cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3048
Views
0
Helpful
2
Replies

How to match envelope/smtp header MAIL FROM and FROM: specified in message body?

Maros RAJNOCH
Level 1
Level 1

Hello dear ESA strong & passion admins,

 

can Cisco ESA filter messages where envelope/smtp header MAIL FROM do not match FROM: specified in message body, which is rendered by MUA (e.g. Outlook)?

 

Thanks a lot

2 Replies 2

alvinrichburg
Level 1
Level 1

As a preliminary answer I would advise looking into message filters. I haven't used them for your particular request, however matching information inthe body of a message is possible using them. Here is a link to the documentation on message filters:

 

https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01000.pdf

 

Please follow up if you have any questions. 

Maros RAJNOCH
Level 1
Level 1

@pmesjar helps us, with focusing on new feature in AsyncOS 10.0, called Forged Email Detection:

https://www.cisco.com/c/en/us/products/collateral/security/email-security-appliance/whitepaper_C11-737596.html

 

Thanks to all.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: