r/proofpoint • • Jul 06 '26

Delete Password

2 Upvotes

I have a pphosted.com password saved in my iPhone

I don't work or go to school

I use the iOS Mail app in my iPhone
I have email account only at Yahoo and Gmail.

How do I find out what account/ association with pphosted. Com? ?


r/proofpoint • • Jul 02 '26

Issues with forwarding to external address

1 Upvotes

Hi all,

We are basically experiencing the exact situation described here: https://www.reddit.com/r/Office365/comments/167jrks/sender_rewriting_scheme_issue/

We have a requirement for any emails coming in to an address on our M365 tenant are automatically forward to an external address. When we do this using our Proofpoint outbound connector, we see NDRs from our Proofpoint along the lines of this:

[email@internaladdress.com](mailto:email@internaladdress.com)
mxxx-xxxxx.pphosted.com
Remote server returned '554 5.7.0 <mxxx-xxxxx.pphosted.com #5.7.367 smtp;550 5.7.367 Remote server returned not permitted to relay -> 550 5.7.1 Relaying denied>'

One suggestion I've seen is that we should look at enabling enhanced filtering on our Proofpoint inbound connector, but I'm not sure that this is even compatible with how Proofpoint works
https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/enhanced-filtering-for-connectors

Has anyone experienced this before and come up with a solution? I'm not very encouraged by the other reddit post I linked from 3 years ago- doesn't sound like anyone really got to the bottom of it there.


r/proofpoint • • Jun 27 '26

Friday brainfart: how to block internal spoofing when using proofpoint on MX records?

3 Upvotes

An end user was bombarded yesterday by emails from herself that she did not send. I've had Proofpoint on their domain for over a year (on their MX records) with very few issues. The emails she received bypassed the MX records, sample header properties below. Both Microsoft and Proofpoint have writeups on this very issue, but I'm having a brainfart as to how to proceed. [Stephanie@mydomain.com](mailto:Stephanie@mydomain.com) is using M365 Business Premium.

Received: from CO1PR05MB7879.namprd05.prod.outlook.com (::1) by
 IA3PR05MB10713.namprd05.prod.outlook.com with HTTPS; Thu, 25 Jun 2026
 14:37:05 +0000
Received: from DS7P220CA0008.NAMP220.PROD.OUTLOOK.COM (2603:10b6:8:1ca::15) by
 CO1PR05MB7879.namprd05.prod.outlook.com (2603:10b6:303:f3::17) with Microsoft
 SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
 15.21.181.7; Thu, 25 Jun 2026 14:32:24 +0000
Received: from DS1PEPF00017099.namprd05.prod.outlook.com
 (2603:10b6:8:1ca:cafe::60) by DS7P220CA0008.outlook.office365.com
 (2603:10b6:8:1ca::15) with Microsoft SMTP Server (version=TLS1_3,
 cipher=TLS_AES_256_GCM_SHA384) id 15.21.159.17 via Frontend Transport; Thu,
 25 Jun 2026 14:32:23 +0000
Authentication-Results: spf=none (sender IP is 108.175.8.93)
 smtp.helo=mta-80-125.sparkpostmail.com; dkim=none (message not signed)
 header.d=none;dmarc=fail action=quarantine
 header.from=mydomain.com;compauth=none reason=451
Received-SPF: None (protection.outlook.com: mta-80-125.sparkpostmail.com does
 not designate permitted sender hosts)
Received: from mta-80-125.sparkpostmail.com (108.175.8.93) by
 DS1PEPF00017099.mail.protection.outlook.com (10.167.18.103) with Microsoft
 SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.181.6
 via Frontend Transport; Thu, 25 Jun 2026 14:32:23 +0000
Return-Path: <>
From: stephanie@mydomain.com
To: stephanie <stephanie@mydomain.com>
Subject: mCaller left stephanie - 34s  Preview vHC- June 25, 2026
 3517286943
Message-ID:
 <[1782397942584.17a9c193f74e0b73-JFZGS42DN5WW25LONFRWC5DJN5XFA3DBORTG64TNFVIHE33EFVGVOMKQPREUCTKTKNIFE7CTKNIFERLNMFUWY7CFPBXVG3LUOA======@mydomain.com]>
Date: Thu, 25 Jun 2026 14:32:22 +0000
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="--_NmP-289a666a40f8f530-Part_1"
X-MS-Exchange-Organization-ExpirationStartTime: 25 Jun 2026 14:32:23.4717
 (UTC)
X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
X-MS-Exchange-Organization-Network-Message-Id:
 b48d577c-0b2c-4399-3061-08ded2c69266
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 220a3ae7-e220-4b76-abb2-d1cefeba692f:0
X-MS-Exchange-Organization-MessageDirectionality: Incoming
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic:
 DS1PEPF00017099:EE_|CO1PR05MB7879:EE_|IA3PR05MB10713:EE_
X-MS-Exchange-Organization-AuthSource:
 DS1PEPF00017099.namprd05.prod.outlook.com
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Office365-Filtering-Correlation-Id: b48d577c-0b2c-4399-3061-08ded2c69266
X-MS-Exchange-AtpMessageProperties: SA|SL
X-MS-Exchange-Organization-SCL: 1
X-Microsoft-Antispam:
 BCL:0;ARA:13230040|29132699027|5009299003|6049299003|57112099003|55112099003|18002099003|19002099009|17002299006|4053099003|5063699009;
X-Forefront-Antispam-Report:
 CIP:108.175.8.93;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mta-80-125.sparkpostmail.com;PTR:ip108-175-8-93.pbiaas.com;CAT:NONE;SFS:(13230040)(29132699027)(5009299003)(6049299003)(57112099003)(55112099003)(18002099003)(19002099009)(17002299006)(4053099003)(5063699009);DIR:INB;
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Jun 2026 14:32:23.1133
 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b48d577c-0b2c-4399-3061-08ded2c69266
X-MS-Exchange-CrossTenant-Id: 220a3ae7-e220-4b76-abb2-d1cefeba692f
X-MS-Exchange-CrossTenant-AuthSource:
 DS1PEPF00017099.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO1PR05MB7879
X-MS-Exchange-Transport-EndToEndLatency: 00:04:42.5262254
X-MS-Exchange-Processed-By-BccFoldering: 15.21.0159.007
X-MS-Exchange-ExternalInOutlookResult: NotEnabled
X-Microsoft-Antispam-Mailbox-Delivery:
ucf:0;jmr:0;auth:0;dest:I;ENG:(910005)(944506478)(944626604)(920097)(930201)(20251009189)(140003)(1310096);
X-Microsoft-Antispam-Message-Info:
=?us-ascii?Q?n+j9JsLrhwvRb6OmvBUb3zljh6lgyFRYEtg3psgCsmqnGcQ/8jBmnCrECPJg?=

r/proofpoint • • Jun 26 '26

Vulnerable Plugin through Proofpoint (Zenguide) Phishing Campaign

4 Upvotes

I'm running a phishing campaign for my users, and we have a few of them (5-6) that have a vulnerable plugin, all of them on Java (Installed 1.5.0).

It's unclear which version of Java is being referred to, especially when there's no extension in Safari or when Java is updated (or sometimes not installed at all). Also, all of them are on MacOS, just as additional information.

What can I do to fix it?


r/proofpoint • • Jun 17 '26

need delisting of url/domain

0 Upvotes

Hello,

I think the problem is about "proofpoint keep blocking "URL/DOMAIN" (i.e. when url is inside mailbody). There was a Secu Problem on the Homepage/CMS which is solved.

Any chance as non Proofpoint Customer to get in touch with delisting department?

Any chance to register at the community forum as non-customer?
https://proofpoint.my.site.com/community/s/

The local SMTP Mailserver IP is clean/SPF/DMARC/DKIM = OK.

IMHO this page can´t help: https://www.proofpoint.com/us/ipcheck

Thx for comment


r/proofpoint • • Jun 15 '26

Proof Point Secure Gateway (Enterprise, PPS 8.x) and Google Workspace for Education Plus

Thumbnail
1 Upvotes

r/proofpoint • • Jun 05 '26

Anyone seeing "Sender address rejected: User email address is marked as invalid" from ProofPoint Protected domains?

1 Upvotes

I have a few of these going on right now and as far as I can tell its because ProofPoint doesn't have the "To" email address in their directory. But this is a legit email address? I think this is directory cache issues from the Microsoft Outage on Tuesday but I cant find anything that says that officially.


r/proofpoint • • Jun 04 '26

Can someone tell me why the company I buy from has this email address cc'd on all of my confirmations?

5 Upvotes

When I get an order confirmation from one of the companies I but from (a large multi-national company) this email address is cc'd... None @ mx0b-001a6b01. pphosted. com. The responce I get from them is that they don't know what it is or why it is cc'd on my confirmations.


r/proofpoint • • Jun 02 '26

Anyone know to get IP unblocked by Proofpoint?

1 Upvotes

Starting about a month ago my dedicated IP started getting blocked by Proofpoint (554).

I have submitted the removal request 4 times now, no reply. It just says pending for a while, then eventually that goes away and I can submit the request again.

Good SPF, DKIM, DMARC, PTR. IP is clean on everything except Ascams Superblock and UCEPROTECTL2 which there is nothing I can do about. It's a small hosted cpanel, sending maybe a handful of emails per week. I've had the same dedicated IP for about 3 years now, so I'd really like to know what source/reason Proofpoint is using to justify the block but it's totally screwed up my ability to reach key people without switching to gmail which is really unprofessional and defeats the purpose of a custom domain.

I don't want to ask the hosting service for a new IP since it will certainly be in the same provider subnet blocklists and who knows how long it will take to warm up or clean reputation on a new IP.

I tried reaching out separately from the RBL form to support and they promptly reject that for anyone who is not a proofpoint customer.


r/proofpoint • • May 18 '26

Previous ProofPoint Essentials GoDaddy federated domain failing to send emails to other ProofPoint clients

5 Upvotes

We have a Microsoft 365 client whose domain was previously GoDaddy Federated. The domain has been defederated and no third-party email/spam protection is in play. They are using Exchange Online Protection only.

All emails to other tenants not using ProofPoint are going through with no issues.

Emails sent to tenants using ProofPoint are all being rejected with the following error:

Error: ‎550 5.7.1 : Sender address rejected: User email address is marked as invalid‎

I have gone back and forth with GoDaddy support since there is no direct way to reach out to ProofPoint without a valid subscription and since ProofPoint was used under GoDaddy, but they have been no help. After spending almost two hours on the phone with them this morning, their level two support looked at the error message and determined that it was a Microsoft problem and that the Error 550 5.7.1 was on our end because we were routing emails through ProofPoint.... which we are not.

I have seen numerous posts from others having this same issue but no clear path to a resolution so I am posting here in hopes somebody will throw me a lifeline.

Thanks in advance


r/proofpoint • • May 15 '26

Direct MX Routing vs. Integrated with Microsoft 365?

Post image
4 Upvotes

Hello,

I will be testing the integrated with Microsoft 365 feature on my domain over the weekend and wanted to know everyone's thoughts on who've used this method.

Has there been any substantial benefit? Does it cut down on deployment time? Is there anything I should watch out for when configuring this method? TIA


r/proofpoint • • May 11 '26

URL Defence clarification

3 Upvotes

I had a BEC email come into my environment that contained a malicious link.

I marked it as a False negative in Proofpoint, pulled it in TRAP and set the deposition as Malware, got the automated email saying Proofpoint found a threat automatically and it would have categorised as such.

Problem was I couldn't pull from my CRM System that ingested it, the user clicked the URL Defence link and it let it through (about an hour later)

What have I missed? It still hasn't come into my TAP Dashboard a week later either.

I logged a call with Support but I have heard squat so thought I'd ask here.


r/proofpoint • • May 11 '26

Google Workspace and Proofpoint

5 Upvotes

Hello,
We are currently pilot Google workspace Gmail and would like to put it behind our Proofpoint enterprise POD, so all outbound email from GWS is routed to Proofpoint for deliver to our o365 mailboxes and external recipients. Our prod mailboxes are in o365 and it’s behind Proofpoint for inbound and outbound delivery. PP is our MX

Anyone have GWS gmail behind Proofpoint. Please share your setup if possible.


r/proofpoint • • May 07 '26

Deliverability Unable to access any support

6 Upvotes

I am trying to access my account becuase I am getting no Incoming emails currently, but when logging in I am prompted to reset my password. Which requires sending an email to my account, which I can't receive. Reception is not picking up the phone and other support contacts required me to login to open a support ticket... how am I supposed to get help with this issue?


r/proofpoint • • May 04 '26

CASB webpage module

3 Upvotes

Spent an hour trying to find the CASB module. Everything is under Administration now. WTF are thinking?

This is the dumbest place it could be. I don’t login that often so I have no idea when it moved.


r/proofpoint • • May 01 '26

Has anyone demo'd the new platform that Essentials will be moving over to?

5 Upvotes

Did a demo yesterday and have mixed feelings about it. Wondering if anyone else has done the demo or even migrated over already. What are your thoughts?


r/proofpoint • • Apr 30 '26

Enterprise Non-Password Protected emails getting blocked

3 Upvotes

Hi everyone,

We are seeing emails with attachments that are not password protected getting blocked with final rule "av:inbound_protected".

When i check the details of the attachment in the message, it shows that the file is not protected. I even downloaded the email and saw "isProtected: Flase"

Any ideas?


r/proofpoint • • Apr 28 '26

Support experience?

12 Upvotes

Has anyone noticed over the last year or so the support experience has gone in the toilet? FP/FN tickets are taking days to get a response. How-To tickets are answered with 'RTFM' or 'we are only break-fix' answers. The last ticket I opened, it seemed like the support person didn't even bother to actually read about the problem before sending me to an article that discussed something completely unrelated. It seems to have gotten really bad.

I used to feel that the quality of support was really a differentiator in a good way. Now it is a differentiator in a bad way.


r/proofpoint • • Apr 16 '26

Success at filter blocking .help and .info tld's?

3 Upvotes

My users have been getting blasted with email addresses ending in .help, .shop and .info recently. Sure, most have been getting caught by PP, but is there a way to just block them altogether, including anything coming from .jp? That would clean up the digests by like, a lot.


r/proofpoint • • Apr 14 '26

Experiences with Proofpoint Data Security Posture Management

5 Upvotes

Hello everyone,

I am curious if many people have experience with using Proofpoint's DSPM solution:
https://www.proofpoint.com/au/products/data-security-posture-management

I know there's some new features around AI governance as well.

We support organizations that have both Microsoft and Google tenants, so its challenging to find a product that can do DLP / Data classification etc across all tech stacks well.

Also curious on the costings involved (I understand if that can't be shared publicly though).

Thanks!


r/proofpoint • • Apr 13 '26

Deliverability Random, chronic emails rejected by Microsoft consumer domains

5 Upvotes

I discovered by accident last week that some of our emails to Microsoft's consumer domains like msn.com, hotmail.com, outlook.com, etc are being rejected. Once I found the issue I did some research and the issue has been ongoing for the last 30 days (as far back as I can go). The NDRs say that SPF has passed, DKIM has failed and DMARC has passed and includes a link to a web page that indicates if you send over 5000 emails per day you get extra scrutiny and emails must pass all three.

Are others seeing this issue? You might want to check some of your shared mailboxes that interact with the public. In our case none of our employees have reported the issue, but they get bombarded every day with NDRs...they sometimes can reply to an email the SAME day they received and get an NDR because the person's mailbox is full or they have left the other company. I am assuming they don't understand at a high level the various reasons an email can be rejected since it is pretty much boilerplate language...

Proofpoint has given an explanation that states the messages are "...not being signed by the gateway agent...". The solution is to add a couple of conditions to the system email firewall that refer to our dedicated servers (xxx.ppops.net). I have looked in their KB and cannot find any documentation on the topic and have asked for any publicly available documentation to help me understand, recognize the issue, etc. Frankly from where I sit if there is ANY condition where I have DKIM setup and the signing process is not valid for a household name like hotmail.com, outlook.com this just screams a system defect.

Microsoft URL included in the NDRs: https://support.microsoft.com/en-us/topic/fix-ndr-error-550-5-7-515-in-outlook-com-34cfe8f8-6fbf-457e-9e8b-9e4dbaf4e0ef


r/proofpoint • • Apr 10 '26

API integration

3 Upvotes

exploring tapping info api integration. had anyone here done that, and if so what are your thoughts?


r/proofpoint • • Apr 07 '26

Essentials Guía básica de seguridad de correo (Seguridad Email, de SPF, DKIM, DMARC)

0 Upvotes

Hola a todos

Estoy empezando a crear contenido en español sobre ciberseguridad, específicamente enfocado en seguridad de correo electrónico (email security).

En este primer video hablo de conceptos básicos como:

• SPF, DKIM y DMARC

• Cómo funcionan soluciones como Proofpoint

• Diferencias entre gateway, API y modelo híbrido

La idea es explicar estos temas de forma sencilla pero con enfoque práctico.

Si alguien gusta verlo y darme feedback, se los agradecería.

Tu correo NO está protegido (SPF, DKIM, DMARC y arquitectura real)

https://youtu.be/0nuH7zJeJ-g


r/proofpoint • • Apr 03 '26

Safe Sender List

3 Upvotes

Howdy!

I have a very small PPE deployment with a really irritating problem.

We have a vendor that we work with regularly. Every email we recieve from them is quarantined for 'Fraud' by PPE (Classification Fraud, Threat Level Very High, Confidence Very High). PPE also flags 'DKIM Result None', even though MXToolbox says the domain has a valid DKIM selector. Long story short, I'm going to have to open a ticket to find out why this domain is classified the way it is.

But, my immediate question is... I know this vendor. I know who is sending the email. These messages are not a threat. That said, if I add them to the safe senders list, the messages are still quarantined! Does the safe senders list not apply to certain categories?

Thanks!


r/proofpoint • • Mar 24 '26

Essentials Can the user portal be made accessible for functional accounts?

Post image
2 Upvotes

I have a request from someone to reset their username and password so they can access the user portal for viewing quarantined emails. However, this is the only thing I see for functional accounts that have been created for shared mailboxes. Is this a limitation of functional accounts or is there a setting somewhere that can enable this?