I'm receiving several bounce messages a minute seemingly because a spammer is using my catch-all domain name to send e-mail from. Is there a way I can make a general rule which gives a high score to any bounce which contains @mydomain.com but does NOT include [EMAIL PROTECTED] which is the address I normally send from? I'm new to this rules business...

An example bounce is attached (if this list allows attachments). The username is obviously random chars, but I always send from [EMAIL PROTECTED]

Thanks,

Nick...

--- Begin Message ---
The original message was received at Tue, 25 May 2004 14:42:46 -0600
from 

   ----- The following addresses had permanent fatal errors -----
<[EMAIL PROTECTED]>
    (expanded from: <[EMAIL PROTECTED]>)

   ----- Transcript of session follows -----
mail.local: unknown name: danw
550 <[EMAIL PROTECTED]>... User unknown
Reporting-MTA: dns; mx1.midamsignal.com
Received-From-MTA: DNS; 
Arrival-Date: Tue, 25 May 2004 14:42:46 -0600

Final-Recipient: RFC822; <[email protected]>
X-Actual-Recipient: RFC822; [email protected]
Action: failed
Status: 5.1.1
Last-Attempt-Date: Tue, 25 May 2004 14:42:46 -0600
--- Begin Message ---
OTCBB:SNNW--The Sun Network Group, Inc.

Huge Profits And Huge PR Campaign Expected For SNNW
All Week, Fax Campaign Is Expected To Begin Wednesday
So Get In Today On Tuesday Immediately!

Current Price : $0.03
3-5 Days target: $0.15
2 Weeks Target: $0.19

The Sun Network Group, Inc  SNNW - Big Profits Expected Immediately!

The stock is expected to explode on 26th of May and the days after.

All Technical Indicators Say - Get SNNW @ 10- 15 cents!

Significant short term trading profits in SNNW are being predicted,
great news already issued by the company and big PR campaign on the

--- End Message ---

--- End Message ---

Reply via email to