Fix Microsoft 365 Anti-Impersonation Sending Legitimate Emails to Junk
Question details
The user needs to prevent Microsoft 365 anti-phishing impersonation protection from incorrectly routing legitimate emails from verified external domains to the Junk folder without completely disabling security measures.

- Product
- Microsoft 365 / Exchange Online
- Device & OS
- not provided
- Scenario
- Managing inter-company email communication across multiple legitimate domains where strict security policies are in place.
- Observed behavior
- Legitimate messages from partner companies are being incorrectly flagged by anti-phishing impersonation protection and sent directly to the Junk email folder.
Ensure you have Security Administrator or Exchange Administrator permissions in the Microsoft 365 Defender portal to modify threat policies and Tenant Allow/Block lists.
Configure Anti-Phishing Policies and Tenant Allow/Block List
Safely bypass impersonation protection for specific, verified senders by updating your threat policies and targeting allowed domains.
Adding verified sender domains to the trusted list within the anti-phishing policy ensures they bypass impersonation algorithms. This should be done with the narrowest scope possible to maintain overall tenant security.
Log in to the Microsoft 365 Defender portal. In the left navigation pane, go to 'Email & collaboration', select 'Policies & rules', and then click on 'Threat policies'.
Click on 'Anti-phishing' and select the policy that affects the receiving users. Click 'Edit actions' or 'Edit impersonation protection' depending on the view.
Under the 'Trusted senders and domains' section, add the specific email addresses or domains of the legitimate external senders that are currently being flagged.
If emails are failing spoof checks rather than just impersonation, navigate back to 'Threat policies', select 'Tenant Allow/Block Lists', and add the verified domains or senders to the Spoofed senders allow list.

Align and Configure SPF, DKIM, and DMARC Records
Ensure the sending domains have proper email authentication records to prevent spoof intelligence from flagging them as malicious.
Looking for a hassle-free alternative to Microsoft Office?
While managing Microsoft 365 security policies can be incredibly complex, your daily document tasks don't have to be. WPS Office offers a free, lightweight, and highly intuitive alternative to the Microsoft Office suite, giving you all the tools you need without the heavy administrative overhead.
- 1. Download the Installer: Visit the official WPS website and download the free WPS Office installer for your operating system.
- 2. Install the Software: Run the lightweight setup file and follow the quick on-screen instructions to install the suite.
- 3. Open Your Documents: Instantly open and edit your existing Microsoft Office files with full layout and formatting retention.

Frequently Asked Questions
Why does Microsoft 365 flag emails from partner companies as impersonation?
Microsoft utilizes machine learning and advanced spoof intelligence to analyze sender behavior. If a partner domain uses a display name similar to an internal executive, or if their domain lacks proper SPF/DKIM alignment, the system may flag it as a potential impersonation attempt.
How long does it take for Microsoft 365 Tenant Allow/Block List changes to take effect?
Changes made to the Tenant Allow/Block List typically propagate across the Microsoft 365 environment within a few minutes. However, in some global routing scenarios, it can take up to 24 hours for the rules to take full effect.
Can I disable anti-impersonation protection completely in Microsoft 365?
While it is technically possible to disable anti-impersonation features in the Microsoft 365 Defender portal, it is highly discouraged. Doing so leaves your organization extremely vulnerable to targeted phishing, malware, and business email compromise (BEC) attacks.
What is the difference between Anti-Phishing policies and Spoof Intelligence?
Anti-phishing policies primarily analyze display name and domain similarities to detect senders mimicking known internal users. Spoof intelligence, on the other hand, checks whether the sending server is actually authorized to send emails on behalf of the stated domain by validating SPF and DKIM records.




