# Preserve the submission envelope when integrating a phishing-report button

> What must a non-Microsoft reporting tool send so Defender can identify the reported message and reason?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:47+00:00
- Modified: 2026-09-10T02:08:05+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

What must a non-Microsoft reporting tool send so Defender can identify the reported message and reason?

## Potentially affected

Supported non-Microsoft reporting tools submitting email to an Exchange Online reporting mailbox.

## DSE recommendation

Validate the attached original, required headers and report-reason prefix rather than only checking mailbox delivery.

## Article

## Source facts

For non-Microsoft reporting tools, Microsoft requires the unchanged original message as an uncompressed EML or MSG attachment, not a forwarded message. Submissions with several attached messages are discarded. The original must retain the documented antispam, message, network-message and tenant headers. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox).

The enclosing subject identifies the reporting reason: 1| or Junk:, 2| or Not junk:, and 3| or Phishing:. Without a prefix, the report is classified as phishing. Microsoft also requires preparation of the reporting mailbox as a SecOps mailbox and exclusion from DLP when DLP is used. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox).

## Applicability

Review supported non-Microsoft reporting tools submitting email to an Exchange Online reporting mailbox. This is an integration-format check, not advice for users to manually forward suspicious messages or a claim that mailbox receipt guarantees successful triage.

## DSE recommendation

DSE recommends documenting the tool’s exact submission envelope before enabling it broadly. Compare a harmless sample’s attachment, preserved headers and reason prefix with Microsoft’s requirements. Treat mailbox preparation as an explicit security configuration decision with an assigned owner. Keep reporting-button behavior separate from any later decision to submit the message to Microsoft for analysis.

## Verification

Test junk, not-junk and phishing selections with approved samples and confirm the corresponding reason on the User reported page. Check that each envelope contains exactly one original message. Investigate a missing or wrongly classified entry by inspecting the submission format, rather than asking users to report the same message repeatedly. Preserve a sanitized example for integration regression tests.

## Official references

[Microsoft Learn: User reported settings](https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox).

## Primary reference

- Name: Configure user reported message settings in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve the submission envelope when integrating a phishing-report button,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-489-preserve-the-submission-envelope-when-integrating-a-phishing-report-button/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
