Submissions Result Definitions
In brief
The “Completed | Spam” definition now says similar items are more likely to be identified by spam filtering and handled according to anti-spam policies, replacing the previous SCL-threshold blocking wording.
What Defender admins need to know
Use the revised description when interpreting spam submission results and expected filtering behavior.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- tier1
description: Admins and end-users can learn about the results of submitting entities to Microsoft for analysis.
ms.service: defender-office-365
ms.date:
06/13/202507/24/2026 appliesto: - ✅ Built-in security features for all cloud mailboxes
- ✅ Microsoft Defender for Office 365 Plan 1 and Plan 2
|Completed|Further analysis needed|In U.S. Government organizations (Microsoft 365 GCC, GCC High, and DoD) receive this result when nothing is found within the allowed checks for Email authentication checks and Policy hits. We recommend opening a support ticket to get the submitted item analyzed.|
|Completed|Unknown - We checked but can't make a decision right now|Microsoft could not reach a decision regarding the submitted item. Explanations include different interpretations by different analysts or the item being inaccessible. Microsoft continuously invests in the analysis process so this result is less common.|
|Completed|Bulk|The submitted item sender was classified as a bulk sender. In the future, similar items are blocked if they meet or exceed the bulk compliant level (BCL) threshold in anti-spam policies. For more information, see Bulk complaint level (BCL). To prevent similar items from being delivered, you can create block entries for domains or email addresses, files, or URLs in the Tenant Allow/Block List. For more information, see Block entries in the Tenant Allow/Block List.|
|Completed|Spam|The submitted item was classified as spam. In the future, similar items are
blocked if they meet or exceed themore likely to be identified as spamconfidence level (SCL) threshold inby spam filtering and handled according to your anti-spam policies. For more information, see Spam confidence level (SCL). To prevent similar items from being delivered, you can create block entries for domains or email addresses, files, or URLs in the Tenant Allow/Block List. For more information, see Block entries in the Tenant Allow/Block List.| |Completed|No threats found|The submitted item was found to be clean. After a period of evaluation, the filters might be updated using the information from the submission. Until the filters learn about the submission, you can create block entries or allow entries for the item in the Tenant Allow/Block List.| |Completed|Threats found|The submitted item was found to be malicious. After a period of evaluation, the filters might be updated using the information from the submission. Until the filters learn about the submission, you can create block entries or allow entries for the item in the Tenant Allow/Block List.|
@@ -10,7 +10,7 @@ ms.collection: - tier1 description: Admins and end-users can learn about the results of submitting entities to Microsoft for analysis. ms.service: defender-office-365-ms.date: 06/13/2025+ms.date: 07/24/2026 appliesto: - ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Built-in security features for all cloud mailboxes</a> - ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>@@ -76,6 +76,6 @@ The following table describes the results of submissions to Microsoft: |Completed|Further analysis needed|In U.S. Government organizations (Microsoft 365 GCC, GCC High, and DoD) receive this result when nothing is found within the allowed checks for **Email authentication checks** and **Policy hits**. We recommend opening a support ticket to get the submitted item analyzed.| |Completed|Unknown - We checked but can't make a decision right now|Microsoft could not reach a decision regarding the submitted item. Explanations include different interpretations by different analysts or the item being inaccessible. Microsoft continuously invests in the analysis process so this result is less common.| |Completed|Bulk|The submitted item sender was classified as a bulk sender. In the future, similar items are blocked if they meet or exceed the bulk compliant level (BCL) threshold in anti-spam policies. For more information, see [Bulk complaint level (BCL)](anti-spam-bulk-complaint-level-bcl-about.md). To prevent similar items from being delivered, you can create block entries for domains or email addresses, files, or URLs in the Tenant Allow/Block List. For more information, see [Block entries in the Tenant Allow/Block List](tenant-allow-block-list-about.md#block-entries-in-the-tenant-allowblock-list).|-|Completed|Spam|The submitted item was classified as spam. In the future, similar items are blocked if they meet or exceed the spam confidence level (SCL) threshold in anti-spam policies. For more information, see [Spam confidence level (SCL)](anti-spam-spam-confidence-level-scl-about.md). To prevent similar items from being delivered, you can create block entries for domains or email addresses, files, or URLs in the Tenant Allow/Block List. For more information, see [Block entries in the Tenant Allow/Block List](tenant-allow-block-list-about.md#block-entries-in-the-tenant-allowblock-list).|+|Completed|Spam|The submitted item was classified as spam. In the future, similar items are more likely to be identified as spam by spam filtering and handled according to your anti-spam policies. For more information, see [Spam confidence level (SCL)](anti-spam-spam-confidence-level-scl-about.md). To prevent similar items from being delivered, you can create block entries for domains or email addresses, files, or URLs in the Tenant Allow/Block List. For more information, see [Block entries in the Tenant Allow/Block List](tenant-allow-block-list-about.md#block-entries-in-the-tenant-allowblock-list).| |Completed|No threats found|The submitted item was found to be clean. After a period of evaluation, the filters might be updated using the information from the submission. Until the filters learn about the submission, you can create block entries or allow entries for the item in the Tenant Allow/Block List.| |Completed|Threats found|The submitted item was found to be malicious. After a period of evaluation, the filters might be updated using the information from the submission. Until the filters learn about the submission, you can create block entries or allow entries for the item in the Tenant Allow/Block List.| 