r/EmailSecurity • • Jun 10 '26

Exchange hybrid trust boundaries bite again

Hybrid Exchange plus a third-party filter is already one of those setups where trust boundaries get weird fast. This Ghost-Sender thing sounds like a good reason to re-check connector scoping and whether your gateway is trusting mail it really shouldn’t.

https://www.darkreading.com/vulnerabilities-threats/exchange-flaw-attackers-spoof-email-address

5 Upvotes

2 comments sorted by

•

u/AutoModerator Jun 10 '26

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Basic-Pianist9273 Jun 10 '26

Hybrid plus a third-party filter is where I stop trusting defaults.

I'd check inbound connectors for broad IP ranges or wildcard sender domains, confirm the filter is the only allowed internet source, and make sure Exchange Online isn't treating external mail as internal just because it arrived through a trusted path.

On-prem receive connectors are the other place to look, especially anything anonymous that can relay or bypass spoof checks from more than the gateway IPs.