Microsoft Exchange Online Marks Gmail Emails as Spam – Fixes Implemented

Microsoft Exchange Online Marks Gmail Emails as Spam – Fixes Implemented

Microsoft Rectifies Gmail Mislabeling Glitch in Exchange Online

Microsoft has resolved a recent issue within its Exchange Online email filtering system that mistakenly flagged legitimate Gmail messages as spam, causing widespread delivery disruptions for Microsoft 365 users.

The glitch, first observed on April 25, impacted organizations across multiple sectors and was internally tracked as incident EX1064599. At the heart of the issue was an overzealous AI filter — a machine learning model in Exchange Online Protection (EOP) — that misjudged routine Gmail communications as phishing threats. These misclassifications assigned them an aggressive spam score (SCL 8), leading to their automatic quarantine.

According to Microsoft, the model mistakenly flagged messages due to similarities in structure or content to known spam patterns. In an official note, the company stated: “Our ML-based threat detection system is designed to proactively identify suspicious messages, but in this case, legitimate emails were caught in the net due to behavioral overlaps with known spam tactics.”

Complicating matters for IT teams was the inconsistent nature of the filtering. Identical messages sent to different users within the same company were delivered inconsistently—some reached inboxes while others were blocked, fueling confusion and complicating diagnostics.

To stop the disruption, Microsoft engineers rolled back the flawed ML model to a previous stable version. This rollback was confirmed effective in a May 1 update: “Following comprehensive telemetry monitoring, we’ve verified that reverting to the earlier ML model has resolved the issue.”

During the week-long disruption, administrators were advised to temporarily sidestep the problem by applying customized mail flow rules or using the Tenant Allow/Block List to ensure Gmail messages could bypass the faulty filter.

Microsoft’s handling of the incident highlights both the power and pitfalls of machine learning in security-sensitive applications—reminding organizations that even intelligent systems can make misjudgments with tangible operational consequences.

Microsoft Tackles Gmail Filtering Issues Amidst Broader Spam Detection Challenges

To resolve the ongoing issue with Gmail messages being incorrectly flagged as spam, Microsoft is recommending a custom configuration that sets the Spam Confidence Level (SCL) to -1 for all emails originating from Gmail addresses. This rule instructs Exchange Online to bypass the spam filtering mechanism entirely, allowing these messages to flow to users’ inboxes without interference.

This latest incident is part of a recurring trend of false positives within Microsoft’s email security infrastructure. Only last week, the company addressed a similar issue where Adobe emails were wrongly flagged as spam due to machine learning errors. Earlier in March, another false positive case involved legitimate emails being quarantined due to improper filtering.

Microsoft has acknowledged these challenges and is actively refining its machine learning models to minimize such misclassifications. In a statement, the company reassured users, saying, “We are focused on enhancing our detection systems to prevent false positives and mitigate any disruption moving forward.”

For organizations still encountering issues with Gmail-related filtering, Microsoft advises users to consult the Microsoft 365 Admin Center for the most current status and updates regarding service incidents.

As the landscape of cloud-based email solutions grows more sophisticated, it’s clear that continuous cooperation between technology providers, IT administrators, and end-users is crucial for maintaining both security and performance in the ever-evolving world of digital communication.

More Articles & Posts