Fix Exchange Online Incorrectly Quarantining Messages with Specific URLs
Question details
Users are encountering an issue where Exchange Online incorrectly flags and quarantines legitimate emails containing specific URLs as phishing.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- Managing email deliverability and releasing legitimate emails caught by erroneous quarantine policies during a service incident.
- Observed behavior
- Messages containing certain URLs are incorrectly identified as phishing and moved to quarantine because domain creation dates are misclassified as new (Incident EX803530).
Ensure you have Microsoft 365 administrator privileges to access the Service Health dashboard and manage the organizational quarantine portal.
Review Service Health and Release Quarantined Messages
Monitor the incident status through the admin center and manually release legitimate emails blocked by this error.
This is a service-side issue (EX803530) managed by Microsoft. Until the fix is fully deployed, administrators must handle affected emails manually.
Log in to the Microsoft 365 admin center, navigate to Health > Service health, and look for incident EX803530 to track deployment updates.
Go to the Microsoft 365 Defender portal and navigate to Email & collaboration > Review > Quarantine.
Select the incorrectly quarantined messages, verify they are legitimate communications, and click 'Release email' to deliver them to the intended recipients.
Instruct users to avoid repeatedly resending the affected emails until the service-side fix is fully deployed, as this can trigger further spam protections.

Temporarily Adjust Anti-Phishing Policies (Workaround)
If critical business emails are being continuously blocked, administrators can temporarily add trusted domains to policy exceptions.
Need a Reliable Office Suite? Try WPS Office
While Microsoft handles your enterprise email troubleshooting, ensure your team stays productive with WPS Office. It's a free, lightweight, and highly compatible alternative for daily document creation.

Frequently Asked Questions
Why are legitimate emails being quarantined in Exchange Online?
In incident EX803530, a service-side misclassification caused domain creation dates to be evaluated incorrectly as new. This triggered anti-phishing filters, sending safe emails with certain URLs directly to quarantine.
Should I tell users to resend the quarantined emails?
No. Repeatedly resending the affected messages may cause further triggering of spam filters and will not bypass the current quarantine issue. Administrators should release them manually.
How long does it take for Microsoft to resolve incident EX803530?
Resolution timelines vary depending on the global deployment of the service-side fix. Administrators should check the Microsoft 365 Service Health dashboard frequently for the latest status updates and completion estimates.
Can end-users release their own quarantined emails?
This depends on your organization's specific quarantine policy. If policies are set to strict anti-phishing, high-confidence phishing detections typically require a Microsoft 365 administrator to review and release the messages.




