Running Business Premium across several clients, protected senders configured, quarantine as the action, and it's been reliable for months/years. In the past few days two separate tenants let through obvious display name spoofs of protected users, exact name match, one of them loaded with red flags too (urgent priority, a reply to address on a completely different domain).
Raw headers on both show SCL 1, SFV NSPM, CAT NONE, so the messages were scanned, not skipped, they simply aren't tripping the impersonation classifier anymore despite matches that used to get caught every time.
Anyone else noticing a dip in impersonation detection reliability the last week or two?
submitted by /u/typecookieyouidiot to r/sysadmin
[link] [comments]
Source: r/sysadmin · by /u/typecookieyouidiot