Inbound email that has been delivered as a spoofing attack has not been captured by SMG policies.
Ensure that sender authentication is enabled. Implement the changes given below:
Prevent email spoofing with Messaging Gateway
Phishing prevention best practices for Messaging Gateway