Hi
You are definitely not alone in this; it is actually a well-documented issue between HubSpot sequences and Microsoft 365. Let me explain what’s actually happening.
Something Microsoft changed in its spam filtering is causing this. HubSpot confirmed they don’t violate Microsoft 365’s 30 messages per minute maximum, and HubSpot limits sequences to 3 emails per minute on their end. The problem is that Microsoft’s AI is flagging the sending pattern as suspicious regardless of the actual volume, likely because the sudden burst of outbound emails from a newly connected integration looks very different from your previous sending behavior.
The reason it worked fine through Zoho and even 1-by-1 through Outlook is that both of those sending patterns look completely normal to Microsoft’s filters. HubSpot sequences, even at low volumes, send in a way that Microsoft’s system doesn’t recognize as organic.
What you can do to fix this is make a custom outbound spam policy in the Microsoft Defender portal. To set up a new outbound policy and apply it to the senders who are affected, go to security.microsoft.com, then Email & Collaboration, then Policies & Rules, then Threat Policies, and finally Anti-spam.
Get your email administrator involved in this. You don’t want to change any of the settings for outbound spam without knowing what they do.
But there are a few other things that are worth checking in the meantime
First, make sure that your domain’s SPF, DKIM, and DMARC records are all set up correctly in HubSpot. HubSpot sends from a different infrastructure than Zoho, so your DNS records need to explicitly allow it. This is a very common mistake when moving CRM systems.
Second, if you have Sales Hub Enterprise, you can set a custom daily send limit in HubSpot that is higher than the default sequences limit. This lets you slow down the rate even more so that Microsoft’s filters don’t kick in. While you work this out, go to Settings → Objects → Activities → Email Frequency Controls and set a lower limit per minute.
Third, while the Defender policy change takes effect, try enrolling fewer people in your active sequence at a time, like 25 to 30 instead of 100 or more.
Hope this helps!
This is a fixable infrastructure issue, not a fundamental HubSpot problem. The combination of the custom outbound spam policy on the Microsoft side and proper DNS authentication on the HubSpot side has resolved it for others in exactly your situation. It’s worth exhausting those options before making a CRM decision based on it.
Hope this helps !