>The problem here is that the spammer is sending out E-mail with the >customer's return address. The spam is being sent from other mailservers >to other mailservers, so it can't be filtered.
Sure, I understand the issue. But maybe you didn't read my post in-depth. The filter is on bounce messages that do NOT contain a local token. So it is the very *fact* that the original impersonation is happening on remote mailservers that makes the technique work! (I gave two examples of tokens, one that currently exists and one which is theoretical, which might have been confusing). Try the filter on some recent impersonated bounces, if you still have 'em around. I think you'll see that, while it does rely on a spammer not bothering to hijack additional available information, it does work most of the time with no false rejections. And with a shifting token, it could work 99-100% of the time. -Sandy Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
