To fix an email false positive in Microsoft 365 without weakening protection, submit the blocked message to Microsoft on the Submissions page in the Microsoft Defender portal, select I've confirmed it's clean, and then select Allow this message. Microsoft then creates allow entries in the Tenant Allow/Block List only for the sender, URL or file that actually caused the block, the entries start working within about 5 minutes, and by default they are removed 45 days after the filters stop needing them. Avoid the older allow methods, such as allowed sender lists in anti-spam policies or sender-domain-only mail flow rules, because they skip far more of the filtering stack.
Who this is for and what you will have
This guide is for Microsoft 365 and security administrators who handle "my email was blocked" tickets in Exchange Online. It applies to all organizations with cloud mailboxes; some details, such as the size of the Tenant Allow/Block List and Threat Explorer links, depend on Defender for Office 365.
At the end you will have:
- A triage routine that finds out which filter blocked a message.
- The submission workflow for false positive email, URLs and attachments, with expiring allow entries.
- Rules for when a direct allow entry is acceptable and when it isn't.
- A review process for allow entries, so exceptions don't pile up.
How allow entries work
The Tenant Allow/Block List overrides filtering verdicts during mail flow and at time of click. It has tabs for Domains & addresses, Spoofed senders, URLs, Files and IP addresses. Block entries always take precedence over allow entries.
Two ways to create allow entries
| Method | Verdicts it can override | Entry types | Override shown in the portal |
|---|---|---|---|
| Submissions page, I've confirmed it's clean > Allow this message | Up to high confidence phishing | Sender, spoofed sender, URL, file | Up to high confidence phishing |
| Directly on the Tenant Allow/Block List or with PowerShell | Bulk, spam, high confidence spam, phishing (not high confidence phishing) | Domains and email addresses, URLs, spoofed senders, IP addresses | Up to regular confidence phishing |
File allow entries can only come from submissions. Allow entries created through submissions automatically update directly created entries for the same value.
What a submission actually allows
When you submit a message as clean and choose Allow this message, allow entries are created during mail flow based on the filters that judged the message bad:
- Blocked by spoof intelligence: an entry on the Spoofed senders tab.
- Blocked by file-based filters: an entry on the Files tab.
- Blocked by URL-based filters: an entry on the URLs tab.
- Blocked for any other reason: an entry for the sender email address or domain on Domains & addresses.
- Blocked by user or domain impersonation protection: no Tenant Allow/Block List entry. The sender or domain is added to Trusted senders and domains in the anti-phishing policy that detected it.
- Not blocked by filtering at all: no allow entry anywhere.
When an allowed entity is seen again, only the filters associated with that entity are skipped; everything else in the message is still evaluated. An allowed sender's message still has to pass URL and file checks, and an allowed URL doesn't make an untrusted sender trusted. That scoping is what makes submissions safer than broad allowlists.
Expiration
| Option | Behavior |
|---|---|
| 45 days after last used date (default) | The entry's last used date updates whenever the filters encounter the entity as bad; the entry is removed 45 days after the filters determine it is clean |
| 1 day, 7 days, 30 days | Fixed expiry |
| Specific date | Up to 30 days from today |
Allow entries for spoofed senders never expire. If Microsoft determines that an allow entry is no longer needed, it removes the entry and the built-in alert policy Removed an entry in Tenant Allow/Block List raises an alert.
Entry limits for domains and email addresses
| Subscription | Allow entries | Block entries |
|---|---|---|
| Without Defender for Office 365 | 500 | 500 |
| Defender for Office 365 Plan 1 | 1,000 | 1,000 |
| Defender for Office 365 Plan 2 | 5,000 | 10,000 |
Spoofed sender entries are limited to 1,024 in total across allow and block.
Prerequisites
- For submissions: membership in the Security Administrator or Security Reader role group in the Defender portal, or the matching Entra ID role.
- For the Tenant Allow/Block List: Organization Management or Security Administrator, or Security Operator assigned directly in the Exchange admin center under Roles > Admin Roles. With Defender XDR Unified RBAC active for email and collaboration, the permission is Authorization and settings/Security settings/Detection tuning (manage).
- For release with allow from quarantine: membership in the Security Administrators role group shows the Submit the message to Microsoft to improve detection option.
- The message itself, or its network message ID. Admins can submit messages up to 30 days old if they are still in the mailbox; for on-premises mailboxes the limit is 7 days.
- Exchange Online PowerShell for the scripted steps.
Step 1: Find out what blocked the message
Don't create an allow entry until you know which filter acted. The fix depends on it.
