What "Sign of Non M365" means and why it matters

When you receive an email that claims to be from Microsoft 365 but wasn't actually sent through Microsoft's servers, your email client can flag it with a "Sign of Non M365" warning. This happens because the email failed authentication checks — specifically, it didn't pass SPF, DKIM, or DMARC verification, which are the technical standards Microsoft uses to prove an email genuinely came from them.

Attackers often spoof Microsoft 365 addresses because people trust them. They might send password reset scams, fake invoice alerts, or malware attachments that look like they came from your organization's Microsoft account. A "Sign of Non M365" warning is your email system's way of saying: "This email claims to be from Microsoft, but the proof doesn't add up."

The good news is that most modern email clients — Outlook, Gmail, and others — already catch these and mark them as suspicious. But you can go further and set up rules to block them entirely, move them to spam automatically, or flag them for review before they reach your inbox.

Key Takeaways

  • A "Sign of Non M365" warning means an email failed authentication checks and is likely spoofed, even if the sender address looks legitimate.
  • Outlook and Gmail both have built-in filters that catch these emails, but you can create additional rules to block or quarantine them automatically.
  • In Outlook, you can use mail flow rules (on desktop) or focused inbox settings (on web) to handle suspicious emails; in Gmail, you can create filters based on authentication status.
  • The most effective approach is to block emails that fail DMARC checks entirely, since legitimate Microsoft 365 emails will always pass this verification.
  • If you manage an organization's email, you can enforce stricter authentication policies at the server level to prevent spoofing before emails reach users.

How email authentication works and why spoofed Microsoft emails fail it

When Microsoft 365 sends an email on your behalf, it signs that email with a digital certificate that says "this really came from Microsoft's servers." The three main authentication methods are SPF (Sender Policy Framework), which checks if the sending server is authorized; DKIM (DomainKeys Identified Mail), which adds a cryptographic signature; and DMARC (Domain-based Message Authentication, Reporting, and Conformance), which ties the other two together and tells receiving servers what to do if an email fails.

A spoofed email might have a "from" address that looks like it came from Microsoft, but it was actually sent from a different server — one the attacker controls. When your email system checks the authentication headers, it finds a mismatch. The email fails DMARC, and your client flags it with a warning or rejects it outright.

The reason this matters: a legitimate email from Microsoft 365 will always pass these checks. If you see a "Sign of Non M365" warning, you can be confident the email is not genuinely from Microsoft, no matter how official it looks.

Blocking suspicious emails in Outlook

If you use Outlook on the web, the simplest approach is to use the focused inbox feature, which already separates emails that fail authentication into a "Other" tab. You can review them there before they clutter your main inbox. To adjust this: open Outlook, go to Settings (the gear icon), select "View all Outlook settings," then navigate to Mail > Focused Inbox and toggle it on if it is not already.

For more control, you can create a rule to automatically move suspicious emails to a folder. In Outlook on the web, go to Settings > Mail > Rules, then click "Add new rule." Set the condition to "The message header contains" and type "Authentication-Results" in the field. In the action section, choose "Move the message to a folder" and select Junk or a custom folder you create for review. This catches emails with failed authentication headers.

If you use Outlook desktop (the Windows or Mac application), you can set up mail flow rules through the File menu. Go to File > Manage Rules & Alerts, then create a new rule. Under "Check the message upon arrival," select "with specific words in the message header." Enter "Authentication-Results" and set the action to move or delete. Desktop Outlook gives you more granular control, but the web version works for most users.

Blocking suspicious emails in Gmail

Gmail's spam filter already catches most spoofed emails, but you can create a custom filter for extra protection. Open Gmail, click the search box at the top, then click the downward arrow to expand advanced search options. In the "From" field, type the legitimate Microsoft 365 address you want to protect against (for example, noreply@microsoft.com). In the "Has the words" field, type "unauthenticated" or "failed authentication."

