Submission of scam messages

John Phelps 0 Reputation points
2026-08-12T15:56:06.68+00:00

When I submit a scam message to your company, what happens to that submission?

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

2 answers

Sort by: Most helpful
  1. Victor1-V 13,020 Reputation points Microsoft External Staff Moderator
    2026-08-13T07:48:04.0066667+00:00

    Hi John Phelps,

    I understand that you would like to know how a scam-message report is handled after you submit it.

    The Q&A Assist answer correctly explains that submitted messages may be analyzed to improve email protection. However, the sections about the Microsoft Defender portal and administrator submissions apply mainly to Microsoft 365 work or school organizations, rather than a personal Outlook.com account.

    Have you had a chance to review or try the guidance provided in the Q&A Assist answer? I would also like to add that, in Outlook.com, selecting Report > Report phishing reports the sender, removes the message from the Inbox, and helps improve future filtering. Reporting does not automatically block the sender, so you can separately add the address to Blocked senders if needed. See Phishing and suspicious behavior in Outlook.

    Please note that this is a user-to-user forum, so contributors cannot access submitted reports or provide their individual review status.

    I hope this clarifies what happens after a scam message is reported.


    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.    

    Was this answer helpful?


  2. AI answer

    2026-08-12T15:56:21.14+00:00

    When a scam or suspicious message is submitted to Microsoft, the submission is copied and included in continual algorithm reviews. The copy can include the message content, headers, attachments, routing data, and other data directly associated with the message.

    Microsoft treats the submission as the organization’s permission to analyze that information to improve submission hygiene algorithms. The submitted data is stored in secured and audited data centers in the USA and is deleted when it is no longer required. Microsoft personnel might read submitted messages and attachments during the review process, but the submission is treated as confidential and isn’t shared with other parties as part of that review.

    For admin submissions in Microsoft 365 organizations, Microsoft also performs analysis such as:

    1. Email authentication checks.
    2. Policy or override checks that could have affected the verdict.
    3. Detonation results for URLs or files to determine whether they are malicious.
    4. Feedback from graders.

    The analysis results are shown on the Submissions page in the Microsoft Defender portal.

    For U.S. Government organizations (GCC, GCC High, and DoD), submissions are analyzed only for email authentication and policy checks. Payload reputation, detonation, and grader analysis aren’t performed because data can’t leave the organization boundary. In that case, the result can show Further investigation needed, and Microsoft support is required for review.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.