Has anyone else seen a sudden increase in messages between users within the same Microsoft 365 tenant being quarantined as "high confidence phish"? These are internal messages sent and received by users on the same local network, using fully updated Outlook Classic. DNS, DKIM, DMARC, and the tenant configuration appear correct, and nothing was intentionally changed. The issue may have started yesterday but became much more noticeable today, affecting multiple senders across the tenant. What could cause Microsoft 365 to classify legitimate internal mail this way?
4 Answers
Check the reputation of the sending domain, hosting IP, and any domains linked from signatures. Look for blacklist listings, unsafe browsing warnings, or expired TLS certificates. A compromised or newly flagged linked domain could affect multiple otherwise legitimate internal messages.
If the quarantine reason is specifically “high confidence phish,” rather than a generic policy match, that points more toward Microsoft’s phishing verdict than a local Outlook or LAN issue. Since it affects several internal senders, compare the messages for shared links, signatures, attachments, or other common content and review the tenant’s recent security-policy and service-health events.
Nothing similar is showing up in either of our tenants so far, but I’d keep monitoring Microsoft 365 service health and quarantine activity in case this is a broader detection change.
Open a quarantined message and inspect the detailed detection reason. A URL in the signature, a linked domain, or another message element can sometimes trigger a false positive even when authentication passes. Also verify that your anti-phishing and quarantine policies haven’t changed.

The quarantine entries all show “high confidence phish.” The messages are staying within the same tenant, and the users are on the same LAN using their normal, fully updated Outlook Classic clients.