There have been reports of links in Google Calendar notification emails being clicked without any user interaction.
Based on collected original email samples and looking at similarities in header contents, the sender is always Google Calendar <firstname.lastname@example.org>.
To resolve the issue:
- Go to the CAS console > ATP Policy Exchange Online > Web Reputation.
- On Web Reputation, configure the Approved Header Field with the following entry:
Value: Google Calendar <email@example.com>
- Click the Save button.
- Wait for at least fifteen (15) minutes before sending test emails.