ML
    • Register
    • Login
    • Search
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups

    Office 365 NDR for strange email address.

    IT Discussion
    office 365 email
    6
    22
    2003
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Dashrender
      Dashrender last edited by

      How about the message you think might be triggering this?

      Does a scan of his email show this address in anything in his account?

      Romo 1 Reply Last reply Reply Quote 0
      • Romo
        Romo @Dashrender last edited by

        @Dashrender No, incoming email is regular email no traces of this [email protected] address on incoming mail.

        1 Reply Last reply Reply Quote 0
        • Obsolesce
          Obsolesce @Romo last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • Obsolesce
            Obsolesce last edited by

            You can also check the audit logs in O365 to confirm successful logins not from him.

            1 Reply Last reply Reply Quote 0
            • Obsolesce
              Obsolesce last edited by

              Oh just seen they were caused by an auto reply. Just disable auto replies to that domain and g2g.

              Romo Dashrender 2 Replies Last reply Reply Quote 0
              • Obsolesce
                Obsolesce @Romo last edited by

                @Romo said in Office 365 NDR for strange email address.:

                Does anyone have an idea of what other things to check to avoid this happening?

                Have him log into OWA and look for auto replies or rules set up.

                1 Reply Last reply Reply Quote 0
                • Obsolesce
                  Obsolesce last edited by

                  There could also be rules set up in O365.

                  1 Reply Last reply Reply Quote 0
                  • F
                    flaxking last edited by

                    I'm pretty sure there is an NDR Backscatter setting in spam rules

                    1 Reply Last reply Reply Quote 0
                    • Romo
                      Romo @Obsolesce last edited by

                      @Obsolesce said in Office 365 NDR for strange email address.:

                      Oh just seen they were caused by an auto reply. Just disable auto replies to that domain and g2g.

                      Not sure what is causing it yet really, I cant seem to find any autoreply or rule enabled.

                      1 Reply Last reply Reply Quote 0
                      • Dashrender
                        Dashrender @Obsolesce last edited by

                        @Obsolesce said in Office 365 NDR for strange email address.:

                        Oh just seen they were caused by an auto reply. Just disable auto replies to that domain and g2g.

                        Wouldn't an auto-reply mean that an email has to come in with a reply address of the one in question?

                        Obsolesce 1 Reply Last reply Reply Quote 0
                        • Obsolesce
                          Obsolesce @Dashrender last edited by Obsolesce

                          @Dashrender said in Office 365 NDR for strange email address.:

                          @Obsolesce said in Office 365 NDR for strange email address.:

                          Oh just seen they were caused by an auto reply. Just disable auto replies to that domain and g2g.

                          Wouldn't an auto-reply mean that an email has to come in with a reply address of the one in question?

                          To me, it looks like a spam email is being sent in, and from what OP said, the user may have something set up that is auto-replying to the spam email, which has a reply address consisting of a non-existent domain, which is causing the NDR.

                          Dashrender Romo 2 Replies Last reply Reply Quote 0
                          • Dashrender
                            Dashrender @Obsolesce last edited by

                            @Obsolesce said in Office 365 NDR for strange email address.:

                            @Dashrender said in Office 365 NDR for strange email address.:

                            @Obsolesce said in Office 365 NDR for strange email address.:

                            Oh just seen they were caused by an auto reply. Just disable auto replies to that domain and g2g.

                            Wouldn't an auto-reply mean that an email has to come in with a reply address of the one in question?

                            To me, it looks like a spam email is being sent in, and from what OP said, the user may have something set up that is auto-replying to the spam email, which has a reply address consisting of a non-existent domain, which is causing the NDR.

                            Right - but I inquired earlier if they had found an actual email with the invalid email address in it? and the answer was - no, they found no email with the bad email address in it.

                            1 Reply Last reply Reply Quote 0
                            • Romo
                              Romo @Obsolesce last edited by

                              @Obsolesce Found the client side rules that were set to forward to that address, thanks

                              Dashrender 1 Reply Last reply Reply Quote 0
                              • Dashrender
                                Dashrender @Romo last edited by

                                @Romo said in Office 365 NDR for strange email address.:

                                @Obsolesce Found the client side rules that were set to forward to that address, thanks

                                What client? something on mobile?

                                1 Reply Last reply Reply Quote 0
                                • Romo
                                  Romo last edited by

                                  @Dashrender said in Office 365 NDR for strange email address.:

                                  @Romo said in Office 365 NDR for strange email address.:

                                  @Obsolesce Found the client side rules that were set to forward to that address, thanks

                                  What client? something on mobile?

                                  Rules were set on OWA, targetting specific keywords on emails that was why not all emails where trying to get forwarded. Account was indeed compromised.

                                  1 Reply Last reply Reply Quote 1
                                  • Obsolesce
                                    Obsolesce last edited by

                                    Azure AD > Monitoring > Sign-ins: to track unauthorized access to accounts. There's no telling what all they did, so it may be best to back up the data and recreate the account... and of course enable 2FA/MFA on ALL accounts.

                                    wrx7m 1 Reply Last reply Reply Quote 2
                                    • wrx7m
                                      wrx7m @Obsolesce last edited by

                                      @Obsolesce said in Office 365 NDR for strange email address.:

                                      Azure AD > Monitoring > Sign-ins: to track unauthorized access to accounts. There's no telling what all they did, so it may be best to back up the data and recreate the account... and of course enable 2FA/MFA on ALL accounts.

                                      This is a good idea. You can also set alerts to be notified if forwarding rules are created like the ones you discovered.

                                      1 Reply Last reply Reply Quote 0
                                      • A
                                        anamanp @Romo last edited by

                                        @Romo Can you please tell me if this was resolved?

                                        Dashrender 1 Reply Last reply Reply Quote 0
                                        • Dashrender
                                          Dashrender @anamanp last edited by

                                          @anamanp said in Office 365 NDR for strange email address.:

                                          @Romo Can you please tell me if this was resolved?

                                          Yes, his reply with the solution was three above your post.

                                          Rules set on OWA to keyword autoforward. The account was compromised.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post