logo
search
Security Policy Errors

Why Are Malicious Emails Passing Through Microsoft 365?

Guest WriterGuest Writer Oct 9, 2026 869 views

Question details

Users need to understand why malicious messages sent through onmicrosoft.com domains are bypassing security filters and how to trace their delivery path.

Why Are Malicious Emails Passing Through Microsoft 365?
Product
Microsoft 365
Device & OS
not provided
Scenario
Investigating the delivery path of spam or malicious emails that successfully bypassed Exchange Online Protection and third-party filters.
Observed behavior
Malicious emails bypass standard security controls and reach user inboxes, requiring an analysis of the original message headers to identify routing gaps.
Before you start

Ensure you have administrator access to the Microsoft 365 portal and have obtained the complete original message header of the malicious email from the affected user.

Solution 1Recommended

Analyze Message Headers and Contact Your Third-Party Filtering Provider

Extract the original email header to identify routing gaps and escalate the issue to the third-party email filtering service involved in the delivery path.

Microsoft uses multiple security controls, but attackers constantly evolve their methods. Often, malicious emails slip through if a third-party filtering service routes the message to Microsoft 365 without properly flagging the threat.

1
Retrieve the message header

Open the malicious email in your email client (e.g., Outlook), navigate to File > Properties, and copy the text in the 'Internet headers' box.

2
Analyze the delivery path

Paste the copied header into an online message header analyzer tool to trace the routing path and identify if a third-party service processed the email before Exchange Online Protection.

3
Escalate to the provider

Contact the support team of the identified third-party email filtering provider. Provide them with the complete message header so they can adjust their security policies.

Analyze Message Headers and Contact Your Third-Party Filtering Provider
Important: An incomplete header will prevent support teams from accurately tracing the email's origin and delivery path. Always provide the full original header.
Free Microsoft Office alternative

Experience a Secure and Lightweight Office Suite with WPS Office

While resolving Microsoft 365 email security configurations, ensure your local document workflow remains secure and efficient. WPS Office offers a free, highly compatible alternative to Microsoft Office, featuring robust tools for managing your everyday files.

  1. 1. Download the software: Visit the official WPS website and download the free installer for your operating system.
  2. 2. Install the suite: Run the lightweight installer and follow the on-screen prompts to complete the setup in minutes.
  3. 3. Open existing files: Directly open your Microsoft Office files and email attachments with complete formatting retention.
Keep your local documents and downloaded email attachments secure with robust file encryption.Fully compatible with Microsoft Office formats including DOCX, XLSX, and PPTX.Lightweight design ensures fast startup and smooth operation on any device.Familiar, intuitive user interface requires zero learning curve for seamless migration.
microsoft office alternative - wps office

Frequently Asked Questions

Why do some malicious emails bypass Microsoft Exchange Online Protection?

While Microsoft employs multiple layers of security, attackers continuously develop new evasion techniques such as advanced domain spoofing. In some cases, specific payloads or sender IPs are not immediately blocked by default filters, especially if routed through trusted third-party gateways.

How do I find the complete original message header in Outlook?

Double-click the email to open it in a separate window. Click on 'File', select 'Properties', and look for the 'Internet headers' box at the bottom of the dialog window. Copy the entire contents of this box.

What role do third-party email filtering services play in Microsoft 365?

Many organizations route their incoming mail through an external security gateway before delivering it to Microsoft 365. If the third-party service fails to block a malicious email, Exchange Online might trust the handoff, inadvertently allowing the threat into the user's inbox.

Can regular users submit service requests for Microsoft 365 security issues?

No, standard users do not have the required permissions. Only users with specific administrator roles, such as Global Admin or Exchange Admin, can access the Microsoft 365 Admin Center to submit formal service requests.