Alerts related to data source "Microsoft 365 Emails".
Display text URL differs from actual URL
Email attachment with a potentially malicious file extension
Email attachment with multiple extensions
Email attachment with Right-to-Left Override Unicode character
Email attachment(s) with potentially malicious MIME type
Email containing a link with an IP address convention was detected
Email containing a redirected link
Email contains URL delivering high-risk file type
Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values
Email mimics replies or forwards without an actual ongoing conversation
Email sent using an automated system or script detected
Email was received from an unknown address using a public provider domain
Email was received from an unknown sender using a disposable domain
Email with file-sharing link containing auto-download parameter
Email with URL shortener detected
External email display name impersonation of internal personnel
External email with a single internal recipient hidden in BCC
First-seen email from mailbox owner to external recipient's address in the last 30 days
First-time attachment exchange
Initial person-to-person email contact
Moniker link detected in URL(s)
Near-empty email from an external sender
Numerous emails sent by a single sender to multiple internal recipients
Outbound email contains file-sharing service link sent to external recipient
Outbound email includes an external BCC recipient observed for the first time
Outbound email to an address hosted by a public email service provider
Potential Phishing has been detected
Potential spoofing of internal domain spotted
Punycode characters detected in URL(s)
Quarantined email released to recipients
Rarely seen sender address in the organization
Rarely seen sender domain in the organization
Sending unusual file(s) to an external address
Sudden spike in outbound email volume
Suspicious brand affiliation detected
Suspicious DKIM Result
Suspicious DMARC result
Suspicious sender exhibiting automated sending patterns
Suspicious sending domain with sender address randomization
Suspicious SPF Result
Suspicious theme and sentiment in email
Suspicious Unicode character detected in email
Training simulation email detected
Uncommon URL domain(s) in your organization detected in email
Unrecognized internal address (AAD mismatch)
Unusual attachment volume in outbound emails
Unusual display name in From header
Unusual file-sharing links for mailbox owner
Unusual hostname for the sending mail server in the email headers
Unusual sender IP subnet
Unusual URL(s) sent by a brand were observed in the email
Usage of homograph characters detected in an email
Usage of homograph characters detected in an email attachment(s) name
Usage of homograph characters detected in an email's from header
Well-known brand in sender headers with header inconsistencies
X-Forefront-Antispam-Report has flagged this email as a potential threat
Was this helpful?