You can check an email that has entered the user's mailbox to see if the sender address in the email header is consistent, preventing this from being a Domain Spoof. also, you can check the SPF record.
double click the message->properties->internet headers
If so: Setting Up Domain Spoof Protection in Microsoft 365
(Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.)
Regards
Shaofan
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.