Share via

EOP can be used for sending email by anonymous user

Ardan Zaki 236 Reputation points
Feb 6, 2024, 2:12 AM

Hi all, I just found this discovery where my EOP can be used for sending email by anonymous. I'm using smtp test by DNS Checker. I used a made up email address. Screenshot 2024-02-06 084738 And the message is sent.Screenshot 2024-02-06 090924

How can I prevent this?

Microsoft Exchange Online
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,817 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
2,260 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Kael Yao-MSFT 37,721 Reputation points Microsoft External Staff
    Feb 6, 2024, 6:12 AM

    Hi @Ardan Zaki

    Please note that this is like you are sending from a mail server to EOP, it is expected that as an external sender you are anonymous to EOP.

    If you want to send as an authenticated sender you need to authenticate with your credentials in Azure AD (in other words only internal users can authenticate).

    If you check the message header, you will see Received: from dnschecker.org and the domain in message-ID is dnschecker.org, which indicates the message is originated from dnchecker.org.

    Hope it answers your question.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.