I need to create a rule that covers the scenarios below. We have already checked for support from Symantec and had the answer that it is not possible to set up to detect a sender by sending a message to only one recipient (one to one).
Scenario 1: Detect (@acme for a popular domain- one for one)
sender: @ ACME.com.br
recipient: @ XXX.com
Scenario 2: Do not detect (when you have @YYY.com as your recipient)
sender: @ ACME.com.br
recipient: @ XXX.com
recipient: @ YYY.com.br