logo
search
Security Policy Errors

How to Handle Legitimate Gmail Messages Marked as Phishing in Microsoft 365 Defender

Elise WilliamsElise Williams Oct 1, 2026 868 views

Question details

The user needs a practical method to manage and release legitimate Gmail messages that are incorrectly marked and quarantined as phishing by Microsoft 365 Defender.

How to Handle Legitimate Gmail Messages Marked as Phishing in Microsoft 365 Defender
Product
Microsoft 365 Defender
Device & OS
not provided
Scenario
Administrators are trying to ensure that essential customer emails from Gmail accounts reach user mailboxes instead of being held in quarantine for several days.
Observed behavior
Legitimate messages from Gmail senders are being flagged as phishing by Microsoft 365 Defender, preventing them from reaching users, and releasing them individually is highly inefficient.
Before you start

Ensure you have the necessary Microsoft 365 Defender administrator privileges (such as Security Administrator or Quarantine Administrator roles) before attempting to review or modify quarantine policies.

Solution 1Recommended

Review Headers and Bulk Release Quarantined Messages

Safely review the detection details of the flagged emails and release multiple messages simultaneously to save time.

Instead of releasing dozens of messages individually, administrators can use the bulk action features in the Defender portal.

It is critical to review the authentication results (SPF, DKIM, DMARC) and message headers to confirm the emails are genuinely from your customers before releasing them.

1
Access the Quarantine page

Log in to the Microsoft 365 Defender portal, navigate to the 'Email & Collaboration' section on the left menu, and click on 'Review', then select 'Quarantine'.

2
Filter and select messages

Use the filter options to narrow down the quarantined items by sender domain (gmail.com) or quarantine reason (Phishing). Check the boxes next to the legitimate messages you want to release.

3
Release in bulk

Click the 'Release' or 'Release messages' button at the top of the list. Choose whether to release the messages to all recipients or specific ones, and confirm the action.

Review Headers and Bulk Release Quarantined Messages
Security Warning: Always verify sender identities before performing a bulk release. Releasing actual phishing emails can compromise your organization's security.
Free Microsoft Office alternative

Simplify Document Management with WPS Office

While you manage your organization's email security and Microsoft 365 infrastructure, consider simplifying your team's document management with WPS Office. It is a highly compatible, free, and lightweight alternative to Microsoft Office that allows you to work seamlessly across multiple platforms without heavy subscription fees.

  1. 1. Visit the WPS Office website: Navigate to the official WPS Office website using your preferred web browser.
  2. 2. Download the software: Click on the 'Download' button to get the installer for your specific operating system (Windows, Mac, or Linux).
  3. 3. Install and launch: Run the downloaded installer, follow the on-screen instructions, and launch WPS Office to start working on your documents.
Fully compatible with Microsoft Office formats (Word, Excel, PowerPoint)Lightweight design that runs smoothly on most operating systemsFree core features for everyday document creation and editingFamiliar user interface ensuring a seamless migration for your team
microsoft office alternative - wps office

Frequently Asked Questions

Why are legitimate Gmail messages suddenly marked as phishing in Defender?

This can happen due to recent changes in Microsoft's heuristic scanning, strict anti-phishing policies applied to your tenant, or issues with the sender's DMARC, SPF, or DKIM records failing authentication checks.

Can I whitelist the entire gmail.com domain in Microsoft 365 Defender?

Broadly whitelisting free email providers like Gmail is highly discouraged. Doing so bypasses essential phishing protection and exposes your organization to significant security risks. Exceptions should be configured narrowly for specific sender addresses.

Is there a way to automate the release of false-positive quarantined emails?

Complete automation for releasing phishing-flagged emails is restricted to prevent security breaches. However, administrators can use the bulk release feature in the Defender portal to manage large volumes of quarantined messages more efficiently.