Security & identity

Fix email false positives with submissions and the Tenant Allow/Block List

Release wrongly blocked email in Microsoft 365 the safe way: admin submissions, expiring Tenant Allow/Block List allow entries, and the allow methods to avoid.

13 min read
On this page

To fix an email false positive in Microsoft 365 without weakening protection, submit the blocked message to Microsoft on the Submissions page in the Microsoft Defender portal, select I've confirmed it's clean, and then select Allow this message. Microsoft then creates allow entries in the Tenant Allow/Block List only for the sender, URL or file that actually caused the block, the entries start working within about 5 minutes, and by default they are removed 45 days after the filters stop needing them. Avoid the older allow methods, such as allowed sender lists in anti-spam policies or sender-domain-only mail flow rules, because they skip far more of the filtering stack.

Who this is for and what you will have

This guide is for Microsoft 365 and security administrators who handle "my email was blocked" tickets in Exchange Online. It applies to all organizations with cloud mailboxes; some details, such as the size of the Tenant Allow/Block List and Threat Explorer links, depend on Defender for Office 365.

At the end you will have:

  • A triage routine that finds out which filter blocked a message.
  • The submission workflow for false positive email, URLs and attachments, with expiring allow entries.
  • Rules for when a direct allow entry is acceptable and when it isn't.
  • A review process for allow entries, so exceptions don't pile up.

How allow entries work

The Tenant Allow/Block List overrides filtering verdicts during mail flow and at time of click. It has tabs for Domains & addresses, Spoofed senders, URLs, Files and IP addresses. Block entries always take precedence over allow entries.

Two ways to create allow entries

MethodVerdicts it can overrideEntry typesOverride shown in the portal
Submissions page, I've confirmed it's clean > Allow this messageUp to high confidence phishingSender, spoofed sender, URL, fileUp to high confidence phishing
Directly on the Tenant Allow/Block List or with PowerShellBulk, spam, high confidence spam, phishing (not high confidence phishing)Domains and email addresses, URLs, spoofed senders, IP addressesUp to regular confidence phishing

File allow entries can only come from submissions. Allow entries created through submissions automatically update directly created entries for the same value.

What a submission actually allows

When you submit a message as clean and choose Allow this message, allow entries are created during mail flow based on the filters that judged the message bad:

  • Blocked by spoof intelligence: an entry on the Spoofed senders tab.
  • Blocked by file-based filters: an entry on the Files tab.
  • Blocked by URL-based filters: an entry on the URLs tab.
  • Blocked for any other reason: an entry for the sender email address or domain on Domains & addresses.
  • Blocked by user or domain impersonation protection: no Tenant Allow/Block List entry. The sender or domain is added to Trusted senders and domains in the anti-phishing policy that detected it.
  • Not blocked by filtering at all: no allow entry anywhere.

When an allowed entity is seen again, only the filters associated with that entity are skipped; everything else in the message is still evaluated. An allowed sender's message still has to pass URL and file checks, and an allowed URL doesn't make an untrusted sender trusted. That scoping is what makes submissions safer than broad allowlists.

Expiration

OptionBehavior
45 days after last used date (default)The entry's last used date updates whenever the filters encounter the entity as bad; the entry is removed 45 days after the filters determine it is clean
1 day, 7 days, 30 daysFixed expiry
Specific dateUp to 30 days from today

Allow entries for spoofed senders never expire. If Microsoft determines that an allow entry is no longer needed, it removes the entry and the built-in alert policy Removed an entry in Tenant Allow/Block List raises an alert.

Entry limits for domains and email addresses

SubscriptionAllow entriesBlock entries
Without Defender for Office 365500500
Defender for Office 365 Plan 11,0001,000
Defender for Office 365 Plan 25,00010,000

Spoofed sender entries are limited to 1,024 in total across allow and block.

