Missing Important Emails? Do Not Just Weaken the Spam Filter

Important legitimate emails can be diverted to Junk, held in quarantine, blocked by rules, rejected because of sender-configuration problems or never successfully delivered. This article explains how to trace a missing message, distinguish the different causes, and make the narrowest safe correction — without unnecessarily reducing protection for everyone.
Missing an important email can be costly. Delayed payments, missed tenders, lost sales enquiries, supplier disputes, overdue legal correspondence — the consequences of a message failing to reach the right inbox can extend well beyond the inconvenience of a single conversation.
When this happens, the instinctive request is often: can you turn the spam filter down? That is understandable, but it starts with the proposed fix rather than the diagnosis.
The core principle
A missing email is not automatically a spam-filter problem.
A legitimate message might instead have been moved to Junk, placed in quarantine, blocked by an inbox rule, rejected because of the sender’s authentication problems, classified as bulk mail, held by a third-party security service, addressed incorrectly or never successfully sent in the first place. Reducing spam-filter sensitivity may solve none of these and could make the business significantly more vulnerable to phishing, fraudulent invoices and credential-stealing messages.
The first rule
Do not change the filter until you know which filter — or other control — made the decision.
Last checked: 29 July 2026.
Missing does not always mean blocked
An expected email can be absent from the inbox for many different reasons. Before adjusting any security setting, establish where the message actually went.
| Category | Possible explanation |
|---|---|
| Message was not sent | Left in Drafts, wrong address used, non-delivery report received, outbound delivery failure, message queued or deferred |
| Delivered elsewhere | Junk or Spam folder, quarantine, inbox tab or category, archive, Deleted Items, shared mailbox, delegated mailbox, subfolder, online archive |
| Rule moved or deleted it | Outlook inbox rule, Gmail filter, administrator transport rule, third-party gateway rule, compromised-account rule |
| Security control held it | Spam detection, phishing detection, impersonation protection, malware scanning, attachment policy, URL protection, content-compliance or data-loss prevention policy |
| Delivery failed | Incorrect address, DNS or domain problem, mailbox unavailable, message-size limit, sending reputation, sender-authentication failure, server rejection |
Before adjusting security
Before adjusting security, establish whether the email reached your organisation at all.
Junk, spam and quarantine explained
These terms are sometimes used interchangeably, but they describe different situations:
- Junk or Spam folder — the message is delivered to the mailbox but separated from the main Inbox. The user can typically open it, mark it as not junk or not spam, move it and report an incorrect classification.
- Quarantine — the message is held outside normal mailbox delivery by a security control. Depending on the detection type, platform, policy and administrator configuration, the recipient may be able to view limited details, preview the message, request release, release it themselves or take no action without administrator approval. Some detection categories require administrator review regardless of user preference.
- Rejection — the receiving service refuses the message during or after SMTP delivery. The sender may receive a non-delivery report with an error code.
- Deletion — a policy, rule, user action or malicious rule removes the message after delivery. The user may not know it arrived.
The key distinction
Junk is usually delivered but diverted. Quarantine is held for review. Rejection means delivery was refused.
These definitions are general. Different email platforms use different terminology and behaviour, and the actions available to ordinary users vary significantly between detection types and platform configurations.
What is a false positive?
A false positive occurs when a legitimate message is incorrectly classified as unwanted or harmful. Examples include a genuine invoice classified as spam, a supplier notification classified as bulk email, a legitimate internal announcement classified as impersonation, a valid attachment classified as containing malware, or a real login notification classified as phishing.
The opposite problem — a false negative — is when a malicious or unwanted message is incorrectly allowed through.
- Too many false positives: missed business, frustrated users, unsafe workarounds, loss of trust in security controls
- Too many false negatives: phishing, malware, fraud, account compromise, data loss
The balance
Good email security must reduce malicious delivery without making legitimate communication unreliable.
