I see that ClamAV is blocking emails that it thinks are phishing emails:
But it's blocking a few legitimate emails (e.g. in the above example, that's a legitimate paypal IP address so seems genuine). I'd rather have Rspamd do all the filtering so I want to turn off clamav trying to detect phishing emails. I think turning off PhishingSignatures and PhishingScanURLs in /etc/clamd.d/scan.conf should work (yet untested). Will that file get overwritten on clamav updates? I can't see anything in /usr/local/directadmin/custombuild/configure/clamav/ to use.Message from 13.110.227.128 denied - virus of harmful content (Heuristics.Phishing.Email.SpoofedDomain)