eofolarin.com
Emmanuel Folarin

IT Infrastructure Developer/ Manage

Web/Mobile App Developer

Cybersecurity

IT Consultant

Emmanuel Folarin

IT Infrastructure Developer/ Manage

Web/Mobile App Developer

Cybersecurity

IT Consultant

Blog Post

Why You Keep Getting Spam and Phishing Emails in Microsoft 365

June 4, 2025 Articles, Business Insight

Many organisations invest in Microsoft 365 but still complain about frequent spam and phishing emails. Staff see fake invoices, suspicious links, and emails pretending to be the CEO. Some even get through every day.

If this is happening in your company, it’s not because Microsoft 365 is weak. It’s usually because the right protections are not enabled or enforced.

What You Might Be Doing Wrong

  1. Relying only on default Exchange Online Protection (EOP).
  2. No SPF, DKIM, or DMARC on your domain.
  3. Not enforcing Multi-Factor Authentication (MFA).
  4. Overly permissive mail flow rules.
  5. No user awareness training.

What You Should Do Instead

1. Harden Microsoft 365 Security

2. Protect Your Domain with SPF, DKIM, and DMARC

Review DMARC reports (use external tools like MxToolbox).

Configure in Microsoft 365 Admin Center:
https://admin.microsoft.com

Check & enable DKIM:
https://security.microsoft.com/dkimv2

Example DNS setup:

SPF: v=spf1 include:spf.protection.outlook.com -all
DKIM: Enabled in Microsoft 365 Security & Compliance
DMARC: v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourcompany.com

3. Enforce MFA for All Users

4. Review Mail Flow Rules

5. Train Your Users

How to Check if Your Domain is Protected

Leadership Takeaway

Spam and phishing are not just IT issues they are business risks. Finance, HR, and CEOs are prime targets.

If phishing keeps slipping through in Microsoft 365, the likely cause is misconfigured security, missing domain protection, or poor staff training.

The fix is available today:

  • Enable Defender protections.
  • Enforce MFA.
  • Lock your domain with SPF/DKIM/DMARC.
  • Train your staff.
1 Comment
  • Arabella3600 2:49 pm September 5, 2025 Reply

    thanks for this

Write a comment