Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
The behavior is expected based on how the filtering stack, safelists, and quarantine work together.
Key points from the headers and quarantine details:
-
SCL:8→ The message was classified as High confidence spam. -
SFV:SPM→ Spam filtering verdict was spam. - Quarantine shows High confidence phishing and Policy type: Anti‑spam, detection technology Advanced Filter.
From the documented precedence:
- Messages that are malware or high confidence phishing are always quarantined and the filter verdict overrides user safelists and safe senders.
- In the precedence table, for High confidence phishing, both the user’s Safe Senders/Recipients list and Blocked Senders list lose to the filter: “Filter wins: Email quarantined.”
- The same appendix notes that domain allows in Safe Senders might not work if:
- The message is identified as malware or high confidence phishing, or
- Anti‑spam policy actions are configured to quarantine instead of move to Junk, or
- The message content is also blocked by a Tenant Allow/Block List entry.
Therefore, even though the domain or sender is in the Trusted Senders list of the anti‑phishing policy, that trust does not override a high confidence spam/phish verdict coming from the anti‑spam stack (Advanced Filter). The filtering stack verdict takes precedence and the message is quarantined.
Why only some messages from that domain are affected:
- Spam/anti‑phishing decisions are per‑message. Different content, URLs, or attachments can cause different SCL/BCL values and different verdicts, even from the same domain.
- The FAQ and quarantine documentation explain that the Quarantine reason and Policy type show which feature actually quarantined the message (in this case, anti‑spam with a high confidence phishing verdict), which can differ from other messages from the same sender that did not cross the high‑confidence threshold.
How to investigate and tune:
- In the Defender portal, open Quarantine → Email and check the Quarantine reason, Policy type, and Detection technology for the affected message to confirm it is high confidence phishing from anti‑spam.
- Review the relevant anti‑spam policy actions for spam/high confidence spam/phishing to see whether they are set to Quarantine rather than Move to Junk Email.
- If the sender is truly trusted and business‑critical, consider:
- Adjusting anti‑spam policy actions for high confidence spam/phishing (with caution, as this reduces protection), or
- Using organization‑level allow mechanisms (such as Tenant Allow/Block List or advanced delivery) where appropriate, understanding from the appendix that some organization allows can override certain verdicts.
- Continue to treat this domain cautiously, since the context notes that domains can be abused and that organization/user allows do not override malware or high‑confidence phishing in many cases.
References:
- Order and precedence of email protection
- Quarantined email messages in cloud organizations
- Frequently asked questions - Quarantined messages
- Spam confidence level (SCL) in cloud organizations
- Advanced Spam Filter (ASF) settings in anti-spam policies
- Manage quarantined messages and files as an admin
- Manage quarantined messages and files as a user
- Anti-phishing policies in cloud organizations