Gemini: Serious Issue Checking for Phishing Email Anaysis

I asked Gemini to analyze a suspicious Microsoft 365 email that appeared to come from one of my aliases. Gemini concluded that my account might be compromised. Having followed this wrong result could have been uneccesarily costly in terms of time and money. We at CharlesWorks want to save our clients this kind of headache.

My Gemini Phishing Email Analysis

Over the past couple days I noticed what I thought was a phishing email in my Inbox. So I used Gemini first in a phishing email analysis. I like using Microsoft Outlook web mail for my Office 365 account. Having been in the web business in excess of 28 years I am most confident saying it is the most secure 🔐 email to use for one’s business or personal connecting. Whether you are running a business or use email only for personal use, security is a must because our email is tied to many aspects of our lives.

When I see a phishing or otherwise bad actor originated email that perplexes me, I almost always investigate it to learn more about it. This is important to me because one of my purposes in life is to help my web clients avoid what can be difficult issues to avoid concerning their email.

My Suspicious Email Goto AIs

Gemini and ChatGPT are my favorite go to AIs when it comes to checking a suspicious email. They are both quick and easy as long as you have the header information of the email.

However, I was taken aback with my Gemini result. It popped up a warning as shown below – something I don’t recall it having done before. The warning warned me that my account should be treated as potentially compromised until confirmed otherwise. While I would say this is normally good advise – to always prove the account is safe when in doubt – it is an expensive and time consuming endeavor when – like most of my web clients – one has to hire a firm like ours or any IT firm to go through the necessary steps to investigate. That process involves changing all account credentials which can cause a multitude of issues depending on what you have hooked into the account.

This output from Gemini merely proved what all the AI outputs usually indicate: they can be wrong. It also points out the importance of what I choose: a second opinion. My second opinions are in the form of using one to three separate AIs to examine a problem of this nature. If they all agree, great! When two out of three agree, that’s a good indication. But if none agree, I probably an not asking the right question.

The most important thing I learned in my master’s degree studies: it’s all about knowing the right questions to ask.

Here is what I asked Gemini followed by its WRONG assessment, including the warning message before its output. My identical ask of ChatGPT follows in the next post:

