We have received a lot of alerts coming from O365 that this email address sender:[.]com is sending email with malware content, by investigating the alerts, we can see all the originating IPs are coming from Microsoft, only one IP is not registered as permitted sender but it is still a Microsoft IP. are you aware of a similar issue? 


It's a known issue, and something Microsoft has fixed since. You can get more info from the SHD, incident EX189242.

