The Email Came From Me
The message looked legitimate. It came from the same address it was sent to. But there was no breach, no suspicious login and no mailbox compromise. It was identity spoofing at protocol level — and a reminder that trust without verification is exactly what attackers exploit.
This is why stronger identity and access enforcement matters beyond sign-ins alone. Email trust is part of identity too.
Briefing summary
The email appeared to come from the same address it was sent to. But no account had been breached. The real issue was spoofing — a forged identity being trusted because email authentication and enforcement were not strong enough.
What you'll learn on this page
What happened
What we checked before panicking
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
let TargetUser = "user@yourdomain.com"; let RecentSignins = SigninLogs | where UserPrincipalName =~ TargetUser | where TimeGenerated > ago(7d) | project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, ResultType, Location = strcat(tostring(LocationDetails.city), ", ", tostring(LocationDetails.countryOrRegion)); let InboxRuleActivity = OfficeActivity | where UserId =~ TargetUser | where Operation in ("New-InboxRule", "Set-InboxRule", "Set-Mailbox") | project TimeGenerated, UserId, Operation, ClientIP; let MailboxSuspicion = EmailEvents | where RecipientEmailAddress =~ TargetUser | where SenderFromAddress =~ TargetUser | project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, AuthenticationDetails, ThreatTypes, UrlCount; RecentSignins | union InboxRuleActivity | order by TimeGenerated desc
Why this works
The controls that actually matter
Email spoofing investigation workflow
Related investigations
Understand how SPF, DKIM and DMARC actually aligned — and why an email may still have been delivered. Read more →
SenderFrom and SenderMailFrom don’t always match.
Understand the difference →
Continue with practical KQL evidence
Learn the KQL behind this case
Frequently asked questions
Yes. Email sender fields can be spoofed. A message can appear to come from your own address even when your mailbox was not breached, especially if email authentication and DMARC enforcement are weak.
No. You should check sign-ins, mailbox rules and mailbox activity first. If those are clean, the issue may be sender spoofing rather than account compromise.
EmailEvents, AuthenticationDetails, DeliveryAction, NetworkMessageId, UrlClickEvents, SigninLogs and OfficeActivity can help confirm whether the message was spoofed, delivered, clicked or connected to account activity.
SPF defines authorised senders, DKIM signs messages, and DMARC tells receiving systems what to do when sender identity does not align. DMARC enforcement is what turns authentication into action.
Final thought
If your environment has Microsoft security tools but your mail identity controls are still weak, the next step is closing that trust gap properly. 👉 Review Microsoft security operations and identity protection
Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD