How can I filter messages based on their Received: headers?

1

On my Exchange account, I'm getting spam mail with forged, valid From: addresses (e.g. my own). The forging can be told by the Received: headers.

How can I define a filter based on the contents of the Received: headers? I'm using Outlook 2010 and Exchange 2010. (No, I can't do anything about the Exchange server.)

reinierpost

Posted 2013-09-03T07:15:37.600

Reputation: 1 904

Answers

1

I don't believe you can. However you can filter based on specified words in the Message Header. You just can't narrow the search to the Received: header specifically. If the forge-signature that you are searching for is specific enough, that may get you what you need.

kmote

Posted 2013-09-03T07:15:37.600

Reputation: 2 322

What exactly do you mean by 'the Message Header', all headers collectively? – reinierpost – 2013-09-03T22:04:47.540

Thanks. I found the option in the Rules Wizard, but I do not see how to use this to filter out messages whose From header is in a particular domain, while the Received headers indicate it was sent from elsewhere. So your answer is helpful but I'm still hoping for a definite 'yes' or 'no'. – reinierpost – 2013-09-04T09:48:07.790

ah, now I understand better what you are trying to accomplish: you're looking for a mismatch between the From: domain and the Received: domain. I'm afraid you won't be able to do that from within an Outlook filter. I would think that anti-phishing software on the Exchange server should be able to do this readily. Perhaps yours needs an upgrade? – kmote – 2013-09-04T15:30:10.503

As I said, the Exchange server is not under my control. Generally it's (i.e. its sysadmins are) pretty much perfect at weeding out spam; I just want to know what additional things I can do myself. – reinierpost – 2013-09-04T16:05:34.700

I would address your specific concerns to them. – kmote – 2013-09-04T16:23:11.457