You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/outbound-spam-policies-external-email-forwarding.md
+9-2Lines changed: 9 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ f1.keywords:
5
5
author: chrisda
6
6
ms.author: chrisda
7
7
manager: bagol
8
-
ms.date: 02/05/2025
8
+
ms.date: 10/06/2025
9
9
audience: ITPro
10
10
ms.topic: overview
11
11
ms.collection:
@@ -45,6 +45,8 @@ You can use outbound spam filter policies to control automatic forwarding to ext
45
45
-**On - Forwarding is enabled**: Automatic external forwarding is allowed and not restricted.
46
46
-**Off - Forwarding is disabled**: Automatic external forwarding is disabled and results in a non-delivery report (also known as an NDR or bounce message) to the sender.
47
47
48
+
:::image type="content" source="media/outbound-spam-protection-settings.png" alt-text="Screenshot of the Protection settings flyout in the properties of the default outbound spam filter policy with the Automatic forwarding rules options highlighted." lightbox="media/outbound-spam-protection-settings.png":::
49
+
48
50
For instructions on how to configure these settings, see [Configure outbound spam filtering](outbound-spam-policies-configure.md).
49
51
50
52
> [!NOTE]
@@ -57,7 +59,12 @@ For instructions on how to configure these settings, see [Configure outbound spa
57
59
As an admin, you might use other controls to allow or block automatic email forwarding. For example:
58
60
59
61
-[Remote domains](/exchange/mail-flow-best-practices/remote-domains/remote-domains) to allow or block automatic email forwarding to some or all external domains.
60
-
- Conditions and actions in Exchange [mail flow rules](/exchange/security-and-compliance/mail-flow-rules/mail-flow-rules) (also known as transport rules) to detect and block automatically forwarded messages to external recipients.
62
+
63
+
:::image type="content" source="media/outbound-spam-remote-domains-auto-forwarding.png" alt-text="Screenshot of the Email reply types flyout in the properties of a remote domain in the Exchange admin center with the Allow automatic forwarding option highlighted." lightbox="media/outbound-spam-remote-domains-auto-forwarding.png":::
64
+
65
+
- Conditions and actions in Exchange [mail flow rules](/exchange/security-and-compliance/mail-flow-rules/mail-flow-rules) (also known as transport rules) to detect and block automatically forwarded messages to external recipients by Inbox rules.
66
+
67
+
:::image type="content" source="media/outbound-spam-mail-flow-rule-detect-block-forwarded.png" alt-text="Screenshot of a mail flow rule to detect and block messages automatically forwarded to external recipients by Inbox rules." lightbox="media/outbound-spam-mail-flow-rule-detect-block-forwarded.png":::
61
68
62
69
When one setting allows external forwarding, but another setting blocks external forwarding, the block typically wins. Examples are described in the following table:
Copy file name to clipboardExpand all lines: defender-office-365/submissions-user-reported-messages-custom-mailbox.md
+35-14Lines changed: 35 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.collection:
16
16
ms.custom:
17
17
description: "Admins can configure where user reported messages go for analysis: to an internal reporting mailbox, to Microsoft, or both. Other settings complete the reporting experience for users when they report good messages, spam, or phishing messages from Outlook."
18
18
ms.service: defender-office-365
19
-
ms.date: 02/24/2024
19
+
ms.date: 10/06/2025
20
20
appliesto:
21
21
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
22
22
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -37,7 +37,6 @@ User reported settings and the reporting mailbox work with the following message
37
37
Delivering user reported messages to a reporting mailbox instead of directly to Microsoft allows admins to selectively and manually submit messages to Microsoft from the **User reported** tab on the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>. For more information, see [Admin submission](submissions-admin.md).
38
38
39
39
> [!NOTE]
40
-
>
41
40
> For information about user reported message settings in Microsoft Teams in Defender for Office 365 Plan 2, see [User reported message settings in Microsoft Teams](submissions-teams.md).
