Hi AMS Admin,
Let me help address your questions by answering them one by one:
1/ Is there a reputation remediation process beyond admin submissions?
Based on the documentations I have researched, there is no expedited reputation remediation button in EOP/Exchange Online that admins can invoke after a restricted sender incident. The listed paths include:
- Remove the affected user/connector from Restricted entities after securing the account
- Submit false positives to Microsoft from the Defender Submissions workflow, especially for inbound replies that are going to Junk with SCL 5 to 9, BCL 7 to 9 or SFV: SPM
- For outbound reputation specifically, suspicious outbound messages are scanned and messages determined to be spam are sent through the high-risk delivery pool, which is intentionally lower reputation and not guaranteed to be accepted by all recipients. Microsoft monitors Microsoft 365 outbound IP reputation and has internal processes for delisting Microsoft IPs when needed
2/ About typical decay timeline
- There isn't a public fixed decay timeline for tenant/domain reputation recovery or high-risk pool routing after an incident. Under most circumstances, all restrictions should be removed within one hour, and transient issues should not exceed 24 hours.
- For high-risk delivery pool routing, if outbound mail is still being classified as suspicious or spam, it can continue to route through HRDP. If the cause is removed, authentication is clean, no new complaints occur, and normal one-to-one traffic resumes, reputation improves but there is still not a guaranteed estimated time.
3/ Can a support engineer verify no residual tenant-level restrictions remains?
Yes, you can reach out to the Microsoft Support directly and ask to verify whether:
- There is/are user(s) are present in Restricted entities
- Any connector is restricted
- There is a tenant-level outbound spam restriction remains.
- Recent outbound messages are not still being routed through the high-risk delivery pool.
- Inbound messages going to Junk are not caused by a tenant policy, transport rule, tenant block entry, spoof intelligence override, connection filter block, or preset security policy conflict.
For references:
That said, the best next step I would like to recommend is to ask your IT admin to create a support ticket from Microsoft 365 Admin Center > Support > Help & Support. This route ensures you can contact a Microsoft support engineer, who can initiate a remote session to investigate backend configurations, run advanced diagnostic tools, and, if necessary, escalate the case to specialized teams with access to internal systems and logs.
As a community moderator, I'm here to guide you, but due to privacy and security limitations, I don’t have access to the backend tools required for a full resolution. For this reason, contacting Microsoft Support via the Admin Center is the most secure and efficient way forward.
If you have any questions or need further assistance, please feel free to share them in the comments on this post so I can continue to support you.
Thank you for your patience and your understanding.
If the answer is helpful, please click "Yes" and kindly upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.