Home

Exchange Online Mail Traffic Report

%3CLINGO-SUB%20id%3D%22lingo-sub-193909%22%20slang%3D%22en-US%22%3EExchange%20Online%20Mail%20Traffic%20Report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-193909%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20noticed%20a%20couple%20of%20times%20when%20I%20look%20at%20my%20weekly%20MailTraffic%20report%20that%20the%20number%20of%20%22Spam%22%20messages%20do%20not%20equal%20the%20amount%20when%20I%20run%20a%20mail%20trace%20for%20the%20same%20time%20period.%26nbsp%3B%20I've%20also%20take%20into%20consideration%20IP%20blocks%20as%20well.%26nbsp%3B%20Just%20wondering%20what%20could%20be%20the%20cause.%26nbsp%3B%20Appreciate%20the%20assistance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-193909%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EReports%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-194285%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%20Mail%20Traffic%20Report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-194285%22%20slang%3D%22en-US%22%3E%3CP%3EWell%20the%20data%20from%20those%20two%20sources%20seems%20to%20match%20in%20my%20case%2C%20but%20after%20all%20that's%20my%20personal%20tenant%20with%20just%20~100%20messages%20per%20day.%20I%20guess%20you%20can%20open%20a%20support%20case%20to%20get%20this%20investigated%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-194257%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%20Mail%20Traffic%20Report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-194257%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20Evening%20Vasil%3A%20Yes%20I%20have%20it%20set%20to%20run%20both%20Inbound%20%26amp%3B%20Outbound%20msg%2C%20in%20addition%20to%20I%20actually%20included%202%20extra%20days%20just%20to%20make%20sure%20that%20I%20could%20pull%20everything.%26nbsp%3B%20My%20main%20concern%20was%20that%20something%20had%20%22slipped%22%20through%20Exchange%20when%20it%20was%20not%20suppose%20to.%26nbsp%3B%20Yes%20I'm%20using%20Security%20%26amp%3B%20Compliance%20portal%20to%20run%20the%20trace.%26nbsp%3B%20Really%20like%20that%20we%20are%20not%20restricted%20to%20just%207%20day%20logs%2C%26nbsp%3B%20It's%20nice%20to%20be%20able%20to%20pull%20additional%20days%20with%20out%20having%20to%20wait%20for%20Exchange%20team%20to%20run%20the%20logs%20for%20us.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-193977%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%20Mail%20Traffic%20Report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-193977%22%20slang%3D%22en-US%22%3E%3CP%3EAre%20you%20including%20both%20outbound%20and%20inbound%20messages%20in%20the%20trace%3F%20The%20reports%20do%20that%20(directionality%20is%20set%20to%20%22All%22%20by%20default)%2C%20and%20if%20you%20run%20the%20same%20report%20from%20the%20SCC%20(%3CA%20href%3D%22https%3A%2F%2Fprotection.office.com%2F%23%2Freportv2%3Fid%3DSentAndReceivedMailATP%26amp%3Bpivot%3DEventType%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fprotection.office.com%2F%23%2Freportv2%3Fid%3DSentAndReceivedMailATP%26amp%3Bpivot%3DEventType%3C%2FA%3E)%2C%20you%20will%20actually%20get%20a%20breakdown%20by%20sent%2Freceived%20messages.%20Similarly%2C%20make%20sure%20you%20include%20all%20recipients.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%20make%20sure%20to%20account%20for%20the%20timezones%20when%20doing%20the%20trace%20for%20a%20specific%20date%20range.%20The%20only%20differences%20I%20can%20spot%20in%20my%20tenant%20are%20for%20the%20first%2Flast%20day%2C%20probably%20due%20to%20the%20cutoff%20time.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Scott Johnson
Contributor

I've noticed a couple of times when I look at my weekly MailTraffic report that the number of "Spam" messages do not equal the amount when I run a mail trace for the same time period.  I've also take into consideration IP blocks as well.  Just wondering what could be the cause.  Appreciate the assistance.

3 Replies

Are you including both outbound and inbound messages in the trace? The reports do that (directionality is set to "All" by default), and if you run the same report from the SCC (https://protection.office.com/#/reportv2?id=SentAndReceivedMailATP&pivot=EventType), you will actually get a breakdown by sent/received messages. Similarly, make sure you include all recipients.

 

Also make sure to account for the timezones when doing the trace for a specific date range. The only differences I can spot in my tenant are for the first/last day, probably due to the cutoff time.

Good Evening Vasil: Yes I have it set to run both Inbound & Outbound msg, in addition to I actually included 2 extra days just to make sure that I could pull everything.  My main concern was that something had "slipped" through Exchange when it was not suppose to.  Yes I'm using Security & Compliance portal to run the trace.  Really like that we are not restricted to just 7 day logs,  It's nice to be able to pull additional days with out having to wait for Exchange team to run the logs for us.

Well the data from those two sources seems to match in my case, but after all that's my personal tenant with just ~100 messages per day. I guess you can open a support case to get this investigated?

Related Conversations
Using Flow to send out automatic emails on a weekly basis
sokva in Office 365 on
2 Replies
Reporting on Project Online (PWA) Timesheets
Andy Dennis in Project on
3 Replies
Outlook (365) Need Password - Issue
Muhammad Ali Khan in Office 365 on
20 Replies
Accessing a shared mailbox from a mobile device
Hexsysadmins in Office 365 on
14 Replies
Add, Edit, Delete Project Online data using Excel
MonteStJohns in Project on
5 Replies