Click "Create filter with this search." In the dialog that appears, check the box for "Skip the Inbox (Archive)" or "Delete it" depending on how aggressive you want to be. You can also check "Apply the label" and create a label like "Review — Suspicious" if you want to keep them for investigation rather than delete them immediately.

Another approach in Gmail is to use the "Report phishing" button when you receive a suspicious email. Click the three dots next to the email, select "Report phishing," and Gmail learns from your report. Over time, this trains Gmail's filter to catch similar emails.

Setting up organization-wide protections if you manage email

If you manage Microsoft 365 for a business or organization, you can enforce stricter authentication at the server level. In the Microsoft 365 admin center, go to Settings > Org settings > Security & Privacy, then enable "DMARC-based email authentication for your organization." This tells Microsoft's servers to reject or quarantine emails that fail DMARC checks before they reach any user's inbox.

You can also create transport rules in Exchange Online (the email backbone of Microsoft 365). Go to the Exchange admin center, select Mail flow > Rules, and create a new rule. Set the condition to "The sender's domain" and specify Microsoft's domain (microsoft.com). Add a second condition: "The message header contains" with "Authentication-Results: fail." Set the action to "Reject the message" or "Quarantine it for review." This stops spoofed Microsoft emails at the gateway.

For Gmail administrators, go to the Google Admin console, navigate to Security > Authentication, and enable "Enforce DMARC authentication." You can also set up security sandbox rules to quarantine suspicious emails before users see them, then review them in the quarantine folder.

What to do if you receive a suspicious email despite these protections

Even with rules in place, some spoofed emails may slip through. If you receive an email claiming to be from Microsoft 365 but you are unsure, do not click any links or download attachments. Instead, go directly to the Microsoft 365 website by typing the URL into your browser (not by clicking a link in the email) and log in to check your account. If there is a real alert, you will see it there.

Report the email to Microsoft. In Outlook, right-click the email and select "Report" > "Report phishing." In Gmail, click the three dots and select "Report phishing." Include the full email headers if possible — this helps Microsoft and Gmail identify the spoofing campaign and block it more broadly.

If the email came from inside your organization (spoofed to look like it came from a colleague's Microsoft 365 account), report it to your IT department immediately. This could indicate a compromised account or a more serious breach.

Frequently Asked Questions

Can I block all emails that fail DMARC without blocking legitimate ones?

Yes. Legitimate emails from Microsoft 365 will always pass DMARC checks. If you set a rule to reject or quarantine emails that fail DMARC, you will not accidentally block real Microsoft emails. The only risk is if someone forwards a Microsoft email to you — forwarding can sometimes break authentication — but the original email will still be intact in the forwarded message.

What if my organization uses Microsoft 365 but I still see "Sign of Non M365" warnings?

This usually means someone outside your organization is spoofing a Microsoft address, not that your own Microsoft 365 setup is broken. Your IT department can check your DMARC, SPF, and DKIM records to make sure they are configured correctly. If they are, the warnings you see are legitimate alerts about external spoofing attempts.

Will blocking these emails prevent me from getting real Microsoft notifications?

No. Real Microsoft notifications come from authenticated Microsoft 365 servers and will pass all authentication checks. If you set rules to block emails that fail authentication, you will only block spoofed emails, not genuine ones from Microsoft.

Can I tell if an email is spoofed just by looking at it?

Not reliably. Spoofed emails can look nearly identical to real ones. The "From" address can be faked, and the email body can include real Microsoft logos and formatting. The only reliable way to tell is to check the authentication headers (which your email client does automatically) or to go directly to the Microsoft website and check your account there, rather than clicking links in the email.

What is the difference between moving suspicious emails to a folder and deleting them?

Moving them to a folder (like Junk or a custom "Review" folder) lets you check them later if you are unsure. Deleting them immediately is more aggressive but means you might miss a legitimate email if the authentication system makes a mistake. Most people find moving to a folder is the safer middle ground.