Try something like this index=* sourcetype=maillogs (earliest=-30d@d latest=-5d@d) OR (earliest=-24h)
| eventstats earliest(_time) as earliest_time latest(_time) as latest_time by sender
| where earliest_time < relative_time(now(),"-24h") AND latest_time >= relative_time(now(),"-24h")
... View more