Link to home
Create AccountLog in
Avatar of Miffanwee
Miffanwee

asked on

Exchange 2013 Stop Spoof Emails from Internal addresses

New migration from Exchange 2010 to Exchange 2013 latest patch.
Symantec Mail Security for Exchange (latest version).

Internal users receiving small amounts of phishing emails from spoofed domain email address.
e.g. user1@microsoft.co.uk recieves email from user2@microsoft.com claiming to be internal user.
If you click reply then the reply address is obviously a different email domain account (malicious user).

This is a single installation of Exchange, internet facing.

In an earlier post Simon Butler suggested that this installation is "fine"....and also quotes...

"Sender ID etc is no good unless you have your own domain setup correctly.
You need to put in SPF records in to the DNS. If your internal DNS domain name matches your external then you will also need SPF records on your internal DNS. "

Please can anyone explain this further?

Is there anywhere written that explains exactly how to stop this behavior in Exchange 2013?

Also I noticed that in my Exchange Admin Centre, under "protection" section  I cannot see "antispam" feature installed, only "MALWARE feature".
In Exchange 2010 Antispam settings were setup correctly, but I cant find them in Exchange 2013.

I should note that these phishing emails are going into Outlook client "junk" folder, but still I would like to be more protected.
ASKER CERTIFIED SOLUTION
Avatar of Vincent Burton
Vincent Burton

Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Miffanwee
Miffanwee

ASKER

woo, thanks.
I will have a read through that lot!
Built in 2013 Antispam? I cannot find it in my installation.
aha, i need to install using a script!
Microsoft Exchange Server 2013 customers are automatically provided with anti-spam and anti-malware protection to get in detailed please check this: https://technet.microsoft.com/en-us/library/jj150481%28v=exchg.150%29.aspx
Why on earth has Microsoft turned this AntiSpam stuff into Poweshell interface???
Hi Vincent,
Many thanks for your advice.
Could you explain the " block your own domain with sender filtering:" bit?
That's a bit confusing.
Many thanks for help on this matter