I have noticed that dmarc feedback reports from Microsoft are consistently marked as spam.

Any suggestions on how to prevent this (apart from trying to persuade Microsoft to modify their mails!)?

You can see I updated to latest spamassassin as part of my testing.

Typical headers:

Return-Path: <[email protected]>
Delivered-To: dmarc-feedback@alias-localdelivery-esmith
Return-Path: <[email protected]>
X-Original-To: [email protected]
X-Virus-Checked: by ClamAV 1.4.5 on server.com
X-Virus-Found: No
X-Spam-Level: ******
X-Spam-Status: Yes, score=6.0 required=5.0 autolearn=disabled
X-Spam-Details: *  0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
        *      [52.101.62.85 listed in wl.mailspike.net]
        * -0.0 SPF_HELO_PASS SPF: HELO matches SPF record
        * -0.0 SPF_PASS SPF: sender matches SPF record
        *  0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
        *      valid
        * -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
        *  0.0 ARC_VALID Message has a valid ARC signature
        *  0.0 ARC_SIGNED Message has a ARC signature
        *  0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
        *      [score: 0.4948]
        *  0.1 HTML_OBFUSCATE_10_20 BODY: Message is 10% to 20% HTML obfuscation
        *  0.0 T_TVD_MIME_NO_HEADERS BODY: No description available.
        *  0.0 HTML_MESSAGE BODY: HTML included in message
        *  0.1 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME         *  1.5 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line
        *      length greater than 79 characters
        *  0.8 MPART_ALT_DIFF BODY: HTML and text parts are different
        *  0.1 BASE64_LENGTH_78_79 BODY: No description available.
        *  1.7 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
        * -0.0 DMARC_PASS DMARC pass policy
        * -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no
        *      trust
        *      [52.101.62.85 listed in list.dnswl.org]
        *  1.4 PYZOR_CHECK Listed in Pyzor
        *      (https://pyzor.readthedocs.io/en/latest/)
        * -0.5 DKIMWL_WL_MED DKIMwl.org - Medium trust sender
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 4.0.3-rsvnunknown (svnunknown) on
        my.server.com
X-GeoIP-City: Des Moines
X-GeoIP-Continent: NA
X-GeoIP-Country: US
X-HELO: DM5PR21CU001.outbound.protection.outlook.com
Authentication-Results: server.com; auth=none; spf=pass smtp.mailfrom=microsoft.com; dkim=pass [email protected]; dmarc=pass (p=reject) d=microsoft.com Received: from mail-centralusazon11021085.outbound.protection.outlook.com (HELO DM5PR21CU001.outbound.protection.outlook.com) (52.101.62.85)  by server.com (qpsmtpd/1.00) with ESMTPS (TLS_AES_256_GCM_SHA384 encrypted); Thu, 23 Jul 2026 07:09:55 +0200 X-DKIM-Authentication: domain: notification.microsoft.com, selector: selector1, result: pass, policy: o=~, name: sender, policy_result: neutral, policy: o=~, name: author, policy_result: neutral, policy: , name: ADSP, policy_result: neutral Received-SPF: pass (microsoft.com: Sender is authorized to use '[email protected]' in 'mfrom' identity (mechanism 'include:_spf-a.microsoft.com' matched)) receiver=my.server.com; identity=mailfrom; envelope-from="[email protected]"; helo=DM5PR21CU001.outbound.protection.outlook.com; client-ip=52.101.62.85
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;

Return-Path: <[email protected]>
Delivered-To: dmarc-feedback@alias-localdelivery-esmith
Return-Path: <[email protected]>
X-Original-To: [email protected]
X-Virus-Checked: by ClamAV 1.4.5 on server.com
X-Virus-Found: No
X-Spam-Level: *********
X-Spam-Flag: YES
X-Spam-Status: Yes, score=9.1 required=5.0 autolearn=disabled
X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on
        my.server.com
X-Spam-Details: * -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no
        *      trust
        *      [52.101.43.99 listed in list.dnswl.org]
        * -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
        *      [52.101.43.99 listed in wl.mailspike.net]
        * -0.0 SPF_PASS SPF: sender matches SPF record
        * -0.0 SPF_HELO_PASS SPF: HELO matches SPF record
        * -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature         *  0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
        *      valid
        *  3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100%
        *      [score: 1.0000]
        *  0.2 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
        *      [score: 1.0000]
        *  0.1 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
        *  0.0 HTML_MESSAGE BODY: HTML included in message
        *  0.8 MPART_ALT_DIFF BODY: HTML and text parts are different
        *  0.0 T_TVD_MIME_NO_HEADERS BODY: No description available.
        *  0.1 BASE64_LENGTH_78_79 BODY: No description available.
        *  1.5 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line
        *      length greater than 79 characters
        *  1.7 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
        * -0.0 DMARC_PASS DMARC pass policy
        *  1.4 PYZOR_CHECK Listed in Pyzor
        *      (https://pyzor.readthedocs.io/en/latest/)
        * -0.2 DKIMWL_WL_MED DKIMwl.org - Medium trust sender
X-GeoIP-City: San Jose
X-GeoIP-Continent: NA
X-GeoIP-Country: US
X-HELO: SJ2PR03CU001.outbound.protection.outlook.com
Authentication-Results: server.com; auth=none; spf=pass smtp.mailfrom=microsoft.com; dkim=pass [email protected]; dmarc=pass (p=reject) d=microsoft.com Received: from mail-westusazon11022099.outbound.protection.outlook.com (HELO SJ2PR03CU001.outbound.protection.outlook.com) (52.101.43.99)  by server.com (qpsmtpd/1.00) with ESMTPS (TLS_AES_256_GCM_SHA384 encrypted); Sat, 18 Jul 2026 07:08:59 +0200 X-DKIM-Authentication: domain: notification.microsoft.com, selector: selector1, result: pass, policy: o=~, name: sender, policy_result: neutral, policy: o=~, name: author, policy_result: neutral, policy: , name: ADSP, policy_result: neutral Received-SPF: pass (microsoft.com: Sender is authorized to use '[email protected]' in 'mfrom' identity (mechanism 'include:_spf-a.microsoft.com' matched)) receiver=my.server.com; identity=mailfrom; envelope-from="[email protected]"; helo=SJ2PR03CU001.outbound.protection.outlook.com; client-ip=52.101.43.99
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;

Attachment: OpenPGP_0x4F1BA3C4EFD05AC9.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to