Why legitimate email gets filtered
Email filtering uses multiple signals simultaneously rather than one simple rule. A legitimate message can be classified as suspicious when:
- A sender’s authentication is incomplete or misconfigured
- A marketing platform is sending on behalf of a domain without being listed in its SPF record
- A supplier changes mail provider and does not update authentication records
- A compromised sender account damages the sending domain’s reputation
- A message resembles common phishing patterns in structure or content
- An attachment contains macros, executable content or script elements
- A new domain has little established reputation
- A message is sent to many recipients simultaneously
- Forwarding breaks authentication alignment
- A third-party gateway modifies the message in a way that affects DKIM verification
- An anti-spoofing control sees an unexpected sending source for a known domain
A legitimate problem
A legitimate sender can still produce a technically suspicious message.
First checks for the recipient
- 1Search the whole mailbox — search by sender address, sender name, subject, attachment name, distinctive wording and approximate date. Do not assume the message was not delivered simply because it is not visible in the Inbox.
- 2Check Junk or Spam — where available, use the Not junk, Not spam or Report as not junk function rather than simply moving the message. This provides feedback to the platform.
- 3Check quarantine — use the organisation’s approved quarantine portal or notification. Note that some detection categories may require administrator action rather than user release.
- 4Check Deleted Items, archive and subfolders — also check Focused Inbox, Other, Gmail tabs, shared mailboxes and any delegated mailbox the recipient may access.
- 5Check rules and filters — review inbox rules for unfamiliar entries, rules that move, delete, forward or mark messages as read, or rules that were not intentionally created.
- 6Check blocked senders — confirm the address or domain has not been accidentally added to a blocked-sender list.
- 7Confirm the address — compare the exact recipient address the sender used against the correct address.
- 8Ask for delivery evidence — request the exact sender address, exact recipient address, date and time sent, subject, any non-delivery report, and the message ID where available.
Evidence standard
Ask the sender for evidence of delivery — not merely a screenshot showing the message in Sent Items.
First checks for the sender
The sender should check: the correct recipient address was used; the message left the Outbox; no non-delivery report or delayed-delivery notice was received; the attachment size and type are within normal limits; no suspicious links were included; and whether a marketing platform or automation tool was involved in sending. The sender should also check whether their domain’s SPF record includes the actual sending service, whether DKIM signing is active, whether DMARC alignment is correct, and whether the sending IP or domain has any current reputation problems.
Repeatedly resending the same message does not correct the technical reason it was rejected or quarantined. The same detection will apply to the same message.
A temporary diagnostic test — a plain-text message with no attachments, no links, a single recipient and a clear subject sent through the normal business sending system — can help establish whether the underlying sending path works. This is a diagnostic step, not a permanent workaround.
How administrators trace the message
A structured administrator investigation should begin by recording the exact sender and recipient addresses, the date and time including time zone, the subject, the message ID, the sending service or platform, any attachment names, known URLs and the expected mail route.
- 1Did the organisation receive the message at all?
- 2Which gateway or service handled it?
- 3What security verdict was applied?
- 4Which policy or rule applied that verdict?
- 5Where was the message delivered or held?
- 6Was it rejected, and did the sender receive an SMTP error response?
- 7Did a user or administrator subsequently move, release or delete it?
- 8Did an inbox rule act on the message after delivery?
- 9Was the message modified in transit in a way that affected authentication?
- 10Did a third-party service make the decision rather than Microsoft 365 or Google Workspace?
- 11Is this an isolated incident or a pattern affecting multiple messages or recipients?
The investigation principle
Trace first, change second.
Sender authentication in plain English
Three email-authentication standards are relevant to most missing-email investigations:
- SPF (Sender Policy Framework) — helps identify which mail systems are authorised to send email for a domain. An SPF pass means the sending server was listed in the domain’s SPF record. It does not mean the message content is safe.
- DKIM (DomainKeys Identified Mail) — adds a cryptographic signature that helps show the message was authorised by the signing domain and was not materially altered after signing. A DKIM pass does not guarantee the sender is honest or that the content is benign.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) — uses SPF and/or DKIM alignment and tells receiving systems how the domain owner wants authentication failures handled. A DMARC pass does not scan attachments or links.
