The Email Passed SPF, DKIM and DMARC — Why Did Composite Authentication Still Fail?
The email looked legitimate.
SPF passed. DKIM passed. DMARC passed.
Yet Microsoft Defender still considered the message suspicious. Agent Foskett wanted to know why.
Briefing summary
An email successfully passed SPF, DKIM and DMARC validation checks. Despite that, Microsoft Defender XDR reported a Composite Authentication failure. Understanding why required looking beyond individual authentication mechanisms and examining the complete trust decision.
What is Composite Authentication?
Why can Composite Authentication fail?
The investigation
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
EmailEvents | where TimeGenerated > ago(30d) | where EmailAuthenticationResults has "compauth=fail" | project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, EmailAuthenticationResults
What the logs revealed
Why this matters
Agent Foskett moment
How defenders can investigate
Questions every analyst should ask
Related investigations
Final thought
The email passed SPF. It passed DKIM. It passed DMARC. But Composite Authentication still failed. Explore related investigations including Investigating EmailAuthenticationResults, Email Spoofing KQL, and SenderFrom vs SenderMailFrom.
Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD