> Source: [sk173247](https://support.checkpoint.com/results/sk/sk173247)

# sk173247 - Mail Transfer Agent drops a packet with error "Vanished by MTA custom post processing"

| Property | Value |
|----------|-------|
| Solution ID | sk173247 |
| Date Created | 2021-04-26 |
| Last Modified | 2021-10-10 |
| Technical Level | Advanced |
| Products | Email Security |
| Versions | Cloud |

## Symptoms

- * Some e-mails are dropped with error "`Vanished by MTA custom post processing`". The issue happens sporadically on some e-mails, but nothing general is seen.
* This output shows in var/log/maillog:

  ```
   grep "MAIL@USER>COM" /var/log/maillog
  
   postfix/smtpd[8669]:...: client=localhost[127.0.0.1], orig_queue_id=..., orig_client=unknown[10.60.2.9]
  .postfix/smtp[8668]: ...: to=, relay=127.0.0.1[127.0.0.1]:10025, delay=0.43, delays=0.05/0/0/0.37, dsn=2.0.0, status=sent (221 Vanished by MTA custom post processing. .
  
  relay=127.0.0.1[127.0.0.1]:10025, delay=0.43, delays=0.05/0/0/0.37, dsn=2.0.0, status=sent (221 Vanished by MTA custom post processing. Email Session ID: {})
  Mar 23 05:39:40 2021postfix/qmgr[27315]: ....: removed 
  ```

* Log looks like:

  ```
  
  Time:                  2x
  Interface Direction:   inbound
  Interface Name:        MTA
  Id:                    xx
  Sequencenum:           94
  Log ID:                4000
  Source:                x
  Destination Country:   x
  Destination:           1.162.8.46
  IP Protocol:           6
  Source Port:           x
  Destination Port:      25
  Rule Id:               x
  Sender:                x.com
  Email Subject:          xxx
  Last Failure Reason:   Vanished by MTA custom post processing
  Original Queue ID:     x
  Action:                Prevent
  Type:                  Log
  Blade:                 MTA
  Origin:                x1
  Service:               TCP/25
  Product Family:        Threat
  Marker:                x
  Log Server Origin:     x
  Orig Log Server Ip:    x
  Index Time:            2x
  Lastupdatetime:        x
  Lastupdateseqnum:      94
  Email Message ID:      
  Email Queue Name:      N/A
  Arrival Time:          x
  Scan Started:          x
  Scan Ended:            2x
  Email Status:          Dropped
  Last status update:    2x
  Logid:                 131840
  Stored:                true
  Severity:              Informational
  Rounded Sent Bytes:    0
  Confidence Level:      N/A
  Rounded Bytes:         0
  Rounded Received Bytes:0
  Interface:             MTA
  Description:           An email from axxxx.com was dropped
  ```

* Threat prevention is configured as fail-close.
* A customer is using one of the features which require post-processing of the e-mails (such as adding a subject prefix or banners in case of a malicious e-mail).

## Cause

By default, if there is any issue during the process, the configuration of Threat Prevention fail mode is applied (if a customer is using fail-close, the email is rejected/vanished).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
