May 12 2023 08:06 AM
The following MS Learn page recognises GTUBE as a test resource to provoke a spam detection from Exchange Online. It's in the last section:
However, if I send from Live mail to our tenancy, I receive an NDR with error 550 5.7.520 “Message blocked because it contains content identified as spam (AS 4810)”. It looks as if the bounce was from EOP rather than Live / consumer Outlook.com blocking my mail on "exit". Yes, the GTUBE string is correctly recognised and blocked but there is absolutely nothing in Threat Explorer to show that a spam was blocked or even attempted. It is as if the message had bounced off of EOP edge protection.
If I send the same string on an intra-org basis, it is delivered!
As a method of testing if a particular anti-spam policy is engaging, it's a complete flop and I would welcome any suggestions on how best to discover that. Threat Explorer doesn't show which policy acted, though it does show the detection technology if you wait for a real spam to come along.
May 12 2023 12:55 PM
SolutionMay 15 2023 07:14 AM