Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

In an aim to increase online security, SU has multiple policies in place for email.  

...

Info
titleAnti Malware Policy

Messages containing the following attachment types are automatically quarantined in Exchange Online:

.ace, .ani, .app, .docm, .exe, .jar, .reg, .scr, .vbe, .vbs

Info
titleAnti Phishing Policy
  • Domain impersonation protection is enabled for all SU email.  Impersonated domain attempts are quarantined.
  • Impersonated User protection is enabled via mailbox intelligence. Impersonated user attempts are quarantined.
  • Spoofed domain intelligence is enabled.  Spoofed domain messages are sent to junk mail folder.
Info
titleSafe Links Policy
  • Check a list of known (Microsoft managed), malicious links when users click links in Email or Microsoft Teams. URLs are rewritten by default.  Malicious links are blocked and click tracking is enabled.  See Advanced Threat Protection(ATP)/SafeLinks Email Scan for more information. 
Info
titleQuarantined Email Attachment Types

Outlook blocks the sending and receiving of certain types of files (such as .exe and certain database files) as attachments. If you need to send one of these file types to an email recipient, we recommend using OneDrive and sending the recipient a link to the file instead. See Microsoft Office 365 Outlook Email Quarantined File Extensions for a complete list.  

Info
titleEmail Retention Policy

The following retention policies are applied to everyone

  • Junk Email Folder deleted after 30 days
  • Deleted Items Folder deleted after 30 days
  • Messages older than 2 years automatically moved to archive mailbox (currently students do not use an archive mailbox due to limited time at the University)
  • All Messages from standard mailbox and archive mailbox are deleted after 10 years
Info
titleWhat is sent to Outlook Junk/Spam Folder

In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, inbound messages go through spam filtering in EOP and are assigned a spam score. That score is mapped to an individual spam confidence level (SCL) that's added to the message in an X-header. A higher SCL indicates a message is more likely to be spam. EOP takes action on the message based on the SCL.

Things that are known to affect the SCL score to mark them as Junk/Spam are email with no content and a URL only, spoofing domains, using a URL with IP's IPs instead of DNS names, text with numbers for instead of letters, embedded embedding images with URLs and no context, and attachment types.