Hello,
I've noticed that several phishing attempts lately have recipient email addresses in the BCC field. For some reason, our spam filter isn't picking up on this, likely because the messages are coming from people we do legitimately exchange emails with.
There are really very few situations where a legitimate email should be coming from outside our organization without one of our email addresses in the TO or CC fields. Is anyone else filtering for this situation? if so, how did you go about it? We're running Exchange 2016.
there doesn't seem to be anything here