How to detect forged From and Reply-to addresses from your own domain

Kai Schaetzl maillists at conactive.com
Fri Mar 5 17:31:18 GMT 2010


Daniel Straka wrote on Fri, 05 Mar 2010 09:00:36 -0700:

> We are receiving a ton of SPAM where the From and/or Reply-to addresses
> have been forged so they appear to have come from users in our own
> domain. Of course, these BC several users at a time. Is there any
> way to detect these with MailScanner?

This is getting asked frequently. Please peruse the archives. There are 
basically two solutions and they are done at MTA, not MailScanner:

- SPF
- reject your own domains as sender if not coming from your network or not 
authenticated, this can easily be done with postfix, I assume with other 
MTAs as well.

Kai

-- 
Get your web at Conactive Internet Services: http://www.conactive.com





More information about the MailScanner mailing list