Hello,
We have a phishing scenario on Exchange and we use local Exchange. However, in the new scenario, O365 has been added and some emails are being moved here. In the new environment, some emails are on Exchange and some on O365. How can we use the two environments in the same scenario and how can we tell which server the incoming mail is from?
@adem_netsys , try comparing the headers of sample email from both servers. I would guess the incoming paths would be different.
@anarula How can we do this, have you tried before?
@adem_netsys , can you share the headers from 2 samples (one from O365, and other from Exchange Server)
Actually, I don't think it is very important what the two headers are here. It could be what you think as an example.
Do you have any updates? @anarula
No @adem_netsys -- Infact, I am waiting on you to provide the sample emails from these 2 different servers. When you proovide that, we would compare the headers and search for a clue to differentiate. Basically I expect to see differences in Recieved property in the header to identify where is the mail delivered from
see this as an example
Received: from abc.abc.com (192.168.DD.YY) by
abc.abc.com (192.168.DD.YY) with Microsoft SMTP Serve
when you parse this header (actually it would be available in JSON format (so easy to lookup), you should be able to spot the differece.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.