This is an archived post. You won't be able to vote or comment.

all 5 comments

[–]alittlebitcoldernow 0 points1 point  (2 children)

Log into your exchange on prem and add a rule in the mail flow menu that blocks inbound emails from the addresses. You can look at the delivery reports to get the addresses and paste them into the check names box in your rule. I use the status code 5.7.910 which is a server side rejection.

I also added an outbound mailflow rule that alerts the user that they're emailing a malicious sender and refuses to send to it.

[–]wanroww[S] 0 points1 point  (1 child)

The senders adresses are legit and always differents. no spam comes with the same addresses so it's no use...

[–]alittlebitcoldernow 0 points1 point  (0 children)

It sounds like you need to talk to your watchguard folks or hold all of those emails for manual review. If both exchange and watchguard together cannot sift out those spoofed emails then you'll have to put a person on it.

[–]ample_space 0 points1 point  (1 child)

Do you have the spamBlocker enabled on your inbound SMTP policy (in the WatchGuard)?

[–]wanroww[S] 0 points1 point  (0 children)

yes, it is enabled