I have one user that is constantly receiving spoofed emails (appears to be from an old user but isn’t). Looking at the headers, show they are sent from:
“korea-7ugtwa8l7.org ([12.146.192.91])”
“korea-7ugtwa8l7.com ([12.146.192.91])”
“korea-7ugtwa8l7.net ([12.146.192.91])”
The user is a fussy person and does not want to block it using a rule and would like it to be blocked at the server.
So, what I have done on the mail server: In the Exchange System Manager, I have added the IP address to the Deny list in Connection Filtering and then Applied the Connection Filter in the Default SMTP Virtual Server Properties. Even after a server reboot, these ‘spoofed’ emails are still being received. Is there something else I can try or a step that I have missed for this to work?