Using Office 365 or EOP to protect your email and worried about spoofed emails? Then try this cmdlet in Remote PowerShell for EOP:
PS C:\Users\brian.reid> Get-SpoofMailReport
Date Event Type Direction Domain Action Spoofed Sender True Sender Sender IP
—- ———- ——— —— —— ————– ———– ———
14/04/2016 00:00:00 SpoofMail Inbound GoodMail no-reply@domain.com mandrillapp.com 198.2.186.0/24
18/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com mimecast.com 1.130.217…
07/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com 1.130.217…
14/04/2016 00:00:00 SpoofMail Inbound GoodMail no-reply@domain.com someapp.com 198.2.179.0/24
08/04/2016 00:00:00 SpoofMail Inbound GoodMail paul@domain.com mimecast.com 1.130.217…
13/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com 1.130.217…
14/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com 1.130.217…
07/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com 1.130.217…
07/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com mimecast.com 91.220.42.0/24
07/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com 91.220.42.0/24
07/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 91.220.42.0/24
13/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 1.130.217…
18/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com 1.130.217…
18/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com mimecast.com 91.220.42.0/24
07/04/2016 00:00:00 SpoofMail Inbound GoodMail paul@domain.com mimecast.com 91.220.42.0/24
07/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com mimecast.com 1.130.217…
07/04/2016 00:00:00 SpoofMail Inbound GoodMail paul@domain.com 1.130.217…
08/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 1.130.217…
08/04/2016 00:00:00 SpoofMail Inbound GoodMail paul@domain.com 91.220.42.0/24
08/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 91.220.42.0/24
08/04/2016 00:00:00 SpoofMail Inbound GoodMail paul@domain.com mimecast.com 91.220.42.0/24
10/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com 1.130.217…
11/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com 1.130.217…
11/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 91.220.42.0/24
13/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@domain.co.uk 1.130.217…
14/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 1.130.217…
18/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 1.130.217…
07/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 1.130.217…
07/04/2016 00:00:00 SpoofMail Inbound GoodMail paul@domain.com 91.220.42.0/24
07/04/2016 00:00:00 SpoofMail Inbound GoodMail no-reply@domain.com mandrillapp.com 198.2.132.0/24
08/04/2016 00:00:00 SpoofMail Inbound GoodMail andrew@domain.com mimecast.com 91.220.42.0/24
08/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com mimecast.com 91.220.42.0/24
08/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com 91.220.42.0/24
08/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.co.uk mimecast.com 1.130.217…
10/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 1.130.217…
10/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@other.com 1.130.217…
11/04/2016 00:00:00 SpoofMail Inbound CaughtAsSpam wordpress@other.com host-h.net 129.232.144…
11/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@domain.co.uk mimecast.com 91.220.42.0/24
13/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@domain.co.uk mimecast.com 91.220.42.0/24
13/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@other.com host-h.net 197.189.237…
13/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 91.220.42.0/24
13/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@other.com 91.220.42.0/24
14/04/2016 00:00:00 SpoofMail Inbound GoodMail no-reply@domain.com mandrillapp.com 198.2.187.0/24
14/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.co.uk 1.130.217…
14/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@other.com host-h.net 197.189.237…
14/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 91.220.42.0/24
14/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@other.com 91.220.42.0/24
14/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.co.uk mimecast.com 1.130.217…
17/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@domain.co.uk mimecast.com 1.130.217…
17/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com 1.130.217…
17/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 1.130.217…
17/04/2016 00:00:00 SpoofMail Inbound GoodMail wordpress@domain.co.uk mimecast.com 91.220.42.0/24
17/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 91.220.42.0/24
18/04/2016 00:00:00 SpoofMail Inbound GoodMail support@domain.com 91.220.42.0/24
18/04/2016 00:00:00 SpoofMail Inbound GoodMail postmaster@domain.com mimecast.com 91.220.42.0/24
Thats the output I get from running this on the afternoon of April 20th (UK style dates for the American readers of this blog)! Notice a few things (its been somewhat redacted to remove private into), but the spam filter provider in front of EOP in this tenant is seen as spoofing postmaster emails and there are some from mandrillapp.com in a similar vein. Both of these companies send email on our behalf, so I expect to see them here – so nothing to see here for these. How about the others? One is a hosting company, probably hosting WordPress instances and so these are probably alerts of some kind from a web hoster to us, so again I think for us nothing here.
What do you get – is it more interesting for you?
Then finally, how about getting the results in date order, as they are not by default: Get-SpoofMailReport | sort -Property Date
Leave a Reply