How to configure the LDAP lookup plug-in across multiple OUs?
Choose the base DN that is above the level of all OUs that contain users, and leave the DN specification out of the individual attributes.
If you have the OUs listed in the root, you can use the following:
attr.Last\ Name = :(mail=$sender-email$):sn