On-premise user receive spam

adam900331 50 Reputation points
2024-10-02T12:32:24.01+00:00

Hy!

I have a Hybrid Exchange. The MX is point to Exchange Online. There are some user on our on-premise Exchange. There is a distribution list: sales@domain.com. The on-premise users who are in distribution group get spam too much message, but users who is in cloud, doesn't get any spam. The spam message SCL is 1. Why? I dont understand this situation. Why don't filter the EOP these spam message? Thanks.

Microsoft Exchange Online
Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
1,337 questions
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,575 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,666 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
2,134 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Jake Zhang-MSFT 6,385 Reputation points Microsoft Vendor
    2024-10-03T08:06:02.51+00:00

    Hi @adam900331 ,

    Welcome to the Microsoft Q&A platform!

    Based on your description, you are experiencing a common problem in a hybrid Exchange environment where the MX record points to Exchange Online but some users are still on-premises. Here are some potential reasons and solutions for why on-premises users receive spam but cloud users do not:

    1. Make sure your mail flow is configured correctly. Because your MX record points to Exchange Online, all incoming emails should be filtered by Exchange Online Protection (EOP) before being routed to on-premises users. If mail flow is not set up correctly, some emails may bypass EOP filtering.
    2. For hybrid environments, it is critical to enable enhanced filtering for connectors. This ensures that EOP applies the same filtering to emails routed to on-premises users as it does to cloud users.
    3. An SCL of 1 means that the message has a low risk of being considered spam. However, if these messages are indeed spam, you may need to adjust the spam filtering policies or rules in EOP to make them more aggressive.
    4. Check if there are any transport rules that may affect spam filtering for on-premises users. Sometimes, specific rules may inadvertently allow spam to pass.

    Please feel free to contact me for any updates. And if this helps, don't forget to mark it as an answer.

    Best,

    Jake Zhang


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.