How to prevent internal email spoofing in my Exchange organization?

Majid 26 Reputation points
2020-07-31T12:13:21.55+00:00

Recently, some employees of my organization received couple of phishing email from internal email addresses. I found out that spoofed messages may originate from someone or somewhere other than the actual address. However, they thought that they had to click on the link which hacker sent since the sender is valid. However, I could see any solution to prevent these dangerous emails. Please let me know if I should configure something in Exchange Server to block this kind of threat.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,386 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 142.7K Reputation points MVP
    2020-07-31T12:19:52.41+00:00

    What are you using for anti-spam? Thats where this should really be handled. Third party or 365/EOP is much better than trying to do this with Exchange or using the built-in anti-spam features.

    Otherwise, I would create a transport rule and block the messages that way. Be sure to exclude any IPs of sending servers that may be allowed to send as your domain..https://support.knowbe4.com/hc/en-us/articles/212679977-Domain-Spoof-Prevention-in-Exchange-2013-2016-Office-365

    You should also have a valid SPF record at minimum (DKIM and DMARC even better) and you can checking for that with your anti-spam solution.


1 additional answer

Sort by: Most helpful
  1. Adam (CodeTwo) 241 Reputation points
    2020-07-31T12:53:13.11+00:00

    See if this article helps: https://www.codetwo.com/admins-blog/how-to-prevent-internal-email-spoofing-in-exchange/. It shows how to prevent email spoofing in an Exchange organization.

    0 comments No comments