Home

How do I report on mails that have been blocked by my AutoForwarding to external domain block rules?

%3CLINGO-SUB%20id%3D%22lingo-sub-804380%22%20slang%3D%22en-US%22%3EHow%20do%20I%20report%20on%20mails%20that%20have%20been%20blocked%20by%20my%20AutoForwarding%20to%20external%20domain%20block%20rules%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-804380%22%20slang%3D%22en-US%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20a%20rule%20setup%20on%20Exchange%20online%20which%20successfully%20blocks%20emails%20that%20satisfy%20a%20%22Block%20Automatic%20forwarding%20of%20mail%20to%20external%20domains%22%20policy%20rule.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20see%20the%20report%20which%20shows%20a%20%22rule%20hit%22%20and%20get%20an%20email%20notification%20every%20time%20the%20rule%20is%20hit%20as%20well.%20I%20don't%2C%20however%2C%20see%20a%20report%20of%20the%20evidence%20of%20the%20blocked%20emails.%20Is%20this%20possible%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20%22Show%20me%20a%20list%20of%20actual%20blocked%20emails%22%20rather%20than%20%22show%20me%20a%20list%20of%20rule%20hits%22%20if%20that%20makes%20sense.%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20problem%20is%26nbsp%3BI%20cannot%20distinguish%20between%20rule%20hits%20and%20blocks%2C%20as%20currently%2C%20the%20notification%20shows%3A%3C%2FP%3E%3CP%3E%22Rule%20Hit%3A%20Block%20Client%20Forwarding%20to%20an%20external%20domain%2C%20Action%3A%20AuditSeverityLevel%2C%20RejectMessage%2C%20GenerateIncidentReport%22%26nbsp%3B%20but%20it%20shows%20the%20same%20message%20for%20auto-forwarded%20emails%20inside%20the%20domain%20as%20well.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20that%20makes%20sense%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-804380%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-805150%22%20slang%3D%22en-US%22%3ERe%3A%20How%20do%20I%20report%20on%20mails%20that%20have%20been%20blocked%20by%20my%20AutoForwarding%20to%20external%20domain%20block%20ru%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-805150%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46448%22%20target%3D%22_blank%22%3E%40Christo%20De%20Lange%3C%2FA%3E%26nbsp%3B%20Solution%2FWorkaround%20-%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Create%20a%20Shared%20Mailbox%20dedicated%20for%20this%20specific%20purpose.%3C%2FP%3E%3CP%3E2.%20In%20your%20existing%20Transport%20rule%20for%20blocking%20auto-forward%20to%20external%20domains%26nbsp%3B%20%26lt%3B%20Add%20additional%20action%20%26lt%3B%20send%20a%20copy%20%2F%20bcc%20the%20email%20to%20%26lt%3B%20Newsharedmailbox%40domain.com%20.%3C%2FP%3E%3CP%3E3.%20Apply%20%26lt%3B%20ok%20%26lt%3B%20Enforced%20%26lt%3B%20High%20Severity%20audit.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20gives%20you%20the%20copy%20of%20email%20(which%20are%20actually%20blocked%20from%20being%20auto-forwarded)%3C%2FP%3E%3CP%3ETest%20to%20see%20if%20it%20works%2C%20else%20we%20can%20probably%20go%20for%20another%20workaround%20in%20that%20case.%20You%20can%20have%20many%20actions%20to%20corresponding%20conditions%20defined%20in%20a%20Transport%20Rule.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%20!%3C%2FP%3E%3CP%3EAnkit%20Shukla%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-805190%22%20slang%3D%22en-US%22%3ERe%3A%20How%20do%20I%20report%20on%20mails%20that%20have%20been%20blocked%20by%20my%20AutoForwarding%20to%20external%20domain%20block%20ru%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-805190%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20get%20this%20data%20from%20the%20message%20trace%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fsecuritycompliance%2Fmessage-trace-scc%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fsecuritycompliance%2Fmessage-trace-scc%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Christo De Lange
Occasional Contributor

Hello

 

We have a rule setup on Exchange online which successfully blocks emails that satisfy a "Block Automatic forwarding of mail to external domains" policy rule.

 

I can see the report which shows a "rule hit" and get an email notification every time the rule is hit as well. I don't, however, see a report of the evidence of the blocked emails. Is this possible? 

 

So "Show me a list of actual blocked emails" rather than "show me a list of rule hits" if that makes sense. 

The problem is I cannot distinguish between rule hits and blocks, as currently, the notification shows:

"Rule Hit: Block Client Forwarding to an external domain, Action: AuditSeverityLevel, RejectMessage, GenerateIncidentReport"  but it shows the same message for auto-forwarded emails inside the domain as well.

 

Hope that makes sense

 

Thanks in advance

 

2 Replies
Highlighted

@Christo De Lange  Solution/Workaround - 

 

1. Create a Shared Mailbox dedicated for this specific purpose.

2. In your existing Transport rule for blocking auto-forward to external domains  < Add additional action < send a copy / bcc the email to < Newsharedmailbox@domain.com .

3. Apply < ok < Enforced < High Severity audit.

 

This gives you the copy of email (which are actually blocked from being auto-forwarded)

Test to see if it works, else we can probably go for another workaround in that case. You can have many actions to corresponding conditions defined in a Transport Rule.

 

 

Cheers !

Ankit Shukla