Topic: Blocking Fake Emails
iRedMail v0.9.8 MySQL Nginx
I am having two spam/phishing issues lately and I cannot seem to get ahead of it. The main issue is fake emails, where the From name shows an employee's name but the email address is some random email. Those are passing all the SPF and Blacklist rules, mostly because they are hacked, valid email accounts and they simply change the From Name that is shows. Lately a new one is that the from is showing a real email as the name, but then a fake email underneath it. This is what I really want to block.
Example: realemail@domain.com <fakeemail@randomdomain.com>
Since most email clients show the Name and not the email, recipient think its from the real email address. Is there a regex I could put in Amavis to block the @ sign or even domain.com in the from side not including the actual email?
Is there a way to look up names to see if they exist locally and soft blacklist them?
Example: Real Name <fakeemail@randomdomain.com>
If "Real Name" exists in the DB or even in a manually created file, but is external it would add Spamassassin points or soft black list.
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.