{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/",
        "slug": "dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/"
        },
        "title": "Preserve the submission envelope when integrating a phishing-report button",
        "summary": "What must a non-Microsoft reporting tool send so Defender can identify the reported message and reason?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:47+00:00",
        "modified_at": "2026-09-10T02:08:05+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 249,
        "potentially_affected": "Supported non-Microsoft reporting tools submitting email to an Exchange Online reporting mailbox.",
        "dse_recommendation": "Validate the attached original, required headers and report-reason prefix rather than only checking mailbox delivery.",
        "primary_source": {
            "name": "Configure user reported message settings in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For non-Microsoft reporting tools, Microsoft requires the unchanged original message as an uncompressed EML or MSG attachment, not a forwarded message. Submissions with several attached messages are discarded. The original must retain the documented antispam, message, network-message and tenant headers. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>The enclosing subject identifies the reporting reason: 1| or Junk:, 2| or Not junk:, and 3| or Phishing:. Without a prefix, the report is classified as phishing. Microsoft also requires preparation of the reporting mailbox as a SecOps mailbox and exclusion from DLP when DLP is used. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review supported non-Microsoft reporting tools submitting email to an Exchange Online reporting mailbox. This is an integration-format check, not advice for users to manually forward suspicious messages or a claim that mailbox receipt guarantees successful triage.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends documenting the tool&#8217;s exact submission envelope before enabling it broadly. Compare a harmless sample&#8217;s attachment, preserved headers and reason prefix with Microsoft&#8217;s requirements. Treat mailbox preparation as an explicit security configuration decision with an assigned owner. Keep reporting-button behavior separate from any later decision to submit the message to Microsoft for analysis.</p>\n<h2>Verification</h2>\n<p>Test junk, not-junk and phishing selections with approved samples and confirm the corresponding reason on the User reported page. Check that each envelope contains exactly one original message. Investigate a missing or wrongly classified entry by inspecting the submission format, rather than asking users to report the same message repeatedly. Preserve a sanitized example for integration regression tests.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: User reported settings</a>.</p>",
        "content_text": "Source facts\nFor non-Microsoft reporting tools, Microsoft requires the unchanged original message as an uncompressed EML or MSG attachment, not a forwarded message. Submissions with several attached messages are discarded. The original must retain the documented antispam, message, network-message and tenant headers. Microsoft Learn.\nThe enclosing subject identifies the reporting reason: 1| or Junk:, 2| or Not junk:, and 3| or Phishing:. Without a prefix, the report is classified as phishing. Microsoft also requires preparation of the reporting mailbox as a SecOps mailbox and exclusion from DLP when DLP is used. Microsoft Learn.\nApplicability\nReview supported non-Microsoft reporting tools submitting email to an Exchange Online reporting mailbox. This is an integration-format check, not advice for users to manually forward suspicious messages or a claim that mailbox receipt guarantees successful triage.\nDSE recommendation\nDSE recommends documenting the tool’s exact submission envelope before enabling it broadly. Compare a harmless sample’s attachment, preserved headers and reason prefix with Microsoft’s requirements. Treat mailbox preparation as an explicit security configuration decision with an assigned owner. Keep reporting-button behavior separate from any later decision to submit the message to Microsoft for analysis.\nVerification\nTest junk, not-junk and phishing selections with approved samples and confirm the corresponding reason on the User reported page. Check that each envelope contains exactly one original message. Investigate a missing or wrongly classified entry by inspecting the submission format, rather than asking users to report the same message repeatedly. Preserve a sanitized example for integration regression tests.\nOfficial references\nMicrosoft Learn: User reported settings.",
        "content_markdown": "## Source facts\n\nFor non-Microsoft reporting tools, Microsoft requires the unchanged original message as an uncompressed EML or MSG attachment, not a forwarded message. Submissions with several attached messages are discarded. The original must retain the documented antispam, message, network-message and tenant headers. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox).\n\nThe enclosing subject identifies the reporting reason: 1| or Junk:, 2| or Not junk:, and 3| or Phishing:. Without a prefix, the report is classified as phishing. Microsoft also requires preparation of the reporting mailbox as a SecOps mailbox and exclusion from DLP when DLP is used. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox).\n\n## Applicability\n\nReview supported non-Microsoft reporting tools submitting email to an Exchange Online reporting mailbox. This is an integration-format check, not advice for users to manually forward suspicious messages or a claim that mailbox receipt guarantees successful triage.\n\n## DSE recommendation\n\nDSE recommends documenting the tool’s exact submission envelope before enabling it broadly. Compare a harmless sample’s attachment, preserved headers and reason prefix with Microsoft’s requirements. Treat mailbox preparation as an explicit security configuration decision with an assigned owner. Keep reporting-button behavior separate from any later decision to submit the message to Microsoft for analysis.\n\n## Verification\n\nTest junk, not-junk and phishing selections with approved samples and confirm the corresponding reason on the User reported page. Check that each envelope contains exactly one original message. Investigate a missing or wrongly classified entry by inspecting the submission format, rather than asking users to report the same message repeatedly. Preserve a sanitized example for integration regression tests.\n\n## Official references\n\n[Microsoft Learn: User reported settings](https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve the submission envelope when integrating a phishing-report button",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/",
                "headline": "Preserve the submission envelope when integrating a phishing-report button",
                "description": "What must a non-Microsoft reporting tool send so Defender can identify the reported message and reason?",
                "abstract": "What must a non-Microsoft reporting tool send so Defender can identify the reported message and reason?",
                "articleBody": "Source facts\nFor non-Microsoft reporting tools, Microsoft requires the unchanged original message as an uncompressed EML or MSG attachment, not a forwarded message. Submissions with several attached messages are discarded. The original must retain the documented antispam, message, network-message and tenant headers. Microsoft Learn.\nThe enclosing subject identifies the reporting reason: 1| or Junk:, 2| or Not junk:, and 3| or Phishing:. Without a prefix, the report is classified as phishing. Microsoft also requires preparation of the reporting mailbox as a SecOps mailbox and exclusion from DLP when DLP is used. Microsoft Learn.\nApplicability\nReview supported non-Microsoft reporting tools submitting email to an Exchange Online reporting mailbox. This is an integration-format check, not advice for users to manually forward suspicious messages or a claim that mailbox receipt guarantees successful triage.\nDSE recommendation\nDSE recommends documenting the tool’s exact submission envelope before enabling it broadly. Compare a harmless sample’s attachment, preserved headers and reason prefix with Microsoft’s requirements. Treat mailbox preparation as an explicit security configuration decision with an assigned owner. Keep reporting-button behavior separate from any later decision to submit the message to Microsoft for analysis.\nVerification\nTest junk, not-junk and phishing selections with approved samples and confirm the corresponding reason on the User reported page. Check that each envelope contains exactly one original message. Investigate a missing or wrongly classified entry by inspecting the submission format, rather than asking users to report the same message repeatedly. Preserve a sanitized example for integration regression tests.\nOfficial references\nMicrosoft Learn: User reported settings.",
                "datePublished": "2026-09-10T00:23:47+00:00",
                "dateModified": "2026-09-10T02:08:05+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve the submission envelope when integrating a phishing-report button"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 249,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure user reported message settings in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox"
                }
            }
        ]
    }
}