Sending, receiving, and organizing email in Outlook on the web for business
Hi Mitch,
The rate-limit error is the important clue. Genuine spoofing (someone forging your domain from their own servers) doesn't count against your tenant's sending limits. If you've hit the tenant external recipient rate limit (TERRL), mail is almost certainly leaving your tenant, most likely from a compromised mailbox or an app/connector sending via SMTP AUTH or Graph. That's also why nothing appears in Sent Items.
Getting sending back TERRL is a rolling 24-hour window, so it clears automatically once outbound volume drops below the threshold. It won't clear, though, while the spam is still going out, so stop the source first:
- In Exchange admin centre, run a message trace for outbound mail over the last few days and identify which sender or connector is generating the volume.
- In the Defender portal, check Email & collaboration > Review > Restricted entities. If a user has been blocked for outbound spam, release them there once they're cleaned up.
- For any affected account: reset the password, revoke sessions, enforce MFA, and remove any suspicious inbox rules, forwarding or OAuth app consents.
- Disable SMTP AUTH tenant-wide (and per mailbox) unless something genuinely needs it, and review any inbound connectors.
Stopping genuine spoofing going forward
- SPF: end with
-alland list only your real senders. - DKIM: enable it for your custom domain in Defender.
- DMARC: start at
p=nonewith reporting, review the reports, then move top=quarantineand finallyp=reject. Enforcingp=rejectis the real "next step after DMARC". Until you do, receivers will still accept forged mail. - ARC: this helps legitimate forwarded mail survive authentication checks. It's worth configuring trusted ARC sealers if you use third-party filtering, but it won't stop spoofing on its own.
- Beyond that: BIMI (brand logo, requires DMARC enforcement) and MTA-STS/TLS-RPT (transport security) are nice to have but don't address this problem.
Defender for Office 365 (Plan 1/2)
- Anti-phishing policy: enable spoof intelligence, user and domain impersonation protection, and mailbox intelligence.
- Outbound spam policy: set sensible per-user external limits and alert/block on breach, so a compromised account gets caught before it trips the tenant-wide limit.
- Set up alerting for "User restricted from sending email" and "Suspicious email sending patterns".
Once DMARC is at p=reject, the out-of-office and NDR backscatter from forged mail should largely stop too, because receivers will drop those messages rather than deliver and bounce them.
Regards, Seán