Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


1101

3122 posts

Uber Geek


#259733 18-Oct-2019 09:56
Send private message

Are 365 Exchange's Spam & malwarefilters damn near worthless ?

So MS's filters cant detect when email is spoofing as a MS email ? , ie they didnt block email pretendng to be from MS itself

 

similar to this, so its not uncommon
https://www.bleepingcomputer.com/news/security/beware-of-fake-microsoft-account-unusual-sign-in-activity-emails/

 

 


Create new topic
Dynamic
3867 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2340080 18-Oct-2019 10:13
Send private message

We encourage the use of third party anti-spam systems for our clients to supplement the built-in stuff.  Like Windows Defender, the Microsoft anti-spam stuff is better than nothing, but not by a big margin.





“Don't believe anything you read on the net. Except this. Well, including this, I suppose.” Douglas Adams

 

Referral links to services I use, really like, and may be rewarded if you sign up:
PocketSmith for budgeting and personal finance management.  A great Kiwi company.




dt

dt
1152 posts

Uber Geek
Inactive user


  #2340095 18-Oct-2019 10:32
Send private message

yeah do no solely rely on inbuilt protections, if its not their core business focus it usually does the bare minimum. 

 

even on prem exchange has built in malware and spam detection 

 

I dont believe it will natively drop spoofed emails either, this needs to be configured


Jogre
182 posts

Master Geek


  #2341372 21-Oct-2019 13:56
Send private message

1101:

 

Are 365 Exchange's Spam & malwarefilters damn near worthless ?

So MS's filters cant detect when email is spoofing as a MS email ? , ie they didnt block email pretendng to be from MS itself

 

similar to this, so its not uncommon
https://www.bleepingcomputer.com/news/security/beware-of-fake-microsoft-account-unusual-sign-in-activity-emails/

 

 

 

 

At a baseline, not really. Adding ATP is a solid option for most partners as you have a range of policies (safe links and anti-phishing) you can put in place to protect against this. Unfortunately, most partners just put SPF records in place as a 'least-effort' solution, but that doesn't protect you when someone spins up a trial then you're both using 365 and passing SPF checks.




ANglEAUT
2320 posts

Uber Geek

Trusted
Lifetime subscriber

  #2341486 21-Oct-2019 18:56
Send private message

1101: Are 365 Exchange's Spam & malwarefilters damn near worthless ? ...

 

I think so.





Please keep this GZ community vibrant by contributing in a constructive & respectful manner.


1101

3122 posts

Uber Geek


  #2341681 22-Oct-2019 10:11
Send private message

Jogre:

 

At a baseline, not really. Adding ATP is a solid option for most partners as you have a range of policies (safe links and anti-phishing) you can put in place to protect against this. Unfortunately, most partners just put SPF records in place as a 'least-effort' solution, but that doesn't protect you when someone spins up a trial then you're both using 365 and passing SPF checks.

 

 

MS's filters should be able to block email spoofed to look like Official MS email's
They dont.

Email claims to be from MS => check server IP it came from => block if not from MS's servers
Is that really too hard ?
I mean, its would help to protect MS's 365/exchange  , would help stop 365 stolen passwords being used to sent 10000's of spams from MS's servers

 

 

 

 


Jogre
182 posts

Master Geek


  #2342419 23-Oct-2019 12:37
Send private message

1101:

 

Jogre:

 

At a baseline, not really. Adding ATP is a solid option for most partners as you have a range of policies (safe links and anti-phishing) you can put in place to protect against this. Unfortunately, most partners just put SPF records in place as a 'least-effort' solution, but that doesn't protect you when someone spins up a trial then you're both using 365 and passing SPF checks.

 

 

MS's filters should be able to block email spoofed to look like Official MS email's
They dont.

Email claims to be from MS => check server IP it came from => block if not from MS's servers
Is that really too hard ?
I mean, its would help to protect MS's 365/exchange  , would help stop 365 stolen passwords being used to sent 10000's of spams from MS's servers

 

 

But we use 365 so if we check the server IPs, it'd check out 😅

 

It is a challenge, but we need to balance privacy as well so we can't just check the body of the message for telltales unless there's a link in there that ATP can test out. Anti-phishing policies in ATP check spoofing of the From Headers which would pick this particular phishing attack up. 


1101

3122 posts

Uber Geek


  #2342865 24-Oct-2019 10:29
Send private message

sound like excuses :-)

 

"@accountprotection.microsoft.com"
Spammers using/spoofing that email domain , its been happening for some time
Its common enough that MS's forums are full of questions about it, lots of Tech website mention it

Is it REALLY that hard to , by default, either block or do a basic check on @xxxxx.microsoft.com .
Even some of the worst email hosting services can do better with their spam filters .

 


spammers/hackers pretending to be MS , nothing too serious it seems then.
Have your own (365) customers a/c's potentially compromised , pfft .

 

 

 

 

 

 


1101

3122 posts

Uber Geek


  #2343414 25-Oct-2019 10:36
Send private message

and another one

 

The default 365 spam filter cant detect when noreply@microsoft.com is a spoofed email , trying to steal 365 logins & passwords

 

I guess we just wait till the problem is so bad that MS is shamed into doing something


CYaBro
4583 posts

Uber Geek

ID Verified
Trusted

  #2343486 25-Oct-2019 12:46
Send private message

Microsoft want you to pay for ATP.

 

I use MXGuardDog with some of our O365 tenants and disable the Junk mail filter in O365 completely.
Works great and very cheap at US$0.25 per email address.

 

 





Opinions are my own and not the views of my employer.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.