[exim] stopping spam with forged from:

Top Page
Delete this message
Reply to this message
Author: Chad Leigh Shire.Net LLC
Date:  
To: Exim-users
Subject: [exim] stopping spam with forged from:
Hi

I’ve been seeing a lot of spam come in with forged from: showing the from: the same as the recipient. These are passing things like SPF checks as they use a different envelope-sender (I didn’t see a sender header at all but my spf log line shows what it was using).

What is the best strategy to combat and right out reject mail that has the from: and the recipient address the same? Or alternately to force things like SPF checking against the from: in addition to the envelope-sender? (Not sure if that is a good idea — will it mess up legit email from mail processors etc )

Thanks
Chad
Shire.Net <http://shire.net/> LLC