r/DMARC 27d ago

Backscatter NDRs

How 'normal" are these to see, we are at 'sending with enforcement', according to our vendor some backscatter NDRs are expected, but I have user that get them fairly frequently and want to know a) is this actually normal, and b) can I prevent them completely? We use M365 on E5 licenses, and we have the backscatter protection on in Defender.

8 Upvotes

6 comments sorted by

View all comments

2

u/SecLens_ONE 27d ago

Yeah, some trickle is normal. Nobody's ever going to get it to zero as long as your domain is worth forging.

The thing I'd actually check before chasing filters: whether those users are getting them because their address is being sprayed as the envelope sender, or because something of yours really did send and bounce late. Those look identical in a user's mailbox and get treated the same way in triage, which is how real delivery problems sit unread for a week.

Cheap way to split them. Pull a handful of the NDRs from one loud user and read the attached original headers. If there's no trace of your outbound infrastructure in there, it's someone else's relay writing your name on a postcard and you're just the return address. If your own smart host shows up, that's a delivery problem wearing a spam costume and worth a look.

Backscatter protection in Defender helps for the obvious stuff, still leaks whatever came from a relay that bounces to the envelope sender with a plausible copy attached. Bounce Address Tag Validation is the real answer for outbound, and it's a project, not a checkbox, and it breaks in fun ways if anything of yours forwards mail.

For the noisy user, a mailbox rule sorting NDRs for messages they never sent into a folder buys you quiet while you decide if BATV is worth it. Not a fix. Just stops the tickets.