I am trying to find out where this message came from and why it ends up in my Inbox. I use Outlook web mail and I believe it may be a phishing message but the option to “Report” it as either spam or phishing do not show up when I right click on it (although that option shows on other emails). It indicates it was sent by ro***@**********ks.com but there is only an alias for ro***@**********ks.com to su*****@**********ks.com and mail could not have been sent from that nonexistent address:
This message was created automatically by mail delivery software. Your email message was not delivered to the intended recipients because malware was detected.
— Additional Information —:
Subject: -Caller left 34s September 19, 2026 – cJIBRTd8.
Sender: ro***@**********ks.com
Time received: 9/19/2026 4:10:15 AM
Message ID:<[1789791014415.e37452553538c5d1-JFZGS42DN5WW25LONFRWC5DJN5XFA3DBORTG64TNFVIHE33EFVGVOMKQPREUCTKTKNIFE7CTKNIFERLNMFUWY7CFPBXVG3LUOA======@charlesworks.com]>
Detections found:
Vrecording_Erecorded_ATT61.svg..        Script/SvgStealer.ADX!MTB
The “view Massage” option in my Outlook web mail shows me this:
Received: from PH8PR11MB7024.namprd11.prod.outlook.com (2603:10b6:510:220::19)
 by SAVPR11MB9574.namprd11.prod.outlook.com with HTTPS; Sat, 19 Sep 2026
 04:10:18 +0000
Received: from SmtpServer.Submit by PH8PR11MB7024 with Microsoft SMTP Server
 id 15.21.406.11; Sat, 19 Sep 2026 04:10:18 +0000
MIME-Version: 1.0
Content-Type: text/plain; charset=”utf-8″
From: Postmaster <po********@**********ks.com>
Subject: Undeliverable message
Content-Transfer-Encoding: quoted-printable
To: <su*****@**********ks.com>
Message-ID:
 <7f**********************************@*********************************ok.com>
Return-Path: po********@**********ks.com
Date: Sat, 19 Sep 2026 04:10:18 +0000
X-MS-Exchange-Organization-ExpirationStartTime: 19 Sep 2026 04:10:18.2837
 (UTC)
X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
X-MS-Exchange-Organization-Network-Message-Id:
 29b93226-d43b-478f-fcd1-08df1603ea60
X-MS-Exchange-Organization-AuthSource: PH8PR11MB7024.namprd11.prod.outlook.com
X-MS-Exchange-Organization-AuthAs: Internal
X-MS-Exchange-Organization-AuthMechanism: 05
X-MS-Exchange-Parent-Message-Id:
 <[1789791014415.e37452553538c5d1-JFZGS42DN5WW25LONFRWC5DJN5XFA3DBORTG64TNFVIHE33EFVGVOMKQPREUCTKTKNIFE7CTKNIFERLNMFUWY7CFPBXVG3LUOA======@charlesworks.com]>
Auto-Submitted: auto-generated
X-MS-Exchange-Generated-Message-Source: DC Post Content Filter Agent
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: PH8PR11MB7024:EE_|SAVPR11MB9574:EE_
X-MS-Exchange-Organization-SCL: 1
X-Microsoft-Antispam:
 BCL:0;ARA:13230040|1930700014|366016|56012099006|12063799003|10067099003|18002099003|41050700001;
X-Forefront-Antispam-Report:
 CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:;PTR:;CAT:NONE;SFS:(13230040)(1930700014)(366016)(56012099006)(12063799003)(10067099003)(18002099003)(41050700001);DIR:INT;
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Sep 2026 04:10:18.2834 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id:
 29b93226-d43b-478f-fcd1-08df1603ea60
X-MS-Exchange-CrossTenant-AuthSource: PH8PR11MB7024.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH8PR11MB7024
X-MS-Exchange-Organization-MessageDirectionality: Originating
X-MS-Exchange-Transport-EndToEndLatency: 00:00:00.6486099
X-MS-Exchange-Processed-By-BccFoldering: 15.21.0428.008
X-MS-Exchange-ExternalInOutlookResult: NotEnabled
X-Microsoft-Antispam-Mailbox-Delivery:
ucf:0;jmr:0;auth:0;dest:I;ENG:(910005)(944506478)(944626604)(920097)(425001)(930201)(20251009189)(140003);

X-Microsoft-Antispam-Message-Info:xuNr8XT2UiI8kmeQ7vTwjjloBhzPu/NOSnDZ8nYwnyjaERxMG5YzKr35E2fY/Ja+bMQAd9LPy0fbIn9ejg8cTQVMmPfNLeEQ2Krgx1F6DxdeAufyJfN0jjFjkgr4eUrr2/bahM6aMBHXalIKcAy0HqlN100CggPEgGABIWOyuhttlvvX/Tdl0OViDHgOtPw9lCUi1vx3u/zwNovLrZltOsoVBKT/yggFMCquH/6gm1d95gnQwZhhRUYH/lVN/UZfdx1XLWUt3eaO5VMl0CHnw/MKpu8dDHsYtn9u89Q1Zk8lS0MPCxKuuvBkGfobsYvR+kOsCf7+Arz/ltMO99w5DuocxkuDLLFNO4DfSWRkw+Ovm2XBelFakkrv0WHSK4q+08Allgeox1hWGEIeknDBwIWj0t6JkmiqIW3FWVhFzFqArsBfbqZaxGWo3PZOFgTBpRoALq3aJ86kISw1OZVs9IBDZYht0367UoWe0GImW808FeuiC1efb1Emfx686OW0NddoP36TMqjiEaOBKCrkSklyc1Gk7wEPX1vDGA+u0tCkEnOl3Pj/aqaQqXwirS9F0ZTRdRwUxpS6SR0fb3IRUdcGG++r8+BxYwHa1vOSlSC8u8/Gy1ZJIK/fxdcp2A35orzJRsFY4ftB+TK5nYos5allhlQdZEzdYMeD/nbof0pj81gJ/Z1dCCgVXF8NicNIJAlgFMbkCDqPRay9qsAhg4zM/bXaghQAqwCw1PpGHnOn0oetsOiyqpNJpj9SVGvSIRJT2T6bVN0m/pjRXFujF8cwU+AZq6wPtCxvdRodrAX63c4ZUjcykjCZmsC9I7fL

Potential Account Compromise This message indicates an outbound email containing malware was actively submitted through your Microsoft 365 tenant using the robin@charlesworks.com identity. You should treat the underlying mailbox (support@charlesworks.com) as potentially compromised until confirmed otherwise.

Gemini AI LogoWhy You See This and Why “Report” Is Missing

  1. Why the “Report” button is missing:
    This email is an authentic, system-generated Non-Delivery Report (NDR) from your own Microsoft 365 tenant (From: Postmaster <po********@**********ks.com>). The headers contain X-MS-Exchange-Organization-AuthAs: Internal and Auto-Submitted: auto-generated. Outlook intentionally disables the “Report Phishing” or “Report Junk” options on internal system messages from your own postmaster.
  2. Where the message came from:
    The NDR was generated by Microsoft’s filter (DC Post Content Filter Agent). The filter intercepted an outbound message carrying a malicious SVG payload (Script/SvgStealer.ADX!MTB disguised as a voicemail file), blocked delivery to the external recipient, and generated a bounce back to the sender.
  3. Why it landed in your Inbox:
    Because the NDR is an authentic system communication from postmaster@, it received an internal Spam Confidence Level of SCL: 1 (SFV: NSPM — non-spam) and was delivered straight to the Inbox (dest: I).
  4. How mail was sent from an alias:
    Exchange Online supports “Send as Alias.” If someone obtains access to su*****@**********ks.com—via compromised credentials, session hijacking, or basic SMTP submission—they can authenticate as the primary account and send mail appearing from any configured alias (ro***@**********ks.com). It could also originate from an internal relay connector if IP authentication is loosely scoped.

Immediate Troubleshooting Steps

1.Reset Credentials and Terminate Active Sessions:Immediate Priority.

Change the password for su*****@**********ks.com in the Microsoft 365 admin center, and click Sign out of all sessions to revoke any stolen refresh tokens or active web sessions.
Verification: Check the user status in the Microsoft 365 Admin Center to confirm session revocation was executed.

2.Trace the Originating Message in Exchange:Investigation.

In the Exchange Admin Center (EAC), navigate to Mail flow > Message trace and search using the Parent Message ID from the header:
1789791014415.e37452553538c5d1-JFZGS42DN5WW25LONFRWC5DJN5XFA3DBORTG64TNFVIHE33EFVGVOMKQPREUCTKTKNIFE7CTKNIFERLNMFUWY7CFPBXVG3LUOA======@charlesworks.com
Examine the message events to locate the client IP address, authentication status, and the intended external recipient.
Verification: Confirm the trace displays the original submission method and whether it used authenticated SMTP or an Exchange connector.

3.Check Entra ID (Azure AD) Sign-in Logs:Log Review.

In the Entra admin center, review the sign-in logs for su*****@**********ks.com filtered by User sign-ins (non-interactive) and User sign-ins (interactive) around 04:10 UTC on September 19, 2026. Look for unfamiliar IP addresses, unexpected geographical locations, or connections from client apps like “Exchange ActiveSync” or “Other clients” (SMTP).
Verification: Ensure all successful sign-ins match known IP addresses and approved devices.

4.Disable Authenticated SMTP on the Mailbox:Remediation.

Spam bots frequently use compromised credentials via basic SMTP AUTH on port 587. If you do not have software or hardware specifically sending automated mail via SMTP through this mailbox, turn off SMTP AUTH for su*****@**********ks.com under Mailbox settings > Email apps.
Verification: Verify in the admin center or via PowerShell that Authenticated SMTP shows as disabled.

Leave a Reply

Your email address will not be published. Required fields are marked *