SMTP Inbound control setting

In R8.0.1 in SMTP Inbound Controls and under the Inbound Sender Controls tab I have .ru listed in the ‘Deny messages from the following internet addresses/domains’ section. So why would I have one user receiving spam from multiple .ru email addresses?

Thanks!

Subject: *.ru, or spoofing

Where I have blocked a TLD like that, I have used *.ru . So you might want to do that. I believe .ru would have to match user@.ru, which would never happen.

Another thing might be sender spoofing address. It might appear to the user to come from someone@somedomain.ru (The From field), but if you look at the headers, it really doesn’t (the SMTPOriginator field is different).