Outlook Spam Filter Explained: Junk Settings for Recipients, Header Clues for Senders

Outlook Spam Filter Explained: Junk Settings for Recipients, Header Clues for Senders

Author
Vladyslav Podoliako
Published
Sep 28, 2026
Reading duration
17 min

The Outlook spam filter is really two filters: Microsoft's server-side filtering (Exchange Online Protection for Microsoft 365, SmartScreen for Outlook.com), which decides most outcomes before mail reaches you, and the Junk Email settings in your Outlook app, which apply your personal safe and blocked lists. Recipients control the second one. Senders can read the first one's verdict in every message header, in a field called X-Forefront-Antispam-Report.

This guide has two parts. Part 1 is for people managing their own inbox. Part 2 is for senders asking why their emails are going to junk in Outlook, with a full header decoder. For IP-level monitoring, use Microsoft's current SNDS portal and sender guidance.

Where filtering actually happens

LayerWho controls itWhat it does
Connection filteringMicrosoft (plus M365 admin IP allow/block lists)Rejects or accepts by sending IP reputation. Microsoft says most spam is rejected here.
Content and spam filtering (EOP / SmartScreen)Microsoft (plus M365 admin anti-spam policy)Assigns a verdict: bulk, spam, high confidence spam, phishing, high confidence phishing
Tenant policy actionMicrosoft 365 adminJunk folder, quarantine, or other action per verdict
User safe and blocked listsThe mailbox ownerOverrides some verdicts for that one mailbox
Classic Outlook client filterThe mailbox ownerOptional extra filtering on the desktop (Low, High, Safe Lists Only)

The practical takeaway: changing your Outlook settings shifts what you see, but it cannot fix a sender's reputation, and a sender cannot change your settings.

Part 1: For recipients, Outlook junk email filter settings

Classic Outlook for Windows

Go to Home > Block (in the Delete group) > Junk E-mail Options. Microsoft's four protection levels:

LevelWhat it doesUse when
No Automatic Filtering (default)Client filter off, but your Blocked Senders list still appliesYour server-side filter is doing its job (most Microsoft 365 users)
LowCatches only the most obvious junkLight spam, low tolerance for false positives
HighCatches more, with more false positivesHeavy spam; check the Junk folder often
Safe Lists OnlyEverything not from Safe Senders or to Safe Recipients is junkLocked-down mailboxes only; you will miss legitimate new contacts

You can also tick Permanently delete suspected junk email instead of moving it to the Junk E-mail folder. Microsoft warns this removes your ability to catch false positives. Do not use it on a sales or support inbox.

The lists in classic Outlook:

  • Safe Senders: addresses and domains never treated as junk. Limit of 1,024 entries. Contacts can be trusted automatically.
  • Safe Recipients: mailing lists you belong to.
  • Blocked Senders: always junked.
  • Blocked Top-Level Domains and Blocked Encodings: block by country code or character set.

On Exchange and Microsoft 365 accounts, these lists are saved on the server and used by the server to filter, so they follow you across devices.

New Outlook, Outlook on the web and Outlook.com

Go to Settings > Mail > Junk email. You can:

  • Add a blocked sender or domain. Mail goes straight to Junk.
  • Add a safe sender or domain. Mail skips Junk.
  • Add a safe mailing list (Outlook.com).

There is no protection-level slider here. Filtering strength is set on Microsoft's side, and in business accounts by your admin.

To rescue a message, open Junk, select it and choose Not junk (Outlook.com: "It's not junk"). Microsoft says marking mail as not junk "helps us improve our service," so it is worth doing rather than just dragging the message out.

Why safe senders still go to junk (Microsoft 365)

Microsoft's own precedence rules explain it:

Filter verdictYour Safe Senders entryYour Blocked Senders entry
MalwareFilter wins: quarantinedFilter wins: quarantined
High confidence phishingFilter wins: quarantinedFilter wins: quarantined
PhishingYou win: InboxOrganization's policy decides
High confidence spamYou win: InboxOrganization's policy decides
SpamYou win: InboxOrganization's policy decides
BulkYou win: InboxYou win: Junk
Not spamYou win: InboxYou win: Junk

Three more catches:

  1. A domain entry may not be enough in Exchange Online. Add the full sender address when testing a safe-sender exception rather than relying on the domain alone.
  2. Admin blocks beat your safe list. A Tenant Allow/Block List block entry wins over your Safe Senders.
  3. Spoofed or failing mail can still be caught. If the sender's authentication fails, the verdict may be phishing or spoof, and your entry may not help.

