Jump to content

Recommended Posts

Posted

I have a sensitive email that has appeared in outlook. What I can't fathom is why. I'm not listed as a recipient. (nor any of my other pseudonyms) I can see all 3 recipients (1 to and 2 CC'd) and the sender of course, they're all logical single user accounts belonging to real staff. (not groups or shared)

 

I've looked at the email properties and I still can't see my account as a recipient. Any other ideas how I can see this email? Why is it in my inbox?

 

The nature of the email is also quite sensitive. (not enough to be encrypted)

Posted
I have had similar and it is linked to personal data being in an email, so it is being flagged to the admin, you. But I have not been able to find the process that does this or how to turn it off. I think it is something like data leakage protection. It is really annoying that it doesn't flag the email in any way, shape of form as I start reading the email, get confused about why I have been sent this and then realise I haven't been.
Posted (edited)

I did a message trace, the user had sent it to my mailbox but using the name (admin@domain) this was marked as "resolved" in the trace, then I appear later (myname@domain). the admin@ is just one of many names for my mailbox (for certs and stuff) so I don't know why it didn't still show as "Mr myname" as a recipient, still that is an oddity.

 

EDIT: The message trace said it was re-directed to me from the admin@ account. I sent from an external email account directly to admin@ and this was also re-directed BUT it correctly showed "mr myname"

 

I'm wondering what kind of user error could have caused this. The admin@domin isn't on the gal and can't be searched. although listed as one of my smtp. (you'd have to dig)

Edited by chazzy2501
Posted
So as my brain remembered it was DLP I went looking. In the M365 portal there is Compliance Admin Center, then go to Data Loss Prevention. You could see if there is a policy set up there and look at the activity explorer .
Posted

surely if it was flagged it'd arrive with a header and the violation of sorts and wouldn't contain the contents of the email. (like the GDPR stuff)

 

The user says they didn't sent it to me or the admin email. We are in a few teams groups together but not exclusively.

 

maybe an email got bounced and they started a reply using the bounce?!>!

Posted
surely if it was flagged it'd arrive with a header and the violation of sorts and wouldn't contain the contents of the email. (like the GDPR stuff)

 

The user says they didn't sent it to me or the admin email. We are in a few teams groups together but not exclusively.

 

maybe an email got bounced and they started a reply using the bounce?!>!

 

Doesn't seem to - my stock DLP policy basically dumps it with me as though I was the recipient.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...