Share via

This is a hacked email. Can you please show the name and location of it.

DG 0 Reputation points
2026-04-29T23:52:00.5566667+00:00

[Moderator note: Personal information has been removed to protect privacy and security]

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Hani-Ng 10,575 Reputation points Microsoft External Staff Moderator
    2026-04-30T04:18:05.8266667+00:00

    Since this is a public platform, I’ve moved the detailed information to a private message to avoid exposing any personal or organizational information. Please refer to the private message for those details. Kindly ensure that you hide any personal or organizational information the next time you post an error or other details to protect personal data.

    Hi DG

    Based on the full email message headers you provided, the email was sent through Microsoft 365 / Exchange Online Protection infrastructure with detail:

    • Sending server and IP address: I will also send you via private message.
    • Service owner: Microsoft Exchange Online Protection
    • Datacenter location: Sydney, Australia (Microsoft Azure - Australia East region)
    • SPF and DMARC checks passed, it means the sender was authorized to send mail on behalf of the domain.
    • The spam confidence level was very low (SCL 1).

    Microsoft 365 masks the sender’s personal device IP by design, so the absence of a user IP is expected and does not indicate compromise. According to headers, the email appears to have been sent via Microsoft’s mail system.

    From a header‑analysis perspective alone, the message appears to have been sent through legitimate Microsoft infrastructure, but only the tenant owner or Microsoft Support can perform a full security investigation.

    If there are ongoing concerns about a possible account compromise, the appropriate next step would be for the organization’s Microsoft 365 administrator to:

    • Review Azure AD / Entra ID sign‑in logs
    • Verify MFA enforcement
    • Reset credentials if required
    • Raise a support ticket directly with Microsoft

    Additionally, I hope you understand that this forum is a peer-to-peer community. While members can share advice and experiences only.

    I hope this information helps and if you have any question, please feel free to ask.


    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.