Emails being labeled as phishing incorrectly

2026-05-15T14:28:25.7733333+00:00

Hello,

After this recent update, we are seeing emails that should be sent to the users are being labeled as phishing. The emails in question are from our [Moderator note: Personally Identifiable Information removed] ogs notifying employees of any comments on Customer Complaint cases. Due to this store employees are missing valuable updates to cases being worked.

Is there a work around to have these emails taken off the phishing list?

Outlook | Web | Outlook on the web for business | Security
0 comments No comments

3 answers

Sort by: Most helpful
  1. Ruby-N 13,320 Reputation points Microsoft External Staff Moderator
    2026-05-15T17:35:13.79+00:00

    Dear @Pottinger Christopher F (he/him/his)

    Good day, and I appreciate the clear explanation of your concern.   

    These messages are likely being flagged by Microsoft 365 anti-phishing filters as spoofing or impersonation. This can happen more often after updates or when security settings are stricter, especially if sender authentication isn’t fully aligned (e.g., from domain doesn’t match DKIM or MAIL FROM), which can lead to false positives. 

    Please see the following workarounds that will help you verify the issue:  

    Note: The steps below must be performed by your organization’s IT admin. If you are an end-user, please contact your IT admin for assistance. 

    Step 1: Identify which protection triggered the detection 

    Go to Microsoft Defender portal: https://security.microsoft.com/reportsubmission  

    Open Submissions > Submit one of the affected emails for analysis. 

    Review the results to confirm whether it was flagged as spoofing or impersonation. 

    This step helps determine the exact cause and guides the correct mitigation approach. 

    Step 2: If the issue is spoof intelligence or general filtering 

    In the Submissions page, select the email you submitted: 

    • Choose “I have confirmed this is clean”. 
    • Select “Allow this message”. 

    User's image

    This creates an allow entry in the Tenant Allow Block List. It helps prevent repeated false positives while keeping overall protection intact. 

    Note: Allow entries created this way typically expire after 45 days of inactivity, except for spoofed sender entries which may not expire. 

    This article provides further guidance on the topic: Manage submissions - Microsoft Defender for Office 365 | Microsoft Learn 

    Step 3: If the issue is impersonation detection 

    Go to Microsoft 365 Defender portal > Email & collaboration > Navigate to Policies and rules and open Threat policies > Select Anti phishing policy. 

    User's image

    Edit the policy that detected the message. 

    Add the sender domain or address under Trusted senders and domains. 

    User's image

    Step 4: Improve sender authentication alignment 

    Review the sending domain configuration: 

    • Ensure SPF passes. 
    • Ensure DKIM is enabled and passes. 

    User's image

    • Align DKIM domain or MAIL FROM domain with the From domain. 

    You can refer to the following documentation for SPF, DKIM and MAIL FROM domain configuration: 

    Anti-phishing policies in Microsoft 365 - Microsoft Defender for Office 365 | Microsoft Learn 

    This is usually configured on the sending platform side and plays an important role in reducing false positives over time. 

    Step 5: Reduce impact during investigation 

    You can suggest a workaround for end users: 

    • In Outlook or Outlook on the web. 
    • Open the message in Junk folder > Select Report and choose Not junk. 

    User's image

    • This moves the message back to Inbox and provides feedback to the system. 

    (Optional) The IT admin may consider configuring quarantine policies to grant users certain permissions.

    • Go to Microsoft Defender portal > Navigate to Quarantine policies. 
    • Configure notification frequency such as every four hours or daily. 
    • Allow users to review and release messages if appropriate. 

    User's image

    This ensures important emails are not missed while adjustments are being made. 

    Step 6: Contact Microsoft Support 

    If the issue continues after these steps, the best next step is to raise a support request with Microsoft via the Microsoft 365 Admin Center > Support > Help & Support to allow deeper investigation into the message classification and policy behavior. 

    As a moderator, I don't have the tools to investigate your specific account directly because this is a user-to-user support forum. Moderators and contributors, including external Microsoft employees, cannot directly intervene in Microsoft product features or access back-end systems. Our role is limited to providing technical guidance on reported issues, requests, or ideas. However, I will try my best to guide you as clearly as possible.    

    I hope this information is helpful. If you have any questions or need further support, please don’t hesitate to reach out at any time. 

    Thank you for your patience and understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have any extra questions about this answer, please click "Comment"           

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread

    Was this answer helpful?

    0 comments No comments

  2. Pottinger, Christopher F (he/him/his) 0 Reputation points
    2026-05-15T17:09:49.6933333+00:00

    Is there a solution that the TD technology team does so the store users don't have to take any steps to correct? We have over 8K users in the system so having all of them do these steps might not be an option?

    Was this answer helpful?

    0 comments No comments

  3. AI answer

    2026-05-15T14:28:39.0433333+00:00

    Salesforce notification mail is being treated as phishing (a false positive). Use Defender for Office 365 tools and Outlook features to both fix the immediate issue and prevent recurrences.

    Recommended steps:

    1. Ask affected users to report the messages as “Not junk”
      • In Outlook or Outlook on the web, users should use the built‑in Report button and choose Not junk for these Salesforce notifications. This both corrects the classification for the user and provides samples for analysis.
      • This is the standard first step for handling legitimate messages that are incorrectly blocked or filtered.
    2. Add Salesforce notification senders to Safe Senders (user side)
      • Users can add the Salesforce notification address or domain to their Safe Sender List in Outlook so future messages are less likely to be treated as junk/phishing.
    3. Triage user‑reported messages and submit to Microsoft
      • In the Microsoft Defender portal, go to the Submissions page and use the User reported tab to find these Salesforce messages.
      • From there, submit representative samples to Microsoft for analysis. This helps determine why they are being flagged as phishing and can improve backend detection.
    4. Create an allow entry for the Salesforce sender (admin side)
      • While submitting samples to Microsoft, an admin can judiciously create an allow entry for the Salesforce notification sender domain or specific addresses in the Tenant Allow/Block List. This is the main “workaround” to stop these specific notifications from being treated as phishing, provided the sender is trusted.
    5. Investigate why they are flagged as phishing
      • For a long‑term fix, review:
        • Message headers (SPF/DKIM/DMARC results, spam/phish verdicts).
        • Anti‑spam and anti‑phishing policies that might be catching Salesforce patterns.
      • Adjust policies only as needed, keeping overall protection in mind.
    6. Educate users
      • Explain that these Salesforce messages are legitimate and how to distinguish them from real phishing, and remind them to use the Report button appropriately (Not junk vs Phishing) so filters learn correctly.

    These steps will both restore delivery of Salesforce case‑comment notifications and reduce the chance that similar business‑critical notifications are misclassified in the future.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.