Home

Users are flooded with NDR emails (GraphTransactionItem)

%3CLINGO-SUB%20id%3D%22lingo-sub-42933%22%20slang%3D%22en-US%22%3EUsers%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-42933%22%20slang%3D%22en-US%22%3E%3CP%3EHello!%20We%20desperately%26nbsp%3Bneed%20help%20in%20determining%20where%20thousands%20of%20NDR%20emails%20are%20coming%20from.%20This%20is%20Exchange%20Online%20only%2C%20not%26nbsp%3Ba%20hybrid%20deployment.%26nbsp%3B%3C%2FP%3E%3CP%3EAbout%20a%20month%20ago%20all%20mailboxes%20on%20one%20of%20the%20domains%20started%20receiving%20NDR%20emails%20with%20a%20subject%20similart%20to%20this%3A%26nbsp%3B%22Undeliverable%3A%20GraphTransactionItem%3Agti%20gti.TransactionId%3A8ab6ade9-1783-4d96-xxxx-b7a2b1df83fb%20gti.Name%3AUpdateSecondaryShallowCopy%E2%80%9D.%20The%20transaction%20names%20sometimes%20are%20different%2C%20and%20so%20far%20we%20got%20emails%20with%204%20types%20of%20Graph%20transactions%3A%3C%2FP%3E%3CP%3E%E2%80%A2%20PropagateActionToSubscribers%3CBR%20%2F%3E%E2%80%A2%20UpdateSecondaryShallowCopy%3CBR%20%2F%3E%E2%80%A2%20DeleteSecondaryShallowCopy%3CBR%20%2F%3E%E2%80%A2%20PublicRelationshipNodePropagation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMicrosoft%20Support%20engineers%20have%20no%20idea%20what%20is%20going%20on%20and%20how%20to%20resolve%20this%20issue%2C%20and%20our%20users%20are%20getting%20very%20impatient%26nbsp%3Bsince%20they%20all%20are%20receiving%20thousands%20of%20NDR%20emails%20per%20week.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20tried%20to%20create%20transport%20rules%20to%20stop%20those%20emails%20but%20somehow%20they%20have%20no%20effect%2C%20and%20so%20does%20the%20NDR%20backscatter%20setting.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20emails%20are%20sent%20from%20Microsoft%20Outlook%3CBR%20%2F%3E%3CMICROSOFTEXCHANGE329E71EC88AE4615BBC36AB6CE99999E%3E%26nbsp%3Band%20all%20users%20on%20that%20domain%20receive%20them.%20There%20are%20also%20multiple%20addresses%20similar%20to%20this%20SPO_Arbitration_d91eee03-1846-9999-ab71-8b51cdb7f4df%40domainname.onmicrosoft.com%20to%20which%20the%26nbsp%3B%3CSPAN%3EGraphTransactionItem%20emails%20are%20sent%20but%3C%2FSPAN%3E%26nbsp%3Bfail%20to%20be%20delivered%20(%23Receive%2C%20Fail).%20This%20has%20made%20me%20think%20that%20it%20has%20something%20to%20do%20with%20arbitration%20mailboxes.%20I%E2%80%99m%20not%20an%20Exchange%20expert%2C%20my%20specialty%20is%20SharePoint%2C%20so%20I%20could%20only%20guess.%20But%20hopefully%20this%20will%20make%20sense%20to%20someone%20and%20this%20mistery%20will%20be%20solved!%20%3A)%3C%2Fimg%3E%3C%2FMICROSOFTEXCHANGE329E71EC88AE4615BBC36AB6CE99999E%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20this%20might%20helps%2C%26nbsp%3BI%20can%20provide%20a%20sample%20of%20the%20NDR%20email.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EElena.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-42933%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-151897%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-151897%22%20slang%3D%22en-US%22%3E%3CP%3EHave%20you%20tried%20this%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F30431.new-boomerang-feature-in-eop-to-prevent-backscatter-reverse-ndr-attack.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F30431.new-boomerang-feature-in-eop-to-prevent-backscatter-reverse-ndr-attack.aspx%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148833%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148833%22%20slang%3D%22en-US%22%3E%3CP%3ESame%20for%20me.%20I%20made%20a%20ticket%20with%20Microsoft%2C%20and%20they%20ultimately%20said%2C%20%22It%20came%20from%20you%2C%20it's%20your%20problem%22.%20They%20still%20come%20through%20every%20once%20in%20awhile.%20Mine%20sends%20to%20like%207%20people%20or%20so%2C%20and%20it's%20always%20the%20same%20people.%20Don't%20know%20what%20the%20correlation%20is%20though.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148626%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148626%22%20slang%3D%22en-US%22%3E%3CP%3EI%20had%20an%20email%20go%20out%20to%20some%20of%20my%20colleagues%20with%20the%20subject%20GraphTransactionItem%3Agti%20gti.TransactionId%3Ab724c242-5606-41b5-8666-b5b0ce9c78e6%20gti.Name%3APropagateItemUpdate%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20just%20want%20to%20know%20what%20is%20this%2C%20this%20email%20was%20not%20in%20my%20sent%20items.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-138922%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-138922%22%20slang%3D%22en-US%22%3E%3CP%3EI%20just%20had%20a%20few%20more%20of%20these%20this%20week%20coming%20from%20my%20email%20address.%20I%20have%20no%20clue%20what%20these%20are.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-127669%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-127669%22%20slang%3D%22en-US%22%3E%3CP%3EOne%20of%20my%20users%20is%20reporting%20this%20today.%20I%20can%20pull%20the%20message%20in%20the%20search%20center%2C%20no%20info%20in%20it%20at%20all%2C%20and%20just%20the%20weird%20subject%20line.%20Users%20think%20they%20are%20being%20spoofed.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-121207%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-121207%22%20slang%3D%22en-US%22%3E%3CP%3EI%20just%20had%20an%20email%20also%20go%20out%20with%26nbsp%3BGraphTransactionItem%20in%20the%20subject.%20No%20body.%20It%20was%20sent%20from%20my%20email%20address%2C%20though%2C%20and%20that%20is%20strange.%20We%20only%20saw%20this%20one%2C%20I%20guess%20we'll%20hold%20off%20on%20a%20ticket%20unless%20we%20see%20a%20second%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43392%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43392%22%20slang%3D%22en-US%22%3E%3CP%3EOur%20open%20support%20ticket%20%23%20is%26nbsp%3B617010594021142.%20There's%20also%20this%20%3CA%20href%3D%22https%3A%2F%2Fanswers.microsoft.com%2Fen-us%2Fmsoffice%2Fforum%2Fmsoffice_o365admin-mso_other%2Foffice-365-mail-flow-backscatter%2Fb3997119-95c4-4cb6-9753-f746b49571e3%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ethread%3C%2FA%3E%26nbsp%3Baddressing%20the%20same%20issue%2C%20but%20no%20solution%20so%20far.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43304%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20are%20flooded%20with%20NDR%20emails%20(GraphTransactionItem)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43304%22%20slang%3D%22en-US%22%3E%3CP%3ECan%20you%20post%20the%20support%20incident%20number%3F%20This%20might%20help%20some%20of%20the%20Exchange%20engineers%20look%20into%20the%20problem.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20certainly%20seems%20like%20something%20odd%20is%20happening%20somewhere%20along%20the%20line...%20The%20name%20%22graph%20transaction%20item%22%20might%20make%20you%20think%20that%20it%20has%20something%20to%20do%20with%20providing%20the%20Office%20Graph%20with%20some%20data%2C%20but%20it%20could%20be%20something%20completely%20different!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Elena Nakhmanson
Occasional Contributor

