Filter rule not working properly


Well-Known Member
Apr 14, 2011

A client of mine has the following global e-mail filter rule:

filtername: domain deny
match: ends
opt: or
part: "$header_from:"
val: .co
unescaped: 1
action: save
dest: $home/mail/.spam
enabled: 1

Now for some reason he still receives some mail from ".co" ending e-mail from addresses (about 3-5 from 30 per day).
This shouldn't be happening...

Any ideas?

Thanks in advance!


Here is the header of the mail, just in case:

Return-Path: <[email protected]>
Delivered-To: [email protected]
Received: from cpanel.ourdomain.tld
by cpanel.ourdomain.tld with LMTP
id sMb5ERstiGFdVQAAUXkrYg
(envelope-from <[email protected]>)
for <[email protected]>; Sun, 07 Nov 2021 20:46:35 +0100
Return-path: <[email protected]>
Envelope-to: [email protected]
Delivery-date: Sun, 07 Nov 2021 20:46:35 +0100
Received: from ([]:23187)
by cpanel.ourdomain.tld with esmtp (Exim 4.94.2)
(envelope-from <[email protected]>)
id 1mjo7d-0005jK-4F
for [email protected]; Sun, 07 Nov 2021 20:46:35 +0100
Date: Sun, 07 Nov 2021 14:40:26 -0500
From: "WT2 Smart Watch" <[email protected]>
MIME-Version: 1.0
Precedence: bulk
To: <[email protected]>
Subject: It's like having a 24-hour doctor on your wrist
Message-ID: <um7NDF2_CAI2vfgDUHho6MlrMXrVo69gyxFFqhs[email protected]>
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit