Edit

Tune anti-phishing protection

Although Microsoft 365 includes many anti-phishing features, some phishing messages can still be delivered to mailboxes in your organization. This article describes how to discover why a phishing message was delivered, and how to adjust anti-phishing settings without accidentally making things worse.

First things first: deal with any compromised accounts and make sure you block any more phishing messages from getting through

If a recipient's account was compromised as a result of the phishing message, follow the steps in Responding to a compromised cloud email account.

If you have Microsoft Defender for Office 365 (included or in an add-on subscription), you can use Office 365 Threat Intelligence to identify other users who also received the phishing message. Defender for Office 365 includes more ways to block phishing messages:

Verify that Safe Links, Safe Attachments, and anti-phishing policies are working. Safe Links and Safe Attachments protection is turned on by default via Built-in protection in preset security policies. Anti-phishing has a default policy that applies to all recipients where anti-spoofing protection is turned on by default. Impersonation protection isn't turned on in the default anti-phishing policy, and therefore needs to be configured. For instructions, see Configure anti-phishing policies in Microsoft Defender for Office 365.

Report the phishing message to Microsoft

Reporting phishing messages is helpful in tuning the filters that are used to protect all customers in Microsoft 365. For instructions, see Use the Submissions page to submit suspected spam, phish, URLs, legitimate email getting blocked, and email attachments to Microsoft.

Inspect the message headers

You can examine the headers of the phishing message to see whether any of your organization's settings allowed similar phishing messages to be delivered. In other words, examining the message headers can help you identify settings in your organization that allowed this phishing message or similar phishing messages to be delivered.

Specifically, check the Spam Filtering Verdict (SFV) value in the X-Forefront-Antispam-Report header field. The SFV value indicates whether spam or phishing filtering was skipped. Messages that skip filtering have an entry of SCL:-1, which means one of your settings overrode the phishing verdict and allowed delivery of the message. For more information on how to get message headers and the complete list of all available anti-spam and anti-phishing message headers, see Anti-spam message headers.

Tip

You can copy and paste the contents of a message header into the Message Header Analyzer tool. This tool helps parse headers and presents them in a human readable format.

You can also use the configuration analyzer to compare your threat policies to the Standard and Strict recommendations.

Best practices to stay protected

Use the following best practices to reduce future phishing risk and validate your protection settings.