Authentication failure may result from legitimate misconfiguration rather than fraud. Legitimate email forwarding can break SPF and DKIM alignment. Authentication success is one signal among many.
Authentication and safety are different things
Email authentication helps establish whether a message is authorised to use a domain. It does not certify that the message is harmless.
Delivery, authentication and trust
Delivery, authentication and trust are related — but they are not the same thing.
DMARC guidance
For a full explanation of how DMARC helps protect against email impersonation and what it cannot do, see our Technology Intelligence article on email spoofing.
Why broad allow-listing is dangerous
When an important message is unexpectedly classified, the tempting response is to trust the entire sender domain, IP range or gateway. This approach carries significant risk.
The allow-listing principle
Allow-listing says, “Apply less suspicion here.” It should never be broader than the business requirement.
A trusted supplier can still be compromised, spoofed, used to distribute malware, used for invoice fraud, or used to send malicious links. A broad domain-level trust entry does not distinguish between a genuine supplier message and an attacker who has compromised or imitated that supplier.
- Trusting an entire external domain
- Trusting an entire IP range
- Trusting all messages from a gateway
- Trusting a sender based only on their display name
- Applying reduced suspicion to every message for one mailbox
- Broadly trusting all attachments from one supplier
- Trusting messages based on a forged From address
These approaches should all be avoided or applied only with significant caution and narrow scope. Where a correction is genuinely needed, preferred approaches include fixing sender authentication, reporting the false positive through supported tools, creating a targeted exception restricted to one authenticated sender or one recipient group, and setting an expiry date on any exception.
Safer ways to correct delivery
- 1Report the false positive — use the platform’s built-in reporting and submission tools. This improves classification over time without creating a bypass.
- 2Fix the sender’s configuration — correct SPF, DKIM, DMARC, the sending platform, the From domain, the return path, routing, or any reputation problem. This solves the underlying cause rather than masking it.
- 3Correct internal rules — remove or amend incorrect inbox rules, transport rules, spam settings, content-compliance rules or third-party gateway policies.
- 4Use a targeted exception — if an exception is genuinely required, limit it by specific sender address, specific recipients, authenticated sending domain or known sending service. Do not apply it organisation-wide.
- 5Use quarantine notifications — configure appropriate users or administrators to receive notifications when messages are held, reducing the time before a legitimate message is identified and released.
- 6Review bulk-mail thresholds carefully — do not reduce organisation-wide bulk-mail sensitivity to solve a single newsletter classification.
- 7Document and schedule review — record the business reason, owner, scope, approval, date, expiry and review date for any exception created.
The safest fix
The safest fix is the smallest change that restores legitimate delivery without creating a wider route for malicious email.
A security exception without an owner or expiry date tends to become permanent.
Microsoft 365 investigation
Microsoft 365 administrators investigating a missing message should use the platform’s current investigation tools. The message trace in the Exchange admin centre provides a starting point for most missing-email investigations, showing whether a message was received, the verdict applied and the delivery action. For deeper investigation where licensed, Defender Explorer or Real-time detections provides additional signal including detection category, policy and recipient detail.
Relevant areas to review include: the quarantine portal (noting that high-confidence phishing and malware detections are typically administrator-only); user-reported messages and the Submissions portal; the email entity page for detailed verdict information; anti-spam policies including spam confidence levels and bulk complaint levels; anti-phishing policies including impersonation settings; Safe Links and Safe Attachments verdicts; the tenant allow/block list; connection filter policies; and inbound connectors. Where mail-flow rules exist, check whether any are overriding default verdicts.
Do not create a mail-flow rule that blindly sets every message from a supplier to bypass spam filtering. This creates a broad unmonitored exception that may also trust an attacker who successfully impersonates that supplier.
Policy precedence matters in Microsoft 365: preset security policies take precedence over custom policies. Only the most specific applicable policy affects a given recipient. Different detection categories have different remediation routes — a spam false positive should not be handled the same way as a malware or high-confidence phishing detection.
Google Workspace investigation
Google Workspace administrators can investigate missing messages through Email Log Search in the Admin console, which shows message delivery events, status, reason codes and timestamps. For Gmail-specific investigation, the admin console provides access to Gmail logs, message detail and the ability to identify where a message went.
Relevant admin areas include: spam settings, approved senders, email allowlists, routing configuration, content compliance, attachment compliance, blocked senders, advanced phishing and malware protection settings, and sender-authentication results. Gmail’s spam scanning remains active by default; administrators can customise how messages are handled but should do so with care.
Do not approve an entire domain merely because one expected message was classified incorrectly. A broader trust entry applies to every future message from that domain, including messages from a compromised or spoofed sending account.
Users can mark legitimate messages as not spam. Administrators should ensure appropriate users know this option exists rather than requesting broad policy changes for avoidable false positives. Platform terminology in Google Workspace differs from Microsoft 365; do not assume controls operate identically between platforms.
Third-party email security
Many businesses route email through a third-party security gateway before it reaches Microsoft 365 or Google Workspace. These services — which include products from providers such as Mimecast, Proofpoint, Barracuda, Hornetsecurity and others — apply their own filtering, quarantine and classification decisions. A message may pass through:
- 1The sender’s email platform
- 2The sender’s outbound gateway
- 3Internet mail routing
- 4The recipient’s third-party gateway
- 5Microsoft 365 or Google Workspace
- 6Mailbox-level rules
Changing Microsoft or Google settings will not fix a message held by a separate gateway in front of them.
Administrators should identify which service accepted the message, which applied the verdict, which quarantined it and where the relevant logs are held. Check whether routing causes duplicate scanning, whether connectors are correctly configured, whether authentication is preserved through the gateway, and whether any allow rules are applied at the correct layer. Third-party gateway licences should be current — an expired service may silently affect mail flow.
Warning signs of a wider problem
The following patterns suggest a problem beyond a single misclassified message and warrant urgent investigation:
- Multiple users stop receiving mail from many external senders simultaneously
- One entire domain cannot send to anyone in the business
- Outbound mail is also being rejected
- Unfamiliar inbox or forwarding rules appear in user mailboxes
- Messages disappear after confirmed delivery
- Administrator policies changed without a known reason
- Many legitimate messages move to quarantine suddenly
- A known sender’s domain unexpectedly fails SPF, DKIM or DMARC
- A known supplier begins sending unusual invoices or links
- An allow-list entry appears without approval
- Mail flow routes through an unknown connector
- A third-party gateway licence has expired
- Mail queues or delivery delays increase
- Security alerts indicate account compromise
- Quarantine releases occur without a known user or administrator action
Possible causes include account compromise (recipient or sender), DNS changes, domain or infrastructure problems, policy errors, a compromised supplier, malicious forwarding rules, domain-reputation damage or an email-provider incident.
Immediate business actions
- 1Do not turn off protection — avoid broad emergency bypasses while investigation is under way.
- 2Collect the message details — exact sender, exact recipient, date, time and subject as a minimum.
- 3Check user locations — search Inbox, Junk or Spam, quarantine, Deleted Items, archive and all inbox rules.
- 4Trace the message — use platform logs, gateway logs or message trace tools to identify whether and where the message was received.
- 5Identify the verdict — determine whether it was classified as spam, bulk, phishing, impersonation, malware, a policy match, a rule movement or a delivery failure.
- 6Report the false positive — use supported platform reporting tools to submit the misclassified message.
- 7Correct the root cause — fix authentication records, routing errors or policy mismatches where the cause is identifiable.
- 8Create the narrowest necessary exception — only where no other correction is available, and with documented scope and expiry.
- 9Document it — record the business reason, owner, scope and expiry date.
- 10Monitor the result — confirm that future legitimate messages arrive and that malicious messages continue to be blocked.
