Any suggestions on how to prevent this (apart from trying to persuade Microsoft to modify their mails!)?
You can see I updated to latest spamassassin as part of my testing. Typical headers: Return-Path: <[email protected]> Delivered-To: dmarc-feedback@alias-localdelivery-esmith Return-Path: <[email protected]> X-Original-To: [email protected] X-Virus-Checked: by ClamAV 1.4.5 on server.com X-Virus-Found: No X-Spam-Level: ****** X-Spam-Status: Yes, score=6.0 required=5.0 autolearn=disabled X-Spam-Details: * 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) * [52.101.62.85 listed in wl.mailspike.net] * -0.0 SPF_HELO_PASS SPF: HELO matches SPF record * -0.0 SPF_PASS SPF: sender matches SPF record* 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
* valid* -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
* 0.0 ARC_VALID Message has a valid ARC signature * 0.0 ARC_SIGNED Message has a ARC signature * 0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60% * [score: 0.4948]* 0.1 HTML_OBFUSCATE_10_20 BODY: Message is 10% to 20% HTML obfuscation
* 0.0 T_TVD_MIME_NO_HEADERS BODY: No description available. * 0.0 HTML_MESSAGE BODY: HTML included in message* 0.1 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME * 1.5 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line
* length greater than 79 characters * 0.8 MPART_ALT_DIFF BODY: HTML and text parts are different * 0.1 BASE64_LENGTH_78_79 BODY: No description available.* 1.7 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
* -0.0 DMARC_PASS DMARC pass policy* -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no
* trust * [52.101.62.85 listed in list.dnswl.org] * 1.4 PYZOR_CHECK Listed in Pyzor * (https://pyzor.readthedocs.io/en/latest/) * -0.5 DKIMWL_WL_MED DKIMwl.org - Medium trust sender X-Spam-Flag: YES X-Spam-Checker-Version: SpamAssassin 4.0.3-rsvnunknown (svnunknown) on my.server.com X-GeoIP-City: Des Moines X-GeoIP-Continent: NA X-GeoIP-Country: US X-HELO: DM5PR21CU001.outbound.protection.outlook.comAuthentication-Results: server.com; auth=none; spf=pass smtp.mailfrom=microsoft.com; dkim=pass [email protected]; dmarc=pass (p=reject) d=microsoft.com Received: from mail-centralusazon11021085.outbound.protection.outlook.com (HELO DM5PR21CU001.outbound.protection.outlook.com) (52.101.62.85) by server.com (qpsmtpd/1.00) with ESMTPS (TLS_AES_256_GCM_SHA384 encrypted); Thu, 23 Jul 2026 07:09:55 +0200 X-DKIM-Authentication: domain: notification.microsoft.com, selector: selector1, result: pass, policy: o=~, name: sender, policy_result: neutral, policy: o=~, name: author, policy_result: neutral, policy: , name: ADSP, policy_result: neutral Received-SPF: pass (microsoft.com: Sender is authorized to use '[email protected]' in 'mfrom' identity (mechanism 'include:_spf-a.microsoft.com' matched)) receiver=my.server.com; identity=mailfrom; envelope-from="[email protected]"; helo=DM5PR21CU001.outbound.protection.outlook.com; client-ip=52.101.62.85
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; Return-Path: <[email protected]> Delivered-To: dmarc-feedback@alias-localdelivery-esmith Return-Path: <[email protected]> X-Original-To: [email protected] X-Virus-Checked: by ClamAV 1.4.5 on server.com X-Virus-Found: No X-Spam-Level: ********* X-Spam-Flag: YES X-Spam-Status: Yes, score=9.1 required=5.0 autolearn=disabled X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on my.server.comX-Spam-Details: * -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no
* trust * [52.101.43.99 listed in list.dnswl.org] * -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) * [52.101.43.99 listed in wl.mailspike.net] * -0.0 SPF_PASS SPF: sender matches SPF record * -0.0 SPF_HELO_PASS SPF: HELO matches SPF record* -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature * 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
* valid * 3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100% * [score: 1.0000] * 0.2 BAYES_999 BODY: Bayes spam probability is 99.9 to 100% * [score: 1.0000]* 0.1 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
* 0.0 HTML_MESSAGE BODY: HTML included in message * 0.8 MPART_ALT_DIFF BODY: HTML and text parts are different * 0.0 T_TVD_MIME_NO_HEADERS BODY: No description available. * 0.1 BASE64_LENGTH_78_79 BODY: No description available.* 1.5 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line
* length greater than 79 characters* 1.7 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
* -0.0 DMARC_PASS DMARC pass policy * 1.4 PYZOR_CHECK Listed in Pyzor * (https://pyzor.readthedocs.io/en/latest/) * -0.2 DKIMWL_WL_MED DKIMwl.org - Medium trust sender X-GeoIP-City: San Jose X-GeoIP-Continent: NA X-GeoIP-Country: US X-HELO: SJ2PR03CU001.outbound.protection.outlook.comAuthentication-Results: server.com; auth=none; spf=pass smtp.mailfrom=microsoft.com; dkim=pass [email protected]; dmarc=pass (p=reject) d=microsoft.com Received: from mail-westusazon11022099.outbound.protection.outlook.com (HELO SJ2PR03CU001.outbound.protection.outlook.com) (52.101.43.99) by server.com (qpsmtpd/1.00) with ESMTPS (TLS_AES_256_GCM_SHA384 encrypted); Sat, 18 Jul 2026 07:08:59 +0200 X-DKIM-Authentication: domain: notification.microsoft.com, selector: selector1, result: pass, policy: o=~, name: sender, policy_result: neutral, policy: o=~, name: author, policy_result: neutral, policy: , name: ADSP, policy_result: neutral Received-SPF: pass (microsoft.com: Sender is authorized to use '[email protected]' in 'mfrom' identity (mechanism 'include:_spf-a.microsoft.com' matched)) receiver=my.server.com; identity=mailfrom; envelope-from="[email protected]"; helo=SJ2PR03CU001.outbound.protection.outlook.com; client-ip=52.101.43.99
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;
OpenPGP_0x4F1BA3C4EFD05AC9.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
