Are you using Clam Antivirus or ClamWin Antivirus? This is the forums for ClamWin. Clam Antivirus does provide the scanning engine and signature database used by ClamWin Antivirus. You should report false positives for both of these antiviruses to Clam Antivirus at its submission page starting at http://www.clamav.net/sendvirus/
on the web. If you are reporting a false positive, be sure to fill in the false positive designation, and tell them the exact name of the false positive virus.
Clam will need a copy of any file that has a false positive detection in order to verify it and to help them prepare a signature that will exclude that file. If you are using ClamWin, perhaps you could change ClamWin's detection option to Report Only and capture the file for submission to Clam. They get some false positives on Spoofed Domains, but it seems to me that any email with a spoofed domain is suspect. Why would anyone spoof a domain if they are legitimate?