Preventing future missed email
Quarantine notifications
Ensure appropriate users receive notifications when messages are held in quarantine. A user who does not know quarantine exists will request broad allow-list changes rather than reviewing held messages.
User education
Teach staff to check Junk and quarantine regularly, to report false positives through approved methods rather than demanding broad exceptions, and to remain vigilant about suspicious messages even when they appear to come from known suppliers.
Clear escalation process
Provide a clear internal route for reporting a missing expected email, a message incorrectly quarantined, repeated delivery problems and suspected supplier compromise. An escalation process reduces the time between a legitimate message being held and a correct investigation beginning.
Sender requirements
Ask critical suppliers, marketing platforms and automated services to maintain current SPF, DKIM and DMARC records, consistent sending domains, appropriate list hygiene and functioning abuse contacts. Suppliers who do not maintain authentication are more likely to be misclassified.
Business-continuity channels
For time-critical processes — contract deadlines, urgent payment approvals, incident response — establish alternative contact methods that do not depend solely on email: telephone, a secure supplier portal, a support ticket system, a verified messaging channel or a shared platform.
Email as a single point of failure
Email should not be the only control protecting a deadline-critical business process.
Questions to ask before changing a spam filter
- 1Was the message definitely sent?
- 2Was the recipient address correct?
- 3Did our organisation receive it?
- 4Was it delivered to Junk or Spam?
- 5Was it quarantined?
- 6Was it rejected?
- 7Which security product made the decision?
- 8Which verdict was applied?
- 9Which policy applied?
- 10Did an inbox or mail-flow rule move it?
- 11Did the sender pass SPF, DKIM and DMARC?
- 12Is the sender using a new or changed mail platform?
- 13Was the message classified as bulk email?
- 14Did it contain an attachment or suspicious URL?
- 15Has the sender’s account been compromised?
- 16Is this one message or a repeated pattern?
- 17Can the sender correct the underlying authentication problem?
- 18Can a targeted exception solve it without affecting others?
- 19What malicious mail could the exception also allow?
- 20Who will own and review the exception?
- 21When will the exception expire?
- 22How will future false positives be reported?
Practical business implications
Missed email can have real cost
Legitimate false positives can disrupt sales, finance, legal and operational processes. A quarantined invoice or missed tender represents a real business consequence — but so does the phishing message that reaches the inbox because protection was reduced.
Weaker filtering creates a different cost
Broad bypasses increase exposure to phishing, malware and supplier-compromise fraud. The cost of a successful phishing attack or fraudulent payment almost always exceeds the inconvenience of a false positive.
The sender may own the root cause
Poor authentication, misconfigured sending infrastructure or poor sender reputation cannot always be safely corrected by the recipient. Where the underlying problem sits with the sender, the most effective solution is for the sender to correct their configuration.
Users need visibility
Quarantine notifications and simple false-positive reporting reduce the risk of users demanding broad allow-listing as the only way they know to escalate a delivery problem.
Exceptions need governance
Every allow rule should have a documented business reason, a named owner, a defined scope and a scheduled review date. Exceptions created under pressure and forgotten become permanent gaps.
Reliable email
Reliable email depends on both security and observability — you need to block threats and understand what happened to legitimate messages.
The IT Club View
When an important email goes missing, the natural reaction is: “Can you turn the spam filter down?” That is understandable. It starts with a proposed fix rather than a diagnosis, but it reflects a reasonable frustration.
The message may have been rejected before it arrived, quarantined as phishing, moved by an inbox rule, blocked by a third-party gateway, sent from a misconfigured domain, addressed incorrectly or never sent successfully. Weakening spam protection may do nothing to solve the actual issue. It may simply make it easier for the next fraudulent invoice or credential-stealing message to reach the inbox.
The core lesson
Do not solve one missed email by making every future email less safe.
The correct business approach is to trace the message, classify the cause, correct the underlying problem where possible, apply a narrow documented exception only where necessary, monitor the result and review exceptions regularly.
