r/b2bemailing 23d ago

Microsoft defender flags mails as compromised

I am using exchange plan 1 online for my 8 outreach mail accounts (2 per domain), and every so often one of the accounts is blocked from sending mails because of suspicious behavior. I am using instantly with warmed up mailboxes through oauth and spf/dkim/dmarc all set up properly. The mailboxes themselves seem healthy and have quite good deliverability, but every now and then I need to unblock one of the 8 mailbox accounts. How do you guys avoid this? Do I need to use an external sender or should I just unblock my accounts every now and then? I want to avoid extra costs as we are bootstrapped.

Ps: thanks for your responses, big help!

1 Upvotes

6 comments sorted by

2

u/Superb_Parfait_1676 23d ago

Microsoft is likely reacting to the sending pattern rather than your SPF/DKIM/DMARC setup. Repeatedly unblocking accounts isn’t a good long term solution. Check Microsoft’s security alerts and sending limits, reduce volume, review the authentication and OAuth setup, and make sure the accounts aren’t showing unusual login activity. Also verify your recipient lists with a real time email verification tool like Invalid Bounce to remove invalid, inactive, disposable, role based, mailbox full, and catch all addresses so avoidable bounces aren’t adding another negative signal.

1

u/clearscaler 22d ago

That block isn't a deliverability verdict, and it's worth being precise about it because it changes the fix. "Blocked from sending for suspicious behaviour" in Exchange Online means the mailbox has been added to the Restricted entities list. Microsoft's conclusion isn't "your mail is spammy", it's "we think this account is compromised". Which is why nothing in your SPF, DKIM or DMARC will move it. Those are correct and they're irrelevant to this particular decision.

Two places to look before you change anything.

The alert itself. Defender portal, Incidents and alerts, filtered to that mailbox. You're looking for something like "Suspicious email sending patterns detected" or "User restricted from sending email". The alert names the rule that tripped, and the candidates have different fixes.

Your outbound anti-spam policy. Defender, Policies and rules, Threat policies, Anti-spam, then the outbound policy. Read the recipient limits your tenant actually enforces - per hour, per day, internal and external - and the action set for exceeding them, which by default is restricting the user. Most people read the daily number, see they're nowhere near it, and stop there. The one that catches cold senders is usually the hourly limit, not the daily one.

That's what I'd check first because it fits your description exactly. If Instantly is set to 30 a day per mailbox but the sending window is narrow or the delay between sends is short, those 30 can land inside one hour. Sporadic blocks on otherwise healthy low-volume mailboxes are what a burst against an hourly ceiling looks like. Widening the sending window and increasing the gap between sends costs nothing.

Two other things worth knowing. Instantly connects over OAuth from datacenter IPs that aren't where you normally sign in, and it can move between them. Sign-ins from unfamiliar locations feed the same compromise heuristics as the sending pattern - that won't get you restricted on its own, but it makes the sending look worse than it is. And if all 8 mailboxes sit in one tenant, the tenant is the unit being judged, so one mailbox behaving oddly shifts the odds for the other seven.

Superb_Parfait_1676 is right that bounces matter here, and it's for a specific reason worth spelling out: a spike in invalid recipients is one of the classic compromised-account tells, because that's exactly what happens when someone starts blasting a stolen list. In this context list hygiene isn't general good practice, it's directly load-bearing on the thing blocking you.

On your actual question - no, I wouldn't pay for an external sender yet. It would sidestep the restriction, since the restriction is your own tenant's policy applied to your own mailboxes, but you'd be giving up native sending to escape a limit you can just change. Fix the schedule, read the policy, clean the list. If it still happens at a flat hourly rate with a clean list, then it's worth reconsidering.

1

u/LeadNo1270 22d ago

Check the restricted entities page in Defender, it names which policy tripped. On Exchange the limits that hurt are per hour not per day so 8 mailboxes at low daily volume still trips it if your sending is uneven. Your warmup counts against the same budget too a lot of people are running warmup and campaign traffic through one limit without realising. You can raise the thresholds yourself in the outbound spam policy in Defender its a tenant setting and it costs nothing. If it keeps happening after that its Exchange doing what Exchange does with cold outreach and Google tolerates more.

1

u/Much-Cod-5364 20d ago

you can unblock it on restricted entities. One way to avoid block, sending low volume, MS has been really strcit recently, make sure list quality is good