Microsoft Defender for Office 365
Email and collaboration

Anti Phishing Protection Tuning

In brief

The article now documents `SFV:SKN` as an example for messages where a mail flow rule skips spam filtering, and adds a related-content link. The page date was also updated.

What Defender admins need to know

Administrators troubleshooting filtering results can use the SFV header value to identify messages affected by mail flow rules and find related guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

You can examine the headers of the phishing message to see whether any of your organization's settings allowed similar phishing messages to be delivered. In other words, examining the message headers can help you identify settings in your organization that allowed this phishing message or similar phishing messages to be delivered.

Specifically, check the Spam Filtering Verdict (SFV) value in the X-Forefront-Antispam-Report header field. The SFV value indicates whether spam or phishing filtering was skipped. MessagesFor example, messages that used a mail flow rule (transport rule) to skip spam filtering have an entry ofthe value SCL:-1SFV:SKN, which means one of your settings overrode the phishing verdict and allowed delivery of the message.. For more information on how to get message headers and the complete list of all available anti-spam and anti-phishing message headers, see Anti-spam message headers.

Related content

Anti-phishing protection in cloud organizations \ No newline at end of file