Prerequisites

  • For submissions: membership in the Security Administrator or Security Reader role group in the Defender portal, or the matching Entra ID role.
  • For the Tenant Allow/Block List: Organization Management or Security Administrator, or Security Operator assigned directly in the Exchange admin center under Roles > Admin Roles. With Defender XDR Unified RBAC active for email and collaboration, the permission is Authorization and settings/Security settings/Detection tuning (manage).
  • For release with allow from quarantine: membership in the Security Administrators role group shows the Submit the message to Microsoft to improve detection option.
  • The message itself, or its network message ID. Admins can submit messages up to 30 days old if they are still in the mailbox; for on-premises mailboxes the limit is 7 days.
  • Exchange Online PowerShell for the scripted steps.

Step 1: Find out what blocked the message

Don't create an allow entry until you know which filter acted. The fix depends on it.

  1. Check quarantine. In the Defender portal, open Email & collaboration > Review > Quarantine > Email (https://security.microsoft.com/quarantine) and search for the message. The quarantine reason tells you the verdict, for example spam, phishing, high confidence phishing, malware or a mail flow rule.
  2. Check the headers if the message reached Junk Email. The X-Forefront-Antispam-Report header records the verdict. Microsoft documents values such as SFV:SKN when a mail flow rule bypassed spam filtering, SFV:SFE when a user's Safe Senders list bypassed it, and IPV:CAL when the IP Allow List was used.
  3. Get the network message ID. It is in the X-MS-Exchange-Organization-Network-Message-Id header, or X-MS-Office365-Filtering-Correlation-Id in quarantined messages. You need it to submit without having the file.
  4. Check for your own blocks. A block entry for a URL or domain in the Tenant Allow/Block List can make a legitimate message high confidence phishing. If the message contains a blocked URL or domain, fix the block entry rather than adding an allow.

If you need to trace the message's path first, message trace in the Defender portal or Exchange Online PowerShell shows delivery events.

Step 2: Submit the message as a false positive

  1. In the Defender portal, go to Actions & submissions > Submissions (https://security.microsoft.com/reportsubmission) and keep the Emails tab selected.
  2. Select Submit to Microsoft for analysis.
  3. In the flyout:
    • Select the submission type: Email.
    • Add the network message ID or upload the email file: paste the network message ID, or upload the .eml or .msg file.
    • Choose at least one recipient who had an issue: the policy check runs against these recipients to find out whether user or organization policies or overrides caused the block.
    • Why are you submitting this message to Microsoft?: select I've confirmed it's clean and then Next. Choose It appears clean instead only if you aren't sure and want Microsoft's verdict first.
  4. On the second page, select Allow this message, keep Remove allow entry after at 45 days after last used date unless you want a shorter window, and enter an Allow entry note with the ticket number and business owner.
  5. Select Submit, then Done.

After a few moments the resulting entries appear on the relevant tab of the Tenant Allow/Block List. Admin submissions are throttled to 150 per 15 minutes, and the same item can be submitted once per 15 minutes and three times in 24 hours.

Releasing from quarantine at the same time

If the message is in quarantine, you can do both in one step. Select the message, choose Release email, select Submit the message to Microsoft to improve detection (false positive), then Allow this message and an expiry. The same 45-days-after-last-used default applies. You can't release a message to the same recipient twice.

False positive URLs and attachments

When the problem is a link or file rather than the sender, use the URLs or Email attachments tab:

  • URLs: enter up to 50 URLs, select I've confirmed it's clean, then Allow this URL. Variations of the reported URL are also allowed, so reporting www.contoso.com/abc covers www.contoso.com/abc?id=1 and deeper paths under it. Safe Links detonation and URL reputation checks are overridden for that URL.
  • Email attachments: upload the file, select I've confirmed it's clean, then Allow this file. Safe Attachments detonation and file reputation checks are overridden for that file.

Don't use URL allow entries for third-party phishing simulation links. Microsoft directs those to the advanced delivery policy instead.

