Link to home
Start Free TrialLog in
Avatar of Ivan Keleher
Ivan KeleherFlag for Australia

asked on

Exchange 2010 - Spoofing of Internal Email Address Inbound (Accepted Domains)

I have been battling with trying to mitigate inbound phishing emails to our staff. The email FROM header address is that of valid staff to other staff requesting information with a REPLY-TO the fraudster.

I have previously stopped these by enabling SENDER ID rejections on the Exchange 2010 Edge servers.

Unfortunately this prevents valid emails coming in from the internet where organisations neglect to add their SMTP servers to SPF records.

Is there a way to specifically block these emails for our Accepted Domains? Our own SPF records cover all SMTP servers internally and EDM.


Thank you.
SOLUTION
Avatar of Ivan
Ivan
Flag of Serbia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
if you follow the above method, then no internet email with your domain will arrive to your systems that could potential block legit email.

I have solved this by using 3rd party cloud services like Mimecast and they have capability to inspect mail from and envelope header, further, they can whitelist the IP address that validate such issues.

by doing others, you probably swapping one problem with anothers.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Ivan Keleher

ASKER

Removing ms-exch-smtp-accept-authoritative-domain-sender certainly fixes the situation however we use third-party systems such as MailChimp for marketing emails.

When they are delivered to staff email addresses they are blocked, what would be the best way around this?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Jian emails are sent using the MailChimp servers obviously and those emails are delivered to MX servers.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Not helpful Jian, anyone else?
why not? since your public receive connector are receiving internet email address and exchange server is directly on MX..
Anyway, I leave it to others to chip in their thoughts.
Your solution is not clear enough. Little effort has been put into explaining each step.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial