Email Impersonation log has a "Matched Content" field within the output of the log. Within this "matched content" field is the HELO that contains sending email server's domain name. This idea would be to pull that sending email server's domain name out of this message and put into a separate column in the log to allow for quicker sorting to help diagnose failures and fix configuration problems.
↧