42
41
43
42
## Configuration requirements for the reporting mailbox
@@ -85,21 +84,34 @@ On the **User reported settings** page, the available settings for reporting mes
85
84
86
85
-**Monitor reported messages in Outlook** is selected: The following configurations are supported:
87
86
88
-
- Use the built-in **Report** button in [supported versions of Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook) on virtually all Outlook platforms to report email messages.
87
+
-**Use the built-in Report button in Outlook**: Use the**Report** button in [supported versions of Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook) on virtually all Outlook platforms to report email messages.
89
88
- Configure user reported messages to go to the reporting mailbox, to Microsoft, or both.
90
89
- Decide whether users receive default or customized pre-reporting and post-reporting pop-ups in supported version of Outlook.
91
90
- Decide whether to customize the feedback email sent to users after an admin reviews and marks the message on the **User submissions** tab on the **Submissions** page.
92
91
- Decide whether users can report email messages from quarantine as they release quarantined messages.
93
92
94
93
For details, see the [Options for Microsoft reporting tools](#options-for-microsoft-reporting-tools) section in this article.
95
94
96
-
- Use a non-Microsoft add-in to report email messages.
97
-
- Configure user reported messages from a non-Microsoft reporting mailbox to Microsoft.
95
+
-**Use a non-Microsoft add-in button**:
96
+
- Configure user reported messages to go to the reporting mailbox, or the reporting mailbox and Microsoft (Microsoft only isn't available).
98
97
- Decide whether to customize the feedback email sent to users after an admin reviews and marks the message on the **User submissions** tab on the **Submissions** page.
99
98
- Decide whether users can report email messages from quarantine as they release quarantined messages.
100
99
101
100
For details, see the [Options for non-Microsoft reporting tools](#options-for-non-microsoft-reporting-tools) section in this article.
102
101
102
+
The available feature differences for the built-in **Report** button vs. a non-Microsoft add-in button are summarized in the following table:
|Ask the user to confirm before reporting|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_absent_icon.png":::|
107
+
|Show a success (pop-up) message after the message is reported|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_absent_icon.png":::|
108
+
|Customize (pop-up) messages for **Report phishing**, **Report junk**, **Report not junk**, **Phishing reported**, and **Junk reported** in up to seven languages|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_absent_icon.png":::|
109
+
|Reported message destination|<ul><li>Microsoft and reporting mailbox</li><li>Reporting mailbox only</li><li>Microsoft only</li></ul>|<ul><li>Microsoft and reporting mailbox</li><li>Reporting mailbox only</li></ul>|
110
+
|Email users the results of the investigation|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::|
111
+
|Customize the body and footer of the results email for **Phishing**, **Junk**, and **No threats found**|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::|
112
+
|Customize the logo in all reporting experiences|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::|
113
+
|Allow reporting for quarantined messages|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::|
114
+
103
115
### Options for Microsoft reporting tools
104
116
105
117
When **Monitor reported messages in Outlook** is selected and you also select **Use the built-in Report button in Outlook**, the following options are available on the **User reported settings** page:
@@ -156,17 +168,19 @@ When **Monitor reported messages in Outlook** is selected and you also select **
156
168
157
169
To specify a different mailbox, select :::image type="icon" source="media/m365-cc-sc-remove-selection-icon.png" border="false"::: next to any existing entry in the **Add an Exchange Online mailbox to send reported messages to** box. Click in the box and wait for the list of mailboxes to populate, or start typing a value to filter the list, and then select the mailbox in the results. Distribution groups and routing to an external or on-premises mailbox aren't allowed.
158
170
159
-
-**Microsoft only**: User reported messages go directly to Microsoft for analysis.
171
+
In organizations with Defender for Office 365 Plan 2, [Automatic investigation and response (AIR)](air-about.md) is triggered automatically to carry out analysis and clean up actions for you.
160
172
161
173
-**My reporting mailbox only**: User reported messages go only to the specified reporting mailbox for an admin or the security operations team to analyze.
162
174
163
175
Follow the previous instructions to select the mailbox in the **Add an Exchange Online mailbox to send reported messages to** box.
