Post
Thu Jan 01, 2009 4:33 am
Don't bother with the blacklist; the "from" address is never real in spam. Even ones that superficially are following the CAN-SPAM law will keep registering new domains, spam them a short time, and discard them. They don't expose their real website unless you click though the link to the "throwaway domain." All you get from adding things to the blacklist is a blacklist so long it slows down MWP.
MWP is very good for filtering for these, though. Is there anything about your emails that is unique (they all come from one IP address, for instance?) Or if not, can you get everyone to add the same exact string of text to the "organization" field of their outgoing emails (maybe the name of your company if it isn't the same as the domain name of the email, or even just a number that everyone in the company can remember, like the phone number of the local luncheonette)?
Anyway, make sure everyone who sends an email that will be listed as "from" your email address will include that same filterable item. Then set up a filter that IF the "from" is one of your addresses AND IF the complete headers do NOT include that item, it is spam. If you can make sure no one is going to get a new laptop and forget to set up his email on the new machine correctly for this, then it's a good enough filter to use as an autodelete.