The IT Club View
The goal is not the strictest possible filter or the loosest possible filter. It is dependable email delivery with security controls that can explain and correct their decisions.
Can’t find an important email?
Use our Missing Email Investigation Checklist to establish whether the message was sent, delivered, quarantined, moved by a rule or rejected — and identify the safest corrective action.
Related business questions
Why do legitimate emails go to Junk?
Legitimate messages can trigger spam filters when the sender’s domain fails authentication, the sending IP has a poor reputation, the message content resembles common spam patterns, a marketing platform is sending on an unconfigured domain, or the message is bulk email with characteristics that scoring engines flag. The filter is making a statistical judgement rather than a deliberate error. Reporting the false positive through the platform’s built-in tools helps improve future classification.
What is the difference between Junk and quarantine?
Junk is a mailbox folder — the message has been delivered to the recipient’s mailbox but separated from the Inbox. The user can generally access and move it themselves. Quarantine is a security hold outside the normal mailbox, controlled by the email platform or gateway. Depending on the detection type and administrator configuration, the recipient may or may not be able to release a quarantined message without administrator involvement.
Can I safely add a whole domain to an allow list?
Rarely. A domain-level trust entry applies to every future message from that domain, including messages from a compromised sender account, a spoofed From address, or an attacker who has taken over the supplier’s sending infrastructure. Where an exception is genuinely required, target a specific sender address with authentication alignment checks rather than the entire domain. See our guidance on connected applications for related risks from compromised trusted suppliers.
Does SPF stop email going to spam?
SPF helps identify which servers are authorised to send for a domain, but passing SPF does not guarantee delivery to the Inbox. Spam filters use many signals simultaneously. A message can pass SPF and still be classified as spam based on content, sending reputation, bulk-mail characteristics or other signals. SPF is one factor among many, and its absence or failure is a signal that increases suspicion rather than one that alone determines the outcome.
Does a DMARC pass mean an email is safe?
No. A DMARC pass confirms that the message passed SPF or DKIM alignment for the sending domain — it does not scan attachments, check URLs, assess content for social engineering, or confirm that the sender is acting in good faith. A compromised legitimate sender can send malicious messages that pass DMARC. A DMARC pass is an authentication signal, not a safety certificate.
How do I check Microsoft 365 quarantine?
Users with appropriate permissions can typically review quarantined messages through the Microsoft Defender portal at security.microsoft.com under the Email and Collaboration section. Administrators can review all quarantined messages, apply policies controlling which detection types users may view or release, and configure quarantine notifications to alert recipients when messages are held. Licensing determines which investigation tools are available. Check current Microsoft documentation for navigation, as the portal is updated regularly.
How do I find a missing email in Google Workspace?
Google Workspace administrators can search for missing messages using Email Log Search in the Admin console. This shows delivery events, status codes and timestamps for messages sent to or from the organisation. Results indicate whether a message was accepted, rejected, marked as spam or delivered. Users can check the Gmail Spam folder directly. For more detailed investigation, the Admin console provides access to Gmail logs where licensed investigation tooling is available.
Can an inbox rule hide incoming email?
Yes. Inbox rules can automatically move, delete, mark as read or forward messages without the user being aware it has happened. This includes rules created intentionally by the user, rules created by an administrator through transport or mail-flow rules, and — in cases of account compromise — malicious rules created by an attacker to hide security alerts or redirect sensitive correspondence. Reviewing inbox rules and forwarding settings should be part of any missing-email investigation.
Why did a supplier’s email suddenly start being blocked?
Common causes include the supplier changing their email provider or sending platform without updating SPF and DKIM records, a compromised supplier account damaging the sending domain’s reputation, a new domain being used to send from that has little established reputation, a marketing platform misconfiguration, or a newly applied anti-spam policy at your organisation. Investigate the delivery logs before concluding the cause — and consider asking the supplier to check their authentication and sending configuration.
Should users be allowed to release quarantined email?
