Hello all, I was the original poster of this topic but was away for a
couple of days.
I find it amazing to see the number of suggestions and ideas that
have come up here.

However none of the constuctions matched "my" From: lines of the form

From: "Firstname Lastname@" <recipient-domain.com
sendern...@real-senders-domain.com
<mailto:sendern...@real-senders-domain.com>>

Are you getting a lot of these? It looks more like a mistake than a
tactic.

Not a lot, but the trick is that Outlooks displays both parts, and users think that it is an internal mail because the "Firstname Lastname" is real in the company and the "recipient-domain.com" is the real recipient domain. So it is a trick to circumvent SPF denials which prevent a spammer from sending "internal" mails from external addresses. So I think it is not a mistake, I suppose this is carefully crafted to achieve exactly this result.

JC


Reply via email to