Trusted Sender emails quarantined even if added to Trusted Domains list

Alyse Hart 90 Reputation points
2026-03-24T21:05:27.27+00:00

There are two emails with the same domain in my environment that are in our Trusted Senders list in the Anti-Phishing policy. Recently one of those emails was stopped in quarantine as a High Confidence Phish, with the header information indicating the message should have been classified as spam. The quarantine details show the policy type as hitting our Anti-Spam policy and the detection technology is 'Advanced Filter'. Below are a couple of header items for reference:

  1. SFV:SPM
  2. SCL:8
  3. BCL:4 - Our threshold is 7
  4. X-Email-Rejection-Mode:LearningMode - (Not familiar with this X-Header)

User's image

All the Composite Authentication checks passed and there were other messages sent from this domain that weren't blocked, we're unsure as to why only this one email was blocked if it's listed in our trusted sender list.

Unfortunately, this domain has been known to be abused in some phishing campaigns, so we didn't rush to add it to our Anti-Spam policy trusted sender list.

Is anyone else experiencing this issue or able to provide some insight?

Also, the affected user account is protected in our Priority Account settings in Defender.

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-24T21:05:53.3933333+00:00

    The behavior is expected based on how the filtering stack, safelists, and quarantine work together.

    Key points from the headers and quarantine details:

    • SCL:8 → The message was classified as High confidence spam.
    • SFV:SPM → Spam filtering verdict was spam.
    • Quarantine shows High confidence phishing and Policy type: Anti‑spam, detection technology Advanced Filter.

    From the documented precedence:

    • Messages that are malware or high confidence phishing are always quarantined and the filter verdict overrides user safelists and safe senders.
    • In the precedence table, for High confidence phishing, both the user’s Safe Senders/Recipients list and Blocked Senders list lose to the filter: “Filter wins: Email quarantined.”
    • The same appendix notes that domain allows in Safe Senders might not work if:
      • The message is identified as malware or high confidence phishing, or
      • Anti‑spam policy actions are configured to quarantine instead of move to Junk, or
      • The message content is also blocked by a Tenant Allow/Block List entry.

    Therefore, even though the domain or sender is in the Trusted Senders list of the anti‑phishing policy, that trust does not override a high confidence spam/phish verdict coming from the anti‑spam stack (Advanced Filter). The filtering stack verdict takes precedence and the message is quarantined.

    Why only some messages from that domain are affected:

    • Spam/anti‑phishing decisions are per‑message. Different content, URLs, or attachments can cause different SCL/BCL values and different verdicts, even from the same domain.
    • The FAQ and quarantine documentation explain that the Quarantine reason and Policy type show which feature actually quarantined the message (in this case, anti‑spam with a high confidence phishing verdict), which can differ from other messages from the same sender that did not cross the high‑confidence threshold.

    How to investigate and tune:

    1. In the Defender portal, open Quarantine → Email and check the Quarantine reason, Policy type, and Detection technology for the affected message to confirm it is high confidence phishing from anti‑spam.
    2. Review the relevant anti‑spam policy actions for spam/high confidence spam/phishing to see whether they are set to Quarantine rather than Move to Junk Email.
    3. If the sender is truly trusted and business‑critical, consider:
      • Adjusting anti‑spam policy actions for high confidence spam/phishing (with caution, as this reduces protection), or
      • Using organization‑level allow mechanisms (such as Tenant Allow/Block List or advanced delivery) where appropriate, understanding from the appendix that some organization allows can override certain verdicts.
    4. Continue to treat this domain cautiously, since the context notes that domains can be abused and that organization/user allows do not override malware or high‑confidence phishing in many cases.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.