Full Breakdown
Microsoft Exchange Online Incident: Legitimate Emails Flagged as Phishing
2/9/2026, 11:46:03 PM
Overview of the Incident
Since February 5, 2026, Microsoft Exchange Online has been incorrectly flagging legitimate emails as phishing, resulting in their quarantine. This issue, tracked as service alert EX1227432, has affected organizations globally, causing significant operational disruptions. The root cause is a newly introduced URL detection rule that mistakenly identifies safe URLs as malicious due to overly aggressive detection criteria. As a result, users are experiencing difficulties in sending and receiving emails, with both inbound and outbound messages being trapped in quarantine.
Technical Cause and Resolution Efforts
Microsoft has acknowledged that the surge in false positives stems from the evolving criteria used to identify suspicious emails. The company stated, “We’ve determined that the URLs associated with these email messages are incorrectly marked as phish and quarantined in Exchange Online.” Engineers are actively reviewing quarantined messages and unblocking confirmed legitimate URLs, with some previously quarantined messages now being delivered. However, Microsoft has not provided a specific timeline for a full resolution or disclosed the number of affected customers or regions.
Historical Context and Recurring Issues
This incident is not isolated; it follows a pattern of similar issues within Microsoft Exchange Online. Notably, in May 2025, a machine learning model incorrectly flagged Gmail emails as spam, and similar incidents occurred in March and September 2025. The recurring nature of these disruptions raises concerns about the reliability of Microsoft’s email infrastructure. A previous incident in June-July 2024 also involved legitimate emails being misclassified as phishing due to changes in the detection system. These historical patterns suggest ongoing challenges in balancing aggressive security measures with reliable email delivery.
Criticism and User Guidance
The lack of transparency regarding the timeline for resolution has frustrated IT administrators, who require clear communication with users about service restoration. Administrators are advised to prepare contingency plans, including backup communication channels and incident response playbooks for false-positive quarantines. Users have expressed mounting frustration over Exchange’s anti-phishing policies, which often override whitelists for high-confidence detections. Cybersecurity forums have reported persistent issues, with many users requiring support tickets for backend fixes.
Conclusion and Next Steps
As Microsoft continues to address the false positive issue, organizations dependent on Exchange Online are encouraged to establish parallel communication systems and develop comprehensive incident response strategies. With no confirmed resolution date for the ongoing incident, administrators face immediate decisions regarding user notifications and backup communication protocols. The situation underscores the need for proactive monitoring and effective management of complex email environments.
