For the past two days, one user per day has been flooded with non-English emails claiming they were subscribed to various services. The messages keep arriving for more than 30 minutes at a time and are getting through our current email filtering. I tried changing our DMARC policy to reject with strict SPF alignment, but it did not help. What is the best way to contain this attack and make sure we do not miss anything important?
3 Answers
Check the headers and mail-delivery logs to confirm the messages are coming from outside your organization and that no allowlist rule is bypassing filtering. If your current service cannot quarantine this type of traffic before delivery, temporarily move the affected user into a stricter filtering policy or use an edge filtering service. The volume often subsides within a day or two, but keep reviewing the delivered messages for the account notification the attacker may be trying to conceal.
DMARC, SPF, and DKIM mainly tell other mail systems whether messages claiming to come from your domain are legitimate. They do not stop inbound messages sent by legitimate services, so changing your DMARC policy will not solve this. Use your inbound filtering system to quarantine or rate-limit the flood, and check whether it supports rules for subscription-style messages, unusual languages, bulk senders, or repeated patterns.
Be alert for a follow-up social-engineering attempt. Attackers may call through a collaboration app or phone pretending to be IT support and offer to fix the flood. Tell the user not to let anyone connect remotely, install software, or provide credentials or MFA codes. Consider restricting unsolicited external calls and messages while the incident is investigated.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures