A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
Hi @ Rob,
Based on the information in the message header that you provide, compauth=fail reason=601 means that the message failed compound authentication due to spoofing within your organization.
I recommended that you create allow entries for spoofed senders in the tenant allow/block list, and select Internal for the spoofing type to see if that helps resolve the issue.
Allow or block email using the Tenant Allow/Block List | Microsoft Learn
In addition, please check the SCL value of messages marked as spam.
For messages with SCL values of 5, 6, 8, 9, the default anti-spam policy and the new anti-spam policy are also delivered to the recipient's spam folder.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.