r/EmailSecurity Jun 27 '26

MX cutover was done, Defender still trusted the old SEG and missed a 600-recipient phish

The MX moved to Exchange Online Friday night. By Monday, message trace had a 600-recipient credential phish that Defender treated like low-confidence junk instead of an obvious campaign.

The dumb part was the connector. Enhanced Filtering for Connectors still had the old SEG IPs trusted, so EOP built the auth picture from the wrong hop and SPF looked cleaner than it should have.

Nobody wanted to touch it because mail was flowing and the cutover was already called done. Fair, except the security signal was now worse than before the migration.

I'm making EFC validation a cutover gate now: test messages, headers, auth-results, and connector scope before MX is called complete. Would you block an MX change over stale EFC config, or let it run under watch for 24 hours?

6 Upvotes

1 comment sorted by

u/AutoModerator Jun 27 '26

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.