logo
search
Security Policy Errors

Fix Microsoft 365 Anti-Impersonation Sending Legitimate Emails to Junk

Chanuka GeekiyanageChanuka Geekiyanage Oct 7, 2026 868 views

Question details

The user needs to prevent Microsoft 365 anti-phishing impersonation protection from incorrectly routing legitimate emails from verified external domains to the Junk folder without completely disabling security measures.

How to Fix Microsoft 365 Anti-Impersonation Sending Legitimate Emails to Junk
Product
Microsoft 365 / Exchange Online
Device & OS
not provided
Scenario
Managing inter-company email communication across multiple legitimate domains where strict security policies are in place.
Observed behavior
Legitimate messages from partner companies are being incorrectly flagged by anti-phishing impersonation protection and sent directly to the Junk email folder.
Before you start

Ensure you have Security Administrator or Exchange Administrator permissions in the Microsoft 365 Defender portal to modify threat policies and Tenant Allow/Block lists.

Solution 1Recommended

Configure Anti-Phishing Policies and Tenant Allow/Block List

Safely bypass impersonation protection for specific, verified senders by updating your threat policies and targeting allowed domains.

Adding verified sender domains to the trusted list within the anti-phishing policy ensures they bypass impersonation algorithms. This should be done with the narrowest scope possible to maintain overall tenant security.

1
Access Threat Policies

Log in to the Microsoft 365 Defender portal. In the left navigation pane, go to 'Email & collaboration', select 'Policies & rules', and then click on 'Threat policies'.

2
Edit Anti-Phishing Policy

Click on 'Anti-phishing' and select the policy that affects the receiving users. Click 'Edit actions' or 'Edit impersonation protection' depending on the view.

3
Add Trusted Senders and Domains

Under the 'Trusted senders and domains' section, add the specific email addresses or domains of the legitimate external senders that are currently being flagged.

4
Update Tenant Allow/Block List

If emails are failing spoof checks rather than just impersonation, navigate back to 'Threat policies', select 'Tenant Allow/Block Lists', and add the verified domains or senders to the Spoofed senders allow list.

Configure Anti-Phishing Policies and Tenant Allow/Block List
Security Warning: Avoid creating broad allowlists, such as allowing entire top-level domains. Overly broad rules can bypass critical anti-phishing controls and increase your vulnerability to attacks.
Free Microsoft Office alternative

Looking for a hassle-free alternative to Microsoft Office?

While managing Microsoft 365 security policies can be incredibly complex, your daily document tasks don't have to be. WPS Office offers a free, lightweight, and highly intuitive alternative to the Microsoft Office suite, giving you all the tools you need without the heavy administrative overhead.

  1. 1. Download the Installer: Visit the official WPS website and download the free WPS Office installer for your operating system.
  2. 2. Install the Software: Run the lightweight setup file and follow the quick on-screen instructions to install the suite.
  3. 3. Open Your Documents: Instantly open and edit your existing Microsoft Office files with full layout and formatting retention.
Seamless format compatibility with Microsoft Word, Excel, and PowerPoint (.docx, .xlsx, .pptx).Lightweight installation that runs smoothly on Windows, Mac, Linux, iOS, and Android.Completely free to use with a familiar, tabbed user interface for effortless multitasking.Built-in PDF editing, conversion, and rich collaboration tools included natively.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Microsoft 365 flag emails from partner companies as impersonation?

Microsoft utilizes machine learning and advanced spoof intelligence to analyze sender behavior. If a partner domain uses a display name similar to an internal executive, or if their domain lacks proper SPF/DKIM alignment, the system may flag it as a potential impersonation attempt.

How long does it take for Microsoft 365 Tenant Allow/Block List changes to take effect?

Changes made to the Tenant Allow/Block List typically propagate across the Microsoft 365 environment within a few minutes. However, in some global routing scenarios, it can take up to 24 hours for the rules to take full effect.

Can I disable anti-impersonation protection completely in Microsoft 365?

While it is technically possible to disable anti-impersonation features in the Microsoft 365 Defender portal, it is highly discouraged. Doing so leaves your organization extremely vulnerable to targeted phishing, malware, and business email compromise (BEC) attacks.

What is the difference between Anti-Phishing policies and Spoof Intelligence?

Anti-phishing policies primarily analyze display name and domain similarities to detect senders mimicking known internal users. Spoof intelligence, on the other hand, checks whether the sending server is actually authorized to send emails on behalf of the stated domain by validating SPF and DKIM records.