Why your emails go to spam in Microsoft 365 (Exchange Online Protection / Defender)
Microsoft 365 business mailboxes are filtered by Exchange Online Protection plus Defender, layering tenant/admin anti-spam policies and a spam-confidence-level (SCL) score on top of Microsoft's IP reputation - making it both reputation-strict and subject to per-organization rules Gmail never has.
Causes and fixes
1. EOP IP reputation and the same SmartScreen/SNDS lineage flag your sending IP. M365 shares Microsoft's reputation backbone; a cold or low-rep IP gets a high Spam Confidence Level and lands in Junk or is bulk-foldered before tenant rules even apply.
Fix: Warm IPs into Microsoft slowly, keep PTR/reverse-DNS valid, and use SNDS to monitor the IP. Maintain consistent volume; EOP's reputation read punishes spiky cold-IP behavior with elevated SCL across all M365 tenants.
2. Bulk Complaint Level (BCL) threshold trips on marketing-style cold mail. EOP assigns a BCL score to bulk/marketing mail, and each tenant's anti-spam policy junks anything above a threshold (often BCL 6-7). Templated cold outreach reads as bulk and crosses the line.
Fix: Make mail look 1:1, not bulk - personalize content, avoid mass-mail HTML/footers, send at human cadence, and keep List-Unsubscribe clean. Lowering the 'bulkiness' fingerprint keeps BCL under common tenant thresholds so it isn't auto-junked as bulk.
3. Tenant-level admin policies and connection filtering block you regardless of global reputation. M365 admins set their own allow/block lists, anti-spam aggressiveness, and connection filters; many block unknown external senders or quarantine first-contact mail - something no consumer provider does.
Fix: Where you have a legitimate relationship, ask the recipient/admin to allow-list your domain or add you as a safe sender. Recognize some tenants quarantine all first-contact external mail by policy - target accordingly and prioritize getting a reply that prompts the admin to trust you.
4. Defender Safe Links / Safe Attachments and URL detonation flag your links. M365 with Defender rewrites and detonates URLs and attachments; link shorteners, redirect-based open/click tracking, low-rep link domains, and attachments common in cold tooling get scored as phishing-like.
Fix: Drop URL shorteners and tracking redirects through sketchy domains, avoid attachments on first contact, and link only to your reputable primary domain. Clean, direct URLs survive Safe Links detonation; redirect chains and new tracking domains look like phishing to Defender.
5. DMARC/DKIM/SPF failures hit harder under Defender anti-spoofing. M365's anti-phishing and spoof intelligence aggressively quarantine or reject mail failing alignment, and Defender adds composite-auth (compauth) checks beyond basic SPF/DKIM that cold-email setups often fail.
Fix: Get SPF+DKIM+DMARC aligned and passing composite auth - test against an M365 mailbox and read the Authentication-Results/compauth verdict in headers. Move DMARC toward p=quarantine/reject; Defender treats aligned authenticated senders far more leniently.
6. First-contact safety tip + spoof-intelligence demotion. M365 stamps unfamiliar external senders ('You don't often get email from...') and spoof intelligence flags lookalike/new domains, both of which suppress engagement and feed the spam score for cold senders using freshly-registered domains.
Fix: Send cold outreach from an established domain with sending history rather than a domain registered days ago, and keep From-name/address consistent so spoof intelligence learns you. Building familiarity removes the first-contact penalty over repeated legitimate sends.
7. Cold lists hit M365 invalid/disabled mailboxes and traps, raising bounce-driven reputation damage. Business domains churn employees constantly, so scraped B2B lists are full of deactivated mailboxes; high NDR/bounce volume signals list abuse to EOP.
Fix: Verify addresses before sending and process NDRs promptly to suppress dead mailboxes. Keep bounce rate low - EOP correlates high invalid-recipient rates with spam operations and raises your SCL/blocks the IP accordingly.
Microsoft 365 (Exchange Online Protection / Defender) specifics
- EOP (Exchange Online Protection) + Microsoft Defender for Office 365 filter business M365 mailboxes, scoring SCL (Spam Confidence Level) and BCL (Bulk Complaint Level) per message.
- Per-tenant admin anti-spam/connection/allow-block policies override or tighten Microsoft defaults - placement varies by organization, unlike consumer providers.
- Defender Safe Links / Safe Attachments detonate URLs and files; redirect-based tracking and shorteners read as phishing.
- Composite authentication (compauth) and spoof intelligence go beyond basic SPF/DKIM - check Authentication-Results headers for the compauth verdict.
- M365 shares Microsoft's IP-reputation backbone with Outlook.com, so SNDS monitoring and PTR/reverse-DNS still apply; admin allow-listing is the most reliable inbox path.
Fix Microsoft 365 (Exchange Online Protection / Defender) deliverability for good.
Scheduler Zero handles authentication, warmup, and reputation so your cold email reaches the Microsoft 365 (Exchange Online Protection / Defender) inbox, not the spam folder.