- Check quarantine. In the Defender portal, open Email & collaboration > Review > Quarantine > Email (
https://security.microsoft.com/quarantine) and search for the message. The quarantine reason tells you the verdict, for example spam, phishing, high confidence phishing, malware or a mail flow rule. - Check the headers if the message reached Junk Email. The X-Forefront-Antispam-Report header records the verdict. Microsoft documents values such as
SFV:SKNwhen a mail flow rule bypassed spam filtering,SFV:SFEwhen a user's Safe Senders list bypassed it, andIPV:CALwhen the IP Allow List was used. - Get the network message ID. It is in the X-MS-Exchange-Organization-Network-Message-Id header, or X-MS-Office365-Filtering-Correlation-Id in quarantined messages. You need it to submit without having the file.
- Check for your own blocks. A block entry for a URL or domain in the Tenant Allow/Block List can make a legitimate message high confidence phishing. If the message contains a blocked URL or domain, fix the block entry rather than adding an allow.
If you need to trace the message's path first, message trace in the Defender portal or Exchange Online PowerShell shows delivery events.
Step 2: Submit the message as a false positive
- In the Defender portal, go to Actions & submissions > Submissions (
https://security.microsoft.com/reportsubmission) and keep the Emails tab selected. - Select Submit to Microsoft for analysis.
- In the flyout:
- Select the submission type: Email.
- Add the network message ID or upload the email file: paste the network message ID, or upload the
.emlor.msgfile. - Choose at least one recipient who had an issue: the policy check runs against these recipients to find out whether user or organization policies or overrides caused the block.
- Why are you submitting this message to Microsoft?: select I've confirmed it's clean and then Next. Choose It appears clean instead only if you aren't sure and want Microsoft's verdict first.
- On the second page, select Allow this message, keep Remove allow entry after at 45 days after last used date unless you want a shorter window, and enter an Allow entry note with the ticket number and business owner.
- Select Submit, then Done.
After a few moments the resulting entries appear on the relevant tab of the Tenant Allow/Block List. Admin submissions are throttled to 150 per 15 minutes, and the same item can be submitted once per 15 minutes and three times in 24 hours.
Releasing from quarantine at the same time
If the message is in quarantine, you can do both in one step. Select the message, choose Release email, select Submit the message to Microsoft to improve detection (false positive), then Allow this message and an expiry. The same 45-days-after-last-used default applies. You can't release a message to the same recipient twice.
False positive URLs and attachments
When the problem is a link or file rather than the sender, use the URLs or Email attachments tab:
- URLs: enter up to 50 URLs, select I've confirmed it's clean, then Allow this URL. Variations of the reported URL are also allowed, so reporting
www.contoso.com/abccoverswww.contoso.com/abc?id=1and deeper paths under it. Safe Links detonation and URL reputation checks are overridden for that URL. - Email attachments: upload the file, select I've confirmed it's clean, then Allow this file. Safe Attachments detonation and file reputation checks are overridden for that file.
Don't use URL allow entries for third-party phishing simulation links. Microsoft directs those to the advanced delivery policy instead.
Step 3: Read the result
Select the submission on the Emails tab to open its details. The result explains whether email authentication failed at delivery, whether a policy or override affected the verdict, current detonation results and grader feedback. If an override or policy configuration explains the block, the result usually appears within minutes; detonation and grader analysis can take up to a day.
Act on what the result tells you:
- A policy or override in your tenant caused it. Fix that policy, for example an anti-spam blocked sender list, a mail flow rule or one of your own block entries.
- Email authentication failed. The real fix is on the sender's side: SPF, DKIM and DMARC for their domain. An allow entry should be temporary while they correct it.
- No threats found. Microsoft can adjust filtering, and your allow entry will age out once it is no longer used.
- You disagree with the result. For completed items on the Emails or URLs tab with a result of Threats found, No threats found, Spam or Bulk, select Dispute submission result and choose Result. You can dispute an item only once; resubmitting starts the analysis over.
Step 4: Direct allow entries, only when justified
Sometimes you know a sender will be filtered as spam or bulk before any message arrives, for example a new payroll provider. For those verdicts you can create the entry directly.
In the portal: Email & collaboration > Policies & rules > Threat policies > Tenant Allow/Block Lists > Domains & addresses > Add > Allow. Enter up to 20 values, choose the expiry and add a note.
In PowerShell, -RemoveAfter 45 sets the 45-days-after-last-used behavior and is the only valid value for that parameter:
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
New-TenantAllowBlockListItems -ListType Sender -Allow -Entries "payroll@fabrikam.com" -RemoveAfter 45 -Notes "INC-20417 payroll notices, owner: HR"Prefer an email address over a whole domain. Microsoft notes that if you allow at least seven email addresses in the same domain, submissions roll them up into a domain allow entry automatically, so watch for that when many addresses from one sender are being allowed.
