Files
management-scripts/rmm/M365-EnableSuspiciousEmailDisclaimer.ps1
2026-10-01 09:39:44 -04:00

247 lines
9.8 KiB
PowerShell

# Settings
$UserPrincipalName = "admin@constructtechservices.com"
$EnableExternalTagging = $true
$ExternalTaggingAllowedDomains = @{Add="emberkom.com", "ef-capital.com", "elysionconstruction.com", "elysioncreations.com", "tesseractrentals.com", "arcadiapropertyservices.com"}
$BypassSenderDomains = @(
"emberkom.com",
"notify.emberkom.com",
"ef-capital.com",
"elysionconstruction.com",
"elysioncreations.com",
#"constructtechservices.com",
"tesseractrentals.com",
"arcadiapropertyservices.com"
)
$SetImpersonationRule = $true
$SetSuspiciousEmailRule = $true
$SetGeneralExternalEmailRule = $true
# Connect to EOL
Connect-ExchangeOnline -UserPrincipalName $UserPrincipalName
# Enable/disable external tagging for Outlook clients
If ( (Get-ExternalInOutlook).Enabled -ne $EnableExternalTagging ) {
If ( $EnableExternalTagging ) {
Write-Output "Enabling external email tagging"
} Else {
Write-Output "Disabling external email tagging"
}
If ( $EnableExternalTagging -and $ExternalTaggingAllowedDomains ) {
Set-ExternalInOutlook -Enabled $EnableExternalTagging -AllowList $ExternalTaggingAllowedDomains
} Else {
Set-ExternalInOutlook -Enabled $EnableExternalTagging
}
}
# Impersonation Rule
If ( $SetImpersonationRule ) {
$ImpersonationEmailDisclaimerTitle = "Warning:"
$ImpersonationEmailDisclaimerText = "This appears to be a fradulent email attempting to impersonate someone inside your organization. Do not click on links or open attachments unless you are certain this email is safe."
$ImpersonationRuleName = "Impersonation Warning"
$ImpersonationDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
<tr>
<td style="background:#dc3232;padding:5pt 2pt 5pt 2pt"></td>
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
<div style="color:#222222;">
<span style="color:#222; font-weight:bold;">' + $ImpersonationEmailDisclaimerTitle + ' </span>' + $ImpersonationEmailDisclaimerText + '
</div>
</td>
</tr>
</table>
<br/>'
# Set the transport rule for user impersonation
$DisplayNames = (Get-EXOMailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox).DisplayName
$ImpersonationTransportRule = Get-TransportRule | Where-Object { $_.Name -eq $ImpersonationRuleName }
If ( $ImpersonationTransportRule ) {
Write-Output "Updating transport rule: ${ImpersonationRuleName}"
Set-TransportRule -Identity $ImpersonationRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-HeaderMatchesMessageHeader From `
-HeaderMatchesPatterns $DisplayNames `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule updated"
} Else {
Write-Output "Creating transport rule: ${ImpersonationRuleName}"
New-TransportRule -Name $ImpersonationRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-HeaderMatchesMessageHeader From `
-HeaderMatchesPatterns $DisplayNames `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule created"
}
}
# Suspicious Email Rule
If ( $SetSuspiciousEmailRule ) {
$SuspiciousEmailDisclaimerTitle = "Caution:"
$SuspiciousEmailDisclaimerText = "This is a suspicious email from outside your organization. Please be cautious when clicking links or opening attachments."
