TFW a client in the financial advising business wants to know whether the stern email purportedly from the SEC is real…
I mean, it really looks valid. I looked hard. Checked the DKIM & ARC sigs. If it is fake, it’s a fake by someone who owns that sec.gov email address. I doubt that one could credibly fake an all-#MS365 cross-tenant message with all the DKIM/DMARC/ARC trimmings.
BUT.
That’s not impossible. It’s how I would run a scam on a CFP, If I did such things.