{"id":7891,"date":"2024-05-15T22:54:25","date_gmt":"2024-05-15T22:54:25","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=7891"},"modified":"2024-05-17T08:50:58","modified_gmt":"2024-05-17T08:50:58","slug":"message-from-internal-domain-made-it-through-antiphish-protection-in-defender-due-to-header-from","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/message-from-internal-domain-made-it-through-antiphish-protection-in-defender-due-to-header-from","title":{"rendered":"Message from Internal Domain made it through AntiPhish Protection in Defender due to Header From"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p><strong>Mail From&nbsp;(<\/strong>envelope-from &lt;<a href=\"mailto:hellowon@gator4212.hostgator.com\">@gator4212.hostgator.com<\/a>&gt;)&nbsp;( RFC5321.MailFrom ) <\/p>\n\n\n\n<p><strong>Header From&nbsp;<\/strong>From: CEO Name &lt;ceo@domain.com&gt;( RFC5322.From ) <\/p>\n\n\n\n<p>Reply-To: CEO Name &nbsp;&lt;edkl@gmail.com&gt;<\/p>\n\n\n\n<p><strong>SPF and DKIM only apply on Mail From ( Not header from ) so it passed through DKIM and SPF Protection<\/strong><\/p>\n\n\n\n<p>Authentication-Results: spf=pass (sender IP is 44.202.169.33)<\/p>\n\n\n\n<p>&nbsp;smtp.mailfrom=gator4212.hostgator.com; dkim=pass (signature was verified)<\/p>\n\n\n\n<p>&nbsp;header.d=hellowonder.co;dmarc=fail action=none<\/p>\n\n\n\n<p>&nbsp;header.from=domain.com;compauth=fail reason=601<\/p>\n\n\n\n<p><strong>DMARC<\/strong>:&nbsp;<a href=\"https:\/\/aus01.safelinks.protection.outlook.com\/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fdefender-office-365%2Femail-authentication-dmarc-configure&amp;data=05%7C02%7CParis.Wells%40pa.com.au%7C83203772992d416af84e08dc74c6772f%7Ce417d5cce5d84cadb2cdc5ef82dea0a0%7C0%7C0%7C638513642958144080%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=RKe%2BbQ2hzXeNBmLI8vtxexMUoKukndHHH0bLt6Az6p0%3D&amp;reserved=0\">Set up DMARC to validate the From address domain for senders in Microsoft 365<\/a>, DMARC&nbsp;<strong>uses SPF and DKIM to check for alignment between the domains in the MAIL FROM and From addresses<\/strong>. DMARC also specifies the action that the destination email system should take on messages that fail DMARC, and identifies where to send DMARC results (both pass and fail).<\/p>\n\n\n\n<p><\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"1\">\n<li>Look to enable Dmarc in Fail Mode ( Not None ) <\/li>\n\n\n\n<li>We have increased the Anti Phishing Threshold in Defender from 2 to 3<\/li>\n\n\n\n<li>Make sure all important accounts are added to Impersonation Users in Defender Anti Phish Policy<\/li>\n\n\n\n<li>We have created a Rule in Exchange to Delete any emails with\u00a0<strong>Header From<\/strong>\u00a0CEO outside the organisation\u00a0 ( Can also try &#8216;Authentication-Results&#8217; header contains &#8221;compauth=fail reason=601&#8221; ) <\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-4.png\"><img loading=\"lazy\" decoding=\"async\" width=\"525\" height=\"715\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-4.png\" alt=\"\" class=\"wp-image-7892 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-4.png 525w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-4-220x300.png 220w\" sizes=\"auto, (max-width: 525px) 100vw, 525px\" \/><\/a><\/figure>\n\n\n\n<ol class=\"wp-block-list\" start=\"1\">\n<li>We have created an Audit Rule in exchange with&nbsp;<strong>Header From&nbsp;<\/strong>emails domain.com so we can whitelist any legitimate emails before we turn this rule to delete<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-6.png\"><img loading=\"lazy\" decoding=\"async\" width=\"558\" height=\"814\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-6.png\" alt=\"\" class=\"wp-image-7894 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-6.png 558w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-6-206x300.png 206w\" sizes=\"auto, (max-width: 558px) 100vw, 558px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Mail From&nbsp;(envelope-from &lt;@gator4212.hostgator.com&gt;)&nbsp;( RFC5321.MailFrom ) Header From&nbsp;From: CEO Name &lt;ceo@domain.com&gt;( RFC5322.From ) Reply-To: CEO Name &nbsp;&lt;edkl@gmail.com&gt; SPF and DKIM only apply on Mail From ( Not header [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7891","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=7891"}],"version-history":[{"count":3,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7891\/revisions"}],"predecessor-version":[{"id":7903,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7891\/revisions\/7903"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=7891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=7891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=7891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}