Fix Microsoft 365 Emails Missing SPF, DKIM, and DMARC Results
Question details
User needs to resolve an issue where specific Microsoft 365 messages are sent to the Junk folder due to missing SPF, DKIM, and DMARC authentication results in the headers.

- Product
- Microsoft 365 Exchange
- Device & OS
- not provided
- Scenario
- Receiving emails where specific recipients experience false positives in spam filtering because authentication results are not being recognized.
- Observed behavior
- Emails are incorrectly routed to the Junk folder with a Spam Confidence Level (SCL) of 6, and the message headers are missing expected authentication results, despite passing for other recipients.
Ensure you have Microsoft 365 global administrator or Exchange administrator privileges to access the Exchange Admin Center and modify mail-flow rules.
Create an Exchange Mail-Flow Rule to Bypass Spam Filtering
Set up a temporary Exchange mail-flow rule to modify the Spam Confidence Level (SCL) for affected accounts while investigating the root cause.
Since authentication results are missing in headers for specific users, the email client or an intermediate routing server might be stripping or failing to recognize these headers.
To prevent legitimate emails from going to Junk while you investigate the mail-flow topology, you can create a temporary Exchange mail-flow rule that bypasses spam filtering for the affected recipients.
Log in to the Microsoft 365 admin center with your administrator credentials, expand the left navigation menu, and select 'Exchange'.
In the Exchange admin center, go to 'Mail flow' and select 'Rules' to manage your organization's routing configurations.
Click the '+' icon (or 'Add a rule') and select 'Create a new rule'. Give it a clear, descriptive name such as 'Temporary Spam Filter Bypass for User'.
Under 'Apply this rule if', select the affected recipient. Under 'Do the following', choose 'Modify the message properties', then 'set the spam confidence level (SCL)' to 'Bypass spam filtering'.
Save the rule and wait for it to propagate across your tenant. Monitor the affected user's inbox to confirm messages are no longer sent to Junk.

Looking for a Lightweight Office Suite Alternative?
While resolving Microsoft 365 Exchange and email server configurations, you might also be evaluating your overall software suite. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office for your document, spreadsheet, and presentation needs.
- 1. Visit the official website: Go to the official WPS Office website to find the correct installer for your operating system.
- 2. Download and install: Download the free setup file, run the installer, and follow the simple on-screen instructions.
- 3. Open and edit files: Launch WPS Writer, Spreadsheet, or Presentation to immediately begin working with your existing Microsoft Office files.

Frequently Asked Questions
What does an SCL of 6 mean in Microsoft 365?
A Spam Confidence Level (SCL) of 6 indicates that Exchange Online Protection (EOP) suspects the email is spam. Emails with an SCL of 5 or 6 are automatically routed to the recipient's Junk Email folder by default.
Why do some users see SPF, DKIM, and DMARC results while others don't?
This typically points to a user-specific mail-flow issue. An intermediate server might be stripping headers, a specific client configuration could be ignoring them, or there may be customized transport rules affecting only certain mailboxes within the organization.
How can I view message headers to check for authentication results?
In Outlook, double-click the email to open it in a new window, click File, select Properties, and look at the 'Internet headers' box at the bottom. Search for the 'Authentication-Results' string to verify the status of SPF, DKIM, and DMARC.
Is it safe to leave the spam filter bypass rule on permanently?
No, this is highly discouraged. Bypassing spam filtering entirely leaves the mailbox vulnerable to phishing, malware, and excessive spam. The rule should be strictly temporary until the underlying authentication recognition issue is resolved.




