Views:

"Unknown@unknown" that shows up in IMSVA reports is for blank sender addresses. IMSVA looks/logs the SMTP envelope addresses for their report. If you are familiar with sending emails through telnet command, below is a typical format of commands that a sending MTA sends to receiving MTA.

telnet MTA_IP or FQDN 25
helo/ehlo
MAIL FROM: sender@domain.com
RCPT TO: recipient@domain.com
DATA
From: Sender@Domain.Com
To: Recipient@Domain.Com
Subject: Test email

This is message body or content.
.

The addresses in MAIL FROM: and RCPT TO: commands are the SMTP envelope addresses. These are the ones logged/recorded by IMSS in reports.

The addresses in From: and To: headers after the DATA command are the message headers. These are the addresses displayed and the addresses you see once you received the email.

Generally and is the case in MOST MTA's, NDR mails, and DSN mails, and sometimes email read receipts as well as OOO (Out of Office) messages (in the case of MS EXchange for example) are sent with a blank MAIL FROM: address. Thus, IMSVA will have no address to put in the logs/reports for those emails. So IMSVA simply consolidates them to one category which is unknown@unknown.