If a message from a known contact keeps landing in junk or quarantine, forward the case to your IT admin. Admins can submit the message to Microsoft as a false positive from the Submissions page in the Defender portal (security.microsoft.com/reportsubmission) and create allow entries from that submission.

Junk vs quarantine, and how long mail stays

  • Junk is in your mailbox. Outlook.com deletes junk automatically after 10 to 30 days; Outlook on the web keeps it 30 days, then it is gone for good.
  • Quarantine is outside your mailbox (Microsoft 365 only). Default retention is 15 days, or 30 days under the Standard and Strict presets. High confidence phishing can only be released by an admin.

Part 2: For senders, why Microsoft junks your email

Microsoft's Postmaster site says consumer filtering weighs "the sending IP, domain, authentication, list accuracy, complaint rates, content and more," and calls the junk complaint rate "one of the principal factors" in reputation. In Microsoft 365, add each tenant's policy on top.

The most common reasons, roughly in the order we check them:

  1. Authentication fails or does not align. DMARC needs SPF or DKIM to pass for the From domain. Sending platforms often sign with their own domain.
  2. High-volume rule. At 5,000 or more messages a day to Outlook.com consumer addresses, SPF and DKIM must both pass and DMARC must pass, or mail is rejected with 550 5.7.515.
  3. Complaints. Outlook.com users clicking Report junk.
  4. Reputation. New domains and IPs start with none; shared IPs inherit neighbors' behavior.
  5. Bulk signals. Templated, high-volume sends earn a high BCL and hit the tenant's bulk threshold.
  6. Content and links. Link and tracking domains with poor reputation, URL shorteners, IP-address URLs (Microsoft advises against them), heavy images.
  7. Recipient or tenant rules. A blocked sender entry, a transport rule, or a Strict preset.

The header tells you which one. Think of the header as the referee's match report: the score (SCL) is in there, but the report also says which rule was broken (CAT) and who made the call (SFV).

How to get the header

  • New Outlook / Outlook on the web: open the message, More actions, View > View message details.
  • Classic Outlook: open the message in its own window, File > Properties, copy the Internet headers box.
  • Easier reading: paste into Microsoft's Message Header Analyzer.

Send test messages to a Microsoft 365 mailbox and an Outlook.com mailbox you control so you can see both systems.

An example header, annotated

Illustrative values (documentation IP and example domain):

Authentication-Results: spf=pass (sender IP is 203.0.113.25)
 smtp.mailfrom=bounce.vendor-mail.com; dkim=pass (signature was verified)
 header.d=vendor-mail.com; dmarc=fail action=none
 header.from=example.com;compauth=fail reason=001
X-Forefront-Antispam-Report: CIP:203.0.113.25;CTRY:US;LANG:en;SCL:5;
 SRV:;IPV:NLI;SFV:SPM;H:mta25.vendor-mail.com;PTR:mta25.vendor-mail.com;
 CAT:SPM;SFS:(...);DIR:INB;
X-Microsoft-Antispam: BCL:4;ARA:...

How to read it:

  • spf=pass and dkim=pass, but both for vendor-mail.com, while the From domain is example.com. So dmarc=fail: passing authentication for another domain is not alignment with the visible From domain.
  • compauth=fail reason=001: implicit authentication failure (weak or no enforcing policy).
  • SFV:SPM and CAT:SPM: the spam filter marked it spam. SCL:5 agrees but is not the deciding field.
  • IPV:NLI: the IP is not on any IP reputation list, so this is not a block list problem.
  • BCL:4: seen as bulk with mixed complaints, below the default threshold of 7.
  • DIR:INB: inbound message.

