Would this work to blacklist mail with a "From: " claiming to be PayPal, but sent from fakedomain.tld?
blacklist_from *@paypal.com whitelist_from_rcvd *@paypal.com paypal.com -- Apple broke AppleScripting signatures in Mail.app, so no random signatures.