Overview
Messages from internal or trusted senders can land in Junk because of mailbox junk settings, blocked-sender entries, message authentication problems, spam scoring, mail-flow rules, or a compromised sender. Do not whitelist broadly until you know why the message was classified.
Why this happens
Microsoft 365 evaluates sender reputation, authentication, content, user-level junk settings, tenant security policy, and other signals. Internal-looking messages can also be spoofed or sent from a compromised account.
Before you begin
- Preserve one example message.
- Record sender, recipient, subject, and time.
- Do not add whole domains to safe-sender lists as a first step.
- If the message appears suspicious, treat it as a security issue.
Click-by-click troubleshooting
Step 1: Confirm where Microsoft 365 placed the message
Action: Open Outlook on the web > Junk Email and locate the message.
Why this matters: This confirms the server mailbox classification rather than a local Outlook view issue.
What to look for: Confirm the message is actually in Junk Email and not moved by a rule.
Expected result: You should establish that junk filtering, rather than a mailbox rule, placed the message there.
Step 2: Review blocked and safe sender entries
Action: Open Outlook on the web > Settings > Mail > Junk email.
Why this matters: A user-level blocked sender or domain can override normal expectations.
What to look for: Look for the sender or domain under Blocked senders and domains and review existing safe-sender entries.
Expected result: No accidental block should explain the message placement.
Step 3: Review inbox rules
Action: Open Settings > Mail > Rules and inspect active rules that affect the sender or subject.
Why this matters: Rules can move messages in ways that users may mistake for junk filtering.
What to look for: Look for unexpected move, delete, or redirect actions.
Expected result: The message placement should be attributable to either a rule or filtering, not both.
Step 4: Check whether the sender is truly internal and expected
Action: Review the displayed sender address and, if available, message details or headers. Confirm the actual domain and sending address.
Why this matters: Display-name spoofing can make an external message look internal.
What to look for: Look for misspelled domains, unexpected external addresses, or unusual Reply-To information.
Expected result: The message should be confirmed as legitimately originating from the expected sender before any filtering exception is considered.
Step 5: Compare another message from the same sender
Action: Locate a previous legitimate message from the same sender or have the sender send a controlled test message.
Why this matters: This shows whether the issue affects all messages from the sender or only one message's content or authentication.
What to look for: Compare whether both messages are classified the same way.
Expected result: You should know whether the problem is sender-wide or message-specific.
Step 6: Escalate tenant filtering questions with evidence
Action: If multiple users receive the same trusted sender in Junk, preserve the example message and provide it to IT for Exchange Online security review.
Why this matters: Tenant anti-spam policy, authentication, or sender reputation may require administrative investigation.
What to look for: Look for the same pattern across recipients, especially after a sender-system change.
Expected result: IT should have enough evidence to evaluate filtering without creating an overly broad bypass.
What to look for
- Blocked sender entry: user-level configuration.
- Only one suspicious message: content or spoofing concern.
- Many recipients affected: tenant filtering or sender authentication issue.
- Unexpected forwarding or rules: possible account compromise.
When to stop
When to contact IT
Contact J3 Systems Group if trusted messages are repeatedly junked for multiple users, the sender appears spoofed, authentication may be failing, or an administrative filtering change may be required. Include article code KB-05.009 and a preserved example message.
Need help with this issue?
J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.
Contact J3 Systems GroupAuthoritative references
Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.