Step 3: Read the result

Select the submission on the Emails tab to open its details. The result explains whether email authentication failed at delivery, whether a policy or override affected the verdict, current detonation results and grader feedback. If an override or policy configuration explains the block, the result usually appears within minutes; detonation and grader analysis can take up to a day.

Act on what the result tells you:

  • A policy or override in your tenant caused it. Fix that policy, for example an anti-spam blocked sender list, a mail flow rule or one of your own block entries.
  • Email authentication failed. The real fix is on the sender's side: SPF, DKIM and DMARC for their domain. An allow entry should be temporary while they correct it.
  • No threats found. Microsoft can adjust filtering, and your allow entry will age out once it is no longer used.
  • You disagree with the result. For completed items on the Emails or URLs tab with a result of Threats found, No threats found, Spam or Bulk, select Dispute submission result and choose Result. You can dispute an item only once; resubmitting starts the analysis over.

Step 4: Direct allow entries, only when justified

Sometimes you know a sender will be filtered as spam or bulk before any message arrives, for example a new payroll provider. For those verdicts you can create the entry directly.

In the portal: Email & collaboration > Policies & rules > Threat policies > Tenant Allow/Block Lists > Domains & addresses > Add > Allow. Enter up to 20 values, choose the expiry and add a note.

In PowerShell, -RemoveAfter 45 sets the 45-days-after-last-used behavior and is the only valid value for that parameter:

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
New-TenantAllowBlockListItems -ListType Sender -Allow -Entries "payroll@fabrikam.com" -RemoveAfter 45 -Notes "INC-20417 payroll notices, owner: HR"

Prefer an email address over a whole domain. Microsoft notes that if you allow at least seven email addresses in the same domain, submissions roll them up into a domain allow entry automatically, so watch for that when many addresses from one sender are being allowed.

Allow methods to avoid

Microsoft ranks the available allow methods from most to least recommended:

RankMethodMain risk
1Tenant Allow/Block List allow entriesScoped to the entity that caused the block; expire by default
2Mail flow rules that set SCL to bypass spam filteringA rule matching only the sender domain lets spoofed mail skip spam filtering and authentication checks
3Outlook Safe SendersPer mailbox; bypasses parts of the stack and interferes with zero-hour auto purge
4IP Allow List in the connection filter policySkips spam filtering and SPF, DKIM and DMARC for that source
5Allowed sender or domain lists in anti-spam policiesBypasses spam, spoof and phishing protection (except high confidence phishing) and sender authentication

Whatever you use, messages identified as malware or high confidence phishing are still quarantined. If you must use a mail flow rule, add a condition that the Authentication-Results header contains dmarc=pass or dmarc=bestguesspass, or use a tightly scoped IP Allow List entry, and never use your own accepted domains or popular domains as the condition.

Impersonation detections are a separate case. Submitting a message blocked by user or domain impersonation protection doesn't create a Tenant Allow/Block List entry. Handle those in the anti-phishing policy's trusted senders list, as described in Defender for Office 365 anti-phishing impersonation settings.

Verify and review entries

After creating an entry:

Get-TenantAllowBlockListItems -ListType Sender -Allow | Format-List
Get-TenantAllowBlockListItems -ListType Url -Allow | Format-List
Get-TenantAllowBlockListSpoofItems -Action Allow

In the portal, the Domains & addresses tab shows Override verdicts, Last used date and Remove on for each entry, and the details flyout has View submission for entries created by a submission. Filter by Last used date to find entries that haven't been needed recently, and by Never expire to find permanent exceptions.

To shorten or change an entry, use Edit in the portal or Set-TenantAllowBlockListItems; to delete it, use Remove-TenantAllowBlockListItems:

Remove-TenantAllowBlockListItems -ListType Sender -Entries "payroll@fabrikam.com"

Troubleshooting

The submission didn't create an allow entry. Either the filters didn't find the sender malicious, or the block came from impersonation protection, which updates the anti-phishing policy instead. Check the anti-phishing policy's Trusted senders and domains list.

