Do emails from one specific person or one specific company always end up in your Junk Email folder or quarantine? The problem may lie in your own Outlook settings, but it could also be due to the sender’s technical configuration or reputation. In this article, you will read what you can check yourself and when it is better to have IT investigate this.
It can happen that you receive almost all emails normally, but messages from one specific contact person or organisation are repeatedly blocked.
This could be, for example:
- a regular supplier;
- a customer;
- an external accountant;
- a particular webshop;
- a partner company;
- one specific employee of an external organisation.
First: spam or quarantine?
This distinction is important.
Junk Email
If the message is in your Junk Email folder, then the message has been delivered to your mailbox but classified as spam.
Quarantine
If the message is in Microsoft 365 quarantine, then your organisation’s security has blocked the message before it could normally reach your inbox.
Something that Outlook locally treats as junk can sometimes be adjusted by the user. A message blocked by central security often requires investigation by your IT administrator.
1. Check if you have accidentally blocked the sender
Outlook allows you to block individual email addresses and entire domains.
Therefore, check if the sender is not accidentally on your Blocked Senders list.
In the new Outlook and Outlook on the web, you can check this via:
Look there for:
- the full email address of the sender;
- or possibly the full domain name of the company.
If the sender is listed under Blocked senders and domains, remove them from that list when you are sure they are trustworthy.
2. Add a trusted sender to Safe Senders
If you are sure that a particular person is trustworthy, you can add the email address to your list of Safe Senders.
In the new Outlook or Outlook on the web, go to:
For example, add:
If you want to consider an entire organisation as safe, in some situations a domain can also be added:
If the problem concerns only one person, it is usually safer to add only that specific email address.
3. In classic Outlook, you can use Never Block Sender
Are you still using classic Outlook for Windows?
Then you can select a trusted message and choose:
This adds the sender to Outlook’s safe senders list.
a local safe senders list is not always sufficient. Exchange Online or your organisation’s security solution can still block a message centrally.
4. The message is in quarantine
If the mail is not in Junk Email but in Microsoft 365 quarantine, your organisation’s central security intercepted the message.
This can happen, for example, because Microsoft or another security layer classifies the message as:
- spam;
- high-confidence spam;
- phishing;
- high-confidence phishing;
- malware;
- a message with a suspicious link or attachment.
Depending on your organisation’s policy, you may be able to view, release, or report certain messages yourself.
You can open Microsoft 365 quarantine via:
The real account of a customer or supplier can also be hacked.
5. Why is the same sender repeatedly blocked?
If the problem keeps recurring, there may be more going on than your own Outlook settings.
Possible causes include:
- The sender’s SPF is misconfigured;
- DKIM is missing or fails;
- DMARC fails;
- the sending domain has a poor reputation;
- the mail server used has a poor reputation;
- the sender uses an external application that is misconfigured;
- links in the message are considered suspicious;
- attachments trigger a security rule;
- the message technically resembles phishing;
- the sender’s organisation has a problem with its mail configuration.
6. Do not simply add an entire domain to an allowlist
It may seem easy to say:
But that is not always wise.
A full domain exception can mean that certain security checks are applied less strictly to all messages from that domain.
If that organisation’s domain is later abused or an account hacked, such a broad exception can pose a security risk.
7. How does IT know why the message is blocked?
An IT administrator can check much more than just the folder where the message ended up.
For example, we can look at:
- the full email headers;
- SPF results;
- DKIM validation;
- DMARC alignment;
- the Spam Confidence Level;
- anti-phishing detections;
- message trace;
- quarantine data;
- suspicious links or attachments;
- the reputation of the sending infrastructure.
This usually allows determining whether:
- your environment is reacting too strictly;
- the sender is technically misconfigured;
- or the message was rightly treated as suspicious.
It is not always your IT department that can solve the problem
If it turns out that the sender consistently makes errors with SPF, DKIM, DMARC or their sending platform, then the IT partner of that organisation must fix the problem.
Your IT administrator can help to technically demonstrate what is going wrong.
all messages from a supplier fail DMARC because their invoicing software sends email in a way that is not correctly configured. Your spam filter may then not be the problem but rather the one detecting the problem.
When can you simply mark the sender as safe?
This can be reasonable when:
- you know the sender personally;
- the correct email address has been confirmed;
- it concerns a normal spam classification;
- there are no signs of phishing or malware;
- the technical analysis does not show a bigger problem.
But with repeated quarantine, phishing detection or authentication failures, it is best to have the message investigated first.
FLEXAMIT can investigate this for you
Are you a FLEXAMIT customer and do emails from a particular person or organisation systematically end up in spam or quarantine?
Then we can investigate why Microsoft 365 or another security layer is blocking the message.
FLEXAMIT can check, among other things, the mail headers, Microsoft 365 message trace, quarantine data and email authentication.
This way, we avoid solving a problem by unnecessarily disabling security or making too broad an exception.
Contact our service desk via:
support@flexamit.com
What should you send to support?
To enable a quick investigation of the problem, it is best to provide:
- the sender’s email address;
- the sender’s domain;
- the date and time of a sample message;
- the recipient within your organisation;
- whether the message ended up in spam or quarantine;
- possibly a screenshot or quarantine message.
The technical details of the original message can be useful to determine the cause.
In summary
- First check if the sender is accidentally blocked.
- A known sender can be added to Safe Senders if appropriate.
- Spam and quarantine are not the same.
- A central Microsoft 365 security rule can override a local safe sender setting.
- Repeated problems can be caused by SPF, DKIM, DMARC or the sender’s reputation.
- Do not simply put an entire external domain permanently on an allowlist.
- A known company can itself be compromised.
- Have the technical cause investigated first in case of repeated problems.
Comments
0 comments
Please sign in to leave a comment.