164
176
165
177
On the **User reported** tab on the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>, the **Result** value for these entries is **Not Submitted to Microsoft**. Messages don't go to Microsoft for analysis unless an admin manually submits the message. For instructions, see [Submit user reported messages to Microsoft for analysis](submissions-admin.md#submit-user-reported-messages-to-microsoft-for-analysis).
166
178
179
+
-**Microsoft only**: User reported messages go directly to Microsoft for analysis.
180
+
167
181
> [!NOTE]
168
182
>
169
-
> - When you select **Use the built-in Report button in Outlook** and users report messages using the built-in **Report** button in [supported versions of Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook), user reported messages are available to admins on the **User reported** tab on the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>, regardless of the value you select for **Send the reported messages to**. For more information, see [Admin options for user reported messages](submissions-admin.md#admin-options-for-user-reported-messages).
183
+
> - When using the built-in **Report** button in [supported versions of Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook), user reported messages are available to admins on the **User reported** tab on the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>, regardless of the value you select for **Send the reported messages to**. For more information, see [Admin options for user reported messages](submissions-admin.md#admin-options-for-user-reported-messages).
170
184
>
171
185
> - In U.S. Government organizations (Microsoft 365 GCC, GCC High, and DoD), the only available value for **Send the reported messages to** is **My reporting mailbox only**. The other two options are unavailable for compliance reasons (data isn't allowed to leave the organization boundary).
172
186
@@ -219,19 +233,26 @@ The message formatting requirements for integrating non-Microsoft reporting solu
219
233
220
234
When **Monitor reported messages in Outlook** is selected and you also select **Use a non-Microsoft add-in button**, the following options are available on the **User reported settings** page:
221
235
222
-
-**Reported message destinations** section:
236
+
-**Reported message destinations** section\>**Send the reported messages to**: Select one of the following options:
223
237
224
238
> [!TIP]
225
239
> For more information about how Microsoft stores and handle your submissions, see [Report suspicious email messages to Microsoft](submissions-report-messages-files-to-microsoft.md#report-suspicious-email-messages-to-microsoft).
226
240
>
227
241
> For more information about the available **Result** values for user reported messages on **User reported** tab of the **Submissions** page after analysis by Microsoft, see [Submission result definitions](submissions-result-definitions.md).
228
242
229
-
-**Send reported messages to**: Select one of the following options:
230
-
-**My reporting mailbox only** : Microsoft pulls metadata about user reported messages from the non-Microsoft reporting mailbox. Messages appear on the **User reported** tab of the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user> with the **Result** value **Not Submitted to Microsoft**.
243
+
-**Microsoft and my reporting mailbox**: User reported messages go to Microsoft for analysis and to the specified reporting mailbox. Admins or security operations (SecOps) personnel can analyze the messages.
231
244
232
-
-**Microsoft and My reporting mailbox**: Microsoft pulls metadata and message content about user reported messages from the non-Microsoft reporting mailbox. Messages appear on the **User reported**tab of the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>.
245
+
The default user reporting mailbox is the Exchange Online mailbox of the global admin. Currently, the global admin isn't _shown_ as the user reported mailbox on the **User reported settings**page until _after_the first user in the organization reports a message from Outlook.
233
246
234
-
-**Add an Exchange Online mailbox to send reported messages to**: Specify an existing internal reporting mailbox to hold user reported messages from non-Microsoft reporting tools. In organizations with Defender for Office 365 Plan 2, [Automatic investigation and response (AIR)](air-about.md) is triggered automatically to carry out analysis and clean up actions for you.
247
+
To specify a different mailbox, select :::image type="icon" source="media/m365-cc-sc-remove-selection-icon.png" border="false"::: next to any existing entry in the **Add an Exchange Online mailbox to send reported messages to** box. Click in the box and wait for the list of mailboxes to populate, or start typing a value to filter the list, and then select the mailbox in the results. Distribution groups and routing to an external or on-premises mailbox aren't allowed.
248
+
249
+
In organizations with Defender for Office 365 Plan 2, [Automatic investigation and response (AIR)](air-about.md) is triggered automatically to carry out analysis and clean up actions for you.
250
+
251
+
-**My reporting mailbox only**: User reported messages go only to the specified reporting mailbox for an admin or the security operations team to analyze.
