Microsoft 365 & email
Why Microsoft 365 emails go to junk.
A Microsoft 365 mailbox can send a perfectly normal-looking message and still have it treated cautiously. The useful question is not “How do we force inbox placement?” but “Which trust signal changed?”
Updated September 2026 · Cyber Bounds Inc.
First, establish where the problem occurs
Is one recipient receiving messages in junk, or is the pattern broad? Is the message a person-to-person email, a quote from a shared mailbox, an invoice from an application, or mail sent through a marketing platform? Does it happen only at Microsoft recipients, only at Gmail recipients, or everywhere?
These details separate a recipient-side filtering decision from a sender configuration or reputation problem. A single person’s junk-folder issue does not automatically mean the organization’s domain is broken.
Check authentication before changing content
Your Microsoft 365 tenant, domain DNS, and any outside application need to agree about who may send. Check SPF, DKIM, and DMARC, then examine the headers of a message that arrived in junk. Look for the authentication-results line and compare the domains shown there with the visible From address.
Do not assume all mail uses Microsoft 365 simply because the employee’s mailbox does. Website forms, CRM platforms, scanners, invoicing tools, and help desks may send from your address through completely different infrastructure.
Look for changes in sending behaviour
Filters also respond to patterns: sudden volume increases, unfamiliar recipient lists, high bounces, vague or misleading subject lines, and recipient complaints. A compromised mailbox can create a rapid change in behaviour too, so unexpected forwarding rules or login activity deserve attention.
What not to do
- Do not keep altering DNS records without a map of legitimate senders.
- Do not ask customers to whitelist you as the primary solution.
- Do not remove DMARC just because a third-party platform is failing.
- Do not test only with messages sent to your own colleagues.
A practical diagnostic sequence
- Collect a few examples, including recipient provider and email type.
- Inspect headers for SPF, DKIM, and DMARC results.
- List every sender using the domain.
- Confirm DKIM is enabled in Microsoft 365 and relevant third-party systems.
- Review recent account, forwarding, platform, or sending-volume changes.
When it needs a deeper review
Talk to an expert when customer or revenue email is affected, more than one sending platform is involved, or you cannot tell which system sent a problematic message. Cyber Bounds can help with Microsoft 365 support and deliverability diagnosis without treating them as separate problems when they are connected.