Skip to content
DnsLister Forum

Where domain hunters compare notes

Anyone else seeing Defender impersonation protection miss obvious display name spoofs lately?

Running Business Premium across several clients, protected senders configured, quarantine as the action, and it's been reliable for months/years. In the past few days two separate tenants let through obvious display name spoofs of protected users, exact name match, one of them loaded with red flags too (urgent priority, a reply to address on a completely different domain).

Raw headers on both show SCL 1, SFV NSPM, CAT NONE, so the messages were scanned, not skipped, they simply aren't tripping the impersonation classifier anymore despite matches that used to get caught every time.

Anyone else noticing a dip in impersonation detection reliability the last week or two?

submitted by /u/typecookieyouidiot to r/sysadmin
[link] [comments]

Source: r/sysadmin · by /u/typecookieyouidiot

Leave a Reply

Your email address will not be published. Required fields are marked *