cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3477
Views
0
Helpful
2
Replies

How to match envelope/smtp header MAIL FROM and FROM: specified in message body?

Maros RAJNOCH
Level 1
Level 1

Hello dear ESA strong & passion admins,

 

can Cisco ESA filter messages where envelope/smtp header MAIL FROM do not match FROM: specified in message body, which is rendered by MUA (e.g. Outlook)?

 

Thanks a lot

2 Replies 2

alvinrichburg
Level 1
Level 1

As a preliminary answer I would advise looking into message filters. I haven't used them for your particular request, however matching information inthe body of a message is possible using them. Here is a link to the documentation on message filters:

 

https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01000.pdf

 

Please follow up if you have any questions. 

Maros RAJNOCH
Level 1
Level 1

@pmesjar helps us, with focusing on new feature in AsyncOS 10.0, called Forged Email Detection:

https://www.cisco.com/c/en/us/products/collateral/security/email-security-appliance/whitepaper_C11-737596.html

 

Thanks to all.