From field being changed - How?

This is probably going to be a rather dumb question, but here it goes. My company's CEO received a SPAM message the other day. The concern he had was that the message was not only addressed from him, but it appeared as though the sender was him also.
I was able to find the message through Ironport Mailflow and saw that the message came into the Ironport device with a from field of ;
Sender: [email protected]
Recipient(s): [email protected]
Subject: Your Featured Products of the Week?
Message-ID Header: 20090318140646.3977.qmail@OMAR1
So how does a Spammer get the message to change the sender field information to reflect the same as the To field?
We are using Lotus Notes (Domino) for mail. They are only accepting messages from our Ironport devices.

It's because the envelope sender doesn't necessarily have to be the same as the header('From') email address. For legitimate mail, this doesn't come up, but spammers use this to try and bypass spam filters and such.
For example, here is what a potential smtp conversation between the Internet and the Ironport appliance:
(sender) helo
(receiver) 220 ok
(sender) mail-from: [email protected]
(receiver) 250 ok
(sender) rcpt-to: [email protected]
(receiver) 250 ok
(sender) data
(receiver) 334 go ahead, end with "." on it's own line
(sender) From: [email protected]
(sender) To: [email protected]
(sender) Subject: Do you want to buy a brand new Rolex watch?
(sender)
(sender) Go to this website to buy it, http://newrolex.com
(sender) .
(receiver) 250 message accepted
What happened above is perfectly legal. It is RFC compliant and it's not breaking any rules.
Now, what I would recommend to counter this is the following:
1. Would there be any scenario where both the header("From") and the header("To") would be the same domain, in this case, "ourcompany.org".
When two co-workers send mail to one another, should it stay on the mailserver and never hit the Ironport appliance.
If this is the case, we can implement an incoming content filter like the following:
Same_from_to_domain_in_headers_quarantine:
Conditions (All of the following must match):
header("From") == "ourcompany.com$"
header("To") == "ourcompany.com$"
Actions:
quarantine ("Policy")
This kb article may help you with content filters.
What conditions / actions are available to content filters?
http://tinyurl.com/jpqwl
This is probably going to be a rather dumb question, but here it goes. My company's CEO received a SPAM message the other day. The concern he had was that the message was not only addressed from him, but it appeared as though the sender was him also.
I was able to find the message through Ironport Mailflow and saw that the message came into the Ironport device with a from field of ;
Sender: [email protected]
Recipient(s): [email protected]
Subject: Your Featured Products of the Week?
Message-ID Header: 20090318140646.3977.qmail@OMAR1
So how does a Spammer get the message to change the sender field information to reflect the same as the To field?
We are using Lotus Notes (Domino) for mail. They are only accepting messages from our Ironport devices.

Similar Messages

  • Why is the "From:" field being changed in Mac Mail.  I have multiple gmail accounts setup and it seems to change the "FROM" field even though I've selected which account to use to send the email.

    So
    I've got multiple gmail accounts setup in Mac Mail.
    Somtimes when I send or forward emails, it uses the wrong FROM field even though I'm declaring
    specifically which account to use.
    This becomes apparent when the person replies to my message and it goes to the wrong account

    Check you accounts in Mail and make sure each account has the correct outgoing server address. Check the box to use only that server.
    Second, go to the gmail website and in settings under the account tab, make sure you have the correct settings for replying to messages.

  • Sort field being changed by system

    We are using Sort field ILOA-EQFNR as a reference to an external system. If a user changes the functional location on an order, this field is being overwritten by the sort field associated to the Functioanl location. How can we prevent this from happening.

    Scott,
    This is because of the data transfer functinality.
    When you install an equipment, make sure you select "with data transfer" button and do not transfer the Sort field.
    I don't have system access so the names above may not be accurate...
    PeteA

  • From: header being changed in Mail 2.1

    My Mac is on a small LAN I set up in my house to enable multiple Net access with only one phone line.  To send mail I have to use the SMTP server that goes with the other computer on the network, though incoming mail comes to me via a quite different server and ISP.
    Until two days ago everything worked fine, but starting yesterday my outging mail started showing, not my account information, but that of the other account holder, information which is included in the outgoing server settings.  This has become an issue for two reasons: some of my correspondants, for whatever reason, reply to the From: address rather than the Reply-to: address. And when sending to certain mailing lists my messages will be rejected because the list doesn't recognise the From: address.
    Does anyone know why this would suddenly change? And how would I go about changing it back?

    Problem solved. I couldn't fix the problem directly, but I was able to access my 'other' ISP's outgoing mail server (this wasn't possible a few years ago, which is why I never thought of it) and after restarting Mail and creating/erasing a duplicate account it seems to work fine. For some reason Mail seems a bit slow on the uptake when it comes to changing account information...

  • Outgoing mail contains all-caps letters in "From" field email address

    For some reason, all of a sudden Mail is sending email with all caps email addresses in the "From" field. Before the entire address was capitalized; now it's just my username (e.g. [email protected]).
    This happened about a month ago and I noticed that in Address Book, my contact information (for myself) was in edit mode. I turned editing off and that seemed to fix the problem. But this time, Address Book is not even open. Any ideas as to why my outgoing email address in the From: field would change to all capital letters? It's definitely machine/software-specific as this does not happen on my other computer, a MacBook.

    Hi Sara,
    I believe that selection is controlled by attribute typed_context->mail->GV_SELECTION_FROM.
    So, when you populate the possible entries in typed_context->mail->gt_default_from_addresses, just try to fill your desired default value in mentioned attribute and check if that works.
    Kind regards,
    Garcia

  • How can I change how email "from" and "to" are being handled by Groupware?

    When a follow-up business activity (e.g. sales visit) is created in CRM and assigned to another by the "person responsible" field, it triggers the following action in Outlook:
    u2022 Outlook recognizes that "created by" and "person responsible" are different
    u2022 This recognition triggers sending an email invitation for an appointment
    u2022Groupware presents / Outllok reads the "person responsible" to populate "from" Email field and "created by" to populate "to" Email field
    u2022Outlook Email invitation is received by creator of the assigned follow-up (confusing the user since they are naturally thinking that the person they made responsible for the follow-up would need to accept the assignment)
    How can I change how the email "from" and "to" are being handled by Groupware/Outlook ... in standard functionality?  ... In custom work?
    Edited by: Daniel A. Joseph on Jul 24, 2008 4:00 PM

    Welcome to the Apple Community.
    If you have a @me.com address, you can change the address you use to send email from using the drop down box in the from field in your email.

  • How to fix my Apple ID from not being disabled? I have changed the password many times already and it still wont let me update apps or download apps

    How to fix my Apple ID from not being disabled? I have changed the password many times already and it still wont let me update apps or download apps

    Apple ID disabled
    http://support.apple.com/kb/TS2446
    If you still have problem, contact iTune Support
    https://ssl.apple.com/emea/support/itunes/contact.html

  • How can I change the "From:" field in iOS Mail?

    This is a weird one.
    I have a gmail work email account that has been set up for me. There's a primary email address assigned to it, and a secondary one (which is the one I want to use).
    No problem at all sending from the secondary account on my MacBook Pro. I just hit the drop down menu by the "From:" field, and I can select it from there.
    However, when I send from my iPhone, I'm only given the option of sending from my primary email address, not the secondary one. This is despite the fact that I've synced Mail accounts via iTunes.
    Any idea how I might fix this so I can send from the secondary account on my iPhone?

    First of all, please fill in the Computer Model and Operating System fields on your My Settings’s profile (and click Save). This is essential information that should always be provided when asking for help.
    Now, what does “I can't change it” mean? What appears in the From header of the messages you send is determined by your Mail > Preferences > Accounts > Account Information settings...

  • How to change email "From" field???

