Spoofing and distribution groups

%3CLINGO-SUB%20id%3D%22lingo-sub-324587%22%20slang%3D%22en-US%22%3ESpoofing%20and%20distribution%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-324587%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20customer%20with%20distribution%20groups%20set%20up%20to%20allow%20external%20emails%20however%20they%20are%20not%20wide%20open%20to%20the%20world.%20They%20are%20limited%20by%20groups%20in%20Office%20365.%20We%20are%20having%20a%20major%20issue%20with%20internal%20users%20being%20spoofed%20and%20Office%20365%20allowing%20the%20email%20to%20go%20into%20the%20distribution%20list%20and%20be%20delivered.%20To%20the%20internal%20people%2C%20ATP%20is%20catching%20the%20spoofs%20and%20sending%20them%20to%20junk.%20The%20external%20people%20are%20all%20getting%20the%20spoofs%20delivered%20to%20them.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20need%20a%20way%20to%20be%20able%20to%20stop%20those%20spoofs%20from%20being%20able%20to%20enter%20the%20distribution%20group%20but%20so%20far%20have%20found%20no%20way%20to%20accomplish%20this.%20Im%20hoping%20someone%20else%20has%20run%20into%20this%20and%20come%20up%20with%20some%20kind%20of%20clever%20workaround.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20run%20into%20this%20or%20have%20any%20ideas%20how%20I%20can%20address%20this%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-324587%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-324986%22%20slang%3D%22en-US%22%3ERe%3A%20Spoofing%20and%20distribution%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-324986%22%20slang%3D%22en-US%22%3E%3CP%3EATP%20is%20catching%20them%20for%20internal%20users%20but%20they%20are%20still%20going%20out%20to%20external%20users.%20What%20I%20would%20like%20to%20do%20is%20stop%20them%20from%20going%20out%20at%20all%20but%20I%20dont%20know%20how%20to%20determine%20these%20emails%20are%20fake%20given%20what%20I%20have%20to%20work%20with%20in%20the%20portal%20for%20rule%20creation.%20They%20appear%20to%20authenticate%20so%20I%20cant%20check%20if%20they%20are%20external%20and%20use%20that.%20Im%20kind%20of%20at%20a%20loss.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20ticket%20open%20with%20Microsoft%20regarding%20this%20but%20no%20one%20has%20reached%20out%20to%20me%20yet.%20The%20last%203%20Office%20365%20tickets%20Ive%20opened%2C%20support%20has%20been%20abysmal%20on%20them%20so%20Im%20not%20really%20expecting%20a%20lot%20on%20MS's%20side.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-324835%22%20slang%3D%22en-US%22%3ERe%3A%20Spoofing%20and%20distribution%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-324835%22%20slang%3D%22en-US%22%3E%3CP%3ESeveral%20options%20to%20explore%20here.%20You%20can%20change%20the%20spam%20policy%20action%20to%20quarantine%20or%20remove%2C%20you%20can%20create%20a%20transport%20rule%20to%20detect%2Freject%20such%20messages%2C%20report%20it%20as%20false%20negative%20and%20work%20with%20support%20to%20identify%20why%20exactly%20this%20is%20happening.%20My%20guess%20would%20be%20that%20the%20messages%20are%20still%20being%20marked%20as%20spam%20but%20some%20setting%20on%20recipient's%20end%20is%20causing%20them%20to%20end%20up%20in%20Inbox%2C%20for%20example%20headers%20being%20stripped%2C%20trusted%20senders%20list%2C%20etc.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I have a customer with distribution groups set up to allow external emails however they are not wide open to the world. They are limited by groups in Office 365. We are having a major issue with internal users being spoofed and Office 365 allowing the email to go into the distribution list and be delivered. To the internal people, ATP is catching the spoofs and sending them to junk. The external people are all getting the spoofs delivered to them.

 

I need a way to be able to stop those spoofs from being able to enter the distribution group but so far have found no way to accomplish this. Im hoping someone else has run into this and come up with some kind of clever workaround.

 

Anyone run into this or have any ideas how I can address this?

2 Replies
Highlighted

Several options to explore here. You can change the spam policy action to quarantine or remove, you can create a transport rule to detect/reject such messages, report it as false negative and work with support to identify why exactly this is happening. My guess would be that the messages are still being marked as spam but some setting on recipient's end is causing them to end up in Inbox, for example headers being stripped, trusted senders list, etc.

Highlighted

ATP is catching them for internal users but they are still going out to external users. What I would like to do is stop them from going out at all but I dont know how to determine these emails are fake given what I have to work with in the portal for rule creation. They appear to authenticate so I cant check if they are external and use that. Im kind of at a loss. 

 

I have a ticket open with Microsoft regarding this but no one has reached out to me yet. The last 3 Office 365 tickets Ive opened, support has been abysmal on them so Im not really expecting a lot on MS's side.