with the path fixed and the spool not excluded, both MpCmdRun.exe -Scan -ScanType 3 -File <eml> and Sophos’ sophosinterceptxcli.exe scan --expand_archives <eml> report an .eml with a base64-encoded EICAR attachment as clean. The same EICAR string in a plain file is detected immediately. File scanners don’t parse .eml/MIME, so a command-line scanner only helps if the product itself understands mail formats. The built-in engines work because SmarterMail extracts the content and hands it over: clamd for ClamAV, AMSI for Defender.
5. SmarterMail re-adds its Defender exclusions on every service start
After a restart we got the “Windows Defender Exclusions Added” notification. That’s useful, but worth knowing if you’re testing Defender exclusions by hand.
Suggestions for SmarterTools
- Fix the Assets path in the Command-Line Antivirus documentation.
- Pass %FILEPATH with Windows-style backslashes, or document the forward slashes.
- Document that the Defender engine needs Defender real-time protection, and show a warning in the antivirus settings when it is off.
- Log an error when the command-line script isn’t found.
- Consider an option to pass extracted attachments to the command-line scanner, or to act on its exit code, so third-party file scanners become useful.
Is anyone else running the Defender engine alongside a third-party endpoint AV? How did you handle it?