The Email Came From Me
The message looked legitimate. It came from the same address it was sent to. But there was no breach, no suspicious login and no mailbox compromise. It was identity spoofing at protocol level — and a reminder that trust without verification is exactly what attackers exploit.
This is why stronger identity and access enforcement matters beyond sign-ins alone. Email trust is part of identity too.
Briefing summary
The email appeared to come from the same address it was sent to. But no account had been breached. The real issue was spoofing — a forged identity being trusted because email authentication and enforcement were not strong enough.
What happened
What we checked before panicking
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
let TargetUser = "user@yourdomain.com"; let RecentSignins = SigninLogs | where UserPrincipalName =~ TargetUser | where TimeGenerated > ago(7d) | project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, ResultType, Location = strcat(tostring(LocationDetails.city), ", ", tostring(LocationDetails.countryOrRegion)); let InboxRuleActivity = OfficeActivity | where UserId =~ TargetUser | where Operation in ("New-InboxRule", "Set-InboxRule", "Set-Mailbox") | project TimeGenerated, UserId, Operation, ClientIP; let MailboxSuspicion = EmailEvents | where RecipientEmailAddress =~ TargetUser | where SenderFromAddress =~ TargetUser | project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, AuthenticationDetails, ThreatTypes, UrlCount; RecentSignins | union InboxRuleActivity | order by TimeGenerated desc
Why this works
The controls that actually matter
Final thought
If your environment has Microsoft security tools but your mail identity controls are still weak, the next step is closing that trust gap properly. 👉 Review Microsoft security operations and identity protection
Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD