Commands › Exchange Online

Get-SpoofMailReport

Exchange Online ExchangeOnlineManagement Get-*

View information about spoofed senders in your cloud-based organization for the past 90 days. Spoofing is where the sender of the inbound message is different than the actual source of the message (for example, the sender is lila@contoso.com, but the message was sent from the email infrastructure of fabrikam.com).

Quick start script

# Get-SpoofMailReport — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Get-SpoofMailReport | Format-List

# 3. Export for evidence / drift tracking
Get-SpoofMailReport | Export-Clixml .\SpoofMailReport-$(Get-Date -Format yyyyMMdd).xml

Syntax

Get-SpoofMailReport [-Action <MultiValuedProperty>]
 [-Direction <MultiValuedProperty>]
 [-EndDate <DateTime>]
 [-EventType <MultiValuedProperty>]
 [-Page <Int32>]
 [-PageSize <Int32>]
 [-ProbeTag <String>]
 [-StartDate <DateTime>]
 [<CommonParameters>]

Parameters (8)

ParameterTypeRequiredWhat it controls
-Action MultiValuedProperty The Action parameter filters the report by the action taken on messages. To view the complete list of valid values for this parameter, run the command: `Get-MailFilterListReport -SelectionTarget Actions`. The action...
-Direction MultiValuedProperty The Direction parameter filters the results by incoming messages. The valid value for this parameter is Inbound.
-EndDate DateTime The EndDate parameter specifies the end date of the date range.
-EventType MultiValuedProperty The EventType parameter filters the report by the event type. The only valid value for this parameter is SpoofMail.
-Page Int32 The Page parameter specifies the page number of the results you want to view. Valid input for this parameter is an integer between 1 and 1000. The default value is 1.
-PageSize Int32 The PageSize parameter specifies the maximum number of entries per page. Valid input for this parameter is an integer between 1 and 5000. The default value is 1000.
-ProbeTag String This parameter is reserved for internal Microsoft use.
-StartDate DateTime The StartDate parameter specifies the start date of the date range.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.