I've got an email for zoom webinars that immediately gets delivered to deleted items. I've checked the transport rules, I've checked the defender actions, threat type is none, I've checked hidden inbox rules, and am returning nothing fruitful. I am seeing an interesting header:
Received: from <EXO_MAILBOX_SERVER> by <EXO_MAILBOX_SERVER> with HTTPS; Received: from <EXO_TRANSPORT_SERVER> by <EXO_MAILBOX_SERVER> with Microsoft SMTP Server; Received: from <EOP_FRONTEND> by <EXO_TRANSPORT_SERVER> via Frontend Transport; Received: from <MAIL_GATEWAY> by <EOP_SERVER> via Frontend Transport; Received: from <SENDER_HOST> by <MAIL_GATEWAY> with ESMTPS; Received: from <APPLICATION_SERVER> by <SENDER_HOST> with HTTP;
Authentication-Results: mx.microsoft.com; spf=softfail; dkim=fail (body hash did not verify); dmarc=fail action=oreject; compauth=none reason=452
Authentication-Results-Original: spf=pass; dkim=pass; dmarc=pass
DKIM-Signature: d=<SENDER_DOMAIN>
Content-Type: multipart/mixed From: "<ORGANIZATION_NAME>" <no-reply@<SENDER_DOMAIN>> To: <RECIPIENT_EMAIL> Subject: Webinar host invited you to be panelist for <WEBINAR_NAME> Reply-To: <REPLYTO_ADDRESS>
Return-Path: <BOUNCE_ADDRESS>
X-MS-Exchange-Organization-MessageDirectionality: Incoming X-MS-Exchange-Organization-SCL: -1
X-MS-Exchange-AtpMessageProperties: SA|SL
X-Forefront-Antispam-Report: CAT:NONE; SCL:-1; SFV:SKN;
X-Microsoft-Antispam-Mailbox-Delivery: dest:D
Message Trace:
Receive Transport rule: "Outside Org Disclaimer"
Transport rule: "Bypass SafeLinks"
Deliver: The message was delivered to the Deleted Items folder.
What's interesting to me is this: X-Forefront-Antispam-Report: CAT:NONE; SCL:-1; SFV:SKN;
X-Microsoft-Antispam-Mailbox-Delivery: dest:D
It's a trusted email based on scl but destination is deleted items from the antispam mailbox delivery.
Source: r/sysadmin · by /u/DesignDifficult4772