    Hi Everyone, 
    New to blackberry.   I would like to know how I can change the "From" field when you send an email from the phone to a name or email address I want it to say.    
    Here is my email situation:
    My email address is ''[email protected]" (which i purchased) and anbody who sends an email to me gets forwarded to my yahoo email account.  In yahoo I created an "alias" "[email protected]" so when I send an email, nobody sees my actual yahoo account which I want to keep private.  How do I do this?  
    I searched in the forum but coudn't find any solutions.  Thanks so much for any help. 

    You couldn't find any solution because there is none given your current configuration.
    You're receiving your email from your Yahoo account - not your peronal domain account.  It's kind of a security issue for you not to be able to forge an email address on your BlackBerry.  In fact, you can't change the FROM address when replying at all on a BlackBerry.  You can forward using another email address that's set up on the device, but you can't manually enter a FROM address even when forwarding.
    First thing to do is to set up your personal email account through your BIS setup.
    Once you've done that, you can either stop forwarding your personal email to your Yahoo account, OR filter your personal email to NOT be forwarded to your device through your Yahoo BIS setup, OR have your personal email filtered on your Yahoo account and delivered to a folder other than the Inbox and it shouldn't be seen by your BIS setup.
    Jerry

  • Wiki Server: how to change who "From" field in Mail

    I have Mail set up to receive an RSS feed from our Wiki Server and in the "From" field it comes up as "Workgroup: Search Results."
    Is there any way to change this, say to "Workgroup Intranet"?

    >
    Sukhi Singh wrote:
    > Hi
    > I want to change a Parameter field in Crystal report from YYYY-MM-DD format to DD/MM/YY format
    What do you mean by Crystal Report?  Are you sure you posted this to the correct forum?

  • How do you change the "From" field to have a name that you want?

    For instance, I receive sports updates from Rotoworld and ESPN. Their email addresses are '[email protected]' and '[email protected]'. Can I change this somehow? Can I change the name so that the From field show what I want it to show instead of the long email address? I would like to just have it say "Rotoworld" and "ESPN".

    if you REALLY wanted to you could edit the .elmx email file as a text file and replace the sender name there. this can of course, be automated. However, that would be wa-a-y too much trouble and is entirely not worth it.
    Message was edited by: V.K.

  • How to extend Sales org for a material being Changed

    Hi Experts,
    i need to extend sales org , distribution Channel for a material .
    my table look like this and having 6 fields shown below
      1             2         3               4            5                     6
    Sales org | Des | Distn Chnl | desc |  Copy from So | Copy from Dstn Chnl
    If the user enters the existing value in Copy From SO and Copy Fron Distn Chnl  .  Then i need to copy all the values corresponding to the Existing SO and Distrn Chnl to the Newly entered Sales Org . 
    the table im displaying in ALV , if user perss F4 in copy From SO and Copy From Distn  , i need to show the existing values for the material being changed , this is working fine and i am able to get the existing values.
    After user selects one of the existing value for SO and Distrn channel  , i need to copy all the values to newly created So and distrn Chnl  .
    i dont know how to proceed . Please help me to solve this problem.
    Thanks,
    Shrikanth

    You can use AET to extend the sales area data of BP.  However, it wont add the fields automatically in GUI, But the generated fields are available in the relevant DB tables.
    BP GUI transaction is no more supported . Im not sure why you want to work on GUI.
    Regards,
    Shaik

  • How to restrict the user from making any changes in Sales order- item level

    Hi to all
    How to restrict the users from making any changes in sales order at item level if the same sales order is released by senior user through status profile.
    Regards
    Anish Parikh
    Edited by: anish parikh on Jan 24, 2008 5:16 AM

    Hi Anish,
    This can be achieved through the roles and authorization.
    This can be done through the basis team. they can create user profiles and roles.
    For the roles they assign some transaction codes so that they can view the only assigned tr. codes.
    Like that ur requirement can be done.
    Also u can prevent the user to change any fields in the sales order screen (VA02). for that please modify the authorisations.
    Hope i answers.
    Reward points if useful.
    Edited by: kaleeswaran bhoopathy on Jan 24, 2008 9:57 AM

  • How can I allow the application to line through a field that has been locked after being digitally signed?  We have multiple sections on a form with some fields being proposed information and other in another section having the approved information. once

    How can I allow the application to line through a field that has been locked after being digitally signed?
    We have multiple sections on a form with some fields being proposed information and other in another section having the approved information. once the approved information is entered we line through the proposed field so the data entry clerk won't pick up the wrong information.  However we are receiving an error when attempting to enter data  in the field which we have this edit.  Error property: line through cannot be set because doing so would violate the document permission setting.  any idea how we can get around this issue?

