Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
All organizations with cloud mailboxes assign a bulk complaint level (BCL) value to inbound messages from bulk senders. The BCL value is added to the message in an X-header and is similar to the spam confidence level (SCL) that identifies messages as spam. A higher BCL value indicates a bulk message is more likely to exhibit undesirable spam-like behavior. Microsoft uses both internal and non-Microsoft sources to identify bulk mail and determine the appropriate BCL value.
Bulk senders vary in their sending patterns, content creation, and recipient acquisition practices. Good bulk senders send desired messages with relevant content to their subscribers. These messages generate few complaints from recipients. Other bulk senders send unsolicited messages that closely resemble spam and generate many complaints from recipients. Messages from a bulk sender are known as bulk mail or gray mail.
Spam filtering marks messages as Bulk email based on the BCL threshold in anti-spam policies and takes the specified action on the message. For more information, see Configure anti-spam policies and What's the difference between junk email and bulk email?
The BCL thresholds are described in the following table:
BCL | Description |
---|---|
0 | The message isn't from a bulk sender. |
1, 2, 3 | The message is from a bulk sender that generates few complaints. |
4, 5, 6, 7 | The message is from a bulk sender that generates a mixed number of complaints. |
8, 9 | The message is from a bulk sender that generates a high number of complaints. |
The default BCL threshold that's used in anti-spam policies is described in the following list:
- Default anti-spam policy and new anti-spam policies: 7.
- Standard preset security policy: 6.
- Strict preset security policy: 5.
Messages that meet or exceed the configured BCL threshold have the following default actions taken on them:
- Default anti-spam policy, new anti-spam policies, and Standard preset security policy: Deliver the message to recipient Junk Email folders.
- Strict preset security policy: Quarantine the message.
BCL threshold in the Threat protection status report
The filters in the View data by Email > Spam and Chart breakdown by Detection Technology view of the Threat protection status report in the Microsoft Defender portal at https://security.microsoft.com/reports/TPSEmailSpamReportATP contain the Bulk complaint level slider.
Select
Filter. In the Filters flyout that opens, select only the Detection value Bulk in the Filters flyout that opens. Use the Bulk complaint level slider to increase or decrease the BCL threshold.
After you apply the filters and return to the main report page, you see that hanging the BCL threshold changes the data in the report:
- Increasing the BCL threshold identifies fewer messages as bulk.
- Decreasing the BCL threshold value identifies more messages as bulk.
- Set a minimum and maximum BCL threshold to see the effect on bulk detections.
Bulk senders insight
The bulk senders insight in the Defender portal allows you to see how much mail was identified as bulk at the current BCL threshold in anti-spam policies, and to simulate identified vs. allowed bulk email based on changes in the BCL threshold.
The bulk senders insight is available in the following locations in the Defender portal:
- In the properties of the default anti-spam policy or custom anti-spam policies.
- On the Email & collaboration reports and insights page at https://security.microsoft.com/emailandcollabreport.
For more information, see Bulk senders insight.