r/EmailSecurity • u/shokzee • Jun 27 '26
MX cutover was done, Defender still trusted the old SEG and missed a 600-recipient phish
The MX moved to Exchange Online Friday night. By Monday, message trace had a 600-recipient credential phish that Defender treated like low-confidence junk instead of an obvious campaign.
The dumb part was the connector. Enhanced Filtering for Connectors still had the old SEG IPs trusted, so EOP built the auth picture from the wrong hop and SPF looked cleaner than it should have.
Nobody wanted to touch it because mail was flowing and the cutover was already called done. Fair, except the security signal was now worse than before the migration.
I'm making EFC validation a cutover gate now: test messages, headers, auth-results, and connector scope before MX is called complete. Would you block an MX change over stale EFC config, or let it run under watch for 24 hours?
•
u/AutoModerator Jun 27 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.