Why are emails being marked as junk or phishing in Outlook 365?

Summary

Emails are marked as junk or phishing in Outlook 365 due to a confluence of factors related to sender reputation, email content, list hygiene, authentication practices, and Microsoft's evolving filtering mechanisms. These factors encompass everything from technical configuration issues like missing or misconfigured SPF, DKIM, and DMARC records, and negative sender reputation metrics (high bounce rates, low engagement, spam complaints), to content characteristics such as the use of spam trigger words, suspicious links, URL shorteners, or poor HTML coding. Microsoft's increasingly sophisticated filtering, including sandboxed link analysis and revised anti-spam policies, is also a key contributor. Finally, basic email marketing best practices, like practicing good list hygiene through regular cleaning and employing double opt-in processes, play a crucial role in maintaining good deliverability and avoiding the junk folder.

Key findings

  • Authentication is Key: Missing or misconfigured SPF, DKIM, and DMARC records are major factors in deliverability problems, allowing spoofing and increasing the likelihood of phishing classification.
  • Sender Reputation Matters: A sender's reputation, influenced by IP history, domain authentication, bounce rates, engagement metrics, and complaint rates, directly impacts inbox placement.
  • Content Triggers Spam Filters: Suspicious links, spam trigger words, excessive capitalization, poor HTML coding, and URL shorteners can trigger spam filters.
  • List Hygiene is Essential: Poor list hygiene (sending to outdated or invalid email addresses) significantly increases the chance of being caught by spam filters.
  • Microsoft's Advanced Filtering: Microsoft's increasingly sophisticated filtering techniques, including sandboxed link analysis, actively scan and classify emails, impacting deliverability.
  • User Engagement Impacts Deliverability: Low engagement (low open rates and click-through rates) signals to spam filters that emails are unwanted, leading to junk placement.
  • Complaint Rates Hurt: High complaint rates (recipients marking emails as spam) directly and negatively impact deliverability.
  • Sending Frequency Counts: Sending too many emails in a short period, or sending emails too infrequently, can lead to deliverability problems.

Key considerations

  • Implement Robust Authentication: Configure SPF, DKIM, and DMARC records to verify email sources and prevent spoofing.
  • Monitor and Manage Sender Reputation: Actively monitor IP and domain reputation, addressing blacklistings promptly and tracking engagement metrics.
  • Optimize Email Content: Avoid spam trigger words, suspicious links, URL shorteners, and poor HTML. Use secure URLs and clear sender identification.
  • Practice Excellent List Hygiene: Regularly clean and validate email lists to remove inactive or invalid addresses.
  • Adapt to Evolving Filtering: Stay informed about the latest email filtering techniques employed by providers like Microsoft and adapt sending practices accordingly.
  • Encourage User Engagement: Create compelling content that encourages opens and clicks, improving engagement rates.
  • Minimize Spam Complaints: Provide clear and easy unsubscribe options and target recipients with relevant content to reduce spam complaints.
  • Use Double Opt-In: Implement double opt-in to confirm subscribers' interest and reduce the likelihood of spam complaints.
  • Maintain a Consistent Sending Schedule: Establish and maintain a consistent email sending schedule to avoid being flagged for erratic sending patterns.

What email marketers say
10Marketer opinions

Emails are often marked as junk or phishing in Outlook 365 due to various factors affecting sender reputation and email content. Issues include poor list hygiene, low engagement, high complaint rates, and inconsistent sending schedules. The content itself can trigger spam filters if it contains suspicious links, requests sensitive information, uses spam trigger words, has excessive capitalization, or exhibits poor HTML coding. Proper authentication (SPF, DKIM, DMARC), avoiding URL shorteners, using double opt-in, and personalizing email content are crucial to improve deliverability and avoid junk/phishing classifications. Furthermore, Microsoft's advanced filtering now includes clicking links and evaluating linked web pages.

Key opinions

  • Content triggers: Suspicious links, requests for sensitive information, spam trigger words, excessive capitalization, and poor HTML can all cause emails to be flagged.
  • Sender Reputation: Factors like low engagement, high complaint rates, poor list hygiene, and inconsistent sending schedules negatively impact sender reputation and lead to junk/phishing classifications.
  • Authentication: Lack of proper email authentication (SPF, DKIM, DMARC) makes it easier for emails to be spoofed and marked as phishing attempts.
  • Microsoft Filtering: Microsoft actively clicks links in emails and evaluates the content of linked web pages, leading to single-use links expiring and potentially flagging suspicious content.

Key considerations

  • List Hygiene: Regularly clean and validate email lists to remove inactive or invalid addresses, reducing bounce rates and improving sender reputation.
  • Email Authentication: Implement SPF, DKIM, and DMARC to verify that emails are sent from authorized servers and protect against spoofing.
  • Content Optimization: Avoid spam trigger words, excessive capitalization, poor HTML, and URL shorteners. Personalize content and use clear, concise language.
  • Engagement Tracking: Monitor open rates, click-through rates, and complaint rates to identify and address deliverability issues.
  • Sending Schedule: Establish a consistent and measured sending schedule to avoid being flagged for erratic sending patterns.
  • Double Opt-In: Implement double opt-in to ensure subscribers genuinely want to receive emails, reducing spam complaints.
Marketer view

Email marketer from Email Geeks shares they've observed a significant rise in O365 customers reporting that their 'Forgot Password' emails are being quarantined and flagged as phishing risks, also observing that Microsoft is now clicking links, causing issues with single-use links expiring before user interaction.

August 2021 - Email Geeks
Marketer view

Email marketer from Litmus shares that tracking email engagement metrics like open rates, click-through rates, and complaint rates helps identify issues affecting deliverability. Low engagement can signal spam filters that your emails are unwanted.

November 2024 - Litmus
Marketer view

Email marketer from Email on Acid explains that using spam trigger words, excessive capitalization, or poor HTML coding can cause emails to be flagged as junk. Ensuring clean, well-formatted content is essential for improving deliverability.

September 2023 - Email on Acid
Marketer view

Email marketer from Gmass shares that personalizing emails and avoiding generic content can help bypass spam filters. Tailoring emails to individual recipients makes them less likely to be marked as junk.

October 2021 - Gmass
Marketer view

Email marketer from StackOverflow explains that regular list cleaning and validation helps to remove invalid or inactive email addresses, thus reducing bounce rates and improving sender reputation, and reducing the risk of being marked as junk.

January 2022 - StackOverflow
Marketer view

Email marketer from HubSpot shares that avoiding URL shorteners in emails can help prevent spam classifications. Spam filters often flag emails with shortened URLs as suspicious, so using full URLs is recommended.

July 2022 - HubSpot
Marketer view

Email marketer from Mailjet explains that improving email deliverability in Outlook requires ensuring proper authentication (SPF, DKIM, DMARC), maintaining a clean sending reputation by avoiding spam traps and high bounce rates, and segmenting email lists to send targeted content that recipients are more likely to engage with.

March 2023 - Mailjet
Marketer view

Email marketer from Sendinblue explains that using double opt-in ensures that subscribers genuinely want to receive emails, reducing the likelihood of spam complaints and improving sender reputation.

December 2021 - Sendinblue
Marketer view

Email marketer from Email Marketing Forum answers that sending too many emails in a short period or sending emails too infrequently can lead to deliverability problems. Consistent, measured sending schedules are preferable to avoid being marked as junk.

May 2022 - Email Marketing Forum
Marketer view

Email marketer from Reddit shares that emails can be flagged as phishing if they contain suspicious links, request sensitive information, or mimic legitimate company communications. To avoid this, always use secure URLs, clearly identify the sender, and avoid generic greetings.

August 2021 - Reddit

What the experts say
7Expert opinions

Emails are marked as junk or phishing in Outlook 365 due to a combination of factors related to content, sender reputation, list hygiene, and Microsoft's evolving filtering techniques. An SCL score of 5+ typically results in junk placement. Microsoft has updated its anti-spam policies, potentially deploying a sandboxed browser for link analysis, scrutinizing linked webpage content more thoroughly. Single-use links are problematic due to active link clicking by filters. Maintaining good list hygiene is essential to avoid spam filters. Sender reputation, influenced by IP history, authentication, bounce/complaint rates, and engagement, plays a crucial role. High complaint rates directly harm deliverability.

Key opinions

  • SCL Score: An SCL score of 5+ is a strong indicator of spam and results in junk placement by Outlook 365's default policies.
  • Microsoft Filtering Updates: Microsoft has implemented new anti-spam policies and technologies, including sandboxed link analysis and webpage content scrutiny, influencing deliverability.
  • Single-Use Link Issues: Automated link clicking by Microsoft filters is causing problems with single-use links, necessitating changes to link expiration and interaction methods.
  • List Hygiene Importance: Poor list hygiene, with outdated or invalid addresses, increases the likelihood of spam filter detection and junk classification.
  • Sender Reputation Impact: Sender reputation, influenced by IP history, authentication, engagement, and complaint rates, is a critical determinant of inbox placement.
  • Complaint Rate Significance: High complaint rates directly and negatively impact deliverability, requiring active monitoring and reduction efforts.

Key considerations

  • Monitor SCL Scores: Pay attention to SCL scores assigned to your emails, adjusting content and practices to avoid high scores.
  • Adapt to MS Filtering: Be aware of Microsoft's updated filtering techniques, particularly regarding link analysis and website content.
  • Re-evaluate Links: Re-evaluate single-use links, using time-based expiration or interactive actions to prevent issues with automated clicking.
  • Clean Email Lists: Regularly clean and validate email lists to remove inactive or invalid addresses and improve deliverability.
  • Build Reputation: Focus on building and maintaining a positive sender reputation by authenticating emails, engaging recipients, and minimizing bounce and complaint rates.
  • Manage Complaints: Actively monitor and address complaint rates to maintain good deliverability, refining targeting and content relevance.
Expert view

Expert from Spamresource.com explains that poor list hygiene, including sending to outdated or invalid email addresses, significantly increases the likelihood of being caught by spam filters and being classified as junk. Regular list cleaning is essential.

December 2021 - Spamresource.com
Expert view

Expert from Email Geeks explains that single-use links in emails are becoming problematic due to filtering, recommending links expire after a reasonable time or direct to a page requiring user interaction, emphasizing the need for interactive actions due to filters running non-interactive JavaScript. Suggesting Microsoft is clamping down harder with new technologies and potentially refining their approach.

August 2023 - Email Geeks
Expert view

Expert from Email Geeks explains that an SCL score of 5+ typically indicates the email is considered spam, leading to placement in the junk folder based on standard O365 policies.

March 2022 - Email Geeks
Expert view

Expert from Word to the Wise (Laura Atkins) explains that sender reputation is crucial for inbox placement. Factors influencing reputation include IP address history, domain authentication, bounce rates, complaint rates, and engagement metrics. Building and maintaining a positive sender reputation is key to avoiding the junk folder.

August 2022 - Word to the Wise
Expert view

Expert from Email Geeks suggests Microsoft may have either fixed an issue causing spam to bypass filters or pushed an internal update with new anti-spam policies.

March 2022 - Email Geeks
Expert view

Expert from Email Geeks shares that Microsoft seems to have deployed a sandboxed browser to open links in emails, allowing for thorough analysis of webpage content, which indicates they’re closely monitoring linked web pages rather than just email content and links.

December 2022 - Email Geeks
Expert view

Expert from Spamresource.com explains that high complaint rates (recipients marking emails as spam) directly and negatively impact email deliverability. Monitoring and reducing complaint rates through improved targeting and relevant content are essential.

March 2023 - Spamresource.com

What the documentation says
5Technical articles

Emails land in the Junk Email folder in Outlook 365 due to reasons like being blocklisted, triggering spam filters with content, or recipients marking them as junk. Maintaining good IP and domain reputation by monitoring blacklists and addressing complaints is crucial. Implementing DMARC prevents spoofing and phishing, ensuring only authorized emails are delivered. SPF records verify emails are sent from authorized servers, also preventing spoofing. Google Postmaster Tools help monitor domain and IP reputation, identifying deliverability issues.

Key findings

  • Blocklisting: Sender's email address or domain being on a blocklist can lead to junk placement.
  • Spam Filter Triggers: Email content triggering spam filters can cause emails to be marked as junk.
  • Recipient Actions: Recipients marking emails as junk directly impacts future deliverability.
  • Reputation Importance: Maintaining a good IP and domain reputation is crucial for avoiding junk/phishing classifications.
  • DMARC Benefits: Implementing DMARC prevents email spoofing and phishing attacks, improving deliverability.
  • SPF Authentication: SPF records verify authorized sending servers, preventing spoofing.
  • Monitoring Tools: Google Postmaster Tools enables monitoring of domain/IP reputation for deliverability issues.

Key considerations

  • Avoid Blacklists: Take steps to ensure your sending IPs and domains are not on blocklists.
  • Optimize Content: Refine email content to avoid triggering spam filters.
  • Encourage Engagement: Work to improve recipient engagement and reduce spam complaints.
  • Reputation Management: Proactively monitor and manage your IP and domain reputation.
  • Implement DMARC: Configure DMARC policies to authenticate emails and prevent spoofing.
  • Setup SPF Records: Ensure correct SPF record configuration to authorize sending servers.
  • Utilize Postmaster Tools: Leverage Google Postmaster Tools to monitor reputation and troubleshoot deliverability.
Technical article

Documentation from DMARC.org explains that implementing DMARC (Domain-based Message Authentication, Reporting & Conformance) helps prevent email spoofing and phishing attacks. Properly configured DMARC policies ensure that only authorized emails are delivered, protecting sender reputation and improving deliverability.

June 2024 - DMARC.org
Technical article

Documentation from Microsoft Support explains that emails might land in the Junk Email folder due to various reasons, including the sender's email address or domain being on a blocklist, the email content triggering spam filters, or the recipient having previously marked similar emails as junk.

February 2022 - Microsoft Support
Technical article

Documentation from Google Postmaster Tools explains that using Google Postmaster Tools allows senders to monitor their domain and IP reputation, identify deliverability issues, and troubleshoot problems affecting email delivery to Gmail users.

September 2024 - Google
Technical article

Documentation from RFC explains that implementing SPF (Sender Policy Framework) records helps verify that emails are sent from authorized servers, preventing spoofing and phishing attacks. It is crucial to have a correctly configured SPF record to tell receiving servers which IP addresses are allowed to send email on behalf of your domain.

January 2023 - RFC
Technical article

Documentation from Spamhaus explains that maintaining a good IP and domain reputation is crucial for avoiding junk or phishing classifications. Regularly monitor blacklists, promptly address complaints, and adhere to best practices for email sending to prevent reputation damage.

November 2023 - Spamhaus