What if the sender’s account was compromised?¶
A fraudulent or disputed message can come through a completely genuine mailbox.
It may pass normal domain-authentication checks, appear in Sent Items and travel through the provider's real infrastructure — while somebody other than the account holder is controlling the account.
That makes compromise a practical hypothesis to test, not an excuse to dismiss genuine sending evidence.
Treat the account as its own evidence source¶
Useful records may include:
- sign-ins and sessions;
- MFA and recovery changes;
- devices;
- password changes;
- connected applications;
- delegate or Send As permissions;
- mailbox rules and forwarding;
- message access and deletion;
- Sent and Draft items; and
- message trace or audit records linking the disputed send to an account event.
What account-access records may exist? explains how those datasets fit together.
Look for a change in practical control¶
A compromise often becomes clearer when events are placed into a timeline.
No single event has to carry the whole conclusion.
An unfamiliar IP address may have an innocent explanation. A rule change may be legitimate. The value comes from testing the combined sequence against the account holder's normal activity and the disputed message.
Existing sessions and applications matter¶
A hostile user may not need a fresh conventional login at the time of the send.
Activity may continue through:
- a previously created session;
- a trusted device;
- a connected application;
- delegated authority; or
- another token-based route.
That is why a search for “the suspicious login nearest the email” can miss the real access path.
Preserve while containing active risk¶
If the account is still exposed, protective action may be necessary before every investigative question is resolved.
That may include revoking sessions, resetting credentials, removing unauthorised methods or rules, or warning affected parties under the organisation's normal process.
Record what was changed, by whom and when.
Containment changes the evidence state. It should be documented, not postponed simply to preserve an untouched account.
Keep the conclusion in layers¶
That the genuine mailbox submitted the message during a period of suspicious or unauthorised account activity.
Who controlled the hostile session, device or application responsible for that activity.
The worked example of a genuine account used after compromise shows how those records can be combined into a practical account-control timeline.
The practical point is: genuine provider delivery and account compromise can exist at the same time. Follow the account history, sessions, rules and devices rather than treating valid sending infrastructure as proof of the account holder's authorship.