Spoofing emails causing issues

Techniform Graphics 0 Reputation points
2026-09-30T08:33:18.98+00:00

We receive spoofing attacked where someone is using our email name to send out batch spam emails but there is nothing in our sent box. We then receive a ton of out of offices or undeliverable from the recipients of the spam emails in our clutter / inbox. I usually create a rule to remove these from the inbox but as it's happen slightly more frequently now (about twice a month). I've gone to send an email to a customer this morning and the error that came back was: 'Your message can't be sent because your tenant has exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit). For more information..etc'

As this is now affecting our business use, I need to put an end to the spoofing emails, can anyone help please? How do I unlock my emails also so I can start sending again? Is it a 24 hour limit?

Thanks for any help.

Regards

Outlook | Web | Outlook on the web for business | Email
0 comments No comments

2 answers

Sort by: Most helpful
  1. Killian N 4,410 Reputation points Independent Advisor
    2026-09-30T09:06:37.82+00:00

    Hi Techniform Graphics

    The undeliverable messages you receive for emails you did not send are known as backscatter. This usually happens when a spammer forges your address in the From field. The messages will not necessarily appear in Sent Items because they may not have originated from your mailbox. (To learn more, please visit: Backscatter in cloud organizations)

    However, the tenant external recipient rate limit error is separate and means that your Microsoft 365 tenant has reached its outbound limit for external recipients. The limit applies across the entire tenant, including users, shared mailboxes, applications, and automated services. It uses a rolling 24-hour window, so sending becomes available again as earlier recipients fall outside that window. The limit cannot be manually increased or reset.

    Because simple address spoofing occurs outside your tenant, it would not normally use your Microsoft 365 outbound allowance. Therefore, I recommend asking your Microsoft 365 administrator to investigate whether an account, application, connector, or automated process has been compromised or is sending unexpectedly.

    Your organization's IT administrator should:

    1. Check Exchange admin center > Reports > Mail flow > Tenant outbound external recipients to review current usage and quota.
    2. Run a message trace for the affected period to identify which mailbox or service generated the outbound messages.
    3. Review the Microsoft Defender portal for restricted users and suspicious activity.
    4. If an account appears compromised, reset its password, revoke active sessions, enable multifactor authentication, and inspect mailbox forwarding and Inbox rules. Suspicious rules, unexpected forwarding, and a mailbox being blocked from sending can indicate compromise.
    5. Verify that SPF, DKIM, and DMARC are correctly configured for the domain. These authentication methods work together to help receiving systems identify forged messages. SPF alone does not provide complete spoofing protection.

    You can share these guides with your administrator:

    In short, the restriction should clear automatically as usage drops below the tenant limit during the rolling 24-hour window.

    For more information, please refer to the following link:"

    I hope this helps you restore sending and prevent the issue from recurring. If you have any further questions or updates, please don’t hesitate to share.

    Kind regards,

    Was this answer helpful?

    0 comments No comments

  2. Sean O'Farrell 0 Reputation points
    2026-09-30T08:58:55.7933333+00:00

    Hi Mitch,

    The rate-limit error is the important clue. Genuine spoofing (someone forging your domain from their own servers) doesn't count against your tenant's sending limits. If you've hit the tenant external recipient rate limit (TERRL), mail is almost certainly leaving your tenant, most likely from a compromised mailbox or an app/connector sending via SMTP AUTH or Graph. That's also why nothing appears in Sent Items.

    Getting sending back TERRL is a rolling 24-hour window, so it clears automatically once outbound volume drops below the threshold. It won't clear, though, while the spam is still going out, so stop the source first:

    1. In Exchange admin centre, run a message trace for outbound mail over the last few days and identify which sender or connector is generating the volume.
    2. In the Defender portal, check Email & collaboration > Review > Restricted entities. If a user has been blocked for outbound spam, release them there once they're cleaned up.
    3. For any affected account: reset the password, revoke sessions, enforce MFA, and remove any suspicious inbox rules, forwarding or OAuth app consents.
    4. Disable SMTP AUTH tenant-wide (and per mailbox) unless something genuinely needs it, and review any inbound connectors.

    Stopping genuine spoofing going forward

    • SPF: end with -all and list only your real senders.
    • DKIM: enable it for your custom domain in Defender.
    • DMARC: start at p=none with reporting, review the reports, then move to p=quarantine and finally p=reject. Enforcing p=reject is the real "next step after DMARC". Until you do, receivers will still accept forged mail.
    • ARC: this helps legitimate forwarded mail survive authentication checks. It's worth configuring trusted ARC sealers if you use third-party filtering, but it won't stop spoofing on its own.
    • Beyond that: BIMI (brand logo, requires DMARC enforcement) and MTA-STS/TLS-RPT (transport security) are nice to have but don't address this problem.

    Defender for Office 365 (Plan 1/2)

    • Anti-phishing policy: enable spoof intelligence, user and domain impersonation protection, and mailbox intelligence.
    • Outbound spam policy: set sensible per-user external limits and alert/block on breach, so a compromised account gets caught before it trips the tenant-wide limit.
    • Set up alerting for "User restricted from sending email" and "Suspicious email sending patterns".

    Once DMARC is at p=reject, the out-of-office and NDR backscatter from forged mail should largely stop too, because receivers will drop those messages rather than deliver and bounce them.

    Regards, Seán

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.