252
+
253
+
Follow the previous instructions to select the mailbox in the **Add an Exchange Online mailbox to send reported messages to** box.
254
+
255
+
On the **User reported** tab on the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>, the **Result** value for these entries is **Not Submitted to Microsoft**. Messages don't go to Microsoft for analysis unless an admin manually submits the message. For instructions, see [Submit user reported messages to Microsoft for analysis](submissions-admin.md#submit-user-reported-messages-to-microsoft-for-analysis).
235
256
236
257
-**Email notifications** section: These options affect the notification email message that's sent to users when an admin selects :::image type="icon" source="media/m365-cc-scc-mark-and-notify-icon.png" border="false"::: **Mark as and notify** on the **Submissions** page at <https://security.microsoft.com/reportsubmission>. The following options are available:
237
258
@@ -253,7 +274,7 @@ When **Monitor reported messages in Outlook** is selected and you also select **
253
274
For more information, see [Automatic user notifications for user reported phishing results in AIR](air-user-automatic-feedback-response.md).
254
275
255
276
-**Customize sender and branding** section:
256
-
-**Specify a Microsoft 365 mailbox to use ads the From address of email notifications**: Select this option and enter the sender's email address in the box that appears. If you don't select this option, the default sender is `[email protected]`.
277
+
-**Specify a Microsoft 365 mailbox to use as the From address of email notifications**: Select this option and enter the sender's email address in the box that appears. If you don't select this option, the default sender is `[email protected]`.
257
278
-**Replace the Microsoft logo with my organization's logo across all reporting experiences**: Select this option to replace the default Microsoft logo that's used in notifications. Before you do this step, follow the instructions in [Customize the Microsoft 365 theme for your organization](/microsoft-365/admin/setup/customize-your-organization-theme) to upload your custom logo.
258
279
259
280
-**Report from quarantine** section \>**Allow reporting for quarantined messages**: Verify that this setting is selected to let users report messages from quarantine as they [release quarantined email messages](quarantine-end-user.md#release-quarantined-email). Otherwise, uncheck this setting.
@@ -654,7 +675,7 @@ The following examples show how to change the user reporting experience without
Copy file name to clipboardExpand all lines: defender-office-365/submissions-users-report-message-add-in-configure.md
+4-2Lines changed: 4 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ manager: bagol
8
8
audience: Admin
9
9
ms.reviewer: dhagarwal
10
10
ms.topic: how-to
11
-
ms.date: 08/27/2025
11
+
ms.date: 10/06/2025
12
12
ms.localizationpriority: medium
13
13
search.appverid:
14
14
- MET150
@@ -70,7 +70,9 @@ The rest of this article describes how to remove the Report Message and Report P
70
70
> [!IMPORTANT]
71
71
> <sup>\*</sup> Microsoft strongly advocates for the principle of least privilege. Assigning accounts only the minimum permissions necessary to perform their tasks helps reduce security risks and strengthens your organization's overall protection. Global Administrator is a highly privileged role that you should limit to emergency scenarios or when you can't use a different role.
72
72
73
-
- For organizational removals, the organization needs to be configured to use OAuth authentication. For more information, see [Determine if Centralized Deployment of add-ins works for your organization](/Microsoft-365/admin/manage/centralized-deployment-of-add-ins).
73
+
- The Report Message and Report Phishing add-ins now use Nested app authentication. For more information, see [Nested app auth requirement set](/javascript/api/requirement-sets/common/nested-app-auth-requirement-sets) . If your Outlook client doesn't support the required NAA authentication, we suggest updating clients in the Microsoft admin center or advising users to use the built-in **Report** button.
74
+
75
+
- For organizational removals, the organization needs to be configured to use OAuth authentication. For more information, see [Determine if Centralized Deployment of add-ins works for your organization](/Microsoft-365/admin/manage/centralized-deployment-of-add-ins).
74
76
75
77
- For more information on how to report a message using reporting in Outlook, see [Report false positives and false negatives in Outlook](submissions-outlook-report-messages.md).
0 commit comments