It depends on the detection type. Spam and bulk-mail quarantine releases are lower risk and can typically be permitted for users. Phishing and high-confidence phishing detections carry higher risk and should generally require administrator review before release. Malware detections should not be releasable by ordinary users. Configure quarantine policies to reflect these distinctions rather than allowing unrestricted self-release across all detection categories.
Can a compromised trusted supplier bypass an allow list?
Yes. An allow-list entry based on a sender’s domain or sending infrastructure applies to every message from that source, including messages sent from a compromised account at that supplier. A supplier who has been breached may send malicious invoices, credential-stealing links or malware payloads that benefit from the trust your allow list extends. This is one of the principal reasons broad domain-level allow-listing is dangerous — it reduces friction for a trusted sender but also reduces friction for an attacker who has taken over that sender.
Administrator Technical Note
This section is intended for IT administrators, email security engineers and compliance leads rather than general readers. It covers technical investigation workflows, message-header analysis, platform-specific controls and exception design.
Technical investigation workflow
- 1Collect identifiers: sender address, envelope sender, From address, reply-to address, recipient, date and time with time zone, subject, Internet Message ID, network message ID where applicable, SMTP response, sending IP, sending hostname, return path, attachment names and URLs
- 2Run message trace or Email Log Search to establish whether the organisation received the message
- 3Identify all mail hops and which service applied each verdict
- 4Locate the security verdict: spam, phishing, high-confidence phishing, malware, impersonation, bulk, policy match or rule action
- 5Determine the applicable policy and confirm no higher-priority policy overrode it
- 6Inspect authentication results: SPF result, DKIM result, DMARC result, ARC results where applicable, and From-domain alignment
- 7Inspect message headers: Received headers, Authentication-Results, anti-spam classification headers, bulk-complaint level and spam-confidence level headers, gateway-added headers and forwarding indicators
- 8Review user and administrator inbox rules and transport rules for rule actions that may have moved, deleted or forwarded the message
- 9Review third-party gateway logs if a security gateway is in the mail path
- 10Check sender reputation where appropriate: sending IP reputation, domain reputation, DMARC reports
- 11Submit false positive through the platform’s approved submission mechanism
- 12Apply targeted remediation: fix authentication, correct routing, amend the offending rule, create a narrow time-limited exception
- 13Monitor subsequent messages to confirm resolution
- 14Remove temporary exceptions when no longer required
A single “pass” or “fail” value rarely explains the entire delivery decision. Review the full authentication chain and applied policy before making changes.
Microsoft 365 technical review
Use the Exchange admin centre message trace for basic investigation. Where licensed, use Defender Explorer or Real-time detections for richer signal including detection category, email entity details, Safe Links detonation results and Safe Attachments verdicts. Review the email entity page for the full verdict chain. Check the quarantine portal, noting that spam and bulk quarantine may permit user action while high-confidence phishing and malware typically require administrator release.
When reviewing policy configuration: preset Standard and Strict security policies take precedence over custom policies; only the most specific applicable policy affects a given recipient; anti-phishing impersonation settings apply to specific sender addresses and domains listed there. The tenant allow/block list entries should be time-limited where the platform supports it. Spoof intelligence overrides differ from anti-spam allow entries. Connection filter safe IPs bypass spam filtering — ensure these are currently accurate and minimal.
- SCL (spam confidence level) and BCL (bulk complaint level) are embedded in message headers and inform anti-spam policy decisions
- Transport rules that set SCL=-1 or bypass spam filtering are dangerous and should be documented, minimal and regularly reviewed
- A sender entry based solely on the visible From address may also trust an attacker who successfully spoofs that address
- Invalidating a user’s safe-sender list entry may require the administrator to check per-user safe-sender settings
- Preset Standard or Strict policies offer a structured security baseline and should be considered before applying arbitrary custom weakening
Google Workspace technical review
Use Email Log Search to trace the message through all Google-side delivery events. Review the spam settings in the Admin console: approved senders and email allowlists should be scoped to specific addresses or authenticated sending hosts where possible rather than entire domains. Check inbound gateways to confirm connector configuration, whether authentication is preserved and whether routing rules interact with spam settings. Review content compliance and attachment compliance rules that may have acted on the message.
