NethServer Version: 7.6.1810
Module: nethserver-mail 2.4.3-1 | clamav 0.101.0-1 | rspamd 1.8.2-2 | dovecot-antispam 0.0.49-3
Some of my users have been getting unwanted mails with malware, this mails addresses has this in common:
some.known.user@some.known.domain.user.attacker@attacker.domian.
For example:
rosario@konfort.cucancun@jbge.com.mx
rosario@konfort.cu is the mail address that is known to my user
This mails some random description like:
Please review the following invoice
And a .doc file which contains some kind of malware.
I have Anti-spam and Anti-virus features enabled, yet this messages keep getting through. Is there a rule or something I can do to stop this.
Since this mails has a @ on the user, maybe a rule might stop them. Any ideas?