Recently, my colleagues and I have seen a drastic increase in the number of NDR’s being sent to our users, in response to spoofed emails to various domains, being sent from various servers (not our own, of course). This began as a few sporatic returns, and has since increased accross several of our clients. With most filters not using SPF filtering (most of these domains have legit V1 SPF records), has anyone seen a method to cut this down? Anybody want to back me up with similar issues?