Blog/Cloud Solutions
Cloud SolutionsMicrosoft 365Anti-SpamEmail SecurityHow-To

How to Configure Microsoft 365 Anti-Spam Filtering Properly (Step-by-Step)

SAS IT TeamPublished 17 May 20268 min read

Why Default Settings Are Not Enough

Out of the box, Microsoft 365 catches most obvious spam but leaves gaps. Properly tuned policies significantly reduce phishing, spoofing, and business email compromise attempts.


Layer 1: Email Authentication (Do This First)

Before tuning filters, confirm these DNS records are in place:

RecordPurpose
SPFAuthorises sending servers
DKIMCryptographic email signing
DMARCPolicy enforcement on SPF and DKIM failures

Without DMARC at least p=quarantine, spoofed emails from your own domain can still reach inboxes.


Layer 2: Anti-Spam Policy Tuning

In Microsoft Defender > Email and Collaboration > Policies > Anti-Spam:

  • Bulk email threshold: Lower from default 7 to 5 for stricter filtering
  • Spam action: Move to Junk folder (or quarantine for tighter control)
  • High-confidence spam: Quarantine
  • Phishing: Quarantine
  • High-confidence phishing: Quarantine and notify admin

Layer 3: Anti-Phishing Policy

  • Enable impersonation protection for key executives
  • Add your domain and executive names to monitored senders
  • Enable mailbox intelligence
  • Set spoofed sender action to quarantine

  • Enable Safe Links for all users — rewrites URLs and checks on click
  • Enable Safe Attachments — detonates attachments in sandbox before delivery
  • Both require Microsoft Defender for Office 365 Plan 1 or higher

Quarantine Review Routine

  • Assign a staff member to review quarantine weekly
  • Release false positives and add to safe sender list
  • Report false negatives (spam that got through) to Microsoft

Related: Managed IT Services Dubai | Networking and Security Dubai

Tags

Microsoft 365Anti-SpamEmail SecurityHow-ToCybersecurity

About the Author

Reviewed by Mustafa Husain, Founder of SAS IT Services, with 10+ years of experience in IT infrastructure, networking, and security — alongside the same engineers who design, install, and support the work described on this site. SAS IT Services was founded on 22 February 2020 in Dubai and has since delivered 500+ projects for businesses across the UAE.

We specialize in Fortinet, Cisco, and Microsoft, among 17 vendor product lines we regularly install, configure, and support across networking, cybersecurity, CCTV, and cloud infrastructure — hands-on experience that informs the technical guidance in our articles.

Our work is independently rated 5.0 out of 5 from 17 verified Google Reviews. Every article is reviewed internally for technical accuracy before publishing and reflects practices we apply on real client deployments in Dubai and the UAE.

SAS IT Services — Dubai

Need expert IT support?

Our experienced engineers cover all of Dubai & UAE with same-day response and 24/7 support contracts.