Mail Filter Settings -> Always reject the message...

This does not reject the message on the SMTP level, but happily accepts this:

$ telnet mail.example.com 25
Connected to example.com.
Escape character is '^]'.
220 example.com ESMTP Postfix
HELO foo
250 mail.example.com
MAIL FROM: user at example.com
250 2.1.0 Ok
RCPT TO: user at example.com
250 2.1.5 Ok
354 End data with <CR><LF>.<CR><LF>
From: user at example.com
To: user at example.com
Subject: foo

250 2.0.0 Ok: queued as 500C41086A0A
221 2.0.0 Bye

After this it sends a bounce message to user at example.com:

<user at example.com>: permission denied. Command output: Invalid From: header.
    user at example.com looks like a forged sender

I think this should be rejected earlier, because we already assume that
the address is forged. And we already know that user at example.com hasn't
authenticated itself.

