No it remains prety much the same. It now states strip: instead of ignore: in the logs
Fun fact: Looking at the headers in my received e-mail, it is actually gone!!
But in Mailwatch, it is shown and therefore cannot be acted upon
So it is probably a process-order of some kind.
2 things that popup during search on Google:
Make a temp postfix queue, let it be cleaned and send it back to postfix (Nah, too difficult and altering EFA too much for succesfull updates)
Alter the Spam Assasin Score for SPF_FAIL and SPF_SOFTFAIL (Might just do that if it can't be fixed with header_checks)
Here's a (somewhat anonymised) copy of the log.
Jun 12 15:06:23 mailgtw postfix/smtpd[32244]: connect from smtp21.bsmtpprovider.nl[12.345.678.33]
Jun 12 15:06:23 mailgtw postfix/smtpd[32244]: Anonymous TLS connection established from smtp21.bsmtpprovider.nl[12.345.678.33]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Jun 12 15:06:24 mailgtw postfix/smtpd[32244]: 49k1FX3BRdz52w39: client=smtp21.bsmtpprovider.nl[12.345.678.33]
Jun 12 15:06:24 mailgtw postfix/cleanup[32406]: 49k1FX3BRdz52w39: strip: header Received: from mx03.bsmtpprovider.nl (smtp21.bsmtpprovider.nl [12.345.678.33])??(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))??(No client certificate requested)??by mailgtw.e-d-i-t.nl (Po from smtp21.bsmtpprovider.nl[12.345.678.33]; from=<
me@somewhereelse.nl> to=<
me@home.nl> proto=ESMTP helo=<mx03.bsmtpprovider.nl>: stripheader
Jun 12 15:06:24 mailgtw postfix/cleanup[32406]: 49k1FX3BRdz52w39: message-id=<
AM0PR10MB2849FC649028D71EC847BDBFAC810@AM0PR10MB2849.EURPRD10.PROD.OUTLOOK.COM>
Jun 12 15:06:26 mailgtw MSMilter[32404]: MailWatch: Whitelist refresh time reached
Jun 12 15:06:26 mailgtw MSMilter[32404]: MailWatch: Starting up MailWatch SQL Whitelist
Jun 12 15:06:26 mailgtw MSMilter[32404]: MailWatch: Read 29 whitelist entries
Jun 12 15:06:26 mailgtw MSMilter[32404]: MailWatch: Blacklist refresh time reached
Jun 12 15:06:26 mailgtw MSMilter[32404]: MailWatch: Starting up MailWatch SQL Blacklist
Jun 12 15:06:26 mailgtw MSMilter[32404]: MailWatch: Read 16 blacklist entries
Jun 12 15:06:27 mailgtw postfix/cleanup[32406]: 49k1FX3BRdz52w39: milter-discard: END-OF-MESSAGE from smtp21.bsmtpprovider.nl[12.345.678.33]: milter triggers DISCARD action; from=<
me@somewhereelse.nl> to=<
me@home.nl> proto=ESMTP helo=<mx03.bsmtpprovider.nl>
Jun 12 15:06:27 mailgtw postfix/smtpd[32244]: disconnect from smtp21.bsmtpprovider.nl[12.345.678.33] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7
Jun 12 15:06:28 mailgtw MailScanner[23382]: New Batch: Scanning 1 messages, 49671 bytes
Jun 12 15:06:28 mailgtw MailScanner[23382]: Virus and Content Scanning: Starting
Jun 12 15:06:28 mailgtw MailScanner[23382]: <A> tag found in message 49k1FX3BRdz52w39 from
me@somewhereelse.nl
Jun 12 15:06:28 mailgtw MailScanner[23382]: HTML Img tag found in message 49k1FX3BRdz52w39 from
me@somewhereelse.nl
Jun 12 15:06:28 mailgtw MailScanner[23382]: Spam Checks: Starting
Jun 12 15:06:28 mailgtw MailScanner[23382]: MailWatch: Whitelist refresh time reached
Jun 12 15:06:28 mailgtw MailScanner[23382]: MailWatch: Starting up MailWatch SQL Whitelist
Jun 12 15:06:28 mailgtw MailScanner[23382]: MailWatch: Read 29 whitelist entries
Jun 12 15:06:28 mailgtw MailScanner[23382]: MailWatch: Blacklist refresh time reached
Jun 12 15:06:28 mailgtw MailScanner[23382]: MailWatch: Starting up MailWatch SQL Blacklist
Jun 12 15:06:28 mailgtw MailScanner[23382]: MailWatch: Read 16 blacklist entries
Jun 12 15:06:34 mailgtw postfix/smtpd[32244]: connect from unknown[192.168.10.50]
Jun 12 15:06:34 mailgtw postfix/smtpd[32244]: disconnect from unknown[192.168.10.50] ehlo=1 quit=1 commands=2
Jun 12 15:06:35 mailgtw MailScanner[32437]: Found phishing fraud from
https://www.covidopstart.nl/c-19/nl-NL/ ... gn=veenman claiming to be
www.veenman.nl in 49k1FX3BRdz52w39
Jun 12 15:06:35 mailgtw MailScanner[23382]: Content Checks: Detected and have disarmed phishing tags in HTML message in 49k1FX3BRdz52w39 from
me@somewhereelse.nl
Jun 12 15:06:35 mailgtw MailScanner[23382]: Requeue: 49k1FX3BRdz52w39 to 49k1Fl25F6zs4Pj
Jun 12 15:06:35 mailgtw postfix/qmqpd[32439]: connect from localhost[127.0.0.1]
Jun 12 15:06:35 mailgtw postfix/qmqpd[32439]: 49k1Fl27Ryz52w39: client=localhost[127.0.0.1]
Jun 12 15:06:35 mailgtw postfix/cleanup[32406]: 49k1Fl27Ryz52w39: strip: header Received: from mx03.bsmtpprovider.nl (smtp21.bsmtpprovider.nl [12.345.678.33])? (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))? (no client certificate requested)? by m from localhost[127.0.0.1]; from=<
me@somewhereelse.nl> to=<
me@home.nl> proto=QMQP: stripheader
Jun 12 15:06:35 mailgtw postfix/cleanup[32406]: 49k1Fl27Ryz52w39: message-id=<
AM0PR10MB2849FC649028D71EC847BDBFAC810@AM0PR10MB2849.EURPRD10.PROD.OUTLOOK.COM>
Jun 12 15:06:35 mailgtw postfix/qmqpd[32439]: disconnect from localhost[127.0.0.1]
Jun 12 15:06:35 mailgtw postfix/qmgr[32021]: 49k1Fl27Ryz52w39: from=<
me@somewhereelse.nl>, size=50187, nrcpt=1 (queue active)
Jun 12 15:06:35 mailgtw MailScanner[23382]: Uninfected: Delivered 1 messages
Jun 12 15:06:35 mailgtw MailScanner[23382]: Deleted 1 messages from processing-database
Jun 12 15:06:35 mailgtw MailScanner[23382]: MailWatch: Logging message 49k1FX3BRdz52w39 to SQL
Jun 12 15:06:35 mailgtw MailScanner[30442]: MailWatch: 49k1FX3BRdz52w39: Logged to MailWatch SQL
Jun 12 15:06:35 mailgtw postfix/smtp[32440]: 49k1Fl27Ryz52w39: to=<
me@home.nl>, relay=192.168.10.65[192.168.10.65]:25, delay=0.07, delays=0.01/0.01/0.02/0.03, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 57043E4005E)
Jun 12 15:06:35 mailgtw postfix/qmgr[32021]: 49k1Fl27Ryz52w39: removed