Hello all, I was the original poster of this topic but was away for a
couple of days.
I find it amazing to see the number of suggestions and ideas that
have come up here.
However none of the constuctions matched "my" From: lines of the form
From: "Firstname Lastname@" <recipient-domain.com
sendern...@real-senders-domain.com
<mailto:sendern...@real-senders-domain.com>>
Are you getting a lot of these? It looks more like a mistake than a
tactic.
Not a lot, but the trick is that Outlooks displays both parts, and users
think that it is an internal mail because the "Firstname Lastname" is
real in the company and the "recipient-domain.com" is the real recipient
domain.
So it is a trick to circumvent SPF denials which prevent a spammer from
sending "internal" mails from external addresses.
So I think it is not a mistake, I suppose this is carefully crafted to
achieve exactly this result.
JC