Fix: set a custom Return-Path on your domain and sign DKIM with d=example.com, then retest.

X-Forefront-Antispam-Report fields

From Microsoft Learn. Fields not listed are internal to Microsoft's anti-spam team.

FieldMeaningSender interpretation
CIPConnecting IP addressConfirm it is your sending IP
CTRYSource country of the connecting IPUnexpected country can signal a routing or relay issue
LANGDetected languageTenants can junk by language
HHELO/EHLO string of the sending serverShould be a valid hostname, matching PTR ideally
PTRReverse DNS of the source IPMissing PTR hurts; Outlook.com requires valid rDNS
IPV:CALSkipped filtering, IP on tenant IP Allow ListTenant allowed you; not reputation
IPV:NLIIP not found on any IP reputation listGood; not a block list issue
SCLSpam confidence level, -1 to 9Informational in cloud tenants (see below)
SFVSpam filter verdict (table below)The key field
CATCategory of policy applied (table below)What caught you
SRV:BULKIdentified as bulk by BCL thresholdYou are being treated as bulk mail
SFTYPhishing safety tip: 9.19 domain impersonation, 9.20 user impersonation, 9.25 first contactImpersonation logic fired
DIRINB inbound, OUT outbound, INT internalContext
ARCARC chain results (AAR, AMS, AS, cv=)Relevant when forwarded or relayed
X-CustomSpamMatched an Advanced Spam Filter (ASF) settingA tenant-specific ASF rule caught you, not global reputation

SFV values

ValueMeaning
SFV:NSPMNot spam; delivered to intended recipients
SFV:SPMMarked as spam by spam filtering
SFV:BLKBlocked because the sender is on the user's Blocked Senders list
SFV:SFEAllowed because the sender is on the user's Safe Senders list
SFV:SKASkipped filtering; sender on the allowed senders or domains list in an anti-spam policy
SFV:SKBMarked as spam; sender on the blocked senders or domains list in an anti-spam policy
SFV:SKISkipped filtering; source IP on the connection filter IP Allow List
SFV:SKNBypassed spam filtering via a mail flow rule
SFV:SKQReleased from quarantine
SFV:SKSMarked as spam before filtering by a mail flow rule or on-premises decision (only stamped when honored)

If you see SFV:BLK or SFV:SKB, the recipient or their admin blocked you specifically. No reputation work will change that for that mailbox.

CAT values

ValueCategory
BULKBulk
SPMSpam
HSPMHigh confidence spam
PHSHPhishing
HPHSH / HPHISHHigh confidence phishing
SPOOFSpoofing
DIMP / UIMP / GIMP / BIMPDomain, user, mailbox intelligence, brand impersonation (Defender for Office 365)
MALW / AMP / FTBPMalware / anti-malware / common attachments filter
INTOSIntra-organization phishing
OSPMOutbound spam
SAPSafe Attachments (Defender for Office 365)

Microsoft evaluates categories in a fixed order: malware, high confidence phishing, phishing, DMARC reject spoof, DMARC quarantine spoof, spoofing, impersonation, high confidence spam, spam, then bulk. The first match wins, so a spoof verdict hides any gentler bulk verdict.

SCL: why it matters less than it used to

SCL runs from -1 to 9. Microsoft's Message Headers documentation, last updated July 27, 2026, describes SCL as mainly useful for on-premises or hybrid delivery; in cloud organizations it does not determine whether a message is spam or what action is taken. The same SCL can therefore appear with different verdicts.

SCLHow to read it today
-1Filtering bypassed (for example a mail flow rule or allow list)
0 to 4Below the level Microsoft calls generally bad
5 to 9Generally considered bad; 5 or 6 is what admins set to mark spam, 9 for high confidence spam

Use SCL as a hint. Use CAT and SFV as the answer. SCL still drives Junk folder thresholds in on-premises Exchange and hybrid setups.

BCL: the bulk complaint level

Stamped in X-Microsoft-Antispam:

BCLMeaning
0Not from a bulk sender
1 to 3Bulk sender, few complaints
4 to 7Bulk sender, mixed complaints
8 to 9Bulk sender, high complaints

Default thresholds: 7 for the default anti-spam policy, 6 for the Standard preset, 5 for Strict. At or above the threshold, default and Standard policies send the message to Junk; Strict quarantines it. For a one-to-one sales email, any BCL above 0 tells you Microsoft sees your send pattern as bulk.

Authentication-Results and compauth reason codes

ResultMeaning
spf=pass / fail / softfail / neutral / none / temperror / permerrorSPF for the smtp.mailfrom (Return-Path) domain
dkim=pass / fail (reason) / noneDKIM for header.d
dmarc=pass / fail / bestguesspass / noneDMARC for header.from. bestguesspass: no DMARC record, but it would pass
action=oreject / pct.quarantine / pct.rejectWhat the DMARC policy asked for
compauth=pass / fail / softpass / noneMicrosoft's composite authentication verdict

Key compauth reason codes:

CodeMeaningFix
000Failed DMARC with p=quarantine or p=rejectAlign SPF or DKIM with From
001Implicit failure: no records, or weak policy (~all, ?all, p=none) with no alignmentPublish and align SPF, DKIM, DMARC
002Tenant explicitly blocks this sender/domain pair from spoofingRecipient admin setting
010DMARC fail from a domain the recipient org ownsIntra-org spoof
100 to 102Passed: aligned SPF or DKIMNone
108DKIM broken by a legitimate hop modifying the bodyCheck relays and footers
130ARC from a trusted sealer overrode DMARC failureNone
2xxSoft pass on implicit authenticationImprove alignment
601Failed: sender claims the recipient's own accepted domainSpoof
701 to 704DMARC not enforced due to history of legitimate mail from that infrastructureNone, but do not rely on it

Troubleshooting decision table

What you seeLikely causeFix
Bounce 550 5.7.515High-volume authentication rulePass SPF and DKIM; DMARC aligned with From
dmarc=fail with spf=pass and dkim=passAlignment: vendor domains in Return-Path and DKIMCustom Return-Path and DKIM d= on your domain
compauth=fail reason=001Weak or missing recordsPublish SPF, DKIM, DMARC; confirm the result with the live DMARC checker
CAT:SPM, SFV:SPM, authentication passesContent, link domains, or reputationRemove risky link and tracking domains; reduce links and images; warm up
CAT:BULK, SRV:BULK, BCL at or above 7Bulk pattern with complaintsSegment, personalize, cut unengaged recipients
CAT:HSPM or quarantinedHigh confidence spam; often reputation or known bad URLsStop, fix reputation, then resume slowly
CAT:SPOOF or CAT:PHSHAuthentication failure looks like spoofingFix alignment first
SFV:BLK or SFV:SKBRecipient or admin blocked youOnly the recipient can reverse it
Junk at Outlook.com onlyComplaints and IP reputation at Outlook.comCheck SNDS; suppress complainers via JMRP
Rejected with S3150, SC-00x or 5.7.606 to 649Block listCheck Microsoft's current sender-support path and the sending domain's reputation
Mail from a Microsoft 365 mailbox junkedMailbox sending pattern or SMTP setupReview Outlook SMTP settings and sending limits

Fixes that move the needle at Microsoft

  1. Align authentication. SPF and DKIM passing is not enough; one must match your From domain for DMARC. Publish DMARC with at least p=none and a rua address, then read the reports.
  2. Watch complaints at Outlook.com. If you own IPs, enroll in JMRP and suppress every complainer. If not, suppress anyone who has not engaged in months.
  3. Warm up new domains and mailboxes at Microsoft specifically. Microsoft says new IPs typically ramp "within a couple of weeks or sooner depending on volume, list accuracy" and low complaints. Gmail-only warmup does not build Microsoft reputation.
  4. Look less like bulk. Vary copy, personalize beyond the first name, keep volume per mailbox modest, and avoid identical blasts to one company's tenant.
  5. Clean links. Use your own branded tracking domain, avoid shorteners and raw IP URLs, and check every linked domain's reputation.
  6. Respect SMTP etiquette. No retries after 5xx errors, valid rDNS, no namespace mining.
  7. Test before and after every change. Check placement at Outlook.com and Microsoft 365, not just Gmail, and keep the message, provider mix and header evidence for comparison.

When NOT to chase the filter

  • The recipient has Safe Lists Only on. Nothing you do will land you in their inbox except being added.
  • A third-party gateway sits in front. If the headers show Proofpoint, Mimecast or another gateway's verdict before Microsoft's, you are debugging the wrong filter.
  • Your list is wrong. High complaints from a poor-fit audience will outlast every technical fix.

How Folderly helps

For sender-side checks outside Microsoft's headers, use the live domain reputation checker and DMARC checker.

FAQ

How do I change the spam filter settings in Outlook?

In classic Outlook for Windows, go to Home, Block (in the Delete group), Junk E-mail Options, and choose No Automatic Filtering, Low, High or Safe Lists Only. In new Outlook, Outlook on the web and Outlook.com, go to Settings, Mail, Junk email to manage blocked and safe senders. There is no protection-level slider there, because filtering happens on Microsoft's servers.

Why are my emails going to junk in Outlook?

The most common causes are failed or misaligned authentication (SPF, DKIM, DMARC), a high junk complaint rate at Outlook.com, a new or poorly reputed sending IP or domain, bulk-style content that earns a high BCL, and recipient rules such as blocked senders. Open a junked message's headers and read X-Forefront-Antispam-Report: the CAT and SFV values show which filter acted and why.

Why do emails from safe senders still go to junk in Outlook?

In Microsoft 365, a Safe Senders entry does not override malware or high confidence phishing verdicts, and a domain entry may not be sufficient by itself in Exchange Online, so test with the full sender address. Tenant admin block entries also beat a user's safe list. For Outlook.com, a Safe Senders entry does not override high-volume sender authentication enforcement.

What does SCL mean in Outlook headers?

SCL is the spam confidence level, a value from -1 to 9 in the X-Forefront-Antispam-Report header. Values of 5 or higher generally mean the message was considered bad, and -1 means filtering was bypassed. Microsoft updated its documentation in 2026 to say SCL no longer decides the verdict or action in cloud tenants, so read the CAT and SFV fields to learn what happened.

What is a good BCL score?

BCL 0 means Microsoft did not identify the message as bulk. BCL 1 to 3 means a bulk sender with few complaints, 4 to 7 a mixed number, and 8 to 9 a high number. Default Microsoft 365 policies junk bulk mail at BCL 7 or higher, the Standard preset at 6, and the Strict preset at 5. For one-to-one sales email, aim for 0.

How do I find the X-Forefront-Antispam-Report header?

In new Outlook or Outlook on the web, open the message, select More actions, then View, then View message details. In classic Outlook for Windows, open the message in its own window and select File, Properties; the headers are in the Internet headers box. Paste them into Microsoft's Message Header Analyzer at mha.azurewebsites.net for a readable breakdown.

Does Outlook have a spam filter I can turn off?

You can set classic Outlook's client filter to No Automatic Filtering, and Outlook on the web lets users stop moving email to Junk, but server-side filtering still runs. Microsoft says spam filtering in Microsoft 365 cannot be turned off completely. Admins can only bypass most of it with mail flow rules, and high confidence phishing and malware are always filtered.

How long does Outlook keep junk email?

Microsoft says Outlook.com automatically deletes messages in the Junk folder between 10 and 30 days after they arrive. For Outlook on the web, Microsoft states junk email is kept 30 days and then deleted permanently. Quarantined mail in Microsoft 365 is kept 15 days under the default policy and 30 days under the Standard and Strict presets.

Last reviewed: September 28, 2026.

Sources

Vladyslav Podoliako
Author:
Vladyslav Podoliako
Founder & CEO
Vlad is a Founder & CEO of Belkins and Folderly, a series entrepreneur and investor with over ten years of management expertise in companies with 100 million evaluation. Vlad has years of experience building and growing service companies and SaaS startups in SalesTech and MarTech. He is skilled in creating successful businesses from the ground up and building top-notch teams that drive all ventures to the top of their industries.