Microsoft 365 Spam Filter: The Complete Guide
This complete guide to Microsoft 365 spam filtering covers Exchange Online Protection architecture, anti-spam and anti-phishing policy setup, allow and blocklists, quarantine management, Safe Attachments, Safe Links, and how to test your configuration. Written for IT administrators and business owners managing their own Microsoft 365 tenant.
Nathan Hill-Haimes
Technical Director
Most UK SMEs run EOP on its factory defaults and quietly accept whatever it lets through. That is a mistake. The defaults are deliberately permissive so Microsoft does not block legitimate mail for millions of tenants. Tighten the policies and you cut spam, throttle bulk mail, and close the gap that business email compromise walks through. This guide shows exactly which settings to change, drawing on how we harden Microsoft 365 security for UK businesses every week.
How does Exchange Online Protection filter email?
Every message hitting a Microsoft 365 mailbox runs through EOP's pipeline in a fixed order, and knowing that order is the difference between fixing a filtering problem in minutes versus hours. EOP is included at no extra cost in all paid Microsoft 365 plans and supplies the baseline spam, malware and phishing defence for the platform.
The stages run in this sequence (learn.microsoft.com):
1. Connection filtering — checks the sending IP against Microsoft's safe list, block lists and reputation data 2. Anti-malware scanning — inspects attachments and content against known malware signatures 3. Mail flow rules (transport rules) — any custom rules you have built that can override or modify filtering 4. Anti-spam filtering — content analysis that assigns a Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) 5. Anti-phishing — spoof detection, lookalike domains and impersonation checks
On Business Premium and above, two further layers switch on: Safe Attachments and Safe Links, both part of Defender for Office 365 Plan 1. These are where serious phishing protection begins, and they are the reason we steer most clients to Business Premium at £16.90 per user per month (microsoft.com/en-gb).
What is the Spam Confidence Level (SCL)?
The Spam Confidence Level is Microsoft's verdict on how likely a message is to be spam, scored from -1 to 9 (learn.microsoft.com). The higher the number, the more confident EOP is that the mail is junk, and the SCL drives what happens to the message next.
| SCL value | Verdict | Default action |
|---|---|---|
| -1 | Allowed by connection filtering | Delivered to inbox |
| 0–1 | Not spam | Delivered to inbox |
| 2–4 | Low-probability spam | Delivered to inbox |
| 5–6 | Spam | Junk Email folder |
| 7–9 | High-confidence spam | Quarantine |
The default thresholds are adjustable, and this is the single highest-value change most businesses can make. Moving SCL 5–6 mail to quarantine instead of junk gives you real control: admins and users can review and release from quarantine, whereas junk-folder mail is routinely ignored and the dangerous ones get clicked.
How do you configure anti-spam policies?
Anti-spam settings live at security.microsoft.com under Email & Collaboration > Policies & Rules > Threat Policies > Anti-spam. The default inbound policy covers every user, but you can build custom policies with tighter thresholds for high-risk groups such as finance or the leadership team.
The settings worth reviewing first:
- Spam action — where mail goes at each SCL threshold (junk, quarantine or delete)
- Bulk email threshold (BCL) — scored 1–9; lower values filter more bulk mail. The default is 7 (learn.microsoft.com). Dropping it to 5 noticeably cuts marketing and newsletter noise.
- Quarantine policy — controls what users can do with their quarantined messages
- Safety tips — enable first-contact and suspicious-sender warnings so staff get a visible flag on unfamiliar senders
These are low-risk, high-return changes. None of them block legitimate business mail when set sensibly, and together they strip out a large share of the spam that defaults wave through.
How do anti-phishing policies stop impersonation?
Anti-phishing policies are the controls that defend against CEO fraud and business email compromise — the attacks that cost UK organisations the most. The default policy is thin; you need a custom policy with impersonation and spoof protection switched on and tuned to your business.
Impersonation protection
Add your key people — CEO, CFO, Head of Finance — as protected users so Microsoft flags mail that mimics their display name or uses a lookalike domain. You can protect your full leadership team and key finance roles this way, which is ample for most SMEs. This is one of the most effective controls against business email compromise, where an attacker poses as a director to authorise a fraudulent payment. Add your own domains and key supplier domains to protected domains as well.
Spoofed sender intelligence
Spoofed sender intelligence uses Microsoft's threat data to catch forged sender addresses. It is on by default, but verify it is active and review the Spoof Intelligence report in the Defender portal periodically. It shows which senders are flagged as spoofed and lets you explicitly allow genuine senders being caught by mistake. Pair this with dedicated phishing protection for staff who handle payments.
How should you manage allow and block lists?
The Tenant Allow/Block List is the correct, organisation-wide place to allow or block specific senders, domains, URLs and file hashes — found under Threat Policies > Tenant Allow/Block Lists. Used carefully it is precise; used carelessly it opens a hole attackers exploit.
The trap is domain allows. Adding a domain to the allow list bypasses spam filtering for *all* mail claiming to come from that domain, including spoofed mail. For suppliers and partners, use spoofed-sender allows rather than blanket domain allows wherever you can. Individual users can still manage their own Outlook Safe Senders and Blocked Senders lists for personal newsletters, and admins can bulk-manage these via PowerShell when needed.
What extra protection do Safe Attachments and Safe Links add?
Safe Attachments and Safe Links are the Defender for Office 365 layers included with Business Premium, and they are where protection moves from "good enough" to genuinely hard to beat. They defend against threats that signature-based scanning misses entirely.
- Safe Attachments detonates every attachment in an isolated sandbox before delivery, analysing behaviour rather than signatures. Turn on Dynamic Delivery so the message body arrives immediately while the attachment is scanned, then drops in once cleared — no frustrating delays.
- Safe Links rewrites URLs in email and Teams messages and re-checks them at the moment of click. A link that was clean on arrival but later weaponised is blocked when the user clicks it.
Apply Safe Links to both email and Teams for full coverage, and track click data in the Defender portal to spot users who keep clicking risky links. We configure these alongside Microsoft Defender for Business so endpoint and email defence reinforce each other.
How do you test and monitor the spam filter?
Testing proves your filter actually works rather than assuming it does. The GTUBE string (Generic Test for Unsolicited Bulk Email, published at spamassassin.apache.org) is the standard anti-spam test — send a message containing it and it should trigger the filter. If it sails through, your filtering is broken.
For ongoing health, review the Email & Collaboration reports in the Microsoft Defender portal. They chart spam, malware and phishing detections over time, and a spike in phishing aimed at your domain is worth investigating fast. The Microsoft Remote Connectivity Analyzer (testconnectivity.microsoft.com) helps diagnose delivery and filtering faults. The NCSC's guidance on defending against phishing is a useful companion for staff training (ncsc.gov.uk).
This is where most SMEs fall down — not on setup, but on the weekly discipline of reviewing reports and acting on them. That is exactly what our managed Microsoft 365 service covers, and we add BarracudaOne email security as an extra filtering layer for businesses that need protection beyond EOP. For the wider picture, see our email security hub.
Is Your Microsoft 365 Email Filtering Properly Configured?
AMVIA audits and configures Microsoft 365 anti-spam, anti-phishing and Defender for Office 365 settings for UK businesses.
Frequently Asked Questions
By default, mail with an SCL of 5–6 goes to the user's Junk Email folder and SCL 7–9 (high-confidence spam) is quarantined. Both thresholds can be changed in the anti-spam policy. Many businesses benefit from sending SCL 5–6 to quarantine instead of junk for better visibility and control over what staff actually see.
Add the sender address or domain to the Tenant Allow/Block List in the Microsoft Defender portal under Threat Policies. This blocks it across the whole organisation. Individual users can also add senders to their Outlook Blocked Senders list, but that only applies to their own mailbox, so use the tenant list for anything organisation-wide.
Exchange Online Protection (EOP) ships with every paid Microsoft 365 plan and provides baseline spam, malware and anti-phishing filtering. Defender for Office 365, included in Business Premium, adds Safe Attachments sandbox scanning and Safe Links click-time URL checks. Defender gives materially stronger protection against sophisticated phishing and malware that EOP alone can miss.
Microsoft 365 retains quarantined email for up to 30 days by default, after which messages are permanently deleted (learn.microsoft.com). Administrators can set the quarantine retention period anywhere up to that 30-day maximum. Users and admins can release or delete quarantined messages at any point before the retention period expires.
Yes. Microsoft 365 sends quarantine digest notifications on a configurable schedule, daily or weekly. The digest lists quarantined messages so users can review and release legitimate mail without an admin. You set the frequency and contents in the quarantine policy, which also controls exactly what each user is allowed to do from the notification.
For basic spam, the EOP defaults are a reasonable start, but they are deliberately permissive and leave gaps against targeted phishing and business email compromise. Tightening anti-spam thresholds, enabling impersonation protection, and turning on Safe Attachments and Safe Links on Business Premium close most of those gaps. Many SMEs add a second filtering layer for extra cover.
Related Reading
Microsoft 365 Spam Filter | How to Manage Email Filtering
Overview of managing spam filtering in Microsoft 365 for business administrators.
BarracudaOne | How AMVIA Keeps Your Business Compliant
How AMVIA's advanced email security platform adds protection beyond EOP.
Microsoft 365 Email | Exchange Online Setup Guide
Setting up and managing Exchange Online email for your business.