How to identify what assigned SCL 9?

Nathan Tilsley 0 Reputation points
2026-06-11T13:18:26.3066667+00:00

We are experiencing persistent Junk folder delivery to Outlook.com and Hotmail recipients from our Google Workspace domain, prtheating.com.

Authentication is fully successful:

  • SPF = pass

DKIM = pass

DMARC = pass

Composite Authentication = pass

Headers show:

X-MS-Exchange-Organization-SCL: 9

BCL:0

Mailbox delivery headers show:

dest:J

RF:JunkEmail

The issue has persisted for more than 10 weeks.

We have tested:

Plain text emails.

Minimal signatures.

No attachments.

Multiple Outlook.com and Hotmail recipients.

Gmail web, Hiver, mobile devices and separate office locations.

Microsoft Sender Support recently advised that one of the Google Workspace IPs qualified for conditional mitigation, however messages continue to receive SCL 9.

The article below explains that the component responsible for assigning the SCL can be identified from values in the X-Forefront-Antispam-Report header:

https://learn.microsoft.com/en-us/defender-office-365/anti-spam-policies-troubleshooting#determine-which-component-set-the-scl

However, Outlook.com consumer mailbox headers do not appear to contain an X-Forefront-Antispam-Report header.

Is the absence of this header normal for Outlook.com consumer accounts?

Is there another method to determine which filtering or reputation component assigned the SCL 9 score?

Or is this information only available internally to Microsoft?

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-06-11T13:18:43.9533333+00:00

    For Outlook.com and other consumer Microsoft accounts, the behavior seen is consistent with the documentation:

    1. The SCL value itself is exposed via the X-MS-Exchange-Organization-SCL header. An SCL of 9 means the service has rated the message as extremely likely to be spam.
    2. The X-Forefront-Antispam-Report header and the detailed anti-spam diagnostic fields described in the article about “Determine which component set the SCL” are documented for cloud organizations (Microsoft 365 / Exchange Online) and Defender for Office 365 scenarios. Those headers and diagnostics are not guaranteed to be present or exposed in consumer Outlook.com/Hotmail mailboxes.
    3. The SCL semantics are the same: 0–9, where 9 is highest spam probability, and -1 indicates bypassed antispam scanning. The actions taken (Inbox vs Junk vs quarantine) are driven by SCL thresholds and junk mail rules, but in consumer Outlook.com those thresholds and the underlying component decisions are managed by Microsoft and not fully surfaced.

    From the available documentation:

    • SCL is stamped in X-MS-Exchange-Organization-SCL, and 9 indicates an extremely high probability of spam.
    • In Microsoft 365 organizations, the component that set SCL can be inferred from headers like X-Forefront-Antispam-Report, X-CustomSpam, and Authentication-Results.
    • The article that describes using X-Forefront-Antispam-Report explicitly targets cloud organizations with Defender for Office 365 and Exchange Online, not consumer Outlook.com.

    Therefore, for Outlook.com/Hotmail consumer mailboxes:

    • The absence of X-Forefront-Antispam-Report is normal and expected.
    • There is no documented external method to reliably determine which specific filtering or reputation component assigned SCL 9 for a consumer mailbox.
    • The detailed component-level attribution (for example, whether content filtering, ASF, DMARC enforcement, or another pipeline element set SCL) is only available internally to Microsoft in the consumer service.

    For enterprise tenants (Microsoft 365 / Defender for Office 365), the recommended approach is to:

    1. Collect full message headers from Outlook or the Defender portal.
    2. Use the X-Forefront-Antispam-Report, X-MS-Exchange-Organization-SCL, X-CustomSpam, and Authentication-Results headers to trace the SCL source as described in the troubleshooting guidance.
    3. Use that information to adjust anti-spam policies, ASF settings, or allow/block entries, or to handle false positives.

    But this level of visibility and control is not exposed for Outlook.com consumer accounts, so the exact component that set SCL 9 for those recipients cannot be determined from headers alone.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.