Why does ORF whitelist emails with blank sender addresses?
Article was last updated on September 7, 2015. View products that this article applies to.You probably have the Whitelist Delivery Status Notifications option enabled (Administration Tool: Whitelists / Sender Whitelist page) in your configuration. Disabling it and saving the configuration should solve the problem.
ORF has this option because it is an RFC standards requirement that every SMTP server must accept Delivery Status Notifications. These emails are sent with blank sender address. To keep your server compatible with the Internet standards, ORF could exclude incoming Delivery Status Notifications (e.g., Non-Delivery Reports) from filtering.
Unfortunately, spammers often try to exploit this requirement by sending spam with blank addresses to avoid filtering, so we strongly suggest not having this option enabled.
Applies To
The article above is not specific to any ORF versions.