how can i find who sent this in email (the IP address, owners name or any information)

Araque, Karlota mdcps 0 Reputation points
2026-05-02T14:55:46.8433333+00:00

DS4PR01MB9251.prod.exchangelabs.com

DS4PR01MB9251.prod.exchangelabs.com

******@dadeschools.net

******@dadeschools.net

SJ0PR01MB6240.prod.exchangelabs.com SJ0PR01MB6240.prod.exchangelabs.com mapi *
SJ0PR01MB6240.prod.exchangelabs.com SJ0PR01MB6240.prod.exchangelabs.com mapi *****
2 5/2/2026 2:19:06 PM SJ0PR01MB6240.prod.exchangelabs.com DS4PR01MB9251.prod.exchangelabs.com Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) 1 sec

Original Message Headers

Authentication-Results: dkim=none (message not signed)
 header.d=none;dmarc=none action=none header.from=students.dadeschools.net;
Received: from SJ0PR01MB6240.prod.exchangelabs.com (2603:10b6:a03:290::14) by
 DS4PR01MB9251.prod.exchangelabs.com (2603:10b6:8:281::10) with Microsoft SMTP
 Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
 15.20.9846.23; Sat, 2 May 2026 14:19:06 +0000
Received: from SJ0PR01MB6240.prod.exchangelabs.com
 ([fe80::3deb:36a1:83c4:3009]) by SJ0PR01MB6240.prod.exchangelabs.com
 ([fe80::3deb:36a1:83c4:3009%4]) with mapi id 15.20.9870.022; Sat, 2 May 2026
 14:19:05 +0000
Content-Type: application/ms-tnef; name="winmail.dat"
Content-Transfer-Encoding: binary
Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-02T14:55:56.1733333+00:00

    The code 550 5.7.1 TRANSPORT.RULES.RejectMessage; the message was rejected by organization policy means that an Exchange Online (Microsoft 365) mail flow rule or other organization policy blocked the message. The server name DS4PR01MB9251.prod.exchangelabs.com is just one of Microsoft’s Exchange Online mailbox servers; it does not identify an attacker and is not evidence of who “cyber robbed” the account.

    What this error tells:

    • The message hit a transport (mail flow) rule or policy in the recipient’s or sender’s Microsoft 365 organization.
    • The rule’s action was to reject the message, which generated the 550 5.7.1 non‑delivery report (NDR).
    • The rejection is due to security or compliance configuration (for example, anti‑spam, DLP, or a custom rule), not because someone is actively intercepting the mail.

    How to find more detail (admin steps):

    1. Run a message trace in the Exchange admin center for the affected message to see:
      • The exact rule or policy that rejected it.
      • Whether the message was classified as spam, malware, or matched a specific rule condition.
    2. Review mail flow rules and security policies that could be rejecting messages (for example, rules that reject messages from external senders, or that enforce TLS and reject on failure).

    If there is concern about account compromise or “cyber robbery,” that must be investigated separately (sign‑in history, device checks, MFA status, password changes, etc.). The 550 5.7.1 TRANSPORT.RULES.RejectMessage NDR itself only shows that organization policy blocked the email, not where an attacker is located or who they are.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.