Hi @adam900331 ,
Welcome to the Microsoft Q&A platform!
Based on your description, you are experiencing a common problem in a hybrid Exchange environment where the MX record points to Exchange Online but some users are still on-premises. Here are some potential reasons and solutions for why on-premises users receive spam but cloud users do not:
- Make sure your mail flow is configured correctly. Because your MX record points to Exchange Online, all incoming emails should be filtered by Exchange Online Protection (EOP) before being routed to on-premises users. If mail flow is not set up correctly, some emails may bypass EOP filtering.
- For hybrid environments, it is critical to enable enhanced filtering for connectors. This ensures that EOP applies the same filtering to emails routed to on-premises users as it does to cloud users.
- An SCL of 1 means that the message has a low risk of being considered spam. However, if these messages are indeed spam, you may need to adjust the spam filtering policies or rules in EOP to make them more aggressive.
- Check if there are any transport rules that may affect spam filtering for on-premises users. Sometimes, specific rules may inadvertently allow spam to pass.
Please feel free to contact me for any updates. And if this helps, don't forget to mark it as an answer.
Best,
Jake Zhang