Skip to main content
All CollectionsPhishArm
Phisharm-MS integration: How to forward junk emails to Phisharm?
Phisharm-MS integration: How to forward junk emails to Phisharm?
K
Written by Karthek S
Updated over 3 months ago

The following steps will help you add the Mail flow rules:

  1. Login to your Microsoft 365 Defender portal and navigate Settings > Email & collaboration.

  2. Now, navigate to Mail flow > Rules > click + icon (add new rule). You can copy the existing rules for future reference.

  3. From the + icon (add new rule) drop-down, select Create new rule…

  4. Enter Forward Junk Emails to PhishArm in the name field.

  5. From the Apply this rule if… drop-down, select The recipient address includes…

  6. In the specified words or phrases pop-up, paste the Internal Mailbox email.

  7. Click on the + icon next to the condition to add another rule.

  8. In the And The message headers.... drop-down, select includes any of these words.

    Enter 'X-Forefront-Antispam-Report' and 'SFV:SPM' in the corresponding fields as per the above screenshot.

  9. As we finish the condition, we have to define the action.
    From the Do the following… drop-down, select Add receipients and from the options, select to the To box.

  10. Click on Select On, and a window with the list of all the contacts will appear. Search for the right-hand reporting email, i.e., [email protected], and select it. Then click on the save button to save the recipient.

  11. Now Click on the Next button and set the following values to

  12. Click on Next and then the Finish button. The rule will appear in the list.

  13. Now, we need to edit this rule further. Click on the rule, and it will open the slider. Enable this rule by clicking the toggle and then clicking on the rule settings. Change the Priority to 0 and click on the save button.

  14. After that, the rule will appear enabled at the top of the list.

    The configuration has been successfully set up :)

Did this answer your question?