cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
354
Views
0
Helpful
1
Replies

1of 3 Office 365 email domains falsely tagged as SPAM

Iain Last
Level 1
Level 1

Immediately following a mail flow incident in Exchange Online on Tuesday, approx. 95% of emails sent internally between employees in a single domain are now being tagged as SPAM. The remediation for SPAM is set to "move to JUNK" in Cisco Secure Email Threat Defense and so the outcome has been disastrous. All Inbound (internal) and sent items are being deposited in the user's JUNK folder. MS support has been investigating with little joy and I discovered by turning off the remediation as a temporary measure has mitigated the issue for now.

Category, Spam. Technique
FREQUENT SENDER FOR RECIPIENT
Sender name@domain.co.uk communicates frequently with recipient name@domain.co.uk
FREQUENT SENDER FOR RECIPIENT'S DOMAIN
Sender name@domain.co.uk communicates frequently with recipient domain @domain.co.uk

My question is, which service is responsible for the classification of the email. Exchange Online or CSE? and how can I remove this false-positive classification for the affected domain?

Many thanks.

1 Reply 1

Nasreen Al Haddad
Cisco Employee
Cisco Employee

Please open a TAC case to have this escalated  as Efficacy problem and solve the False positive