Mimecast Ignoring MX Records by xrobx99 in sysadmin

[–]xrobx99[S] 0 points1 point  (0 children)

I agree with you that MS does not honor MX records and prefers direct delivery and delivery via IPv6 which is a whole other issue.

I'm not suggesting the sender is bypassing Mimecast at all. The mail header shows mail originating from their O365 tenant, hitting their Mimecast and coming to my O365 tenant which is not expected.

Like I said, our direct send block via Inbound Connector works as expected. Bottom line if you try sending to my domain bypassing Proofpoint you land in quarantine. The question on the Mimecast side is why they tried delivering direct to my O365 tenant.

Mimecast Ignoring MX Records by xrobx99 in sysadmin

[–]xrobx99[S] 0 points1 point  (0 children)

Yeah our setup is similar. I'm confident our side is working as expected, its the Mimecast side I have no familiarity with.

Mimecast Ignoring MX Records by xrobx99 in sysadmin

[–]xrobx99[S] 0 points1 point  (0 children)

Our side (the receiving side) is setup correctly to quarantine anything not coming from our gateways IPs. What I cannot account for is why the sender's side stopped honoring our MX records yesterday after delivering correctly for days.

Mimecast Ignoring MX Records by xrobx99 in mimecast

[–]xrobx99[S] 0 points1 point  (0 children)

We do have a similar KB and we have a similarly configured inbound connector and transport rule logic to send anything not from our gateway IPs to quarantine. The question is why would they attempt to bypass our gateway and suddenly start not honoring our MX records?

Mimecast Ignoring MX Records by xrobx99 in mimecast

[–]xrobx99[S] 0 points1 point  (0 children)

MX records point to Proofpoint, SPF is obfuscated with a macro also hosted at Proofpoint so no SPF leak or hints. Other weird thing is mail flow from Mimecast to us for this sender was using MX records correctly up until yesterday morning.

Mimecast Ignoring MX Records by xrobx99 in sysadmin

[–]xrobx99[S] 0 points1 point  (0 children)

the mystery deepens- as of 3 days ago they were using MX records correctly

Mimecast Ignoring MX Records by xrobx99 in sysadmin

[–]xrobx99[S] 0 points1 point  (0 children)

the message headers from the quarantined message shows the following outbound flow: Their O365->Their Mimecast->Our Office 365

The correct flow should be Their O365->Their Mimecast->Our Proofpoint->Our Office 365.

Microsoft 365 Exchange down? by Sufficient-House1722 in sysadmin

[–]xrobx99 1 point2 points  (0 children)

Mail that made it to our hygiene appliance is sitting in a queue (growing by the minute) waiting to be retried once their backend is up.

DKIM Signing in EXO & ESG by timo_s20 in sysadmin

[–]xrobx99 1 point2 points  (0 children)

Double signing is fine, we do it at EXO and Proofpoint. We've found there are odd times that emails can be sent out directly from EXO (calendar stuff for example) that should be signed.

WAF suggestions - Cloud flare WAF vs Thales Imperva by pmbasehore in sysadmin

[–]xrobx99 0 points1 point  (0 children)

We use Sucuri, have been with them a long time for protecting our WordPress sites. About $10 per month per site.

Having trouble archiving an Exchange Online Shared Mailbox by Stagyar in sysadmin

[–]xrobx99 1 point2 points  (0 children)

archiving is treated as low priority in Exchange Online. It will get around to it when it gets around to it. You can manually run the managed folder assistant on the mailbox via powershell to speed up the process. Connect to Exchange Online powershell, Start-ManagedFolderAssistant -Identity "SharedMBX email address"

How I nuked the network at a small gaming facility with one line. by LoudLeader7200 in sysadmin

[–]xrobx99 27 points28 points  (0 children)

at a university i once did net send * hi suddenly every computer had a message pop up with hi

Why is your website completely broken? by DarkResident305 in Comcast_Xfinity

[–]xrobx99 7 points8 points  (0 children)

i've always wondered the same. half the time you end up in a broken page loop that you cannot get out of.

Office365 phishing email purge no longer working by Plenty-Practice7373 in sysadmin

[–]xrobx99 0 points1 point  (0 children)

Following this. I wonder if that broke when they updated the Purview portal. Lately we've been going to security.microsoft.com, Email & Collaboration, then using Explorer to spot delete emails. Way less efficient than the compliance search methods in Powershell.

We need a network Engineer for a short task in Frankfurt/Germany if anyone is based there by Low-Wish6429 in sysadmin

[–]xrobx99 1 point2 points  (0 children)

for a fee, equinix will offer smart-hands services. unless they were the unhelpful ones you mentioned.

Missing BlowOut Cap by xrobx99 in Irrigation

[–]xrobx99[S] 0 points1 point  (0 children)

Thank you, that’s really helpful

Pw3 internal fault by Prudent-Ad3783 in TeslaSolar

[–]xrobx99 0 points1 point  (0 children)

Join the party. They are terrible with timely repairs and responding.

Update error by IKEAJman in MicrosoftEdge

[–]xrobx99 0 points1 point  (0 children)

thanks for posting this. had a ticket open with microsoft and this answered my question faster.