Allow methods to avoid
Microsoft ranks the available allow methods from most to least recommended:
| Rank | Method | Main risk |
|---|---|---|
| 1 | Tenant Allow/Block List allow entries | Scoped to the entity that caused the block; expire by default |
| 2 | Mail flow rules that set SCL to bypass spam filtering | A rule matching only the sender domain lets spoofed mail skip spam filtering and authentication checks |
| 3 | Outlook Safe Senders | Per mailbox; bypasses parts of the stack and interferes with zero-hour auto purge |
| 4 | IP Allow List in the connection filter policy | Skips spam filtering and SPF, DKIM and DMARC for that source |
| 5 | Allowed sender or domain lists in anti-spam policies | Bypasses spam, spoof and phishing protection (except high confidence phishing) and sender authentication |
Whatever you use, messages identified as malware or high confidence phishing are still quarantined. If you must use a mail flow rule, add a condition that the Authentication-Results header contains dmarc=pass or dmarc=bestguesspass, or use a tightly scoped IP Allow List entry, and never use your own accepted domains or popular domains as the condition.
Impersonation detections are a separate case. Submitting a message blocked by user or domain impersonation protection doesn't create a Tenant Allow/Block List entry. Handle those in the anti-phishing policy's trusted senders list, as described in Defender for Office 365 anti-phishing impersonation settings.
Verify and review entries
After creating an entry:
Get-TenantAllowBlockListItems -ListType Sender -Allow | Format-List
Get-TenantAllowBlockListItems -ListType Url -Allow | Format-List
Get-TenantAllowBlockListSpoofItems -Action AllowIn the portal, the Domains & addresses tab shows Override verdicts, Last used date and Remove on for each entry, and the details flyout has View submission for entries created by a submission. Filter by Last used date to find entries that haven't been needed recently, and by Never expire to find permanent exceptions.
To shorten or change an entry, use Edit in the portal or Set-TenantAllowBlockListItems; to delete it, use Remove-TenantAllowBlockListItems:
Remove-TenantAllowBlockListItems -ListType Sender -Entries "payroll@fabrikam.com"Troubleshooting
The submission didn't create an allow entry. Either the filters didn't find the sender malicious, or the block came from impersonation protection, which updates the anti-phishing policy instead. Check the anti-phishing policy's Trusted senders and domains list.
I can't add an allow entry for a domain on the Domains & addresses tab for this message. The verdict was malware or high confidence phishing. Direct allow entries only override up to regular phishing; use the Submissions page.
Allowed mail is still quarantined as high confidence phishing. A block entry for a URL or domain in the message overrides the allow, because block entries take precedence. Review your block entries.
A Safe Senders entry for a domain doesn't stop quarantine. When the policy action is Quarantine, Outlook Safe Senders domain entries aren't honored; address entries are, unless the message is malware, high confidence phishing or matches a Tenant Allow/Block List block entry.
Users can't email a partner after you blocked them. Block entries for domains and addresses also stop outbound mail, with the NDR 550 5.7.703 Your message can't be delivered because messages to XXX, YYY are blocked by your organization using Tenant Allow Block List. Remove or narrow the block entry.
Adding an address with special characters fails. Encode the special characters with UTF-8 hexadecimal URL encoding, for example %22 for a double quotation mark and %20 for a space.
A released message never arrives or is quarantined again. Non-Microsoft filtering services, outbound connectors and inbox rules are common causes. Use message trace to confirm delivery.
Checklist
- Verdict and responsible filter identified before any allow is created.
- False positives submitted with I've confirmed it's clean and Allow this message, URL or file.
- Default 45-days-after-last-used expiry kept unless there is a reason for a shorter window.
- Every allow entry has a note with the ticket and owner.
- Direct allow entries used only for bulk, spam and regular phishing, and scoped to addresses rather than domains where possible.
- No sender-domain-only SCL bypass rules or broad anti-spam allowed domain lists.
- Impersonation false positives handled in the anti-phishing policy.
- Monthly review of allow entries by last used date and of any never-expiring entries.
References
- Submit messages, URLs, and attachments for analysis in the Microsoft Defender portal
- Manage allows and blocks in the Tenant Allow/Block List
- Allow or block email using the Tenant Allow/Block List
- Create allowlists
- Manage quarantined messages and files as an admin
- New-TenantAllowBlockListItems
- Get-TenantAllowBlockListItems