Hello,
Just using the ESA Spoofing message filter at the moment, however it is catching anything that has the specified domain name in it...
http://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/200166-Quarantine-Spoofed-Email-M...