BCC spam

Oct 13, 2025
1
0
1
Hello all,

some users receive weird mail responses from sender they don't know and the users mail address even isn't listed in the To: header. The recipients of those mails have been put in BCC. It looks like someone has setup a mailing list like googlegoups and is spreading spam mails. Any automatic or manual replies to that sender address again gets sent out to all recipients on that list.

I'm looking for a way to create a rule, which can detect that the recipient was on BCC but was not listed in the To: header field. For cases where there is no To: header provided i found a way by creating an object looking for "to:undisclosed-recipients". But i want also the combination of recipient is present in BCC and some other unknown mail address or even multiple addresses are present in either To: or CC headers. Or maybe even in To: and CC header.

Any ideas?

//entirenet