Bird
Bird

A world of possibilities.
One place to start.

Microsoft SCL and BCL: Reading Email Spam Headers

Microsoft SCL and BCL: Reading Email Spam Headers

A message header can tell you how Microsoft processed an email, but a single score cannot explain every delivery decision.

This article was first published in 2018. Microsoft's documentation has changed: its August 2026 SCL guidance explicitly cautions against treating the score as the verdict or action for a cloud mailbox. The explanation below now reflects that distinction. For consumer Outlook.com delivery requirements, use our separate Outlook deliverability checklist.

Read the headers from the affected message

Start with a message the recipient actually received, keeping its message ID and delivery time. Microsoft's header reference describes three useful fields:

HeaderWhat to inspect
X-Forefront-Antispam-ReportProcessing fields including CAT, DIR and SCL
X-Microsoft-AntispamBulk-mail information including BCL
Authentication-ResultsSPF, DKIM and DMARC results

Use the email analyzer to inspect a received message's headers. Keep the original header text available when discussing the case with the recipient's administrator; a summary can omit a field they need.

SCL is not a universal inbox verdict

SCL means Spam Confidence Level. Microsoft's current documentation says that, in cloud organizations, SCL does not by itself determine a spam classification or the action taken. The same value can accompany different verdicts. Inspect the category and direction fields, then the relevant policy. SCL retains specific uses in mail flow rules and on-premises or hybrid Exchange. Microsoft's SCL guidance.

That is why we removed the old table promising that -1 always means Inbox and 5–9 always means Junk. Those statements collapse different environments and policy decisions into one number.

For a support case, ask which system handled the message: a Microsoft 365 cloud mailbox, an on-premises Exchange server, a hybrid route, or the Outlook.com consumer service. An answer for one is not automatically an answer for the others.

BCL describes bulk-mail complaint risk

BCL means Bulk Complaint Level. Microsoft's published bands are:

BCLPublished interpretation
0Not from a bulk sender
1–3Bulk sender associated with few complaints
4–7Bulk sender associated with a mixed number of complaints
8–9Bulk sender associated with a high number of complaints

The recipient organization's anti-spam policy sets the threshold and resulting action. A BCL value is not your campaign's complaint percentage. Microsoft's bulk-mail guidance.

If bulk classification is implicated, review the affected subscription stream: how addresses joined it, what they expected, how often you send, and whether opt-outs stop subsequent messages. Keep that review separate from fixing a failed authentication check.

Be careful with older PCL explanations

Earlier editions discussed Phishing Confidence Level alongside SCL and BCL as though three scores decided placement everywhere. Microsoft's current cloud header reference documents phishing categories and other diagnostic fields. Use that reference to interpret the fields actually present in the message instead of applying the old PCL table universally. Microsoft's anti-spam header reference.

Do not infer an undocumented field's meaning from its name. If the recipient's administrator needs a field that Microsoft reserves for internal diagnostics, preserve the original message for support.

Turn a score into a useful investigation

  1. Collect one affected message and one relevant comparison message. Match the application, sender domain and message type where possible.
  2. Inspect Bird's recipient events to distinguish a provider rejection from acceptance followed by filtering.
  3. Check the received authentication results. If they fail, review SPF, DKIM and DMARC configuration before changing the template.
  4. Ask the recipient's administrator to inspect the applied category, policy and message trace. The sender cannot read a tenant's policy from an SCL value alone.
  5. Record the change made and verify another message through the same path.

The useful outcome is an explained message-handling decision and a tested correction, rather than a lower score with no account of what changed.

Start with one channel.
Add the others when you're ready.

A test API key is yours immediately. Production unlocks when you add a payment method and verify a sender.

Read docs
Using Claude Code, Cursor, or Codex? Copy a setup prompt and your agent installs the Bird CLI and skills for you. Pick yours:
Cursor