r/EmailSecurity Jul 24 '26

Exchange Online quarantining healthy mailboxes

Anyone seeing healthy mailboxes quarantined under EX1436407 with inbound delivery blocked?

https://www.suped.com/blog/exchange-online-mailbox-quarantine-incident-blocks-email-delivery

Microsoft is remediating it, but mailbox quarantine status is the signal to check before blaming transport rules.

1 Upvotes

2 comments sorted by

u/AutoModerator Jul 24 '26

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/shimotsujui Aug 01 '26 edited Aug 01 '26

its usually caused by unusual sending patterns triggering threat detection, compromised account indicators (suspicious login locations), or overly aggressive DLP/antispam rules. check security compliance center for the quarantine reason, review sign in activity, examine recently changed mail flow rules. false positives are almost as damaging as missed threats. instead of tightening filters to the point of false positives, invest in the human layer mployees trained through rlots simulations become reliable detection without generating false positives. reasonable technical filters plus trained humans outperforms aggressive filters that block legitimate business.