An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
I just got this email several hours ago, I never click on emails that look sketchy, but the email headers says you sent it, or it came through your mail servers.
So, if its a scam email then why is it coming from Microsofts servers?
As you can see below, it was signed by microsoft mail servers.
dkim=pass (1024-bit key; unprotected) header.d=sponaeop.onmicrosoft.com header.i=@sponaeop.onmicrosoft.com header.a=rsa-sha256 header.s=selector1-sponaeop-onmicrosoft-com header.b=jaTijtV1;
dkim=pass (2048-bit key; unprotected) header.d=OUTLOOK.MAIL.MICROSOFT header.i=@OUTLOOK.MAIL.MICROSOFT header.a=rsa-sha256 header.s=selector1 header.b=ZgXj7Efz;
dkim-atps=neutral
Authentication-Results: OpenDMARC; dmarc=pass (p=reject dis=none) header.from=outlook.mail.microsoft
Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=2a01:111:f403:c110::3; helo=bn8pr05cu002.outbound.protection.outlook.com; envelope-from=******@outlook.mail.microsoft; receiver=initcorp.co.uk
Received: from BN8PR05CU002.outbound.protection.outlook.com (mail-eastus2azlp170110003.outbound.protection.outlook.com [IPv6:2a01:111:f403:c110::3])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange ECDHE (secp384r1) server-signature ECDSA (prime256v1) server-digest SHA256)
(No client certificate requested)
by sambuca.psychonet.co.uk (Postfix) with ESMTPS id 216A32DC0FAA
for <--REMOVED-->; Fri, 18 Sep 2026 23:32:16 +0000 (UTC)
and
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=sponaeop.onmicrosoft.com; s=selector1-sponaeop-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=+41i0V9Ns2HWjGSlPIvpwyqdccm94h2CPMkVxgAkA34=;
b=jaTijtV1gzJ5eO5aGec6XbM0l0LPB2NtDt5D8567E+zZ/v0ABKJh2A7mTZ6KpNQLuIM6k1iwiOg9B918t9u/nzAN/rFpOliq7hPQg7cp+jXrjJvbuLvr8sAVefvxFd4X6t+opyA9E1i6A9Kz37yGTjMwYiYCLLxxxHpcUsHxYqU=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=OUTLOOK.MAIL.MICROSOFT; s=selector1;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=+41i0V9Ns2HWjGSlPIvpwyqdccm94h2CPMkVxgAkA34=;
b=ZgXj7EfzfYGnqWRUHJsdij5FU1L9mh4VqV6O3IJl1KwwPaXLPrcPsgjd7+HWh8lMWqlL+BT+0uIZYXU8ZFSYe6ZrC/sRJCL1qr8wgxPHappOXoMKCLLTsVYJRCilzg3+8kTF5qm9XX0YvbzAn8xj02S3dQbaWcscxLx2MGdCBO8xebksId3RxCSGxLPHdhsExBWPH3A4LeRJBtG46MMnjRED/e2bJtwfY9/SUbsOJrpjuie4PzQs80AmV/L2es8JJJV5JRXMoBd7Gp7DBhlzsrDTywXrZSnHUBxplw7jQLyAjNix06cQfwRQhrECjm7sl9QwGCGQvYZiBN+w7VJE0A==
Received: from substrate.office.com (2603:10b6:5:336::19) by
DSAPR10MB479029.namprd10.prod.outlook.com with HTTP via
DM6PR06CA0086.NAMPRD06.PROD.OUTLOOK.COM; Fri, 18 Sep 2026 23:32:13 +0000
Date: Fri, 18 Sep 2026 23:32:12 +0000
Subject: Action Required: Re-attest Your Network Access
So you or one of your employees sent it.
https://www.whois.com/whois/onmicrosoft.com
So can you confirm if this is a legit or scam email and if its a scam email then you have a breach on your servers.