logo
search
Security Policy Errors

Fix Exchange Online Protection Blocking Phishing Simulation Messages

Amos GikundaAmos Gikunda Sep 30, 2026 868 views

Question details

Exchange Online Protection (EOP) is blocking phishing simulation emails despite transport rules setting the spam confidence level to -1.

How to Resolve Exchange Online Protection Blocking Phishing Simulations
Product
Microsoft Exchange Online Protection
Device & OS
not provided
Scenario
Running internal phishing simulation campaigns to train employees and test organizational security.
Observed behavior
Phishing simulation messages are blocked by antimalware filtering, overriding the transport rules designed to bypass spam filtering.
Before you start

Gather necessary diagnostic information such as message traces, email headers, timestamps, and your current transport rule settings before reaching out for support.

Solution 1Recommended

Open a Microsoft 365 Support Request

Contact Microsoft Support to properly configure your tenant without broadly bypassing essential antimalware protections.

Because antimalware filtering operates independently of transport-rule settings, setting the spam confidence level (SCL) to -1 will not prevent messages from being blocked if malware is detected. It is highly recommended not to broadly bypass Exchange Online Protection or antimalware filtering, as this exposes your organization to real threats. Instead, you should coordinate with Microsoft Support for a secure solution.

1
Sign in to Admin Center

Log in to the Microsoft 365 admin center using an account with Global Administrator privileges.

2
Access Help & Support

Click the 'Help & support' icon located in the lower right corner of the admin center dashboard.

3
Create a New Service Request

Briefly describe your issue (e.g., 'EOP is blocking our authorized phishing simulation campaigns') and select the option to contact support.

4
Provide Diagnostic Data

Upload or paste your collected message traces, email headers, exact timestamps, sender and recipient details, and relevant policy settings so the support team can investigate effectively.

Open a Microsoft 365 Support Request
Reseller Subscriptions: If your Microsoft 365 subscription was purchased through a reseller or Cloud Solution Provider (CSP), you may need to contact them directly to open the service request.
Free Microsoft Office alternative

Try WPS Office for Your Daily Productivity Needs

While resolving your Microsoft 365 security policy configurations, consider using WPS Office as a lightweight, reliable, and cost-effective alternative for your document, spreadsheet, and presentation tasks.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the free installer.
  2. 2. Install the Software: Run the downloaded setup file and follow the simple on-screen instructions to complete the installation.
  3. 3. Start Creating: Open WPS Office and start creating or editing your Word, Excel, and PowerPoint documents instantly.
Highly compatible with Microsoft Office formats (DOCX, XLSX, PPTX)Secure offline document creation independent of complex cloud security policiesFree, lightweight, and incredibly fast to installFamiliar user interface for seamless migration and low learning curveBuilt-in PDF editing and comprehensive cross-platform support
microsoft office alternative - wps office

Frequently Asked Questions

Why does EOP ignore my transport rule setting the Spam Confidence Level (SCL) to -1?

Antimalware filtering in Exchange Online Protection operates completely independently of standard spam transport rules. Even if the SCL is set to -1, the antimalware engine can still block messages if it detects recognized malicious patterns, attachments, or links.

Can I permanently disable antimalware filtering for phishing simulations?

It is strongly advised against broadly bypassing or disabling antimalware filtering, as doing so leaves your organization vulnerable to genuine malware attacks. You should work with Microsoft to use targeted advanced delivery policies instead.

What information do I need when submitting a Microsoft 365 support ticket for blocked emails?

You should gather detailed message traces, full email headers, exact timestamps, sender and recipient addresses, and details of any transport rules or security policies you currently have configured.

How can I safely test phishing simulations in Microsoft 365?

Microsoft typically recommends using the built-in Attack Simulation Training features or configuring specific Advanced Delivery policies that are designed strictly for authorized third-party phishing simulation URLs and IP addresses.