Introduction
Microsoft Defender for Office 365 does a great job of protecting our mailboxes from spam, phishing attacks, and malicious emails. It automatically scans every incoming email and blocks anything that looks suspicious.
But sometimes, it can also block genuine emails.
I recently faced this issue while setting up a Mailchimp account using a Microsoft 365 Shared Mailbox. Mailchimp sent a verification email, but it never appeared in Outlook. At first, I thought there was a problem with Mailchimp or the shared mailbox. After a little investigation, I found that Microsoft Defender had quarantined the email.
If you've ever wondered why an expected email is missing, this guide will show you how to find and release it from Microsoft Defender Quarantine.
The Problem I Faced
I was creating a new Mailchimp account and used a Shared Mailbox as the account email address.
After entering the email address, Mailchimp displayed a message saying that a verification email had been sent.
So I opened Outlook and waited.
Nothing arrived.
I checked:
Inbox
Junk Email
Deleted Items
Clutter (if enabled)
Still nothing.
There were no bounce-back messages, and Mailchimp confirmed that the email had been sent successfully.
That's when I suspected Microsoft Defender might have blocked it.
Why Does Microsoft Defender Quarantine Emails?
Microsoft Defender checks every incoming email before it reaches your mailbox. If it thinks an email might be unsafe, it moves it to Quarantine instead of delivering it.
This can happen for several reasons, including:
The sender is new.
The email contains tracking or marketing links.
SPF, DKIM, or DMARC validation doesn't fully pass.
The email matches anti-phishing or anti-spam rules.
Your organization has strict email security policies.
Even trusted services like Mailchimp, HubSpot, SendGrid, or DocuSign can sometimes have their emails quarantined.
How to Check if Your Email is in Quarantine
Open the Microsoft Defender Portal.
Go to:
Email & Collaboration → Review → Quarantine
Here you'll see all the emails that Microsoft Defender has quarantined.
Find Your Email
To make it easier to locate the email, use the available filters.
For example, I searched using:
Recipient
[email protected]Sender
mailchimp.comor
*@mailchimp.comWithin a few seconds, I found the missing verification email.
Review the Email Before Releasing It
Before releasing any email, always make sure it's safe.
Check details like:
Sender
Recipient
Subject
Why it was quarantined
Threat type
Links
Attachments
If you recognize the sender and know the email is legitimate, you can safely release it.
Never release emails from unknown or suspicious senders.
How to Release the Email
Once you've selected the email, click Release Email.
Depending on your organization's settings, you may see options such as:
Release to recipient
Report as False Positive
Allow future emails from this sender
Choose the options that apply, then click Release.
Within a few seconds, the email should be delivered to your mailbox.
Verify the Email
Go back to Outlook and refresh the mailbox.
The Mailchimp verification email should now appear in your Inbox.
Open it, click the verification link, and continue setting up your Mailchimp account.
Problem solved!
My Experience
Here's exactly what happened in my case.
Issue
Mailchimp sent the verification email.
Outlook didn't receive it.
Nothing was in the Junk folder.
What I Did
Opened Microsoft Defender.
Navigated to Quarantine.
Filtered emails by the shared mailbox.
Found the Mailchimp verification email.
Released the email.
Within a few seconds, the email appeared in Outlook, and I completed the Mailchimp account verification without any issues.
What If You Can't Release the Email?
Some organizations don't allow end users to release quarantined emails.
If you see a message like "Release not allowed", don't worry.
Simply contact your Microsoft 365 administrator and provide:
Recipient email address
Sender email address
Subject
Date and time the email was expected
Your administrator can review and release the email if it's safe.
How to Prevent This in the Future
If you regularly receive emails from a trusted sender, you can reduce the chances of them being quarantined again by:
Reporting the email as a False Positive.
Adding the sender or domain to the Allow List.
Reviewing your Anti-Spam policies.
Reviewing your Anti-Phishing policies.
Using the Tenant Allow/Block List when appropriate.
These steps help Microsoft Defender recognize trusted senders.
Best Practices
Whenever you're releasing emails from quarantine, keep these tips in mind:
Only release emails from trusted senders.
Double-check the sender's domain.
Review SPF, DKIM, and DMARC results if available.
Report false positives to Microsoft.
Regularly review quarantined emails.
Educate users about phishing and suspicious emails.
Troubleshooting Tips
If you still can't find your email, try these checks:
Search the Microsoft Defender Quarantine.
Run a Message Trace in the Exchange Admin Center.
Confirm that the sender actually sent the email.
Verify that the recipient email address is correct.
Check if a mail flow rule blocked the email.
Review your Anti-Spam and Anti-Phishing policies.
Contact your Microsoft 365 administrator if needed.
Conclusion
Microsoft Defender is designed to keep your organization safe, but occasionally it can quarantine genuine emails.
Before assuming an email wasn't sent, always check the Microsoft Defender Quarantine.
In my case, the missing Mailchimp verification email was sitting in quarantine the entire time. After releasing it, the email appeared in Outlook within seconds, and I was able to finish setting up the account.
If you're working with Shared Mailboxes or third-party services like Mailchimp, knowing how to check and release quarantined emails can save you a lot of time and unnecessary troubleshooting.

Join the conversation! Your thoughts help the community grow.