Why Are M365 Users Getting Spam From Their Own Accounts?

0
1
Asked By CuriousCoder42 On

I've received a few reports from an organization where users are finding spam emails coming from their own accounts. The trace logs suggest these emails are being sent internally, from one user back to themselves. We've already had them change their passwords, and multi-factor authentication (MFA) is enabled. I've checked their inbox rules and confirmed that DKIM is set up, but I'm still at a loss for what might be causing this. Any ideas on what I should investigate next?

3 Answers

Answered By CuriousCoder42 On
Answered By AdminAce21 On

Definitely consider disabling Direct Send as soon as possible. You'll also want to ensure that you have the correct connectors set up for any legitimate email sources outside of Office 365.

Answered By TechieTom64 On

This issue is likely due to Microsoft's Direct Send vulnerability. Users with an Exchange account can send emails that bypass standard security measures, and that's probably why you're seeing these spam emails. We had similar problems and had to set up specific rules in Exchange to block it, while allowing certain email addresses to still use direct send because we couldn’t disable it organization-wide.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.