X-Microsoft-Antispam-Message-Info contains offensive language.

HankEU 1 Reputation point
2022-11-30T13:33:03.497+00:00

Can a spammer post content into the “X-Microsoft-Antispam-Message-Info” in the email header? Should they even be able to? Especially taboo language content.

The sender appears to be using MS Outlook/Office online services.

=?iso-8859-1?Q?um1pff14+*****fUMzARsiSg=3D=3D?=

I replaced the plural for female anatomy slang word with ***** (a 4 letter word beginning with a “C”, 5 letters plural)

MN0PR12MB5787.namprd12.prod.outlook.com (::1) by
PH7PR12MB6719.namprd12.prod.outlook.com with HTTPS; Wed, 30 Nov 2022 [hh:nn:ss]
+0000
Received: from DS7PR05CA0056.namprd05.prod.outlook.com (2603:10b6:8:2f::17) by
MN0PR12MB5787.namprd12.prod.outlook.com (2603:10b6:208:376::9) with Microsoft
SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)

This spam email was for a dental whitening treatment (spf none, dkim none, From address strange, image content hosted on a platform against their tos, target URLs to a seemingly unrelated website)

They previously also sent a very threatening abusive email last week, with foul language in the email body. I’ve reported to report_spam@Karima ben .com but not sure what more I can do.

Microsoft 365 and Office | Development | Other
Outlook | Windows | Classic Outlook for Windows | For business
{count} votes

2 answers

Sort by: Most helpful
  1. Michael Taylor 60,331 Reputation points
    2022-11-30T15:05:42.197+00:00

    You can send an email (using whatever network software you want) with any HTTP header you want with any content you want. So yes it is trivial to do that. Unless the HTTP header in question has special meaning (e.g. Content-Type or Content-Length) then it is just a string value and no validation is really done. You can do this with any HTTP packet.

    0 comments No comments

  2. KyleXu-MSFT 26,396 Reputation points
    2022-12-02T08:11:13.563+00:00

    @HankEU

    Which mailbox server that you used?

    If you are using a mail server that managed by your organization, it is suggested to add a spam filter tool for your mail server.
    If you are using a mail server that managed by Microsoft, such as hotmail.com, the most suitable way is reported to Microsoft and add this sender into a block sender in Outlook.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.