If your messages are missing Outlook and Microsoft 365 inboxes, the priority order is authenticate properly, read the message headers to see what Microsoft actually recorded, cut sending volume to recent engagers only, and submit through the correct Microsoft form if you are blocked. Check the BCL, CAT, SFV and Authentication-Results values first, because they tell you whether you are dealing with a content problem, a reputation problem or a DNS fault. Some fixes land within hours; reputation repair can take longer, sometimes several weeks.
TL;DR:
- Ensuring SPF, DKIM, and DMARC records are correctly aligned and within DNS limits is essential, as failures here can result in prolonged delivery issues.
- Analyzing headers for CAT, SFV, BCL, and Authentication-Results values quickly reveals whether mail is quarantined, flagged as spam, or blocked, guiding targeted remediation.
- Submitting sample messages through the appropriate Microsoft forms for quarantined or blocked emails can lead to faster resolution, especially when reputation issues are involved.
- Improving sender reputation involves prioritizing engaged recipients, gradually increasing volume, and automating complaint suppression using SNDS and JMRP signals.
- Addressing Outlook deliverability problems requires a staged approach focusing first on technical fixes, then content adjustments, and finally reputation recovery over several weeks or months.
Digistrat
Diagnose Your Outlook Deliverability
Digistrat assesses sender reputation, infrastructure, and list quality to identify email issues affecting engagement and revenue.
Table of Contents
- Quick actionable checklist to run now
- Authentication: SPF, DKIM and DMARC and alignment for Microsoft
- Header diagnostics: reading X-Forefront-Antispam-Report and Authentication-Results
- Anti-spam policies, tenant allow/block and admin remediation
- Reputation, IP history and the tools that reveal what is really happening
- Content, engagement and sending patterns that avoid Outlook filters
- Step-by-step recovery plan for a sender failing into Outlook
- How a specialist approaches an Outlook deliverability problem
- Getting a proper diagnosis without the guesswork
- Authoritative Microsoft and specialist resources to consult next
- Sources
- FAQ
Quick actionable checklist to run now
Before touching your email platform’s settings, gather evidence. Most Outlook deliverability problems reveal themselves in the headers and trace logs long before you need to change anything.
- Run a message trace for the affected recipients and pull the full headers from at least three sample messages.
- Confirm SPF, DKIM and DMARC are passing, and check that your sending domain has valid MX and A records.
- Look for CAT, SFV and BCL values in the headers to establish whether mail is being quarantined, junked or delivered normally.
- Pause or throttle sends to Microsoft recipients showing low engagement, and prioritise anyone who has opened or clicked recently.
- If mail is quarantined or blocked, identify whether the affected accounts are consumer (Outlook.com) or business (Microsoft 365), then submit samples through the matching Microsoft form.
This sequence usually surfaces the root cause within a working day, even if the fix itself takes longer to bed in.
Authentication: SPF, DKIM and DMARC and alignment for Microsoft
Microsoft leans heavily on composite authentication, known internally as compauth, which combines SPF, DKIM and DMARC results into a single verdict instead of judging each in isolation. A message can pass SPF and still fail compauth if the DKIM domain does not align with the visible From address, so alignment matters as much as the individual checks. Before assuming a content or reputation issue, work through the DNS basics:
- Check that your SPF record has not exceeded the ten DNS lookup limit, which causes a permanent SPF failure regardless of how correct the record looks.
- Confirm the DKIM selector referenced in your outbound mail matches a published public key in DNS, since a mismatched or expired selector fails silently.
- Verify your DMARC record specifies a policy and includes RUA and, where useful, RUF reporting addresses so you can see alignment failures as they happen.
- Check that the sending domain has a valid MX or A record, because Microsoft documents that mail from domains without one is always routed through the high-risk delivery pool, regardless of content quality.
These are DNS checks an admin can usually complete and correct within an afternoon. For a fuller walkthrough of how the three records interact and where they typically go wrong, see this explanation of SPF, DKIM and DMARC.
Header diagnostics: reading X-Forefront-Antispam-Report and Authentication-Results
Outlook and Microsoft 365 attach diagnostic headers to every message they process, and these headers are the clearest record of why a message was classified the way it was. You can view them in Outlook by opening the message, selecting the options menu and choosing to view the source or internet headers, then feeding the raw text into a header analyser such as Microsoft’s own Message Header Analyzer tool.
- SFV (Spam Filtering Verdict) shows whether a message was marked as spam, skipped filtering, or blocked outright, with SFV:BLK indicating a block.
- CAT identifies which filter category triggered the verdict, so CAT:SPM means spam and CAT:HSPM means high-confidence spam.
- BCL (Bulk Complaint Level) and SCL (Spam Confidence Level) are numeric scores that drive the delivery decision, with higher numbers pushing mail towards Junk or quarantine.
- Authentication-Results records the individual SPF, DKIM and DMARC outcomes alongside the compauth verdict Microsoft actually used.
Microsoft records these values directly in the message headers to explain both the spam verdict and the authentication outcome, which is why parsing anti-spam headers is the fastest route to a diagnosis. A CAT:HSPM reading almost always means you are looking at quarantine remediation and a formal submission to Microsoft, whereas a milder CAT:SPM with a moderate BCL might respond to a simple anti-spam policy adjustment.
Anti-spam policies, tenant allow/block and admin remediation
Microsoft 365 administrators have several levers to correct false positives without switching off protection entirely, and it helps to know which one applies to which symptom.
- Open the anti-spam policies in the Defender portal and check whether bulk mail action is set to Move to Junk Folder or Quarantine, since the two produce very different symptoms for the recipient.
- Review the Tenant Allow/Block List, because entries here override the default verdict and can conflict with a user’s own Safe Senders list in unexpected ways.
- Use message trace alongside the Submissions page to report false positives directly to Microsoft, since submitting misclassified mail for analysis is the recognised route to a lasting fix rather than a workaround.
- While waiting on Microsoft’s verdict, create a temporary allow entry to reduce business impact, but treat it as a stopgap rather than a permanent setting.
Adjusting BCL thresholds or enabling the Promotions folder option can soften the impact of a high bulk complaint score, though both change what recipients see rather than fixing the underlying reputation problem.
Reputation, IP history and the tools that reveal what is really happening
Microsoft weighs sending IP history heavily, and a new or unfamiliar IP is treated with more suspicion than one with an established sending pattern. Mail from a poor-reputation or newly active source can also be routed through the relay pools Microsoft uses for forwarded or low-trust traffic, separate from the high-risk pool reserved for authentication failures.
- Smart Network Data Services (SNDS) shows complaint rate spikes, spam-trap hits and a red, yellow or green health flag for any IP you register, and it is usually the first place a specialist looks.
- The Junk Mail Reporting Program (JMRP) feeds you individual complaint events; the practical approach is to treat every JMRP report as an unsubscribe and remove that address automatically, rather than reviewing each one by hand.
- The Smart Reputation Data (SRD) system behaves like a voting mechanism, where enough recipients marking mail as junk can drag placement down within days even when SPF, DKIM and DMARC all pass cleanly.
Pro Tip: Automate JMRP suppression the same day reports arrive; a backlog of unprocessed complaints does more reputation damage than the original complaints themselves.
For a longer look at how these signals fit into an ongoing monitoring routine, this guide to deliverability monitoring covers the operational side in more depth.

Content, engagement and sending patterns that avoid Outlook filters
Filtering decisions are not made on authentication alone. Microsoft’s systems also weigh how recipients behave once mail lands, and that behavioural signal can override an otherwise clean technical setup.
- Send to your most engaged segment first: recent openers and clickers carry more weight than a broad blast to an entire list.
- Pause the bottom third of a cold list rather than continuing to mail addresses that never interact, since repeated non-engagement quietly damages the sending domain’s standing.
- Keep a visible, working unsubscribe link, balance text against images, and avoid subject lines that promise something the body does not deliver.
- When warming a new IP or domain, increase volume gradually rather than jumping straight to full send volume, and avoid sudden spikes specifically to Microsoft-hosted recipients.
- Run regular bounce handling, avoid purchased or rented lists entirely, and run a re-permission campaign for any segment that has gone quiet for months.
Step-by-step recovery plan for a sender failing into Outlook
Recovery works best as a staged process rather than a single fix, because authentication, content and reputation each move at a different speed.
- Immediately: confirm whether the problem is consumer (Outlook.com) or business (Microsoft 365) recipients, pull and read message headers, and pause the riskiest sends while throttling volume to recent engagers.
