Emails being labeled as phishing incorrectly 2

2026-05-15T17:12:24.9033333+00:00

Hello,

After this recent update, we are seeing emails that should be sent to the users are being labeled as phishing. The emails in question are from our Salesforce ogs notifying employees of any comments on Customer Complaint cases. Due to this store employees are missing valuable updates to cases being worked.

Is there a solution that the TD technology team does so the store users don't have to take any steps to correct? We have over 8K users in the system so having all of them do these steps might not be an option?

Microsoft Security | Microsoft Defender | Other
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-15T17:12:41.5066667+00:00

    For organization-wide fixes where Salesforce notification mail is being incorrectly labeled as phishing in Microsoft Defender for Office 365, the remediation needs to be done centrally by administrators rather than by end users.

    Admin-side options based on the provided guidance:

    1. Investigate why the messages are flagged as phishing
      • Use the Submissions page in Microsoft Defender for Office 365 to submit several of the affected Salesforce messages as false positives (legitimate mail blocked/marked as phishing). This lets Microsoft analyze why they are being classified as phishing and return a verdict.
      • Follow the workflow described for legitimate messages: from the User reported or admin-submitted items on the Submissions page, submit to Microsoft for analysis and review the results to understand which policy or signal is causing the phishing verdict.
    2. Create central allow entries (admin only)
      • If the Salesforce sender/domain is confirmed legitimate and the phishing verdict is a false positive, admins can create allow entries for the Salesforce sending domain or specific email addresses in the Tenant Allow/Block List. This is done while or after submitting the messages for analysis.
      • Creating allow entries is an admin-only, tenant-wide mitigation and does not require any action from the 8K users. Use this judiciously and only for well-controlled, trusted Salesforce senders.
    3. Tune anti-phishing protection instead of relying on user actions
      • Review and adjust anti-phishing policies in Microsoft Defender for Office 365, especially if recent changes increased aggressiveness and started catching Salesforce notifications as phishing.
      • If the Phishing email threshold was recently raised (for example, to Aggressive/More aggressive/Most aggressive), consider tuning it back for the affected users/groups or creating a dedicated policy scope that treats Salesforce notification mail more leniently.
      • Ensure that Safe Links, Safe Attachments, and anti-phishing policies are configured correctly and that impersonation/sender spoof settings are not unintentionally catching Salesforce as a spoofed or impersonated sender.
    4. Fix underlying sender/authentication issues (if applicable)
      • If the Salesforce messages are failing SPF/DKIM/DMARC or otherwise appear unauthenticated, this can contribute to phishing/spam classification. Work with the Salesforce/email team to ensure proper email authentication for the Salesforce sending domain.
    5. Use quarantine and admin review where needed
      • If these messages are landing in quarantine, admins can centrally review them on the quarantine review page, submit them to Microsoft for analysis, and release them as needed, again without requiring user action.

    This combination—admin submissions for false positives, tenant allow entries for the Salesforce senders, and careful tuning of anti-phishing policies—provides a solution that does not require any corrective steps from the 8K end users.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.