> This raises a question: if the user "spoofs" the from address, is > there a way to scan the headers so that that message doesn't get > through either?
All headers are untrustworthy, save for the connecting IP of the most recent SMTP server. This is why rules alone are insufficient for stopping knowledgeable spammers. You would need to use a product such as Declude Junkmail (http://www.declude.com/JunkMail/index.html) to consult IP blacklists and stop shooting in the dark. -Sandy Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
