Contact forms

Contact form emails not reaching Outlook or Microsoft 365

Outlook and Microsoft 365 junk, quarantine or reject form emails that are not authenticated. How to check the junk folder, quarantine and message trace, and what to fix on the sending side.

October 3, 2026 · 6 min read

Your site sends the form email, but it never shows up in Outlook, Hotmail or your company’s Microsoft 365 mailbox. Microsoft is strict about unauthenticated mail, so this is often where contact form emails disappear first. Here is where to look, and what to change so it stops happening.

If you are not sure the email was sent at all, start with Contact form not sending email? Why it happens and how to fix it.

1. Check Junk, Other and your rules

  • Open the Junk Email folder and search for the form’s subject line.
  • If Focused Inbox is on, check the Other tab.
  • Review your rules for anything that moves or deletes mail from your website.

If you find the email in Junk, mark it as Not junk and add the sender to Safe senders under Settings → Mail → Junk email. That helps your mailbox while you fix the cause below.

2. Microsoft 365: quarantine and message trace

In a business Microsoft 365 account, suspicious mail may be quarantined and never reach the mailbox at all.

  • Quarantine: users and admins can review held messages in the Microsoft Defender portal. Many companies send a quarantine notification email, which is easy to overlook.
  • Message trace: an admin can search for the email in the Exchange admin center under Mail flow → Message trace. It shows whether Microsoft received it and whether it was delivered, junked, quarantined or rejected.

An allow entry or a mail-flow rule that skips spam filtering for your website’s address will make the emails appear, but it also lets anyone forging that address through. Fix authentication instead.

3. Check for rejections at the sending side

If the email never reached Microsoft at all, your SMTP or delivery log will show a rejection. Since 2025 Microsoft enforces SPF, DKIM and DMARC for high-volume senders to Outlook.com, Hotmail and Live addresses, and rejects failing mail with errors such as 550 5.7.515. Other common rejections mean the sending server’s IP has a poor reputation, which is frequent on shared web hosting. Our guide to bounce codes explains how to read them.

4. Fix the sending side

  1. Send through an authenticated mail service, not the web server’s PHP mail function.
  2. Make sure that service passes SPF and signs with DKIM for the domain in your From address.
  3. Publish a DMARC record for your domain. See SPF vs DKIM vs DMARC.
  4. Send from your own domain and put the visitor in Reply-To: why the From address matters.

With SecureSMTP, form emails are DKIM-signed and pass SPF and DMARC, and every message appears in your delivery log, so you can see straight away whether Microsoft accepted it or bounced it.

Frequently asked questions

What does the error 550 5.7.515 mean?

Microsoft rejected the email because it did not meet its authentication requirements for the sending domain (SPF, DKIM and DMARC). Fix the authentication on the sending side; nothing in the recipient’s mailbox can change it.

Is adding the sender to Safe senders enough?

It helps that one mailbox, and only for messages that reach it. Rejected messages never arrive, and quarantined ones may bypass the setting. Treat it as a stopgap while you fix authentication.

Why do emails reach Gmail but not Outlook?

Each provider filters differently. Microsoft weighs authentication and sender reputation heavily, so a form that sends unauthenticated mail through a shared web server often fails at Outlook first.

Related reading

Fix email delivery on your site

SecureSMTP delivers WordPress, Shopify, and custom form emails with SPF + DKIM + DMARC alignment. Free tier covers most small sites.