$SuspiciousEmailRuleName = "Suspicious Email Warning"
$SuspiciousEmailDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
<tr>
<td style="background:#ffb900;padding:5pt 2pt 5pt 2pt"></td>
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
<div style="color:#222222;">
<span style="color:#222; font-weight:bold;">' + $SuspiciousEmailDisclaimerTitle + ' </span>' + $SuspiciousEmailDisclaimerText + '
</div>
</td>
</tr>
</table>
<br />'
# This list is copied from: https://github.com/SwiftOnSecurity/PhishingRegex/blob/master/PhishingRegex.txt
$SuspiciousEmailPatterns = @(
'blocked\ your?\ online',
'suspicious\ activit',
'updated?\ your\ account\ record',
'Securely\ \S{3,4}\ one(\ )?drive',
'Securely\ \S{3,4}\ drop(\ )?box',
'Securely\ \S{3,4}\ Google\ Drive',
'sign\ in\S{0,7}(with\ )?\ your\ email\ address',
'Verify\ your\ ID\s',
'dear\ \w{3,8}(\ banking)?\ user',
'chase\S{0,10}\.html"',
'\b(?<=https?://)(www\.)?icloud(?!\.com)',
'(?<![\x00\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5A])appie\W',
'/GoogleDrive/',
'/googledocs?/',
'/Dropfile/',
'limit\ (and\ suspend\ )?your\ account',
'\b(?<=https?://)(?!www\.paypal\.com/)\S{0,40}pa?y\S{0,2}al(?!\S*\.com/)',
'sitey\.me',
'myfreesites\.net',
'/uploadfile/',
'/\S{0,3}outloo\S{0,2}k\S{1,3}\W',
'\b(?<=https?://webmail\.)\S{0,40}webmail\w{0,3}(?!/[0-9])(?!\S{0,40}\.com/)',
'owaportal',
'outlook\W365',
'/office\S{0,3}365/',
'-icloud\Wcom',
'pyapal',
'/docu\S{0,3}sign\S{1,4}/',
'/helpdesk/',
'pay\Sa\S{0,2}login',
'/natwest/',
'/dro?pbo?x/',
'%20paypal',
'\.invoice\.php',
'security-?err',
'/newdropbox/',
'/www/amazon',
'simplefileupload',
'security-?warning',
'-(un)?b?locked',
'//helpdesk(?!\.)',
'\.my-free\.website',
'mail-?update',
'\.yolasite\.com',
'//webmail(?!\.)',
'\.freetemplate\.site',
'\.sitey\.me',
'\.ezweb123\.com',
'\.tripod\.com',
'\.myfreesites\.net',
'mailowa',
'-icloud',
'icloud-',
'contabo\.net',
'\.xyz/',
'ownership\ validation\ (has\ )?expired',
'icloudcom',
'\w\.jar(?=\b)',
'/https?/www/',
'\.000webhost(app)?\.com',
'is\.gd/',
'\.weebly\.com',
'\.wix\.com',
'tiny\.cc/',
'\.joburg',
'\.top/'
)
# Set the transport rule for suspicious emails
$SuspiciousEmailRule = Get-TransportRule | Where-Object { $_.Name -eq $SuspiciousEmailRuleName }
If ( $SuspiciousEmailRule ) {
Write-Output "Updating transport rule: ${SuspiciousEmailRuleName}"
Set-TransportRule -Identity $SuspiciousEmailRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-SubjectOrBodyMatchesPatterns $SuspiciousEmailPatterns `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $SuspiciousEmailDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule updated"
} Else {
Write-Output "Creating transport rule: ${SuspiciousEmailRuleName}"
New-TransportRule -Name $SuspiciousEmailRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-SubjectOrBodyMatchesPatterns $SuspiciousEmailPatterns `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $SuspiciousEmailDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule created"
}
}
# General External Email Rule
If ( $SetGeneralExternalEmailRule ) {
$GeneralExternalEmailDisclaimerTitle = "Notice:"
$GeneralExternalEmailDisclaimerText = "This email came from outside your organization. Please be sure you know the recipient or were expecting this email before clicking on links or opening attachments."
$GeneralExternalEmailRuleName = "External Email Warning"
$GeneralExternalEmailDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
<tr>
<td style="background:#00A0d2;padding:5pt 2pt 5pt 2pt"></td>
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#e5f5fa;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
<div style="color:#222222;">
<span style="color:#222; font-weight:bold;">' + $GeneralExternalEmailDisclaimerTitle + ' </span>' + $GeneralExternalEmailDisclaimerText + '
</div>
</td>
</tr>
</table>
<br/>'
# Set the transport rule for all external emails
$GeneralExternalEmailRule = Get-TransportRule | Where-Object { $_.Name -eq $GeneralExternalEmailRuleName }
If ( $GeneralExternalEmailRule ) {
Write-Output "Updating transport rule: ${GeneralExternalEmailRuleName}"
Set-TransportRule -Identity $GeneralExternalEmailRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule updated"
} Else {
Write-Output "Creating transport rule: ${GeneralExternalEmailRuleName}"
New-TransportRule -Name $GeneralExternalEmailRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule created"
}
}
# Close connection to EOL
Disconnect-ExchangeOnline -Confirm:$false | Out-Null