logo
search
Security Policy Errors

How to Fix Microsoft 365 Emails Quarantined as Phishing

Khadija KhanKhadija Khan Oct 9, 2026 869 views

Question details

Administrators need to resolve an issue where legitimate company emails containing invoices, URLs, or PDF attachments are incorrectly flagged and blocked by email security filters.

How to Fix Microsoft 365 Emails Quarantined as Phishing
Product
Microsoft 365
Device & OS
not provided
Scenario
Sending legitimate outbound emails from a Microsoft 365 domain to clients or other Microsoft 365 domains.
Observed behavior
Messages are incorrectly quarantined as high-confidence phishing, and standard tenant overrides such as Safe Senders or IP allow lists fail to bypass the block.
Before you start

Ensure you have Exchange Administrator or Security Administrator privileges in your Microsoft 365 tenant to access Microsoft Defender portals, message traces, and submission features.

Solution 1Recommended

Submit Incorrectly Blocked Messages for Analysis

Use the Microsoft 365 admin submissions feature to report false positives, as standard allow lists do not override high-confidence phishing detections due to Secure by Default policies.

Microsoft's Secure by Default changes mean that some tenant overrides (such as allowed sender lists, Outlook Safe Senders, IP allow lists, and Exchange mail-flow rules) no longer apply to malware or high-confidence phishing detections. The correct method to resolve this is to submit the messages for review.

1
Access the Defender Portal

Log in to the Microsoft Defender portal at security.microsoft.com using your administrator credentials.

2
Navigate to Submissions

In the left-hand navigation pane, go to 'Actions & submissions' and then click on 'Submissions'.

3
Submit the False Positive

Select the 'Emails' tab, click 'Add to submit', locate the quarantined message, select 'Should not have been blocked (False positive)', and submit it to Microsoft for analysis.

4
Verify Email Authentication

While waiting for the submission review, check your DNS records to ensure SPF, DKIM, and DMARC are configured correctly and not failing, as misconfigurations increase the likelihood of phishing false positives.

Submit Incorrectly Blocked Messages for Analysis
Tenant Overrides: Avoid relying on mail-flow rules or IP allow lists for ongoing phishing blocks, as Microsoft's security filters will deliberately ignore these rules for high-confidence threats.
Free Microsoft Office alternative

Create Secure, Professional PDF Invoices with WPS Office

While you work with Microsoft to resolve email delivery issues, ensure your actual documents and PDF attachments are created cleanly and securely. WPS Office is a lightweight, free alternative to Microsoft Office that offers full compatibility with Word, Excel, and PDF formats.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Create Professional PDFs: Open WPS Writer or WPS Spreadsheet, format your company invoice or document, and use the 'Export to PDF' feature to create a clean, standardized file to attach to your outbound emails.
Free and lightweight office suite for creating professional documentsFully compatible with Microsoft Office formats (.docx, .xlsx, .pptx)Built-in robust PDF editor for creating secure invoices and reports without triggering malware filtersFamiliar user interface allowing seamless migration and zero learning curve
microsoft office alternative - wps office

Frequently Asked Questions

Why are my allowed senders still being quarantined as phishing?

Microsoft's 'Secure by Default' policy restricts tenant overrides. Features like allowed sender lists, domain lists, Outlook Safe Senders, and Exchange mail-flow rules are deliberately ignored when a message is classified as malware or high-confidence phishing.

How do I check if SPF, DKIM, or DMARC are causing the quarantine?

You can run a message trace in the Exchange admin center and view the message header details of the blocked email. Look for the 'Authentication-Results' header to see if SPF, DKIM, or DMARC resulted in a 'fail', which heavily influences phishing classifications.

How long does it take for Microsoft to resolve a false positive submission?

When you submit a false positive through the Microsoft 365 admin submissions feature, Microsoft's automated systems and analysts typically review the message and adjust the filters within 24 to 48 hours.

Can I manually release emails quarantined as high-confidence phishing?

Standard users cannot release messages quarantined as high-confidence phishing. Only an administrator can review these messages in the Microsoft Defender portal and choose to release them to the intended recipient's inbox while simultaneously submitting them for review.