Managing security settings and protections in Outlook on the web for business
Dear @Pottinger Christopher F (he/him/his),
Good day, and I appreciate the clear explanation of your concern.
These messages are likely being flagged by Microsoft 365 anti-phishing filters as spoofing or impersonation. This can happen more often after updates or when security settings are stricter, especially if sender authentication isn’t fully aligned (e.g., from domain doesn’t match DKIM or MAIL FROM), which can lead to false positives.
Please see the following workarounds that will help you verify the issue:
Note: The steps below must be performed by your organization’s IT admin. If you are an end-user, please contact your IT admin for assistance.
Step 1: Identify which protection triggered the detection
Go to Microsoft Defender portal: https://security.microsoft.com/reportsubmission
Open Submissions > Submit one of the affected emails for analysis.
Review the results to confirm whether it was flagged as spoofing or impersonation.
This step helps determine the exact cause and guides the correct mitigation approach.
Step 2: If the issue is spoof intelligence or general filtering
In the Submissions page, select the email you submitted:
- Choose “I have confirmed this is clean”.
- Select “Allow this message”.
This creates an allow entry in the Tenant Allow Block List. It helps prevent repeated false positives while keeping overall protection intact.
Note: Allow entries created this way typically expire after 45 days of inactivity, except for spoofed sender entries which may not expire.
This article provides further guidance on the topic: Manage submissions - Microsoft Defender for Office 365 | Microsoft Learn
Step 3: If the issue is impersonation detection
Go to Microsoft 365 Defender portal > Email & collaboration > Navigate to Policies and rules and open Threat policies > Select Anti phishing policy.
Edit the policy that detected the message.
Add the sender domain or address under Trusted senders and domains.
Step 4: Improve sender authentication alignment
Review the sending domain configuration:
- Ensure SPF passes.
- Ensure DKIM is enabled and passes.
- Align DKIM domain or MAIL FROM domain with the From domain.
You can refer to the following documentation for SPF, DKIM and MAIL FROM domain configuration:
Anti-phishing policies in Microsoft 365 - Microsoft Defender for Office 365 | Microsoft Learn
This is usually configured on the sending platform side and plays an important role in reducing false positives over time.
Step 5: Reduce impact during investigation
You can suggest a workaround for end users:
- In Outlook or Outlook on the web.
- Open the message in Junk folder > Select Report and choose Not junk.
- This moves the message back to Inbox and provides feedback to the system.
(Optional) The IT admin may consider configuring quarantine policies to grant users certain permissions.
- Go to Microsoft Defender portal > Navigate to Quarantine policies.
- Configure notification frequency such as every four hours or daily.
- Allow users to review and release messages if appropriate.
This ensures important emails are not missed while adjustments are being made.
Step 6: Contact Microsoft Support
If the issue continues after these steps, the best next step is to raise a support request with Microsoft via the Microsoft 365 Admin Center > Support > Help & Support to allow deeper investigation into the message classification and policy behavior.
As a moderator, I don't have the tools to investigate your specific account directly because this is a user-to-user support forum. Moderators and contributors, including external Microsoft employees, cannot directly intervene in Microsoft product features or access back-end systems. Our role is limited to providing technical guidance on reported issues, requests, or ideas. However, I will try my best to guide you as clearly as possible.
I hope this information is helpful. If you have any questions or need further support, please don’t hesitate to reach out at any time.
Thank you for your patience and understanding.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have any extra questions about this answer, please click "Comment"
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread