The Outlook spam filter is really two filters: Microsoft's server-side filtering (Exchange Online Protection for Microsoft 365, SmartScreen for Outlook.com), which decides most outcomes before mail reaches you, and the Junk Email settings in your Outlook app, which apply your personal safe and blocked lists. Recipients control the second one. Senders can read the first one's verdict in every message header, in a field called X-Forefront-Antispam-Report.
This guide has two parts. Part 1 is for people managing their own inbox. Part 2 is for senders asking why their emails are going to junk in Outlook, with a full header decoder. For IP-level monitoring, use Microsoft's current SNDS portal and sender guidance.
Where filtering actually happens
| Layer | Who controls it | What it does |
|---|---|---|
| Connection filtering | Microsoft (plus M365 admin IP allow/block lists) | Rejects or accepts by sending IP reputation. Microsoft says most spam is rejected here. |
| Content and spam filtering (EOP / SmartScreen) | Microsoft (plus M365 admin anti-spam policy) | Assigns a verdict: bulk, spam, high confidence spam, phishing, high confidence phishing |
| Tenant policy action | Microsoft 365 admin | Junk folder, quarantine, or other action per verdict |
| User safe and blocked lists | The mailbox owner | Overrides some verdicts for that one mailbox |
| Classic Outlook client filter | The mailbox owner | Optional extra filtering on the desktop (Low, High, Safe Lists Only) |
The practical takeaway: changing your Outlook settings shifts what you see, but it cannot fix a sender's reputation, and a sender cannot change your settings.
Part 1: For recipients, Outlook junk email filter settings
Classic Outlook for Windows
Go to Home > Block (in the Delete group) > Junk E-mail Options. Microsoft's four protection levels:
| Level | What it does | Use when |
|---|---|---|
| No Automatic Filtering (default) | Client filter off, but your Blocked Senders list still applies | Your server-side filter is doing its job (most Microsoft 365 users) |
| Low | Catches only the most obvious junk | Light spam, low tolerance for false positives |
| High | Catches more, with more false positives | Heavy spam; check the Junk folder often |
| Safe Lists Only | Everything not from Safe Senders or to Safe Recipients is junk | Locked-down mailboxes only; you will miss legitimate new contacts |
You can also tick Permanently delete suspected junk email instead of moving it to the Junk E-mail folder. Microsoft warns this removes your ability to catch false positives. Do not use it on a sales or support inbox.
The lists in classic Outlook:
- Safe Senders: addresses and domains never treated as junk. Limit of 1,024 entries. Contacts can be trusted automatically.
- Safe Recipients: mailing lists you belong to.
- Blocked Senders: always junked.
- Blocked Top-Level Domains and Blocked Encodings: block by country code or character set.
On Exchange and Microsoft 365 accounts, these lists are saved on the server and used by the server to filter, so they follow you across devices.
New Outlook, Outlook on the web and Outlook.com
Go to Settings > Mail > Junk email. You can:
- Add a blocked sender or domain. Mail goes straight to Junk.
- Add a safe sender or domain. Mail skips Junk.
- Add a safe mailing list (Outlook.com).
There is no protection-level slider here. Filtering strength is set on Microsoft's side, and in business accounts by your admin.
To rescue a message, open Junk, select it and choose Not junk (Outlook.com: "It's not junk"). Microsoft says marking mail as not junk "helps us improve our service," so it is worth doing rather than just dragging the message out.
Why safe senders still go to junk (Microsoft 365)
Microsoft's own precedence rules explain it:
| Filter verdict | Your Safe Senders entry | Your Blocked Senders entry |
|---|---|---|
| Malware | Filter wins: quarantined | Filter wins: quarantined |
| High confidence phishing | Filter wins: quarantined | Filter wins: quarantined |
| Phishing | You win: Inbox | Organization's policy decides |
| High confidence spam | You win: Inbox | Organization's policy decides |
| Spam | You win: Inbox | Organization's policy decides |
| Bulk | You win: Inbox | You win: Junk |
| Not spam | You win: Inbox | You win: Junk |
Three more catches:
- A domain entry may not be enough in Exchange Online. Add the full sender address when testing a safe-sender exception rather than relying on the domain alone.
- Admin blocks beat your safe list. A Tenant Allow/Block List block entry wins over your Safe Senders.
- Spoofed or failing mail can still be caught. If the sender's authentication fails, the verdict may be phishing or spoof, and your entry may not help.
If a message from a known contact keeps landing in junk or quarantine, forward the case to your IT admin. Admins can submit the message to Microsoft as a false positive from the Submissions page in the Defender portal (security.microsoft.com/reportsubmission) and create allow entries from that submission.
Junk vs quarantine, and how long mail stays
- Junk is in your mailbox. Outlook.com deletes junk automatically after 10 to 30 days; Outlook on the web keeps it 30 days, then it is gone for good.
- Quarantine is outside your mailbox (Microsoft 365 only). Default retention is 15 days, or 30 days under the Standard and Strict presets. High confidence phishing can only be released by an admin.
Part 2: For senders, why Microsoft junks your email
Microsoft's Postmaster site says consumer filtering weighs "the sending IP, domain, authentication, list accuracy, complaint rates, content and more," and calls the junk complaint rate "one of the principal factors" in reputation. In Microsoft 365, add each tenant's policy on top.
The most common reasons, roughly in the order we check them:
- Authentication fails or does not align. DMARC needs SPF or DKIM to pass for the From domain. Sending platforms often sign with their own domain.
- High-volume rule. At 5,000 or more messages a day to Outlook.com consumer addresses, SPF and DKIM must both pass and DMARC must pass, or mail is rejected with
550 5.7.515. - Complaints. Outlook.com users clicking Report junk.
- Reputation. New domains and IPs start with none; shared IPs inherit neighbors' behavior.
- Bulk signals. Templated, high-volume sends earn a high BCL and hit the tenant's bulk threshold.
- Content and links. Link and tracking domains with poor reputation, URL shorteners, IP-address URLs (Microsoft advises against them), heavy images.
- Recipient or tenant rules. A blocked sender entry, a transport rule, or a Strict preset.
The header tells you which one. Think of the header as the referee's match report: the score (SCL) is in there, but the report also says which rule was broken (CAT) and who made the call (SFV).
How to get the header
- New Outlook / Outlook on the web: open the message, More actions, View > View message details.
- Classic Outlook: open the message in its own window, File > Properties, copy the Internet headers box.
- Easier reading: paste into Microsoft's Message Header Analyzer.
Send test messages to a Microsoft 365 mailbox and an Outlook.com mailbox you control so you can see both systems.
An example header, annotated
Illustrative values (documentation IP and example domain):
Authentication-Results: spf=pass (sender IP is 203.0.113.25)
smtp.mailfrom=bounce.vendor-mail.com; dkim=pass (signature was verified)
header.d=vendor-mail.com; dmarc=fail action=none
header.from=example.com;compauth=fail reason=001
X-Forefront-Antispam-Report: CIP:203.0.113.25;CTRY:US;LANG:en;SCL:5;
SRV:;IPV:NLI;SFV:SPM;H:mta25.vendor-mail.com;PTR:mta25.vendor-mail.com;
CAT:SPM;SFS:(...);DIR:INB;
X-Microsoft-Antispam: BCL:4;ARA:...
How to read it:
spf=passanddkim=pass, but both forvendor-mail.com, while the From domain isexample.com. Sodmarc=fail: passing authentication for another domain is not alignment with the visible From domain.compauth=fail reason=001: implicit authentication failure (weak or no enforcing policy).SFV:SPMandCAT:SPM: the spam filter marked it spam.SCL:5agrees but is not the deciding field.IPV:NLI: the IP is not on any IP reputation list, so this is not a block list problem.BCL:4: seen as bulk with mixed complaints, below the default threshold of 7.DIR:INB: inbound message.
Fix: set a custom Return-Path on your domain and sign DKIM with d=example.com, then retest.
X-Forefront-Antispam-Report fields
From Microsoft Learn. Fields not listed are internal to Microsoft's anti-spam team.
| Field | Meaning | Sender interpretation |
|---|---|---|
| CIP | Connecting IP address | Confirm it is your sending IP |
| CTRY | Source country of the connecting IP | Unexpected country can signal a routing or relay issue |
| LANG | Detected language | Tenants can junk by language |
| H | HELO/EHLO string of the sending server | Should be a valid hostname, matching PTR ideally |
| PTR | Reverse DNS of the source IP | Missing PTR hurts; Outlook.com requires valid rDNS |
| IPV:CAL | Skipped filtering, IP on tenant IP Allow List | Tenant allowed you; not reputation |
| IPV:NLI | IP not found on any IP reputation list | Good; not a block list issue |
| SCL | Spam confidence level, -1 to 9 | Informational in cloud tenants (see below) |
| SFV | Spam filter verdict (table below) | The key field |
| CAT | Category of policy applied (table below) | What caught you |
| SRV:BULK | Identified as bulk by BCL threshold | You are being treated as bulk mail |
| SFTY | Phishing safety tip: 9.19 domain impersonation, 9.20 user impersonation, 9.25 first contact | Impersonation logic fired |
| DIR | INB inbound, OUT outbound, INT internal | Context |
| ARC | ARC chain results (AAR, AMS, AS, cv=) | Relevant when forwarded or relayed |
| X-CustomSpam | Matched an Advanced Spam Filter (ASF) setting | A tenant-specific ASF rule caught you, not global reputation |
SFV values
| Value | Meaning |
|---|---|
| SFV:NSPM | Not spam; delivered to intended recipients |
| SFV:SPM | Marked as spam by spam filtering |
| SFV:BLK | Blocked because the sender is on the user's Blocked Senders list |
| SFV:SFE | Allowed because the sender is on the user's Safe Senders list |
| SFV:SKA | Skipped filtering; sender on the allowed senders or domains list in an anti-spam policy |
| SFV:SKB | Marked as spam; sender on the blocked senders or domains list in an anti-spam policy |
| SFV:SKI | Skipped filtering; source IP on the connection filter IP Allow List |
| SFV:SKN | Bypassed spam filtering via a mail flow rule |
| SFV:SKQ | Released from quarantine |
| SFV:SKS | Marked as spam before filtering by a mail flow rule or on-premises decision (only stamped when honored) |
If you see SFV:BLK or SFV:SKB, the recipient or their admin blocked you specifically. No reputation work will change that for that mailbox.
CAT values
| Value | Category |
|---|---|
| BULK | Bulk |
| SPM | Spam |
| HSPM | High confidence spam |
| PHSH | Phishing |
| HPHSH / HPHISH | High confidence phishing |
| SPOOF | Spoofing |
| DIMP / UIMP / GIMP / BIMP | Domain, user, mailbox intelligence, brand impersonation (Defender for Office 365) |
| MALW / AMP / FTBP | Malware / anti-malware / common attachments filter |
| INTOS | Intra-organization phishing |
| OSPM | Outbound spam |
| SAP | Safe Attachments (Defender for Office 365) |
Microsoft evaluates categories in a fixed order: malware, high confidence phishing, phishing, DMARC reject spoof, DMARC quarantine spoof, spoofing, impersonation, high confidence spam, spam, then bulk. The first match wins, so a spoof verdict hides any gentler bulk verdict.
SCL: why it matters less than it used to
SCL runs from -1 to 9. Microsoft's Message Headers documentation, last updated July 27, 2026, describes SCL as mainly useful for on-premises or hybrid delivery; in cloud organizations it does not determine whether a message is spam or what action is taken. The same SCL can therefore appear with different verdicts.
| SCL | How to read it today |
|---|---|
| -1 | Filtering bypassed (for example a mail flow rule or allow list) |
| 0 to 4 | Below the level Microsoft calls generally bad |
| 5 to 9 | Generally considered bad; 5 or 6 is what admins set to mark spam, 9 for high confidence spam |
Use SCL as a hint. Use CAT and SFV as the answer. SCL still drives Junk folder thresholds in on-premises Exchange and hybrid setups.
BCL: the bulk complaint level
Stamped in X-Microsoft-Antispam:
| BCL | Meaning |
|---|---|
| 0 | Not from a bulk sender |
| 1 to 3 | Bulk sender, few complaints |
| 4 to 7 | Bulk sender, mixed complaints |
| 8 to 9 | Bulk sender, high complaints |
Default thresholds: 7 for the default anti-spam policy, 6 for the Standard preset, 5 for Strict. At or above the threshold, default and Standard policies send the message to Junk; Strict quarantines it. For a one-to-one sales email, any BCL above 0 tells you Microsoft sees your send pattern as bulk.
Authentication-Results and compauth reason codes
| Result | Meaning |
|---|---|
| spf=pass / fail / softfail / neutral / none / temperror / permerror | SPF for the smtp.mailfrom (Return-Path) domain |
| dkim=pass / fail (reason) / none | DKIM for header.d |
| dmarc=pass / fail / bestguesspass / none | DMARC for header.from. bestguesspass: no DMARC record, but it would pass |
| action=oreject / pct.quarantine / pct.reject | What the DMARC policy asked for |
| compauth=pass / fail / softpass / none | Microsoft's composite authentication verdict |
Key compauth reason codes:
| Code | Meaning | Fix |
|---|---|---|
| 000 | Failed DMARC with p=quarantine or p=reject | Align SPF or DKIM with From |
| 001 | Implicit failure: no records, or weak policy (~all, ?all, p=none) with no alignment | Publish and align SPF, DKIM, DMARC |
| 002 | Tenant explicitly blocks this sender/domain pair from spoofing | Recipient admin setting |
| 010 | DMARC fail from a domain the recipient org owns | Intra-org spoof |
| 100 to 102 | Passed: aligned SPF or DKIM | None |
| 108 | DKIM broken by a legitimate hop modifying the body | Check relays and footers |
| 130 | ARC from a trusted sealer overrode DMARC failure | None |
| 2xx | Soft pass on implicit authentication | Improve alignment |
| 601 | Failed: sender claims the recipient's own accepted domain | Spoof |
| 701 to 704 | DMARC not enforced due to history of legitimate mail from that infrastructure | None, but do not rely on it |
Troubleshooting decision table
| What you see | Likely cause | Fix |
|---|---|---|
Bounce 550 5.7.515 | High-volume authentication rule | Pass SPF and DKIM; DMARC aligned with From |
dmarc=fail with spf=pass and dkim=pass | Alignment: vendor domains in Return-Path and DKIM | Custom Return-Path and DKIM d= on your domain |
compauth=fail reason=001 | Weak or missing records | Publish SPF, DKIM, DMARC; confirm the result with the live DMARC checker |
CAT:SPM, SFV:SPM, authentication passes | Content, link domains, or reputation | Remove risky link and tracking domains; reduce links and images; warm up |
CAT:BULK, SRV:BULK, BCL at or above 7 | Bulk pattern with complaints | Segment, personalize, cut unengaged recipients |
CAT:HSPM or quarantined | High confidence spam; often reputation or known bad URLs | Stop, fix reputation, then resume slowly |
CAT:SPOOF or CAT:PHSH | Authentication failure looks like spoofing | Fix alignment first |
SFV:BLK or SFV:SKB | Recipient or admin blocked you | Only the recipient can reverse it |
| Junk at Outlook.com only | Complaints and IP reputation at Outlook.com | Check SNDS; suppress complainers via JMRP |
Rejected with S3150, SC-00x or 5.7.606 to 649 | Block list | Check Microsoft's current sender-support path and the sending domain's reputation |
| Mail from a Microsoft 365 mailbox junked | Mailbox sending pattern or SMTP setup | Review Outlook SMTP settings and sending limits |
Fixes that move the needle at Microsoft
- Align authentication. SPF and DKIM passing is not enough; one must match your From domain for DMARC. Publish DMARC with at least
p=noneand aruaaddress, then read the reports. - Watch complaints at Outlook.com. If you own IPs, enroll in JMRP and suppress every complainer. If not, suppress anyone who has not engaged in months.
- Warm up new domains and mailboxes at Microsoft specifically. Microsoft says new IPs typically ramp "within a couple of weeks or sooner depending on volume, list accuracy" and low complaints. Gmail-only warmup does not build Microsoft reputation.
- Look less like bulk. Vary copy, personalize beyond the first name, keep volume per mailbox modest, and avoid identical blasts to one company's tenant.
- Clean links. Use your own branded tracking domain, avoid shorteners and raw IP URLs, and check every linked domain's reputation.
- Respect SMTP etiquette. No retries after 5xx errors, valid rDNS, no namespace mining.
- Test before and after every change. Check placement at Outlook.com and Microsoft 365, not just Gmail, and keep the message, provider mix and header evidence for comparison.
When NOT to chase the filter
- The recipient has Safe Lists Only on. Nothing you do will land you in their inbox except being added.
- A third-party gateway sits in front. If the headers show Proofpoint, Mimecast or another gateway's verdict before Microsoft's, you are debugging the wrong filter.
- Your list is wrong. High complaints from a poor-fit audience will outlast every technical fix.
How Folderly helps
For sender-side checks outside Microsoft's headers, use the live domain reputation checker and DMARC checker.
FAQ
How do I change the spam filter settings in Outlook?
In classic Outlook for Windows, go to Home, Block (in the Delete group), Junk E-mail Options, and choose No Automatic Filtering, Low, High or Safe Lists Only. In new Outlook, Outlook on the web and Outlook.com, go to Settings, Mail, Junk email to manage blocked and safe senders. There is no protection-level slider there, because filtering happens on Microsoft's servers.
Why are my emails going to junk in Outlook?
The most common causes are failed or misaligned authentication (SPF, DKIM, DMARC), a high junk complaint rate at Outlook.com, a new or poorly reputed sending IP or domain, bulk-style content that earns a high BCL, and recipient rules such as blocked senders. Open a junked message's headers and read X-Forefront-Antispam-Report: the CAT and SFV values show which filter acted and why.
Why do emails from safe senders still go to junk in Outlook?
In Microsoft 365, a Safe Senders entry does not override malware or high confidence phishing verdicts, and a domain entry may not be sufficient by itself in Exchange Online, so test with the full sender address. Tenant admin block entries also beat a user's safe list. For Outlook.com, a Safe Senders entry does not override high-volume sender authentication enforcement.
What does SCL mean in Outlook headers?
SCL is the spam confidence level, a value from -1 to 9 in the X-Forefront-Antispam-Report header. Values of 5 or higher generally mean the message was considered bad, and -1 means filtering was bypassed. Microsoft updated its documentation in 2026 to say SCL no longer decides the verdict or action in cloud tenants, so read the CAT and SFV fields to learn what happened.
What is a good BCL score?
BCL 0 means Microsoft did not identify the message as bulk. BCL 1 to 3 means a bulk sender with few complaints, 4 to 7 a mixed number, and 8 to 9 a high number. Default Microsoft 365 policies junk bulk mail at BCL 7 or higher, the Standard preset at 6, and the Strict preset at 5. For one-to-one sales email, aim for 0.
How do I find the X-Forefront-Antispam-Report header?
In new Outlook or Outlook on the web, open the message, select More actions, then View, then View message details. In classic Outlook for Windows, open the message in its own window and select File, Properties; the headers are in the Internet headers box. Paste them into Microsoft's Message Header Analyzer at mha.azurewebsites.net for a readable breakdown.
Does Outlook have a spam filter I can turn off?
You can set classic Outlook's client filter to No Automatic Filtering, and Outlook on the web lets users stop moving email to Junk, but server-side filtering still runs. Microsoft says spam filtering in Microsoft 365 cannot be turned off completely. Admins can only bypass most of it with mail flow rules, and high confidence phishing and malware are always filtered.
How long does Outlook keep junk email?
Microsoft says Outlook.com automatically deletes messages in the Junk folder between 10 and 30 days after they arrive. For Outlook on the web, Microsoft states junk email is kept 30 days and then deleted permanently. Quarantined mail in Microsoft 365 is kept 15 days under the default policy and 30 days under the Standard and Strict presets.
Last reviewed: September 28, 2026.
Sources
- Microsoft Learn: Anti-spam message headers in cloud organizations
- Microsoft Learn: Bulk email detection and BCL
- Microsoft Learn: Anti-spam protection in cloud organizations
- Microsoft Learn: Recommended EOP and Defender settings
- Microsoft Learn: Order and precedence of email protection
- Microsoft Learn: Admin submissions in the Defender portal
- Microsoft Support: Change the level of protection in the Junk Email Filter
- Microsoft Support: Overview of the Junk Email Filter in classic Outlook
- Microsoft Support: Filter junk email and spam in Outlook
- Microsoft Support: Safe Senders in Outlook.com
- Microsoft Support: View internet message headers in Outlook
- Microsoft Support: Fix NDR error 550 5.7.515
- Microsoft: Outlook.com sender troubleshooting
- Microsoft Message Header Analyzer