    You can control which fields are locked down after signing by setting up a collection. Then those that are not locked can be changed after signing. If this is not possible, then the line outs must occur prior to signing.

  • Shortcut for changing "from" field in Lion Mail?

    I manage a number of email accounts from Mail, and frequently need to send messages from one account, and then another account, and then another account ... In Snow Leopard, I enjoyed creating shortcuts to change the "from" field of an outgoing message.  For example, in the keyboard system preferences pane, I assigned the command "My Name <[email protected]>" the shortcut of "SHIFT+CMD+X".  That way, while writing an email, if I noticed that it was about to send from the wrong account, I'd just hit the keystroke instead of grabbing my mouse.  Mail apparently knew what I was doing, because on the drop-down tab for "From", each of my mail accounts also showed the custom assigned shortcut.
    This ability seems blocked in Lion.  Whenever I try to re-create these shortcuts in the preferences / application-shortcuts pane, they won't work!  What's worse, whenever I quite and re-open System Preferences, I find that my shortcuts have been re-assigned an extra open-bracket, such as: ">My Name <[email protected]>".
    Does anyone know what I'm doing wrong?  Is it possible to re-create these shortcuts in Lion Mail? 

    MOE O wrote:
    So Entourage can go to the previous message?  How do you do that?
    I can't stand that Mail always goes to the next newest message after deleting.
    Every other email program I've ever seen (including Entourage - see below) can do this.  Why can't Apple?  I don't want to touch the mouse most of the time because it really slows down work to move ones hands back and forth.   I did a quick web search and found these shortcuts for all the major programs.  If you know of any other program besides Apple Mail that doesn't have this, let me know.
    Until then, if Outlook, Outlook Express, Entourage, Sparrow, Postbox, and Thunderbird have had this, what's Apple's problem adding it?
    David
    Postbox Shortcuts
    For our power users, here's a list of Keyboard Shortcuts that you can use to navigate your way through Postbox.
    Message Navigation
    Mac OS X
    Windows
    Go Home
    Command + Shift + H
    Home
    Go to Next Message
    F
    F
    Go to Previous Message
    B
    B
    Go to Next Unread Message
    N
    N
    Go to Previous Unread Message
    P
    P
    Go to Next Viewed Message
    Go to Previously Viewed Message
    Sparrow
    Go to previous / next message  - cmd-[ / cmd-]
    Outlook Express
    Go to the next message in the list
    CTRL+> or CTRL+SHIFT+>
    Go to the previous message in the list
    CTRL+< or CTRL+SHIFT+<
    View properties of a selected message
    ALT+ENTER
    Refresh news messages and headers
    F5
    Go to the next unread e-mail message
    CTRL+U
    Entourage
    Display the previous message
    ⌘+[
    Display the next message
    ⌘+]
    Display the previous unread message
    CONTROL+[
    Display the next unread message
    CONTROL+]
    Moving around Thunderbird
      ⇐  |   ⇑  |   ⇒ 
    Moving between messages
    Go to Next Message
    F
    Go to Previous Message
    B
    Go to Next Unread Message
    N
    Go to Previous Unread Message
    P
    Go to Next Unread Thread (and mark current thread as read)
    T
    Go to Next Viewed Message
    Go to Previous Viewed Message
    outlook 2010:
    Switch to next message (with message open).
    CTRL+PERIOD
    Switch to previous message (with message open).
    CTRL+COMMA 

Maybe you are looking for