Fix Microsoft 365 Users Not Receiving One-Time Passcode (OTP) Emails
Question details
Users are unable to receive automated one-time passcode (OTP) emails from a specific external organization, even though standard emails from other domains arrive normally and the sender has been added to the Safe Senders list.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- A team needs to log into a third-party portal but is blocked because the required authentication passcode emails are failing to reach their Microsoft 365 inboxes.
- Observed behavior
- The expected one-time passcode emails do not appear in the inbox or junk folder, despite user-level Safe Senders configurations, while generic emails from domains like Gmail are delivered successfully.
Ensure you have Exchange Administrator or Global Administrator privileges in your Microsoft 365 tenant, as investigating tenant-level mail flow and quarantine requires admin access.
Use Message Trace and Check Microsoft Defender Quarantine
Identifying exactly where the email was blocked or routed within your tenant is the most effective way to resolve delivery failures.
Often, automated emails from third-party organizations are flagged by Microsoft 365 security policies before they ever reach the user's mailbox, making user-level Safe Senders lists ineffective.
Navigate to admin.exchange.microsoft.com and log in with your Microsoft 365 administrator credentials.
Go to Mail flow > Message trace. Enter the sender's email address and the recipient's address, then run the trace to see if the message was rejected, blocked, or delivered elsewhere.
Open the Microsoft 365 Defender portal. Navigate to Email & Collaboration > Review > Quarantine to see if the OTP emails were intercepted and flagged as spam, phishing, or bulk mail.
If you find the missing passcode emails in quarantine, select them and choose 'Release' to deliver them to the intended recipient's inbox.
Review Anti-Spam Policies and Sender Authentication
Sometimes external organizations have misconfigured SPF, DKIM, or DMARC records, causing Microsoft 365 to reject their automated emails.
Submit a Microsoft 365 Support Request
If message traces show no record of the email hitting your tenant, the issue might be on the sender's side or require advanced Microsoft support to unblock an IP.
Looking for a Lightweight, Cost-Effective Office Suite?
While troubleshooting complex Microsoft 365 email server issues requires administrator intervention, you don't need heavy corporate software for your daily document tasks. WPS Office is a free, lightweight, and highly compatible alternative to Microsoft Office, perfect for creating, editing, and managing your documents without the administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website and download the free version for your operating system.
- 2. Install the Software: Run the setup file and follow the on-screen instructions to complete the fast installation process.
- 3. Open Your Documents: Launch WPS Office and immediately start opening, editing, and saving your Microsoft Office files without any compatibility issues.

Frequently Asked Questions
Why are emails from Gmail delivered but not OTP emails from a specific organization?
Organizations sending automated OTPs sometimes have misconfigured email authentication records (SPF, DKIM, DMARC), causing stringent security filters in Microsoft 365 to reject or quarantine them. Major providers like Gmail usually have properly configured authentication, so their emails pass through the filters.
Does adding a sender to the Safe Senders list guarantee delivery?
No. The Safe Senders list in Outlook applies at the user mailbox level. If the email is blocked at the tenant level by Microsoft Defender anti-spam, anti-phishing, or malware policies, it will never reach the user's mailbox to be evaluated against their personal Safe Senders list.
What if the Exchange Message Trace shows no record of the email?
If the message trace in the Exchange Admin Center shows no results for the expected email, the message never reached your Microsoft 365 tenant. The sender's email server likely failed to send it, or it was dropped before reaching Microsoft's network. You will need to contact the sending organization's support team.




