Spam filter tuning without blind spots
Aggressive block lists feel productive until legitimate mail vanishes. How to tighten filtering without losing invoices, MFA codes, and vendor threads.

Every MSP has seen the same cycle: leadership gets tired of spam, someone cranks filtering to “High,” finance stops seeing ACH confirmations, and suddenly you are the reason payroll almost missed a cutoff. Tuning spam filters is a balance problem, not a slider you set once and forget.
The goal is fewer unwanted messages and visible proof that good mail still arrives. If you cannot show that second part, you are guessing.
Why aggressive tuning backfires
Business mail looks like spam. New domains, shared hosting, PDF invoices, and one-off Gmail senders trip reputation and content rules constantly.
Blind quarantine is invisible failure. Messages deleted or quarantined without user-visible release paths do not generate help desk tickets. They generate silent business problems.
Allow lists grow without owners. “Just whitelist the domain” fixes today’s ticket and hides tomorrow’s compromised vendor account.
Different users need different tolerance. Accounts payable lives on attachments from strangers. Executives need fewer pitches, not fewer attorney emails.
A sane tuning posture
Think in layers instead of one nuclear setting:
- Platform defaults first. Microsoft Defender for Office 365 (or your provider’s baseline) with standard anti-phish policies before custom rules
- Targeted rules for repeat offenders. Block known bad TLD campaigns, not entire countries, unless you have data
- User-visible quarantine with a daily digest or self-service release where policy allows
- Separate handling for bulk vs phish. Marketing noise and credential theft are not the same problem
When leadership asks for “zero spam,” translate that to “reduce phish and obvious junk without hiding mail we might need to pay.”
What to measure before you tighten
Pull two weeks of data before you change policies:
- Quarantine and filter hits by sender domain and recipient role (finance, HR, general)
- False positive reports from staff (even informal “did anyone not get X?” counts)
- Authentication failures (SPF/DKIM/DMARC) on mail you actually want
If you cannot see quarantined messages, fix visibility before you add blocks.
Do and don’t
Do
- Pilot policy changes on a security group before the whole tenant
- Document every allow/block entry with owner and review date
- Tell finance and AP when you change attachment or spoof policies
- Keep impersonation protection enabled for executives and payment roles
Don’t
- Block top-level domains because one scam used
.zip - Delete quarantined mail silently with no audit trail
- Add permanent allows for “anyone who complained once”
- Assume Google Postmaster or Microsoft secure score alone means mail flow is healthy
When to escalate to stricter controls
Tighten deliberately when you see repeated phish from the same pattern, not when someone is annoyed by newsletters. Pair stricter filtering with pre-delivery review for high-risk mail types if licensing allows, and always keep a monitored mailbox for “mail I expected.”
Bottom line
Spam filtering is operational security, not a volume knob. Measure quarantine and false positives, change policies in pilots, document allow lists with owners, and keep business-critical recipients in the loop. Less junk mail is only a win if the mail you need still shows up.

Michael Narehood