DKIM and DMARC failed, received an spoofed email from ourselves

Tomass Pētersons 336 Reputation points
2022-02-22T13:26:05.7+00:00

Hi,

Our organization has one distribution group containing only one member - a mail user that has an external email address. No users has been granted Send as or Send on behalf permissions.

Few days ago a member from this group received a spoofed spam email message that has been sent on behalf of the group. It looks like this email message has been sent through Microsoft 365. Now we're wondering why Microsoft hasn't blocked this email message?
NrZ3Zgg.png

Here is a report from external member email system.
CCUvfWe.png

Our organization has already configured DKIM and DMARC and it has always worked fine for us. But this case is a little weird. Has anyone experienced something similar?

Thanks!

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,537 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 148.2K Reputation points MVP
    2022-02-22T13:52:05.71+00:00

    We've seen an uptick in messages that have failed the auth checks and still get through. I would open a ticket with 365 support.

    What about those transport rules? Did they allow the message? worth checking...:)


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.