prevent external senders from spoofing my internal domains
Incoming email delivered to the Appliance contains a sender's address spoofed as an internal domain hosted on the destination network. The Appliance is configured with mydomain.com as an permited domain, what I sloud do to block the fake email?
Re: prevent external senders from spoofing my internal domains
sorry for this late answer. But I think this is better than no answer
Concerining Your issue, create a separate Policy for incoming mails and add a condition that checks senderaddress and serverips that are allowed to use your domain.
... and create a policy based action on this Policy Rule with the following settings:
Important: Disable all other Filters, such as SPAM, Reputation and URL Checks, on this Policy Rule in order not to allow a higher priortity filter like SPAM to bypass this Mail to the Users quarantine before a policy based action can take place.
This Rule checks only the Senderadress that is seen on the SMTP connector, not the Adress that might has been faked in the mailheader. So You may want to add a condition that checks Regular expression on the FROM Field in the mailheader.
P.S.: If you find this post helpful, thank You for giving it a Kudo :o)
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.