> It looks like GV0CHE01FT013.mail.protection.outlook.com is happily accepting phishing emails which, according to SPF should get rejected.

No, they shouldn't.

Specifying how unauthenticated mail from a domain should be treated is done using DMARC.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop

Reply via email to