Avatar of Garry Shape
Garry Shape
Flag for United States of America asked on

Does Exchange Online not apply spam filter to mailbox forwarded messages?

In Exchange Online, you can set forwarded on a mailbox by opening up its properties from the Exchange Admin Center (Mailbox features > Mail flow > Forwarding Address).

It seems any e-mail forwarded this way isn't being filtered for phishing or spam.

Why is that? Is there a way of getting it to filter just like regular e-mail not being forwarded?
ExchangeMicrosoft 365Email Servers

Avatar of undefined
Last Comment
Garry Shape

8/22/2022 - Mon
Vasil Michev (MVP)

Depends. If they are forwarded internally, they might skip some/most checks.
Garry Shape

ASKER
Hi Vasil -
Yes it's instant but I cannot tell if that's instantly after or before O365 runs their spam/phish detection on them.

forwarding
Vasil Michev (MVP)

Not sure what you mean by "instant", I meant internal as in forwarded to another mailbox within the company. In any case you should look into the message headers and run a message trace.
Your help has saved me hundreds of hours of internet surfing.
fblack61
Garry Shape

ASKER
By instant I mean as soon as a the message lands in O365 via the mx record, Exchange is forwarding it, even if the thing is a complete and total phishing e-mail. If I leave it to also deliver to inbox of the mailbox that's forwarding it, they'll actually quarantine such e-mails. But they won't quarantine it before it forwards however.
SOLUTION
Amit

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Vasil Michev (MVP)

The "instant" part is expected if forwarding is set via the forwardingaddress/forwardingSMTPaddress attribute or a transport rule, basically Exchange intercepts the message before it's delivered and redirects/copies it as needed. If the message is an obvious phish, that shouldnt cause it to bypass any form of scanning though. Do you perhaps have some transport rule that marks "internal" email as safe? Again, check the headers/message trace - it should give you an idea why it wasnt marked.
Garry Shape

ASKER
The e-mail is in O365 Exchange quarantine as  "Phish" yet the e-mail still forwarded out to the external address set for forwarding.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Garry Shape

ASKER
redirect happens first before hitting EOP:

2020-04-07_11-38-52.png2020-04-07_11-38-52.png
ASKER CERTIFIED SOLUTION
Vasil Michev (MVP)

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Garry Shape

ASKER
Thanks I'll report back Microsoft's remarks.
Garry Shape

ASKER
I got with O365 phone support. They said this is working as intended.
It appears they just assume that the recipient e-mail servers will honor their tags they put on the message.
So they're telling me to re-do it as a mailflow rule or something, since clearly redirection bypasses their spam filtering.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck