chazzy2501 Posted June 9, 2021 Posted June 9, 2021 I have a sensitive email that has appeared in outlook. What I can't fathom is why. I'm not listed as a recipient. (nor any of my other pseudonyms) I can see all 3 recipients (1 to and 2 CC'd) and the sender of course, they're all logical single user accounts belonging to real staff. (not groups or shared) I've looked at the email properties and I still can't see my account as a recipient. Any other ideas how I can see this email? Why is it in my inbox? The nature of the email is also quite sensitive. (not enough to be encrypted)
TechMonkey Posted June 9, 2021 Posted June 9, 2021 I have had similar and it is linked to personal data being in an email, so it is being flagged to the admin, you. But I have not been able to find the process that does this or how to turn it off. I think it is something like data leakage protection. It is really annoying that it doesn't flag the email in any way, shape of form as I start reading the email, get confused about why I have been sent this and then realise I haven't been.
chazzy2501 Posted June 9, 2021 Author Posted June 9, 2021 (edited) I did a message trace, the user had sent it to my mailbox but using the name (admin@domain) this was marked as "resolved" in the trace, then I appear later (myname@domain). the admin@ is just one of many names for my mailbox (for certs and stuff) so I don't know why it didn't still show as "Mr myname" as a recipient, still that is an oddity. EDIT: The message trace said it was re-directed to me from the admin@ account. I sent from an external email account directly to admin@ and this was also re-directed BUT it correctly showed "mr myname" I'm wondering what kind of user error could have caused this. The admin@domin isn't on the gal and can't be searched. although listed as one of my smtp. (you'd have to dig) Edited June 9, 2021 by chazzy2501
TechMonkey Posted June 9, 2021 Posted June 9, 2021 It may not have been user error if the system decided it needed to be redirected and admin@domain is set as the email to flag it to.
TechMonkey Posted June 9, 2021 Posted June 9, 2021 So as my brain remembered it was DLP I went looking. In the M365 portal there is Compliance Admin Center, then go to Data Loss Prevention. You could see if there is a policy set up there and look at the activity explorer .
chazzy2501 Posted June 9, 2021 Author Posted June 9, 2021 surely if it was flagged it'd arrive with a header and the violation of sorts and wouldn't contain the contents of the email. (like the GDPR stuff) The user says they didn't sent it to me or the admin email. We are in a few teams groups together but not exclusively. maybe an email got bounced and they started a reply using the bounce?!>!
Oaktech Posted June 9, 2021 Posted June 9, 2021 surely if it was flagged it'd arrive with a header and the violation of sorts and wouldn't contain the contents of the email. (like the GDPR stuff) The user says they didn't sent it to me or the admin email. We are in a few teams groups together but not exclusively. maybe an email got bounced and they started a reply using the bounce?!>! Doesn't seem to - my stock DLP policy basically dumps it with me as though I was the recipient.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now