I can't add an allow entry for a domain on the Domains & addresses tab for this message. The verdict was malware or high confidence phishing. Direct allow entries only override up to regular phishing; use the Submissions page.

Allowed mail is still quarantined as high confidence phishing. A block entry for a URL or domain in the message overrides the allow, because block entries take precedence. Review your block entries.

A Safe Senders entry for a domain doesn't stop quarantine. When the policy action is Quarantine, Outlook Safe Senders domain entries aren't honored; address entries are, unless the message is malware, high confidence phishing or matches a Tenant Allow/Block List block entry.

Users can't email a partner after you blocked them. Block entries for domains and addresses also stop outbound mail, with the NDR 550 5.7.703 Your message can't be delivered because messages to XXX, YYY are blocked by your organization using Tenant Allow Block List. Remove or narrow the block entry.

Adding an address with special characters fails. Encode the special characters with UTF-8 hexadecimal URL encoding, for example %22 for a double quotation mark and %20 for a space.

A released message never arrives or is quarantined again. Non-Microsoft filtering services, outbound connectors and inbox rules are common causes. Use message trace to confirm delivery.

Checklist

  • Verdict and responsible filter identified before any allow is created.
  • False positives submitted with I've confirmed it's clean and Allow this message, URL or file.
  • Default 45-days-after-last-used expiry kept unless there is a reason for a shorter window.
  • Every allow entry has a note with the ticket and owner.
  • Direct allow entries used only for bulk, spam and regular phishing, and scoped to addresses rather than domains where possible.
  • No sender-domain-only SCL bypass rules or broad anti-spam allowed domain lists.
  • Impersonation false positives handled in the anti-phishing policy.
  • Monthly review of allow entries by last used date and of any never-expiring entries.

References

Questions people ask

How do I stop Microsoft 365 from blocking a legitimate sender?

Submit a blocked message on the Submissions page in the Microsoft Defender portal with I've confirmed it's clean, then select Allow this message. Microsoft creates allow entries only for the parts of the message that caused the block, such as the sender, a URL or a file, and by default removes them 45 days after the filters last needed them.

Why can't I add an allow entry directly in the Tenant Allow/Block List?

Allow entries created directly on the Domains & addresses or URLs tabs only override bulk, spam, high confidence spam and phishing verdicts. For malware and high confidence phishing you must submit the message to Microsoft from the Submissions page, and allow entries for files can only be created through submissions.

How long do Tenant Allow/Block List allow entries last?

The default is 45 days after last used date, meaning the entry stays until 45 days after the filters stop treating the item as bad. You can instead choose 1, 7 or 30 days or a specific date up to 30 days away. Allow entries for spoofed senders never expire.

Should I use a mail flow rule to bypass spam filtering for a partner?

Only if you can't use the Tenant Allow/Block List, which Microsoft lists as the most recommended allow method. If you do use a rule, never match on the sender domain alone; also require dmarc=pass in the Authentication-Results header or a tightly scoped source IP address.

Defender for Office 365Exchange Online ProtectionTenant Allow/Block ListSubmissions
  1. Defender for Office 365 anti-phishing: stop CEO fraud and lookalike domains

    Configure impersonation, mailbox intelligence and spoof protection in Defender for Office 365 anti-phishing policies to stop executive and lookalike-domain phishing.

  2. A Microsoft 365 tenant security baseline you can apply in a day

    Harden a new or existing Microsoft 365 tenant in one working day: emergency access, admin roles, MFA and legacy auth, app consent, email protection, external forwarding, audit logging and Secure Score.

  3. Find and remove malicious inbox and forwarding rules after a BEC

    After a compromised mailbox, find hidden inbox rules, SMTP forwarding and delegate access in Exchange Online, remove them safely and block external auto-forwarding so the attacker can't come back.