Forum Discussion
SMTP via User
Looks like a typical spoof attempt to me. Anyone can send anything as anyone on the internet when it comes to SMTP. I could pop out to my SMTP server and send an e-mail as YYYY@risebakingcompany.com if I wanted to to anyone I wanted. If they aren't using DKIM or SPF etc. it could very well get through, but in this case it was blocked and returned whom the message was set as the from address.
This is hard for me to believe, simply because I have devices on my network that I have set up to send alerts via SMTP, and if I do not authenticate as the same email as the sender it fails to send the email. SMTP via O365 seems to be very picky on what it accepts, simply because SMTP use to be so open and allow for anyone to send anything. I thought that was fixed now.
- DeletedMar 07, 2018This email originated from some other IP outside of 365. You don’t have to use their servers to send as their domains.
- Tyler MillerMar 07, 2018Brass Contributor
So you are saying that their servers allowed them to send email from our O365 domain to us, using their SMTP servers, not ours? If so, wouldn't it show the email address they used to authenticate against their SMTP server, or they just sent it anonymously with no authentication?
- DeletedMar 07, 2018They didn’t send anything to your servers you said it got blocked and then you got the NDR. I can go right now to my smtp server and send as you to some random place and if it got blocked you would get the NDR.