- Within 48 to 72 hours: correct any DNS or authentication faults found in the headers, submit sample messages through the matching Microsoft consumer or business form, and add a temporary allow entry if Microsoft is still reviewing.
- Over the following weeks: run a structured IP or domain warm-up, monitor SNDS and JMRP daily, automate complaint suppression, and adjust content and segmentation based on what the data shows.
- Escalate to a paid deliverability consultancy or a sustained monitoring arrangement if placement has not recovered after several weeks of correct technical setup, since that pattern usually points to a reputation issue that needs closer diagnosis than routine self-service allows.
A team following this order typically resolves straightforward DNS and policy issues within days, while genuine reputation recovery after a blacklisting event or a complaint spike can take considerably longer. For more detail on translating these steps into a working plan, see this guide to fixing email deliverability issues.
How a specialist approaches an Outlook deliverability problem
Digistrat works with UK and European businesses sending opted-in email, and the pattern that shows up most often is a technical fault, usually authentication or IP reputation, sitting alongside a commercial one, usually the revenue lost while mail sits in junk. The useful part of an outside review is less about spotting a header value and more about sequencing the fix correctly: authentication first, then submission, then the slower reputation work, so that nothing is wasted chasing a symptom before the cause is addressed.
Most Outlook deliverability failures are not mysterious once you read the headers properly; the difficulty is usually persuading a business to fix the boring DNS record before it starts blaming the email platform.
Getting a proper diagnosis without the guesswork
Working through headers, SNDS flags and anti-spam policy settings on your own is possible, but it takes time your team may not have while mail keeps missing the inbox. A free health check can give you a diagnostic pass over your authentication, header history and sending pattern, with a list of quick wins you can action in a short time.

| Service | What it covers |
|---|---|
| Free health check | Initial diagnostic, header review, quick wins list |
| Deliverability Review and Fix | Full technical review and remediation of the root causes |
| Advisory session (£250 one-off) | Focused session to work through a specific blocking issue |
| Reputation monitoring | Ongoing tracking of sender reputation and complaint signals |
Work is carried out directly by a specialist rather than handed to a generalist support team, with fixes implemented rather than just reported. You can see the full range of deliverability services or go straight to booking a free check-up if Outlook placement is already costing you revenue.
Authoritative Microsoft and specialist resources to consult next

Microsoft’s own documentation on anti-spam message headers and false positive remediation are the primary references for diagnosis and submission. For list hygiene practice that supports the engagement rules above, SmartFlowCRM’s email marketing features and this guide to CRM data hygiene are worth a look.
FAQ
Why do my emails go to Outlook junk even with SPF and DKIM passing?
SPF and DKIM passing individually does not guarantee a good outcome, because Microsoft’s compauth check also requires domain alignment between them and the visible From address. Reputation signals such as complaint rate and IP history, tracked through SNDS, can also push mail to Junk even when authentication is technically correct.
What does CAT:HSPM mean in a Microsoft message header?
CAT:HSPM means the message was categorised as high-confidence spam by Microsoft’s filtering system, which is a stronger classification than the standard CAT:SPM spam label. Messages carrying this value usually need a formal submission to Microsoft through the anti-spam header review process rather than a simple policy tweak.
How do I unblock my domain from Outlook.com or Microsoft 365?
The correct route depends on whether the affected recipients are Outlook.com consumer accounts or Microsoft 365 business accounts, since Microsoft runs separate submission forms for each. You should also confirm your authentication and DNS records are correct before submitting, since Microsoft will typically decline an unblock request while a technical fault remains unresolved.
What is the difference between BCL and SCL in Microsoft headers?
The Bulk Complaint Level measures how often recipients complain about bulk mail from a similar source, while the Spam Confidence Level is Microsoft’s overall numeric verdict on how likely a message is to be spam. Both values sit in the anti-spam headers and a high reading in either can push mail towards Junk or quarantine.
Should I turn off the Outlook client’s Junk Email Filter?
Microsoft recommends setting the Outlook client’s Junk Email Filter to No automatic filtering in cloud organisations, since the client filter can conflict with the server-side verdict already applied by Microsoft 365’s own spam filtering. Leaving both filters active can produce inconsistent results for end users trying to find legitimate mail.

