Hi,
we are currently running proxmox mail gateway 6.4-4 and an exchange server 2019 fully patched. the patch for the hafnium exploit was installed as soon as possible. the proxylogon script for exchange did not find any vulnerabilities
we recently received an email from an external sender that hid under the identity of a legit business customer.
today we received an email that was looking like a legit internal email.
the attacker or attackers know how our email footer looks like.
they manipulated the email header in a way that their original mail address is hidden.
envelope-from= was their address,
from= was our email address.
both times HEADER_FROM_DIFFERENT_DOMAINS had a value of around 0.25 which was not enough to classify the mails as spam.
i know that newsletters sometimes need this aspect.
what could we do that improves detection of mails that have a suspicious header? could those mails be quarantined first that have any sort of difference in envelope-from and from fields?
grateful for any ideas or suggestions.
we are currently running proxmox mail gateway 6.4-4 and an exchange server 2019 fully patched. the patch for the hafnium exploit was installed as soon as possible. the proxylogon script for exchange did not find any vulnerabilities
we recently received an email from an external sender that hid under the identity of a legit business customer.
today we received an email that was looking like a legit internal email.
the attacker or attackers know how our email footer looks like.
they manipulated the email header in a way that their original mail address is hidden.
envelope-from= was their address,
from= was our email address.
both times HEADER_FROM_DIFFERENT_DOMAINS had a value of around 0.25 which was not enough to classify the mails as spam.
i know that newsletters sometimes need this aspect.
what could we do that improves detection of mails that have a suspicious header? could those mails be quarantined first that have any sort of difference in envelope-from and from fields?
grateful for any ideas or suggestions.