If items are getting through that you expect to be blocked, take a look at the threat policies configuration analyzer and see what you can tune. https://security.microsoft.com/configurationAnalyzer. There are probably some thresholds you can adjust to reduce instances of bad mail getting through. When you say it is going in the mailbox, do you mean the inbox or junk mail? By changing anti-spam policy "actions" section, you can quarantine items instead of allowing them to go to a user's junk mail folder.