I manage Microsoft 365 Business Premium for several clients. Protected senders are configured with quarantine as the action, and display-name impersonation detection had worked reliably for months or even years. Over the past week or two, two separate tenants allowed obvious spoofing attempts through, including exact display-name matches for protected users. One message also had several warning signs, such as an urgent request and a reply-to address on an unrelated domain. The headers showed SCL 1, SFV NSPM, and CAT NONE, indicating the messages were scanned rather than bypassing filtering, but the impersonation classifier still did not flag them. Has anyone else noticed a recent drop in impersonation-detection accuracy?
2 Answers
I’d report each example through your provider or Microsoft support and include the full headers, policy configuration, and original messages. A few reports may help establish whether there’s a service-side regression and give them enough data to investigate.
Yes, I’ve seen several similar messages get through since last week. It does seem like something changed recently rather than being an isolated configuration issue.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures