If you use Postfix, catch it with the reject_multi_recipient_bounce restriction.
p@ Am 16.10.19 um 08:21 schrieb Mika Ilmaranta: > > Hi, > > We have seen a few phishing messages go through filtering that are > disguised to look like bounces. > > Envelope sender is "<>" and the messages have multiple recipients and > From: and To: headers missing. I tried to catch them with spamassassin > plugin only to find out that envelope sender/recipient is not > available in spamassassin. > > Amavis code seems to be too much perl for me .. > > Any ideas? > > BR, > Mika > -- [*] sys4 AG https://sys4.de, +49 (89) 30 90 46 64 Schleißheimer Straße 26/MG,80333 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorstand: Patrick Ben Koetter, Marc Schiffbauer, Wolfgang Stief Aufsichtsratsvorsitzender: Florian Kirstein
smime.p7s
Description: S/MIME Cryptographic Signature
