High Volume Anonymous SMTP Relay from Single IP

This rule detects a high volume of successful sign-in attempts to Exchange Online from a single IP address where the UserPrincipalName ends with '@' (indicating an anonymous or malformed UPN) and Conditional Access was not applied. This pattern can be indicative of anonymous SMTP relay abuse, often used for spamming or phishing campaigns.