Managing security settings and protections in Outlook on the web for business
Salesforce notification mail is being treated as phishing (a false positive). Use Defender for Office 365 tools and Outlook features to both fix the immediate issue and prevent recurrences.
Recommended steps:
- Ask affected users to report the messages as “Not junk”
- In Outlook or Outlook on the web, users should use the built‑in Report button and choose Not junk for these Salesforce notifications. This both corrects the classification for the user and provides samples for analysis.
- This is the standard first step for handling legitimate messages that are incorrectly blocked or filtered.
- Add Salesforce notification senders to Safe Senders (user side)
- Users can add the Salesforce notification address or domain to their Safe Sender List in Outlook so future messages are less likely to be treated as junk/phishing.
- Triage user‑reported messages and submit to Microsoft
- In the Microsoft Defender portal, go to the Submissions page and use the User reported tab to find these Salesforce messages.
- From there, submit representative samples to Microsoft for analysis. This helps determine why they are being flagged as phishing and can improve backend detection.
- Create an allow entry for the Salesforce sender (admin side)
- While submitting samples to Microsoft, an admin can judiciously create an allow entry for the Salesforce notification sender domain or specific addresses in the Tenant Allow/Block List. This is the main “workaround” to stop these specific notifications from being treated as phishing, provided the sender is trusted.
- Investigate why they are flagged as phishing
- For a long‑term fix, review:
- Message headers (SPF/DKIM/DMARC results, spam/phish verdicts).
- Anti‑spam and anti‑phishing policies that might be catching Salesforce patterns.
- Adjust policies only as needed, keeping overall protection in mind.
- For a long‑term fix, review:
- Educate users
- Explain that these Salesforce messages are legitimate and how to distinguish them from real phishing, and remind them to use the Report button appropriately (Not junk vs Phishing) so filters learn correctly.
These steps will both restore delivery of Salesforce case‑comment notifications and reduce the chance that similar business‑critical notifications are misclassified in the future.
References: