How to Investigate Phishing Emails Bypassing Microsoft Defender
Question details
The user needs to understand how to investigate and resolve an issue where a phishing email successfully bypassed Microsoft Defender and Advanced Threat Protection.

- Product
- Microsoft Defender
- Device & OS
- not provided
- Scenario
- A phishing email impersonating a government agency reached the inbox despite having no trusted sender or domain exceptions configured.
- Observed behavior
- The phishing email bypassed all configured security policies in Microsoft Defender and ATP, landing in the user's inbox instead of quarantine.
Before starting your investigation, ensure you have global administrator or security administrator privileges in your Microsoft 365 tenant to access message traces and threat policies.
Review Message Headers and Security Policies
Identify why the email bypassed filters by analyzing the message headers and reviewing your anti-phishing configurations.
Phishing emails often bypass security filters if there is a misconfigured mail flow rule or if the attacker successfully spoofs authentication records. Reviewing the raw headers is the most effective way to identify the security failure point.
Open the phishing email safely and extract the internet message headers. Look closely at the Authentication-Results (SPF, DKIM, DMARC) and the Spam Confidence Level (SCL) to see how Microsoft evaluated the message.
Navigate to the Exchange Admin Center and review your mail flow rules (transport rules). Ensure no rule is inadvertently bypassing spam filtering for specific keywords or spoofed domains.
Go to the Microsoft 365 Defender portal. Under Email & collaboration, select Policies & rules, then Threat policies. Check your Anti-phishing and Anti-spam settings to ensure impersonation protection is actively enabled.

Consult the Microsoft Defender Community
Advanced threat bypassing often requires specialized investigation by Microsoft security experts.
Secure Your Local Documents with WPS Office
While enterprise email security requires specialized tools like Microsoft Defender, maintaining a secure, lightweight, and efficient local workspace is equally important. WPS Office offers a highly compatible alternative to Microsoft Office, ensuring your offline document management remains safe and hassle-free.
- 1. Download the Installer: Visit the official WPS Office website and download the free version for your operating system.
- 2. Install the Software: Run the downloaded setup file and follow the simple on-screen instructions to complete the installation.
- 3. Open Your Documents: Launch WPS Office and directly open your existing Microsoft Office files without worrying about format compatibility.

Frequently Asked Questions
Why did a spoofed email bypass Microsoft Defender?
Spoofed emails can bypass Defender if there is a misconfigured Exchange transport rule acting as an allow-list, missing impersonation protection settings in your Threat Policies, or if the attacker successfully compromised a legitimate domain with high reputation.
How can I check if a domain is on an allow list?
In the Microsoft 365 Defender portal, navigate to Threat policies, select Anti-spam, and open the Anti-spam inbound policy. Check the 'Allowed and blocked senders and domains' section to see if the malicious domain was accidentally trusted.
What is Advanced Threat Protection (ATP) in Microsoft 365?
ATP, now integrated into Microsoft Defender for Office 365, is a cloud-based email filtering service that provides real-time protection against unknown malware, viruses, malicious URLs, and advanced impersonation attacks.
Where can I report phishing emails that bypass filters?
You can use the 'Report Message' add-in directly in Outlook to submit false negatives to Microsoft for analysis. This helps improve their machine learning detection algorithms and updates global threat intelligence.




