SJ98 Posted June 23, 2023 Posted June 23, 2023 Hello all, We have ran into some issues that we're not sure how to proceed on. We have a company that uses one of our internal email addresses as an external address to send financial information to people within the school. Microsoft keeps picking these emails up as suspicious, meaning they are left in the Junk folder and are being constantly missed. We've tried to look in our admin center, but there's nothing clear to indicate that we can get these emails to send to staff Inboxes rather than Junk. The emails do also say 'The sender is not a verified sender' at the top. Does anyone have any ideas for this? Thank you in advance! Sam
TechMonkey Posted June 23, 2023 Posted June 23, 2023 (edited) How are they sending the email? From their own system with your email slapped in as the sender? If so, you need to add their details in to your SPF record so it is marked as a trusted source. EDIT: If you have direct access to one of the emails then copy the headers and paste into MXToolbox email header analyzer and it should point you in a good direction. Edited June 23, 2023 by TechMonkey 1
SJ98 Posted June 23, 2023 Author Posted June 23, 2023 Hi TechMonkey, Thank you for the response. I will look into adding it to our SPF record. Yes, one of the email accounts here is used as the sender. I will update with a response once I have received more information! Thanks, Sam
FN-GM Posted June 23, 2023 Posted June 23, 2023 The SPF is the way to go. But it does come with risk. This third party could act on your behalf. Also their messages are sent without going through any filters, if it is misused your domain reputation is at risk. 1
Rob_D Posted June 23, 2023 Posted June 23, 2023 If it's specifically identifiable emails (always from the same email or with the same subject), then you could use mailflow rules to set the spam confidence to 0.
phil0569 Posted June 23, 2023 Posted June 23, 2023 This is the rule we have in place, just enter the email address and when they are received it sets the confidence level so they dont go in the Junk.
TechMonkey Posted June 23, 2023 Posted June 23, 2023 Is that a bit of a gamble though? If an actual spam/phishing email came through it would be waved through with no checks. Many attacks use real emails gleaned from dumps, lists or from compromised address books and email accounts so the email could well be out there. There are no other checks happening there except the address.
phil0569 Posted June 23, 2023 Posted June 23, 2023 You have to put in the incoming email address, which you should be confident is real.
SJ98 Posted June 23, 2023 Author Posted June 23, 2023 TechMonkey, Yes, it is a gamble to be honest. The problem we've had is that we initially had the spam confidence set to -1 but that didn't seem to have changed anything and all of our staff are still saying emails are being sent to their junk. It may just be something we have to keep an eye on.
SJ98 Posted June 23, 2023 Author Posted June 23, 2023 Hi Rob_D, Yes - this is something we tried, but they were still going to the Junk folder. It's always the same email - probably the same subject as well?
SJ98 Posted June 23, 2023 Author Posted June 23, 2023 Hi phil0569, Is this setting for an individual user on their account, or the one in the Admin Center? We have tried to set the confidence to -1, but we're still seeing complaints about them being sent to Junk.
TechMonkey Posted June 23, 2023 Posted June 23, 2023 (edited) You have to put in the incoming email address, which you should be confident is real. Yes, I get that. But if a phisher sends an email pretending to be that email it will get passed through your system with no checking. If it was an internal system I could understand, but you have specifically stated from outside. Pretending to be from an email is a phishes So if someone guesses that email address, or that email is farmed from a compromised account, then email will go through to users with no troubles at all, even if it is the spammiest of spams or the phishiest of phishes. Edited June 23, 2023 by TechMonkey
phil0569 Posted June 23, 2023 Posted June 23, 2023 This is a mail flow rule, we put it on for any incoming mail, so it's not just put for one person it's any incoming mail, then you add the incoming mail address. So for example we add [email protected] in to the field, when it comes across a message from them it changes the confidence level in the message header to -1 (not to go into junk). There is also another setting to bypass clutter which does the same thing. - - - Updated - - - Clutter and junk in OWA are both the same thing now.
phil0569 Posted June 23, 2023 Posted June 23, 2023 Yes in some ways, but if it contains an executable payload then it goes for authorization before it gets let through, if it is just plain spam then yes it will get through, we have another rule which checks for any attachments that can be used for execution to stop any malicious payloads coming through.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now