Microsoft Defender for Office 365
Email and collaboration

Message Headers Eop Mdo

In brief

The documentation now explains that SCL does not determine spam identification or actions in cloud organizations, and clarifies SFV:SKI, SFV:SKN, and SFV:SKS values and their filtering causes. It also updates bulk-mail and formatting details.

What Defender admins need to know

Use the revised header definitions when investigating message filtering, allow-list behavior, mail flow rules, and hybrid mail flow.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.localizationpriority: high ms.assetid: 2e3fcfc5-5604-4b88-ac0a-c5c45c03f1db ms.collection:

  • m365-security
  • tier2 description: Admins can learn about the header fields added to incoming messages by the built-in security features for all cloud mailboxes and by Microsoft Defender for Office 365. These header fields provide information about the message and how it was processed. ms.custom: seo-marvel-apr2020apr2020, msecd-doc-authoring-1015 ms.service: defender-office-365 ms.date: 10/08/202507/27/2026 ai-usage: ai-assisted appliesto:
  • Built-in security features for all cloud mailboxes
  • Microsoft Defender for Office 365 Plan 1 and Plan 2 |IPV:NLI|The IP address wasn't found on any IP reputation list.| |LANG|The language that the message was written in as specified by the country code (for example, ru_RU for Russian).| |PTR:[ReverseDNS]|The PTR record (also known as the reverse DNS lookup) of the source IP address.| |SCL|The spam confidence level (SCL) of the message. A higherIn cloud organizations, this value indicatesdoesn't determine whether the message is more likelyidentified as spam or the action taken on it. It's used primarily in on-premises Exchange environments, including hybrid delivery to be spam.the Junk Email folder. To understand how the message was filtered, use the CAT and DIR values instead. For more information, see Spam confidence level (SCL).| |SFTY|The message was identified as phishing and is also marked with one of the following values:
    • 9.19: Domain impersonation. The sending domain is attempting to impersonate a protected domain. The safety tip for domain impersonation is added to the message (if domain impersonation is enabled).
    • 9.20: User impersonation. The sending user is attempting to impersonate a user in the recipient's organization, or a protected user specified in an anti-phishing policy in Microsoft Defender for Office 365. The safety tip for user impersonation is added to the message (if user impersonation is enabled).
    • 9.25: First contact safety tip. This value might be an indication of a suspicious or phishing message. For more information, see First contact safety tip.
    | |SFV:BLK|Filtering was skipped and the message was blocked because it was sent from an address in a user's Blocked Senders list.



    For more information about how admins can manage a user's Blocked Senders list, see Configure junk email settings on cloud mailboxes.| |SFV:NSPM|Spam filtering marked the message as nonspam and the message was sent to the intended recipients.| |SFV:SFE|Filtering was skipped and the message was allowed because it was sent from an address in a user's Safe Senders list.



    For more information about how admins can manage a user's Safe Senders list, see Configure junk email settings on cloud mailboxes.| |SFV:SKA|The message skipped spam filtering and was delivered to the Inbox because the sender was in the allowed senders list or allowed domains list in an anti-spam policy. For more information, see Configure anti-spam policies.| |SFV:SKB|The message was marked as spam because it matched a sender in the blocked senders list or blocked domains list in an anti-spam policy. For more information, see Configure anti-spam policies.| |SFV:SKI|The message skipped spam filtering because the source IP address was in the IP Allow List in the connection filter policy. For more information, see Configure connection filtering.| |SFV:SKN|The message was marked as nonspam before processing bybypassed spam filtering. For example, the message was marked as SCL -1 or Bypass spam filtering by a mail flow rule. due to an Exchange mail flow rule (transport rule).| |SFV:SKQ|The message was released from the quarantine and was sent to the intended recipients.| |SFV:SKS|The message was marked as spam before processingspam filtering processed it, either by an Exchange mail flow rule (transport rule) that set the SCL, or by a spam filtering. For example,decision passed from on-premises Exchange in a hybrid deployment. These actions are inputs to filtering, not the final decision. Secure by default evaluates the request and might not honor it, so SFV:SKS is stamped only when the request to mark the message was marked as SCL 5 to 9 by a mail flow rule.spam is honored.| |SFV:SPM|The message was marked as spam by spam filtering.| |SRV:BULK|The message was identified as bulk email by spam filtering and the bulk complaint level (BCL) threshold. When the MarkAsSpamBulkMail parameter is On (it's on by default), a bulk email message is markedmessages are identified as spam (SCL 6).spam. For more information, see Configure anti-spam policies.| |X-CustomSpam: [ASFOption]|The message matched an Advanced Spam Filter (ASF) setting. To see the X-header value for each ASF setting, see Advanced Spam Filter (ASF) settings in anti-spam policies.

    Note: ASF adds X-CustomSpam: X-header fields to messages after Exchange mail flow rules (also known as transport rules) process messages. You can't use mail flow rules to identify and act on messages filtered by ASF.|

X-Microsoft-Antispam message header fields