logo
search
Security Policy Errors

How to Investigate Phishing Emails Bypassing Microsoft Defender

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 869 views

Question details

The user needs to understand how to investigate and resolve an issue where a phishing email successfully bypassed Microsoft Defender and Advanced Threat Protection.

How to Investigate Phishing Emails That Bypass Microsoft Defender
Product
Microsoft Defender
Device & OS
not provided
Scenario
A phishing email impersonating a government agency reached the inbox despite having no trusted sender or domain exceptions configured.
Observed behavior
The phishing email bypassed all configured security policies in Microsoft Defender and ATP, landing in the user's inbox instead of quarantine.
Before you start

Before starting your investigation, ensure you have global administrator or security administrator privileges in your Microsoft 365 tenant to access message traces and threat policies.

Solution 1Recommended

Review Message Headers and Security Policies

Identify why the email bypassed filters by analyzing the message headers and reviewing your anti-phishing configurations.

Phishing emails often bypass security filters if there is a misconfigured mail flow rule or if the attacker successfully spoofs authentication records. Reviewing the raw headers is the most effective way to identify the security failure point.

1
Analyze Message Headers

Open the phishing email safely and extract the internet message headers. Look closely at the Authentication-Results (SPF, DKIM, DMARC) and the Spam Confidence Level (SCL) to see how Microsoft evaluated the message.

2
Check Transport Rules

Navigate to the Exchange Admin Center and review your mail flow rules (transport rules). Ensure no rule is inadvertently bypassing spam filtering for specific keywords or spoofed domains.

3
Review Anti-Phishing Settings

Go to the Microsoft 365 Defender portal. Under Email & collaboration, select Policies & rules, then Threat policies. Check your Anti-phishing and Anti-spam settings to ensure impersonation protection is actively enabled.

Review Message Headers and Security Policies
Sanitize Data: Always sanitize personal or sensitive information from message headers before sharing them in public forums or with third-party support.
Free Microsoft Office alternative

Secure Your Local Documents with WPS Office

While enterprise email security requires specialized tools like Microsoft Defender, maintaining a secure, lightweight, and efficient local workspace is equally important. WPS Office offers a highly compatible alternative to Microsoft Office, ensuring your offline document management remains safe and hassle-free.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free version for your operating system.
  2. 2. Install the Software: Run the downloaded setup file and follow the simple on-screen instructions to complete the installation.
  3. 3. Open Your Documents: Launch WPS Office and directly open your existing Microsoft Office files without worrying about format compatibility.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight installation with fast loading times and minimal system impact.Built-in PDF reader and editor for secure document handling.Familiar, easy-to-use interface for a seamless transition from Microsoft Office.
QA img-9

Frequently Asked Questions

Why did a spoofed email bypass Microsoft Defender?

Spoofed emails can bypass Defender if there is a misconfigured Exchange transport rule acting as an allow-list, missing impersonation protection settings in your Threat Policies, or if the attacker successfully compromised a legitimate domain with high reputation.

How can I check if a domain is on an allow list?

In the Microsoft 365 Defender portal, navigate to Threat policies, select Anti-spam, and open the Anti-spam inbound policy. Check the 'Allowed and blocked senders and domains' section to see if the malicious domain was accidentally trusted.

What is Advanced Threat Protection (ATP) in Microsoft 365?

ATP, now integrated into Microsoft Defender for Office 365, is a cloud-based email filtering service that provides real-time protection against unknown malware, viruses, malicious URLs, and advanced impersonation attacks.

Where can I report phishing emails that bypass filters?

You can use the 'Report Message' add-in directly in Outlook to submit false negatives to Microsoft for analysis. This helps improve their machine learning detection algorithms and updates global threat intelligence.