Hello! We desperately need help in determining where thousands of NDR emails are coming from. This is Exchange Online only, not a hybrid deployment. 

About a month ago all mailboxes on one of the domains started receiving NDR emails with a subject similart to this: "Undeliverable: GraphTransactionItem:gti gti.TransactionId:8ab6ade9-1783-4d96-xxxx-b7a2b1df83fb gti.Name:UpdateSecondaryShallowCopy”. The transaction names sometimes are different, and so far we got emails with 4 types of Graph transactions:

• PropagateActionToSubscribers
• UpdateSecondaryShallowCopy
• DeleteSecondaryShallowCopy
• PublicRelationshipNodePropagation.

 

Microsoft Support engineers have no idea what is going on and how to resolve this issue, and our users are getting very impatient since they all are receiving thousands of NDR emails per week.

 

We tried to create transport rules to stop those emails but somehow they have no effect, and so does the NDR backscatter setting.

 

All emails are sent from Microsoft Outlook
<MicrosoftExchange329e71ec88ae4615bbc36ab6ce99999e@domainname.onmicrosoft.com> and all users on that domain receive them. There are also multiple addresses similar to this SPO_Arbitration_d91eee03-1846-9999-ab71-8b51cdb7f4df@domainname.onmicrosoft.com to which the GraphTransactionItem emails are sent but fail to be delivered (#Receive, Fail). This has made me think that it has something to do with arbitration mailboxes. I’m not an Exchange expert, my specialty is SharePoint, so I could only guess. But hopefully this will make sense to someone and this mistery will be solved! :)

 

If this might helps, I can provide a sample of the NDR email.

 

Elena.

8 Replies

Can you post the support incident number? This might help some of the Exchange engineers look into the problem.

 

It certainly seems like something odd is happening somewhere along the line... The name "graph transaction item" might make you think that it has something to do with providing the Office Graph with some data, but it could be something completely different!

Our open support ticket # is 617010594021142. There's also this thread addressing the same issue, but no solution so far. 

I just had an email also go out with GraphTransactionItem in the subject. No body. It was sent from my email address, though, and that is strange. We only saw this one, I guess we'll hold off on a ticket unless we see a second?

One of my users is reporting this today. I can pull the message in the search center, no info in it at all, and just the weird subject line. Users think they are being spoofed.

I just had a few more of these this week coming from my email address. I have no clue what these are. 

I had an email go out to some of my colleagues with the subject GraphTransactionItem:gti gti.TransactionId:b724c242-5606-41b5-8666-b5b0ce9c78e6 gti.Name:PropagateItemUpdate

 

I just want to know what is this, this email was not in my sent items.

Same for me. I made a ticket with Microsoft, and they ultimately said, "It came from you, it's your problem". They still come through every once in awhile. Mine sends to like 7 people or so, and it's always the same people. Don't know what the correlation is though.