I want to make sure I'm correctly understanding your reply...

1) If a custom from header is set in MailScanner.conf, and that header is
also defined in spam.assassin.prefs.conf via 'envelope-sender-header', then
the placement of that header in the email does not matter. Since SA knows
it has been specifically told to watch for that custom header, then it will
accept it as valid since a spoofer would not know what name to use to forge
the header.

2) If however the standard 'X-Envelope-From' header is used, it must be
placed at the top of the headers, or SA will not 'trust' its validity.

Thanks for your time!


