Protecting against Email Bombs with Microsoft Tooling
Email

Protecting against Email Bombs with Microsoft Tooling

Philip Marsh October 5th, 2025 2 min read

As the world becomes more and more connected, and digital technologies continue to evolve, email remains a critical tool for communications both for individuals and for commercial use. Email security has become more and more important, with a significant rise in digital attacks of late targeting critical communication within email. One such threat that has been growing in popularity is the email bomb.

What is an email bomb?

In simple terms, an email bomb typically involves subscribing victims to a large number of newsletter and subscription services. Each of these sends its own email notification to the victim making email triage for legitimate emails very difficult.

But why should I care?

Email bombs are commonly used to obfuscate more nefarious activity. For example, it is harder to spot emails about login attempts or changes to your MFA settings if these are buried amongst hundreds or thousands of emails that have bombed your inbox.

More recently, attackers have used email bombs alongside lures on Microsoft Teams, phone calls, etc. whereby the attacker will impersonate IT Support to gain access to the victim's device to conduct further attack. Microsoft has a great write-up of an example of this here: https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/

💡
Hint: If you're not using Quick Assist as part of your support service, block the URL as an indicator to reduce your attack surface!

Protecting against email bombs

Microsoft Defender for Office have released a new solution to help protect against the sudden rise of email bombing attacks. One such feature is limiting the influx of emails to a mailbox. By analysing a baseline of message volumes across different sources and time intervals, a new detection can then leverage historical patterns of the sender and any signals that may indicate spam content. These messages are then sent to the Junk folder of Outlook, instead of the inbox.

Advanced hunting

An advanced hunting query can be used to detect mail bombing attacks. This can then be used to create a custom detection to alert the SOC team whenever a mail bombing attack is detected. For example:

EmailEvents 
   | where Timestamp > ago(1d) 
   | where DetectionMethods contains "Mail bombing" 
   | project Timestamp, NetworkMessageId, SenderFromAddress, Subject, ReportId

In the portal

SOC analysts can now view the new Detection technology as Mail bombing within the following surfaces: Threat Explorer, Email entity page and Advanced Hunting empowering them to investigate, filter and hunt for threats related to mail bombing.

Philip Marsh

Philip Marsh

Writing practical notes on Microsoft security, identity protection, detections, and building safer systems.

View all posts