- Allowlisting an IP range that includes large shared cloud sending infrastructure may trust many unrelated senders
- Routing that bypasses Gmail spam scanning should be documented and reviewed regularly
- Unauthenticated senders that are approved risk extending trust to spoofed messages
- Domain-wide delegation in Google Workspace service accounts is a separate risk category — see connected-application guidance
- Admin audit logs provide a record of configuration changes including who made them and when
Safe exception design
Where an exception is genuinely required, the design should specify: exact sender address or authenticated sending domain; specific recipients or recipient group; expected sending IP or infrastructure; limited duration; logging and alerting for matched messages; documented business approval; expiry date; and a review date. Avoid trusting all senders from a domain without authentication checks, trusting large shared IP ranges, disabling malware or phishing protection, bypassing protection for executive mailboxes or creating permanent undocumented exceptions.
A bypass based only on the visible sender address may also trust an attacker who successfully spoofs that address.
Quarantine governance
Define which detection categories users may view, which they may release without approval, which require a release request, and which require administrator action only. Set notification frequency so users are aware when messages are held. Define administrator review frequency for quarantine backlogs. Allowing unrestricted self-release of high-risk detections — particularly phishing and high-confidence phishing — may undermine the security control entirely.
Email-authentication remediation
Where the sender controls the affected domain, review all authorised sending platforms and ensure they are included in the SPF record. Check the SPF lookup count — excessive lookups cause failures. Confirm DKIM signing is active for the From domain or a DMARC-aligned domain. Check DMARC alignment mode and subdomain policy. Review DMARC aggregate reports to identify unexpected sending sources. Do not publish a DMARC enforcement policy (p=quarantine or p=reject) without first understanding all legitimate sending sources and confirming authentication passes for each.
Operational Heartbeat
Email-delivery risk changes as new suppliers are added, marketing platforms change, senders change mail providers, authentication records change, filtering engines update, users create new rules, attackers alter phishing techniques, gateways change configuration, mail-flow rules accumulate, exceptions are added, staff leave, domains expire, services lose licences and sender reputation changes.
A recurring review should check false-positive rates, false-negative incidents, quarantine volume and trends, user release requests, blocked legitimate senders, allow-list entries and their owners, exception expiry dates, mail-flow rules, inbox-rule alerts for anomalous new rules, sender-authentication failures and DMARC reports, gateway health, message-trace trends, bulk-mail thresholds, user reporting volume, supplier changes, platform alerts and corrective actions taken.
Operational Heartbeat
Email filtering needs an operational heartbeat: false positives, quarantine, authentication, exceptions and delivery failures should be reviewed rather than treated as isolated complaints.
Plain-English Takeaway
If an important email appears to be missing, do not immediately weaken your spam filter. Check the Junk or Spam folder, quarantine, rules and delivery logs to identify what happened. Fix the sender’s configuration or the specific policy where possible, and use only narrow, documented exceptions that do not unnecessarily reduce protection for everyone.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
Which Apps Can Access Your Google or Microsoft Account?
Signing into another service with Google or Microsoft is convenient — but some applications request far more than basic identity information. That access may remain long after you stop using the service, and changing your password does not necessarily remove it.
Read articleCould a Browser Extension Be Reading Your AI Conversations?
Employees use AI chatbots for drafting, research and problem-solving — and sometimes paste in confidential information. The AI provider's privacy terms are not the only risk. A browser extension with the right permissions may already be reading the conversation.
Read articleWould You Let an AI Coach Your Employees?
AI coaching platforms can now let employees practise workplace conversations with interactive avatars and receive automated scoring and feedback. That could make training more accessible and repeatable. The question is whether the practice room quietly becomes a performance monitoring system.
Read article