We have someone spoofing mail to and from a particular user at one of our domains. I would like to get rid of all of this mail. Some of this is spoofed to the user and some is bounced back to the user. I can not locate where it is originating. If I set up whitelisting such as:

FromOrTo:    BadUser at our.domain    no
FromOrTo:    *@our.domain    yes
FromOrTo:    default    no

and blacklist such as:

FromOrTo:    BadUser at our.domain    yes
FromOrTo:    default    no

Will this allow all mail from everyone at our.domain to pass either way with the exception of BadUser at our.domain? 

