Why Are Malicious Emails Passing Through Microsoft 365?
Question details
Users need to understand why malicious messages sent through onmicrosoft.com domains are bypassing security filters and how to trace their delivery path.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Investigating the delivery path of spam or malicious emails that successfully bypassed Exchange Online Protection and third-party filters.
- Observed behavior
- Malicious emails bypass standard security controls and reach user inboxes, requiring an analysis of the original message headers to identify routing gaps.
Ensure you have administrator access to the Microsoft 365 portal and have obtained the complete original message header of the malicious email from the affected user.
Analyze Message Headers and Contact Your Third-Party Filtering Provider
Extract the original email header to identify routing gaps and escalate the issue to the third-party email filtering service involved in the delivery path.
Microsoft uses multiple security controls, but attackers constantly evolve their methods. Often, malicious emails slip through if a third-party filtering service routes the message to Microsoft 365 without properly flagging the threat.
Open the malicious email in your email client (e.g., Outlook), navigate to File > Properties, and copy the text in the 'Internet headers' box.
Paste the copied header into an online message header analyzer tool to trace the routing path and identify if a third-party service processed the email before Exchange Online Protection.
Contact the support team of the identified third-party email filtering provider. Provide them with the complete message header so they can adjust their security policies.

Create a Service Request via Microsoft 365 Admin Portal
Submit a support ticket directly to Microsoft if the emails are bypassing Exchange Online Protection without third-party interference.
Experience a Secure and Lightweight Office Suite with WPS Office
While resolving Microsoft 365 email security configurations, ensure your local document workflow remains secure and efficient. WPS Office offers a free, highly compatible alternative to Microsoft Office, featuring robust tools for managing your everyday files.
- 1. Download the software: Visit the official WPS website and download the free installer for your operating system.
- 2. Install the suite: Run the lightweight installer and follow the on-screen prompts to complete the setup in minutes.
- 3. Open existing files: Directly open your Microsoft Office files and email attachments with complete formatting retention.

Frequently Asked Questions
Why do some malicious emails bypass Microsoft Exchange Online Protection?
While Microsoft employs multiple layers of security, attackers continuously develop new evasion techniques such as advanced domain spoofing. In some cases, specific payloads or sender IPs are not immediately blocked by default filters, especially if routed through trusted third-party gateways.
How do I find the complete original message header in Outlook?
Double-click the email to open it in a separate window. Click on 'File', select 'Properties', and look for the 'Internet headers' box at the bottom of the dialog window. Copy the entire contents of this box.
What role do third-party email filtering services play in Microsoft 365?
Many organizations route their incoming mail through an external security gateway before delivering it to Microsoft 365. If the third-party service fails to block a malicious email, Exchange Online might trust the handoff, inadvertently allowing the threat into the user's inbox.
Can regular users submit service requests for Microsoft 365 security issues?
No, standard users do not have the required permissions. Only users with specific administrator roles, such as Global Admin or Exchange Admin, can access the Microsoft 365 Admin Center to submit formal service requests.




