Blog Post

Exchange Team Blog
2 MIN READ

Enhancements to the Outbound Messages in Transit Security Report

The_Exchange_Team's avatar
Aug 05, 2024

Today, we are excited to announce enhancements to the Outbound Messages in Transit Security report that help you track and optimize the security of your outbound email. 

To help you identify and reduce the number of emails that are sent in plain text, we have added two new elements to the outbound messages in transit report: a new field in the Messages Sent section, and a new page called Recipient Domains Not Supporting TLS. 

We have split the ‘Opportunistic TLS’ category in the Messages Sent section of the mail flow report into 2 categories: ‘TLS’ and ‘No-TLS’ so there are now 5 security categories.  

With the addition of Recipient Domains Not Supporting TLS, the Outbound Messages in Transit Security report now has 3 views: 

  1. The Messages Blocked section compiles data for tenant admins on any SMTP DANE with DNSSEC or MTA-STS issues encountered during attempts to send messages to domains that use these security protocols. 
  2. The Messages Sent section provides time-series data for emails secured by SMTP DANE with DNSSEC, MTA-STS, Both SMTP DANE with DNSSEC and MTA-STS, TLS, or No-TLS. 
  3. Recipient Domains Not Supporting TLS provides time series data for messages that were sent to a destination domain unencrypted (in plain text) because the destination didn't support TLS. Exchange Online always attempts to send using TLS, but if the destination server or domain doesn’t support it then the default behavior is to send the email. 

How to access the new features 

These updates are available right now! To access the report, go to the Exchange admin center, and then click Reports > Mail flow. Once the page loads, select Outbound Messages in Transit Security report. 

To learn more about the report, visit Outbound messages in Transit Security report in the Exchange Admin Center for Exchange Online | Microsoft Learn 

How to use the data to improve your email security 

The data in the Outbound Messages in Transit Security report can help you monitor and improve email security in several ways. Here are some examples of how you can use the data: 

  • If you see a high number of emails sent in plain text to an organization, you can contact the receiving organization and ask them to enable TLS on their email servers. 
  • If you see a sudden spike in the number of emails experiencing SMTP DANE with DNSSEC or MTA-STS failures, you can alert the destination organization, so they take corrective measures. 
  • If you see a consistent pattern of emails being blocked or sent in plain text to certain domains, you can consider alternative ways of communicating with those domains. For example, you can use secure file sharing services or secure web portals to exchange information with those domains. 

We hope that you will find these enhancements helpful. If you have any feedback or suggestions, please let us know in the comments below!

Microsoft 365 Messaging Team
(Formerly Exchange Online Transport Team)

Published Aug 05, 2024
Version 1.0
  • Hi all,

    it would be great to have a report of INBOUND messages that used the protocols MTA-STS and/or SMTP DANE with DNSSEC. With only outbound report we don't know if the protocols are configured properly in our tenant and our domain.

    Many thanks.

    Raffaele

  • Thanks for the comment RaffaColavecchi-MVP! We will release (In Preview) an Inbound SMTP DANE with DNSSEC and MTA-STS EAC report around the end of this month. It will be powered by TLS RPT reports that we receive from external senders, so the data will not be comprehensive, but it should be very helpful.

     

    In the meantime, here are some ways to confirm the inbound configuration is working as expected: 

    1. Confirm your Inbound SMTP DANE with DNSSEC configuration with the Microsoft Remote Connectivity Analyzer: Test Input

    2. Set up a second tenant and send emails between tenants these tenants, then check the Outbound Messages in Transit Security Report

  • Tnx IanMcDonald,

    now I'm using solution 2 from my tenant but for customers it's better to wait native inbound reports in their own tenant.

    Many thanks for feedback.

    Raffaele