0

Using impersonation insight to view domains that are sending phishes, there are several that are being delivered, even though our policy is to quarantine.

One domain that is commonly abused is icloud.com. Although, there are some false positives being labeled as impersonated and being delivered, but most are nasty phishes.

Instead of quarantining, is Microsoft adding a hit to the score to move to quarantine?

Why aren't all these impersonations of our domain being blocked? The rule specifically says to quarantine all domain impersonations:

enter image description here

  • What is your question? – schroeder Mar 28 '23 at 05:11
  • 1
    Please clarify your specific problem or provide additional details to highlight exactly what you need. As it's currently written, it's hard to tell exactly what you're asking. –  Mar 28 '23 at 07:35

0 Answers0